CVE-2022-26597

Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the site name.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.3:-:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.3:fix_pack_1:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.3:fix_pack_2:*:*:*:*:*:*
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*

History

09 Jul 2026, 00:17

Type Values Removed Values Added
References
  • {'url': 'http://liferay.com', 'tags': ['Vendor Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}

05 Jul 2026, 13:16

Type Values Removed Values Added
References
  • () https://liferay.dev/w/cve-2022-26597-stored-xss-with-site-name-in-open-graph-integration -

21 Nov 2024, 06:54

Type Values Removed Values Added
References () http://liferay.com - Vendor Advisory () http://liferay.com - Vendor Advisory

Information

Published : 2022-04-25 16:16

Updated : 2026-07-09 00:17


NVD link : CVE-2022-26597

Mitre link : CVE-2022-26597

CVE.ORG link : CVE-2022-26597


JSON object : View

Products Affected

liferay

  • liferay_portal
  • digital_experience_platform
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')