cbcvebase.

Liferay Portal vulnerabilities

319 known vulnerabilities affecting liferay/liferay_portal.

Total CVEs
319
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH47MEDIUM259LOW5

Vulnerabilities

Page 5 of 16
CVE-2025-43819P3MEDIUMCVSS 6.5≥ 7.4.3.121, < 7.4.3.1322025-09-24
CVE-2025-43819 [MEDIUM] CWE-613 CVE-2025-43819: A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, a A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, and 2024.Q1.1 through 2024.Q1.12 is allow an remote non-authenticated attacker to reuse old user session by SLO API
nvd
CVE-2025-43764P4MEDIUMCVSS 6.5≥ 7.4.0, < 7.4.3.1322025-08-23
CVE-2025-43764 [MEDIUM] CWE-1333 CVE-2025-43764: Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Design Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScript in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.1, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20 and 7.4 GA through update 92, which allows authenti
nvd
CVE-2022-45320P3MEDIUMCVSS 6.3fixed in 7.4.3.162024-02-20
CVE-2022-45320 [MEDIUM] CWE-284 CVE-2022-45320: Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users to become the owner of a wiki page by editing the wiki page.
nvd
CVE-2025-62257P4MEDIUMCVSS 5.3≥ 7.4.0, < 7.4.3.1202025-10-30
CVE-2025-62257 [MEDIUM] CWE-307 CVE-2025-62257: Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote attackers to determine a user’s password even if account lockout i
nvd
CVE-2020-15839P4MEDIUMCVSS 6.5fixed in 7.3.32020-09-22
CVE-2020-15839 [MEDIUM] CWE-434 CVE-2020-15839: Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.
nvd
CVE-2025-62259P3MEDIUMCVSS 5.4fixed in 7.4.3.1102025-10-27
CVE-2025-62259 [MEDIUM] CWE-863 CVE-2025-62259: Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 th Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has verified their email address, which allows remote users to access and edit content via the API.
nvd
CVE-2025-62256P4MEDIUMCVSS 5.3≥ 7.4.0, < 7.4.3.1102025-10-23
CVE-2025-62256 [MEDIUM] CWE-862 CVE-2025-62256: Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 throu Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not properly restrict access to OpenAPI in certain circumstances, which allows remote attackers to access the OpenAPI YAML file via a crafted URL.
nvd
CVE-2024-25144P4MEDIUMCVSS 6.5≥ 7.2.0, < 7.4.3.262024-02-08
CVE-2024-25144 [MEDIUM] CWE-835 CVE-2024-25144: The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Life The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 6, 7.2 before fix pack 19, and older unsupported versions does not check the URL of the IFrame, which allows remote authenticated users to cause a denial-of-service (DoS) via a self referencing IFrame.
nvd
CVE-2025-43745P4MEDIUMCVSS 6.5≥ 7.4.0, ≤ 7.4.3.1322025-08-19
CVE-2025-43745 [MEDIUM] CWE-352 CVE-2025-43745: A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 20 A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 and 7.4 GA through update 92 allows remote attackers to performs cross-origin request on behal
nvd
CVE-2025-43792P4MEDIUMCVSS 5.3fixed in 7.4.3.1062025-09-15
CVE-2025-43792 [MEDIUM] CWE-15 CVE-2025-43792: Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Lifera Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not properly obtain the remote address of the live site from the database which, which allows remote authenticated use
nvd
CVE-2024-25143P4MEDIUMCVSS 6.5fixed in 7.2.0≥ 7.2.0, ≤ 7.2.1+1 more2024-02-07
CVE-2024-25143 [MEDIUM] CWE-770 CVE-2024-25143: The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 13, and older unsupported versions, does not limit resource consumption when generating a preview image, which allows remote authenticated users to cause a denial of service (memory consu
nvd
CVE-2025-62266P4MEDIUMCVSS 6.1≥ 7.4.0, < 7.4.3.1102025-10-30
CVE-2025-62266 [MEDIUM] CWE-601 CVE-2025-62266: By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions is vulnerable to DNS rebinding attacks, which allows remote attackers to redirect users to arbitrary exter
nvd
CVE-2025-62243P4MEDIUMCVSS 5.4≥ 7.4.1, < 7.4.3.1132025-10-13
CVE-2025-62243 [MEDIUM] CWE-863 CVE-2025-62243: Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 throug Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticated attackers to view publication comments via the _com_liferay_change_tracking_web_portlet_PublicationsPortlet
nvd
CVE-2025-43808P4MEDIUMCVSS 5.3≥ 7.4.0, < 7.4.3.1132025-09-19
CVE-2025-43808 [MEDIUM] CWE-732 CVE-2025-43808: The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and 7.3 service pack 3 through update 35 saves virtual products uploaded to Documents and Media with guest view permission, which allows remote attackers to access and download virtual
nvd
CVE-2025-43758P4MEDIUMCVSS 5.3≥ 7.4.0, ≤ 7.4.3.1322025-08-22
CVE-2025-43758 [MEDIUM] CWE-552 CVE-2025-43758: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 throu Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows unauthenticated users (guests) to access via URL files uploaded by object entry and stored in document_library
nvd
CVE-2025-62275P4MEDIUMCVSS 5.3≥ 7.4.0, < 7.4.3.1122025-11-01
CVE-2025-62275 [MEDIUM] CWE-863 CVE-2025-62275: Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 202 Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions does not check permission of images in a blog entry, which allows remote attackers to view the images in a blog entry via crafted URL.
nvd
CVE-2025-43749P4MEDIUMCVSS 5.3≥ 7.4.0, ≤ 7.4.3.1322025-08-20
CVE-2025-43749 [MEDIUM] CWE-552 CVE-2025-43749: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 throu Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows unauthenticated users (guests) to access via URL files uploaded in the form and stored in document_library
nvd
CVE-2022-38512P4MEDIUMCVSS 6.5≥ 7.4.3.12, ≤ 7.4.3.362022-09-22
CVE-2022-38512 [MEDIUM] CWE-862 CVE-2022-38512: The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 t The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via crafted URL.
nvd
CVE-2024-25609P4MEDIUMCVSS 6.1fixed in 7.4.3.132024-02-20
CVE-2024-25609 [MEDIUM] CVE-2024-25609: HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, an HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 service pack 3, 7.2 fix pack 15 through 18, and older unsupported versions can be circumvented by using two forward slashes, which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirec
nvd
CVE-2024-26268P4MEDIUMCVSS 5.3≤ 7.3.7≥ 7.4.0, < 7.4.3.272024-02-20
CVE-2024-26268 [MEDIUM] CWE-203 CVE-2024-26268: User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versi User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 8, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to determine if an account exist in the application by comparing the request's response time.
nvd