cbcvebase.

Liferay Dxp vulnerabilities

240 known vulnerabilities affecting liferay/dxp.

Total CVEs
240
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH30MEDIUM202LOW3

Vulnerabilities

Page 3 of 12
CVE-2025-3602P3HIGHCVSS 7.5≥ 7.2.10-dxp-8, ≤ dxp-20≥ 7.3.10, ≤ 7.3.10-u35+2 more2025-06-16
CVE-2025-3602 [HIGH] CWE-400 CVE-2025-3602: Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through u Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through update 35, and 7.2 fix pack 8 through fix pack 20 does not limit the depth of a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing complex queries.
nvd
CVE-2025-43796P3HIGHCVSS 7.5≥ 7.3.10, ≤ 7.3.10-u35≥ 7.4.13, ≤ 7.4.13-u92+1 more2025-09-12
CVE-2025-43796 [HIGH] CWE-400 CVE-2025-43796: Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA though update 35 does not limit the number of objects returned from a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing queries that return a large number of obj
nvd
CVE-2025-43750P3MEDIUMCVSS 6.5≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.14+4 more2025-08-20
CVE-2025-43750 [MEDIUM] CWE-434 CVE-2025-43750: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 throu Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows remote unauthenticated users (guests) to upload files via the form attachment field without proper validation, e
nvd
CVE-2025-43825P3MEDIUMCVSS 6.5≥ 2023.Q3.1, ≤ 2023.Q3.10≥ 2023.Q4.0, ≤ 2024.Q4.10+5 more2025-10-03
CVE-2025-43825 [MEDIUM] CWE-201 CVE-2025-43825: A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1 A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows sensitive user data to be includ
nvd
CVE-2025-62247P3MEDIUMCVSS 6.5≥ 2024.Q1.1, ≤ 2024.Q1.19≥ 2024.Q2.0, ≤ 2024.Q2.13+4 more2025-10-22
CVE-2025-62247 [MEDIUM] CWE-862 CVE-2025-62247: Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132 Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 allows instance users to read and select unauthorized Bl
nvd
CVE-2025-62258P3MEDIUMCVSS 6.5≥ 7.3.10, ≤ 7.3.10-u35≥ 7.4.13, ≤ 7.4.13-u92+1 more2025-10-27
CVE-2025-62258 [MEDIUM] CWE-352 CVE-2025-62258: CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to execute any Headless API via the `endpoint` parameter.
nvd
CVE-2025-43772P3HIGHCVSS 7.1≥ 6.2.0, ≤ portal-173≥ 7.0.10, ≤ de-102+4 more2025-09-04
CVE-2025-43772 [HIGH] CWE-400 CVE-2025-43772: Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through up Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not restrict the saving of request parameters in the portlet session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP request.
nvd
CVE-2025-43763P3MEDIUMCVSS 6.5≥ 2024.Q1.1, ≤ 2024.Q1.20≥ 2024.Q2.0, ≤ 2024.Q2.13+2 more2025-09-09
CVE-2025-43763 [MEDIUM] CWE-918 CVE-2025-43763: A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3. A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20 that affects custom object attachment fields. This flaw allows an attacker to manipulate the application into m
nvd
CVE-2024-26265P3MEDIUMCVSS 6.5≥ 7.4.13, ≤ 7.4.13.u15≥ 7.3.10, ≤ 7.3.10-dxp-3+1 more2024-02-20
CVE-2024-26265 [MEDIUM] CWE-770 CVE-2024-26265: The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions relies on a request parameter to limit the size of files that can be uploaded, which allows remote authenticated users to upload arbitrari
nvd
CVE-2024-25604P3MEDIUMCVSS 6.5v7.4.13≥ 7.3.10, ≤ 7.3.10-dxp-2+1 more2024-02-20
CVE-2024-25604 [MEDIUM] CWE-863 CVE-2024-25604: Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 be Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions does not properly check user permissions, which allows remote authenticated users with the VIEW user permission to edit their own permission via the User and Organizations sec
nvd
CVE-2025-43752P3MEDIUMCVSS 6.5≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.15+4 more2025-08-22
CVE-2025-43752 [MEDIUM] CWE-770 CVE-2025-43752: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 throu Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allow users to upload an unlimited amount of files through the object entries attachment fields, the files are stored i
nvd
CVE-2025-62251P3MEDIUMCVSS 6.5≥ 7.3.10, ≤ 7.3.10-u36≥ 7.4.13, ≤ 7.4.13-u92+2 more2025-10-13
CVE-2025-62251 [MEDIUM] CWE-732 CVE-2025-62251: Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 throu Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA through update 92 and 7.3 GA though update 36 shows content to users who do not have permission to view it via the Menu Display Widget. This security flaw could result in sensitive information being exposed to unauthorized users.
nvd
CVE-2025-43784P3MEDIUMCVSS 6.5≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.12+1 more2025-09-10
CVE-2025-43784 [MEDIUM] CWE-863 CVE-2025-43784: Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 20 Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.8, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows guest users to obtain object entries information via the API Builder.
nvd
CVE-2025-43747P3MEDIUMCVSS 6.5≥ 2025.Q2.0, ≤ 2025.Q2.32025-08-21
CVE-2025-43747 [MEDIUM] CWE-918 CVE-2025-43747: A server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025. A server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025.Q2.3 due to insecure domain validation on analytics.cloud.domain.allowed, allowing an attacker to perform requests by change the domain and bypassing the validation method, this insecure validation is not distinguishing between trusted subdomains and
nvd
CVE-2025-43762P3MEDIUMCVSS 6.5≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.14+4 more2025-08-22
CVE-2025-43762 [MEDIUM] CWE-770 CVE-2025-43762: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 throu Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allow users to upload an unlimited amount of files through the forms, the files are stored in the document_library allo
nvd
CVE-2025-43819P3MEDIUMCVSS 6.5≥ 2024.Q1.1, ≤ 2024.Q1.12≥ 2024.Q2.0, ≤ 2024.Q2.13+2 more2025-09-24
CVE-2025-43819 [MEDIUM] CWE-613 CVE-2025-43819: A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, a A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, and 2024.Q1.1 through 2024.Q1.12 is allow an remote non-authenticated attacker to reuse old user session by SLO API
nvd
CVE-2025-43798P3MEDIUMCVSS 6.5≥ 7.3.10, ≤ 7.3.10-u35≥ 7.4.13, ≤ 7.4.13-u92+2 more2025-09-15
CVE-2025-43798 [MEDIUM] CWE-304 CVE-2025-43798: Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through upda Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time password (TOTP) to be used multiple times during the validity period, which allows attackers with access to a user’s TOTP to authenticate as the user.
nvd
CVE-2025-43764P4MEDIUMCVSS 6.5≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.20+3 more2025-08-23
CVE-2025-43764 [MEDIUM] CWE-1333 CVE-2025-43764: Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Design Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScript in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.1, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20 and 7.4 GA through update 92, which allows authenti
nvd
CVE-2025-62257P4MEDIUMCVSS 5.3≥ 7.4.13, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.10+2 more2025-10-30
CVE-2025-62257 [MEDIUM] CWE-307 CVE-2025-62257: Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote attackers to determine a user’s password even if account lockout i
nvd
CVE-2025-62259P3MEDIUMCVSS 5.4≥ 7.3.10, ≤ 7.3.10-u35≥ 7.4.13, ≤ 7.4.13-u92+1 more2025-10-27
CVE-2025-62259 [MEDIUM] CWE-863 CVE-2025-62259: Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 th Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has verified their email address, which allows remote users to access and edit content via the API.
nvd