Liferay Dxp vulnerabilities
240 known vulnerabilities affecting liferay/dxp.
Total CVEs
240
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH30MEDIUM202LOW3
Vulnerabilities
Page 11 of 12
CVE-2021-29048P4MEDIUMCVSS 6.1v7.32021-05-17
CVE-2021-29048 [MEDIUM] CWE-79 CVE-2021-29048: Cross-site scripting (XSS) vulnerability in the Layout module's page administration page in Liferay
Cross-site scripting (XSS) vulnerability in the Layout module's page administration page in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.2 before fix pack 11 and 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_layout_admin_web_portlet_GroupPagesPortlet_name parameter.
nvd
CVE-2021-29046P4MEDIUMCVSS 6.1v7.32021-05-17
CVE-2021-29046 [MEDIUM] CWE-79 CVE-2021-29046: Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Life
Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_asset_categories_admin_web_portlet_AssetCategoriesAdminPortlet_title parameter.
nvd
CVE-2021-29045P4MEDIUMCVSS 6.1v7.32021-05-17
CVE-2021-29045 [MEDIUM] CWE-79 CVE-2021-29045: Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in
Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Liferay Portal 7.3.2 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_redirect_web_internal_portlet_RedirectPortlet_destinationURL parameter.
nvd
CVE-2021-29049P4MEDIUMCVSS 6.1v7.32021-06-09
CVE-2021-29049 [MEDIUM] CWE-79 CVE-2021-29049: Cross-site scripting (XSS) vulnerability in the Portal Workflow module's edit process page in Lifera
Cross-site scripting (XSS) vulnerability in the Portal Workflow module's edit process page in Liferay DXP 7.0 before fix pack 99, 7.1 before fix pack 23, 7.2 before fix pack 12 and 7.3 before fix pack 1, allows remote attackers to inject arbitrary web script or HTML via the currentURL parameter.
nvd
CVE-2022-42113P4MEDIUMCVSS 6.1v7.4-update_30v7.4-update_31+5 more2022-10-18
CVE-2022-42113 [MEDIUM] CWE-79 CVE-2022-42113: A Cross-site scripting (XSS) vulnerability in Document Library module in Liferay Portal 7.4.3.30 thr
A Cross-site scripting (XSS) vulnerability in Document Library module in Liferay Portal 7.4.3.30 through 7.4.3.36, and Liferay DXP 7.4 update 30 through update 36 allows remote attackers to inject arbitrary web script or HTML via the `redirect` parameter.
nvd
CVE-2022-28979P4MEDIUMCVSS 6.1v7.3v7.3-sp1+2 more2022-09-22
CVE-2022-28979 [MEDIUM] CWE-79 CVE-2022-28979: Liferay Portal v7.1.0 through v7.4.2 and Liferay DXP 7.1 before fix pack 26, 7.2 before fix pack 15,
Liferay Portal v7.1.0 through v7.4.2 and Liferay DXP 7.1 before fix pack 26, 7.2 before fix pack 15, and 7.3 before service pack 3 was discovered to contain a cross-site scripting (XSS) vulnerability in the Portal Search module's Custom Facet widget. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in
nvd
CVE-2022-38902P4MEDIUMCVSS 5.4v7.3v7.3-sp1+10 more2022-10-13
CVE-2022-38902 [MEDIUM] CWE-79 CVE-2022-38902: A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Lifer
A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic.
nvd
CVE-2023-33940P4MEDIUMCVSS 5.4≥ 7.4.13, ≤ 7.4.13.u302023-05-24
CVE-2023-33940 [MEDIUM] CWE-79 CVE-2023-33940: Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through
Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through 7.4.3.30, and Liferay DXP 7.4 before update 31 allows remote attackers to inject arbitrary web script or HTML via the Remote App's IFrame URL.
nvd
CVE-2022-42114P4MEDIUMCVSS 5.4fixed in 7.4v7.4-ga1+36 more2022-10-18
CVE-2022-42114 [MEDIUM] CWE-79 CVE-2022-42114: A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay
A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.4 before update 37 allows remote attackers to inject arbitrary web script or HTML.
nvd
CVE-2022-42112P4MEDIUMCVSS 5.4v7.3v7.3-sp1+31 more2022-10-18
CVE-2022-42112 [MEDIUM] CWE-79 CVE-2022-42112: A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Port
A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Portal 7.2.0 through 7.4.3.24, and Liferay DXP 7.2 before fix pack 19, 7.3 before update 5, and DXP 7.4 before update 25 allows remote attackers to inject arbitrary web script or HTML via a crafted payload.
nvd
CVE-2022-42119P4MEDIUMCVSS 5.4v7.3v7.3-update_1+6 more2022-11-15
CVE-2022-42119 [MEDIUM] CWE-79 CVE-2022-42119: Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
nvd
CVE-2023-47798P4MEDIUMCVSS 4.6≥ 7.2.10, ≤ 7.2.10-dxp-42024-02-08
CVE-2023-47798 [MEDIUM] CWE-384 CVE-2023-47798: Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay D
Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been locked.
nvd
CVE-2025-43743P4MEDIUMCVSS 4.3≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.15+4 more2025-08-19
CVE-2025-43743 [MEDIUM] CWE-203 CVE-2025-43743: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 throu
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows any authenticated remote user to view other calendars by allowing them to enumerate the names of other users, gi
nvd
CVE-2025-43827P4MEDIUMCVSS 4.3≥ 7.4.13, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.10+2 more2025-09-30
CVE-2025-43827 [MEDIUM] CWE-639 CVE-2025-43827: Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 thro
Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote authenticated users to from
nvd
CVE-2025-62241P4MEDIUMCVSS 4.3≥ 2023.Q4.0, ≤ 2023.Q4.52025-10-13
CVE-2025-62241 [MEDIUM] CWE-639 CVE-2025-62241: Insecure Direct Object Reference (IDOR) vulnerability with shipment addresses in Liferay DXP 2023.Q4
Insecure Direct Object Reference (IDOR) vulnerability with shipment addresses in Liferay DXP 2023.Q4.1 through 2023.Q4.5 allows remote authenticated users to from one virtual instance to view the shipment addresses of different virtual instance via the _com_liferay_commerce_order_web_internal_portlet_CommerceOrderPortlet_commerceOrderId parameter.
nvd
CVE-2025-62252P4MEDIUMCVSS 4.3≥ 7.4.13, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.10+1 more2025-10-13
CVE-2025-62252 [MEDIUM] CWE-639 CVE-2025-62252: Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and
Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote authenticated users in one virtual instance to assign an organization to a u
nvd
CVE-2025-43806P4MEDIUMCVSS 4.3≥ 7.4.13, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.10+1 more2025-09-22
CVE-2025-43806 [MEDIUM] CWE-863 CVE-2025-43806: Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7,
Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 does not properly check permission with import and export tasks, which allows remote authenticated users to access the exported data via the REST APIs.
nvd
CVE-2022-28982P4MEDIUMCVSS 6.1v7.3v7.3-sp1+2 more2022-09-22
CVE-2022-28982 [MEDIUM] CWE-79 CVE-2022-28982: A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v
A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v7.3 before service pack 3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name of a tag.
nvd
CVE-2022-28980P4MEDIUMCVSS 6.1v7.4-ga2022-09-22
CVE-2022-28980 [MEDIUM] CWE-79 CVE-2022-28980: Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal v7.4.3.4 and Liferay DXP v7.4
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal v7.4.3.4 and Liferay DXP v7.4 GA allows attackers to execute arbitrary web scripts or HTML via parameters with the filter_ prefix.
nvd
CVE-2025-62248P4MEDIUMCVSS 4.8≥ 2024.Q1.1, ≤ 2024.Q1.19≥ 2024.Q2.1, ≤ 2024.Q2.13+4 more2025-10-22
CVE-2025-62248 [MEDIUM] CWE-79 CVE-2025-62248: A reflected cross-site scripting (XSS) vulnerability, resulting from a regression, has been identif
A reflected cross-site scripting (XSS) vulnerability, resulting from a regression, has been identified in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 allows a remot
nvd