VendorsLiferayliferay_portal7.2.0
Vulnerabilities

Liferay Portal 7.2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2019-16891
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
Published 2019-10-04 · Modified
9.8EPSS 0.447
CVE-2019-16147
Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.
Published 2019-09-09 · Modified
6.1EPSS 0.008