CVE-2022-42119EPSS p39.1%
CVE-2022-42119CVE-2022-42119
liferay / liferay_portal
Description
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
Scoring
| CVSS | 5.4 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 0.51% probability of exploitation · percentile 39.1% · 2026-06-19T12:03:05Z |
| Last modified | 2026-06-17 |