Liferay Dxp vulnerabilities
240 known vulnerabilities affecting liferay/dxp.
Total CVEs
240
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH30MEDIUM202LOW3
Vulnerabilities
Page 1 of 12
CVE-2024-25608P1MEDIUMCVSS 6.1ExploitedPoC≥ 7.4.13, ≤ 7.4.13.u18≥ 7.3.10, ≤ 7.3.10-dxp-3+1 more2024-02-20
CVE-2024-25608 [MEDIUM] CWE-601 CVE-2024-25608: HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, an
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be circumvented by using the 'REPLACEMENT CHARACTER' (U+FFFD), which allows remote attackers to redirect users to arbitrary external UR
nvd
CVE-2025-4581P1HIGHCVSS 8.6Exploited≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.15+4 more2025-08-09
CVE-2025-4581 [HIGH] CWE-918 CVE-2025-4581: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 throu
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 allows a pre-authentication blind SSRF vulnerability in the portal-settings-authentication-opensso-web due to improper validat
nvd
CVE-2025-3594P2CRITICALCVSS 9.8≥ 6.2.0, ≤ portal-173≥ 7.0.10, ≤ de-102+3 more2025-06-16
CVE-2025-3594 [CRITICAL] CWE-22 CVE-2025-3594: Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.
Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 34, and older unsupported versions allows remote attackers to (1) add files to arbitrary locations on the server and (2) download and execute arbitrary files from the download server via
nvd
CVE-2025-43766P2CRITICALCVSS 9.8≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.12+3 more2025-08-23
CVE-2025-43766 [CRITICAL] CWE-434 CVE-2025-43766: The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13,
The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows the upload of unrestricted files in the style books component that are processed within the environment enabling arbitrary code execution by attackers.
nvd
CVE-2025-4388P3MEDIUMCVSS 6.1PoC≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.12+3 more2025-05-06
CVE-2025-4388 [MEDIUM] CWE-79 CVE-2025-4388: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131,
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the modules/apps/marketpl
nvd
CVE-2024-38002P3HIGHCVSS 8.8≥ 7.3.10, ≤ 7.3.10-u36≥ 7.4.13, ≤ 7.4.13-u92+2 more2024-10-22
CVE-2024-38002 [HIGH] CWE-862 CVE-2024-38002: The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through
The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does not properly check user permissions before updating a workflow definition, which allows remote authenticated users to modify workflow definitions and execu
nvd
CVE-2025-4576P3MEDIUMCVSS 6.1PoC≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.15+4 more2025-08-08
CVE-2025-4576 [MEDIUM] CWE-79 CVE-2025-4576: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133,
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript i
nvd
CVE-2021-29053P3HIGHCVSS 8.8v7.32021-05-17
CVE-2021-29053 [HIGH] CWE-89 CVE-2021-29053: Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1
Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1 allow remote authenticated users to execute arbitrary SQL commands via the classPKField parameter to (1) CommerceChannelRelFinder.countByC_C, or (2) CommerceChannelRelFinder.findByC_C.
nvd
CVE-2025-43773P3CRITICALCVSS 9.1≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.18+5 more2025-08-29
CVE-2025-43773 [CRITICAL] CWE-862 CVE-2025-43773: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 20
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 has a security vulnerability that allowing for improper access through the expandoTableLocalService.
nvd
CVE-2022-42121P3HIGHCVSS 8.8v7.3v7.3-sp1+2 more2022-11-15
CVE-2022-42121 [HIGH] CWE-89 CVE-2022-42121: A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Life
A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template's 'Name' field.
nvd
CVE-2022-42120P3CRITICALCVSS 9.8v7.3v7.42022-11-15
CVE-2022-42120 [CRITICAL] CWE-89 CVE-2022-42120: A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and L
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.
nvd
CVE-2022-42118P4MEDIUMCVSS 6.1PoCv7.3v7.3-sp1+1 more2022-11-15
CVE-2022-42118 [MEDIUM] CWE-79 CVE-2022-42118: A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 throu
A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the `tag` parameter.
nvd
CVE-2025-43813P3HIGHCVSS 8.2≥ 7.3.10, ≤ 7.3.10-u35≥ 7.4.13, ≤ 7.4.13-u92+2 more2025-09-29
CVE-2025-43813 [HIGH] CWE-22 CVE-2025-43813: Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.
Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.107, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to access arbitrar
nvd
CVE-2025-43790P3HIGHCVSS 8.1≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.12+1 more2025-09-11
CVE-2025-43790 [HIGH] CWE-639 CVE-2025-43790: Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and
Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.6, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows remote authenticated users to from one virtual instance to access, create, edit, relate data/object entries/definitions to an object in a differen
nvd
CVE-2022-42122P3CRITICALCVSS 9.8v7.3-fix_pack_22022-11-15
CVE-2022-42122 [CRITICAL] CWE-89 CVE-2022-42122: A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.
nvd
CVE-2025-3586P3HIGHCVSS 7.2≥ 7.4.13-u27, ≤ 7.4.13-u42≥ 2023.Q3.1, ≤ 2023.Q3.10+2 more2025-09-01
CVE-2025-3586 [HIGH] CWE-863 CVE-2025-3586: In Liferay Portal 7.4.3.27 through 7.4.3.42, and Liferay DXP 2024.Q1.1 through 2024.Q1.20, 2023.Q4.0
In Liferay Portal 7.4.3.27 through 7.4.3.42, and Liferay DXP 2024.Q1.1 through 2024.Q1.20, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 27 through update 42 (Liferay PaaS, and Liferay Self-Hosted), the Objects module does not restrict the use of Groovy scripts in Object actions for Admin Users. This allows remote authenticated
nvd
CVE-2023-33945P3HIGHCVSS 8.1≥ 7.3.10, ≤ 7.3.10.u5≥ 7.4.13, ≤ 7.4.13.u172023-05-24
CVE-2023-33945 [HIGH] CWE-89 CVE-2023-33945: SQL injection vulnerability in the upgrade process for SQL Server in Liferay Portal 7.3.1 through 7.
SQL injection vulnerability in the upgrade process for SQL Server in Liferay Portal 7.3.1 through 7.4.3.17, and Liferay DXP 7.3 before update 6, and 7.4 before update 18 allows attackers to execute arbitrary SQL commands via the name of a database table's primary key index. This vulnerability is only exploitable when chained with other attacks. To expl
nvd
CVE-2024-25148P3HIGHCVSS 8.1v7.3≥ 7.3.10, ≤ 7.3.10-dxp-2+1 more2024-02-08
CVE-2024-25148 [HIGH] CWE-201 CVE-2024-25148: In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before se
In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions the `doAsUserId` URL parameter may get leaked when creating linked content using the WYSIWYG editor and while impersonating a user. This may allow remote authenticated users to imperso
nvd
CVE-2021-33321P3HIGHCVSS 7.5fixed in 7.32021-08-03
CVE-2021-33321 [HIGH] CWE-640 CVE-2021-33321: Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, al
Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enumerate user email address via the forgot password functionality. The portal.property login.secure.forgot.password should be defaulted to true.
nvd
CVE-2025-43793P3HIGHCVSS 7.5≥ 7.3.10, ≤ 7.3.10-u35≥ 7.4.13, ≤ 7.4.13-u92+2 more2025-09-15
CVE-2025-43793 [HIGH] CWE-1284 CVE-2025-43793: Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2
Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions may incorrectly identify the subdomain of a domain name and create a supercookie, which allows remote attackers who control a website that sh
nvd
1 / 12Next →