cbcvebase.

Liferay Portal vulnerabilities

319 known vulnerabilities affecting liferay/liferay_portal.

Total CVEs
319
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH47MEDIUM259LOW5

Vulnerabilities

Page 11 of 16
CVE-2025-43812P4MEDIUMCVSS 5.4≥ 7.4.3.4, < 7.4.3.1122025-09-29
CVE-2025-43812 [MEDIUM] CWE-79 CVE-2025-43812: Cross-site scripting (XSS) vulnerability in web content template in Liferay Portal 7.4.3.4 through 7 Cross-site scripting (XSS) vulnerability in web content template in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into a web content structure's Name
nvd
CVE-2025-43820P4MEDIUMCVSS 5.4≥ 7.4.3.35, < 7.4.3.1112025-09-29
CVE-2025-43820 [MEDIUM] CWE-79 CVE-2025-43820: Multiple cross-site scripting (XSS) vulnerabilities in the Calendar widget when inviting users to a Multiple cross-site scripting (XSS) vulnerabilities in the Calendar widget when inviting users to a event in Liferay Portal 7.4.3.35 through 7.4.3.110, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.6, 7.4 update 35 through update 92, and 7.3 update 25 through update 35 allow remote attackers to inject arbitrary web script or H
nvd
CVE-2025-62263P4MEDIUMCVSS 5.4≥ 7.3.7, < 7.4.3.1042025-10-27
CVE-2025-62263 [MEDIUM] CWE-79 CVE-2025-62263: Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and L Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 service pack 3 through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account Role’s “Title” text field to (1) view ac
nvd
CVE-2025-43753P4MEDIUMCVSS 5.4≥ 7.4.3.32, ≤ 7.4.3.1322025-08-21
CVE-2025-43753 [MEDIUM] CWE-79 CVE-2025-43753: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.32 through 7.4.3.13 A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.32 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.16 and 7.4 update 32 through update 92 allows an remote authenticated user to inject Java
nvd
CVE-2022-25146P4MEDIUMCVSS 5.3≥ 7.4.3.4, < 7.4.3.92022-03-03
CVE-2022-25146 [MEDIUM] CWE-346 CVE-2022-25146: The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 before update 5 does not check if the origin of event messages it receives matches the origin of the Remote App, allowing attackers to exfiltrate the CSRF token via a crafted event message.
nvd
CVE-2021-38263P4MEDIUMCVSS 6.1≤ 7.3.22022-03-03
CVE-2021-38263 [MEDIUM] CWE-79 CVE-2021-38263: Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3 Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 20 and 7.2 before fix pack 10 allows remote attackers to inject arbitrary web script or HTML via the output of a script.
nvd
CVE-2021-33332P4MEDIUMCVSS 6.1≥ 7.1.0, < 7.3.32021-08-03
CVE-2021-33332 [MEDIUM] CWE-79 CVE-2021-33332: Cross-site scripting (XSS) vulnerability in the Portlet Configuration module in Liferay Portal 7.1.0 Cross-site scripting (XSS) vulnerability in the Portlet Configuration module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portlet_configuration_css_web_portlet_PortletConfigurationCSSPortlet_portletResource
nvd
CVE-2021-29051P4MEDIUMCVSS 6.1≥ 7.2.0, ≤ 7.3.52021-05-17
CVE-2021-29051 [MEDIUM] CWE-79 CVE-2021-29051: Cross-site scripting (XSS) vulnerability in the Asset module's Asset Publisher app in Liferay Portal Cross-site scripting (XSS) vulnerability in the Asset module's Asset Publisher app in Liferay Portal 7.2.1 through 7.3.5, and Liferay DXP 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANC
nvd
CVE-2021-29044P4MEDIUMCVSS 6.1≥ 7.0.0, ≤ 7.3.52021-05-17
CVE-2021-29044 [MEDIUM] CWE-79 CVE-2021-29044: Cross-site scripting (XSS) vulnerability in the Site module's membership request administration page Cross-site scripting (XSS) vulnerability in the Site module's membership request administration pages in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_site_my_sites_
nvd
CVE-2022-26594P4MEDIUMCVSS 6.1≥ 7.3.5, < 7.3.7v7.4.02022-04-15
CVE-2022-26594 [MEDIUM] CWE-79 CVE-2022-26594: Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Lifer Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote attackers to inject arbitrary web script or HTML via a form field's help text to (1) Forms module's form builder, or (2) App Builder module's object form view's form builder.
nvd
CVE-2021-38264P4MEDIUMCVSS 6.1v7.4.0v7.4.12022-03-03
CVE-2021-38264 [MEDIUM] CVE-2021-38264: Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7 Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7.4.1 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter. This issue is caused by an incomplete fix in CVE-2021-35463.
nvd
CVE-2022-26596P4MEDIUMCVSS 6.1≥ 7.1.0, ≤ 7.3.32022-04-25
CVE-2022-26596 [MEDIUM] CWE-79 CVE-2022-26596: Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.1.0 through 7.3.3, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 8, allows remote attackers to inject arbitrary web script or HTML via web content template names.
nvd
CVE-2023-42496P4MEDIUMCVSS 6.1≥ 7.3.3, < 7.4.3.982024-02-21
CVE-2023-42496 [MEDIUM] CWE-79 CVE-2023-42496: Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Po Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_roles_admin_web_portlet_RolesAdminPortlet_tabs2
nvd
CVE-2023-42498P4MEDIUMCVSS 6.1≥ 7.4.3.8, < 7.4.3.982024-02-21
CVE-2023-42498 [MEDIUM] CWE-79 CVE-2023-42498: Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay P Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_language_override_web_internal_portlet_PLOPortlet_key paramet
nvd
CVE-2022-42110P4MEDIUMCVSS 6.1≥ 7.1.0, ≤ 7.4.22022-11-15
CVE-2022-42110 [MEDIUM] CWE-79 CVE-2022-42110: A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 throu A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML.
nvd
CVE-2022-42117P4MEDIUMCVSS 6.1≥ 7.3.2, ≤ 7.4.3.162022-10-18
CVE-2022-42117 [MEDIUM] CWE-79 CVE-2022-42117: A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 thr A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 through 7.4.3.16, and Liferay DXP 7.3 before update 6, and 7.4 before update 17 allows remote attackers to inject arbitrary web script or HTML.
nvd
CVE-2023-33938P4MEDIUMCVSS 6.1≥ 7.3.0, ≤ 7.3.7v7.4.02023-05-24
CVE-2023-33938 [MEDIUM] CWE-79 CVE-2023-33938: Cross-site scripting (XSS) vulnerability in the App Builder module's custom object details page in L Cross-site scripting (XSS) vulnerability in the App Builder module's custom object details page in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before update 14 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an App Builder custom object's `Name` field.
nvd
CVE-2023-33941P4MEDIUMCVSS 6.1≥ 7.4.3.41, ≤ 7.4.3.522023-05-24
CVE-2023-33941 [MEDIUM] CWE-79 CVE-2023-33941: Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2Provi Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.52, and Liferay DXP 7.4 update 41 through 52 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter.
nvd
CVE-2023-44311P4MEDIUMCVSS 6.1≥ 7.4.3.41, < 7.4.3.902023-10-17
CVE-2023-44311 [MEDIUM] CVE-2023-44311: Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's O Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.89, and Liferay DXP 7.4 update 41 through update 89 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter. This issue is caused by
nvd
CVE-2024-11993P4MEDIUMCVSS 6.1≥ 7.1.0, < 7.4.3.392024-12-17
CVE-2024-11993 [MEDIUM] CWE-79 CVE-2024-11993: Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Lif Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field
nvd