Robuta

https://advisories.gitlab.com/maven/com.liferay.commerce/com.liferay.commerce.account.web/CVE-2021-29038/ Liferay Portal and Liferay DXP Does Not Obfuscate Password Reminder Answers | GitLab Advisory... CVE-2021-29038 Liferay Portal and Liferay DXP Does Not Obfuscate Password Reminder Answers: In Liferay Impl before 5.18.4, Liferay Users Admin Web before... liferay portaldoes not https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2022-42130/ Incorrect Default Permissions in Liferay Portal | GitLab Advisory Database (GLAD) CVE-2022-42130 Incorrect Default Permissions in Liferay Portal: The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.4.3.4, and Liferay DXP 7.1... default permissionsliferay portalincorrectgitlabadvisory https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2023-33948/ Missing authorization in Liferay portal | GitLab Advisory Database (GLAD) CVE-2023-33948 Missing authorization in Liferay portal: The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not... liferay portalmissingauthorizationgitlabadvisory https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2021-29053/ Liferay Portal and Liferay DXP Vulnerable to Multiple SQL Injections | GitLab Advisory Database... CVE-2021-29053 Liferay Portal and Liferay DXP Vulnerable to Multiple SQL Injections: Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay... liferay portal https://advisories.gitlab.com/pkg/maven/com.liferay.portal/com.liferay.portal.impl/CVE-2020-15840/ https://advisories.gitlab.com/maven/com.liferay.portal/com.liferay.portal.impl/CVE-2020-15840/ liferay portalhttpsadvisoriesgitlabmaven https://advisories.gitlab.com/maven/com.liferay/com.liferay.portal.workflow.kaleo.runtime.impl/CVE-2025-43773/ Liferay Portal allows improper access through the expandoTableLocalService | GitLab Advisory... CVE-2025-43773 Liferay Portal allows improper access through the expandoTableLocalService: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0,... liferay portalallowsimproperaccessgitlab https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2017-1000425/ https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2017-1000425/ liferay portal https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2021-33321/ Liferay Portal and Liferay DXP insecure default configuration | GitLab Advisory Database (GLAD) CVE-2021-33321 Liferay Portal and Liferay DXP insecure default configuration: Insecure default configuration in portal services implementation before 5.11.0 in... liferay portaldefault configurationdxpinsecure https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2023-42496/ Liferay Portal and Liferay DXP vulnerable to reflected Cross-site Scripting | GitLab Advisory... CVE-2023-42496 Liferay Portal and Liferay DXP vulnerable to reflected Cross-site Scripting: Reflected cross-site scripting (XSS) vulnerability on the add... cross site scriptingliferay portal https://advisories.gitlab.com/maven/com.liferay/com.liferay.roles.selector.web/CVE-2025-43732/ Liferay Portal Vulnerable to Insecure Direct Object Reference | GitLab Advisory Database (GLAD) CVE-2025-43732 Liferay Portal Vulnerable to Insecure Direct Object Reference: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through... liferay portal https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2024-25602/ https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2024-25602/ liferay portal https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2020-13444/ https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2020-13444/ liferay portal https://advisories.gitlab.com/maven/com.liferay.portal/release.dxp.bom/CVE-2024-25608/ Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Replacement... CVE-2024-25608 Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Replacement Character: HtmlUtil.escapeRedirect in Liferay... liferay portal https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2024-25608/ https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2024-25608/ liferay portal https://advisories.gitlab.com/pkg/maven/com.liferay/com.liferay.portal.workflow.kaleo.runtime.impl/ Maven/Com.liferay/Com.liferay.portal.workflow.kaleo.runtime.impl | GitLab Advisory Database (GLAD) liferay portal https://advisories.gitlab.com/maven/com.liferay.portal/release.dxp.bom/CVE-2024-25148/ Liferay Portal vulnerable to user impersonation | GitLab Advisory Database (GLAD) CVE-2024-25148 Liferay Portal vulnerable to user impersonation: In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3... liferay portaluser impersonationvulnerablegitlabadvisory https://advisories.gitlab.com/maven/com.liferay/com.liferay.headless.builder.impl/CVE-2025-43784/ Liferay Portal's Incorrect Authorization vulnerability can lead to guest users to obtaining... CVE-2025-43784 Liferay Portal's Incorrect Authorization vulnerability can lead to guest users to obtaining sensitive data: An Improper Access Control... liferay portal https://advisories.gitlab.com/maven/com.liferay/com.liferay.layout.taglib/CVE-2025-43733/ Liferay Portal Vulnerable to Cross-Site Scripting | GitLab Advisory Database (GLAD) CVE-2025-43733 Liferay Portal Vulnerable to Cross-Site Scripting : A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and... cross site scriptingliferay portalvulnerable https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2022-41414/ Liferay Portal Insecure Default Configuration in auth.login.prompt.enabled | GitLab Advisory... CVE-2022-41414 Liferay Portal Insecure Default Configuration in auth.login.prompt.enabled: An insecure default in the component auth.login.prompt.enabled of... liferay portaldefault configuration https://advisories.gitlab.com/maven/com.liferay/com.liferay.server.admin.web/CVE-2025-3594/ Liferay Portal path traversal vulnerability with the downloading and installation of Xuggler |... CVE-2025-3594 Liferay Portal path traversal vulnerability with the downloading and installation of Xuggler: Path traversal vulnerability with the downloading... liferay portalpath traversal https://advisories.gitlab.com/maven/com.liferay/com.liferay.organizations.item.selector.web/CVE-2023-3426/ Liferay Portal and Liferay DXP Organization Selector Does Not Check User Permissions | GitLab... CVE-2023-3426 Liferay Portal and Liferay DXP Organization Selector Does Not Check User Permissions : The organization selector before 4.0.14 from Liferay... liferay portal https://advisories.gitlab.com/maven/com.liferay/com.liferay.calendar.service/CVE-2025-43739/ Liferay Portal Email Modification Vulnerability via Calendar Portlet | GitLab Advisory Database... CVE-2025-43739 Liferay Portal Email Modification Vulnerability via Calendar Portlet: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through... liferay portalemailmodificationvulnerability https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2023-35030/ https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2023-35030/ liferay portal https://advisories.gitlab.com/maven/com.liferay.commerce/com.liferay.commerce.product.type.virtual.service/CVE-2025-43808/ Liferay Portal Commerce component has Incorrect Permission Assignment for Critical Resource |... CVE-2025-43808 Liferay Portal Commerce component has Incorrect Permission Assignment for Critical Resource: The Commerce component in Liferay Portal 7.3.0... liferay portalcommercecomponent https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2023-5190/ https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2023-5190/ liferay portal https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2021-33335/ https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2021-33335/ liferay portal https://advisories.gitlab.com/maven/com.liferay.portal/release.dxp.bom/CVE-2025-2565/ Liferay Portal and Liferay DXP Reveals Data via Forms | GitLab Advisory Database (GLAD) CVE-2025-2565 Liferay Portal and Liferay DXP Reveals Data via Forms: The data exposure vulnerability in Liferay Portal 7.4.0 through 7.4.3.126, and Liferay DXP... liferay portal https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2025-43731/ Liferay Portal Vulnerable to Cross-Site Scripting | GitLab Advisory Database (GLAD) CVE-2025-43731 Liferay Portal Vulnerable to Cross-Site Scripting: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through... cross site scriptingliferay portalvulnerable https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2022-42126/ Missing permissions check in Liferay Portal | GitLab Advisory Database (GLAD) CVE-2022-42126 Missing permissions check in Liferay Portal: The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before... check inliferay portalmissingpermissionsgitlab https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2024-25148/ Liferay Portal vulnerable to user impersonation | GitLab Advisory Database (GLAD) CVE-2024-25148 Liferay Portal vulnerable to user impersonation: In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3... liferay portaluser impersonationvulnerablegitlabadvisory https://advisories.gitlab.com/maven/com.liferay/com.liferay.dynamic.data.mapping.form.web/CVE-2025-43750/ Liferay Portal Unvalidated File Upload | GitLab Advisory Database (GLAD) CVE-2025-43750 Liferay Portal Unvalidated File Upload: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through... liferay portalfile uploadgitlabadvisorydatabase https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2022-45320/ Privilege escalation in Liferay Portal | GitLab Advisory Database (GLAD) CVE-2022-45320 Privilege escalation in Liferay Portal: Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4... privilege escalationliferay portalgitlabadvisorydatabase https://advisories.gitlab.com/maven/com.liferay.portal/release.dxp.bom/CVE-2023-44311/ Liferay Portal and Liferay DXP Vulnerable to XSS via the OAuth2ProviderApplicationRedirect Class |... CVE-2023-44311 Liferay Portal and Liferay DXP Vulnerable to XSS via the OAuth2ProviderApplicationRedirect Class: Multiple reflected cross-site scripting (XSS)... liferay portaldxpvulnerable https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2020-7934/ Liferay Portal Vulnerable to Persistent Cross-Site Scripting (XSS) in MyAccountPortlet | GitLab... CVE-2020-7934 Liferay Portal Vulnerable to Persistent Cross-Site Scripting (XSS) in MyAccountPortlet: In LifeRay Portal CE 7.1.0 through 7.2.1, the First Name,... cross site scriptingliferay portal https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2024-25150/ Liferay Portal and Liferay DXP Information Disclosure Vulnerability in the Control Panel | GitLab... CVE-2024-25150 Liferay Portal and Liferay DXP Information Disclosure Vulnerability in the Control Panel: Information disclosure vulnerability in the Control... in the control panelliferay portalinformation disclosure https://advisories.gitlab.com/maven/com.liferay/com.liferay.blogs.web/CVE-2025-4576/ Liferay Portal Reflected XSS in blogs-web | GitLab Advisory Database (GLAD) CVE-2025-4576 Liferay Portal Reflected XSS in blogs-web: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133,... liferay portalreflectedxss https://advisories.gitlab.com/maven/com.liferay.portal/release.dxp.bom/CVE-2020-15841/ Liferay Portal and Liferay DXP Potentially Reveal LDAP Server Password via Unsafe Connection |... CVE-2020-15841 Liferay Portal and Liferay DXP Potentially Reveal LDAP Server Password via Unsafe Connection: Liferay Portal before 7.3.0, and Liferay DXP 7.0... liferay portal https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2024-26265/ Liferay Portal vulnerable to Denial of Service | GitLab Advisory Database (GLAD) CVE-2024-26265 Liferay Portal vulnerable to Denial of Service: The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported... denial of serviceliferay portalvulnerable https://advisories.gitlab.com/maven/com.liferay.portal/release.dxp.bom/CVE-2020-15842/ Liferay Portal and Liferay DXP have Insecure Deserialization Vulnerability | GitLab Advisory... CVE-2020-15842 Liferay Portal and Liferay DXP have Insecure Deserialization Vulnerability: Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90,... liferay portalinsecure deserializationdxpvulnerabilitygitlab https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2021-33338/ https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2021-33338/ liferay portal https://advisories.gitlab.com/pkg/maven/com.liferay.portal/com.liferay.portal.impl/CVE-2021-29050/ https://advisories.gitlab.com/maven/com.liferay.portal/com.liferay.portal.impl/CVE-2021-29050/ liferay portalhttpsadvisoriesgitlabmaven https://advisories.gitlab.com/maven/com.liferay.portal/release.dxp.bom/CVE-2021-29052/ Liferay Portal and Liferay DXP Fails to Check Permissions | GitLab Advisory Database (GLAD) CVE-2021-29052 Liferay Portal and Liferay DXP Fails to Check Permissions: The Data Engine module in Liferay Portal 7.3.0 through 7.3.5, and Liferay DXP 7.3... liferay portal https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2021-33335/ Liferay Portal and Liferay DXP Has Company Administrator Accounts Vulnerable to Takeovers | GitLab... CVE-2021-33335 Liferay Portal and Liferay DXP Has Company Administrator Accounts Vulnerable to Takeovers: Privilege escalation vulnerability in Liferay Portal... liferay portal https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2024-26269/ https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2024-26269/ liferay portal https://advisories.gitlab.com/pkg/maven/com.liferay/com.liferay.portal.vulcan.api/ Maven/Com.liferay/Com.liferay.portal.vulcan.api | GitLab Advisory Database (GLAD) liferay portalmavenvulcanapigitlab https://advisories.gitlab.com/maven/com.liferay/com.liferay.users.admin.web/CVE-2021-29038/ Liferay Portal and Liferay DXP Does Not Obfuscate Password Reminder Answers | GitLab Advisory... CVE-2021-29038 Liferay Portal and Liferay DXP Does Not Obfuscate Password Reminder Answers: In Liferay Impl before 5.18.4, Liferay Users Admin Web before... liferay portaldoes not https://advisories.gitlab.com/maven/com.liferay/com.liferay.portal.template.freemarker/CVE-2025-43825/ Liferay Portal exposes sensitive user data through its Freemarker template | GitLab Advisory... CVE-2025-43825 Liferay Portal exposes sensitive user data through its Freemarker template: A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and... liferay portaluser data https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2023-40191/ Liferay Portal and Liferay DXP vulnerable to reflected Cross-site Scripting | GitLab Advisory... CVE-2023-40191 Liferay Portal and Liferay DXP vulnerable to reflected Cross-site Scripting: Reflected cross-site scripting (XSS) vulnerability in the instance... cross site scriptingliferay portal https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2025-43757/ Liferay Portal Vulnerable to Cross-Site Scripting via DDMPortlet_definition Parameter | GitLab... CVE-2025-43757 Liferay Portal Vulnerable to Cross-Site Scripting via DDMPortlet_definition Parameter: A reflected cross-site scripting (XSS) vulnerability in... cross site scriptingliferay portal https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2025-43754/ Liferay Portal Username Enumeration Vulnerability | GitLab Advisory Database (GLAD) CVE-2025-43754 Liferay Portal Username Enumeration Vulnerability: Username enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP... liferay portalusernameenumerationvulnerabilitygitlab https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2023-33948/ https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2023-33948/ liferay portal https://advisories.gitlab.com/maven/com.liferay/com.liferay.portal.vulcan.api/CVE-2025-43796/ Liferay Portal: Missing Rate Limiting in GraphQL Endpoint Enables Resource Exhaustion Attack |... CVE-2025-43796 Liferay Portal: Missing Rate Limiting in GraphQL Endpoint Enables Resource Exhaustion Attack: Liferay Portal 7.4.0 through 7.4.3.101, and... liferay portalrate limiting https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2025-43760/ Liferay Portal Reflected Cross-Site Scripting Vulnerability via PortalUtil.escapeRedirect | GitLab... CVE-2025-43760 Liferay Portal Reflected Cross-Site Scripting Vulnerability via PortalUtil.escapeRedirect: A reflected cross-site scripting (XSS) vulnerability... cross site scriptingliferay portalreflected https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2023-33946/ https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2023-33946/ liferay portal