cbcvebase.
CVE-2025-43825
published 2025-10-03

CVE-2025-43825: A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through…

PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.28%
20.3th percentile
A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows sensitive user data to be included in the Freemarker template. This weakness permits an unauthorized actor to gain access to, and potentially render, confidential information that should remain restricted.

Affected

17 ranges
VendorProductVersion rangeFixed in
liferaydigital_experience_platform
liferaydigital_experience_platform2023.Q3.1 – 2023.Q3.10
liferaydigital_experience_platform2023.q4.0 – 2023.q4.10
liferaydigital_experience_platform>= 2024.Q1.1 < 2024.Q1.132024.Q1.13
liferaydigital_experience_platform2024.Q2.1 – 2024.Q2.13
liferaydigital_experience_platform2024.Q3.0 – 2024.Q3.13
liferaydigital_experience_platform>= 2024.Q4.0 < 2024.Q4.62024.Q4.6
liferaydigital_experience_platform>= 2025.Q1.1 < 2025.Q1.42025.Q1.4
liferaydxp2023.Q3.1 – 2023.Q3.10
liferaydxp2023.Q4.0 – 2024.Q4.10
liferaydxp2024.Q1.1 – 2024.Q1.12
liferaydxp2024.Q2.1 – 2024.Q2.13
liferaydxp2024.Q3.0 – 2024.Q3.13
liferaydxp2024.Q4.0 – 2024.Q4.5
liferaydxp2025.Q1.0 – 2025.Q1.4
liferayliferay_portal7.4.0 – 7.4.3.132
liferayportal7.4.0 – 7.4.3.132

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv4.04.6MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.