Liferay Portal vulnerabilities
319 known vulnerabilities affecting liferay/liferay_portal.
Total CVEs
319
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH47MEDIUM259LOW5
Vulnerabilities
Page 6 of 16
CVE-2021-33338P4HIGHCVSS 7.5≥ 7.1.0, ≤ 7.3.22021-08-04
CVE-2021-33338 [HIGH] CWE-352 CVE-2021-33338: The Layout module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and
The Layout module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 6, exposes the CSRF token in URLs, which allows man-in-the-middle attackers to obtain the token and conduct Cross-Site Request Forgery (CSRF) attacks via the p_auth parameter.
nvd
CVE-2021-29038P4MEDIUMCVSS 6.3≤ 7.2.1≥ 7.3.0, < 7.3.62024-02-20
CVE-2021-29038 [MEDIUM] CWE-640 CVE-2021-29038: Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix p
Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attackers to use man-in-the-middle or shoulder surfing attacks to steal user's password reminder answers.
nvd
CVE-2022-28977P4MEDIUMCVSS 6.1≥ 7.3.1, < 7.4.3.42022-09-22
CVE-2022-28977 [MEDIUM] CWE-601 CVE-2022-28977: HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 throu
HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack 17 through 25, 7.2 fix pack 5 through 14, and 7.3 before service pack 3 can be circumvented by using multiple forward slashes, which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` param
nvd
CVE-2025-62253P4MEDIUMCVSS 6.1≤ 7.3.7≥ 7.4.0, < 7.4.3.982025-10-27
CVE-2025-62253 [MEDIUM] CWE-601 CVE-2025-62253: Open redirect vulnerability in page administration in Liferay Portal 7.4.0 through 7.4.3.97, and old
Open redirect vulnerability in page administration in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary external URLs via the _com_lifer
nvd
CVE-2025-43795P4MEDIUMCVSS 6.1≥ 7.1.0, < 7.4.3.1022025-09-12
CVE-2025-43795 [MEDIUM] CWE-601 CVE-2025-43795: Open redirect vulnerability in the System Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Li
Open redirect vulnerability in the System Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4 , 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_configuration_admin_web_portlet_System
nvd
CVE-2022-42132P4MEDIUMCVSS 5.9≥ 7.0.0, < 7.4.3.52022-11-15
CVE-2022-42132 [MEDIUM] CWE-200 CVE-2022-42132: The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix p
The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before update 4, and DXP 7.4 GA includes the LDAP credential in the page URL when paginating through the list of users, which allows man-in-the-middle attackers or attackers with
nvd
CVE-2024-25149P4MEDIUMCVSS 5.4fixed in 7.4.22024-02-20
CVE-2024-25149 [MEDIUM] CWE-863 CVE-2024-25149: Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before servi
Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not properly restrict membership of a child site when the "Limit membership to members of the parent site" option is enabled, which allows remote authenticated users to add users w
nvd
CVE-2025-43797P4MEDIUMCVSS 5.4fixed in 7.4.3.1122025-09-15
CVE-2025-43797 [MEDIUM] CWE-1188 CVE-2025-43797: In Liferay Portal 7.1.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7
In Liferay Portal 7.1.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions, the default membership type of a newly created site is “Open” which allows any registered users to become a member of the site. A remote attacker with site membership
nvd
CVE-2024-25605P4MEDIUMCVSS 5.3fixed in 7.4.3.52024-02-20
CVE-2024-25605 [MEDIUM] CWE-276 CVE-2024-25605: The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Life
The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions grants guest users view permission to web content templates by default, which allows remote attackers to view any template via the UI or API.
nvd
CVE-2025-43751P4MEDIUMCVSS 5.3≥ 7.4.0, ≤ 7.4.3.1322025-08-22
CVE-2025-43751 [MEDIUM] CWE-203 CVE-2025-43751: User enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0
User enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10 and 7.4 GA through update 92 allows remote attackers to determine if an account exis
nvd
CVE-2025-43805P4MEDIUMCVSS 5.3≥ 7.3.0, < 7.4.3.1122025-09-16
CVE-2025-43805 [MEDIUM] CWE-862 CVE-2025-43805: Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4
Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, and 7.3 GA through update 35 does not perform an authorization check when users attempt to view a display page template, which allows remote attackers to view display page templates via crafted URLs.
nvd
CVE-2025-43748P4MEDIUMCVSS 6.8≥ 7.0.0, < 7.4.3.120v6.22025-08-20
CVE-2025-43748 [MEDIUM] CWE-352 CVE-2025-43748: Insufficient CSRF protection for omni-administrator users in Liferay Portal 7.0.0 through 7.4.3.119,
Insufficient CSRF protection for omni-administrator users in Liferay Portal 7.0.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.6, 2023.Q4.0 through 2023.Q4.9, 2023.Q3.1 through 2023.Q3.9, 7.4 GA through update 92, 7.3 GA through update 36, and older unsupported versions allows attackers to execute Cross-Site Request Forgery
nvd
CVE-2023-42627P4MEDIUMCVSS 5.4≥ 7.3.5, < 7.4.3.922023-10-17
CVE-2023-42627 [MEDIUM] CWE-79 CVE-2023-42627: Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal
Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal 7.3.5 through 7.4.3.91, and Liferay DXP 7.3 update 33 and earlier, and 7.4 before update 92 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a (1) Shipping Name, (2) Shipping Phone Number, (3) Shipping Ad
nvd
CVE-2021-29043P4MEDIUMCVSS 5.9≥ 7.0.0, ≤ 7.3.52021-05-17
CVE-2021-29043 [MEDIUM] CWE-522 CVE-2021-29043: The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 9
The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 does not obfuscate the S3 store's proxy password, which allows attackers to steal the proxy password via man-in-the-middle attacks or shoulder surfing.
nvd
CVE-2025-43830P4MEDIUMCVSS 6.1≥ 7.3.2, < 7.4.3.1122025-10-08
CVE-2025-43830 [MEDIUM] CWE-79 CVE-2025-43830: Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111,
Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and 7.3 GA through update 35 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a form with a rich text t
nvd
CVE-2025-4604P4MEDIUMCVSS 6.1≥ 7.4.3.80, ≤ 7.4.3.1322025-08-04
CVE-2025-4604 [MEDIUM] CWE-79 CVE-2025-4604: The vulnerable code can bypass the Captcha check in Liferay Portal 7.4.3.80 through 7.4.3.132, and L
The vulnerable code can bypass the Captcha check in Liferay Portal 7.4.3.80 through 7.4.3.132, and Liferay DXP 2024.Q1.1 through 2024.Q1.19, 2024.Q2.0 through 2024.Q2.13, 2024.Q3.0 through 2024.Q3.13, 2024.Q4.0 through 2024.Q4.7, 2025.Q1.0 through 2025.Q1.15 and 7.4 update 80 through update 92 and then attackers can run scripts in the Gogo shell
nvd
CVE-2022-42128P4MEDIUMCVSS 5.3≥ 7.4.1, < 7.4.3.52022-11-15
CVE-2022-42128 [MEDIUM] CWE-276 CVE-2022-42128: The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does
The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which allows remote attackers to obtain a WikiNode object via the WikiNodeResource.getSiteWikiNodeByExternalReferenceCode API.
nvd
CVE-2024-25146P4MEDIUMCVSS 5.3≥ 7.2.0, ≤ 7.4.12024-02-08
CVE-2024-25146 [MEDIUM] CWE-204 CVE-2024-25146: Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before servi
Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsupported versions returns with different responses depending on whether a site does not exist or if the user does not have permission to access the site, which allows remote attackers to discover the exi
nvd
CVE-2024-26267P4MEDIUMCVSS 5.3≤ 7.3.7≥ 7.4.0, < 7.4.3.262024-02-20
CVE-2024-26267 [MEDIUM] CWE-1188 CVE-2024-26267: In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before
In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix pack 19, and older unsupported versions the default value of the portal property `http.header.version.verbosity` is set to `full`, which allows remote attackers to easily identify the version of the app
nvd
CVE-2025-43824P4MEDIUMCVSS 5.4fixed in 7.4.3.1122025-10-06
CVE-2025-43824 [MEDIUM] CWE-79 CVE-2025-43824: The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Li
The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions uses a user’s name in the “Content-Disposition” header, which allows remote authenticated users to change the file extension wh
nvd