cbcvebase.

Liferay Digital Experience Platform vulnerabilities

264 known vulnerabilities affecting liferay/digital_experience_platform.

Total CVEs
264
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH35MEDIUM224LOW2

Vulnerabilities

Page 6 of 14
CVE-2024-26270P4MEDIUMCVSS 5.3v7.4v2023.q3.0+4 more2024-02-20
CVE-2024-26270 [MEDIUM] CWE-201 CVE-2024-26270: The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 befor The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 76 through 92 embeds the user’s hashed password in the page’s HTML source, which allows man-in-the-middle attackers to steal a user's hashed password.
nvd
CVE-2025-43754P4MEDIUMCVSS 5.3≥ 2024.Q1.1, < 2024.Q1.15≥ 2024.q2.0, ≤ 2024.q2.13+3 more2025-08-21
CVE-2025-43754 [MEDIUM] CWE-208 CVE-2025-43754: Username enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q Username enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows attackers to determine if an account exist in the application by inspecting the server processing time
nvd
CVE-2025-43789P4MEDIUMCVSS 5.3≥ 2024.Q1.1, < 2024.Q1.10v7.42025-09-12
CVE-2025-43789 [MEDIUM] CWE-863 CVE-2025-43789: JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024. JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.9, 7.4 GA through update 92 published to OSGi are registered and invoked directly as classes which allows Service Access Policies get executed.
nvd
CVE-2023-42628P4MEDIUMCVSS 5.4v7.0v7.1+3 more2023-10-17
CVE-2023-42628 [MEDIUM] CWE-79 CVE-2023-42628: Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7 Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay DXP 7.0 fix pack 83 through 102, 7.1 fix pack 28 and earlier, 7.2 fix pack 20 and earlier, 7.3 update 33 and earlier, and 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML into a parent wiki page v
nvd
CVE-2023-42629P4MEDIUMCVSS 5.4v7.42023-10-17
CVE-2023-42629 [MEDIUM] CWE-79 CVE-2023-42629: Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4. Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Vocabulary's 'description' text field.
nvd
CVE-2025-43802P4MEDIUMCVSS 6.1≥ 2023.q3.1, < 2023.q3.5v7.3+1 more2025-09-15
CVE-2025-43802 [MEDIUM] CWE-79 CVE-2025-43802: Stored cross-site scripting (XSS) vulnerability in a custom object’s /o/c/<object-name> API endpoint Stored cross-site scripting (XSS) vulnerability in a custom object’s /o/c/ API endpoint in Liferay Portal 7.4.3.51 through 7.4.3.109, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 update 51 through update 92, and 7.3 update 33 through update 35. allows remote attackers to inject arbitrary web script or HTML via the externalReferenceCode parameter.
nvd
CVE-2025-43769P4MEDIUMCVSS 6.1≥ 2024.Q1.1, < 2024.Q1.13≥ 2024.q2.0, ≤ 2024.q2.13+2 more2025-08-23
CVE-2025-43769 [MEDIUM] CWE-79 CVE-2025-43769: Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.131, and Lifer Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.8, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows remote attackers to execute arbitrary web script or HTML via components tab.
nvd
CVE-2025-62267P4MEDIUMCVSS 6.1v7.4v2023.q3.1+20 more2025-10-31
CVE-2025-62267 [MEDIUM] CWE-79 CVE-2025-62267: Multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page Multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 35 through update 92 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a
nvd
CVE-2025-43778P4MEDIUMCVSS 6.1≥ 2024.q1.1, < 2024.q1.21≥ 2024.q2.0, ≤ 2024.q2.13+4 more2025-09-09
CVE-2025-43778 [MEDIUM] CWE-79 CVE-2025-43778: A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Life A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.11, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20 allows an remote authenticated attacker to inject JavaScript thro
nvd
CVE-2025-43818P4MEDIUMCVSS 6.1≥ 2023.Q3.1, < 2023.Q3.7≥ 2023.Q4.0, < 2023.Q4.5+2 more2025-09-29
CVE-2025-43818 [MEDIUM] CWE-79 CVE-2025-43818: Cross-site scripting (XSS) vulnerability in the Calendar widget in Liferay Portal 7.4.3.35 through 7 Cross-site scripting (XSS) vulnerability in the Calendar widget in Liferay Portal 7.4.3.35 through 7.4.3.110, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.6, 7.4 update 35 through update 92, and 7.3 update 25 through update 36 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into
nvd
CVE-2025-62255P4MEDIUMCVSS 6.1fixed in 7.3v7.3+6 more2025-10-23
CVE-2025-62255 [MEDIUM] CWE-79 CVE-2025-62255: Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Por Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Portal 7.4.0 through 7.4.3.101, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via a crafted payload inje
nvd
CVE-2025-43765P4MEDIUMCVSS 6.1≥ 2024.Q1.1, < 2024.Q1.14≥ 2024.q2.0, ≤ 2024.q2.13+3 more2025-08-23
CVE-2025-43765 [MEDIUM] CWE-79 CVE-2025-43765: A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Lifer A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.13 and 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the text field from a web content.
nvd
CVE-2025-43767P4MEDIUMCVSS 6.1≥ 2024.Q1.1, < 2024.Q1.13≥ 2024.q2.0, ≤ 2024.q2.13+2 more2025-08-23
CVE-2025-43767 [MEDIUM] CWE-601 CVE-2025-43767: Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.8 Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.86 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 update 86 through update 92 allows an attacker to exploit this security vulnerability to redirect users to a malicious
nvd
CVE-2025-4599P4MEDIUMCVSS 6.1≥ 2024.q1.1, ≤ 2024.q1.13≥ 2024.q2.0, ≤ 2024.q2.13+3 more2025-08-04
CVE-2025-4599 [MEDIUM] CWE-79 CVE-2025-4599: The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP 202 The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP 2024.Q4.1 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.13 and 7.4 update 61 through update 92 was found to be vulnerable to postMessage-based XSS because it allows a remote non-authenticated attack
nvd
CVE-2025-62246P4MEDIUMCVSS 5.4≤ 7.4≥ 2023.q3.1, < 2023.q3.9+1 more2025-10-13
CVE-2025-62246 [MEDIUM] CWE-79 CVE-2025-62246: Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.0 through 7.4.3.111 Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions allow remote authenticated users to inject arbitrary web script or HTML via a crafted p
nvd
CVE-2025-62237P4MEDIUMCVSS 5.4≥ 2023.q3.1, < 2023.q3.9≥ 2023.q4.0, < 2023.q4.6+1 more2025-10-10
CVE-2025-62237 [MEDIUM] CWE-79 CVE-2025-62237: Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4. Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 8 through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account’s “Name” t
nvd
CVE-2025-43829P4MEDIUMCVSS 5.4≥ 2023.q3.1, < 2023.q3.9≥ 2023.q4.0, < 2023.q4.6+2 more2025-10-08
CVE-2025-43829 [MEDIUM] CWE-79 CVE-2025-43829: Stored cross-site scripting (XSS) vulnerability in diagram type products in Commerce in Liferay Port Stored cross-site scripting (XSS) vulnerability in diagram type products in Commerce in Liferay Portal 7.4.3.18 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 18 through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a SVG file.
nvd
CVE-2025-43826P4MEDIUMCVSS 5.4≤ 7.4≥ 2023.Q3.1, ≤ 2023.Q3.10+2 more2025-09-30
CVE-2025-43826 [MEDIUM] CWE-79 CVE-2025-43826: Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allow remote attackers to inject arbitrary web script or HTML via an
nvd
CVE-2025-62265P4MEDIUMCVSS 5.4≤ 7.4v2023.q3.1+18 more2025-10-30
CVE-2025-62265 [MEDIUM] CWE-79 CVE-2025-62265: Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.1 Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, 7.3 GA through update 36, and older unsupported versions allows remote attackers to inject arbitrary web script or
nvd
CVE-2025-43776P4MEDIUMCVSS 5.4≥ 2024.q1.1, < 2024.q1.20≥ 2024.q2.0, ≤ 2024.q2.13+5 more2025-09-09
CVE-2025-43776 [MEDIUM] CWE-209 CVE-2025-43776: A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Life A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 and 7.4 GA through update 92 allows an remote authenticated attacker
nvd
Liferay Digital Experience Platform vulnerabilities | cvebase