Security Advisories for com.liferay.portal:release.portal.bom in maven
Moderate
about 1 month ago
Liferay Portal Vulnerable to Reflected XSS via the selectedLanguageId Parameter
maven
com.liferay.portal:release.portal.bom
Moderate
about 1 month ago
Liferay Portal is vulnerable to XSS in the Blogs widget
maven
com.liferay.portal:release.portal.bom
Moderate
about 1 month ago
Liferay Portal is vulnerable to DNS rebinding attacks
maven
com.liferay.portal:release.portal.bom
Moderate
about 1 month ago
Liferay Portal vulnerable to password enumeration
maven
com.liferay.portal:release.portal.bom
High
about 1 month ago
Liferay Portal Vulnerable to DoS via Crafted Headless API Request
maven
com.liferay.portal:release.portal.bom
Moderate
about 1 month ago
Liferay Portal Does Not Limit Access to APIs Before Email Verification
maven
com.liferay.portal:release.portal.bom
High
about 1 month ago
Liferay Portal Vulnerable to CSRF in Headless APIs
maven
com.liferay.portal:release.portal.bom
Moderate
about 1 month ago
Liferay Portal Stores Password Reset Tokens in Plain Text
maven
com.liferay.portal:com.liferay.portal.impl, com.liferay.portal:release.portal.bom
Moderate
2 months ago
Liferay Portal is vulnerable to Stored XSS through Forms text type field
maven
com.liferay.portal:release.portal.bom
Moderate
2 months ago
Liferay Portal has multiple Stored XSS vulnerabilities on its View Order page
maven
com.liferay.portal:release.portal.bom
Moderate
2 months ago
Liferay Portal is vulnerable to XSS through its Commerce Search Result widget
maven
com.liferay.portal:release.portal.bom
Moderate
2 months ago
Liferay Profile Widget does not prevent vCard extension spoofing
maven
com.liferay.portal:release.portal.bom
Moderate
2 months ago
Liferay Portal Vulnerable to XSS in Web Content translation
maven
com.liferay.portal:release.portal.bom
Moderate
2 months ago
Liferay Portal vulnerable to reflected cross-site scripting via the `redirect` parameter
maven
com.liferay.portal:release.portal.bom
Moderate
2 months ago
Liferay Portal vulnerable to cross-site scripting in the web content template
maven
com.liferay:com.liferay.journal.web, com.liferay.portal:release.portal.bom
Moderate
2 months ago
Liferay Portal vulnerable to path traversal and denial-of-service in the ComboServlet
maven
com.liferay.portal:com.liferay.portal.impl, com.liferay.portal:release.portal.bom
Moderate
2 months ago
Liferay Portal vulnerable to cross-site scripting in the Calendar widget
maven
com.liferay:com.liferay.calendar.web, com.liferay.portal:release.portal.bom
Moderate
3 months ago
Liferay Portal Uses Default Password
maven
com.liferay.portal:release.portal.bom
Moderate
3 months ago
Liferay Portal and Liferay DXP vulnerable to Stored Cross-site Scripting
maven
com.liferay:com.liferay.portal.workflow.task.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
3 months ago
Liferay Portal and Liferay DXP vulnerable to store Cross-site Scripting
maven
com.liferay:com.liferay.portal.workflow.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal Reflected Cross-Site Scripting Vulnerability via PortalUtil.escapeRedirect
maven
com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal's Unlimited File Upload Could Result in DoS
maven
com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal Username Enumeration Vulnerability
maven
com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal Reflected Cross-Site Scripting Vulnerability via snippet Parameter
maven
com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal Vulnerable to Cross-Site Scripting via DDMPortlet_definition Parameter
maven
com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal Vulnerable to Cross-Site Scripting in Dynamic Data Mapping
maven
com.liferay.portal:release.portal.bom
High
4 months ago
Liferay Portal Vulnerable to Cross-Site Request Forgery
maven
com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal Unauthenticated File Access via URL
maven
com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal Vulnerable to Cross-Site Scripting via assetTagNames Parameter
maven
com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal Enumeration Discrepancy in Calendars
maven
com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal Vulnerable to Cross-Site Scripting via DDM Structure Field Labels
maven
com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal CSRF Vulnerability via Endpoint Parameter
maven
com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal has Stored Cross-Site Scripting Vulnerability via Message Boards Feature
maven
com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal Vulnerable to Cross-Site Scripting
maven
com.liferay.portal:release.portal.bom
Low
4 months ago
Liferay Portal Login Bypass Vulnerability
maven
com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal 7.4.0 and Liferay DXP have a reflected cross-site scripting (XSS) vulnerability
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal and Liferay DXP have a reflected cross-site scripting vulnerability
maven
com.liferay.portal:com.liferay.portal.impl, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal and Liferay DXP have a Denial Of Service via File Upload (DOS) vulnerability
maven
com.liferay:com.liferay.account.admin.web, com.liferay:com.liferay.users.admin.web, com.liferay:com.liferay.image.uploader.web, com.liferay:com.liferay.frontend.taglib, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal and Liferay DXP vulnerable to Server-Side Request Forgery
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
4 months ago
Liferay Portal and Liferay DXP vulnerable to Server-Side Request Forgery
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
8 months ago
Liferay Cross-site Scripting vulnerability
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
9 months ago
Liferay Portal and Liferay DXP Reveals Data via Forms
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
9 months ago
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
12 months ago
Liferay Portal and Liferay DXP have Cross-site Scripting vulnerability in edit Service Access Policy page
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
12 months ago
Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
about 1 year ago
Liferay Portal and Liferay DXP Vulnerable to CSRF in the Script Console
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
about 1 year ago
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the Content Page Editor
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
about 1 year ago
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the Content Page Editor
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
about 1 year ago
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the My Account Widget
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
about 1 year ago
Liferay Portal and Liferay DXP Workflow Component Does Not Check User Permissions
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
almost 2 years ago
Liferay Portal and Liferay DXP's Users Admin module vulnerable to stored Cross-site Scripting
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
almost 2 years ago
Liferay Portal Message Board widget and Liferay DXP vulnerable to stored Cross-site Scripting
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
almost 2 years ago
Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
almost 2 years ago
Liferay Portal Expando module and Liferay DXP vulnerable to stored Cross-site Scripting
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal and Liferay DXP User Enumeration Vulnerability
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal and Liferay DXP vulnerable to theft of hashed password
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal vulnerable to Denial of Service
maven
com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal and Liferay DXP HTTP Header Can Expose Versions
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
almost 2 years ago
Liferay Portal has a Stored XSS with Blog entries (Insecure defaults)
maven
com.liferay.portal:com.liferay.portal.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Replacement Character
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
almost 2 years ago
Liferay Portal defaults to a low work factor for the default password hashing algorithm
maven
com.liferay.portal:com.liferay.portal.kernel, com.liferay.portal:release.portal.bom, com.liferay.portal:release.dxp.bom
Moderate
almost 2 years ago
Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Two Forward Slashes
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal and Liferay DXP Allows Authenticated Users with View Permissions to Edit Permissions
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal and Liferay DXP Allows Templates to be Viewed via the UI or API
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
almost 2 years ago
Liferay Portal has an XXE vulnerability in Java2WsddTask._format
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom, com.liferay.portal:com.liferay.util.java
Moderate
almost 2 years ago
Liferay Portal and Liferay DXP Does Not Properly Restrict Membership to Child Site Based on Parent Site Options
maven
com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal and Liferay DXP Information Disclosure Vulnerability in the Control Panel
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Privilege escalation in Liferay Portal
maven
com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal and Liferay DXP Vulnerable to Open Redirect in Countries Management's Edit Region Page
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal denial-of-service vulnerability
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal allows attackers to discover the existence of sites
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
almost 2 years ago
Liferay Portal vulnerable to user impersonation
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
almost 2 years ago
Liferay Portal's account lockout does not invalidate existing user sessions
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Critical
almost 2 years ago
Liferay Portal stored cross-site scripting (XSS) vulnerability
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
almost 2 years ago
Liferay Portal denial of service (memory consumption)
maven
com.liferay.portal:release.portal.bom
Critical
about 2 years ago
Liferay Portal XSS with `p_l_back_url_title` on edit content page
maven
com.liferay.portal:release.portal.bom
Moderate
over 2 years ago
Liferay Portal and Liferay DXP Vulnerable to XSS via the Layout Module
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
High
over 2 years ago
Liferay Portal and Liferay DXP Vulnerable to CSRF via the Layout Module
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 2 years ago
Liferay Portal and Liferay DXP Vulnerable to Open Redirect via the Layout Module
maven
com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom
Moderate
over 2 years ago
Insecure Default Initialization In Liferay Portal
maven
com.liferay.portal:release.portal.bom
Moderate
over 2 years ago
Cross-site scripting in Liferay Portal
maven
com.liferay.portal:release.portal.bom
Moderate
over 2 years ago
Liferay portal has unauthorized access to object definition via search
maven
com.liferay.portal:release.portal.bom
High
over 2 years ago
Missing authorization in Liferay portal
maven
com.liferay.portal:release.portal.bom
Moderate
over 2 years ago
Liferay Portal has Inefficient Regular Expression
maven
com.liferay.portal:release.portal.bom
Moderate
over 2 years ago
Liferay portal unauthorized access to objects via OAuth 2 scope
maven
com.liferay.portal:release.portal.bom
Moderate
over 2 years ago
Cross-site scripting in Liferay Portal
maven
com.liferay.portal:release.portal.bom
Moderate
over 2 years ago
Cross-site scripting in Liferay Portal
maven
com.liferay.portal:release.portal.bom
Moderate
over 2 years ago
Cross-site scripting in Liferay Portal
maven
com.liferay.portal:release.portal.bom
Moderate
over 2 years ago
Cross-site scripting in Liferay Portal
maven
com.liferay.portal:release.portal.bom
Moderate
over 2 years ago
Cross-site scripting in Liferay Portal
maven
com.liferay.portal:release.portal.bom
Moderate
over 2 years ago
Cross-site scripting in Liferay Portal
maven
com.liferay.portal:release.portal.bom
Moderate
over 2 years ago
Cross-site scripting in Liferay Portal
maven
com.liferay.portal:release.portal.bom
Moderate
about 3 years ago
Improper Certificate Validation in Liferay Portal
maven
com.liferay.portal:release.portal.bom
Moderate
about 3 years ago
Incorrect Default Permissions in Liferay Portal
maven
com.liferay.portal:release.portal.bom
Moderate
about 3 years ago
Missing permissions check in Liferay Portal
maven
com.liferay.portal:release.portal.bom
Moderate
about 3 years ago
Incorrect Default Permissions in Liferay Portal
maven
com.liferay.portal:release.portal.bom
Moderate
about 3 years ago
Liferay Portal and Liferay DXP Includes LDAP Credentials in the Page URL
maven
com.liferay:com.liferay.portal.settings.authentication.ldap.web, com.liferay.portal:release.dxp.bom, com.liferay.portal:release.portal.bom