cbcvebase.

Liferay Dxp vulnerabilities

240 known vulnerabilities affecting liferay/dxp.

Total CVEs
240
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH30MEDIUM202LOW3

Vulnerabilities

Page 7 of 12
CVE-2025-43781P4MEDIUMCVSS 6.1≥ 2024.Q1.1, ≤ 2024.Q1.12≥ 2024.Q2.0, ≤ 2023.Q2.13+1 more2025-09-09
CVE-2025-43781 [MEDIUM] CWE-79 CVE-2025-43781: Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.110 through 7.4.3.128, an Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.110 through 7.4.3.128, and Liferay DXP 2024.Q3.1 through 2024.Q3.8, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.12 allows remote attackers to inject arbitrary web script or HTML via the URL in search bar portlet
nvd
CVE-2025-43785P4MEDIUMCVSS 6.1≥ 7.4.13-u45, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.12+1 more2025-09-10
CVE-2025-43785 [MEDIUM] CWE-79 CVE-2025-43785: Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45 through 7.4.3.128, and Li Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45 through 7.4.3.128, and Liferay DXP 2024 Q2.0 through 2024.Q2.9, 2024.Q1.1 through 2024.Q1.12, and 7.4 update 45 through update 92 allows remote attackers to execute an arbitrary web script or HTML in the My Workflow Tasks page.
nvd
CVE-2025-43800P4MEDIUMCVSS 6.1≥ 7.4.13-u20, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.4+1 more2025-09-15
CVE-2025-43800 [MEDIUM] CWE-79 CVE-2025-43800: Cross-site scripting (XSS) vulnerability in Objects in Liferay Portal 7.4.3.20 through 7.4.3.111, an Cross-site scripting (XSS) vulnerability in Objects in Liferay Portal 7.4.3.20 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an object with a rich text type field.
nvd
CVE-2025-43791P4MEDIUMCVSS 6.1≥ 7.3.10, ≤ 7.3.10-u36≥ 7.4.13, ≤ 7.4.13-u92+2 more2025-09-15
CVE-2025-43791 [MEDIUM] CWE-79 CVE-2025-43791: Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.0 through 7.4.3.111, and L Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a "Rich Text" type field to (1) a web content str
nvd
CVE-2025-43742P4MEDIUMCVSS 6.1≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.14+4 more2025-08-20
CVE-2025-43742 [MEDIUM] CWE-79 CVE-2025-43742: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.3, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScr
nvd
CVE-2025-43770P4MEDIUMCVSS 6.1≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.12+3 more2025-08-23
CVE-2025-43770 [MEDIUM] CWE-79 CVE-2025-43770: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the referer or FORWA
nvd
CVE-2025-43761P4MEDIUMCVSS 6.1≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.12+3 more2025-08-22
CVE-2025-43761 [MEDIUM] CWE-79 CVE-2025-43761: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.4, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the frontend-editor-
nvd
CVE-2023-47795P4MEDIUMCVSS 5.4≥ 2023.q3.1, ≤ 2023.q3.5≥ 7.4.13.u18, ≤ 7.4.13.u922024-02-21
CVE-2023-47795 [MEDIUM] CWE-79 CVE-2023-47795: Stored cross-site scripting (XSS) vulnerability in the Document and Media widget in Liferay Portal 7 Stored cross-site scripting (XSS) vulnerability in the Document and Media widget in Liferay Portal 7.4.3.18 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 18 through 92 allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into a document's “Title” text field.
nvd
CVE-2024-25610P4MEDIUMCVSS 5.4≥ 7.4.13, ≤ 7.4.13.u8≥ 7.3.10, ≤ 7.3.10-dxp-3+1 more2024-02-20
CVE-2024-25610 [MEDIUM] CWE-1188 CVE-2024-25610: In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions, the default configuration does not sanitize blog entries of JavaScript, which allows remote authenticated users to inject arbitrary web script or HTML (XSS) via a
nvd
CVE-2025-62276P4MEDIUMCVSS 5.5≥ 7.4.13, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.10+1 more2025-11-01
CVE-2025-62276 [MEDIUM] CWE-525 CVE-2025-62276: The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and o The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions uses an incorrect cache-control header, which allows local users to obtain access to downlo
nvd
CVE-2025-43755P4MEDIUMCVSS 5.4≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.17+5 more2025-08-21
CVE-2025-43755 [MEDIUM] CWE-79 CVE-2025-43755: A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 t through 7.4.3.132, and Lif A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 t through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.13, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.17 and 7.4 GA through update 92 allows an remote authenticated attacker to inject JavaS
nvd
CVE-2025-43740P4MEDIUMCVSS 5.4≥ 2024.Q1.9, ≤ 2024.Q1.19≥ 2024.Q2.1, ≤ 2024.Q2.13+4 more2025-08-19
CVE-2025-43740 [MEDIUM] CWE-79 CVE-2025-43740: A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and L A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13 and 2024.Q1.9 through 2024.Q1.19 allows an remote authenticated attacker to inject JavaScript
nvd
CVE-2025-62239P4MEDIUMCVSS 5.4≥ 7.4.13-u21, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.8+1 more2025-10-10
CVE-2025-62239 [MEDIUM] CWE-79 CVE-2025-62239: Cross-site scripting (XSS) vulnerability in workflow process builder in Liferay Portal 7.4.3.21 thro Cross-site scripting (XSS) vulnerability in workflow process builder in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 21 through update 92 allows remote authenticated attackers to inject arbitrary web script or HTML via the crafted input in a workflow definition.
nvd
CVE-2025-62263P4MEDIUMCVSS 5.4≥ 7.3.10-sp3, ≤ 7.3.10-u36≥ 7.4.13, ≤ 7.4.13-u92+1 more2025-10-27
CVE-2025-62263 [MEDIUM] CWE-79 CVE-2025-62263: Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and L Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 service pack 3 through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account Role’s “Title” text field to (1) view ac
nvd
CVE-2025-43822P4MEDIUMCVSS 5.4≥ 7.4.13, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.8+1 more2025-10-07
CVE-2025-43822 [MEDIUM] CWE-79 CVE-2025-43822: Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3. Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 15 through update 92 allow remote attackers to inject arbitrary web script or HTML via crafted payload injected into a Terms and Condition's Name text field t
nvd
CVE-2025-43811P4MEDIUMCVSS 5.4≥ 7.4.13-u50, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.7+1 more2025-09-29
CVE-2025-43811 [MEDIUM] CWE-79 CVE-2025-43811: Multiple stored cross-site scripting (XSS) vulnerability in the related asset selector in Liferay Po Multiple stored cross-site scripting (XSS) vulnerability in the related asset selector in Liferay Portal 7.4.3.50 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.7, and 7.4 update 50 through update 92 allows remote authenticated attackers to inject arbitrary web script or HTML via a crafted payload injected i
nvd
CVE-2025-43775P4MEDIUMCVSS 5.4≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.0, ≤ 2024.Q1.12+2 more2025-09-09
CVE-2025-43775 [MEDIUM] CWE-79 CVE-2025-43775: Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Lifer Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.5, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via remote app title field.
nvd
CVE-2025-43807P4MEDIUMCVSS 5.4≥ 7.4.13, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.10+1 more2025-09-22
CVE-2025-43807 [MEDIUM] CWE-79 CVE-2025-43807: Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0 Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a publication’s “Name” text fie
nvd
CVE-2025-43787P4MEDIUMCVSS 5.4≥ 2024.Q1.1, ≤ 2024.Q1.20≥ 2024.Q2.0, ≤ 2024.Q2.13+5 more2025-09-12
CVE-2025-43787 [MEDIUM] CWE-79 CVE-2025-43787: A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Life A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q3.0, 2025.Q2.0 through 2025.Q2.12, 2025.Q1.0 through 2025.Q1.17, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20 allows an remote authenticated attacker to inject Java
nvd
CVE-2025-43744P4MEDIUMCVSS 5.4≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.19+5 more2025-08-19
CVE-2025-43744 [MEDIUM] CWE-79 CVE-2025-43744: A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.13 A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.5, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 and 7.4 GA through update 92 exists in the Asset Publish
nvd
Liferay Dxp vulnerabilities | cvebase