Vulnerabilities > Liferay > DXP > 7.0

DATE CVE VULNERABILITY TITLE RISK
2024-02-07 CVE-2024-25145 Cross-site Scripting vulnerability in Liferay DXP
Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 through 7.4.3.11, and older unsupported versions, and Liferay DXP 7.4 before update 8, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML into the Search Result app's search result if highlighting is disabled by adding any searchable content (e.g., blog, message board message, web content article) to the application.
network
low complexity
liferay CWE-79
5.4
2022-10-19 CVE-2022-38901 Cross-site Scripting vulnerability in Liferay DXP and Liferay Portal
A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the description field of uploaded svg file.
network
low complexity
liferay CWE-79
5.4
2022-10-18 CVE-2022-42112 Cross-site Scripting vulnerability in Liferay DXP
A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Portal 7.2.0 through 7.4.3.24, and Liferay DXP 7.2 before fix pack 19, 7.3 before update 5, and DXP 7.4 before update 25 allows remote attackers to inject arbitrary web script or HTML via a crafted payload.
network
low complexity
liferay CWE-79
5.4
2022-10-18 CVE-2022-42114 Cross-site Scripting vulnerability in Liferay DXP 7.0/7.4
A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.4 before update 37 allows remote attackers to inject arbitrary web script or HTML.
network
low complexity
liferay CWE-79
5.4
2022-10-18 CVE-2022-42116 Cross-site Scripting vulnerability in Liferay DXP 7.0
A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14, and Liferay DXP 7.3 before update 6, and 7.4 before update 15 allows remote attackers to inject arbitrary web script or HTML via the (1) name, or (2) namespace parameter.
network
low complexity
liferay CWE-79
6.1
2022-10-18 CVE-2022-42117 Cross-site Scripting vulnerability in Liferay DXP 7.0
A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 through 7.4.3.16, and Liferay DXP 7.3 before update 6, and 7.4 before update 17 allows remote attackers to inject arbitrary web script or HTML.
network
low complexity
liferay CWE-79
6.1
2021-08-03 CVE-2021-33331 Open Redirect vulnerability in Liferay DXP 7.0
Open redirect vulnerability in the Notifications module in Liferay Portal 7.0.0 through 7.3.1, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19 and 7.2 before fix pack 8, allows remote attackers to redirect users to arbitrary external URLs via the 'redirect' parameter.
network
liferay CWE-601
5.8
2021-08-03 CVE-2021-33333 Incorrect Default Permissions vulnerability in Liferay DXP 7.0
The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19 and 7.2 before fix pack 6, does not properly check user permission, which allows remote authenticated users to view and delete workflow submissions via crafted URLs.
network
low complexity
liferay CWE-276
6.5
2021-08-03 CVE-2021-33334 Incorrect Default Permissions vulnerability in Liferay DXP 7.0
The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.2, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 6, does not properly check user permissions, which allows remote attackers with the forms "Access in Site Administration" permission to view all forms and form entries in a site via the forms section in site administration.
network
low complexity
liferay CWE-276
4.0
2021-08-03 CVE-2021-33320 Allocation of Resources Without Limits or Throttling vulnerability in Liferay DXP 7.0
The Flags module in Liferay Portal 7.3.1 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20, and 7.2 before fix pack 5, does not limit the rate at which content can be flagged as inappropriate, which allows remote authenticated users to spam the site administrator with emails
network
low complexity
liferay CWE-770
4.0