Liferay Portal vulnerabilities
319 known vulnerabilities affecting liferay/liferay_portal.
Total CVEs
319
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH47MEDIUM259LOW5
Vulnerabilities
Page 1 of 16
CVE-2020-7961P1CRITICALCVSS 9.8KEVPoCfixed in 7.2.12020-03-20
CVE-2020-7961 [CRITICAL] CWE-502 CVE-2020-7961: Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
nvd
CVE-2024-25608P1MEDIUMCVSS 6.1ExploitedPoCfixed in 7.4.3.192024-02-20
CVE-2024-25608 [MEDIUM] CWE-601 CVE-2024-25608: HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, an
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be circumvented by using the 'REPLACEMENT CHARACTER' (U+FFFD), which allows remote attackers to redirect users to arbitrary external UR
nvd
CVE-2025-4581P1HIGHCVSS 8.6Exploited≥ 7.4.0, ≤ 7.4.3.1322025-08-09
CVE-2025-4581 [HIGH] CWE-918 CVE-2025-4581: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 throu
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 allows a pre-authentication blind SSRF vulnerability in the portal-settings-authentication-opensso-web due to improper validat
nvd
CVE-2021-33990P2CRITICALCVSS 9.8PoCv6.2.52023-04-16
CVE-2021-33990 [CRITICAL] CWE-281 CVE-2021-33990: Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.ht
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference link only shows frmfolders.html is accessible and does not demonstrate how an unauthorized user can upload a file.
nvd
CVE-2019-11444P3HIGHCVSS 7.2PoCv7.1.22019-04-22
CVE-2019-11444 [HIGH] CWE-78 CVE-2019-11444: An issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script
An issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script console to execute OS commands. Commands can be executed via a [command].execute() call, as demonstrated by "def cmd =" in the ServerAdminPortlet_script value to group/control_panel/manage. Valid credentials for an application administrator user account a
nvd
CVE-2011-1571P3MEDIUMCVSS 6.8PoC≥ 5.1.0, ≤ 5.1.2≥ 6.0.0, ≤ 6.0.52011-05-07
CVE-2011-1571 [MEDIUM] CVE-2011-1571: Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x an
Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote attackers to execute arbitrary commands via unknown vectors.
nvd
CVE-2019-16891P2CRITICALCVSS 9.8≤ 6.0.6v6.1.0+20 more2019-10-04
CVE-2019-16891 [CRITICAL] CWE-502 CVE-2019-16891: Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
nvd
CVE-2025-3594P2CRITICALCVSS 9.8≥ 7.0.0, ≤ 7.4.3.4v6.22025-06-16
CVE-2025-3594 [CRITICAL] CWE-22 CVE-2025-3594: Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.
Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 34, and older unsupported versions allows remote attackers to (1) add files to arbitrary locations on the server and (2) download and execute arbitrary files from the download server via
nvd
CVE-2025-43766P2CRITICALCVSS 9.8≥ 7.4.0, < 7.4.3.1322025-08-23
CVE-2025-43766 [CRITICAL] CWE-434 CVE-2025-43766: The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13,
The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows the upload of unrestricted files in the style books component that are processed within the environment enabling arbitrary code execution by attackers.
nvd
CVE-2025-4388P3MEDIUMCVSS 6.1PoC≥ 7.4.0, < 7.4.3.1322025-05-06
CVE-2025-4388 [MEDIUM] CWE-79 CVE-2025-4388: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131,
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the modules/apps/marketpl
nvd
CVE-2024-38002P3HIGHCVSS 8.8≥ 7.3.2, ≤ 7.3.7≥ 7.4.0, < 7.4.3.1122024-10-22
CVE-2024-38002 [HIGH] CWE-862 CVE-2024-38002: The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through
The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does not properly check user permissions before updating a workflow definition, which allows remote authenticated users to modify workflow definitions and execu
nvd
CVE-2025-4576P3MEDIUMCVSS 6.1PoC≥ 7.4.0, ≤ 7.4.3.1332025-08-08
CVE-2025-4576 [MEDIUM] CWE-79 CVE-2025-4576: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133,
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript i
nvd
CVE-2010-5327P3HIGHCVSS 8.8≤ 6.2.102017-01-13
CVE-2010-5327 [HIGH] CWE-264 CVE-2010-5327: Liferay Portal through 6.2.10 allows remote authenticated users to execute arbitrary shell commands
Liferay Portal through 6.2.10 allows remote authenticated users to execute arbitrary shell commands via a crafted Velocity template.
nvd
CVE-2020-7934P3MEDIUMCVSS 5.4PoC≥ 7.1.0, ≤ 7.2.12020-01-28
CVE-2020-7934 [MEDIUM] CWE-79 CVE-2020-7934: In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerable to a persistent XSS issue. Any user can modify these fields with a particular XSS payload, and it will be stored in the database. The payload will then be rendered when a user utilizes the search featur
nvd
CVE-2020-13445P3HIGHCVSS 8.8v7.1v7.1.1+2 more2020-06-10
CVE-2020-13445 [HIGH] CWE-74 CVE-2020-13445: In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7
In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not restrict user access to sensitive objects, which allows remote authenticated users to execute arbitrary code via crafted FreeMarker and Velocity templates.
nvd
CVE-2016-3670P3MEDIUMCVSS 6.1PoC≤ 6.22016-06-13
CVE-2016-3670 [MEDIUM] CWE-79 CVE-2016-3670: Cross-site scripting (XSS) vulnerability in users.jsp in the Profile Search functionality in Liferay
Cross-site scripting (XSS) vulnerability in users.jsp in the Profile Search functionality in Liferay before 7.0.0 CE RC1 allows remote attackers to inject arbitrary web script or HTML via the FirstName field.
nvd
CVE-2021-29053P3HIGHCVSS 8.8v7.3.52021-05-17
CVE-2021-29053 [HIGH] CWE-89 CVE-2021-29053: Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1
Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1 allow remote authenticated users to execute arbitrary SQL commands via the classPKField parameter to (1) CommerceChannelRelFinder.countByC_C, or (2) CommerceChannelRelFinder.findByC_C.
nvd
CVE-2025-43773P3CRITICALCVSS 9.1≥ 7.4.0, ≤ 7.4.3.1322025-08-29
CVE-2025-43773 [CRITICAL] CWE-862 CVE-2025-43773: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 20
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 has a security vulnerability that allowing for improper access through the expandoTableLocalService.
nvd
CVE-2022-42121P3HIGHCVSS 8.8≥ 7.1.3, ≤ 7.4.3.4≥ 7.1.0, ≤ 7.4.22022-11-15
CVE-2022-42121 [HIGH] CWE-89 CVE-2022-42121: A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Life
A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template's 'Name' field.
nvd
CVE-2022-42120P3CRITICALCVSS 9.8≥ 7.3.3, ≤ 7.4.3.162022-11-15
CVE-2022-42120 [CRITICAL] CWE-89 CVE-2022-42120: A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and L
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.
nvd
1 / 16Next →