cbcvebase.

Liferay Digital Experience Platform vulnerabilities

264 known vulnerabilities affecting liferay/digital_experience_platform.

Total CVEs
264
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH35MEDIUM224LOW2

Vulnerabilities

Page 9 of 14
CVE-2025-43779P4MEDIUMCVSS 6.1≥ 2024.Q1.1, < 2024.Q1.19v7.42025-09-24
CVE-2025-43779 [MEDIUM] CWE-79 CVE-2025-43779: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 allows a remote authenticated attacker to inject JavaScript code via _com_liferay_commerce_product_definitions_web_internal_portlet_CPDefinitionsPortlet_productTypeName parameter.
nvd
CVE-2025-43817P4MEDIUMCVSS 6.1≥ 2023.q3.1, < 2023.q3.9≥ 2023.Q4.0, < 2023.Q4.7+1 more2025-09-29
CVE-2025-43817 [MEDIUM] CWE-79 CVE-2025-43817: Multiple reflected cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.74 through 7.4 Multiple reflected cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.74 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.6, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 74 through update 92 allow remote attackers to inject arbitrary web script or HTML via the `redirect` parameter to (1) Announcements, or (2) Alerts.
nvd
CVE-2021-29040P4MEDIUMCVSS 5.3fixed in 7.0v7.0+95 more2021-05-16
CVE-2021-29040 [MEDIUM] CWE-209 CVE-2021-29040: The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7 The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 20 and 7.2 before fix pack 10 may provide overly verbose error messages, which allows remote attackers to use the contents of error messages to help launch another, more focused attacks via crafted inputs.
nvd
CVE-2024-25602P4MEDIUMCVSS 5.4fixed in 7.2v7.2+1 more2024-02-21
CVE-2024-25602 [MEDIUM] CWE-79 CVE-2024-25602: Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Po Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload i
nvd
CVE-2024-26266P4MEDIUMCVSS 5.4fixed in 7.2v7.2+2 more2024-02-21
CVE-2024-26266 [MEDIUM] CWE-79 CVE-2024-26266: Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupported versions, and Liferay DXP 7.4 before update 10, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allow remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected in
nvd
CVE-2024-25601P4MEDIUMCVSS 5.4fixed in 7.2v7.2+1 more2024-02-21
CVE-2024-25601 [MEDIUM] CWE-79 CVE-2024-25601: Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Lif Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via a crafted pa
nvd
CVE-2024-25152P4MEDIUMCVSS 5.4fixed in 7.2v7.2+1 more2024-02-21
CVE-2024-25152 [MEDIUM] CWE-79 CVE-2024-25152: Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 thro Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via the filename of an attachment.
nvd
CVE-2024-25603P4MEDIUMCVSS 5.4fixed in 7.2v7.2+2 more2024-02-21
CVE-2024-25603 [MEDIUM] CWE-79 CVE-2024-25603: Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Life Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via the insta
nvd
CVE-2024-25151P4MEDIUMCVSS 5.4fixed in 7.2v7.2+1 more2024-02-21
CVE-2024-25151 [MEDIUM] CWE-79 CVE-2024-25151: The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Lifer The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not escape user supplied data in the default notification email template, which allows remote authenticated users to inject arbitrary web script or HTML via t
nvd
CVE-2023-44310P4MEDIUMCVSS 5.4v7.1v7.42023-10-17
CVE-2023-44310 [MEDIUM] CWE-79 CVE-2023-44310: Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3 Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP 7.3 fix pack 1 through update 23, and 7.4 before update 79 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into page's "Name" text field.
nvd
CVE-2023-33937P4MEDIUMCVSS 5.4v7.1v7.22023-05-24
CVE-2023-33937 [MEDIUM] CWE-79 CVE-2023-33937: Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal 7.1.0 Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal 7.1.0 through 7.3.0, and Liferay DXP 7.1 before fix pack 18, and 7.2 before fix pack 5 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a form's `name` field.
nvd
CVE-2022-42127P4MEDIUMCVSS 5.3v7.4-update1v7.4-update362022-11-15
CVE-2022-42127 [MEDIUM] CWE-276 CVE-2022-42127: The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 tho The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check user permissions, which allows remote attackers to obtain the history of all friendly URLs that was assigned to a page.
nvd
CVE-2025-43760P4MEDIUMCVSS 5.4≥ 2024.Q1.1, ≤ 2024.Q1.20≥ 2024.q2.0, ≤ 2024.q2.13+4 more2025-08-22
CVE-2025-43760 [MEDIUM] CWE-79 CVE-2025-43760: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.6, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20 and 7.4 GA through update 92 allows an remote authenticated attacker to inject JavaScript
nvd
CVE-2025-3760P4MEDIUMCVSS 5.4≥ 7.2, ≤ 7.4≥ 2023.Q3.0, < 2024.Q1.13+2 more2025-04-17
CVE-2025-3760 [MEDIUM] CWE-79 CVE-2025-3760: A stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Lif A stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Liferay Portal 7.2.0 through 7.4.3.129, and Liferay DXP 2024.Q4.1 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 9
nvd
CVE-2025-43746P4MEDIUMCVSS 5.4≥ 2024.Q1.1, < 2024.Q1.19≥ 2024.q2.0, ≤ 2024.q2.13+5 more2025-08-20
CVE-2025-43746 [MEDIUM] CWE-79 CVE-2025-43746: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.2, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 allows a remote authenticated a
nvd
CVE-2025-43757P4MEDIUMCVSS 5.4≥ 2024.Q1.1, < 2024.Q1.19≥ 2024.Q2.1, ≤ 2024.Q2.13+5 more2025-08-20
CVE-2025-43757 [MEDIUM] CWE-79 CVE-2025-43757: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.2, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 allows a remote authenticated a
nvd
CVE-2025-43731P4MEDIUMCVSS 5.4≥ 2024.Q1.1, < 2024.Q1.17≥ 2024.q2.0, ≤ 2024.q2.13+4 more2025-08-18
CVE-2025-43731 [MEDIUM] CWE-79 CVE-2025-43731: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.8, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.16 and 7.4 GA through update 92 allows an remote authenticated user to inject JavaScript in m
nvd
CVE-2025-43734P4MEDIUMCVSS 5.4≥ 2024.q1.1, ≤ 2024.q1.16≥ 2024.Q2.1, ≤ 2024.Q2.13+4 more2025-08-12
CVE-2025-43734 [MEDIUM] CWE-79 CVE-2025-43734: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.16 and 7.4 GA through update 92 allows a remote authenticated attacker to inject JavaScript
nvd
CVE-2025-43741P4MEDIUMCVSS 5.4≥ 2024.Q1.1, < 2024.Q1.15≥ 2024.q2.0, ≤ 2024.q2.13+4 more2025-08-20
CVE-2025-43741 [MEDIUM] CWE-79 CVE-2025-43741: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.3, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows an remote authenticated attacker to inject JavaScrip i
nvd
CVE-2025-43738P4MEDIUMCVSS 5.4≥ 2024.q1.1, < 2024.q1.20≥ 2024.Q2.1, ≤ 2024.Q2.13+4 more2025-08-19
CVE-2025-43738 [MEDIUM] CWE-79 CVE-2025-43738: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.19 allows a remote authenticated user to inject JavaScript c
nvd