Liferay Digital Experience Platform vulnerabilities
264 known vulnerabilities affecting liferay/digital_experience_platform.
Total CVEs
264
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH35MEDIUM224LOW2
Vulnerabilities
Page 10 of 14
CVE-2025-62240P4MEDIUMCVSS 5.4≥ 2023.Q3.1, < 2023.Q3.8≥ 2023.q4.0, < 2023.q4.6+2 more2025-10-09
CVE-2025-62240 [MEDIUM] CWE-79 CVE-2025-62240: Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35
Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 update 35 through update 92, and 7.3 update 25 through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injecte
nvd
CVE-2025-43821P4MEDIUMCVSS 5.4≥ 2023.q3.1, < 2023.q3.9≥ 2023.q4.0, < 2023.q4.6+1 more2025-10-08
CVE-2025-43821 [MEDIUM] CWE-79 CVE-2025-43821: Cross-site scripting (XSS) vulnerability in the Commerce Product Comparison Table widget in Liferay
Cross-site scripting (XSS) vulnerability in the Commerce Product Comparison Table widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Commerce Product'
nvd
CVE-2025-43823P4MEDIUMCVSS 5.4≥ 2023.q3.1, < 2023.q3.9≥ 2023.q4.0, < 2023.q4.6+1 more2025-10-07
CVE-2025-43823 [MEDIUM] CWE-79 CVE-2025-43823: Cross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4.
Cross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 2023.Q4 before patch 6, 2023.Q3 before patch 9, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Commerce Product's Name text field.
nvd
CVE-2025-43753P4MEDIUMCVSS 5.4≥ 2024.Q1.1, < 2024.Q1.17≥ 2024.Q2.1, ≤ 2024.Q2.13+4 more2025-08-21
CVE-2025-43753 [MEDIUM] CWE-79 CVE-2025-43753: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.32 through 7.4.3.13
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.32 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.16 and 7.4 update 32 through update 92 allows an remote authenticated user to inject Java
nvd
CVE-2025-43771P4MEDIUMCVSS 5.4≥ 2023.Q3.1, < 2023.Q3.4≥ 2023.q4.0, < 2023.q4.62025-10-08
CVE-2025-43771 [MEDIUM] CWE-79 CVE-2025-43771: Multiple cross-site scripting (XSS) vulnerabilities in the Notifications widget in Liferay Portal 7.
Multiple cross-site scripting (XSS) vulnerabilities in the Notifications widget in Liferay Portal 7.4.3.102 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5 and 2023.Q3.1 through 2023.Q3.10 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into (1) a user’s “First Name” text field, (2) a user’s
nvd
CVE-2025-43812P4MEDIUMCVSS 5.4≥ 2023.q3.1, < 2023.q3.9≥ 2023.Q4.0, < 2023.Q4.5+1 more2025-09-29
CVE-2025-43812 [MEDIUM] CWE-79 CVE-2025-43812: Cross-site scripting (XSS) vulnerability in web content template in Liferay Portal 7.4.3.4 through 7
Cross-site scripting (XSS) vulnerability in web content template in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into a web content structure's Name
nvd
CVE-2025-43820P4MEDIUMCVSS 5.4≥ 2023.Q3.1, < 2023.Q3.7≥ 2023.Q4.0, < 2023.Q4.5+2 more2025-09-29
CVE-2025-43820 [MEDIUM] CWE-79 CVE-2025-43820: Multiple cross-site scripting (XSS) vulnerabilities in the Calendar widget when inviting users to a
Multiple cross-site scripting (XSS) vulnerabilities in the Calendar widget when inviting users to a event in Liferay Portal 7.4.3.35 through 7.4.3.110, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.6, 7.4 update 35 through update 92, and 7.3 update 25 through update 35 allow remote attackers to inject arbitrary web script or H
nvd
CVE-2021-38263P4MEDIUMCVSS 6.1v7.0v7.0-fix_pack_1+129 more2022-03-03
CVE-2021-38263 [MEDIUM] CWE-79 CVE-2021-38263: Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3
Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 20 and 7.2 before fix pack 10 allows remote attackers to inject arbitrary web script or HTML via the output of a script.
nvd
CVE-2021-33332P4MEDIUMCVSS 6.1v7.1v7.22021-08-03
CVE-2021-33332 [MEDIUM] CWE-79 CVE-2021-33332: Cross-site scripting (XSS) vulnerability in the Portlet Configuration module in Liferay Portal 7.1.0
Cross-site scripting (XSS) vulnerability in the Portlet Configuration module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portlet_configuration_css_web_portlet_PortletConfigurationCSSPortlet_portletResource
nvd
CVE-2021-29051P4MEDIUMCVSS 6.1v7.1v7.1-fix_pack_1+29 more2021-05-17
CVE-2021-29051 [MEDIUM] CWE-79 CVE-2021-29051: Cross-site scripting (XSS) vulnerability in the Asset module's Asset Publisher app in Liferay Portal
Cross-site scripting (XSS) vulnerability in the Asset module's Asset Publisher app in Liferay Portal 7.2.1 through 7.3.5, and Liferay DXP 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANC
nvd
CVE-2021-29044P4MEDIUMCVSS 6.1v7.0v7.0-fix_pack_13+94 more2021-05-17
CVE-2021-29044 [MEDIUM] CWE-79 CVE-2021-29044: Cross-site scripting (XSS) vulnerability in the Site module's membership request administration page
Cross-site scripting (XSS) vulnerability in the Site module's membership request administration pages in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_site_my_sites_
nvd
CVE-2022-26596P4MEDIUMCVSS 6.1v7.0v7.0-fix_pack_1+111 more2022-04-25
CVE-2022-26596 [MEDIUM] CWE-79 CVE-2022-26596: Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page
Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.1.0 through 7.3.3, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 8, allows remote attackers to inject arbitrary web script or HTML via web content template names.
nvd
CVE-2022-42110P4MEDIUMCVSS 6.1v7.1v7.22022-11-15
CVE-2022-42110 [MEDIUM] CWE-79 CVE-2022-42110: A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 throu
A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML.
nvd
CVE-2023-33938P4MEDIUMCVSS 6.1v7.32023-05-24
CVE-2023-33938 [MEDIUM] CWE-79 CVE-2023-33938: Cross-site scripting (XSS) vulnerability in the App Builder module's custom object details page in L
Cross-site scripting (XSS) vulnerability in the App Builder module's custom object details page in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before update 14 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an App Builder custom object's `Name` field.
nvd
CVE-2023-33941P4MEDIUMCVSS 6.1v7.42023-05-24
CVE-2023-33941 [MEDIUM] CWE-79 CVE-2023-33941: Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2Provi
Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.52, and Liferay DXP 7.4 update 41 through 52 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter.
nvd
CVE-2023-44311P4MEDIUMCVSS 6.1v7.42023-10-17
CVE-2023-44311 [MEDIUM] CVE-2023-44311: Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's O
Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.89, and Liferay DXP 7.4 update 41 through update 89 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter. This issue is caused by
nvd
CVE-2023-42497P4MEDIUMCVSS 6.1v7.42023-10-17
CVE-2023-42497 [MEDIUM] CWE-79 CVE-2023-42497: Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Por
Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through 7.4.3.85, and Liferay DXP 7.4 before update 86 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_translation_web_internal_portlet_TranslationPortlet_redirect` parameter.
nvd
CVE-2023-44308P4MEDIUMCVSS 6.1v7.4v2023.q3.0+5 more2024-02-20
CVE-2023-44308 [MEDIUM] CWE-601 CVE-2023-44308: Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patc
Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_adaptive_media_web_portlet_AMPortlet_redirect parameter.
nvd
CVE-2024-11993P4MEDIUMCVSS 6.1≥ 7.1, < 7.4v7.42024-12-17
CVE-2024-11993 [MEDIUM] CWE-79 CVE-2024-11993: Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Lif
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field
nvd
CVE-2020-15840P4MEDIUMCVSS 5.3v7.0v7.1+1 more2020-09-24
CVE-2020-15840 [MEDIUM] CVE-2020-15840: In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the
In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id.banned.paths.regexp' can be bypassed with doubled encoded URLs.
nvd