An open API service providing security vulnerability metadata for many open source software ecosystems.

Browse Security Advisories

Moderate
3 months ago

Liferay Cross-site Scripting vulnerability GSA_kwCzR0hTQS1xaHA2LXZwN2MtZzd4cM4ABG8e

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
4 months ago

Liferay Portal and Liferay DXP Reveals Data via Forms GSA_kwCzR0hTQS05ZmNnLXdycDgtcWhyNM4ABFwV

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
4 months ago

Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) GSA_kwCzR0hTQS1ocmM0LXAyaDMtcGpxd84ABFp_

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
8 months ago

Liferay Portal and Liferay DXP have Cross-site Scripting vulnerability in edit Service Access Policy page GSA_kwCzR0hTQS1weDM4LTIzOWcteDVtZ84ABCiF

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
8 months ago

Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting GSA_kwCzR0hTQS00aHhyLTI4bXYtcTcyOc4ABCiC

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
9 months ago

Liferay Portal and Liferay DXP Vulnerable to CSRF in the Script Console GSA_kwCzR0hTQS1jaGoyLTR2ZzctaGhnM84ABAkm

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
9 months ago

Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the My Account Widget GSA_kwCzR0hTQS02YzR2LXg5djItcmptOM4ABAk1

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
over 1 year ago

Liferay Portal Document and Media widget and Liferay DXP vulnerable to stored Cross-site Scripting GSA_kwCzR0hTQS1xMmN2LTdqNTgtcmZtas4AA5bF

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 1 year ago

Liferay Portal Calendar module and Liferay DXP vulnerable to Cross-site Scripting, content spoofing GSA_kwCzR0hTQS1oZ3I2LTZoaHctODgzZs4AA5aV

maven com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom
Critical
over 1 year ago

Liferay Portal Frontend JS module's portlet.js and Liferay DXP vulnerable to Cross-site Scripting GSA_kwCzR0hTQS1yd2h2LWh2ajItcXJxbc4AA5aN

maven com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom
Critical
over 1 year ago

Liferay Portal's Dynamic Data Mapping module's DDMForm and Liferay DXP vulnerable to stored Cross-site Scripting GSA_kwCzR0hTQS00NGpnLWpnangtM3hnNc4AA5aM

maven com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom
Critical
over 1 year ago

Liferay Portal and Liferay DXP vulnerable to stored Cross-site Scripting GSA_kwCzR0hTQS1yd3hjLTRjbXctN3g3Nc4AA5aL

maven com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom
Critical
over 1 year ago

Liferay Portal Language Override edit screen and Liferay DXP vulnerable to reflected Cross-site Scripting GSA_kwCzR0hTQS03M3gzLThtcmctNXI5M84AA5aE

maven com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom
Critical
over 1 year ago

Liferay Portal and Liferay DXP's Users Admin module vulnerable to stored Cross-site Scripting GSA_kwCzR0hTQS12MnhxLW0yMnctam1wcs4AA5aH

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
over 1 year ago

Liferay Portal and Liferay DXP vulnerable to reflected Cross-site Scripting GSA_kwCzR0hTQS01NHB2LXI2MmotOXFxY84AA5aC

maven com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom
Critical
over 1 year ago

Liferay Portal and Liferay DXP vulnerable to reflected Cross-site Scripting GSA_kwCzR0hTQS00Njh4LWZyY20tZ2h4Ns4AA5aB

maven com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom
Critical
over 1 year ago

Liferay Portal Message Board widget and Liferay DXP vulnerable to stored Cross-site Scripting GSA_kwCzR0hTQS1wMjh4LTRyNWgtcGg2as4AA5aJ

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
over 1 year ago

Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting GSA_kwCzR0hTQS14cGpnLTdoeDctd2djeM4AA5aI

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
over 1 year ago

Liferay Portal Expando module and Liferay DXP vulnerable to stored Cross-site Scripting GSA_kwCzR0hTQS1jcjM2LTN2cWYteDV3Nc4AA5aK

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
over 1 year ago

Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery in Terms of Use Page GSA_kwCzR0hTQS1taDlyLTlwY3gtcng1Nc4AA5Z6

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:com.liferay.portal.impl
Moderate
over 1 year ago

Liferay Portal and Liferay DXP Does Not Obfuscate Password Reminder Answers GSA_kwCzR0hTQS1td2hmLTZtam0tNnczaM4AA5Z2

maven com.liferay.portal:release.dxp.bom, com.liferay.commerce:com.liferay.commerce.account.web, com.liferay:com.liferay.login.web, com.liferay:com.liferay.users.admin.web, com.liferay.portal:portal-impl
Moderate
over 1 year ago

Liferay Portal and Liferay DXP vulnerable to theft of hashed password GSA_kwCzR0hTQS14cTRyLTR4ZmgtdmNoOM4AA5ZB

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 1 year ago

Liferay Portal and Liferay DXP User Enumeration Vulnerability GSA_kwCzR0hTQS1xbTQzLWcyeGotaHZnNc4AA5Y1

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
over 1 year ago

Liferay Portal has a Stored XSS with Blog entries (Insecure defaults) GSA_kwCzR0hTQS12dnBmLTUzcXgtY3hoaM4AA5Ym

maven com.liferay.portal:com.liferay.portal.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 1 year ago

Liferay Portal and Liferay DXP HTTP Header Can Expose Versions GSA_kwCzR0hTQS0ybXZqLXEycTMtd3hqds4AA5Yp

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 1 year ago

Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Two Forward Slashes GSA_kwCzR0hTQS0zcXE1LXdjcngtNGg4cs4AA5Yk

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
over 1 year ago

Liferay Portal defaults to a low work factor for the default password hashing algorithm GSA_kwCzR0hTQS00M2g5LXAzajQtMzlobc4AA5Yf

maven com.liferay.portal:com.liferay.portal.kernel, com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom
Moderate
over 1 year ago

Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Replacement Character GSA_kwCzR0hTQS01NDh4LWo2eDYtaGN2NM4AA5Yc

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 1 year ago

Liferay Portal and Liferay DXP Allows Authenticated Users with View Permissions to Edit Permissions GSA_kwCzR0hTQS1wdzdwLTM2NDgtcXFtZ84AA5YY

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 1 year ago

Liferay Portal and Liferay DXP Allows Templates to be Viewed via the UI or API GSA_kwCzR0hTQS1tZjhoLWdyZmctajlqM84AA5YZ

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
over 1 year ago

Liferay Portal has an XXE vulnerability in Java2WsddTask._format GSA_kwCzR0hTQS04NjloLXFoZngtdzkzOc4AA5Ya

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom, com.liferay.portal:com.liferay.util.java
Moderate
over 1 year ago

Liferay Portal and Liferay DXP Does Not Properly Restrict Membership to Child Site Based on Parent Site Options GSA_kwCzR0hTQS1xcGdoLTZ2OXctdmZ2Ns4AA5YT

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 1 year ago

Liferay Portal and Liferay DXP Information Disclosure Vulnerability in the Control Panel GSA_kwCzR0hTQS00NTg1LTI4djItOGg0Ns4AA5YU

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 1 year ago

Liferay Portal and Liferay DXP Vulnerable to Open Redirect in Countries Management's Edit Region Page GSA_kwCzR0hTQS1mM3JmLWNyN2YtY3djNM4AA5YP

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 1 year ago

Liferay Portal allows attackers to discover the existence of sites GSA_kwCzR0hTQS1tcWY4LTRjcW0tcDgzeM4AA5J6

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
over 1 year ago

Liferay Portal vulnerable to user impersonation GSA_kwCzR0hTQS1xd2o4LXFncHItOGNybc4AA5J7

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 1 year ago

Liferay Portal denial-of-service vulnerability GSA_kwCzR0hTQS13Mjc1LW04Y3ItaGYyds4AA5J4

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 1 year ago

Liferay Portal's account lockout does not invalidate existing user sessions GSA_kwCzR0hTQS0ybXg3LXh2ZmctZmc1M84AA5J2

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
over 1 year ago

Liferay Portal stored cross-site scripting (XSS) vulnerability GSA_kwCzR0hTQS05dmdxLXc1cHYtdjc3cc4AA5JF

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
almost 2 years ago

Liferay Portal and Liferay DXP Vulnerable to XSS in the Commerce Module GSA_kwCzR0hTQS1xcDY4LTV2Mzktcjg2Oc4AA2gl

maven com.liferay.portal:release.dxp.bom, com.liferay.commerce:com.liferay.commerce.address.content.web
Critical
almost 2 years ago

Liferay Portal and Liferay DXP Vulnerable to XSS via the Page Tree Menu GSA_kwCzR0hTQS1qNWd2LXc4MzgtbW1jeM4AA2gC

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.layout.impl
Critical
almost 2 years ago

Liferay Portal and Liferay DXP Vulnerable to XSS via the OAuth2ProviderApplicationRedirect Class GSA_kwCzR0hTQS00OWdtLTU2ODUtOGZ4ds4AA2gK

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.oauth2.provider.rest
Critical
almost 2 years ago

Liferay Portal and Liferay DXP Vulnerable to XSS in the Wiki Widget GSA_kwCzR0hTQS1odjQ1LXIyZjUtZm1oas4AA2gI

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.wiki.web
Critical
over 2 years ago

Liferay Portal and Liferay DXP Vulnerable to SQL Injection via Friendly URL Module GSA_kwCzR0hTQS1odzU2LTd4ajQtN2d4Ns4AAv33

maven com.liferay:com.liferay.friendly.url.service, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 2 years ago

Liferay Portal and Liferay DXP Includes LDAP Credentials in the Page URL GSA_kwCzR0hTQS1mNDNtLWhoajQtcTNqZ84AAv32

maven com.liferay:com.liferay.portal.settings.authentication.ldap.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
over 2 years ago

Liferay Portal and Liferay DXP Vulnerable to SQL Injection via the Fragment Module GSA_kwCzR0hTQS1yNWZqLWo0NDktdnF3Ms4AAv3x

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.fragment.service
Moderate
almost 3 years ago

Liferay Portal and Liferay DXP Vulnerable to XSS in the Frontend Taglib Module GSA_kwCzR0hTQS1nNnIyLTZ4NDYtanBwNs4AAvbH

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.frontend.taglib.clay
Moderate
almost 3 years ago

Liferay Portal and Liferay DXP Vulnerable to XSS via the Role Module GSA_kwCzR0hTQS1jbXJ3LWNnZmMtdjZ4Ms4AAvcp

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.roles.admin.web
Moderate
almost 3 years ago

Liferay Portal and Liferay DXP Vulnerable to XSS in the CKEditor Integration with the Frontend Editor Module GSA_kwCzR0hTQS02N2pwLTI3amotNng4Nc4AAvcm

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.frontend.editor.ckeditor.web
Moderate
almost 3 years ago

Liferay Portal and Liferay DXP Vulnerable to XSS via the Portal Search Module GSA_kwCzR0hTQS03ZjdnLXZoZmYtbWpxas4AAvce

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.portal.search.web
Moderate
almost 3 years ago

Liferay Portal and Liferay DXP Vulnerable to XSS via the Document Library Module GSA_kwCzR0hTQS1yMzJ3LXY3NzUtNTk1Ms4AAvco

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.document.library.web
Moderate
almost 3 years ago

Liferay Portal and Liferay DXP Vulnerable to XSS in the Portal Search Module GSA_kwCzR0hTQS03cjN3LXdnZ20tcGp3Zs4AAvAH

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.portal.search.web
Moderate
almost 3 years ago

Liferay Portal and Liferay DXP Vulnerable to XSS via the filter_ Prefix GSA_kwCzR0hTQS04bXA5LXc3Z3ItcHZqM84AAvAQ

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.fragment.renderer.collection.filter.impl
Moderate
almost 3 years ago

Liferay Portal and Liferay DXP HtmlUtil.escapeRedirect Can Be Circumvented GSA_kwCzR0hTQS13Mzk3LTlwMmotNngyM84AAvAJ

maven com.liferay.portal:com.liferay.util.java, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
almost 3 years ago

Liferay Portal and Liferay DXP Fails to Check Permissions in Translation Module GSA_kwCzR0hTQS1oOXd3LXdqZzQtanZ2Z84AAvAM

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.translation.web
Moderate
almost 3 years ago

Liferay Portal and Liferay DXP Vulnerable to XSS in the Site Module GSA_kwCzR0hTQS03bTY1LWhtdmctcnhwY84AAvAL

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.site.memberships.web
High
about 3 years ago

Liferay Portal and Liferay DXP fails to invalidate password reset tokens after use GSA_kwCzR0hTQS12d2o4LTRncmYtM3I4ds4AArKO

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:com.liferay.portal.impl
High
about 3 years ago

Liferay Portal and Liferay DXP Has Company Administrator Accounts Vulnerable to Takeovers GSA_kwCzR0hTQS01Z2g5LWc2MmgtZjM1bc4AApas

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
about 3 years ago

Liferay Portal Fragment Module and Liferay DXP Vulnerable to Cross-Site Scripting GSA_kwCzR0hTQS03cHhoLXE2anctNnhqOM4AApaW

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
about 3 years ago

Liferay Portal Layout Module and Liferay DXP Exposes the Cross-Site Request Forgery (CSRF) Token in URLs GSA_kwCzR0hTQS00ZnJnLXJweDYtOTZxaM4AApaL

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
about 3 years ago

Liferay Portal Journal Module and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) GSA_kwCzR0hTQS1mdmc2LTlyODgtN3c4Nc4AApad

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
about 3 years ago

Liferay Portal and Liferay DXP Cross-site scripting (XSS) vulnerability in the Document Library module GSA_kwCzR0hTQS12ODhnLTdmeDQtOXE3Zs4AApaP

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.document.library.web
Moderate
about 3 years ago

Liferay Portal and Liferay DXP does not properly check user permission GSA_kwCzR0hTQS0yMndjLTd3bW0tdjRjY84AApYv

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.portlet.configuration.web
Moderate
about 3 years ago

Liferay Portal and Liferay DXP Don't Check Permissions of Pages GSA_kwCzR0hTQS00NzRmLWNteDUtZ202Oc4AApYV

maven com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom
Moderate
about 3 years ago

Liferay Portal and Liferay DXP vulnerable to email spam via lack of flagging rate GSA_kwCzR0hTQS13ZzR4LWhmOTQtZmo1ds4AApYl

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.flags.taglib
Moderate
about 3 years ago

Liferay Portal and Liferay DXP Stores User Passwords in Cleartext GSA_kwCzR0hTQS02Yzg4LWd2eHctZjVoZ84AApYt

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
about 3 years ago

Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in Edit Vocabulary Page GSA_kwCzR0hTQS12cHZtLTN3ZnctNWY1Y84AApYh

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
about 3 years ago

Liferay Portal and Liferay DXP autosaves form data for other users to see GSA_kwCzR0hTQS1meHBmLWpyMnEtdnB2ds4AApYT

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.dynamic.data.mapping.form.web
Moderate
about 3 years ago

Liferay Portal and Liferay DXP Cross-site scripting (XSS) vulnerability in the Frontend JS module GSA_kwCzR0hTQS1oZ2p2LTd3anItcXdxcM4AApYn

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.frontend.js.aui.web
Moderate
about 3 years ago

Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) GSA_kwCzR0hTQS05OTk1LXF2Y2cteDdnNs4AApYE

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
about 3 years ago

Liferay Portal and Liferay DXP Fails to Properly Check User Permissions GSA_kwCzR0hTQS1nMzdmLWo4aGgtNzM2Zs4AApX-

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
about 3 years ago

Liferay Portal and Liferay DXP Fails to Check User Permissions for Workflow Submissions GSA_kwCzR0hTQS1nN3hjLW03NjItd2c4Zs4AApX8

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
about 3 years ago

Liferay Portal and Liferay DXP Allows Arbitrary Redirect of Users to External URLs GSA_kwCzR0hTQS1tajh3LWg1MjItandtOM4AApYH

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
about 3 years ago

Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in the Layout Admin Page GSA_kwCzR0hTQS00Zng4LTgyZjMteGNwY84AAohY

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
about 3 years ago

Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via Membership Request Admin Page GSA_kwCzR0hTQS13Y3I1LTNxOTYtYzJncs4AAohc

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
about 3 years ago

Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via the Redirect's Admin Page GSA_kwCzR0hTQS1xY3Y0LWd2NDMtNDk4ds4AAohR

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
about 3 years ago

Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via Asset Module Parameter GSA_kwCzR0hTQS05ZzU3LW01dmYtcXA3M84AAoha

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
about 3 years ago

Liferay Portal and Liferay DXP May Reveal S3 Store's Proxy Password GSA_kwCzR0hTQS14eDJoLTJoZjUtdjd2ds4AAohe

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
about 3 years ago

Liferay Portal and Liferay DXP Vulnerable to Multiple SQL Injections GSA_kwCzR0hTQS1mOXdqLWM1cGMtZzlyaM4AAohx

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
about 3 years ago

Liferay Portal and Liferay DXP Fails to Check Permissions GSA_kwCzR0hTQS1wcjd2LXF2NjUtcnA5bc4AAohh

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
about 3 years ago

Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in Asset Publisher App GSA_kwCzR0hTQS1qdnZ4LThnNDItOTU1Oc4AAohQ

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
about 3 years ago

Liferay Portal and Liferay DXP Fails to Invalidate CAPTCHA Answers After Use GSA_kwCzR0hTQS05bXhnLXA4NzMtNjc5M84AAogj

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
about 3 years ago

Liferay Portal and Liferay DXP Reveals Data via Overly Verbose Error Messages GSA_kwCzR0hTQS04N3g3LXB3cngtamNoN84AAogi

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
about 3 years ago

Liferay Portal and Liferay DXP Bypass via Double Encoded URL GSA_kwCzR0hTQS12cnd4LXE5cGoteDQ4OM4AAmDc

maven com.liferay.portal:com.liferay.portal.impl, com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom
High
about 3 years ago

Liferay Portal and Liferay DXP have Insecure Deserialization Vulnerability GSA_kwCzR0hTQS1tZzNyLTlqaDgtMzNyOc4AAlbG

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
about 3 years ago

Liferay Portal and Liferay DXP Potentially Reveal LDAP Server Password via Unsafe Connection GSA_kwCzR0hTQS03NzNmLWY5MjktcWdqas4AAlbC

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
about 3 years ago

Liferay Portal and Liferay DXP Fails to Sanitize API Data GSA_kwCzR0hTQS04ajVyLTk2ODctODh3Nc4AAk8n

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
about 3 years ago

Liferay Portal and Liferay DXP Vulnerable to Arbitrary Code Execution GSA_kwCzR0hTQS12Mzc3LThmOGYtNTMyaM4AAk8s

maven com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 3 years ago

Liferay Portal and Liferay DXP allows arbitrary injection via web content template names GSA_kwCzR0hTQS13N2YyLTY4OTYtNm1tMs1BEg

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.journal.content.web
Moderate
over 3 years ago

Liferay Portal and Liferay DXP allows arbitrary injection via the site name GSA_kwCzR0hTQS0zdnd3LWpybW0tOXZmZs1A6w

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.layout.seo.web
Moderate
over 3 years ago

Liferay Portal and Liferay DXP fails to check permissions to view sites/groups GSA_kwCzR0hTQS04MjJmLWpmcGctaGc3aM09mw

maven com.liferay.portal:com.liferay.portal.impl, com.liferay:com.liferay.site.browser.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 3 years ago

Liferay Portal and Liferay DXP allows arbitrary injection via the name of an asset category GSA_kwCzR0hTQS1xMnJwLXhmajgtcjk1aM09mA

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.asset.taglib
Moderate
over 3 years ago

Liferay Portal and Liferay DXP allows arbitrary injection via form field GSA_kwCzR0hTQS02NThmLXhodjQtcDk3OM08rQ

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.dynamic.data.mapping.form.field.type
High
over 3 years ago

Liferay Portal and Liferay DXP fails to properly import users from LDAP GSA_kwCzR0hTQS1qcDNtLXZoM2ctNmdncM0wOg

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.portal.security.ldap.impl
Moderate
over 3 years ago

Liferay Portal and Liferay DXP vulnerable to cross-site scripting (XSS) GSA_kwCzR0hTQS0zeDgzLXdoeHctcHZtZ80wCQ

maven com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.layout.admin.web
Moderate
over 3 years ago

Liferay Portal and Liferay DXP vulnerable to cross-site scripting (XSS) in edit blog entry page GSA_kwCzR0hTQS1yMzl4LTNxcTQtZ3htcs0wCw

maven com.liferay:com.liferay.frontend.js.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom

Filter by Severity

Filter by Ecosystem

Filter by Package

tensorflow 433 tensorflow-gpu 427 tensorflow-cpu 423 moodle/moodle 418 magento/community-edition 300 Microsoft.ChakraCore 247 org.jenkins-ci.main:jenkins-core 239 typo3/cms 190 org.apache.tomcat:tomcat 138 pimcore/pimcore 120 dolibarr/dolibarr 116 github.com/mattermost/mattermost/server/v8 115 typo3/cms-core 111 com.liferay.portal:release.portal.bom 110 Django 107 phpmyadmin/phpmyadmin 107 com.liferay.portal:release.dxp.bom 105 drupal/core 103 magento/project-community-edition 100 microweber/microweber 99 silverstripe/framework 92 apache-airflow 85 drupal/drupal 83 librenms/librenms 82 thorsten/phpmyfaq 73 Plone 72 com.fasterxml.jackson.core:jackson-databind 69 symfony/symfony 69 github.com/usememos/memos 66 concrete5/concrete5 65 salt 65 ansible 63 actionpack 61 apache-superset 57 org.apache.struts:struts2-core 57 shopware/platform 57 github.com/grafana/grafana 56 mlflow 53 craftcms/cms 51 org.keycloak:keycloak-core 50 nova 48 baserproject/basercms 47 org.apache.tomcat.embed:tomcat-embed-core 46 django 46 nokogiri 46 shopware/core 45 vyper 44 github.com/rancher/rancher 44 gradio 44 mautic/core 44 matrix-synapse 42 rdiffweb 42 nilsteampassnet/teampass 42 org.keycloak:keycloak-services 41 mantisbt/mantisbt 41 org.xwiki.platform:xwiki-platform-oldcore 41 org.elasticsearch:elasticsearch 41 plone 41 k8s.io/kubernetes 41 showdoc/showdoc 41 github.com/hashicorp/vault 40 froxlor/froxlor 40 github.com/mattermost/mattermost-server/v6 39 intelliants/subrion 39 directus 38 com.thoughtworks.xstream:xstream 37 net.mingsoft:ms-mcms 36 com.jfinal:jfinal 36 snipe/snipe-it 36 moin 35 org.jenkins-ci.plugins:script-security 34 github.com/answerdev/answer 34 zendframework/zendframework1 34 io.undertow:undertow-core 34 parse-server 33 gogs.io/gogs 33 keystone 32 github.com/hashicorp/nomad 31 Pillow 31 opencv-python 31 github.com/argoproj/argo-cd/v2 31 github.com/docker/docker 31 github.com/argoproj/argo-cd 31 github.com/cilium/cilium 31 opencv-contrib-python 31 shopware/shopware 30 getgrav/grav 30 github.com/hashicorp/consul 29 rack 29 github.com/mattermost/mattermost-server 29 org.apache.solr:solr-core 28 mediawiki/core 28 electron 28 org.opencms:opencms-core 27 centreon/centreon 27 openssl-src 26 prestashop/prestashop 26 next 26 org.springframework.security:spring-security-core 26 pillow 26 org.eclipse.jetty:jetty-server 25 open-webui 25 contao/core-bundle 25 rubygems-update 25 getkirby/cms 24 pocketmine/pocketmine-mp 24 github.com/traefik/traefik/v2 24 org.keycloak:keycloak-parent 24 magento/core 24 surrealdb 24 remdex/livehelperchat 23 grumpydictator/firefly-iii 23 vllm 23 laravel/framework 23 simplesamlphp/simplesamlphp 23 zendframework/zendframework 23 puppet 23 phpoffice/phpexcel 23 Microsoft.AspNetCore.App.Runtime.win-x64 22 tribalsystems/zenario 22 Microsoft.AspNetCore.App.Runtime.win-x86 22 DotNetNuke.Core 22 org.bouncycastle:bcprov-jdk14 22 ckb 22 org.apache.openmeetings:openmeetings-parent 22 @openzeppelin/contracts-upgradeable 22 github.com/ethereum/go-ethereum 21 @openzeppelin/contracts 21 org.apache.tomcat:tomcat-catalina 21 phpoffice/phpspreadsheet 21 github.com/goharbor/harbor 21 activerecord 21 glance 21 Microsoft.AspNetCore.App.Runtime.win-arm 21 org.apache.nifi:nifi 21 code.gitea.io/gitea 20 langchain 20 funadmin/funadmin 20 aim 20 org.cloudfoundry.identity:cloudfoundry-identity-server 20 cockpit-hq/cockpit 20 pyload-ng 20 golang.org/x/net 20 wasmtime 20 github.com/zitadel/zitadel 19 helm.sh/helm/v3 19 org.apache.tomcat:tomcat-coyote 19 Microsoft.AspNetCore.App.Runtime.linux-arm 19 Microsoft.AspNetCore.App.Runtime.linux-arm64 19 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 19 Microsoft.AspNetCore.App.Runtime.linux-x64 19 deno 19 Microsoft.AspNetCore.App.Runtime.osx-x64 19 org.xwiki.platform:xwiki-platform-web-templates 19 Microsoft.AspNetCore.App.Runtime.win-arm64 19 neutron 19 mercurial 18 genix/cms 18 mindsdb 18 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 18 contao/contao 18 cobbler 18 forkcms/forkcms 18 topthink/framework 18 com.vaadin:vaadin-bom 18 org.apache.geode:geode-core 17 ezsystems/ezpublish-kernel 17 yetiforce/yetiforce-crm 17 notebook 17 org.apache.inlong:manager-pojo 17 calibreweb 17 OctoPrint 17 cakephp/cakephp 17 symfony/security 17 cryptography 17 francoisjacquet/rosariosis 17 openmage/magento-lts 17 typo3/cms-backend 17 org.springframework:spring-core 17 opencart/opencart 17 org.apache.activemq:activemq-client 16 ethyca-fides 16 Microsoft.NetCore.App.Runtime.win-arm64 16 org.bouncycastle:bcprov-jdk15 16 github.com/traefik/traefik/v3 16 sequelize 16 Microsoft.NetCore.App.Runtime.win-x64 16 Microsoft.NetCore.App.Runtime.win-arm 16 Microsoft.NetCore.App.Runtime.win-x86 16 org.apache.ranger:ranger 16 tinymce 16 github.com/openfga/openfga 16 october/system 16 phpbb/phpbb 16 org.apache.jspwiki:jspwiki-main 16 PaddlePaddle 16 paddlepaddle 16 lollms 16 org.apache.dubbo:dubbo 16 rusqlite 16

Filter by Repository