CVE-2022-42119EPSS p34.3%
CVE-2022-42119CVE-2022-42119
liferay / liferay_portal
Description
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
Scoring
| CVSS | 5.4 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 0.42% probability of exploitation · percentile 34.3% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-09 |