cbcvebase.

Liferay Digital Experience Platform vulnerabilities

264 known vulnerabilities affecting liferay/digital_experience_platform.

Total CVEs
264
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH35MEDIUM224LOW2

Vulnerabilities

Page 4 of 14
CVE-2025-43798P3MEDIUMCVSS 6.5≥ 2023.q3.1, < 2023.q3.5v7.3+2 more2025-09-15
CVE-2025-43798 [MEDIUM] CWE-304 CVE-2025-43798: Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through upda Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time password (TOTP) to be used multiple times during the validity period, which allows attackers with access to a user’s TOTP to authenticate as the user.
nvd
CVE-2025-43764P4MEDIUMCVSS 6.5≥ 2024.Q1.1, ≤ 2024.Q1.20≥ 2024.q2.0, ≤ 2024.q2.13+3 more2025-08-23
CVE-2025-43764 [MEDIUM] CWE-1333 CVE-2025-43764: Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Design Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScript in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.1, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20 and 7.4 GA through update 92, which allows authenti
nvd
CVE-2022-45320P3MEDIUMCVSS 6.3fixed in 7.2v7.2+2 more2024-02-20
CVE-2022-45320 [MEDIUM] CWE-284 CVE-2022-45320: Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users to become the owner of a wiki page by editing the wiki page.
nvd
CVE-2025-62257P4MEDIUMCVSS 5.3≤ 7.4v2023.q3.0+6 more2025-10-30
CVE-2025-62257 [MEDIUM] CWE-307 CVE-2025-62257: Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote attackers to determine a user’s password even if account lockout i
nvd
CVE-2020-15839P4MEDIUMCVSS 6.5v7.1v7.22020-09-22
CVE-2020-15839 [MEDIUM] CWE-434 CVE-2020-15839: Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.
nvd
CVE-2025-62259P3MEDIUMCVSS 5.4≤ 7.0v7.1+7 more2025-10-27
CVE-2025-62259 [MEDIUM] CWE-863 CVE-2025-62259: Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 th Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has verified their email address, which allows remote users to access and edit content via the API.
nvd
CVE-2025-62256P4MEDIUMCVSS 5.3v7.3v7.4+13 more2025-10-23
CVE-2025-62256 [MEDIUM] CWE-862 CVE-2025-62256: Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 throu Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not properly restrict access to OpenAPI in certain circumstances, which allows remote attackers to access the OpenAPI YAML file via a crafted URL.
nvd
CVE-2024-25144P4MEDIUMCVSS 6.5v7.22024-02-08
CVE-2024-25144 [MEDIUM] CWE-835 CVE-2024-25144: The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Life The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 6, 7.2 before fix pack 19, and older unsupported versions does not check the URL of the IFrame, which allows remote authenticated users to cause a denial-of-service (DoS) via a self referencing IFrame.
nvd
CVE-2025-43745P4MEDIUMCVSS 6.5≥ 2024.q1.1, < 2024.q1.20≥ 2024.q2.0, ≤ 2024.q2.13+5 more2025-08-19
CVE-2025-43745 [MEDIUM] CWE-352 CVE-2025-43745: A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 20 A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 and 7.4 GA through update 92 allows remote attackers to performs cross-origin request on behal
nvd
CVE-2025-43792P4MEDIUMCVSS 5.3fixed in 7.3≥ 2023.q3.1, < 2023.q3.5+3 more2025-09-15
CVE-2025-43792 [MEDIUM] CWE-15 CVE-2025-43792: Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Lifera Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not properly obtain the remote address of the live site from the database which, which allows remote authenticated use
nvd
CVE-2024-25143P4MEDIUMCVSS 6.5fixed in 7.2v7.2+1 more2024-02-07
CVE-2024-25143 [MEDIUM] CWE-770 CVE-2024-25143: The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 13, and older unsupported versions, does not limit resource consumption when generating a preview image, which allows remote authenticated users to cause a denial of service (memory consu
nvd
CVE-2025-62266P4MEDIUMCVSS 6.1v7.3v7.4+13 more2025-10-30
CVE-2025-62266 [MEDIUM] CWE-601 CVE-2025-62266: By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions is vulnerable to DNS rebinding attacks, which allows remote attackers to redirect users to arbitrary exter
nvd
CVE-2025-62243P4MEDIUMCVSS 5.4≥ 2023.q3.1, < 2023.q3.9≥ 2023.q4.0, < 2023.q4.6+1 more2025-10-13
CVE-2025-62243 [MEDIUM] CWE-863 CVE-2025-62243: Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 throug Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticated attackers to view publication comments via the _com_liferay_change_tracking_web_portlet_PublicationsPortlet
nvd
CVE-2025-43808P4MEDIUMCVSS 5.3≥ 2023.Q3.1, ≤ 2023.Q3.10≥ 2023.Q4.0, < 2023.Q4.9+2 more2025-09-19
CVE-2025-43808 [MEDIUM] CWE-732 CVE-2025-43808: The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and 7.3 service pack 3 through update 35 saves virtual products uploaded to Documents and Media with guest view permission, which allows remote attackers to access and download virtual
nvd
CVE-2025-43758P4MEDIUMCVSS 5.3≥ 2024.Q1.1, < 2024.Q1.16≥ 2024.q2.0, ≤ 2024.q2.13+4 more2025-08-22
CVE-2025-43758 [MEDIUM] CWE-552 CVE-2025-43758: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 throu Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows unauthenticated users (guests) to access via URL files uploaded by object entry and stored in document_library
nvd
CVE-2025-62275P4MEDIUMCVSS 5.3v7.4v2023.q3.1+20 more2025-11-01
CVE-2025-62275 [MEDIUM] CWE-863 CVE-2025-62275: Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 202 Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions does not check permission of images in a blog entry, which allows remote attackers to view the images in a blog entry via crafted URL.
nvd
CVE-2025-43749P4MEDIUMCVSS 5.3≥ 2024.Q1.1, < 2024.Q1.15≥ 2024.q2.0, ≤ 2024.q2.13+4 more2025-08-20
CVE-2025-43749 [MEDIUM] CWE-552 CVE-2025-43749: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 throu Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows unauthenticated users (guests) to access via URL files uploaded in the form and stored in document_library
nvd
CVE-2024-25609P4MEDIUMCVSS 6.1fixed in 7.2v7.2+2 more2024-02-20
CVE-2024-25609 [MEDIUM] CVE-2024-25609: HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, an HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 service pack 3, 7.2 fix pack 15 through 18, and older unsupported versions can be circumvented by using two forward slashes, which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirec
nvd
CVE-2024-26268P4MEDIUMCVSS 5.3fixed in 7.2v7.2+2 more2024-02-20
CVE-2024-26268 [MEDIUM] CWE-203 CVE-2024-26268: User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versi User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 8, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to determine if an account exist in the application by comparing the request's response time.
nvd
CVE-2021-33338P4HIGHCVSS 7.5v7.1v7.22021-08-04
CVE-2021-33338 [HIGH] CWE-352 CVE-2021-33338: The Layout module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and The Layout module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 6, exposes the CSRF token in URLs, which allows man-in-the-middle attackers to obtain the token and conduct Cross-Site Request Forgery (CSRF) attacks via the p_auth parameter.
nvd
Liferay Digital Experience Platform vulnerabilities | cvebase