cbcvebase.

Liferay Portal vulnerabilities

319 known vulnerabilities affecting liferay/liferay_portal.

Total CVEs
319
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH47MEDIUM259LOW5

Vulnerabilities

Page 14 of 16
CVE-2023-33940P4MEDIUMCVSS 5.4≥ 7.4.0, ≤ 7.4.3.302023-05-24
CVE-2023-33940 [MEDIUM] CWE-79 CVE-2023-33940: Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through 7.4.3.30, and Liferay DXP 7.4 before update 31 allows remote attackers to inject arbitrary web script or HTML via the Remote App's IFrame URL.
nvd
CVE-2022-42115P4MEDIUMCVSS 5.4≥ 7.4.3.4, < 7.4.3.372022-10-18
CVE-2022-42115 [MEDIUM] CWE-79 CVE-2022-42115: Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Portal 7.4.3.4 through 7.4.3.36 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the object field's `Label` text field.
nvd
CVE-2022-42114P4MEDIUMCVSS 5.4≥ 7.4.0, < 7.4.3.372022-10-18
CVE-2022-42114 [MEDIUM] CWE-79 CVE-2022-42114: A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.4 before update 37 allows remote attackers to inject arbitrary web script or HTML.
nvd
CVE-2022-42112P4MEDIUMCVSS 5.4≥ 7.2.0, < 7.4.3.252022-10-18
CVE-2022-42112 [MEDIUM] CWE-79 CVE-2022-42112: A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Port A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Portal 7.2.0 through 7.4.3.24, and Liferay DXP 7.2 before fix pack 19, 7.3 before update 5, and DXP 7.4 before update 25 allows remote attackers to inject arbitrary web script or HTML via a crafted payload.
nvd
CVE-2022-42119P4MEDIUMCVSS 5.4≥ 7.3.5, ≤ 7.4.22022-11-15
CVE-2022-42119 [MEDIUM] CWE-79 CVE-2022-42119: Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
nvd
CVE-2025-43737P4MEDIUMCVSS 5.4≥ 7.4.0, ≤ 7.4.3.1322025-08-19
CVE-2025-43737 [MEDIUM] CWE-79 CVE-2025-43737: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DX A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8 and 2025.Q1.0 through 2025.Q1.15 allows a remote authenticated user to inject JavaScript code via _com_liferay_journal_web_portlet_JournalPortlet_backURL parameter.
nvd
CVE-2025-43756P4MEDIUMCVSS 5.4v7.4.3.1322025-08-21
CVE-2025-43756 [MEDIUM] CWE-79 CVE-2025-43756: <!--td {border: 1px solid #cccccc;}br {mso-data-placement:same-cell;}-->A reflected cross-site scrip A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.15, 2025.Q2.0 through 2025.Q2.2 and 2024.Q1.13 through 2024.Q1.19 allows a remote authenticated user to inject JavaScript code via snippet parameter.
nvd
CVE-2023-47798P4MEDIUMCVSS 4.6≥ 7.2.0, < 7.3.02024-02-08
CVE-2023-47798 [MEDIUM] CWE-384 CVE-2023-47798: Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay D Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been locked.
nvd
CVE-2025-43782P4MEDIUMCVSS 4.3≥ 7.4.0, < 7.4.3.1252025-09-11
CVE-2025-43782 [MEDIUM] CWE-639 CVE-2025-43782: Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.7, 2024.Q1.1 through 2024.Q1.12, and 7.4 GA through update 92 allows remote authenticated users to access a workflow definition by name via the API
nvd
CVE-2025-62242P4MEDIUMCVSS 4.3≥ 7.4.1, < 7.4.3.1122025-10-13
CVE-2025-62242 [MEDIUM] CWE-639 CVE-2025-62242: Insecure Direct Object Reference (IDOR) vulnerability with account addresses in Liferay Portal 7.4.3 Insecure Direct Object Reference (IDOR) vulnerability with account addresses in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticated users to from one account to view addresses from a different account via the _com_liferay_account_
nvd
CVE-2025-62252P4MEDIUMCVSS 4.3≥ 7.1.0, < 7.4.3.1122025-10-13
CVE-2025-62252 [MEDIUM] CWE-639 CVE-2025-62252: Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote authenticated users in one virtual instance to assign an organization to a u
nvd
CVE-2025-43806P4MEDIUMCVSS 4.3≥ 7.2.0, < 7.4.3.1132025-09-22
CVE-2025-43806 [MEDIUM] CWE-863 CVE-2025-43806: Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 does not properly check permission with import and export tasks, which allows remote authenticated users to access the exported data via the REST APIs.
nvd
CVE-2019-16147P4MEDIUMCVSS 6.1fixed in 7.2.0v7.2.02019-09-09
CVE-2019-16147 [MEDIUM] CWE-79 CVE-2019-16147: Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.
nvd
CVE-2017-17868P4MEDIUMCVSS 6.1v6.1.02017-12-27
CVE-2017-17868 [MEDIUM] CWE-79 CVE-2017-17868: In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as de In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.
nvd
CVE-2017-12645P4MEDIUMCVSS 6.1≤ 7.02017-08-07
CVE-2017-12645 [MEDIUM] CWE-79 CVE-2017-12645: XSS exists in Liferay Portal before 7.0 CE GA4 via an invalid portletId. XSS exists in Liferay Portal before 7.0 CE GA4 via an invalid portletId.
nvd
CVE-2022-28982P4MEDIUMCVSS 6.1≥ 7.3.3, < 7.4.3.42022-09-22
CVE-2022-28982 [MEDIUM] CWE-79 CVE-2022-28982: A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v7.3 before service pack 3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name of a tag.
nvd
CVE-2022-28980P4MEDIUMCVSS 6.1fixed in 7.4.3.52022-09-22
CVE-2022-28980 [MEDIUM] CWE-79 CVE-2022-28980: Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal v7.4.3.4 and Liferay DXP v7.4 Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal v7.4.3.4 and Liferay DXP v7.4 GA allows attackers to execute arbitrary web scripts or HTML via parameters with the filter_ prefix.
nvd
CVE-2025-43794P4MEDIUMCVSS 4.8fixed in 7.4.3.1122025-09-15
CVE-2025-43794 [MEDIUM] CWE-79 CVE-2025-43794: Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote authenticated attackers with the instance administrator role to inject arbit
nvd
CVE-2011-1502P4MEDIUMCVSS 4.0≥ 6.0.0, ≤ 6.0.52011-05-07
CVE-2011-1502 [MEDIUM] CWE-200 CVE-2011-1502: Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to read arbitrary files via an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.
nvd
CVE-2021-33327P4MEDIUMCVSS 4.3≥ 7.2.0, < 7.3.42021-08-03
CVE-2021-33327 [MEDIUM] CWE-276 CVE-2021-33327: The Portlet Configuration module in Liferay Portal 7.2.0 through 7.3.3, and Liferay DXP 7.0 fix pack The Portlet Configuration module in Liferay Portal 7.2.0 through 7.3.3, and Liferay DXP 7.0 fix pack pack 93 and 94, 7.1 fix pack 18, and 7.2 before fix pack 8, does not properly check user permission, which allows remote authenticated users to view the Guest and User role even if "Role Visibility" is enabled.
nvd
Liferay Portal vulnerabilities | cvebase