Vulnerability Name CVE Severity
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-37940) CVE-2023-37940
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-40191) CVE-2023-40191
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-42496) CVE-2023-42496
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-42497) CVE-2023-42497
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-42498) CVE-2023-42498
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-42627) CVE-2023-42627
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-42628) CVE-2023-42628
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-42629) CVE-2023-42629
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-44309) CVE-2023-44309
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-44310) CVE-2023-44310
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-47795) CVE-2023-47795
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-25145) CVE-2024-25145
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-25147) CVE-2024-25147
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-25151) CVE-2024-25151
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-25152) CVE-2024-25152
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-25601) CVE-2024-25601
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-25602) CVE-2024-25602
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-25603) CVE-2024-25603
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-26266) CVE-2024-26266
Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-26269) CVE-2024-26269
Liferay DXP Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2022-42120) CVE-2022-42120
Liferay DXP Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2022-42121) CVE-2022-42121
Liferay DXP Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2023-33945) CVE-2023-33945
Liferay DXP Improper Restriction of XML External Entity Reference Vulnerability (CVE-2024-25606) CVE-2024-25606
Liferay DXP Incorrect Authorization Vulnerability (CVE-2024-25149) CVE-2024-25149
Liferay DXP Incorrect Authorization Vulnerability (CVE-2024-25604) CVE-2024-25604
Liferay DXP Incorrect Authorization Vulnerability (CVE-2024-38002) CVE-2024-38002
Liferay DXP Incorrect Default Permissions Vulnerability (CVE-2021-33334) CVE-2021-33334
Liferay DXP Incorrect Default Permissions Vulnerability (CVE-2021-38268) CVE-2021-38268
Liferay DXP Incorrect Default Permissions Vulnerability (CVE-2022-42128) CVE-2022-42128
Liferay DXP Incorrect Default Permissions Vulnerability (CVE-2022-42130) CVE-2022-42130
Liferay DXP Incorrect Default Permissions Vulnerability (CVE-2024-25605) CVE-2024-25605
Liferay DXP Inefficient Regular Expression Complexity Vulnerability (CVE-2022-42124) CVE-2022-42124
Liferay DXP Insecure Default Initialization of Resource Vulnerability (CVE-2023-33949) CVE-2023-33949
Liferay DXP Insecure Default Initialization of Resource Vulnerability (CVE-2024-25610) CVE-2024-25610
Liferay DXP Insecure Default Initialization of Resource Vulnerability (CVE-2024-26267) CVE-2024-26267
Liferay DXP Missing Authorization Vulnerability (CVE-2022-39975) CVE-2022-39975
Liferay DXP Observable Discrepancy Vulnerability (CVE-2024-25146) CVE-2024-25146
Liferay DXP Observable Discrepancy Vulnerability (CVE-2024-26268) CVE-2024-26268
Liferay DXP Origin Validation Error Vulnerability (CVE-2022-25146) CVE-2022-25146
Liferay DXP Other Vulnerability (CVE-2023-33946) CVE-2023-33946
Liferay DXP Other Vulnerability (CVE-2023-33947) CVE-2023-33947
Liferay DXP Other Vulnerability (CVE-2024-25150) CVE-2024-25150
Liferay DXP Other Vulnerability (CVE-2024-26270) CVE-2024-26270
Liferay DXP Session Fixation Vulnerability (CVE-2023-47798) CVE-2023-47798
Liferay DXP URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-28977) CVE-2022-28977
Liferay DXP URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-5190) CVE-2023-5190
Liferay DXP URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-44308) CVE-2023-44308
Liferay DXP URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2024-25608) CVE-2024-25608
Liferay DXP URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2024-25609) CVE-2024-25609
Liferay DXP Use of Password Hash With Insufficient Computational Effort Vulnerability (CVE-2024-25607) CVE-2024-25607
Liferay Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2020-13445) CVE-2020-13445
Liferay Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Vulnerability (CVE-2019-11444) CVE-2019-11444
Liferay Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Vulnerability (CVE-2020-28884) CVE-2020-28884
Liferay Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Vulnerability (CVE-2020-28885) CVE-2020-28885
Liferay JSON service API authentication vulnerability
Liferay Portal Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2021-33320) CVE-2021-33320
Liferay Portal Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2024-25143) CVE-2024-25143
Liferay Portal Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2024-26265) CVE-2024-26265
Liferay Portal Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2022-42129) CVE-2022-42129
Liferay Portal Cleartext Storage of Sensitive Information Vulnerability (CVE-2021-33323) CVE-2021-33323
Liferay Portal Cleartext Storage of Sensitive Information Vulnerability (CVE-2021-33325) CVE-2021-33325
Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-33338) CVE-2021-33338
Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-35030) CVE-2023-35030
Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-8980) CVE-2024-8980
Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-26271) CVE-2024-26271
Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-26272) CVE-2024-26272
Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-26273) CVE-2024-26273
Liferay Portal CVE-2011-1571 Vulnerability (CVE-2011-1571) CVE-2011-1571
Liferay Portal CVE-2020-13444 Vulnerability (CVE-2020-13444) CVE-2020-13444
Liferay Portal CVE-2020-15840 Vulnerability (CVE-2020-15840) CVE-2020-15840
Liferay Portal CVE-2020-15841 Vulnerability (CVE-2020-15841) CVE-2020-15841
Liferay Portal CVE-2021-33330 Vulnerability (CVE-2021-33330) CVE-2021-33330
Liferay Portal CVE-2021-38266 Vulnerability (CVE-2021-38266) CVE-2021-38266
Liferay Portal CVE-2022-42126 Vulnerability (CVE-2022-42126) CVE-2022-42126