Liferay Dxp vulnerabilities
240 known vulnerabilities affecting liferay/dxp.
Total CVEs
240
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH30MEDIUM202LOW3
Vulnerabilities
Page 5 of 12
CVE-2025-43751P4MEDIUMCVSS 5.3≥ 7.4.13, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.10+5 more2025-08-22
CVE-2025-43751 [MEDIUM] CWE-203 CVE-2025-43751: User enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0
User enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10 and 7.4 GA through update 92 allows remote attackers to determine if an account exis
nvd
CVE-2025-43805P4MEDIUMCVSS 5.3≥ 7.3.10, ≤ 7.3.10-u35≥ 7.4.13, ≤ 7.4.13-u92+2 more2025-09-16
CVE-2025-43805 [MEDIUM] CWE-862 CVE-2025-43805: Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4
Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, and 7.3 GA through update 35 does not perform an authorization check when users attempt to view a display page template, which allows remote attackers to view display page templates via crafted URLs.
nvd
CVE-2025-43748P4MEDIUMCVSS 6.8≥ 6.2.0, ≤ portal-173≥ 7.0.10, ≤ de-102+7 more2025-08-20
CVE-2025-43748 [MEDIUM] CWE-352 CVE-2025-43748: Insufficient CSRF protection for omni-administrator users in Liferay Portal 7.0.0 through 7.4.3.119,
Insufficient CSRF protection for omni-administrator users in Liferay Portal 7.0.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.6, 2023.Q4.0 through 2023.Q4.9, 2023.Q3.1 through 2023.Q3.9, 7.4 GA through update 92, 7.3 GA through update 36, and older unsupported versions allows attackers to execute Cross-Site Request Forgery
nvd
CVE-2023-42627P4MEDIUMCVSS 5.4≥ 7.3.10, ≤ 7.3.10.*≥ 7.4.13, ≤ 7.4.13.u912023-10-17
CVE-2023-42627 [MEDIUM] CWE-79 CVE-2023-42627: Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal
Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal 7.3.5 through 7.4.3.91, and Liferay DXP 7.3 update 33 and earlier, and 7.4 before update 92 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a (1) Shipping Name, (2) Shipping Phone Number, (3) Shipping Ad
nvd
CVE-2021-29043P4MEDIUMCVSS 5.9v7.32021-05-17
CVE-2021-29043 [MEDIUM] CWE-522 CVE-2021-29043: The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 9
The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 does not obfuscate the S3 store's proxy password, which allows attackers to steal the proxy password via man-in-the-middle attacks or shoulder surfing.
nvd
CVE-2025-43830P4MEDIUMCVSS 6.1≥ 7.3.10, ≤ 7.3.10-u35≥ 7.4.13, ≤ 7.4.13-u92+2 more2025-10-08
CVE-2025-43830 [MEDIUM] CWE-79 CVE-2025-43830: Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111,
Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and 7.3 GA through update 35 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a form with a rich text t
nvd
CVE-2025-4604P4MEDIUMCVSS 6.1≥ 7.4.13-u80, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.16+4 more2025-08-04
CVE-2025-4604 [MEDIUM] CWE-79 CVE-2025-4604: The vulnerable code can bypass the Captcha check in Liferay Portal 7.4.3.80 through 7.4.3.132, and L
The vulnerable code can bypass the Captcha check in Liferay Portal 7.4.3.80 through 7.4.3.132, and Liferay DXP 2024.Q1.1 through 2024.Q1.19, 2024.Q2.0 through 2024.Q2.13, 2024.Q3.0 through 2024.Q3.13, 2024.Q4.0 through 2024.Q4.7, 2025.Q1.0 through 2025.Q1.15 and 7.4 update 80 through update 92 and then attackers can run scripts in the Gogo shell
nvd
CVE-2024-25146P4MEDIUMCVSS 5.3v7.3≥ 7.3.10, ≤ 7.3.10-dxp-2+1 more2024-02-08
CVE-2024-25146 [MEDIUM] CWE-204 CVE-2024-25146: Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before servi
Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsupported versions returns with different responses depending on whether a site does not exist or if the user does not have permission to access the site, which allows remote attackers to discover the exi
nvd
CVE-2024-26267P4MEDIUMCVSS 5.3≥ 7.4.13, ≤ 7.4.13.u25≥ 7.3.10, ≤ 7.3.10.u4+1 more2024-02-20
CVE-2024-26267 [MEDIUM] CWE-1188 CVE-2024-26267: In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before
In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix pack 19, and older unsupported versions the default value of the portal property `http.header.version.verbosity` is set to `full`, which allows remote attackers to easily identify the version of the app
nvd
CVE-2025-43824P4MEDIUMCVSS 5.4≥ 7.4.13, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.8+1 more2025-10-06
CVE-2025-43824 [MEDIUM] CWE-79 CVE-2025-43824: The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Li
The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions uses a user’s name in the “Content-Disposition” header, which allows remote authenticated users to change the file extension wh
nvd
CVE-2025-62238P4MEDIUMCVSS 5.4≥ 7.4.13-u21, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.8+1 more2025-10-10
CVE-2025-62238 [MEDIUM] CWE-79 CVE-2025-62238: Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Lifera
Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 21 through update 92 allows remote authenticated attackers to inject arbitrary web script or HTML via a crafted payload inject
nvd
CVE-2024-26270P4MEDIUMCVSS 5.3≥ 2023.q3.1, ≤ 2023.q3.4≥ 7.4.13.u76, ≤ 7.4.13.u922024-02-20
CVE-2024-26270 [MEDIUM] CWE-201 CVE-2024-26270: The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 befor
The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 76 through 92 embeds the user’s hashed password in the page’s HTML source, which allows man-in-the-middle attackers to steal a user's hashed password.
nvd
CVE-2025-43754P4MEDIUMCVSS 5.3≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.14+3 more2025-08-21
CVE-2025-43754 [MEDIUM] CWE-208 CVE-2025-43754: Username enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q
Username enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows attackers to determine if an account exist in the application by inspecting the server processing time
nvd
CVE-2025-43789P4MEDIUMCVSS 5.3≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.92025-09-12
CVE-2025-43789 [MEDIUM] CWE-863 CVE-2025-43789: JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.
JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.9, 7.4 GA through update 92 published to OSGi are registered and invoked directly as classes which allows Service Access Policies get executed.
nvd
CVE-2023-42628P4MEDIUMCVSS 5.4≥ 7.0.10-de-83, ≤ 7.0.10-*≥ 7.1.10, ≤ 7.1.10-*+3 more2023-10-17
CVE-2023-42628 [MEDIUM] CWE-79 CVE-2023-42628: Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7
Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay DXP 7.0 fix pack 83 through 102, 7.1 fix pack 28 and earlier, 7.2 fix pack 20 and earlier, 7.3 update 33 and earlier, and 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML into a parent wiki page v
nvd
CVE-2023-42629P4MEDIUMCVSS 5.4≥ 7.4.13, ≤ 7.4.13.u872023-10-17
CVE-2023-42629 [MEDIUM] CWE-79 CVE-2023-42629: Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.
Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Vocabulary's 'description' text field.
nvd
CVE-2023-35029P4MEDIUMCVSS 6.1v7.4≥ 7.4.13.u70, ≤ 7.4.13.u762023-06-15
CVE-2023-35029 [MEDIUM] CWE-601 CVE-2023-35029: Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 thro
Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to redirect users to arbitrary external URLs via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.
nvd
CVE-2025-43802P4MEDIUMCVSS 6.1≥ 7.3.10-u33, ≤ 7.3.10-u35≥ 7.4.13-u51, ≤ 7.4.13-u92+2 more2025-09-15
CVE-2025-43802 [MEDIUM] CWE-79 CVE-2025-43802: Stored cross-site scripting (XSS) vulnerability in a custom object’s /o/c/<object-name> API endpoint
Stored cross-site scripting (XSS) vulnerability in a custom object’s /o/c/ API endpoint in Liferay Portal 7.4.3.51 through 7.4.3.109, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 update 51 through update 92, and 7.3 update 33 through update 35. allows remote attackers to inject arbitrary web script or HTML via the externalReferenceCode parameter.
nvd
CVE-2025-43769P4MEDIUMCVSS 6.1≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.12+2 more2025-08-23
CVE-2025-43769 [MEDIUM] CWE-79 CVE-2025-43769: Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.131, and Lifer
Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.8, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows remote attackers to execute arbitrary web script or HTML via components tab.
nvd
CVE-2025-62267P4MEDIUMCVSS 6.1≥ 7.4.13-u35, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.10+1 more2025-10-31
CVE-2025-62267 [MEDIUM] CWE-79 CVE-2025-62267: Multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page
Multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 35 through update 92 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a
nvd