pkg:Maven/com.liferay.portal:release.dxp.bom
共 125 筆 CVECRITICAL24HIGH19MEDIUM72
✅ 檢查你的版本
所有已知漏洞
- CRITICAL9.8CVE-2022-42120Liferay Portal and Liferay DXP Vulnerable to SQL Injection via the Fragment Module>= 7.3.0, < 7.3.10.u4
- CRITICAL9.8CVE-2022-42122Liferay Portal and Liferay DXP Vulnerable to SQL Injection via Friendly URL Module>= 7.3.10.fp2, < 7.3.10.u4
- >= 2023.Q3.1, < 2023.Q3.5
- CRITICAL9.6CVE-2024-26269Liferay Portal Frontend JS module's portlet.js and Liferay DXP vulnerable to Cross-site Scripting>= 7.4.13.u1, < 7.4.13.u38
- CRITICAL9.6CVE-2023-42496Liferay Portal and Liferay DXP vulnerable to reflected Cross-site Scripting>= 7.4.10.ep1, <= 7.4.13.u92
- >= 7.3.0, < 7.3.10.u4
- CRITICAL9.6CVE-2023-42498Liferay Portal Language Override edit screen and Liferay DXP vulnerable to reflected Cross-site Scripting>= 2023.Q3, < 2023.Q3.5
- >= 7.4.0, < 7.4.3.13u8
- >= 7.3.0, <= 7.3.10.u33
- CRITICAL9.6CVE-2023-44311Liferay Portal and Liferay DXP Vulnerable to XSS via the OAuth2ProviderApplicationRedirect Class>= 7.4.13.u41, < 7.4.13.u90
- CRITICAL9.6CVE-2023-42497Liferay Portal and Liferay DXP Vulnerable to Reflected XSS via the Export for Translation Page>= 7.4.0, < 7.4.13.u86
- CRITICAL9.0CVE-2024-38002Liferay Portal and Liferay DXP Workflow Component Does Not Check User Permissions>= 2023.Q4.0, < 2023.Q4.6
- CRITICAL9.0CVE-2023-47795Liferay Portal Document and Media widget and Liferay DXP vulnerable to stored Cross-site Scripting>= 2023.Q3, < 2023.Q3.6
- CRITICAL9.0CVE-2024-25603Liferay Portal's Dynamic Data Mapping module's DDMForm and Liferay DXP vulnerable to stored Cross-site Scripting>= 7.4.13.u1, <= 7.4.13.u102
- >= 7.4.13.u1, < 7.4.13.u10
- CRITICAL9.0CVE-2024-25152Liferay Portal Message Board widget and Liferay DXP vulnerable to stored Cross-site Scripting>= 7.3.0, < 7.3.10.u4
- CRITICAL9.0CVE-2024-25601Liferay Portal Expando module and Liferay DXP vulnerable to stored Cross-site Scripting>= 7.3.0, < 7.3.10.u4
- CRITICAL9.0CVE-2024-25602Liferay Portal and Liferay DXP's Users Admin module vulnerable to stored Cross-site Scripting>= 7.3.0, < 7.3.10.u4
- CRITICAL9.0CVE-2023-40191Liferay Portal and Liferay DXP vulnerable to reflected Cross-site Scripting>= 2023.Q3, < 2023.Q3.6
- >= 7.4.0, < 7.4.13.u9
- >= 7.3.10.fp1, <= 7.3.10.fp23
- >= 7.0.10.fp83, <= 7.0.10.fp102
- CRITICAL9.0CVE-2023-42629Liferay Portal and Liferay DXP Vulnerable to Stored XSS in the Manage Vocabulary Page>= 7.4.0, < 7.4.13.u88
- CRITICAL9.0CVE-2023-44309Liferay Portal and Liferay DXP Vulnerable to XSS in the Fragment Components>= 7.4.0, < 7.4.13.u54
- HIGH8.8CVE-2024-26273Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the Content Page Editor>= 2023.Q4.0, < 2023.Q4.3
- HIGH8.8CVE-2024-26271Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the My Account Widget>= 2023.Q4.0, < 2023.Q4.3
- HIGH8.8CVE-2024-26272Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the Content Page Editor>= 2023.Q4.0, < 2023.Q4.3
- HIGH8.8CVE-2021-29050Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery in Terms of Use Page>= 7.2.0, < 7.2.10.fp11
- >= 7.4.13.u70, <= 7.4.13.u76
- HIGH8.8CVE-2022-42121Liferay Portal and Liferay DXP Vulnerable to SQL Injection via the Layout Module>= 7.1.0, < 7.1.10.fp27
- from 0, < 7.3.10.fp1
- >= 7.0.0, < 7.0.10.fp92
- HIGH8.3CVE-2020-15841Liferay Portal and Liferay DXP Potentially Reveal LDAP Server Password via Unsafe Connection>= 7.0.0, < 7.0.10.fp89
- HIGH8.1CVE-2024-25607Liferay Portal defaults to a low work factor for the default password hashing algorithm>= 7.3.0, < 7.3.10.u4
- >= 7.2.0, < 7.2.10.fp15
- >= 7.0.0, < 7.0.10.fp90
- >= 7.3.0, < 7.3.10.u12
- HIGH7.5CVE-2021-33322Liferay Portal and Liferay DXP fails to invalidate password reset tokens after use>= 7.0.0, < 7.0.10.fp96
- HIGH7.5CVE-2021-33338Liferay Portal Layout Module and Liferay DXP Exposes the Cross-Site Request Forgery (CSRF) Token in URLs>= 7.1.0, < 7.1.10.fp19
- >= 7.1.0, < 7.1.10.fp19
- from 0, < 7.3.10.fp1
- from 0, < 7.3.0-ga1
- HIGH7.2CVE-2021-33335Liferay Portal and Liferay DXP Has Company Administrator Accounts Vulnerable to Takeovers>= 7.1.0, < 7.1.10.fp20
- >= 2023.Q3, < 2023.Q3.5
- MEDIUM6.5CVE-2024-25604Liferay Portal and Liferay DXP Allows Authenticated Users with View Permissions to Edit Permissions
- MEDIUM6.5CVE-2022-38512Liferay Portal and Liferay DXP Fails to Check Permissions in Translation Module>= 7.4.13.u8, < 7.4.13.u37
- MEDIUM6.5CVE-2021-29041Liferay DXP Vulnerable to Denial-of-service (DoS) in the Multi-Factor Authentication Modulefrom 0, < 7.3.10.fp1
- >= 7.0.0, < 7.0.10.fp92
- MEDIUM6.5CVE-2021-38268Liferay Portal and Liferay DXP has incorrect default permissions for site members>= 7.0.0, < 7.0.10.fp101
- MEDIUM6.5CVE-2020-15839Unrestricted Upload of File with Dangerous Type in Liferay Portal and Liferay DXPfrom 0, < 7.1.10.fp18
- from 0, < 7.2.10.fp17
- MEDIUM6.3CVE-2021-33333Liferay Portal and Liferay DXP Fails to Check User Permissions for Workflow Submissionsfrom 0, < 7.0.10.fp93
- >= 7.1, < 7.4.13.u39
- MEDIUM6.1CVE-2024-25609Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Two Forward Slashes>= 7.2.10.fp15, <= 7.2.10.fp18
- MEDIUM6.1CVE-2024-25608Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Replacement Characterfrom 0, < 7.2.10.fp19
- MEDIUM6.1CVE-2023-5190Liferay Portal and Liferay DXP Vulnerable to Open Redirect in Countries Management's Edit Region Page>= 2023.Q3, < 2023.Q3.6
- MEDIUM6.1CVE-2023-35029Liferay Portal and Liferay DXP Vulnerable to Open Redirect via the Layout Module>= 7.4.13.u70, <= 7.4.13.u76
- >= 7.4.13.u70, <= 7.4.13.u73
- MEDIUM6.1CVE-2022-42118Liferay Portal and Liferay DXP Vulnerable to XSS via the Portal Search Module>= 7.1.0, < 7.1.10.fp27
- MEDIUM6.1CVE-2022-42110Liferay Portal and Liferay DXP Vulnerable to XSS via the Announcements Module>= 7.1.0, < 7.1.10.fp27
- MEDIUM6.1CVE-2022-42116Liferay Portal and Liferay DXP Vulnerable to XSS in the CKEditor Integration with the Frontend Editor Module>= 7.3.0, < 7.3.10.u6
- MEDIUM6.1CVE-2022-42117Liferay Portal and Liferay DXP Vulnerable to XSS in the Frontend Taglib Module>= 7.3.0, < 7.3.10.u6
- MEDIUM6.1CVE-2022-42113Liferay Portal and Liferay DXP Vulnerable to XSS via the Document Library Module>= 7.4.13.u30, < 7.4.13.u37
- from 0, < 7.4.3.5-ga5
- >= 7.0.10.fp91, < 7.0.10.fp101
- >= 7.1.0
- MEDIUM6.1CVE-2021-29049Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via the currentURL Parameter>= 7.0, < 7.0.10.fp99
- MEDIUM6.1CVE-2021-33337Liferay Portal and Liferay DXP Cross-site scripting (XSS) vulnerability in the Document Library module>= 7.1.0, < 7.1.10.fp20
- MEDIUM6.1CVE-2021-33326Liferay Portal and Liferay DXP Cross-site scripting (XSS) vulnerability in the Frontend JS module>= 7.0.0, < 7.0.10.fp96
- MEDIUM6.1CVE-2021-33331Liferay Portal and Liferay DXP Allows Arbitrary Redirect of Users to External URLs>= 7.0.10.fp0, < 7.0.10.fp94
- >= 7.1.0, < 7.1.10.fp19
- MEDIUM6.1CVE-2021-29046Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via Asset Module Parameter>= 7.3.10.fp0, < 7.3.10.fp1
- MEDIUM6.1CVE-2021-29048Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in the Layout Admin Pagefrom 0, < 7.2.10.fp11
- MEDIUM6.1CVE-2021-29044Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via Membership Request Admin Page>= 7.0.10.fp0, < 7.0.10.fp97
- MEDIUM6.1CVE-2021-29045Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) via the Redirect's Admin Page>= 7.3.10.fp0, < 7.3.10.fp1
- MEDIUM6.1CVE-2021-29051Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in Asset Publisher Appfrom 0, < 7.1.10.fp21
- MEDIUM6.1CVE-2022-26596Liferay Portal and Liferay DXP allows arbitrary injection via web content template names>= 7.0.0, < 7.0.10.fp94
- >= 7.3.0, < 7.3.10.fp3
- >= 7.3.0, < 7.3.10.fp3
- MEDIUM6.1CVE-2021-38263Liferay Portal and Liferay DXP cross-site scripting (XSS) vulnerability via the script consolefrom 0, <= 7.0
- >= 7.0.0, <= 7.0.10.fp102
- from 0, < 7.0.10.fp97
- MEDIUM5.4CVE-2024-25151Liferay Portal Calendar module and Liferay DXP vulnerable to Cross-site Scripting, content spoofing>= 7.3.0, < 7.3.10.u4
- MEDIUM5.4CVE-2024-25149Liferay Portal and Liferay DXP Does Not Properly Restrict Membership to Child Site Based on Parent Site Optionsfrom 0, < 7.2.10.fp15
- >= 7.2.0, < 7.2.10.fp5
- >= 7.2.0, < 7.2.10.fp19
- >= 7.3.0, < 7.3.10.u8
- >= 7.4.0, < 7.4.13.u37
- MEDIUM5.4CVE-2022-42112Liferay Portal and Liferay DXP Vulnerable to XSS via the Portal Search Module>= 7.2.0, < 7.2.10.fp19
- >= 7.0.0, < 7.0.10.fp102
- MEDIUM5.4CVE-2021-33336Liferay Portal Journal Module and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)>= 7.1.0, < 7.1.10.fp18
- MEDIUM5.4CVE-2021-33328Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS) in Edit Vocabulary Page>= 7.0.10.fp0, < 7.0.10.fp96
- MEDIUM5.4CVE-2022-26593Liferay Portal and Liferay DXP allows arbitrary injection via the name of an asset category>= 7.3.0, < 7.3.10.fp3
- MEDIUM5.4CVE-2021-38269Liferay Portal and Liferay DXP vulnerable to cross-site scripting (XSS) in the Gogo Shell module>= 7.1.0, < 7.1.10.fp23
- MEDIUM5.4CVE-2021-38267Liferay Portal and Liferay DXP vulnerable to cross-site scripting (XSS) in edit blog entry page>= 7.3.0, < 7.3.10.fp2
- from 0, <= 7.3
- from 0, < 7.2.10.fp20
- from 0, < 7.2.10.fp19
- MEDIUM5.3CVE-2024-25605Liferay Portal and Liferay DXP Allows Templates to be Viewed via the UI or APIfrom 0, < 7.2.10.fp17
- >= 7.3.0, < 7.3.10.u4
- MEDIUM5.3CVE-2021-29040Liferay Portal and Liferay DXP Reveals Data via Overly Verbose Error Messagesfrom 0, < 7.0.10.fp97
- from 0, < 7.0.10.fp93
- from 0, < 7.4.13.u5
- from 0, < 7.0.10.fp93
- MEDIUM4.8CVE-2023-37940Liferay Portal and Liferay DXP have Cross-site Scripting vulnerability in edit Service Access Policy page>= 7.0, < 7.3.10.u30
- MEDIUM4.8CVE-2021-33339Liferay Portal Fragment Module and Liferay DXP Vulnerable to Cross-Site Scripting>= 7.2.0, < 7.2.10.fp9
- MEDIUM4.3CVE-2024-25150Liferay Portal and Liferay DXP Information Disclosure Vulnerability in the Control Panelfrom 0, < 7.2.10.fp19
- MEDIUM4.3CVE-2023-3426Liferay Portal and Liferay DXP Organization Selector Does Not Check User Permissions>= 7.4.143.u81, <= 7.4.143.u85
- >= 7.0.10.fp93, < 7.0.10.fp95
- MEDIUM4.3CVE-2021-33320Liferay Portal and Liferay DXP vulnerable to email spam via lack of flagging rate>= 7.0.0, < 7.0.10.fp96
- from 0, < 7.1.10.fp20
- >= 7.0.10.fp0, < 7.0.10.fp94
- from 0, < 7.3.10.fp1
- MEDIUM4.3CVE-2022-26595Liferay Portal and Liferay DXP fails to check permissions to view sites/groups>= 7.2.0, < 7.2.10.fp13
- >= 7.2.0, < 7.2.10.fp19
- >= 2024.Q2.0, < 2024.Q3.0
- >= 7.4, <= 7.4.13.u92
- —CVE-2025-43734Liferay Portal 7.4.0 and Liferay DXP have a reflected cross-site scripting (XSS) vulnerability>= 2024.q4.0, <= 2024.q4.7
- >= 2024.q4.0, <= 2024.q4.7
- —CVE-2025-43736Liferay Portal and Liferay DXP have a Denial Of Service via File Upload (DOS) vulnerability>= 2025.Q1.0, < 2025.Q1.9
- >= 2025.Q1.0, < 2025.Q1.6
- >= 2025.Q1.0, < 2025.Q1.5
- >= 7.2.10.fp1, <= 7.2.10.fp20
- >= 2024.Q3.0, < 2024.Q3.1
- >= 2024.Q2.0, <= 2024.Q2.11