cbcvebase.

Liferay Dxp vulnerabilities

240 known vulnerabilities affecting liferay/dxp.

Total CVEs
240
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH30MEDIUM202LOW3

Vulnerabilities

Page 6 of 12
CVE-2025-43778P4MEDIUMCVSS 6.1≥ 2024.Q1.1, ≤ 2024.Q1.20≥ 2024.Q2.0, ≤ 2024.Q2.13+4 more2025-09-09
CVE-2025-43778 [MEDIUM] CWE-79 CVE-2025-43778: A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Life A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.11, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20 allows an remote authenticated attacker to inject JavaScript thro
nvd
CVE-2025-43818P4MEDIUMCVSS 6.1≥ 7.3.10-u25, ≤ 7.3.10-u36≥ 7.4.13-u35, ≤ 7.4.13-u92+2 more2025-09-29
CVE-2025-43818 [MEDIUM] CWE-79 CVE-2025-43818: Cross-site scripting (XSS) vulnerability in the Calendar widget in Liferay Portal 7.4.3.35 through 7 Cross-site scripting (XSS) vulnerability in the Calendar widget in Liferay Portal 7.4.3.35 through 7.4.3.110, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.6, 7.4 update 35 through update 92, and 7.3 update 25 through update 36 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into
nvd
CVE-2025-62255P4MEDIUMCVSS 6.1≥ 7.3.10, ≤ 7.3.10-u34≥ 7.4.13, ≤ 7.4.13-u92+1 more2025-10-23
CVE-2025-62255 [MEDIUM] CWE-79 CVE-2025-62255: Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Por Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Portal 7.4.0 through 7.4.3.101, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via a crafted payload inje
nvd
CVE-2025-43765P4MEDIUMCVSS 6.1≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.13+3 more2025-08-23
CVE-2025-43765 [MEDIUM] CWE-79 CVE-2025-43765: A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Lifer A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.13 and 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the text field from a web content.
nvd
CVE-2025-43767P4MEDIUMCVSS 6.1≥ 7.4.13-u86, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.12+2 more2025-08-23
CVE-2025-43767 [MEDIUM] CWE-601 CVE-2025-43767: Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.8 Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.86 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 update 86 through update 92 allows an attacker to exploit this security vulnerability to redirect users to a malicious
nvd
CVE-2025-4599P4MEDIUMCVSS 6.1≥ 7.4.13-u61, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.13+3 more2025-08-04
CVE-2025-4599 [MEDIUM] CWE-79 CVE-2025-4599: The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP 202 The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP 2024.Q4.1 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.13 and 7.4 update 61 through update 92 was found to be vulnerable to postMessage-based XSS because it allows a remote non-authenticated attack
nvd
CVE-2025-62246P4MEDIUMCVSS 5.4≥ 7.4.13, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.8+1 more2025-10-13
CVE-2025-62246 [MEDIUM] CWE-79 CVE-2025-62246: Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.0 through 7.4.3.111 Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions allow remote authenticated users to inject arbitrary web script or HTML via a crafted p
nvd
CVE-2025-62237P4MEDIUMCVSS 5.4≥ 7.4.13-u8, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.8+1 more2025-10-10
CVE-2025-62237 [MEDIUM] CWE-79 CVE-2025-62237: Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4. Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 8 through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account’s “Name” t
nvd
CVE-2025-43829P4MEDIUMCVSS 5.4≥ 7.4.13-u18, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.8+1 more2025-10-08
CVE-2025-43829 [MEDIUM] CWE-79 CVE-2025-43829: Stored cross-site scripting (XSS) vulnerability in diagram type products in Commerce in Liferay Port Stored cross-site scripting (XSS) vulnerability in diagram type products in Commerce in Liferay Portal 7.4.3.18 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 18 through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a SVG file.
nvd
CVE-2025-43826P4MEDIUMCVSS 5.4≥ 7.4.13, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.10+2 more2025-09-30
CVE-2025-43826 [MEDIUM] CWE-79 CVE-2025-43826: Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allow remote attackers to inject arbitrary web script or HTML via an
nvd
CVE-2025-62265P4MEDIUMCVSS 5.4≥ 7.4.13, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.8+1 more2025-10-30
CVE-2025-62265 [MEDIUM] CWE-79 CVE-2025-62265: Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.1 Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, 7.3 GA through update 36, and older unsupported versions allows remote attackers to inject arbitrary web script or
nvd
CVE-2025-43776P4MEDIUMCVSS 5.4≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.19+5 more2025-09-09
CVE-2025-43776 [MEDIUM] CWE-209 CVE-2025-43776: A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Life A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 and 7.4 GA through update 92 allows an remote authenticated attacker
nvd
CVE-2025-43777P4MEDIUMCVSS 5.3≥ 2024.Q1.1, ≤ 2024.Q1.19≥ 2024.Q2.0, ≤ 2024.Q2.13+4 more2025-09-09
CVE-2025-43777 [MEDIUM] CWE-209 CVE-2025-43777: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 thro Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.19 exposes "Internal Server Error" in the response body when a login attempt is made with a deleted Client Secret.
nvd
CVE-2025-4655P4MEDIUMCVSS 5.0≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.15+4 more2025-08-09
CVE-2025-4655 [MEDIUM] CWE-918 CVE-2025-4655: SSRF vulnerability in FreeMarker templates in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DX SSRF vulnerability in FreeMarker templates in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 allows template editors to bypass access validations via crafted URLs.
nvd
CVE-2024-26269P4MEDIUMCVSS 6.1≥ 7.4.13, ≤ 7.4.13.u37≥ 7.3.10, ≤ 7.3.10.u10+1 more2024-02-21
CVE-2024-26269 [MEDIUM] CWE-79 CVE-2024-26269: Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7. Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via the anchor (hash) part of a URL.
nvd
CVE-2024-25147P4MEDIUMCVSS 6.1≥ 7.3.10, ≤ 7.3.10-dxp-2≥ 7.2.10, ≤ 7.2.10-dxp-142024-02-21
CVE-2024-25147 [MEDIUM] CWE-79 CVE-2024-25147: Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7. Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via crafted javascript: style links.
nvd
CVE-2025-62249P4MEDIUMCVSS 6.1≥ 2023.Q4.0, ≤ 2023.Q4.10≥ 2024.Q1.1, ≤ 2024.Q1.20+6 more2025-10-21
CVE-2025-62249 [MEDIUM] CWE-79 CVE-2025-62249: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q3.0 through 2025.Q3.2, 2025.Q2.0 through 2025.Q2.12, 2025.Q1.0 through 2025.Q1.17, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20, and 2023.Q4.0 through 2023.Q4
nvd
CVE-2025-62264P4MEDIUMCVSS 6.1≥ 7.4.13-u4, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.10+1 more2025-10-31
CVE-2025-62264 [MEDIUM] CWE-79 CVE-2025-62264: Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 t Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 update 4 through update 92 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_portal_language_override_web_internal_
nvd
CVE-2025-43815P4MEDIUMCVSS 6.1≥ 2023.Q3.5, ≤ 2023.Q3.6≥ 2023.Q4.0, ≤ 2023.Q4.22025-09-29
CVE-2025-43815 [MEDIUM] CWE-79 CVE-2025-43815: Reflected cross-site scripting (XSS) vulnerability on the page configuration page in Liferay Portal Reflected cross-site scripting (XSS) vulnerability on the page configuration page in Liferay Portal 7.4.3.102 through 7.4.3.110, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, and 2023.Q3.5 allows remote attackers to inject arbitrary web script or HTML via the com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURLTitle parameter.
nvd
CVE-2025-43804P4MEDIUMCVSS 6.1≥ 2023.Q3.1, ≤ 2023.Q3.4≥ 2023.Q4.0, ≤ 2023.Q4.12025-09-16
CVE-2025-43804 [MEDIUM] CWE-79 CVE-2025-43804: Cross-site scripting (XSS) vulnerability in Search widget in Liferay Portal 7.4.3.93 through 7.4.3.1 Cross-site scripting (XSS) vulnerability in Search widget in Liferay Portal 7.4.3.93 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_search_web_portlet_SearchPortlet_userId parameter.
nvd