Security Advisories for com.liferay.portal:release.dxp.bom in maven
Moderate
3 months ago
Liferay Portal and Liferay DXP vulnerable to Stored Cross-site Scripting
maven
com.liferay:com.liferay.portal.workflow.task.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
3 months ago
Liferay Portal and Liferay DXP vulnerable to store Cross-site Scripting
maven
com.liferay:com.liferay.portal.workflow.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal 7.4.0 and Liferay DXP have a reflected cross-site scripting (XSS) vulnerability
maven
com.liferay:com.liferay.frontend.taglib.clay, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal and Liferay DXP have a reflected cross-site scripting vulnerability
maven
com.liferay.portal:com.liferay.portal.impl, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal and Liferay DXP have a Denial Of Service via File Upload (DOS) vulnerability
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal and Liferay DXP vulnerable to Server-Side Request Forgery
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal and Liferay DXP vulnerable to Server-Side Request Forgery
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
8 months ago
Liferay Cross-site Scripting vulnerability
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
9 months ago
Liferay Portal and Liferay DXP Reveals Data via Forms
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
9 months ago
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
12 months ago
Liferay Portal and Liferay DXP have Cross-site Scripting vulnerability in edit Service Access Policy page
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
12 months ago
Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
about 1 year ago
Liferay Portal and Liferay DXP Vulnerable to CSRF in the Script Console
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
about 1 year ago
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the My Account Widget
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
about 1 year ago
Liferay Portal and Liferay DXP Workflow Component Does Not Check User Permissions
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
about 1 year ago
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the Content Page Editor
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
about 1 year ago
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the Content Page Editor
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
almost 2 years ago
Liferay Portal Document and Media widget and Liferay DXP vulnerable to stored Cross-site Scripting
maven
com.liferay.portal:release.dxp.bom
Moderate
almost 2 years ago
Liferay Portal Calendar module and Liferay DXP vulnerable to Cross-site Scripting, content spoofing
maven
com.liferay.portal:release.dxp.bom
Critical
almost 2 years ago
Liferay Portal's Dynamic Data Mapping module's DDMForm and Liferay DXP vulnerable to stored Cross-site Scripting
maven
com.liferay.portal:release.dxp.bom
Critical
almost 2 years ago
Liferay Portal Frontend JS module's portlet.js and Liferay DXP vulnerable to Cross-site Scripting
maven
com.liferay.portal:release.dxp.bom
Critical
almost 2 years ago
Liferay Portal and Liferay DXP vulnerable to stored Cross-site Scripting
maven
com.liferay.portal:release.dxp.bom
Critical
almost 2 years ago
Liferay Portal and Liferay DXP vulnerable to reflected Cross-site Scripting
maven
com.liferay.portal:release.dxp.bom
Critical
almost 2 years ago
Liferay Portal and Liferay DXP's Users Admin module vulnerable to stored Cross-site Scripting
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
almost 2 years ago
Liferay Portal Message Board widget and Liferay DXP vulnerable to stored Cross-site Scripting
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
almost 2 years ago
Liferay Portal Expando module and Liferay DXP vulnerable to stored Cross-site Scripting
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
almost 2 years ago
Liferay Portal and Liferay DXP vulnerable to reflected Cross-site Scripting
maven
com.liferay.portal:release.dxp.bom
Critical
almost 2 years ago
Liferay Portal Language Override edit screen and Liferay DXP vulnerable to reflected Cross-site Scripting
maven
com.liferay.portal:release.dxp.bom
Critical
almost 2 years ago
Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
almost 2 years ago
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery in Terms of Use Page
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:com.liferay.portal.impl
Moderate
almost 2 years ago
Liferay Portal and Liferay DXP Does Not Obfuscate Password Reminder Answers
maven
com.liferay.portal:release.dxp.bom, com.liferay.commerce:com.liferay.commerce.account.web, com.liferay:com.liferay.login.web, com.liferay:com.liferay.users.admin.web, com.liferay.portal:portal-impl
Moderate
almost 2 years ago
Liferay Portal and Liferay DXP User Enumeration Vulnerability
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal and Liferay DXP vulnerable to theft of hashed password
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
almost 2 years ago
Liferay Portal has a Stored XSS with Blog entries (Insecure defaults)
maven
com.liferay.portal:com.liferay.portal.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal and Liferay DXP HTTP Header Can Expose Versions
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Replacement Character
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Two Forward Slashes
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
almost 2 years ago
Liferay Portal defaults to a low work factor for the default password hashing algorithm
maven
com.liferay.portal:com.liferay.portal.kernel, com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom
Moderate
almost 2 years ago
Liferay Portal and Liferay DXP Allows Templates to be Viewed via the UI or API
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal and Liferay DXP Allows Authenticated Users with View Permissions to Edit Permissions
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
almost 2 years ago
Liferay Portal has an XXE vulnerability in Java2WsddTask._format
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom, com.liferay.portal:com.liferay.util.java
Moderate
almost 2 years ago
Liferay Portal and Liferay DXP Does Not Properly Restrict Membership to Child Site Based on Parent Site Options
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal and Liferay DXP Information Disclosure Vulnerability in the Control Panel
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal and Liferay DXP Vulnerable to Open Redirect in Countries Management's Edit Region Page
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal denial-of-service vulnerability
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
almost 2 years ago
Liferay Portal vulnerable to user impersonation
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal allows attackers to discover the existence of sites
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal's account lockout does not invalidate existing user sessions
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
almost 2 years ago
Liferay Portal stored cross-site scripting (XSS) vulnerability
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
about 2 years ago
Liferay Portal and Liferay DXP Vulnerable to XSS in the Commerce Module
maven
com.liferay.portal:release.dxp.bom, com.liferay.commerce:com.liferay.commerce.address.content.web
Critical
about 2 years ago
Liferay Portal and Liferay DXP Vulnerable to XSS in the Wiki Widget
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.wiki.web
Critical
about 2 years ago
Liferay Portal and Liferay DXP Vulnerable to XSS via the OAuth2ProviderApplicationRedirect Class
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.oauth2.provider.rest
Critical
about 2 years ago
Liferay Portal and Liferay DXP Vulnerable to XSS via the Page Tree Menu
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.layout.impl
Critical
about 2 years ago
Liferay Portal and Liferay DXP Vulnerable to Reflected XSS via the Export for Translation Page
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.translation.web
Critical
about 2 years ago
Liferay Portal and Liferay DXP Vulnerable to XSS in the Fragment Components
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.fragment.entry.processor.impl
Critical
about 2 years ago
Liferay Portal and Liferay DXP Vulnerable to Stored XSS in the Manage Vocabulary Page
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.asset.categories.admin.web
Moderate
over 2 years ago
Liferay Portal and Liferay DXP Organization Selector Does Not Check User Permissions
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.organizations.item.selector.web
High
over 2 years ago
Liferay Portal and Liferay DXP Vulnerable to CSRF via the Layout Module
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 2 years ago
Liferay Portal and Liferay DXP Vulnerable to Open Redirect via the Layout Module
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 2 years ago
Liferay Portal and Liferay DXP Vulnerable to XSS via the Layout Module
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
about 3 years ago
Liferay Portal and Liferay DXP Includes LDAP Credentials in the Page URL
maven
com.liferay:com.liferay.portal.settings.authentication.ldap.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
about 3 years ago
Liferay Portal and Liferay DXP Vulnerable to XSS via the Commerce Module
maven
com.liferay.portal:release.dxp.bom, com.liferay.commerce:com.liferay.commerce.catalog.web
Critical
about 3 years ago
Liferay Portal and Liferay DXP Vulnerable to SQL Injection via the Fragment Module
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.fragment.service
Moderate
about 3 years ago
Liferay Portal and Liferay DXP Vulnerable to XSS via the Announcements Module
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.announcements.web
Moderate
about 3 years ago
Liferay Portal and Liferay DXP Vulnerable to XSS via the Sharing Module
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.sharing.web
Critical
about 3 years ago
Liferay Portal and Liferay DXP Vulnerable to SQL Injection via Friendly URL Module
maven
com.liferay:com.liferay.friendly.url.service, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
about 3 years ago
Liferay Portal and Liferay DXP Vulnerable to XSS via the Portal Search Module
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.portal.search.web
High
about 3 years ago
Liferay Portal and Liferay DXP Vulnerable to SQL Injection via the Layout Module
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.layout.page.template.service
Moderate
about 3 years ago
Liferay Portal and Liferay DXP Vulnerable to XSS in the Frontend Taglib Module
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.frontend.taglib.clay
Moderate
about 3 years ago
Liferay Portal and Liferay DXP Vulnerable to XSS via the Portal Search Module
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.portal.search.web
Moderate
about 3 years ago
Liferay Portal and Liferay DXP Vulnerable to XSS in the CKEditor Integration with the Frontend Editor Module
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.frontend.editor.ckeditor.web
Moderate
about 3 years ago
Liferay Portal and Liferay DXP Vulnerable to XSS via the Role Module
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.roles.admin.web
Moderate
about 3 years ago
Liferay Portal and Liferay DXP Fails to Check Permissions in Translation Module
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.translation.web
Moderate
about 3 years ago
Liferay Portal and Liferay DXP Vulnerable to XSS in the Portal Search Module
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.portal.search.web
Moderate
about 3 years ago
Liferay Portal and Liferay DXP Vulnerable to XSS in the Site Module
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.site.memberships.web
Moderate
about 3 years ago
Liferay Portal and Liferay DXP HtmlUtil.escapeRedirect Can Be Circumvented
maven
com.liferay.portal:com.liferay.util.java, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
about 3 years ago
Liferay Portal and Liferay DXP Vulnerable to XSS via the filter_ Prefix
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.fragment.renderer.collection.filter.impl
High
over 3 years ago
Liferay Portal and Liferay DXP fails to invalidate password reset tokens after use
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:com.liferay.portal.impl
Moderate
over 3 years ago
Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via the currentURL Parameter
maven
com.liferay.portal:release.dxp.bom
High
over 3 years ago
Liferay Portal and Liferay DXP Has Company Administrator Accounts Vulnerable to Takeovers
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
over 3 years ago
Liferay Portal Layout Module and Liferay DXP Exposes the Cross-Site Request Forgery (CSRF) Token in URLs
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 3 years ago
Liferay Portal Fragment Module and Liferay DXP Vulnerable to Cross-Site Scripting
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 3 years ago
Liferay Portal Journal Module and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 3 years ago
Liferay Portal and Liferay DXP Cross-site scripting (XSS) vulnerability in the Document Library module
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.document.library.web
Moderate
over 3 years ago
Liferay Portal and Liferay DXP Don't Check Permissions of Pages
maven
com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom
Moderate
over 3 years ago
Liferay Portal and Liferay DXP vulnerable to email spam via lack of flagging rate
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.flags.taglib
Moderate
over 3 years ago
Liferay Portal and Liferay DXP Stores User Passwords in Cleartext
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 3 years ago
Liferay Portal and Liferay DXP Cross-site scripting (XSS) vulnerability in the Frontend JS module
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.frontend.js.aui.web
Moderate
over 3 years ago
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in Edit Vocabulary Page
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 3 years ago
Liferay Portal and Liferay DXP does not properly check user permission
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.portlet.configuration.web
High
over 3 years ago
Liferay Portal and Liferay DXP autosaves form data for other users to see
maven
com.liferay.portal:release.dxp.bom, com.liferay:com.liferay.dynamic.data.mapping.form.web
Moderate
over 3 years ago
Liferay Portal and Liferay DXP Fails to Properly Check User Permissions
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 3 years ago
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 3 years ago
Liferay Portal and Liferay DXP Fails to Check User Permissions for Workflow Submissions
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 3 years ago
Liferay Portal and Liferay DXP Allows Arbitrary Redirect of Users to External URLs
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 3 years ago
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via Membership Request Admin Page
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 3 years ago
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via the Redirect's Admin Page
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 3 years ago
Liferay Portal and Liferay DXP May Reveal S3 Store's Proxy Password
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 3 years ago
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via Asset Module Parameter
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
over 3 years ago
Liferay Portal and Liferay DXP Vulnerable to Multiple SQL Injections
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom