Vulnerabilities > Liferay > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-04-16 | CVE-2021-33990 | Improper Preservation of Permissions vulnerability in Liferay Portal 6.2.5 Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. | 9.8 |
2022-11-15 | CVE-2022-42120 | SQL Injection vulnerability in Liferay DXP and Liferay Portal A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute. | 9.8 |
2022-11-15 | CVE-2022-42122 | SQL Injection vulnerability in Liferay DXP and Liferay Portal A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL. | 9.8 |
2020-03-20 | CVE-2020-7961 | Deserialization of Untrusted Data vulnerability in Liferay Portal Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS). | 9.8 |
2019-10-04 | CVE-2019-16891 | Deserialization of Untrusted Data vulnerability in Liferay Portal Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload. | 9.8 |
2017-01-23 | CVE-2016-6517 | Path Traversal vulnerability in Liferay 5.1.0 Directory traversal vulnerability in Liferay 5.1.0 allows remote attackers to have unspecified impact via a %2E%2E (encoded dot dot) in the minifierBundleDir parameter to barebone.jsp. | 9.8 |