https://advisories.gitlab.com/maven/com.liferay.commerce/com.liferay.commerce.account.web/CVE-2021-29038/
Liferay Portal and Liferay DXP Does Not Obfuscate Password Reminder Answers | GitLab Advisory...
CVE-2021-29038 Liferay Portal and Liferay DXP Does Not Obfuscate Password Reminder Answers: In Liferay Impl before 5.18.4, Liferay Users Admin Web before...
liferay portaldoes not
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2022-42130/
Incorrect Default Permissions in Liferay Portal | GitLab Advisory Database (GLAD)
CVE-2022-42130 Incorrect Default Permissions in Liferay Portal: The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.4.3.4, and Liferay DXP 7.1...
default permissionsliferay portalincorrectgitlabadvisory
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2023-33948/
Missing authorization in Liferay portal | GitLab Advisory Database (GLAD)
CVE-2023-33948 Missing authorization in Liferay portal: The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not...
liferay portalmissingauthorizationgitlabadvisory
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2021-29053/
Liferay Portal and Liferay DXP Vulnerable to Multiple SQL Injections | GitLab Advisory Database...
CVE-2021-29053 Liferay Portal and Liferay DXP Vulnerable to Multiple SQL Injections: Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay...
liferay portal
https://advisories.gitlab.com/pkg/maven/com.liferay.portal/com.liferay.portal.impl/CVE-2020-15840/
https://advisories.gitlab.com/maven/com.liferay.portal/com.liferay.portal.impl/CVE-2020-15840/
liferay portalhttpsadvisoriesgitlabmaven
https://advisories.gitlab.com/maven/com.liferay/com.liferay.portal.workflow.kaleo.runtime.impl/CVE-2025-43773/
Liferay Portal allows improper access through the expandoTableLocalService | GitLab Advisory...
CVE-2025-43773 Liferay Portal allows improper access through the expandoTableLocalService: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0,...
liferay portalallowsimproperaccessgitlab
https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2017-1000425/
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2017-1000425/
liferay portal
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2021-33321/
Liferay Portal and Liferay DXP insecure default configuration | GitLab Advisory Database (GLAD)
CVE-2021-33321 Liferay Portal and Liferay DXP insecure default configuration: Insecure default configuration in portal services implementation before 5.11.0 in...
liferay portaldefault configurationdxpinsecure
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2023-42496/
Liferay Portal and Liferay DXP vulnerable to reflected Cross-site Scripting | GitLab Advisory...
CVE-2023-42496 Liferay Portal and Liferay DXP vulnerable to reflected Cross-site Scripting: Reflected cross-site scripting (XSS) vulnerability on the add...
cross site scriptingliferay portal
https://advisories.gitlab.com/maven/com.liferay/com.liferay.roles.selector.web/CVE-2025-43732/
Liferay Portal Vulnerable to Insecure Direct Object Reference | GitLab Advisory Database (GLAD)
CVE-2025-43732 Liferay Portal Vulnerable to Insecure Direct Object Reference: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through...
liferay portal
https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2024-25602/
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2024-25602/
liferay portal
https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2020-13444/
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2020-13444/
liferay portal
https://advisories.gitlab.com/maven/com.liferay.portal/release.dxp.bom/CVE-2024-25608/
Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Replacement...
CVE-2024-25608 Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Replacement Character: HtmlUtil.escapeRedirect in Liferay...
liferay portal
https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2024-25608/
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2024-25608/
liferay portal
https://advisories.gitlab.com/pkg/maven/com.liferay/com.liferay.portal.workflow.kaleo.runtime.impl/
Maven/Com.liferay/Com.liferay.portal.workflow.kaleo.runtime.impl | GitLab Advisory Database (GLAD)
liferay portal
https://advisories.gitlab.com/maven/com.liferay.portal/release.dxp.bom/CVE-2024-25148/
Liferay Portal vulnerable to user impersonation | GitLab Advisory Database (GLAD)
CVE-2024-25148 Liferay Portal vulnerable to user impersonation: In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3...
liferay portaluser impersonationvulnerablegitlabadvisory
https://advisories.gitlab.com/maven/com.liferay/com.liferay.headless.builder.impl/CVE-2025-43784/
Liferay Portal's Incorrect Authorization vulnerability can lead to guest users to obtaining...
CVE-2025-43784 Liferay Portal's Incorrect Authorization vulnerability can lead to guest users to obtaining sensitive data: An Improper Access Control...
liferay portal
https://advisories.gitlab.com/maven/com.liferay/com.liferay.layout.taglib/CVE-2025-43733/
Liferay Portal Vulnerable to Cross-Site Scripting | GitLab Advisory Database (GLAD)
CVE-2025-43733 Liferay Portal Vulnerable to Cross-Site Scripting : A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and...
cross site scriptingliferay portalvulnerable
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2022-41414/
Liferay Portal Insecure Default Configuration in auth.login.prompt.enabled | GitLab Advisory...
CVE-2022-41414 Liferay Portal Insecure Default Configuration in auth.login.prompt.enabled: An insecure default in the component auth.login.prompt.enabled of...
liferay portaldefault configuration
https://advisories.gitlab.com/maven/com.liferay/com.liferay.server.admin.web/CVE-2025-3594/
Liferay Portal path traversal vulnerability with the downloading and installation of Xuggler |...
CVE-2025-3594 Liferay Portal path traversal vulnerability with the downloading and installation of Xuggler: Path traversal vulnerability with the downloading...
liferay portalpath traversal
https://advisories.gitlab.com/maven/com.liferay/com.liferay.organizations.item.selector.web/CVE-2023-3426/
Liferay Portal and Liferay DXP Organization Selector Does Not Check User Permissions | GitLab...
CVE-2023-3426 Liferay Portal and Liferay DXP Organization Selector Does Not Check User Permissions : The organization selector before 4.0.14 from Liferay...
liferay portal
https://advisories.gitlab.com/maven/com.liferay/com.liferay.calendar.service/CVE-2025-43739/
Liferay Portal Email Modification Vulnerability via Calendar Portlet | GitLab Advisory Database...
CVE-2025-43739 Liferay Portal Email Modification Vulnerability via Calendar Portlet: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through...
liferay portalemailmodificationvulnerability
https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2023-35030/
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2023-35030/
liferay portal
https://advisories.gitlab.com/maven/com.liferay.commerce/com.liferay.commerce.product.type.virtual.service/CVE-2025-43808/
Liferay Portal Commerce component has Incorrect Permission Assignment for Critical Resource |...
CVE-2025-43808 Liferay Portal Commerce component has Incorrect Permission Assignment for Critical Resource: The Commerce component in Liferay Portal 7.3.0...
liferay portalcommercecomponent
https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2023-5190/
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2023-5190/
liferay portal
https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2021-33335/
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2021-33335/
liferay portal
https://advisories.gitlab.com/maven/com.liferay.portal/release.dxp.bom/CVE-2025-2565/
Liferay Portal and Liferay DXP Reveals Data via Forms | GitLab Advisory Database (GLAD)
CVE-2025-2565 Liferay Portal and Liferay DXP Reveals Data via Forms: The data exposure vulnerability in Liferay Portal 7.4.0 through 7.4.3.126, and Liferay DXP...
liferay portal
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2025-43731/
Liferay Portal Vulnerable to Cross-Site Scripting | GitLab Advisory Database (GLAD)
CVE-2025-43731 Liferay Portal Vulnerable to Cross-Site Scripting: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through...
cross site scriptingliferay portalvulnerable
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2022-42126/
Missing permissions check in Liferay Portal | GitLab Advisory Database (GLAD)
CVE-2022-42126 Missing permissions check in Liferay Portal: The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before...
check inliferay portalmissingpermissionsgitlab
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2024-25148/
Liferay Portal vulnerable to user impersonation | GitLab Advisory Database (GLAD)
CVE-2024-25148 Liferay Portal vulnerable to user impersonation: In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3...
liferay portaluser impersonationvulnerablegitlabadvisory
https://advisories.gitlab.com/maven/com.liferay/com.liferay.dynamic.data.mapping.form.web/CVE-2025-43750/
Liferay Portal Unvalidated File Upload | GitLab Advisory Database (GLAD)
CVE-2025-43750 Liferay Portal Unvalidated File Upload: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through...
liferay portalfile uploadgitlabadvisorydatabase
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2022-45320/
Privilege escalation in Liferay Portal | GitLab Advisory Database (GLAD)
CVE-2022-45320 Privilege escalation in Liferay Portal: Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4...
privilege escalationliferay portalgitlabadvisorydatabase
https://advisories.gitlab.com/maven/com.liferay.portal/release.dxp.bom/CVE-2023-44311/
Liferay Portal and Liferay DXP Vulnerable to XSS via the OAuth2ProviderApplicationRedirect Class |...
CVE-2023-44311 Liferay Portal and Liferay DXP Vulnerable to XSS via the OAuth2ProviderApplicationRedirect Class: Multiple reflected cross-site scripting (XSS)...
liferay portaldxpvulnerable
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2020-7934/
Liferay Portal Vulnerable to Persistent Cross-Site Scripting (XSS) in MyAccountPortlet | GitLab...
CVE-2020-7934 Liferay Portal Vulnerable to Persistent Cross-Site Scripting (XSS) in MyAccountPortlet: In LifeRay Portal CE 7.1.0 through 7.2.1, the First Name,...
cross site scriptingliferay portal
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2024-25150/
Liferay Portal and Liferay DXP Information Disclosure Vulnerability in the Control Panel | GitLab...
CVE-2024-25150 Liferay Portal and Liferay DXP Information Disclosure Vulnerability in the Control Panel: Information disclosure vulnerability in the Control...
in the control panelliferay portalinformation disclosure
https://advisories.gitlab.com/maven/com.liferay/com.liferay.blogs.web/CVE-2025-4576/
Liferay Portal Reflected XSS in blogs-web | GitLab Advisory Database (GLAD)
CVE-2025-4576 Liferay Portal Reflected XSS in blogs-web: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133,...
liferay portalreflectedxss
https://advisories.gitlab.com/maven/com.liferay.portal/release.dxp.bom/CVE-2020-15841/
Liferay Portal and Liferay DXP Potentially Reveal LDAP Server Password via Unsafe Connection |...
CVE-2020-15841 Liferay Portal and Liferay DXP Potentially Reveal LDAP Server Password via Unsafe Connection: Liferay Portal before 7.3.0, and Liferay DXP 7.0...
liferay portal
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2024-26265/
Liferay Portal vulnerable to Denial of Service | GitLab Advisory Database (GLAD)
CVE-2024-26265 Liferay Portal vulnerable to Denial of Service: The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported...
denial of serviceliferay portalvulnerable
https://advisories.gitlab.com/maven/com.liferay.portal/release.dxp.bom/CVE-2020-15842/
Liferay Portal and Liferay DXP have Insecure Deserialization Vulnerability | GitLab Advisory...
CVE-2020-15842 Liferay Portal and Liferay DXP have Insecure Deserialization Vulnerability: Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90,...
liferay portalinsecure deserializationdxpvulnerabilitygitlab
https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2021-33338/
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2021-33338/
liferay portal
https://advisories.gitlab.com/pkg/maven/com.liferay.portal/com.liferay.portal.impl/CVE-2021-29050/
https://advisories.gitlab.com/maven/com.liferay.portal/com.liferay.portal.impl/CVE-2021-29050/
liferay portalhttpsadvisoriesgitlabmaven
https://advisories.gitlab.com/maven/com.liferay.portal/release.dxp.bom/CVE-2021-29052/
Liferay Portal and Liferay DXP Fails to Check Permissions | GitLab Advisory Database (GLAD)
CVE-2021-29052 Liferay Portal and Liferay DXP Fails to Check Permissions: The Data Engine module in Liferay Portal 7.3.0 through 7.3.5, and Liferay DXP 7.3...
liferay portal
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2021-33335/
Liferay Portal and Liferay DXP Has Company Administrator Accounts Vulnerable to Takeovers | GitLab...
CVE-2021-33335 Liferay Portal and Liferay DXP Has Company Administrator Accounts Vulnerable to Takeovers: Privilege escalation vulnerability in Liferay Portal...
liferay portal
https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2024-26269/
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2024-26269/
liferay portal
https://advisories.gitlab.com/pkg/maven/com.liferay/com.liferay.portal.vulcan.api/
Maven/Com.liferay/Com.liferay.portal.vulcan.api | GitLab Advisory Database (GLAD)
liferay portalmavenvulcanapigitlab
https://advisories.gitlab.com/maven/com.liferay/com.liferay.users.admin.web/CVE-2021-29038/
Liferay Portal and Liferay DXP Does Not Obfuscate Password Reminder Answers | GitLab Advisory...
CVE-2021-29038 Liferay Portal and Liferay DXP Does Not Obfuscate Password Reminder Answers: In Liferay Impl before 5.18.4, Liferay Users Admin Web before...
liferay portaldoes not
https://advisories.gitlab.com/maven/com.liferay/com.liferay.portal.template.freemarker/CVE-2025-43825/
Liferay Portal exposes sensitive user data through its Freemarker template | GitLab Advisory...
CVE-2025-43825 Liferay Portal exposes sensitive user data through its Freemarker template: A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and...
liferay portaluser data
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2023-40191/
Liferay Portal and Liferay DXP vulnerable to reflected Cross-site Scripting | GitLab Advisory...
CVE-2023-40191 Liferay Portal and Liferay DXP vulnerable to reflected Cross-site Scripting: Reflected cross-site scripting (XSS) vulnerability in the instance...
cross site scriptingliferay portal
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2025-43757/
Liferay Portal Vulnerable to Cross-Site Scripting via DDMPortlet_definition Parameter | GitLab...
CVE-2025-43757 Liferay Portal Vulnerable to Cross-Site Scripting via DDMPortlet_definition Parameter: A reflected cross-site scripting (XSS) vulnerability in...
cross site scriptingliferay portal
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2025-43754/
Liferay Portal Username Enumeration Vulnerability | GitLab Advisory Database (GLAD)
CVE-2025-43754 Liferay Portal Username Enumeration Vulnerability: Username enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP...
liferay portalusernameenumerationvulnerabilitygitlab
https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2023-33948/
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2023-33948/
liferay portal
https://advisories.gitlab.com/maven/com.liferay/com.liferay.portal.vulcan.api/CVE-2025-43796/
Liferay Portal: Missing Rate Limiting in GraphQL Endpoint Enables Resource Exhaustion Attack |...
CVE-2025-43796 Liferay Portal: Missing Rate Limiting in GraphQL Endpoint Enables Resource Exhaustion Attack: Liferay Portal 7.4.0 through 7.4.3.101, and...
liferay portalrate limiting
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2025-43760/
Liferay Portal Reflected Cross-Site Scripting Vulnerability via PortalUtil.escapeRedirect | GitLab...
CVE-2025-43760 Liferay Portal Reflected Cross-Site Scripting Vulnerability via PortalUtil.escapeRedirect: A reflected cross-site scripting (XSS) vulnerability...
cross site scriptingliferay portalreflected
https://advisories.gitlab.com/pkg/maven/com.liferay.portal/release.portal.bom/CVE-2023-33946/
https://advisories.gitlab.com/maven/com.liferay.portal/release.portal.bom/CVE-2023-33946/
liferay portal