Liferay Digital Experience Platform vulnerabilities
264 known vulnerabilities affecting liferay/digital_experience_platform.
Total CVEs
264
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH35MEDIUM224LOW2
Vulnerabilities
Page 12 of 14
CVE-2022-28979P4MEDIUMCVSS 6.1v7.1v7.1-fix_pack_1+39 more2022-09-22
CVE-2022-28979 [MEDIUM] CWE-79 CVE-2022-28979: Liferay Portal v7.1.0 through v7.4.2 and Liferay DXP 7.1 before fix pack 26, 7.2 before fix pack 15,
Liferay Portal v7.1.0 through v7.4.2 and Liferay DXP 7.1 before fix pack 26, 7.2 before fix pack 15, and 7.3 before service pack 3 was discovered to contain a cross-site scripting (XSS) vulnerability in the Portal Search module's Custom Facet widget. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in
nvd
CVE-2021-33336P4MEDIUMCVSS 5.4v7.1v7.22021-08-04
CVE-2021-33336 [MEDIUM] CWE-79 CVE-2021-33336: Cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal
Cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal 7.3.0 through 7.3.3, and Liferay DXP 7.1 fix pack 18, and 7.2 fix pack 5 through 7, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_journal_web_portlet_JournalPortlet_name parameter.
nvd
CVE-2021-33328P4MEDIUMCVSS 5.4v7.0v7.1+1 more2021-08-03
CVE-2021-33328 [MEDIUM] CWE-79 CVE-2021-33328: Cross-site scripting (XSS) vulnerability in the Asset module's edit vocabulary page in Liferay Porta
Cross-site scripting (XSS) vulnerability in the Asset module's edit vocabulary page in Liferay Portal 7.0.0 through 7.3.4, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20, and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the (1) _com_liferay_journal_web_portlet_JournalPortlet_name or (2) _co
nvd
CVE-2021-38267P4MEDIUMCVSS 5.4fixed in 7.3v7.3+1 more2022-03-03
CVE-2021-38267 [MEDIUM] CWE-79 CVE-2021-38267: Cross-site scripting (XSS) vulnerability in the Blogs module's edit blog entry page in Liferay Porta
Cross-site scripting (XSS) vulnerability in the Blogs module's edit blog entry page in Liferay Portal 7.3.2 through 7.3.6, and Liferay DXP 7.3 before fix pack 2 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_blogs_web_portlet_BlogsAdminPortlet_title and _com_liferay_blogs_web_portlet_BlogsAdminPortlet_subtitle par
nvd
CVE-2021-38265P4MEDIUMCVSS 5.4≤ 7.32022-03-03
CVE-2021-38265 [MEDIUM] CWE-79 CVE-2021-38265: Cross-site scripting (XSS) vulnerability in the Asset module in Liferay Portal 7.3.4 through 7.3.6 a
Cross-site scripting (XSS) vulnerability in the Asset module in Liferay Portal 7.3.4 through 7.3.6 allow remote attackers to inject arbitrary web script or HTML when creating a collection page via the _com_liferay_asset_list_web_portlet_AssetListPortlet_title parameter.
nvd
CVE-2021-38269P4MEDIUMCVSS 5.4v7.1v7.1-fix_pack_1+37 more2022-03-03
CVE-2021-38269 [MEDIUM] CWE-79 CVE-2021-38269: Cross-site scripting (XSS) vulnerability in the Gogo Shell module in Liferay Portal 7.1.0 through 7.
Cross-site scripting (XSS) vulnerability in the Gogo Shell module in Liferay Portal 7.1.0 through 7.3.6 and 7.4.0, and Liferay DXP 7.1 before fix pack 23, 7.2 before fix pack 13, and 7.3 before fix pack 2 allows remote attackers to inject arbitrary web script or HTML via the output of a Gogo Shell command.
nvd
CVE-2022-26593P4MEDIUMCVSS 5.4fixed in 7.3v7.3+1 more2022-04-19
CVE-2022-26593 [MEDIUM] CWE-79 CVE-2022-26593: Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay
Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the name of a asset category.
nvd
CVE-2023-33940P4MEDIUMCVSS 5.4v7.42023-05-24
CVE-2023-33940 [MEDIUM] CWE-79 CVE-2023-33940: Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through
Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through 7.4.3.30, and Liferay DXP 7.4 before update 31 allows remote attackers to inject arbitrary web script or HTML via the Remote App's IFrame URL.
nvd
CVE-2022-42112P4MEDIUMCVSS 5.4fixed in 7.2v7.2+16 more2022-10-18
CVE-2022-42112 [MEDIUM] CWE-79 CVE-2022-42112: A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Port
A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Portal 7.2.0 through 7.4.3.24, and Liferay DXP 7.2 before fix pack 19, 7.3 before update 5, and DXP 7.4 before update 25 allows remote attackers to inject arbitrary web script or HTML via a crafted payload.
nvd
CVE-2023-47798P4MEDIUMCVSS 4.6fixed in 7.2v7.22024-02-08
CVE-2023-47798 [MEDIUM] CWE-384 CVE-2023-47798: Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay D
Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been locked.
nvd
CVE-2025-43743P4MEDIUMCVSS 4.3≥ 2024.Q1.1, < 2024.Q1.16≥ 2024.q2.0, ≤ 2024.q2.13+4 more2025-08-19
CVE-2025-43743 [MEDIUM] CWE-203 CVE-2025-43743: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 throu
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows any authenticated remote user to view other calendars by allowing them to enumerate the names of other users, gi
nvd
CVE-2025-43827P4MEDIUMCVSS 4.3≤ 7.3≥ 2023.Q3.1, ≤ 2023.Q3.10+3 more2025-09-30
CVE-2025-43827 [MEDIUM] CWE-639 CVE-2025-43827: Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 thro
Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote authenticated users to from
nvd
CVE-2025-62241P4MEDIUMCVSS 4.3v2023.q4.1v2023.q4.2+3 more2025-10-13
CVE-2025-62241 [MEDIUM] CWE-639 CVE-2025-62241: Insecure Direct Object Reference (IDOR) vulnerability with shipment addresses in Liferay DXP 2023.Q4
Insecure Direct Object Reference (IDOR) vulnerability with shipment addresses in Liferay DXP 2023.Q4.1 through 2023.Q4.5 allows remote authenticated users to from one virtual instance to view the shipment addresses of different virtual instance via the _com_liferay_commerce_order_web_internal_portlet_CommerceOrderPortlet_commerceOrderId parameter.
nvd
CVE-2025-62252P4MEDIUMCVSS 4.3≤ 7.4≥ 2023.Q3.1, ≤ 2023.Q3.10+1 more2025-10-13
CVE-2025-62252 [MEDIUM] CWE-639 CVE-2025-62252: Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and
Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote authenticated users in one virtual instance to assign an organization to a u
nvd
CVE-2025-43806P4MEDIUMCVSS 4.3≥ 2023.Q3.1, ≤ 2023.Q3.10≥ 2023.Q4.0, < 2023.Q4.8+1 more2025-09-22
CVE-2025-43806 [MEDIUM] CWE-863 CVE-2025-43806: Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7,
Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 does not properly check permission with import and export tasks, which allows remote authenticated users to access the exported data via the REST APIs.
nvd
CVE-2025-62248P4MEDIUMCVSS 4.8≥ 2024.q1.1, < 2024.q1.20≥ 2024.q2.0, ≤ 2024.q2.13+2 more2025-10-22
CVE-2025-62248 [MEDIUM] CWE-79 CVE-2025-62248: A reflected cross-site scripting (XSS) vulnerability, resulting from a regression, has been identif
A reflected cross-site scripting (XSS) vulnerability, resulting from a regression, has been identified in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 allows a remot
nvd
CVE-2025-43794P4MEDIUMCVSS 4.8fixed in 7.3≥ 2023.q3.1, < 2023.q3.5+3 more2025-09-15
CVE-2025-43794 [MEDIUM] CWE-79 CVE-2025-43794: Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older
Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote authenticated attackers with the instance administrator role to inject arbit
nvd
CVE-2021-33327P4MEDIUMCVSS 4.3v7.0v7.1+1 more2021-08-03
CVE-2021-33327 [MEDIUM] CWE-276 CVE-2021-33327: The Portlet Configuration module in Liferay Portal 7.2.0 through 7.3.3, and Liferay DXP 7.0 fix pack
The Portlet Configuration module in Liferay Portal 7.2.0 through 7.3.3, and Liferay DXP 7.0 fix pack pack 93 and 94, 7.1 fix pack 18, and 7.2 before fix pack 8, does not properly check user permission, which allows remote authenticated users to view the Guest and User role even if "Role Visibility" is enabled.
nvd
CVE-2021-33334P4MEDIUMCVSS 4.3v7.0v7.1+1 more2021-08-03
CVE-2021-33334 [MEDIUM] CWE-276 CVE-2021-33334: The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.2, and Liferay DXP 7.0 before fi
The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.2, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 6, does not properly check user permissions, which allows remote attackers with the forms "Access in Site Administration" permission to view all forms and form entries in a site via the forms
nvd
CVE-2022-42126P4MEDIUMCVSS 4.3v7.3v7.4+1 more2022-11-15
CVE-2022-42126 [MEDIUM] CWE-284 CVE-2022-42126: The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before upda
The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset libraries via the UI.
nvd