Vulnerability Name CVE Severity
Liferay Portal Insecure Default Initialization of Resource Vulnerability (CVE-2024-25610) CVE-2024-25610
Liferay Portal Insufficiently Protected Credentials Vulnerability (CVE-2021-29043) CVE-2021-29043
Liferay Portal Missing Authorization Vulnerability (CVE-2022-38512) CVE-2022-38512
Liferay Portal Missing Authorization Vulnerability (CVE-2022-39975) CVE-2022-39975
Liferay Portal Missing Authorization Vulnerability (CVE-2023-3426) CVE-2023-3426
Liferay Portal Observable Discrepancy Vulnerability (CVE-2024-25146) CVE-2024-25146
Liferay Portal Origin Validation Error Vulnerability (CVE-2022-25146) CVE-2022-25146
Liferay Portal Other Vulnerability (CVE-2023-33946) CVE-2023-33946
Liferay Portal Other Vulnerability (CVE-2023-33947) CVE-2023-33947
Liferay Portal Other Vulnerability (CVE-2024-25150) CVE-2024-25150
Liferay Portal Session Fixation Vulnerability (CVE-2023-47798) CVE-2023-47798
Liferay Portal Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-15839) CVE-2020-15839
Liferay Portal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-33331) CVE-2021-33331
Liferay Portal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-28977) CVE-2022-28977
Liferay Portal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-35029) CVE-2023-35029
Liferay Portal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2024-25608) CVE-2024-25608
Liferay Portal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2024-25609) CVE-2024-25609
Liferay version older than 7.1
Liferay XMLRPC Blind SSRF
lightbox2 Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-9441) CVE-2014-9441
Lighttpd Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-1111) CVE-2008-1111
Lighttpd Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-1270) CVE-2008-1270
Lighttpd Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2014-2324) CVE-2014-2324
Lighttpd Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2007-4727) CVE-2007-4727
Lighttpd Other Vulnerability (CVE-2005-0453) CVE-2005-0453
Lighttpd Other Vulnerability (CVE-2006-0814) CVE-2006-0814
Lighttpd Other Vulnerability (CVE-2007-1869) CVE-2007-1869
Lighttpd Other Vulnerability (CVE-2007-3946) CVE-2007-3946
Lighttpd Other Vulnerability (CVE-2007-3947) CVE-2007-3947
Lighttpd Other Vulnerability (CVE-2007-3948) CVE-2007-3948
Lighttpd Other Vulnerability (CVE-2007-3950) CVE-2007-3950
Lighttpd Other Vulnerability (CVE-2008-1531) CVE-2008-1531
Lighttpd Other Vulnerability (CVE-2011-4362) CVE-2011-4362
Lighttpd Out-of-bounds Write Vulnerability (CVE-2022-22707) CVE-2022-22707
Lighttpd Resource Management Errors Vulnerability (CVE-2008-0983) CVE-2008-0983
Lighttpd Resource Management Errors Vulnerability (CVE-2008-4298) CVE-2008-4298
Lighttpd Resource Management Errors Vulnerability (CVE-2010-0295) CVE-2010-0295
Lighttpd Resource Management Errors Vulnerability (CVE-2012-5533) CVE-2012-5533
Lighttpd Use After Free Vulnerability (CVE-2013-4560) CVE-2013-4560
LimeSurvey CVE-2019-16176 Vulnerability (CVE-2019-16176) CVE-2019-16176
LimeSurvey CVE-2019-16180 Vulnerability (CVE-2019-16180) CVE-2019-16180
LimeSurvey Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3752) CVE-2011-3752
LimeSurvey Improper Certificate Validation Vulnerability (CVE-2019-16179) CVE-2019-16179
LimeSurvey Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2007-5573) CVE-2007-5573
LimeSurvey Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2020-11455) CVE-2020-11455
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2008-2571) CVE-2008-2571
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-4995) CVE-2012-4995
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2014-5016) CVE-2014-5016
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2017-18358) CVE-2017-18358
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-17003) CVE-2018-17003
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-20322) CVE-2018-20322
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-16172) CVE-2019-16172
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-16173) CVE-2019-16173
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-16178) CVE-2019-16178
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-16182) CVE-2019-16182
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-17660) CVE-2019-17660
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-11456) CVE-2020-11456
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-16192) CVE-2020-16192
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-23710) CVE-2020-23710
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-25797) CVE-2020-25797
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-25798) CVE-2020-25798
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-25799) CVE-2020-25799
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-42112) CVE-2021-42112
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-29710) CVE-2022-29710
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-48010) CVE-2022-48010
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-44796) CVE-2023-44796
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-28709) CVE-2024-28709
LimeSurvey Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-28710) CVE-2024-28710
LimeSurvey Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2024-42903) CVE-2024-42903
LimeSurvey Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2012-4994) CVE-2012-4994
LimeSurvey Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2015-4628) CVE-2015-4628
LimeSurvey Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2015-5078) CVE-2015-5078
LimeSurvey Improper Restriction of Rendered UI Layers or Frames Vulnerability (CVE-2019-16175) CVE-2019-16175
LimeSurvey Other Vulnerability (CVE-2014-5018) CVE-2014-5018
LimeSurvey Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-16397) CVE-2018-16397