CVE-2024-26269

📊 9.6 CRITICAL0.1%🎯 0 exploits
📅 Published Feb 21, 2024
📋 Status: Analyzed

Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via the anchor (hash) part of a URL.

🎯 Affected Products & Systems

79 product configurations affected

Filter by type:
📱
Application
Vulnerable
Version: ≥ 7.2.0 ∧ < 7.4.3.38
CPE:
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*
Vulnerable
Version: < 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:-:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_1:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_10:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_11:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_12:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_13:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_14:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_15:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_16:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_17:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_18:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_19:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_2:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_3:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_4:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_5:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_6:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_7:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_8:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:fix_pack_9:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:service_pack_1:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:service_pack_2:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:service_pack_3:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:service_pack_4:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:service_pack_5:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:service_pack_6:*:*:*:*:*:*
Vulnerable
Version: 7.2
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.2:service_pack_7:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:-:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:fix_pack_1:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:fix_pack_2:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:service_pack_1:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:service_pack_3:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update10:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update4:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update5:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update6:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update7:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update8:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update9:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:-:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update1:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update10:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update11:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update12:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update13:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update14:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update15:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update16:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update17:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update18:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update19:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update2:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update20:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update21:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update22:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update23:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update24:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update25:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update26:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update27:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update28:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update29:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update3:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update30:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update31:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update32:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update33:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update34:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update35:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update36:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update37:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update4:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update5:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update6:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update7:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update8:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update9:*:*:*:*:*:*
79 productsscroll for more
Metrics
9.6 CRITICALCVSS v3.1[email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector:
NETWORK
Complexity:
LOW
Privileges:
NONE
User Interaction:
REQUIRED
Confidentiality:
HIGH
Integrity:
HIGH
Availability:
HIGH
Scope:
CHANGED

🔍 Technical Details

Analysis Status
Analyzed
CVSS Details
9.6 (CRITICAL)v3.1
EPSS Details
0.1% (Minimal)35.1th percentile
Last updated: Nov 1, 2025
Exploitation probability within 30 days
Published Date
Feb 21, 2024 (1 year ago)
Last Modified
Jan 28, 2025 (9 months ago)
Security Weaknesses2
References2