Vulnerabilities > Liferay > Liferay Portal > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-04-16 | CVE-2021-33990 | Improper Preservation of Permissions vulnerability in Liferay Portal 6.2.5 Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. | 9.8 |
2022-11-15 | CVE-2022-42122 | SQL Injection vulnerability in Liferay DXP and Liferay Portal A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL. | 9.8 |
2022-11-15 | CVE-2022-42120 | SQL Injection vulnerability in Liferay DXP and Liferay Portal A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute. | 9.8 |
2020-03-20 | CVE-2020-7961 | Deserialization of Untrusted Data vulnerability in Liferay Portal Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS). | 9.8 |
2019-10-04 | CVE-2019-16891 | Deserialization of Untrusted Data vulnerability in Liferay Portal Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload. | 9.8 |