Vulnerabilities (CVE)

Filtered by vendor Liferay Subscribe
Filtered by product Liferay Portal
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-7961 1 Liferay 1 Liferay Portal 2021-01-30 7.5 HIGH 9.8 CRITICAL
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).