Description
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
Remediation
References
Related Vulnerabilities
SharePoint CVE-2020-1502 Vulnerability (CVE-2020-1502)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2016-7568)
WordPress Plugin VM Backups Cross-Site Request Forgery (1.0)
WordPress Plugin Chat Room Directory Traversal (0.1.2)
axios Permissive List of Allowed Inputs Vulnerability (CVE-2026-42042)