Vulnerabilities > Liferay > Liferay Portal > 7.3.7

DATE CVE VULNERABILITY TITLE RISK
2022-10-07 CVE-2022-41414 Incorrect Default Permissions vulnerability in Liferay Portal
An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site names, and pages.
network
low complexity
liferay CWE-276
5.3
2022-09-22 CVE-2022-28980 Cross-site Scripting vulnerability in Liferay Portal
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal v7.4.3.4 and Liferay DXP v7.4 GA allows attackers to execute arbitrary web scripts or HTML via parameters with the filter_ prefix.
network
low complexity
liferay CWE-79
6.1
2022-04-19 CVE-2022-26595 Incorrect Default Permissions vulnerability in Liferay Digital Experience Platform and Liferay Portal
Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permission when accessing a list of sites/groups, which allows remote authenticated users to view sites/groups via the user's site membership assignment UI.
network
low complexity
liferay CWE-276
4.0