Known Vulnerabilities for Dxp by Liferay
Listed below are 10 of the newest known vulnerabilities associated with "Dxp" by "Liferay".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-35030 json | Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7... | 8.8 - HIGH | 2023-06-15 | 2023-06-22 |
| CVE-2023-35029 json | Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay... | 6.1 - MEDIUM | 2023-06-15 | 2023-06-22 |
| CVE-2023-3193 json | Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.73... | 6.1 - MEDIUM | 2023-06-15 | 2023-06-22 |
| CVE-2022-42122 json | A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through upda... | 9.8 - CRITICAL | 2022-11-15 | 2022-11-17 |
| CVE-2022-42121 json | A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pa... | 8.8 - HIGH | 2022-11-15 | 2022-11-17 |
| CVE-2022-42120 json | A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before upd... | 9.8 - CRITICAL | 2022-11-15 | 2022-11-17 |
| CVE-2022-42119 json | Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.... | 5.4 - MEDIUM | 2022-11-15 | 2022-11-17 |
| CVE-2022-42118 json | A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP... | 6.1 - MEDIUM | 2022-11-15 | 2022-11-17 |
| CVE-2022-42117 json | A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 through 7.4.3.16, and Lifera... | 6.1 - MEDIUM | 2022-10-18 | 2022-10-20 |
| CVE-2022-42116 json | A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 ... | 6.1 - MEDIUM | 2022-10-18 | 2022-10-20 |