CVE-2025-43830Cross-site Scripting in Digital Experience Platform

Severity
5.1MEDIUMNVD
EPSS
0.0%
top 91.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 8

Description

Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and 7.3 GA through update 35 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a form with a rich text type field.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Packages4 packages

NVDliferay/liferay_portal7.3.27.4.3.112
NVDliferay/digital_experience_platform2023.q3.12023.q3.9+3
CVEListV5liferay/portal7.3.27.4.3.111
CVEListV5liferay/dxp7.3.107.3.10-u35+3

🔴Vulnerability Details

3
GHSA
Liferay Portal is vulnerable to Stored XSS through Forms text type field2025-10-08
CVEList
CVE-2025-43830: Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 72025-10-08
OSV
Liferay Portal is vulnerable to Stored XSS through Forms text type field2025-10-08