cbcvebase.

Liferay Portal vulnerabilities

319 known vulnerabilities affecting liferay/liferay_portal.

Total CVEs
319
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH47MEDIUM259LOW5

Vulnerabilities

Page 4 of 16
CVE-2022-42124P3HIGHCVSS 7.5≥ 7.3.2, < 7.4.3.52022-11-15
CVE-2022-42124 [HIGH] CWE-1333 CVE-2022-42124: ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 through 7.4.3.4 ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 through 7.4.3.4 and Liferay DXP 7.2 fix pack 9 through fix pack 18, 7.3 before update 4, and DXP 7.4 GA allows remote attackers to consume an excessive amount of server resources via a crafted payload injected into the 'name' field of a layout prototype.
nvd
CVE-2022-42123P3HIGHCVSS 7.5≥ 7.3.3, < 7.4.3.192022-11-15
CVE-2022-42123 [HIGH] CWE-22 CVE-2022-42123: A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, an A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin.
nvd
CVE-2025-3602P3HIGHCVSS 7.5≥ 7.4.0, ≤ 7.4.3.972025-06-16
CVE-2025-3602 [HIGH] CWE-400 CVE-2025-3602: Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through u Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through update 35, and 7.2 fix pack 8 through fix pack 20 does not limit the depth of a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing complex queries.
nvd
CVE-2025-43796P3HIGHCVSS 7.5≥ 7.4.0, < 7.4.3.1022025-09-12
CVE-2025-43796 [HIGH] CWE-400 CVE-2025-43796: Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA though update 35 does not limit the number of objects returned from a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing queries that return a large number of obj
nvd
CVE-2020-24554P3HIGHCVSS 7.5fixed in 7.3.32020-09-01
CVE-2020-24554 [HIGH] CWE-601 CVE-2020-24554: The redirect module in Liferay Portal before 7.3.3 does not limit the number of URLs resulting in a The redirect module in Liferay Portal before 7.3.3 does not limit the number of URLs resulting in a 404 error that is recorded, which allows remote attackers to perform a denial of service attack by making repeated requests for pages that do not exist.
nvd
CVE-2022-42125P3HIGHCVSS 7.5≥ 7.4.3.5, < 7.4.3.362022-11-15
CVE-2022-42125 [HIGH] CWE-22 CVE-2022-42125: Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows attackers to create or overwrite existing files on the filesystem via the deployment of a malicious plugin/module.
nvd
CVE-2025-43750P3MEDIUMCVSS 6.5≥ 7.4.0, ≤ 7.4.3.1322025-08-20
CVE-2025-43750 [MEDIUM] CWE-434 CVE-2025-43750: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 throu Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows remote unauthenticated users (guests) to upload files via the form attachment field without proper validation, e
nvd
CVE-2025-43825P3MEDIUMCVSS 6.5≥ 7.4.0, ≤ 7.4.3.1322025-10-03
CVE-2025-43825 [MEDIUM] CWE-201 CVE-2025-43825: A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1 A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows sensitive user data to be includ
nvd
CVE-2025-62247P3MEDIUMCVSS 6.5≥ 7.4.0, ≤ 7.4.3.1322025-10-22
CVE-2025-62247 [MEDIUM] CWE-862 CVE-2025-62247: Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132 Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 allows instance users to read and select unauthorized Bl
nvd
CVE-2025-62258P3MEDIUMCVSS 6.5≥ 7.4.0, < 7.4.3.1082025-10-27
CVE-2025-62258 [MEDIUM] CWE-352 CVE-2025-62258: CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to execute any Headless API via the `endpoint` parameter.
nvd
CVE-2025-43763P3MEDIUMCVSS 6.5≥ 7.4.0, < 7.4.3.1322025-09-09
CVE-2025-43763 [MEDIUM] CWE-918 CVE-2025-43763: A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3. A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20 that affects custom object attachment fields. This flaw allows an attacker to manipulate the application into m
nvd
CVE-2024-26265P3MEDIUMCVSS 6.5≤ 7.3.7≥ 7.4.0, < 7.4.3.162024-02-20
CVE-2024-26265 [MEDIUM] CWE-770 CVE-2024-26265: The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions relies on a request parameter to limit the size of files that can be uploaded, which allows remote authenticated users to upload arbitrari
nvd
CVE-2024-25604P3MEDIUMCVSS 6.5fixed in 7.4.3.52024-02-20
CVE-2024-25604 [MEDIUM] CWE-863 CVE-2024-25604: Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 be Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions does not properly check user permissions, which allows remote authenticated users with the VIEW user permission to edit their own permission via the User and Organizations sec
nvd
CVE-2025-43752P3MEDIUMCVSS 6.5≥ 7.4.0, ≤ 7.4.3.1322025-08-22
CVE-2025-43752 [MEDIUM] CWE-770 CVE-2025-43752: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 throu Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allow users to upload an unlimited amount of files through the object entries attachment fields, the files are stored i
nvd
CVE-2025-62251P3MEDIUMCVSS 6.5≥ 7.3.0, < 7.4.3.1192025-10-13
CVE-2025-62251 [MEDIUM] CWE-732 CVE-2025-62251: Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 throu Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA through update 92 and 7.3 GA though update 36 shows content to users who do not have permission to view it via the Menu Display Widget. This security flaw could result in sensitive information being exposed to unauthorized users.
nvd
CVE-2025-43784P3MEDIUMCVSS 6.5≥ 7.4.0, < 7.4.3.1252025-09-10
CVE-2025-43784 [MEDIUM] CWE-863 CVE-2025-43784: Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 20 Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.8, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows guest users to obtain object entries information via the API Builder.
nvd
CVE-2020-13444P3MEDIUMCVSS 6.5v7.1v7.1.1+2 more2020-06-10
CVE-2020-13444 [MEDIUM] CVE-2020-13444: Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data Providers.
nvd
CVE-2021-38268P3MEDIUMCVSS 6.5≥ 7.0.0, < 7.3.72022-03-02
CVE-2021-38268 [MEDIUM] CWE-276 CVE-2021-38268: The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fi The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 2 incorrectly sets default permissions for site members, which allows remote authenticated users with the site member role to add and duplicate forms, via the UI or the
nvd
CVE-2025-43762P3MEDIUMCVSS 6.5≥ 7.4.0, ≤ 7.4.3.1322025-08-22
CVE-2025-43762 [MEDIUM] CWE-770 CVE-2025-43762: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 throu Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allow users to upload an unlimited amount of files through the forms, the files are stored in the document_library allo
nvd
CVE-2021-33333P3MEDIUMCVSS 6.3fixed in 7.3.32021-08-03
CVE-2021-33333 [MEDIUM] CWE-276 CVE-2021-33333: The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19 and 7.2 before fix pack 6, does not properly check user permission, which allows remote authenticated users to view and delete workflow submissions via crafted URLs.
nvd