Liferay Portal vulnerabilities
319 known vulnerabilities affecting liferay/liferay_portal.
Total CVEs
319
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH47MEDIUM259LOW5
Vulnerabilities
Page 2 of 16
CVE-2018-10795P3HIGHCVSS 8.8≤ 6.2.52018-05-07
CVE-2018-10795 [HIGH] CWE-434 CVE-2018-10795: Liferay 6.2.x and before has an FCKeditor configuration that allows an attacker to upload or transfe
Liferay 6.2.x and before has an FCKeditor configuration that allows an attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment via a browser/liferay/browser.html?Type= or html/js/editor/fckeditor/editor/filemanager/browser/liferay/browser.html URI. NOTE: the vendor disputes this issu
nvd
CVE-2022-42118P4MEDIUMCVSS 6.1PoC≥ 7.1.0, ≤ 7.4.22022-11-15
CVE-2022-42118 [MEDIUM] CWE-79 CVE-2022-42118: A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 throu
A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the `tag` parameter.
nvd
CVE-2019-6588P4MEDIUMCVSS 4.7PoC≤ 6.0.6v6.1.0+16 more2019-06-03
CVE-2019-6588 [MEDIUM] CWE-79 CVE-2019-6588: In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custo
In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call " /> or " />. Liferay Portal out-of-the-box behavior with no customizations is not vulnerable.
nvd
CVE-2025-43813P3HIGHCVSS 8.2≥ 7.3.0, ≤ 7.3.7≥ 7.4.0, < 7.4.3.1082025-09-29
CVE-2025-43813 [HIGH] CWE-22 CVE-2025-43813: Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.
Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.107, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to access arbitrar
nvd
CVE-2025-43790P3HIGHCVSS 8.1≥ 7.4.0, < 7.4.3.1242025-09-11
CVE-2025-43790 [HIGH] CWE-639 CVE-2025-43790: Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and
Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.6, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows remote authenticated users to from one virtual instance to access, create, edit, relate data/object entries/definitions to an object in a differen
nvd
CVE-2020-28885P3HIGHCVSS 7.2v7.2v7.3.52022-01-28
CVE-2020-28885 [HIGH] CWE-78 CVE-2020-28885: Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An adminis
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject commands through the Gogo Shell module to execute any OS command on the Liferay Portal Sever. NOTE: The developer disputes this as a vulnerability since it is a feature for administrators to access and execute commands in Gogo Shel
nvd
CVE-2022-42122P3CRITICALCVSS 9.8v7.3.72022-11-15
CVE-2022-42122 [CRITICAL] CWE-89 CVE-2022-42122: A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.
nvd
CVE-2025-3586P3HIGHCVSS 7.2≥ 7.4.3.27, < 7.4.3.432025-09-01
CVE-2025-3586 [HIGH] CWE-863 CVE-2025-3586: In Liferay Portal 7.4.3.27 through 7.4.3.42, and Liferay DXP 2024.Q1.1 through 2024.Q1.20, 2023.Q4.0
In Liferay Portal 7.4.3.27 through 7.4.3.42, and Liferay DXP 2024.Q1.1 through 2024.Q1.20, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 27 through update 42 (Liferay PaaS, and Liferay Self-Hosted), the Objects module does not restrict the use of Groovy scripts in Object actions for Admin Users. This allows remote authenticated
nvd
CVE-2023-33945P3HIGHCVSS 8.1≥ 7.3.1, ≤ 7.3.7≥ 7.4.0, ≤ 7.4.3.172023-05-24
CVE-2023-33945 [HIGH] CWE-89 CVE-2023-33945: SQL injection vulnerability in the upgrade process for SQL Server in Liferay Portal 7.3.1 through 7.
SQL injection vulnerability in the upgrade process for SQL Server in Liferay Portal 7.3.1 through 7.4.3.17, and Liferay DXP 7.3 before update 6, and 7.4 before update 18 allows attackers to execute arbitrary SQL commands via the name of a database table's primary key index. This vulnerability is only exploitable when chained with other attacks. To expl
nvd
CVE-2020-28884P3HIGHCVSS 7.2v7.2v7.3.52022-01-28
CVE-2020-28884 [HIGH] CWE-78 CVE-2020-28884: Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An adminis
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject Groovy script to execute any OS command on the Liferay Portal Sever. NOTE: The developer disputes this as a vulnerability since it is a feature for administrators to run groovy scripts and therefore not a design flaw.
nvd
CVE-2024-25148P3HIGHCVSS 8.1≥ 7.2.0, ≤ 7.4.12024-02-08
CVE-2024-25148 [HIGH] CWE-201 CVE-2024-25148: In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before se
In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions the `doAsUserId` URL parameter may get leaked when creating linked content using the WYSIWYG editor and while impersonating a user. This may allow remote authenticated users to imperso
nvd
CVE-2021-33321P3HIGHCVSS 7.5≥ 6.2.3, < 7.3.32021-08-03
CVE-2021-33321 [HIGH] CWE-640 CVE-2021-33321: Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, al
Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enumerate user email address via the forgot password functionality. The portal.property login.secure.forgot.password should be defaulted to true.
nvd
CVE-2025-43793P3HIGHCVSS 7.5fixed in 7.4.3.1062025-09-15
CVE-2025-43793 [HIGH] CWE-1284 CVE-2025-43793: Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2
Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions may incorrectly identify the subdomain of a domain name and create a supercookie, which allows remote attackers who control a website that sh
nvd
CVE-2020-15842P3HIGHCVSS 8.1fixed in 7.3.02020-07-20
CVE-2020-15842 [HIGH] CWE-502 CVE-2020-15842: Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2
Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, allows man-in-the-middle attackers to execute arbitrary code via crafted serialized payloads, because of insecure deserialization.
nvd
CVE-2021-33323P3HIGHCVSS 7.5≥ 7.1.0, < 7.3.12021-08-03
CVE-2021-33323 [HIGH] CWE-312 CVE-2021-33323: The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fi
The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, autosaves form values for unauthenticated users, which allows remote attackers to view the autosaved values by viewing the form as an unauthenticated user.
nvd
CVE-2024-26271P3HIGHCVSS 8.8≥ 7.4.3.75, < 7.4.3.1122024-10-22
CVE-2024-26271 [HIGH] CWE-352 CVE-2024-26271: Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75
Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 update 75 through update 92 and 7.3 update 32 through update 36 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute a
nvd
CVE-2021-33322P3HIGHCVSS 7.5fixed in 7.3.12021-08-03
CVE-2021-33322 [HIGH] CWE-613 CVE-2021-33322: In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 18,
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 18, and 7.2 before fix pack 5, password reset tokens are not invalidated after a user changes their password, which allows remote attackers to change the user’s password via the old password reset token.
nvd
CVE-2022-28981P3HIGHCVSS 7.5≥ 7.4.0, ≤ 7.4.22022-09-22
CVE-2022-28981 [HIGH] CWE-22 CVE-2022-28981: Path traversal vulnerability in the Hypermedia REST APIs module in Liferay Portal 7.4.0 through 7.4.
Path traversal vulnerability in the Hypermedia REST APIs module in Liferay Portal 7.4.0 through 7.4.2 allows remote attackers to access files outside of com.liferay.headless.discovery.web/META-INF/resources via the `parameter` parameter.
nvd
CVE-2023-33949P3HIGHCVSS 7.5≥ 7.0.0, ≤ 7.0.6≥ 7.1.0, ≤ 7.1.3+2 more2023-05-24
CVE-2023-33949 [HIGH] CWE-1188 CVE-2023-33949: In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which allows remote attackers to create accounts using fake email addresses or email addresses which they don't control. The portal property `company.security.strangers.verify` should be set to true.
nvd
CVE-2024-25607P3HIGHCVSS 7.5≤ 7.4.3.152024-02-20
CVE-2024-25607 [HIGH] CWE-916 CVE-2024-25607: The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15,
The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions defaults to a low work factor, which allows attackers to quickly crack password hashes.
nvd