CVE-2022-42119EPSS p32.0%
CVE-2022-42119CVE-2022-42119
liferay / liferay_portal
Description
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
Scoring
| CVSS | 5.4 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 0.39% probability of exploitation · percentile 32.0% · 2026-08-03T12:00:16Z |
| Last modified | 2026-07-09 |