Vulnerabilities (CVE)

Filtered by vendor Liferay Subscribe
Filtered by product Dxp
Total 62 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-42120 1 Liferay 2 Dxp, Liferay Portal 2024-02-28 N/A 9.8 CRITICAL
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.
CVE-2022-42119 1 Liferay 2 Dxp, Liferay Portal 2024-02-28 N/A 5.4 MEDIUM
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.