Vulnerabilities > Liferay > Liferay Portal > 7.4.3.9

DATE CVE VULNERABILITY TITLE RISK
2022-10-18 CVE-2022-42112 Cross-site Scripting vulnerability in Liferay DXP
A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Portal 7.2.0 through 7.4.3.24, and Liferay DXP 7.2 before fix pack 19, 7.3 before update 5, and DXP 7.4 before update 25 allows remote attackers to inject arbitrary web script or HTML via a crafted payload.
network
low complexity
liferay CWE-79
5.4
2022-10-18 CVE-2022-42114 Cross-site Scripting vulnerability in Liferay DXP 7.0/7.4
A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.4 before update 37 allows remote attackers to inject arbitrary web script or HTML.
network
low complexity
liferay CWE-79
5.4
2022-10-18 CVE-2022-42115 Cross-site Scripting vulnerability in Liferay Portal
Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Portal 7.4.3.4 through 7.4.3.36 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the object field's `Label` text field.
network
low complexity
liferay CWE-79
5.4
2022-10-18 CVE-2022-42116 Cross-site Scripting vulnerability in Liferay DXP 7.0
A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14, and Liferay DXP 7.3 before update 6, and 7.4 before update 15 allows remote attackers to inject arbitrary web script or HTML via the (1) name, or (2) namespace parameter.
network
low complexity
liferay CWE-79
6.1
2022-10-18 CVE-2022-42117 Cross-site Scripting vulnerability in Liferay DXP 7.0
A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 through 7.4.3.16, and Liferay DXP 7.3 before update 6, and 7.4 before update 17 allows remote attackers to inject arbitrary web script or HTML.
network
low complexity
liferay CWE-79
6.1