Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • M
Use of Default Credentials
com.liferay.portal:com.liferay.portal.impl[,97.0.0)Maven17 Sept 2025
  • L
External Control of System or Configuration Setting
com.liferay.portal:com.liferay.portal.kernel[,130.0.1)Maven17 Sept 2025
  • L
External Control of System or Configuration Setting
com.liferay:com.liferay.staging.taglib[,8.0.4)Maven17 Sept 2025
  • M
Improper Validation of Specified Quantity in Input
com.liferay:com.liferay.cookies.impl[,1.0.12)Maven17 Sept 2025
  • H
Improper Encoding or Escaping of Output
org.webjars.npm:element-plus[0,]Maven15 Sept 2025
  • H
Authorization Bypass Through User-Controlled Key
com.liferay:com.liferay.object.service[,1.0.197)Maven15 Sept 2025
  • H
Improper Resource Shutdown or Release
co.fs2:fs2-io_3[,2.5.13)[3.12.0-RC1,3.12.2)[3.13.0-M1,3.13.0-M7)Maven15 Sept 2025
  • H
Improper Resource Shutdown or Release
co.fs2:fs2-io_2.13[,2.5.13)[3.12.0-RC1,3.12.2)[3.13.0-M1,3.13.0-M7)Maven15 Sept 2025
  • H
Improper Resource Shutdown or Release
co.fs2:fs2-io_2.12[,2.5.13)[3.12.0-RC1,3.12.2)[3.13.0-M1,3.13.0-M7)Maven15 Sept 2025
  • M
Missing Authorization
io.jenkins.plugins:opentelemetry[,3.1543.1545.vf5a_4ec123769)Maven14 Sept 2025
  • M
Incorrect Authorization
com.liferay:com.liferay.headless.builder.impl[,1.0.32)Maven14 Sept 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.frontend.editor.ckeditor.web[5.0.7,5.0.101)Maven14 Sept 2025
  • M
Cross-site Scripting (XSS)
org.keycloak:keycloak-ui-shared[,26.3.4)Maven12 Sept 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.portal.workflow.kaleo.forms.web[5.0.3,5.0.107)Maven12 Sept 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.client.extension.web[,1.0.71)Maven12 Sept 2025
  • M
Timing Attack
com.liferay:com.liferay.portal.workflow.kaleo.runtime.integration.impl[5.0.23,5.0.50)Maven11 Sept 2025
  • M
Timing Attack
com.liferay:com.liferay.portal.vulcan.impl[5.0.7,5.0.127)Maven11 Sept 2025
  • M
Timing Attack
com.liferay:com.liferay.headless.admin.workflow.impl[5.0.4,5.0.83)Maven11 Sept 2025
  • M
Timing Attack
com.liferay:com.liferay.portal.workflow.api[7.0.1,11.0.1)Maven11 Sept 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.portal.search.web[6.0.125,6.0.143)Maven11 Sept 2025
  • M
Allocation of Resources Without Limits or Throttling
org.webjars.bower:axios[0,]Maven11 Sept 2025
  • M
Allocation of Resources Without Limits or Throttling
org.webjars.bowergithub.axios:axios[0,]Maven11 Sept 2025
  • M
Allocation of Resources Without Limits or Throttling
org.webjars.npm:axios[,1.12.2)Maven11 Sept 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.portal.workflow.task.web[,5.0.76)Maven11 Sept 2025
  • M
Information Exposure
com.liferay:com.liferay.portal.security.sso.openid.connect.impl[0,]Maven11 Sept 2025
  • M
Cross-site Scripting (XSS)
com.liferay:com.liferay.portal.workflow.web[0,]Maven11 Sept 2025
  • M
Server-side Request Forgery (SSRF)
com.liferay:com.liferay.object.service[,1.0.208)Maven11 Sept 2025
  • L
Cross-site Scripting (XSS)
org.webjars.bower:jsondiffpatch[0,]Maven10 Sept 2025
  • L
Cross-site Scripting (XSS)
org.webjars.npm:jsondiffpatch[0,]Maven10 Sept 2025
  • C
Expression Language Injection
org.springframework.cloud:spring-cloud-gateway-server[,4.2.5)[4.3.0,4.3.1)Maven10 Sept 2025