cbcvebase.

Liferay Portal vulnerabilities

319 known vulnerabilities affecting liferay/liferay_portal.

Total CVEs
319
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH47MEDIUM259LOW5

Vulnerabilities

Page 13 of 16
CVE-2021-33337P4MEDIUMCVSS 6.1≥ 7.3.0, ≤ 7.3.42021-08-04
CVE-2021-33337 [MEDIUM] CWE-79 CVE-2021-33337: Cross-site scripting (XSS) vulnerability in the Document Library module's add document menu in Lifer Cross-site scripting (XSS) vulnerability in the Document Library module's add document menu in Liferay Portal 7.3.0 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_document_library_web_portlet_DLAdminPortlet_name parameter.
nvd
CVE-2021-29045P4MEDIUMCVSS 6.1≥ 7.3.2, ≤ 7.3.52021-05-17
CVE-2021-29045 [MEDIUM] CWE-79 CVE-2021-29045: Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Liferay Portal 7.3.2 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_redirect_web_internal_portlet_RedirectPortlet_destinationURL parameter.
nvd
CVE-2021-29039P4MEDIUMCVSS 6.1v7.3.42021-05-16
CVE-2021-29039 [MEDIUM] CWE-79 CVE-2021-29039: Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Lif Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 7.3.4 allows remote attackers to inject arbitrary web script or HTML via the site name.
nvd
CVE-2017-12649P4MEDIUMCVSS 6.1≤ 7.02017-08-07
CVE-2017-12649 [MEDIUM] CWE-79 CVE-2017-12649: XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted title or summary that is mishandled in XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted title or summary that is mishandled in the Web Content Display.
nvd
CVE-2017-12648P4MEDIUMCVSS 6.1≤ 7.02017-08-07
CVE-2017-12648 [MEDIUM] CWE-79 CVE-2017-12648: XSS exists in Liferay Portal before 7.0 CE GA4 via a bookmark URL. XSS exists in Liferay Portal before 7.0 CE GA4 via a bookmark URL.
nvd
CVE-2017-12646P4MEDIUMCVSS 6.1≤ 7.02017-08-07
CVE-2017-12646 [MEDIUM] CWE-79 CVE-2017-12646: XSS exists in Liferay Portal before 7.0 CE GA4 via a login name, password, or e-mail address. XSS exists in Liferay Portal before 7.0 CE GA4 via a login name, password, or e-mail address.
nvd
CVE-2022-26597P4MEDIUMCVSS 6.1≥ 7.3.0, ≤ 7.4.02022-04-25
CVE-2022-26597 [MEDIUM] CWE-79 CVE-2022-26597: Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Po Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the site name.
nvd
CVE-2023-47797P4MEDIUMCVSS 6.1≥ 7.4.3.94, ≤ 7.4.3.952023-11-17
CVE-2023-47797 [MEDIUM] CWE-79 CVE-2023-47797: Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7 Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95 allows remote attackers to inject arbitrary web script or HTML via the `p_l_back_url_title` parameter.
nvd
CVE-2022-42113P4MEDIUMCVSS 6.1≥ 7.4.3.30, < 7.4.3.372022-10-18
CVE-2022-42113 [MEDIUM] CWE-79 CVE-2022-42113: A Cross-site scripting (XSS) vulnerability in Document Library module in Liferay Portal 7.4.3.30 thr A Cross-site scripting (XSS) vulnerability in Document Library module in Liferay Portal 7.4.3.30 through 7.4.3.36, and Liferay DXP 7.4 update 30 through update 36 allows remote attackers to inject arbitrary web script or HTML via the `redirect` parameter.
nvd
CVE-2023-42497P4MEDIUMCVSS 6.1≥ 7.4.3.4, < 7.4.3.862023-10-17
CVE-2023-42497 [MEDIUM] CWE-79 CVE-2023-42497: Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Por Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through 7.4.3.85, and Liferay DXP 7.4 before update 86 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_translation_web_internal_portlet_TranslationPortlet_redirect` parameter.
nvd
CVE-2022-28979P4MEDIUMCVSS 6.1≥ 7.1.0, < 7.4.3.42022-09-22
CVE-2022-28979 [MEDIUM] CWE-79 CVE-2022-28979: Liferay Portal v7.1.0 through v7.4.2 and Liferay DXP 7.1 before fix pack 26, 7.2 before fix pack 15, Liferay Portal v7.1.0 through v7.4.2 and Liferay DXP 7.1 before fix pack 26, 7.2 before fix pack 15, and 7.3 before service pack 3 was discovered to contain a cross-site scripting (XSS) vulnerability in the Portal Search module's Custom Facet widget. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in
nvd
CVE-2020-15840P4MEDIUMCVSS 5.3fixed in 7.3.1v6.22020-09-24
CVE-2020-15840 [MEDIUM] CVE-2020-15840: In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id.banned.paths.regexp' can be bypassed with doubled encoded URLs.
nvd
CVE-2021-33336P4MEDIUMCVSS 5.4≥ 7.3.0, < 7.3.42021-08-04
CVE-2021-33336 [MEDIUM] CWE-79 CVE-2021-33336: Cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal Cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal 7.3.0 through 7.3.3, and Liferay DXP 7.1 fix pack 18, and 7.2 fix pack 5 through 7, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_journal_web_portlet_JournalPortlet_name parameter.
nvd
CVE-2021-33328P4MEDIUMCVSS 5.4≥ 7.0.0, < 7.3.52021-08-03
CVE-2021-33328 [MEDIUM] CWE-79 CVE-2021-33328: Cross-site scripting (XSS) vulnerability in the Asset module's edit vocabulary page in Liferay Porta Cross-site scripting (XSS) vulnerability in the Asset module's edit vocabulary page in Liferay Portal 7.0.0 through 7.3.4, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20, and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the (1) _com_liferay_journal_web_portlet_JournalPortlet_name or (2) _co
nvd
CVE-2022-26593P4MEDIUMCVSS 5.4≥ 7.3.3, < 7.3.7v7.4.02022-04-19
CVE-2022-26593 [MEDIUM] CWE-79 CVE-2022-26593: Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the name of a asset category.
nvd
CVE-2021-38267P4MEDIUMCVSS 5.4≥ 7.3.2, ≤ 7.3.62022-03-03
CVE-2021-38267 [MEDIUM] CWE-79 CVE-2021-38267: Cross-site scripting (XSS) vulnerability in the Blogs module's edit blog entry page in Liferay Porta Cross-site scripting (XSS) vulnerability in the Blogs module's edit blog entry page in Liferay Portal 7.3.2 through 7.3.6, and Liferay DXP 7.3 before fix pack 2 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_blogs_web_portlet_BlogsAdminPortlet_title and _com_liferay_blogs_web_portlet_BlogsAdminPortlet_subtitle par
nvd
CVE-2021-38265P4MEDIUMCVSS 5.4≥ 7.3.4, ≤ 7.3.62022-03-03
CVE-2021-38265 [MEDIUM] CWE-79 CVE-2021-38265: Cross-site scripting (XSS) vulnerability in the Asset module in Liferay Portal 7.3.4 through 7.3.6 a Cross-site scripting (XSS) vulnerability in the Asset module in Liferay Portal 7.3.4 through 7.3.6 allow remote attackers to inject arbitrary web script or HTML when creating a collection page via the _com_liferay_asset_list_web_portlet_AssetListPortlet_title parameter.
nvd
CVE-2021-38269P4MEDIUMCVSS 5.4≥ 7.1.0, ≤ 7.3.6v7.4.02022-03-03
CVE-2021-38269 [MEDIUM] CWE-79 CVE-2021-38269: Cross-site scripting (XSS) vulnerability in the Gogo Shell module in Liferay Portal 7.1.0 through 7. Cross-site scripting (XSS) vulnerability in the Gogo Shell module in Liferay Portal 7.1.0 through 7.3.6 and 7.4.0, and Liferay DXP 7.1 before fix pack 23, 7.2 before fix pack 13, and 7.3 before fix pack 2 allows remote attackers to inject arbitrary web script or HTML via the output of a Gogo Shell command.
nvd
CVE-2022-38902P4MEDIUMCVSS 5.4≥ 7.3.0, ≤ 7.4.02022-10-13
CVE-2022-38902 [MEDIUM] CWE-79 CVE-2022-38902: A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Lifer A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic.
nvd
CVE-2023-33942P4MEDIUMCVSS 5.4v7.4.3.502023-05-24
CVE-2023-33942 [MEDIUM] CWE-79 CVE-2023-33942: Cross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Lif Cross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Liferay Liferay Portal 7.4.3.50, and Liferay DXP 7.4 update 50 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a web content article's `Title` field.
nvd
Liferay Portal vulnerabilities | cvebase