Vulnerability Name CVE Severity
Liferay DXP Excessive Iteration Vulnerability (CVE-2024-25144) CVE-2024-25144
Liferay DXP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2022-42132) CVE-2022-42132
Liferay DXP Improper Certificate Validation Vulnerability (CVE-2022-42131) CVE-2022-42131
Liferay DXP Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2022-42123) CVE-2022-42123
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-29049) CVE-2021-29049
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-38263) CVE-2021-38263
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-38265) CVE-2021-38265
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-38267) CVE-2021-38267
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-38269) CVE-2021-38269
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-26593) CVE-2022-26593
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-26596) CVE-2022-26596
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-26597) CVE-2022-26597
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-28978) CVE-2022-28978
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-28979) CVE-2022-28979
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-28982) CVE-2022-28982
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-38901) CVE-2022-38901
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-38902) CVE-2022-38902
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-42110) CVE-2022-42110
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-42111) CVE-2022-42111
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-42112) CVE-2022-42112
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-42114) CVE-2022-42114
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-42116) CVE-2022-42116
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-42117) CVE-2022-42117
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-42118) CVE-2022-42118
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-42119) CVE-2022-42119
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-33937) CVE-2023-33937
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-33938) CVE-2023-33938
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-33939) CVE-2023-33939
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-33940) CVE-2023-33940
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-33944) CVE-2023-33944
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-42497) CVE-2023-42497
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-42627) CVE-2023-42627
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-42628) CVE-2023-42628
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-42629) CVE-2023-42629
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-44309) CVE-2023-44309
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-44310) CVE-2023-44310
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-25145) CVE-2024-25145
Liferay DXP Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2022-42120) CVE-2022-42120
Liferay DXP Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2022-42121) CVE-2022-42121
Liferay DXP Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2023-33945) CVE-2023-33945
Liferay DXP Incorrect Default Permissions Vulnerability (CVE-2021-33334) CVE-2021-33334
Liferay DXP Incorrect Default Permissions Vulnerability (CVE-2021-38268) CVE-2021-38268
Liferay DXP Incorrect Default Permissions Vulnerability (CVE-2022-42128) CVE-2022-42128
Liferay DXP Incorrect Default Permissions Vulnerability (CVE-2022-42130) CVE-2022-42130
Liferay DXP Inefficient Regular Expression Complexity Vulnerability (CVE-2022-42124) CVE-2022-42124
Liferay DXP Insecure Default Initialization of Resource Vulnerability (CVE-2023-33949) CVE-2023-33949
Liferay DXP Missing Authorization Vulnerability (CVE-2022-39975) CVE-2022-39975
Liferay DXP Observable Discrepancy Vulnerability (CVE-2024-25146) CVE-2024-25146
Liferay DXP Origin Validation Error Vulnerability (CVE-2022-25146) CVE-2022-25146
Liferay DXP Other Vulnerability (CVE-2023-33946) CVE-2023-33946
Liferay DXP Other Vulnerability (CVE-2023-33947) CVE-2023-33947
Liferay DXP URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-28977) CVE-2022-28977
Liferay Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2020-13445) CVE-2020-13445
Liferay Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Vulnerability (CVE-2019-11444) CVE-2019-11444
Liferay Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Vulnerability (CVE-2020-28884) CVE-2020-28884
Liferay Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Vulnerability (CVE-2020-28885) CVE-2020-28885
Liferay JSON service API authentication vulnerability
Liferay Portal Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2021-33320) CVE-2021-33320
Liferay Portal Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2022-42129) CVE-2022-42129
Liferay Portal Cleartext Storage of Sensitive Information Vulnerability (CVE-2021-33323) CVE-2021-33323
Liferay Portal Cleartext Storage of Sensitive Information Vulnerability (CVE-2021-33325) CVE-2021-33325
Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-33338) CVE-2021-33338
Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-35030) CVE-2023-35030
Liferay Portal CVE-2011-1571 Vulnerability (CVE-2011-1571) CVE-2011-1571
Liferay Portal CVE-2020-13444 Vulnerability (CVE-2020-13444) CVE-2020-13444
Liferay Portal CVE-2020-15840 Vulnerability (CVE-2020-15840) CVE-2020-15840
Liferay Portal CVE-2020-15841 Vulnerability (CVE-2020-15841) CVE-2020-15841
Liferay Portal CVE-2021-33330 Vulnerability (CVE-2021-33330) CVE-2021-33330
Liferay Portal CVE-2021-38266 Vulnerability (CVE-2021-38266) CVE-2021-38266
Liferay Portal CVE-2022-42126 Vulnerability (CVE-2022-42126) CVE-2022-42126
Liferay Portal CVE-2024-25148 Vulnerability (CVE-2024-25148) CVE-2024-25148
Liferay Portal Deserialization of Untrusted Data Vulnerability (CVE-2019-16891) CVE-2019-16891
Liferay Portal Deserialization of Untrusted Data Vulnerability (CVE-2020-7961) CVE-2020-7961
Liferay Portal Deserialization of Untrusted Data Vulnerability (CVE-2020-15842) CVE-2020-15842
Liferay Portal Excessive Iteration Vulnerability (CVE-2024-25144) CVE-2024-25144