cbcvebase.

Liferay Dxp vulnerabilities

240 known vulnerabilities affecting liferay/dxp.

Total CVEs
240
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL5HIGH30MEDIUM202LOW3

Vulnerabilities

Page 8 of 12
CVE-2025-43786P4MEDIUMCVSS 5.3≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.12+2 more2025-09-09
CVE-2025-43786 [MEDIUM] CWE-79 CVE-2025-43786: Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024 Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 and 7.4 GA through update 92 allow attackers to determine existent ERC in the application by exploit the time response.
nvd
CVE-2023-40191P4MEDIUMCVSS 6.1≥ 2023.q3.1, ≤ 2023.q3.5≥ 7.4.13.u44, ≤ 7.4.13.u922024-02-21
CVE-2023-40191 [MEDIUM] CWE-79 CVE-2023-40191: Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the “Blocked Email Domains” text field
nvd
CVE-2023-42496P4MEDIUMCVSS 6.1≥ 2023.q3.1, ≤ 2023.q3.5≥ 7.4.13, ≤ 7.4.13.u92+1 more2024-02-21
CVE-2023-42496 [MEDIUM] CWE-79 CVE-2023-42496: Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Po Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_roles_admin_web_portlet_RolesAdminPortlet_tabs2
nvd
CVE-2023-42498P4MEDIUMCVSS 6.1≥ 2023.q3.1, ≤ 2023.q3.4≥ 7.4.13.u4, ≤ 7.4.13.u922024-02-21
CVE-2023-42498 [MEDIUM] CWE-79 CVE-2023-42498: Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay P Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_language_override_web_internal_portlet_PLOPortlet_key paramet
nvd
CVE-2023-33944P4MEDIUMCVSS 6.1≥ 7.3.10, ≤ 7.3.10.u23≥ 7.4.13, ≤ 7.4.13.u682023-05-24
CVE-2023-33944 [MEDIUM] CWE-79 CVE-2023-33944: Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before update 24, and 7.4 before update 69 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a container type layout fragment's `URL` text field.
nvd
CVE-2022-42116P4MEDIUMCVSS 6.1fixed in 7.3v7.3+23 more2022-10-18
CVE-2022-42116 [MEDIUM] CWE-79 CVE-2022-42116: A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14, and Liferay DXP 7.3 before update 6, and 7.4 before update 15 allows remote attackers to inject arbitrary web script or HTML via the (1) name, or (2) namespace parameter.
nvd
CVE-2023-3193P4MEDIUMCVSS 6.1≥ 7.4.13.u70, ≤ 7.4.13.u732023-06-15
CVE-2023-3193 [MEDIUM] CWE-79 CVE-2023-3193: Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.73, and Liferay DXP 7.4 update 70 through 73 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.
nvd
CVE-2023-5190P4MEDIUMCVSS 6.1≥ 2023.q3.1, ≤ 2023.q3.5≥ 7.4.13.u45, ≤ 7.4.13.u922024-02-20
CVE-2023-5190 [MEDIUM] CWE-601 CVE-2023-5190: Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.4 Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 45 through 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_address_web_internal_portlet_CountriesManagementAdminPortlet_redirect par
nvd
CVE-2025-2536P4MEDIUMCVSS 6.1≥ 7.4.13-u82, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.10+4 more2025-03-19
CVE-2025-2536 [MEDIUM] CWE-79 CVE-2025-2536: Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay D Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 82 through update 92 in the Frontend JS module's layout-taglib/__liferay__/index.js allows remote attackers t
nvd
CVE-2025-43783P4MEDIUMCVSS 6.1≥ 7.4.13-u73, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.12+2 more2025-09-10
CVE-2025-43783 [MEDIUM] CWE-79 CVE-2025-43783: Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.73 through 7.4.3.128, and Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.73 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 7.4 update 73 through update 92 allows remote attackers to inject arbitrary web script or HTML via the /c/portal/comment/discussion/get_editor path.
nvd
CVE-2025-43735P4MEDIUMCVSS 6.1≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.12+3 more2025-08-12
CVE-2025-43735 [MEDIUM] CWE-79 CVE-2025-43735: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the google_gadget.
nvd
CVE-2024-8980P4MEDIUMCVSS 6.1≥ 6.2.0, ≤ portal-173≥ 7.0.10, ≤ de-102+5 more2024-10-22
CVE-2024-8980 [MEDIUM] CWE-352 CVE-2024-8980: The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023 The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, 7.2 GA through fix pack 20, 7.1 GA through fix pack 28, 7.0 GA through fix pack 102 and 6.2 GA through fix pack 173 does not sufficiently protect against Cross-Site Request Forgery (CSRF) attack
nvd
CVE-2025-43779P4MEDIUMCVSS 6.1≥ 7.4.13, ≤ 7.4.13-u92≥ 2024.Q1.1, ≤ 2024.Q1.182025-09-24
CVE-2025-43779 [MEDIUM] CWE-79 CVE-2025-43779: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 allows a remote authenticated attacker to inject JavaScript code via _com_liferay_commerce_product_definitions_web_internal_portlet_CPDefinitionsPortlet_productTypeName parameter.
nvd
CVE-2025-43817P4MEDIUMCVSS 6.1≥ 7.4.13-u74, ≤ 7.4.13-u92≥ 2023.Q3.1, ≤ 2023.Q3.8+1 more2025-09-29
CVE-2025-43817 [MEDIUM] CWE-79 CVE-2025-43817: Multiple reflected cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.74 through 7.4 Multiple reflected cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.74 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.6, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 74 through update 92 allow remote attackers to inject arbitrary web script or HTML via the `redirect` parameter to (1) Announcements, or (2) Alerts.
nvd
CVE-2024-25602P4MEDIUMCVSS 5.4≥ 7.3.10, ≤ 7.3.10-dxp-2≥ 7.2.10, ≤ 7.2.10-dxp-162024-02-21
CVE-2024-25602 [MEDIUM] CWE-79 CVE-2024-25602: Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Po Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload i
nvd
CVE-2024-26266P4MEDIUMCVSS 5.4≥ 7.4.13, ≤ 7.4.13.u9≥ 7.3.10, ≤ 7.3.10-dxp-3+1 more2024-02-21
CVE-2024-26266 [MEDIUM] CWE-79 CVE-2024-26266: Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupported versions, and Liferay DXP 7.4 before update 10, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allow remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected in
nvd
CVE-2024-25601P4MEDIUMCVSS 5.4≥ 7.3.10, ≤ 7.3.10-dxp-2≥ 7.2.10, ≤ 7.2.10-dxp-162024-02-21
CVE-2024-25601 [MEDIUM] CWE-79 CVE-2024-25601: Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Lif Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via a crafted pa
nvd
CVE-2024-25152P4MEDIUMCVSS 5.4≥ 7.3.10, ≤ 7.3.10-dxp-2≥ 7.2.10, ≤ 7.2.10-dxp-162024-02-21
CVE-2024-25152 [MEDIUM] CWE-79 CVE-2024-25152: Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 thro Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via the filename of an attachment.
nvd
CVE-2024-25603P4MEDIUMCVSS 5.4v7.4.13≥ 7.3.10, ≤ 7.3.10-dxp-3+1 more2024-02-21
CVE-2024-25603 [MEDIUM] CWE-79 CVE-2024-25603: Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Life Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via the insta
nvd
CVE-2024-25151P4MEDIUMCVSS 5.4≥ 7.3.10, ≤ 7.3.10-dxp-2≥ 7.2.10, ≤ 7.2.10-dxp-142024-02-21
CVE-2024-25151 [MEDIUM] CWE-79 CVE-2024-25151: The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Lifer The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not escape user supplied data in the default notification email template, which allows remote authenticated users to inject arbitrary web script or HTML via t
nvd