📦

portal

Vendor: liferay

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 0 Remote Access
Total CVEs 5 Total Indexed
Avg. EPSS 1.94% Exploit Prob.
Latest CVE CVE-2011-1504 May 07

Security Vulnerability Index

Page 1 / 1
3.5 CVSS

Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA allows remote authenticated users to inject arbitrary web script or HTML via a blog title.

EPSS: 0.99%
4.3 CVSS
CVE-2007-6055
Exploit Found

Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay Portal 4.1.0 and 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter. NOTE: this issue reportedly exists because of a regression that followed a fix at an unspecified earlier date.

EPSS: 2.89%