Vulnerabilities (CVE)

Filtered by vendor Liferay Subscribe
Filtered by product Digital Experience Platform
Total 81 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-15839 1 Liferay 2 Digital Experience Platform, Liferay Portal 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.