Liferay Portal vulnerabilities
319 known vulnerabilities affecting liferay/liferay_portal.
Total CVEs
319
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH47MEDIUM259LOW5
Vulnerabilities
Page 13 of 16
CVE-2025-43782P4MEDIUMCVSS 4.3≥ 7.4.0, < 7.4.3.1252025-09-11
CVE-2025-43782 [MEDIUM] CWE-639 CVE-2025-43782: Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and
Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.7, 2024.Q1.1 through 2024.Q1.12, and 7.4 GA through update 92 allows remote authenticated users to access a workflow definition by name via the API
nvd
CVE-2025-62242P4MEDIUMCVSS 4.3≥ 7.4.1, < 7.4.3.1122025-10-13
CVE-2025-62242 [MEDIUM] CWE-639 CVE-2025-62242: Insecure Direct Object Reference (IDOR) vulnerability with account addresses in Liferay Portal 7.4.3
Insecure Direct Object Reference (IDOR) vulnerability with account addresses in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticated users to from one account to view addresses from a different account via the _com_liferay_account_
nvd
CVE-2025-43803P4MEDIUMCVSS 4.3≥ 7.4.0, < 7.4.3.1202025-09-19
CVE-2025-43803 [MEDIUM] CWE-639 CVE-2025-43803: Insecure direct object reference (IDOR) vulnerability in the Contacts Center widget in Liferay Porta
Insecure direct object reference (IDOR) vulnerability in the Contacts Center widget in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.6, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote attackers to view contact information, includi
nvd
CVE-2021-33326P4MEDIUMCVSS 6.1fixed in 7.3.52021-08-03
CVE-2021-33326 [MEDIUM] CWE-79 CVE-2021-33326: Cross-site scripting (XSS) vulnerability in the Frontend JS module in Liferay Portal 7.3.4 and earli
Cross-site scripting (XSS) vulnerability in the Frontend JS module in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20 and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the title of a modal window.
nvd
CVE-2021-29048P4MEDIUMCVSS 6.1v7.3.4v7.3.52021-05-17
CVE-2021-29048 [MEDIUM] CWE-79 CVE-2021-29048: Cross-site scripting (XSS) vulnerability in the Layout module's page administration page in Liferay
Cross-site scripting (XSS) vulnerability in the Layout module's page administration page in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.2 before fix pack 11 and 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_layout_admin_web_portlet_GroupPagesPortlet_name parameter.
nvd
CVE-2021-29046P4MEDIUMCVSS 6.1v7.3.52021-05-17
CVE-2021-29046 [MEDIUM] CWE-79 CVE-2021-29046: Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Life
Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_asset_categories_admin_web_portlet_AssetCategoriesAdminPortlet_title parameter.
nvd
CVE-2021-33337P4MEDIUMCVSS 6.1≥ 7.3.0, ≤ 7.3.42021-08-04
CVE-2021-33337 [MEDIUM] CWE-79 CVE-2021-33337: Cross-site scripting (XSS) vulnerability in the Document Library module's add document menu in Lifer
Cross-site scripting (XSS) vulnerability in the Document Library module's add document menu in Liferay Portal 7.3.0 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_document_library_web_portlet_DLAdminPortlet_name parameter.
nvd
CVE-2021-29045P4MEDIUMCVSS 6.1≥ 7.3.2, ≤ 7.3.52021-05-17
CVE-2021-29045 [MEDIUM] CWE-79 CVE-2021-29045: Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in
Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Liferay Portal 7.3.2 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_redirect_web_internal_portlet_RedirectPortlet_destinationURL parameter.
nvd
CVE-2021-35463P4MEDIUMCVSS 6.1v7.4.02021-08-04
CVE-2021-35463 [MEDIUM] CWE-79 CVE-2021-35463: Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 allow
Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter.
nvd
CVE-2017-12648P4MEDIUMCVSS 6.1≤ 7.02017-08-07
CVE-2017-12648 [MEDIUM] CWE-79 CVE-2017-12648: XSS exists in Liferay Portal before 7.0 CE GA4 via a bookmark URL.
XSS exists in Liferay Portal before 7.0 CE GA4 via a bookmark URL.
nvd
CVE-2017-12646P4MEDIUMCVSS 6.1≤ 7.02017-08-07
CVE-2017-12646 [MEDIUM] CWE-79 CVE-2017-12646: XSS exists in Liferay Portal before 7.0 CE GA4 via a login name, password, or e-mail address.
XSS exists in Liferay Portal before 7.0 CE GA4 via a login name, password, or e-mail address.
nvd
CVE-2021-29039P4MEDIUMCVSS 6.1v7.3.42021-05-16
CVE-2021-29039 [MEDIUM] CWE-79 CVE-2021-29039: Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Lif
Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 7.3.4 allows remote attackers to inject arbitrary web script or HTML via the site name.
nvd
CVE-2022-26597P4MEDIUMCVSS 6.1≥ 7.3.0, ≤ 7.4.02022-04-25
CVE-2022-26597 [MEDIUM] CWE-79 CVE-2022-26597: Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Po
Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the site name.
nvd
CVE-2023-47797P4MEDIUMCVSS 6.1≥ 7.4.3.94, ≤ 7.4.3.952023-11-17
CVE-2023-47797 [MEDIUM] CWE-79 CVE-2023-47797: Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7
Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95 allows remote attackers to inject arbitrary web script or HTML via the `p_l_back_url_title` parameter.
nvd
CVE-2022-42113P4MEDIUMCVSS 6.1≥ 7.4.3.30, < 7.4.3.372022-10-18
CVE-2022-42113 [MEDIUM] CWE-79 CVE-2022-42113: A Cross-site scripting (XSS) vulnerability in Document Library module in Liferay Portal 7.4.3.30 thr
A Cross-site scripting (XSS) vulnerability in Document Library module in Liferay Portal 7.4.3.30 through 7.4.3.36, and Liferay DXP 7.4 update 30 through update 36 allows remote attackers to inject arbitrary web script or HTML via the `redirect` parameter.
nvd
CVE-2022-28979P4MEDIUMCVSS 6.1≥ 7.1.0, < 7.4.3.42022-09-22
CVE-2022-28979 [MEDIUM] CWE-79 CVE-2022-28979: Liferay Portal v7.1.0 through v7.4.2 and Liferay DXP 7.1 before fix pack 26, 7.2 before fix pack 15,
Liferay Portal v7.1.0 through v7.4.2 and Liferay DXP 7.1 before fix pack 26, 7.2 before fix pack 15, and 7.3 before service pack 3 was discovered to contain a cross-site scripting (XSS) vulnerability in the Portal Search module's Custom Facet widget. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in
nvd
CVE-2021-33336P4MEDIUMCVSS 5.4≥ 7.3.0, < 7.3.42021-08-04
CVE-2021-33336 [MEDIUM] CWE-79 CVE-2021-33336: Cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal
Cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal 7.3.0 through 7.3.3, and Liferay DXP 7.1 fix pack 18, and 7.2 fix pack 5 through 7, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_journal_web_portlet_JournalPortlet_name parameter.
nvd
CVE-2021-33328P4MEDIUMCVSS 5.4≥ 7.0.0, < 7.3.52021-08-03
CVE-2021-33328 [MEDIUM] CWE-79 CVE-2021-33328: Cross-site scripting (XSS) vulnerability in the Asset module's edit vocabulary page in Liferay Porta
Cross-site scripting (XSS) vulnerability in the Asset module's edit vocabulary page in Liferay Portal 7.0.0 through 7.3.4, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20, and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the (1) _com_liferay_journal_web_portlet_JournalPortlet_name or (2) _co
nvd
CVE-2021-38267P4MEDIUMCVSS 5.4≥ 7.3.2, ≤ 7.3.62022-03-03
CVE-2021-38267 [MEDIUM] CWE-79 CVE-2021-38267: Cross-site scripting (XSS) vulnerability in the Blogs module's edit blog entry page in Liferay Porta
Cross-site scripting (XSS) vulnerability in the Blogs module's edit blog entry page in Liferay Portal 7.3.2 through 7.3.6, and Liferay DXP 7.3 before fix pack 2 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_blogs_web_portlet_BlogsAdminPortlet_title and _com_liferay_blogs_web_portlet_BlogsAdminPortlet_subtitle par
nvd
CVE-2021-38265P4MEDIUMCVSS 5.4≥ 7.3.4, ≤ 7.3.62022-03-03
CVE-2021-38265 [MEDIUM] CWE-79 CVE-2021-38265: Cross-site scripting (XSS) vulnerability in the Asset module in Liferay Portal 7.3.4 through 7.3.6 a
Cross-site scripting (XSS) vulnerability in the Asset module in Liferay Portal 7.3.4 through 7.3.6 allow remote attackers to inject arbitrary web script or HTML when creating a collection page via the _com_liferay_asset_list_web_portlet_AssetListPortlet_title parameter.
nvd