cbcvebase.

Liferay Portal vulnerabilities

319 known vulnerabilities affecting liferay/liferay_portal.

Total CVEs
319
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH47MEDIUM259LOW5

Vulnerabilities

Page 16 of 16
CVE-2023-37940P4MEDIUMCVSS 4.8≥ 7.0.0, < 7.4.3.882024-12-17
CVE-2023-37940 [MEDIUM] CWE-79 CVE-2023-37940: Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7. Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87, and Liferay DXP 7.4 GA through update 87, 7.3 GA through update 29, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a service access policy's `Servi
nvd
CVE-2021-33320P4MEDIUMCVSS 4.3fixed in 7.3.12021-08-03
CVE-2021-33320 [MEDIUM] CWE-770 CVE-2021-33320: The Flags module in Liferay Portal 7.3.1 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 be The Flags module in Liferay Portal 7.3.1 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20, and 7.2 before fix pack 5, does not limit the rate at which content can be flagged as inappropriate, which allows remote authenticated users to spam the site administrator with emails
nvd
CVE-2021-33330P4MEDIUMCVSS 4.3≥ 7.2.0, < 7.3.32021-08-03
CVE-2021-33330 [MEDIUM] CVE-2021-33330: Liferay Portal 7.2.0 through 7.3.2, and Liferay DXP 7.2 before fix pack 9, allows access to Cross-or Liferay Portal 7.2.0 through 7.3.2, and Liferay DXP 7.2 before fix pack 9, allows access to Cross-origin resource sharing (CORS) protected resources if the user is only authenticated using the portal session authentication, which allows remote attackers to obtain sensitive information including the targeted user’s email address and current CSRF token.
nvd
CVE-2022-26595P4MEDIUMCVSS 4.3v7.3.7v7.4.0+1 more2022-04-19
CVE-2022-26595 [MEDIUM] CWE-276 CVE-2022-26595: Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permission when accessing a list of sites/groups, which allows remote authenticated users to view sites/groups via the user's site membership assignment UI.
nvd
CVE-2024-25150P4MEDIUMCVSS 4.3fixed in 7.4.3.42024-02-20
CVE-2024-25150 [MEDIUM] CWE-201 CVE-2024-25150: Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions allows remote authenticated users to obtain a user's full name from the page's title by enumerating user screen names.
nvd
CVE-2021-33324P4MEDIUMCVSS 4.3≥ 7.1.0, < 7.3.22021-08-03
CVE-2021-33324 [MEDIUM] CWE-276 CVE-2021-33324: The Layout module in Liferay Portal 7.1.0 through 7.3.1, and Liferay DXP 7.1 before fix pack 20, and The Layout module in Liferay Portal 7.1.0 through 7.3.1, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 5, does not properly check permission of pages, which allows remote authenticated users without view permission of a page to view the page via a site's page administration.
nvd
CVE-2022-39975P4MEDIUMCVSS 4.3≥ 7.3.3, < 7.4.3.352022-09-22
CVE-2022-39975 [MEDIUM] CWE-862 CVE-2022-39975: The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before update 35 does not check user permission before showing the preview of a "Content Page" type page, allowing attackers to view unpublished "Content Page" pages via URL manipulation.
nvd
CVE-2025-62262P4MEDIUMCVSS 4.4≥ 7.0.0, < 7.4.3.982025-10-27
CVE-2025-62262 [MEDIUM] CWE-532 CVE-2025-62262: Information exposure through log file vulnerability in LDAP import feature in Liferay Portal 7.4.0 t Information exposure through log file vulnerability in LDAP import feature in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows local users to view user email address in the log files.
nvd
CVE-2025-2565P4MEDIUMCVSS 4.3≥ 7.4.0, ≤ 7.4.3.1282025-03-20
CVE-2025-2565 [MEDIUM] CWE-201 CVE-2025-2565: The data exposure vulnerability in Liferay Portal 7.4.0 through 7.4.3.126, and Liferay DXP 2024.Q3.0 The data exposure vulnerability in Liferay Portal 7.4.0 through 7.4.3.126, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92 allows an unauthorized user to obtain entry data from forms.
nvd
CVE-2025-43809P4MEDIUMCVSS 4.3≥ 7.4.0, < 7.4.3.1122025-09-19
CVE-2025-43809 [MEDIUM] CWE-352 CVE-2025-43809: Cross-Site Request Forgery (CSRF) vulnerability in the server (license) registration page in Liferay Cross-Site Request Forgery (CSRF) vulnerability in the server (license) registration page in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.9, 7.4 GA through update 92, and older unsupported versions allows remote attackers to register a server license vi
nvd
CVE-2021-33339P4MEDIUMCVSS 4.8≥ 7.2.1, < 7.3.52021-08-04
CVE-2021-33339 [MEDIUM] CWE-79 CVE-2021-33339: Cross-site scripting (XSS) vulnerability in the Fragment module in Liferay Portal 7.2.1 through 7.3. Cross-site scripting (XSS) vulnerability in the Fragment module in Liferay Portal 7.2.1 through 7.3.4, and Liferay DXP 7.2 before fix pack 9 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_site_admin_web_portlet_SiteAdminPortlet_name parameter.
nvd
CVE-2014-2963P4MEDIUMCVSS 4.3v6.1.2_ce_ga3v6.1.x_ee+1 more2014-07-10
CVE-2014-2963 [MEDIUM] CWE-79 CVE-2014-2963: Multiple cross-site scripting (XSS) vulnerabilities in group/control_panel/manage in Liferay Portal Multiple cross-site scripting (XSS) vulnerabilities in group/control_panel/manage in Liferay Portal 6.1.2 CE GA3, 6.1.X EE, and 6.2.X EE allow remote attackers to inject arbitrary web script or HTML via the (1) _2_firstName, (2) _2_lastName, or (3) _2_middleName parameter.
nvd
CVE-2011-1503P4LOWCVSS 3.5≥ 5.1.0, ≤ 5.1.2≥ 5.2.0, ≤ 5.2.3+1 more2011-05-07
CVE-2011-1503 [LOW] CWE-200 CVE-2011-1503: The XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when A The XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat or Oracle GlassFish is used, allows remote authenticated users to read arbitrary (1) XSL and (2) XML files via a file:/// URL.
nvd
CVE-2025-62245P4MEDIUMCVSS 4.3≥ 7.4.1, < 7.4.3.1132025-10-10
CVE-2025-62245 [MEDIUM] CWE-352 CVE-2025-62245: Cross-site request forgery (CSRF) vulnerability in Liferay Portal 7.4.1 through 7.4.3.112, and Lifer Cross-site request forgery (CSRF) vulnerability in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote attackers to add and edit publication comments.
nvd
CVE-2009-3742P4MEDIUMCVSS 4.3≤ 5.2.32010-01-07
CVE-2009-3742 [MEDIUM] CWE-79 CVE-2009-3742: Cross-site scripting (XSS) vulnerability in Liferay Portal before 5.3.0 allows remote attackers to i Cross-site scripting (XSS) vulnerability in Liferay Portal before 5.3.0 allows remote attackers to inject arbitrary web script or HTML via the p_p_id parameter.
nvd
CVE-2014-8349P4LOWCVSS 3.5≤ 6.22014-11-24
CVE-2014-8349 [LOW] CWE-79 CVE-2014-8349: Cross-site scripting (XSS) vulnerability in Liferay Portal Enterprise Edition (EE) 6.2 SP8 and earli Cross-site scripting (XSS) vulnerability in Liferay Portal Enterprise Edition (EE) 6.2 SP8 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the _20_body parameter in the comment field in an uploaded file.
nvd
CVE-2011-1570P4LOWCVSS 3.5≥ 6.0.0, ≤ 6.0.52011-05-07
CVE-2011-1570 [LOW] CVE-2011-1570: Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 6.x before 6.0.6 G Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to inject arbitrary web script or HTML via a message title, a different vulnerability than CVE-2004-2030.
nvd
CVE-2025-43759P4LOWCVSS 2.7≥ 7.4.0, ≤ 7.4.3.1322025-08-22
CVE-2025-43759 [LOW] CWE-732 CVE-2025-43759: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0, 2024.Q4.0 through 2024.Q4.7, 2024 Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows admin users of a virtual instance to add pages that are not in the default/main virtual instance, then any tenant can create a list o
nvd
CVE-2025-43732P4LOWCVSS 2.7≥ 7.4.0, ≤ 7.4.3.1322025-08-18
CVE-2025-43732 [LOW] CWE-639 CVE-2025-43732: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 thro Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.17 and 7.4 GA through update 92 is vulnerable to Insecure Direct Object Reference (IDOR) in the groupId parameter of the _com_liferay_roles_selector_web_
nvd