Liferay Dxp vulnerabilities

242 known vulnerabilities affecting liferay/dxp.

Total CVEs
242
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH26MEDIUM204LOW10

Vulnerabilities

Page 5 of 13
CVE-2025-43783MEDIUMCVSS 5.1≥ 7.4.13-u73, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.12+2 more2025-09-10
CVE-2025-43783 [MEDIUM] CWE-79 CVE-2025-43783: Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.73 through 7.4.3.128, and Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.73 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 7.4 update 73 through update 92 allows remote attackers to inject arbitrary web script or HTML via the /c/portal/comment/discussion/get_editor path.
cvelistv5nvd
CVE-2025-43785MEDIUMCVSS 4.6≥ 7.4.13-u45, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.12+1 more2025-09-10
CVE-2025-43785 [MEDIUM] CWE-79 CVE-2025-43785: Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45 through 7.4.3.128, and Li Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45 through 7.4.3.128, and Liferay DXP 2024 Q2.0 through 2024.Q2.9, 2024.Q1.1 through 2024.Q1.12, and 7.4 update 45 through update 92 allows remote attackers to execute an arbitrary web script or HTML in the My Workflow Tasks page.
cvelistv5nvd
CVE-2025-43786MEDIUMCVSS 6.9≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.12+2 more2025-09-09
CVE-2025-43786 [MEDIUM] CWE-79 CVE-2025-43786: Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024 Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 and 7.4 GA through update 92 allow attackers to determine existent ERC in the application by exploit the time response.
cvelistv5nvd
CVE-2025-43778MEDIUMCVSS 4.8≥ 2024.Q1.1, ≤ 2024.Q1.20≥ 2024.Q2.0, ≤ 2024.Q2.13+4 more2025-09-09
CVE-2025-43778 [MEDIUM] CWE-79 CVE-2025-43778: A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Life A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.11, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20 allows an remote authenticated attacker to inject JavaScript thr
cvelistv5nvd
CVE-2025-43776MEDIUMCVSS 4.6≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.19+5 more2025-09-09
CVE-2025-43776 [MEDIUM] CWE-209 CVE-2025-43776: A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Life A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 and 7.4 GA through update 92 allows an remote authenticated attacke
cvelistv5nvd
CVE-2025-43777MEDIUMCVSS 5.1≥ 2024.Q1.1, ≤ 2024.Q1.19≥ 2024.Q2.0, ≤ 2024.Q2.13+4 more2025-09-09
CVE-2025-43777 [MEDIUM] CWE-209 CVE-2025-43777: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 thro Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.19 exposes "Internal Server Error" in the response body when a login attempt is made with a deleted Client Secret.
cvelistv5nvd
CVE-2025-43775MEDIUMCVSS 4.6≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.0, ≤ 2024.Q1.12+2 more2025-09-09
CVE-2025-43775 [MEDIUM] CWE-79 CVE-2025-43775: Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Lifer Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.5, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via remote app title field.
cvelistv5nvd
CVE-2025-43781MEDIUMCVSS 5.3≥ 2024.Q1.1, ≤ 2024.Q1.12≥ 2024.Q2.0, ≤ 2023.Q2.13+1 more2025-09-09
CVE-2025-43781 [MEDIUM] CWE-79 CVE-2025-43781: Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.110 through 7.4.3.128, an Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.110 through 7.4.3.128, and Liferay DXP 2024.Q3.1 through 2024.Q3.8, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.12 allows remote attackers to inject arbitrary web script or HTML via the URL in search bar portlet
cvelistv5nvd
CVE-2025-43763MEDIUMCVSS 4.8≥ 2024.Q1.1, ≤ 2024.Q1.20≥ 2024.Q2.0, ≤ 2024.Q2.13+2 more2025-09-09
CVE-2025-43763 [MEDIUM] CWE-918 CVE-2025-43763: A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3. A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20 that affects custom object attachment fields. This flaw allows an attacker to manipulate the application into
cvelistv5nvd
CVE-2025-43772HIGHCVSS 7.1≥ 6.2.0, ≤ portal-173≥ 7.0.10, ≤ de-102+4 more2025-09-04
CVE-2025-43772 [HIGH] CWE-400 CVE-2025-43772: Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through up Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not restrict the saving of request parameters in the portlet session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP request.
cvelistv5nvd
CVE-2025-3586HIGHCVSS 7.5≥ 7.4.13-u27, ≤ 7.4.13-u42≥ 2023.Q3.1, ≤ 2023.Q3.10+2 more2025-09-01
CVE-2025-3586 [HIGH] CWE-863 CVE-2025-3586: In Liferay Portal 7.4.3.27 through 7.4.3.42, and Liferay DXP 2024.Q1.1 through 2024.Q1.20, 2023.Q4.0 In Liferay Portal 7.4.3.27 through 7.4.3.42, and Liferay DXP 2024.Q1.1 through 2024.Q1.20, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 27 through update 42 (Liferay PaaS, and Liferay Self-Hosted), the Objects module does not restrict the use of Groovy scripts in Object actions for Admin Users. This allows remote authenticated
cvelistv5nvd
CVE-2025-43773MEDIUMCVSS 4.6≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.18+5 more2025-08-29
CVE-2025-43773 [MEDIUM] CWE-862 CVE-2025-43773: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 20 Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 has a security vulnerability that allowing for improper access through the expandoTableLocalService.
cvelistv5nvd
CVE-2025-43768MEDIUMCVSS 5.1≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.15+3 more2025-08-23
CVE-2025-43768 [MEDIUM] CWE-201 CVE-2025-43768: Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 throu Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows authenticated users without any permissions to access sensitive information of admin users using JSONWS APIs.
cvelistv5nvd
CVE-2025-43767MEDIUMCVSS 5.1≥ 7.4.13-u86, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.12+2 more2025-08-23
CVE-2025-43767 [MEDIUM] CWE-601 CVE-2025-43767: Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.8 Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.86 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 update 86 through update 92 allows an attacker to exploit this security vulnerability to redirect users to a malicious
cvelistv5nvd
CVE-2025-43765MEDIUMCVSS 6.9≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.13+3 more2025-08-23
CVE-2025-43765 [MEDIUM] CWE-79 CVE-2025-43765: A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Lifer A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.13 and 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the text field from a web content.
cvelistv5nvd
CVE-2025-43769MEDIUMCVSS 4.6≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.12+2 more2025-08-23
CVE-2025-43769 [MEDIUM] CWE-79 CVE-2025-43769: Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.131, and Lifer Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.8, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows remote attackers to execute arbitrary web script or HTML via components tab.
cvelistv5nvd
CVE-2025-43766MEDIUMCVSS 6.8≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.12+3 more2025-08-23
CVE-2025-43766 [MEDIUM] CWE-434 CVE-2025-43766: The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows the upload of unrestricted files in the style books component that are processed within the environment enabling arbitrary code execution by attackers.
cvelistv5nvd
CVE-2025-43764MEDIUMCVSS 6.9≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.20+3 more2025-08-23
CVE-2025-43764 [MEDIUM] CWE-1333 CVE-2025-43764: Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Design Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScript in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.1, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20 and 7.4 GA through update 92, which allows authenti
cvelistv5nvd
CVE-2025-43770MEDIUMCVSS 6.9≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.12+3 more2025-08-23
CVE-2025-43770 [MEDIUM] CWE-79 CVE-2025-43770: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the referer or FORWA
cvelistv5nvd
CVE-2025-43752MEDIUMCVSS 5.3≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.15+4 more2025-08-22
CVE-2025-43752 [MEDIUM] CWE-770 CVE-2025-43752: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 throu Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allow users to upload an unlimited amount of files through the object entries attachment fields, the files are stored i
cvelistv5nvd