cbcvebase.

Liferay Portal vulnerabilities

319 known vulnerabilities affecting liferay/liferay_portal.

Total CVEs
319
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH47MEDIUM259LOW5

Vulnerabilities

Page 12 of 16
CVE-2022-42117P4MEDIUMCVSS 6.1≥ 7.3.2, ≤ 7.4.3.162022-10-18
CVE-2022-42117 [MEDIUM] CWE-79 CVE-2022-42117: A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 thr A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 through 7.4.3.16, and Liferay DXP 7.3 before update 6, and 7.4 before update 17 allows remote attackers to inject arbitrary web script or HTML.
nvd
CVE-2023-33941P4MEDIUMCVSS 6.1≥ 7.4.3.41, ≤ 7.4.3.522023-05-24
CVE-2023-33941 [MEDIUM] CWE-79 CVE-2023-33941: Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2Provi Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.52, and Liferay DXP 7.4 update 41 through 52 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter.
nvd
CVE-2023-44311P4MEDIUMCVSS 6.1≥ 7.4.3.41, < 7.4.3.902023-10-17
CVE-2023-44311 [MEDIUM] CVE-2023-44311: Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's O Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.89, and Liferay DXP 7.4 update 41 through update 89 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter. This issue is caused by
nvd
CVE-2023-42497P4MEDIUMCVSS 6.1≥ 7.4.3.4, < 7.4.3.862023-10-17
CVE-2023-42497 [MEDIUM] CWE-79 CVE-2023-42497: Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Por Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through 7.4.3.85, and Liferay DXP 7.4 before update 86 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_translation_web_internal_portlet_TranslationPortlet_redirect` parameter.
nvd
CVE-2024-11993P4MEDIUMCVSS 6.1≥ 7.1.0, < 7.4.3.392024-12-17
CVE-2024-11993 [MEDIUM] CWE-79 CVE-2024-11993: Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Lif Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field
nvd
CVE-2020-15840P4MEDIUMCVSS 5.3fixed in 7.3.1v6.22020-09-24
CVE-2020-15840 [MEDIUM] CVE-2020-15840: In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id.banned.paths.regexp' can be bypassed with doubled encoded URLs.
nvd
CVE-2024-25145P4MEDIUMCVSS 5.4≤ 7.2.1≥ 7.3.0, ≤ 7.3.7+1 more2024-02-07
CVE-2024-25145 [MEDIUM] CWE-79 CVE-2024-25145: Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in L Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 through 7.4.3.11, and older unsupported versions, and Liferay DXP 7.4 before update 8, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or H
nvd
CVE-2023-33942P4MEDIUMCVSS 5.4v7.4.3.502023-05-24
CVE-2023-33942 [MEDIUM] CWE-79 CVE-2023-33942: Cross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Lif Cross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Liferay Liferay Portal 7.4.3.50, and Liferay DXP 7.4 update 50 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a web content article's `Title` field.
nvd
CVE-2022-38901P4MEDIUMCVSS 5.4≥ 7.3.5, ≤ 7.4.3.282022-10-19
CVE-2022-38901 [MEDIUM] CWE-79 CVE-2022-38901: A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functional A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the description field of uploaded svg file.
nvd
CVE-2023-33939P4MEDIUMCVSS 5.4≥ 7.1.0, ≤ 7.4.3.122023-05-24
CVE-2023-33939 [MEDIUM] CWE-79 CVE-2023-33939: Cross-site scripting (XSS) vulnerability in the Modified Facet widget in Liferay Portal 7.1.0 throug Cross-site scripting (XSS) vulnerability in the Modified Facet widget in Liferay Portal 7.1.0 through 7.4.3.12, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 18, 7.3 before update 4, and 7.4 before update 9 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a facet label.
nvd
CVE-2022-28978P4MEDIUMCVSS 5.4≥ 7.0.1, < 7.4.22022-09-22
CVE-2022-28978 [MEDIUM] CWE-79 CVE-2022-28978: Stored cross-site scripting (XSS) vulnerability in the Site module's user membership administration Stored cross-site scripting (XSS) vulnerability in the Site module's user membership administration page in Liferay Portal 7.0.1 through 7.4.1, and Liferay DXP 7.0 before fix pack 102, 7.1 before fix pack 26, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the a user's name.
nvd
CVE-2022-42111P4MEDIUMCVSS 5.4≥ 7.2.1, ≤ 7.4.22022-11-15
CVE-2022-42111 [MEDIUM] CWE-79 CVE-2022-42111: A Cross-site scripting (XSS) vulnerability in the Sharing module's user notification in Liferay Port A Cross-site scripting (XSS) vulnerability in the Sharing module's user notification in Liferay Portal 7.2.1 through 7.4.2, and Liferay DXP 7.2 before fix pack 19, and 7.3 before update 4 allows remote attackers to inject arbitrary web script or HTML by sharing an asset with a crafted payload.
nvd
CVE-2023-44309P4MEDIUMCVSS 5.4≥ 7.4.2, < 7.4.3.532023-10-17
CVE-2023-44309 [MEDIUM] CWE-79 CVE-2023-44309: Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Por Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 through 7.4.3.53, and Liferay DXP 7.4 before update 54 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into any non-HTML field of a linked source asset.
nvd
CVE-2023-33943P4MEDIUMCVSS 5.4≥ 7.4.3.21, ≤ 7.4.3.622023-05-24
CVE-2023-33943 [MEDIUM] CWE-79 CVE-2023-33943: Cross-site scripting (XSS) vulnerability in the Account module in Liferay Portal 7.4.3.21 through 7. Cross-site scripting (XSS) vulnerability in the Account module in Liferay Portal 7.4.3.21 through 7.4.3.62, and Liferay DXP 7.4 update 21 through 62 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a user's (1) First Name, (2) Middle Name, (3) Last Name, or (4) Job Title text field.
nvd
CVE-2025-43737P4MEDIUMCVSS 5.4≥ 7.4.0, ≤ 7.4.3.1322025-08-19
CVE-2025-43737 [MEDIUM] CWE-79 CVE-2025-43737: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DX A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8 and 2025.Q1.0 through 2025.Q1.15 allows a remote authenticated user to inject JavaScript code via _com_liferay_journal_web_portlet_JournalPortlet_backURL parameter.
nvd
CVE-2025-43756P4MEDIUMCVSS 5.4v7.4.3.1322025-08-21
CVE-2025-43756 [MEDIUM] CWE-79 CVE-2025-43756: <!--td {border: 1px solid #cccccc;}br {mso-data-placement:same-cell;}-->A reflected cross-site scrip A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.15, 2025.Q2.0 through 2025.Q2.2 and 2024.Q1.13 through 2024.Q1.19 allows a remote authenticated user to inject JavaScript code via snippet parameter.
nvd
CVE-2025-43733P4MEDIUMCVSS 5.4v7.4.3.1322025-08-18
CVE-2025-43733 [MEDIUM] CWE-79 CVE-2025-43733: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DX A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7 allows a remote authenticated attacker to inject JavaScript code via the content page's name field. This malicious payload is then reflected and executed within the user's browser when viewing the "document View Usages" pa
nvd
CVE-2022-25146P4MEDIUMCVSS 5.3≥ 7.4.3.4, < 7.4.3.92022-03-03
CVE-2022-25146 [MEDIUM] CWE-346 CVE-2022-25146: The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 before update 5 does not check if the origin of event messages it receives matches the origin of the Remote App, allowing attackers to exfiltrate the CSRF token via a crafted event message.
nvd
CVE-2022-41414P4MEDIUMCVSS 5.3≥ 7.0.0, ≤ 7.4.22022-10-07
CVE-2022-41414 [MEDIUM] CWE-276 CVE-2022-41414: An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4 An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site names, and pages.
nvd
CVE-2021-33325P4MEDIUMCVSS 4.9fixed in 7.3.32021-08-03
CVE-2021-33325 [MEDIUM] CWE-312 CVE-2021-33325: The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19, and 7.2 before fix pack 7, user's clear text passwords are stored in the database if workflow is enabled for user creation, which allows attackers with access to the database to obtain a user's password.
nvd