cbcvebase.

Liferay Portal vulnerabilities

319 known vulnerabilities affecting liferay/liferay_portal.

Total CVEs
319
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH47MEDIUM259LOW5

Vulnerabilities

Page 11 of 16
CVE-2025-43731P4MEDIUMCVSS 5.4≥ 7.4.0, ≤ 7.4.3.1322025-08-18
CVE-2025-43731 [MEDIUM] CWE-79 CVE-2025-43731: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.8, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.16 and 7.4 GA through update 92 allows an remote authenticated user to inject JavaScript in m
nvd
CVE-2025-43734P4MEDIUMCVSS 5.4≥ 7.4.0, ≤ 7.4.3.1322025-08-12
CVE-2025-43734 [MEDIUM] CWE-79 CVE-2025-43734: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.16 and 7.4 GA through update 92 allows a remote authenticated attacker to inject JavaScript
nvd
CVE-2025-43741P4MEDIUMCVSS 5.4≥ 7.4.0, ≤ 7.4.3.1322025-08-20
CVE-2025-43741 [MEDIUM] CWE-79 CVE-2025-43741: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.3, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows an remote authenticated attacker to inject JavaScrip i
nvd
CVE-2025-43738P4MEDIUMCVSS 5.4≥ 7.4.0, ≤ 7.4.3.1322025-08-19
CVE-2025-43738 [MEDIUM] CWE-79 CVE-2025-43738: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.19 allows a remote authenticated user to inject JavaScript c
nvd
CVE-2025-62240P4MEDIUMCVSS 5.4≥ 7.4.3.35, < 7.4.3.1122025-10-09
CVE-2025-62240 [MEDIUM] CWE-79 CVE-2025-62240: Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 update 35 through update 92, and 7.3 update 25 through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injecte
nvd
CVE-2025-43821P4MEDIUMCVSS 5.4≥ 7.4.0, < 7.4.3.1122025-10-08
CVE-2025-43821 [MEDIUM] CWE-79 CVE-2025-43821: Cross-site scripting (XSS) vulnerability in the Commerce Product Comparison Table widget in Liferay Cross-site scripting (XSS) vulnerability in the Commerce Product Comparison Table widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Commerce Product'
nvd
CVE-2025-43823P4MEDIUMCVSS 5.4≥ 7.4.0, < 7.4.3.1122025-10-07
CVE-2025-43823 [MEDIUM] CWE-79 CVE-2025-43823: Cross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4. Cross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 2023.Q4 before patch 6, 2023.Q3 before patch 9, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Commerce Product's Name text field.
nvd
CVE-2025-43753P4MEDIUMCVSS 5.4≥ 7.4.3.32, ≤ 7.4.3.1322025-08-21
CVE-2025-43753 [MEDIUM] CWE-79 CVE-2025-43753: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.32 through 7.4.3.13 A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.32 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.16 and 7.4 update 32 through update 92 allows an remote authenticated user to inject Java
nvd
CVE-2025-43771P4MEDIUMCVSS 5.4≥ 7.4.3.102, < 7.4.3.1122025-10-08
CVE-2025-43771 [MEDIUM] CWE-79 CVE-2025-43771: Multiple cross-site scripting (XSS) vulnerabilities in the Notifications widget in Liferay Portal 7. Multiple cross-site scripting (XSS) vulnerabilities in the Notifications widget in Liferay Portal 7.4.3.102 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5 and 2023.Q3.1 through 2023.Q3.10 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into (1) a user’s “First Name” text field, (2) a user’s
nvd
CVE-2025-43812P4MEDIUMCVSS 5.4≥ 7.4.3.4, < 7.4.3.1122025-09-29
CVE-2025-43812 [MEDIUM] CWE-79 CVE-2025-43812: Cross-site scripting (XSS) vulnerability in web content template in Liferay Portal 7.4.3.4 through 7 Cross-site scripting (XSS) vulnerability in web content template in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into a web content structure's Name
nvd
CVE-2025-43820P4MEDIUMCVSS 5.4≥ 7.4.3.35, < 7.4.3.1112025-09-29
CVE-2025-43820 [MEDIUM] CWE-79 CVE-2025-43820: Multiple cross-site scripting (XSS) vulnerabilities in the Calendar widget when inviting users to a Multiple cross-site scripting (XSS) vulnerabilities in the Calendar widget when inviting users to a event in Liferay Portal 7.4.3.35 through 7.4.3.110, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.6, 7.4 update 35 through update 92, and 7.3 update 25 through update 35 allow remote attackers to inject arbitrary web script or H
nvd
CVE-2021-38263P4MEDIUMCVSS 6.1≤ 7.3.22022-03-03
CVE-2021-38263 [MEDIUM] CWE-79 CVE-2021-38263: Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3 Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 20 and 7.2 before fix pack 10 allows remote attackers to inject arbitrary web script or HTML via the output of a script.
nvd
CVE-2021-33332P4MEDIUMCVSS 6.1≥ 7.1.0, < 7.3.32021-08-03
CVE-2021-33332 [MEDIUM] CWE-79 CVE-2021-33332: Cross-site scripting (XSS) vulnerability in the Portlet Configuration module in Liferay Portal 7.1.0 Cross-site scripting (XSS) vulnerability in the Portlet Configuration module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portlet_configuration_css_web_portlet_PortletConfigurationCSSPortlet_portletResource
nvd
CVE-2021-29051P4MEDIUMCVSS 6.1≥ 7.2.0, ≤ 7.3.52021-05-17
CVE-2021-29051 [MEDIUM] CWE-79 CVE-2021-29051: Cross-site scripting (XSS) vulnerability in the Asset module's Asset Publisher app in Liferay Portal Cross-site scripting (XSS) vulnerability in the Asset module's Asset Publisher app in Liferay Portal 7.2.1 through 7.3.5, and Liferay DXP 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANC
nvd
CVE-2021-29044P4MEDIUMCVSS 6.1≥ 7.0.0, ≤ 7.3.52021-05-17
CVE-2021-29044 [MEDIUM] CWE-79 CVE-2021-29044: Cross-site scripting (XSS) vulnerability in the Site module's membership request administration page Cross-site scripting (XSS) vulnerability in the Site module's membership request administration pages in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_site_my_sites_
nvd
CVE-2021-38264P4MEDIUMCVSS 6.1v7.4.0v7.4.12022-03-03
CVE-2021-38264 [MEDIUM] CVE-2021-38264: Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7 Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7.4.1 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter. This issue is caused by an incomplete fix in CVE-2021-35463.
nvd
CVE-2022-26596P4MEDIUMCVSS 6.1≥ 7.1.0, ≤ 7.3.32022-04-25
CVE-2022-26596 [MEDIUM] CWE-79 CVE-2022-26596: Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.1.0 through 7.3.3, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 8, allows remote attackers to inject arbitrary web script or HTML via web content template names.
nvd
CVE-2022-26594P4MEDIUMCVSS 6.1≥ 7.3.5, < 7.3.7v7.4.02022-04-15
CVE-2022-26594 [MEDIUM] CWE-79 CVE-2022-26594: Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Lifer Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote attackers to inject arbitrary web script or HTML via a form field's help text to (1) Forms module's form builder, or (2) App Builder module's object form view's form builder.
nvd
CVE-2022-42110P4MEDIUMCVSS 6.1≥ 7.1.0, ≤ 7.4.22022-11-15
CVE-2022-42110 [MEDIUM] CWE-79 CVE-2022-42110: A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 throu A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML.
nvd
CVE-2023-33938P4MEDIUMCVSS 6.1≥ 7.3.0, ≤ 7.3.7v7.4.02023-05-24
CVE-2023-33938 [MEDIUM] CWE-79 CVE-2023-33938: Cross-site scripting (XSS) vulnerability in the App Builder module's custom object details page in L Cross-site scripting (XSS) vulnerability in the App Builder module's custom object details page in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before update 14 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an App Builder custom object's `Name` field.
nvd
Liferay Portal vulnerabilities | cvebase