Liferay Dxp vulnerabilities
240 known vulnerabilities affecting liferay/dxp.
Total CVEs
240
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH30MEDIUM202LOW3
Vulnerabilities
Page 2 of 12
CVE-2024-26271P3HIGHCVSS 8.8≥ 7.3.10-u32, ≤ 7.3.10-u35≥ 7.4.13-u75, ≤ 7.4.13-u92+2 more2024-10-22
CVE-2024-26271 [HIGH] CWE-352 CVE-2024-26271: Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75
Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 update 75 through update 92 and 7.3 update 32 through update 36 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute a
nvd
CVE-2023-33949P3HIGHCVSS 7.5fixed in 7.3.102023-05-24
CVE-2023-33949 [HIGH] CWE-1188 CVE-2023-33949: In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which allows remote attackers to create accounts using fake email addresses or email addresses which they don't control. The portal property `company.security.strangers.verify` should be set to true.
nvd
CVE-2024-25607P3HIGHCVSS 7.5≥ 7.4.13, ≤ 7.4.13.u15≥ 7.3.10, ≤ 7.3.10-dxp-3+1 more2024-02-20
CVE-2024-25607 [HIGH] CWE-916 CVE-2024-25607: The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15,
The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions defaults to a low work factor, which allows attackers to quickly crack password hashes.
nvd
CVE-2024-26272P3HIGHCVSS 8.8≥ 7.3.10, ≤ 7.3.10-u35≥ 7.4.13, ≤ 7.4.13-u92+2 more2024-10-22
CVE-2024-26272 [HIGH] CWE-352 CVE-2024-26272: Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 t
Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 GA through update 35 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrary code
nvd
CVE-2024-25606P3HIGHCVSS 8.7≥ 7.4.13, ≤ 7.4.13.u3≥ 7.3.10, ≤ 7.3.10.u11+1 more2024-02-20
CVE-2024-25606 [HIGH] CWE-611 CVE-2024-25606: XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Lifer
XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12, 7.2 before fix pack 20, and older unsupported versions allows attackers with permission to deploy widgets/portlets/extensions to obtain sensitive information or consume system resources via the Java2Wsdd
nvd
CVE-2023-33948P3HIGHCVSS 7.5v7.4.13.u672023-05-24
CVE-2023-33948 [HIGH] CWE-862 CVE-2023-33948: The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not l
The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Media files which can be downloaded from a Form, which allows remote attackers to download any file from Document and Media via a crafted URL.
nvd
CVE-2025-62254P3HIGHCVSS 7.5≥ 7.3.10, ≤ 7.3.10-u35≥ 7.4.13, ≤ 7.4.13-u92+2 more2025-10-23
CVE-2025-62254 [HIGH] CWE-22 CVE-2025-62254: The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Life
The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number or size of the files it will combine, which allows remote attackers to create v
nvd
CVE-2024-26273P3HIGHCVSS 8.8≥ 7.3.10-u29, ≤ 7.3.10-u35≥ 7.4.13, ≤ 7.4.13-u92+2 more2024-10-22
CVE-2024-26273 [HIGH] CWE-352 CVE-2024-26273: Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 t
Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 update 29 through update 35 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrar
nvd
CVE-2025-43768P3HIGHCVSS 7.7≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.15+3 more2025-08-23
CVE-2025-43768 [HIGH] CWE-201 CVE-2025-43768: Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 throu
Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows authenticated users without any permissions to access sensitive information of admin users using JSONWS APIs.
nvd
CVE-2025-43816P3HIGHCVSS 7.5≥ 7.4.13, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.10+2 more2025-09-25
CVE-2025-43816 [HIGH] CWE-401 CVE-2025-43816: A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119,
A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2024.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows an attacker to cause server unavailability (denial of
nvd
CVE-2021-29047P3HIGHCVSS 7.5fixed in 7.3v7.32021-05-16
CVE-2021-29047 [HIGH] CWE-287 CVE-2021-29047: The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack
The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly perform actions protected by a CAPTCHA challenge by reusing the same CAPTCHA answer.
nvd
CVE-2025-43801P3HIGHCVSS 7.5≥ 7.3.10, ≤ 7.3.10-u35≥ 7.4.13, ≤ 7.4.13-u92+2 more2025-09-16
CVE-2025-43801 [HIGH] CWE-606 CVE-2025-43801: Unchecked input for loop condition vulnerability in XML-RPC in Liferay Portal 7.4.0 through 7.4.3.11
Unchecked input for loop condition vulnerability in XML-RPC in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to perform a denial-of-service (DoS) attacks via a craf
nvd
CVE-2025-62250P3MEDIUMCVSS 6.5≥ 7.3.10, ≤ 7.3.10-u35≥ 7.4.13, ≤ 7.4.13-u92+2 more2025-10-21
CVE-2025-62250 [MEDIUM] CWE-346 CVE-2025-62250: Improper Authentication in Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, a
Improper Authentication in Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to send malicious data to the Liferay Portal 7.4.0 through 7.4.3.132, and older unsupport
nvd
CVE-2023-35030P3HIGHCVSS 8.8v7.4≥ 7.4.13.u70, ≤ 7.4.13.u762023-06-15
CVE-2023-35030 [HIGH] CWE-352 CVE-2023-35030: Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay
Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to execute arbitrary code in the scripting console via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.
nvd
CVE-2023-33950P3HIGHCVSS 7.5≥ 7.4.13.u48, ≤ 7.4.13.u762023-05-24
CVE-2023-33950 [HIGH] CWE-1333 CVE-2023-33950: Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through
Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions that are vulnerable to ReDoS attacks to be used as patterns, which allows remote attackers to consume an excessive amount of server resources via crafted request URLs.
nvd
CVE-2025-3526P3HIGHCVSS 7.5≥ 6.2.0, ≤ portal-173≥ 7.0.10, ≤ de-102+4 more2025-06-16
CVE-2025-3526 [HIGH] CWE-400 CVE-2025-3526: SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3
SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does not restrict the saving of request parameters in the HTTP session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP requests.
nvd
CVE-2025-62260P3HIGHCVSS 7.5≥ 7.3.10, ≤ 7.3.10-u35≥ 7.4.13, ≤ 7.4.13-u92+1 more2025-10-27
CVE-2025-62260 [HIGH] CWE-400 CVE-2025-62260: Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through u
Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number of objects returned from Headless API requests, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing a reque
nvd
CVE-2025-43814P3MEDIUMCVSS 6.5≥ 7.4.13, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.10+1 more2025-09-22
CVE-2025-43814 [MEDIUM] CWE-201 CVE-2025-43814: In Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0
In Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions the audit events records a user’s password reminder answer, which allows remote authenticated users to obtain a user’s password reminder answer
nvd
CVE-2025-43799P3MEDIUMCVSS 6.5≥ 7.3.10, ≤ 7.3.10-u35≥ 7.4.13, ≤ 7.4.13-u92+2 more2025-09-15
CVE-2025-43799 [MEDIUM] CWE-1393 CVE-2025-43799: Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2
Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has changed their initial password, which allows remote users to access and edit content via
nvd
CVE-2025-62261P3MEDIUMCVSS 6.5≥ 7.3.10, ≤ 7.3.10-u34≥ 7.4.13, ≤ 7.4.13-u92+1 more2025-10-27
CVE-2025-62261 [MEDIUM] CWE-312 CVE-2025-62261: Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 thr
Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 34, and older unsupported versions stores password reset tokens in plain text, which allows attackers with access to the database to obtain the token, reset a user’s password and take ove
nvd