cbcvebase.

Liferay Digital Experience Platform vulnerabilities

264 known vulnerabilities affecting liferay/digital_experience_platform.

Total CVEs
264
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH35MEDIUM224LOW2

Vulnerabilities

Page 3 of 14
CVE-2022-42124P3HIGHCVSS 7.5v7.2-fix_pack_10v7.2-fix_pack_11+8 more2022-11-15
CVE-2022-42124 [HIGH] CWE-1333 CVE-2022-42124: ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 through 7.4.3.4 ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 through 7.4.3.4 and Liferay DXP 7.2 fix pack 9 through fix pack 18, 7.3 before update 4, and DXP 7.4 GA allows remote attackers to consume an excessive amount of server resources via a crafted payload injected into the 'name' field of a layout prototype.
nvd
CVE-2022-42123P3HIGHCVSS 7.5v7.3v7.42022-11-15
CVE-2022-42123 [HIGH] CWE-22 CVE-2022-42123: A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, an A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin.
nvd
CVE-2025-3602P3HIGHCVSS 7.5≥ 2023.q3.1, ≤ 2023.q3.2v7.2+2 more2025-06-16
CVE-2025-3602 [HIGH] CWE-400 CVE-2025-3602: Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through u Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through update 35, and 7.2 fix pack 8 through fix pack 20 does not limit the depth of a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing complex queries.
nvd
CVE-2025-43796P3HIGHCVSS 7.5≥ 2023.Q3.0, < 2023.Q3.5v7.3+1 more2025-09-12
CVE-2025-43796 [HIGH] CWE-400 CVE-2025-43796: Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA though update 35 does not limit the number of objects returned from a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing queries that return a large number of obj
nvd
CVE-2022-42125P3HIGHCVSS 7.5v7.4-update1v7.4-update342022-11-15
CVE-2022-42125 [HIGH] CWE-22 CVE-2022-42125: Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows attackers to create or overwrite existing files on the filesystem via the deployment of a malicious plugin/module.
nvd
CVE-2025-43750P3MEDIUMCVSS 6.5≥ 2024.Q1.1, < 2024.Q1.15≥ 2024.q2.0, ≤ 2024.q2.12+4 more2025-08-20
CVE-2025-43750 [MEDIUM] CWE-434 CVE-2025-43750: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 throu Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows remote unauthenticated users (guests) to upload files via the form attachment field without proper validation, e
nvd
CVE-2025-43825P3MEDIUMCVSS 6.5≥ 2023.Q3.1, ≤ 2023.Q3.10≥ 2023.q4.0, ≤ 2023.q4.10+6 more2025-10-03
CVE-2025-43825 [MEDIUM] CWE-201 CVE-2025-43825: A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1 A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows sensitive user data to be includ
nvd
CVE-2025-62247P3MEDIUMCVSS 6.5≥ 2024.q1.1, < 2024.q1.20≥ 2024.q2.0, ≤ 2024.q2.13+2 more2025-10-22
CVE-2025-62247 [MEDIUM] CWE-862 CVE-2025-62247: Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132 Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 allows instance users to read and select unauthorized Bl
nvd
CVE-2025-62258P3MEDIUMCVSS 6.5v7.3v7.4+4 more2025-10-27
CVE-2025-62258 [MEDIUM] CWE-352 CVE-2025-62258: CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to execute any Headless API via the `endpoint` parameter.
nvd
CVE-2025-43763P3MEDIUMCVSS 6.5≥ 2024.q1.1, < 2024.q1.21≥ 2024.q2.0, ≤ 2024.q2.13+2 more2025-09-09
CVE-2025-43763 [MEDIUM] CWE-918 CVE-2025-43763: A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3. A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20 that affects custom object attachment fields. This flaw allows an attacker to manipulate the application into m
nvd
CVE-2024-26265P3MEDIUMCVSS 6.5fixed in 7.2v7.2+2 more2024-02-20
CVE-2024-26265 [MEDIUM] CWE-770 CVE-2024-26265: The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions relies on a request parameter to limit the size of files that can be uploaded, which allows remote authenticated users to upload arbitrari
nvd
CVE-2024-25604P3MEDIUMCVSS 6.5fixed in 7.2v7.2+2 more2024-02-20
CVE-2024-25604 [MEDIUM] CWE-863 CVE-2024-25604: Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 be Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions does not properly check user permissions, which allows remote authenticated users with the VIEW user permission to edit their own permission via the User and Organizations sec
nvd
CVE-2025-43752P3MEDIUMCVSS 6.5≥ 2024.Q1.1, < 2024.Q1.16≥ 2024.q2.0, ≤ 2024.q2.13+4 more2025-08-22
CVE-2025-43752 [MEDIUM] CWE-770 CVE-2025-43752: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 throu Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allow users to upload an unlimited amount of files through the object entries attachment fields, the files are stored i
nvd
CVE-2025-62251P3MEDIUMCVSS 6.5≤ 7.4≥ 2023.q3.1, < 2023.q3.9+1 more2025-10-13
CVE-2025-62251 [MEDIUM] CWE-732 CVE-2025-62251: Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 throu Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA through update 92 and 7.3 GA though update 36 shows content to users who do not have permission to view it via the Menu Display Widget. This security flaw could result in sensitive information being exposed to unauthorized users.
nvd
CVE-2025-43784P3MEDIUMCVSS 6.5≥ 2024.Q1.1, < 2024.Q1.13≥ 2024.Q2.0, < 2024.Q2.9+1 more2025-09-10
CVE-2025-43784 [MEDIUM] CWE-863 CVE-2025-43784: Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 20 Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.8, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows guest users to obtain object entries information via the API Builder.
nvd
CVE-2025-43747P3MEDIUMCVSS 6.5≥ 2025.Q2.0, < 2025.Q2.42025-08-21
CVE-2025-43747 [MEDIUM] CWE-918 CVE-2025-43747: A server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025. A server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025.Q2.3 due to insecure domain validation on analytics.cloud.domain.allowed, allowing an attacker to perform requests by change the domain and bypassing the validation method, this insecure validation is not distinguishing between trusted subdomains and
nvd
CVE-2021-38268P3MEDIUMCVSS 6.5fixed in 7.2.1v7.2-fix_pack_1+10 more2022-03-02
CVE-2021-38268 [MEDIUM] CWE-276 CVE-2021-38268: The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fi The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 2 incorrectly sets default permissions for site members, which allows remote authenticated users with the site member role to add and duplicate forms, via the UI or the
nvd
CVE-2025-43762P3MEDIUMCVSS 6.5≥ 2024.Q1.1, < 2024.Q1.15≥ 2024.q2.0, ≤ 2024.q2.13+4 more2025-08-22
CVE-2025-43762 [MEDIUM] CWE-770 CVE-2025-43762: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 throu Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allow users to upload an unlimited amount of files through the forms, the files are stored in the document_library allo
nvd
CVE-2021-33333P3MEDIUMCVSS 6.3v7.0v7.1+1 more2021-08-03
CVE-2021-33333 [MEDIUM] CWE-276 CVE-2021-33333: The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19 and 7.2 before fix pack 6, does not properly check user permission, which allows remote authenticated users to view and delete workflow submissions via crafted URLs.
nvd
CVE-2025-43819P3MEDIUMCVSS 6.5≥ 2024.Q1.1, < 2024.Q1.13≥ 2024.q2.0, ≤ 2024.q2.13+3 more2025-09-24
CVE-2025-43819 [MEDIUM] CWE-613 CVE-2025-43819: A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, a A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, and 2024.Q1.1 through 2024.Q1.12 is allow an remote non-authenticated attacker to reuse old user session by SLO API
nvd