Known vulnerabilities in Liferay Enterprise Portal 7.0 CE GA5 - page 2

Vendor: Liferay
Version: 7.0 CE GA5
Software CPE: cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*
Website:
Total vulnerabilities: 38
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Liferay Enterprise Portal version 7.0 CE GA5 Liferay Enterprise Portal 7.0 CE GA5 is affected by 38 vulnerabilities: 1 high, 13 medium, 24 low Critical High Medium Low

Vulnerabilities (38)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU86680 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-26266
CWE-79 Low
No
No
7.4.3.14 ga14 21.02.2024 SB2024022110
#VU86669 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-25151
CWE-79 Low
No
No
7.4.3.4 ga4 21.02.2024 SB2024022106
#VU86601 - Permissions, Privileges, and Access Controls
CVE-2022-45320
CWE-264 Medium
No
No
7.4.3.16 ga16 20.02.2024 SB2024022006
#VU86597 - Improper Access Control
CVE-2024-25149
CWE-284 Medium
No
No
7.4.2 ga3 20.02.2024 SB2024022008
#VU74602 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-28978
CWE-79 Low
No
No
7.4.2 ga3 07.04.2023 SB2023040728
#VU60940 - Improper input validation
CWE-20 Low
No
No
7.2.1 02.03.2022 SB2022030203
#VU60022 - Exposure of sensitive information to an unauthorized actor
CWE-200 Medium
No
No
7.3.7 ga8, 7.4.3.4 ga4 26.01.2022 SB2022012620
#VU60012 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Low
No
No
7.3.7 ga8, 7.4.2 ga3 26.01.2022 SB2022012618
#VU53223 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-29044
CWE-79 Low
No
No
7.3.6 ga7 13.05.2021 SB2021051306
#VU12210 - Exposure of sensitive information to an unauthorized actor
CWE-200 Low
No
No
- 26.04.2018 SB2018042602
#VU12208 - Exposure of sensitive information to an unauthorized actor
CWE-200 Low
No
No
- 26.04.2018 SB2018042602
#VU12206 - URL Redirection to Untrusted Site ('Open Redirect')
CWE-601 Low
No
No
- 26.04.2018 SB2018042602
#VU12204 - Permissions, Privileges, and Access Controls
CWE-264 Low
No
No
- 26.04.2018 SB2018042602
#VU12203 - Resource exhaustion
CWE-400 Low
No
No
- 26.04.2018 SB2018042602
#VU12194 - Exposure of sensitive information to an unauthorized actor
CWE-200 Low
No
No
- 26.04.2018 SB2018042602
#VU12192 - Permissions, Privileges, and Access Controls
CWE-264 Low
No
No
- 26.04.2018 SB2018042602
#VU12189 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Low
No
No
- 26.04.2018 SB2018042602
#VU7654 - Improper input validation
CVE-2017-9801
CWE-20 Low
No
No
- 02.08.2017 SB2017080203
SB2018042602
SB2022072718


Showing elements 21 - 40 out of 38