Vulnerabilities > Liferay > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-04-16 CVE-2021-33990 Improper Preservation of Permissions vulnerability in Liferay Portal 6.2.5
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists.
network
low complexity
liferay CWE-281
critical
9.8
2022-11-15 CVE-2022-42120 SQL Injection vulnerability in Liferay DXP and Liferay Portal
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.
network
low complexity
liferay CWE-89
critical
9.8
2022-11-15 CVE-2022-42122 SQL Injection vulnerability in Liferay DXP and Liferay Portal
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.
network
low complexity
liferay CWE-89
critical
9.8
2020-03-20 CVE-2020-7961 Deserialization of Untrusted Data vulnerability in Liferay Portal
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
network
low complexity
liferay CWE-502
critical
9.8
2019-10-04 CVE-2019-16891 Deserialization of Untrusted Data vulnerability in Liferay Portal
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
network
low complexity
liferay CWE-502
critical
9.8
2017-01-23 CVE-2016-6517 Path Traversal vulnerability in Liferay 5.1.0
Directory traversal vulnerability in Liferay 5.1.0 allows remote attackers to have unspecified impact via a %2E%2E (encoded dot dot) in the minifierBundleDir parameter to barebone.jsp.
network
low complexity
liferay CWE-22
critical
9.8