Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • M
Cross-site Scripting (XSS)
com.liferay.portal:com.liferay.portal.kernel[0,]Maven21 Aug 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.comment.sanitizer[0,]Maven21 Aug 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.portal.security.iframe.sanitizer[0,]Maven21 Aug 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.portal.security.antisamy[0,]Maven21 Aug 2025
  • M
Cross-site Request Forgery (CSRF)
com.liferay:com.liferay.headless.discovery.web[,4.0.60)Maven21 Aug 2025
  • M
Files or Directories Accessible to External Parties
com.liferay:com.liferay.dynamic.data.mapping.form.web[,4.0.180)Maven21 Aug 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.asset.taglib[,11.1.9)Maven21 Aug 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.journal.service[,7.0.172)Maven21 Aug 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.asset.api[,10.0.1)Maven21 Aug 2025
  • H
Allocation of Resources Without Limits or Throttling
org.eclipse.jetty.http2:jetty-http2-common[12.0.0-alpha0,12.0.25)[12.1.0.alpha0,12.1.0.beta3)Maven21 Aug 2025
  • H
Allocation of Resources Without Limits or Throttling
org.eclipse.jetty.http2:http2-server[,9.4.58.v20250814)[10.0.0-alpha0,10.0.26)[11.0.0-alpha0,11.0.26)Maven21 Aug 2025
  • H
Allocation of Resources Without Limits or Throttling
org.eclipse.jetty.http2:jetty-http2-server[12.0.0-alpha0,12.0.25)[12.1.0.alpha0,12.1.0.beta3)Maven21 Aug 2025
  • H
Allocation of Resources Without Limits or Throttling
org.eclipse.jetty.http2:http2-common[,9.4.58.v20250814)[10.0.0-alpha0,10.0.26)[11.0.0-alpha0,11.0.26)Maven21 Aug 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.layout.type.controller.display.page[,3.0.59)Maven21 Aug 2025
  • M
Improper Neutralization
com.sun.mail:jakarta.mail[,1.6.8)[2.0.0-RC1,2.0.2)Maven20 Aug 2025
  • H
SQL Injection
org.open-metadata:openmetadata-service[,1.4.5-rc1)Maven20 Aug 2025
  • M
Cross-site Scripting (XSS)
org.webjars.npm:mermaid[11.1.0,]Maven20 Aug 2025
  • M
Cross-site Scripting (XSS)
org.webjars.npm:mermaid[10.9.0,]Maven20 Aug 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.expando.web[,5.0.60)Maven20 Aug 2025
  • H
Access Control Bypass
org.graalvm.sdk:graal-sdk[,17.0.16)[18.0.0,21.0.8)[22.0.0,24.0.2)Maven19 Aug 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.message.boards.web[,5.0.120)Maven19 Aug 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.frontend.editor.ckeditor.web[,5.0.111)Maven19 Aug 2025
  • L
Cross-site Scripting (XSS)
com.liferay:com.liferay.layout.taglib[,16.1.33)Maven19 Aug 2025
  • H
SQL Injection
org.open-metadata:openmetadata-service[,1.4.5-rc1)Maven19 Aug 2025
  • H
SQL Injection
org.open-metadata:openmetadata-service[,1.4.5-rc1)Maven19 Aug 2025
  • C
Deserialization of Untrusted Data
org.graalvm.sdk:graal-sdk[,17.0.16)[18.0.0,21.0.8)[22.0.0,24.0.2)Maven19 Aug 2025
  • C
Deserialization of Untrusted Data
org.graalvm.sdk:graal-sdk[,17.0.16)[18.0.0,21.0.8)[22.0.0,24.0.2)Maven19 Aug 2025
  • M
Authorization Bypass Through User-Controlled Key
com.liferay:com.liferay.roles.selector.web[,5.0.31)Maven19 Aug 2025
  • H
Relative Path Traversal
org.springframework:spring-beans[,6.2.10)Maven19 Aug 2025
  • M
SQL Injection
org.open-metadata:openmetadata-service[,1.4.5-rc1)Maven19 Aug 2025