cbcvebase.

Liferay Portal vulnerabilities

319 known vulnerabilities affecting liferay/liferay_portal.

Total CVEs
319
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH47MEDIUM259LOW5

Vulnerabilities

Page 14 of 16
CVE-2021-38269P4MEDIUMCVSS 5.4≥ 7.1.0, ≤ 7.3.6v7.4.02022-03-03
CVE-2021-38269 [MEDIUM] CWE-79 CVE-2021-38269: Cross-site scripting (XSS) vulnerability in the Gogo Shell module in Liferay Portal 7.1.0 through 7. Cross-site scripting (XSS) vulnerability in the Gogo Shell module in Liferay Portal 7.1.0 through 7.3.6 and 7.4.0, and Liferay DXP 7.1 before fix pack 23, 7.2 before fix pack 13, and 7.3 before fix pack 2 allows remote attackers to inject arbitrary web script or HTML via the output of a Gogo Shell command.
nvd
CVE-2022-26593P4MEDIUMCVSS 5.4≥ 7.3.3, < 7.3.7v7.4.02022-04-19
CVE-2022-26593 [MEDIUM] CWE-79 CVE-2022-26593: Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the name of a asset category.
nvd
CVE-2022-38902P4MEDIUMCVSS 5.4≥ 7.3.0, ≤ 7.4.02022-10-13
CVE-2022-38902 [MEDIUM] CWE-79 CVE-2022-38902: A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Lifer A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic.
nvd
CVE-2023-33940P4MEDIUMCVSS 5.4≥ 7.4.0, ≤ 7.4.3.302023-05-24
CVE-2023-33940 [MEDIUM] CWE-79 CVE-2023-33940: Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through 7.4.3.30, and Liferay DXP 7.4 before update 31 allows remote attackers to inject arbitrary web script or HTML via the Remote App's IFrame URL.
nvd
CVE-2022-42115P4MEDIUMCVSS 5.4≥ 7.4.3.4, < 7.4.3.372022-10-18
CVE-2022-42115 [MEDIUM] CWE-79 CVE-2022-42115: Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Portal 7.4.3.4 through 7.4.3.36 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the object field's `Label` text field.
nvd
CVE-2022-42114P4MEDIUMCVSS 5.4≥ 7.4.0, < 7.4.3.372022-10-18
CVE-2022-42114 [MEDIUM] CWE-79 CVE-2022-42114: A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.4 before update 37 allows remote attackers to inject arbitrary web script or HTML.
nvd
CVE-2022-42112P4MEDIUMCVSS 5.4≥ 7.2.0, < 7.4.3.252022-10-18
CVE-2022-42112 [MEDIUM] CWE-79 CVE-2022-42112: A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Port A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Portal 7.2.0 through 7.4.3.24, and Liferay DXP 7.2 before fix pack 19, 7.3 before update 5, and DXP 7.4 before update 25 allows remote attackers to inject arbitrary web script or HTML via a crafted payload.
nvd
CVE-2022-42119P4MEDIUMCVSS 5.4≥ 7.3.5, ≤ 7.4.22022-11-15
CVE-2022-42119 [MEDIUM] CWE-79 CVE-2022-42119: Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
nvd
CVE-2023-47798P4MEDIUMCVSS 4.6≥ 7.2.0, < 7.3.02024-02-08
CVE-2023-47798 [MEDIUM] CWE-384 CVE-2023-47798: Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay D Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been locked.
nvd
CVE-2025-43743P4MEDIUMCVSS 4.3≥ 7.4.0, ≤ 7.4.3.1322025-08-19
CVE-2025-43743 [MEDIUM] CWE-203 CVE-2025-43743: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 throu Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows any authenticated remote user to view other calendars by allowing them to enumerate the names of other users, gi
nvd
CVE-2025-43827P4MEDIUMCVSS 4.3≥ 7.2.0, < 7.4.3.1182025-09-30
CVE-2025-43827 [MEDIUM] CWE-639 CVE-2025-43827: Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 thro Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote authenticated users to from
nvd
CVE-2025-62252P4MEDIUMCVSS 4.3≥ 7.1.0, < 7.4.3.1122025-10-13
CVE-2025-62252 [MEDIUM] CWE-639 CVE-2025-62252: Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote authenticated users in one virtual instance to assign an organization to a u
nvd
CVE-2025-43806P4MEDIUMCVSS 4.3≥ 7.2.0, < 7.4.3.1132025-09-22
CVE-2025-43806 [MEDIUM] CWE-863 CVE-2025-43806: Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 does not properly check permission with import and export tasks, which allows remote authenticated users to access the exported data via the REST APIs.
nvd
CVE-2017-1000425P4MEDIUMCVSS 6.1fixed in 7.0.3_ga42018-01-02
CVE-2017-1000425 [MEDIUM] CWE-79 CVE-2017-1000425: Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the "movie" parameter.
nvd
CVE-2019-16147P4MEDIUMCVSS 6.1fixed in 7.2.0v7.2.02019-09-09
CVE-2019-16147 [MEDIUM] CWE-79 CVE-2019-16147: Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.
nvd
CVE-2017-12649P4MEDIUMCVSS 6.1≤ 7.02017-08-07
CVE-2017-12649 [MEDIUM] CWE-79 CVE-2017-12649: XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted title or summary that is mishandled in XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted title or summary that is mishandled in the Web Content Display.
nvd
CVE-2017-17868P4MEDIUMCVSS 6.1v6.1.02017-12-27
CVE-2017-17868 [MEDIUM] CWE-79 CVE-2017-17868: In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as de In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.
nvd
CVE-2017-12645P4MEDIUMCVSS 6.1≤ 7.02017-08-07
CVE-2017-12645 [MEDIUM] CWE-79 CVE-2017-12645: XSS exists in Liferay Portal before 7.0 CE GA4 via an invalid portletId. XSS exists in Liferay Portal before 7.0 CE GA4 via an invalid portletId.
nvd
CVE-2022-28982P4MEDIUMCVSS 6.1≥ 7.3.3, < 7.4.3.42022-09-22
CVE-2022-28982 [MEDIUM] CWE-79 CVE-2022-28982: A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v7.3 before service pack 3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name of a tag.
nvd
CVE-2022-28980P4MEDIUMCVSS 6.1fixed in 7.4.3.52022-09-22
CVE-2022-28980 [MEDIUM] CWE-79 CVE-2022-28980: Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal v7.4.3.4 and Liferay DXP v7.4 Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal v7.4.3.4 and Liferay DXP v7.4 GA allows attackers to execute arbitrary web scripts or HTML via parameters with the filter_ prefix.
nvd
Liferay Portal vulnerabilities | cvebase