cbcvebase.

Liferay Portal vulnerabilities

319 known vulnerabilities affecting liferay/liferay_portal.

Total CVEs
319
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH47MEDIUM259LOW5

Vulnerabilities

Page 3 of 16
CVE-2020-15841P3HIGHCVSS 8.8fixed in 7.3.02020-07-20
CVE-2020-15841 [HIGH] CVE-2020-15841: Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, does not safely test a connection to a LDAP server, which allows remote attackers to obtain the LDAP server's password via the Test LDAP Connection feature.
nvd
CVE-2024-26272P3HIGHCVSS 8.8≥ 7.3.2, ≤ 7.3.7≥ 7.4.0, < 7.4.3.1082024-10-22
CVE-2024-26272 [HIGH] CWE-352 CVE-2024-26272: Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 t Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 GA through update 35 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrary code
nvd
CVE-2024-25606P3HIGHCVSS 8.7fixed in 7.4.3.82024-02-20
CVE-2024-25606 [HIGH] CWE-611 CVE-2024-25606: XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Lifer XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12, 7.2 before fix pack 20, and older unsupported versions allows attackers with permission to deploy widgets/portlets/extensions to obtain sensitive information or consume system resources via the Java2Wsdd
nvd
CVE-2023-33948P3HIGHCVSS 7.5v7.4.3.672023-05-24
CVE-2023-33948 [HIGH] CWE-862 CVE-2023-33948: The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not l The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Media files which can be downloaded from a Form, which allows remote attackers to download any file from Document and Media via a crafted URL.
nvd
CVE-2025-62254P3HIGHCVSS 7.5≥ 7.4.0, ≤ 7.4.3.1112025-10-23
CVE-2025-62254 [HIGH] CWE-22 CVE-2025-62254: The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Life The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number or size of the files it will combine, which allows remote attackers to create v
nvd
CVE-2024-26273P3HIGHCVSS 8.8≥ 7.4.0, < 7.4.3.1042024-10-22
CVE-2024-26273 [HIGH] CWE-352 CVE-2024-26273: Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 t Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 update 29 through update 35 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrar
nvd
CVE-2025-43768P3HIGHCVSS 7.7≥ 7.4.0, < 7.4.3.1322025-08-23
CVE-2025-43768 [HIGH] CWE-201 CVE-2025-43768: Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 throu Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows authenticated users without any permissions to access sensitive information of admin users using JSONWS APIs.
nvd
CVE-2025-43816P3HIGHCVSS 7.5fixed in 7.4.3.1202025-09-25
CVE-2025-43816 [HIGH] CWE-401 CVE-2025-43816: A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2024.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows an attacker to cause server unavailability (denial of
nvd
CVE-2021-38266P3HIGHCVSS 7.5≤ 7.2.12022-03-02
CVE-2021-38266 [HIGH] CVE-2021-38266: The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17 and 7.2 before fix pack 5 does not correctly import users from LDAP, which allows remote attackers to prevent a legitimate user from authenticating by attempting to sign in as a user that exist in LDAP.
nvd
CVE-2021-29047P3HIGHCVSS 7.5v7.3.4v7.3.52021-05-16
CVE-2021-29047 [HIGH] CWE-287 CVE-2021-29047: The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly perform actions protected by a CAPTCHA challenge by reusing the same CAPTCHA answer.
nvd
CVE-2025-43801P3HIGHCVSS 7.5fixed in 7.4.3.1122025-09-16
CVE-2025-43801 [HIGH] CWE-606 CVE-2025-43801: Unchecked input for loop condition vulnerability in XML-RPC in Liferay Portal 7.4.0 through 7.4.3.11 Unchecked input for loop condition vulnerability in XML-RPC in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to perform a denial-of-service (DoS) attacks via a craf
nvd
CVE-2025-62250P3MEDIUMCVSS 6.5≥ 7.0.0, < 7.4.3.1322025-10-21
CVE-2025-62250 [MEDIUM] CWE-346 CVE-2025-62250: Improper Authentication in Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, a Improper Authentication in Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to send malicious data to the Liferay Portal 7.4.0 through 7.4.3.132, and older unsupport
nvd
CVE-2023-35030P3HIGHCVSS 8.8≥ 7.4.3.70, < 7.4.3.772023-06-15
CVE-2023-35030 [HIGH] CWE-352 CVE-2023-35030: Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to execute arbitrary code in the scripting console via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.
nvd
CVE-2023-33950P3HIGHCVSS 7.5≥ 7.4.3.48, ≤ 7.4.3.762023-05-24
CVE-2023-33950 [HIGH] CWE-1333 CVE-2023-33950: Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions that are vulnerable to ReDoS attacks to be used as patterns, which allows remote attackers to consume an excessive amount of server resources via crafted request URLs.
nvd
CVE-2021-33335P3HIGHCVSS 7.2≥ 7.0.3, < 7.3.52021-08-03
CVE-2021-33335 [HIGH] CWE-863 CVE-2021-33335: Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9 allows remote authenticated users with permission to update/edit users to take over a company administrator user account by editing the company administrator user.
nvd
CVE-2025-3526P3HIGHCVSS 7.5≥ 7.0.0, ≤ 7.4.3.21v6.22025-06-16
CVE-2025-3526 [HIGH] CWE-400 CVE-2025-3526: SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does not restrict the saving of request parameters in the HTTP session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP requests.
nvd
CVE-2025-62260P3HIGHCVSS 7.5≥ 7.4.0, < 7.4.3.992025-10-27
CVE-2025-62260 [HIGH] CWE-400 CVE-2025-62260: Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through u Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number of objects returned from Headless API requests, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing a reque
nvd
CVE-2025-43814P3MEDIUMCVSS 6.5≥ 7.2.0, < 7.4.3.1132025-09-22
CVE-2025-43814 [MEDIUM] CWE-201 CVE-2025-43814: In Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 In Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions the audit events records a user’s password reminder answer, which allows remote authenticated users to obtain a user’s password reminder answer
nvd
CVE-2025-43799P3MEDIUMCVSS 6.5fixed in 7.4.3.1122025-09-15
CVE-2025-43799 [MEDIUM] CWE-1393 CVE-2025-43799: Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2 Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has changed their initial password, which allows remote users to access and edit content via
nvd
CVE-2025-62261P3MEDIUMCVSS 6.5≥ 7.0.0, < 7.4.3.1002025-10-27
CVE-2025-62261 [MEDIUM] CWE-312 CVE-2025-62261: Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 thr Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 34, and older unsupported versions stores password reset tokens in plain text, which allows attackers with access to the database to obtain the token, reset a user’s password and take ove
nvd
Liferay Portal vulnerabilities | cvebase