cbcvebase.

Liferay Portal vulnerabilities

319 known vulnerabilities affecting liferay/liferay_portal.

Total CVEs
319
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH47MEDIUM259LOW5

Vulnerabilities

Page 7 of 16
CVE-2023-42628P4MEDIUMCVSS 5.4≥ 7.1.0, < 7.4.3.882023-10-17
CVE-2023-42628 [MEDIUM] CWE-79 CVE-2023-42628: Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7 Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay DXP 7.0 fix pack 83 through 102, 7.1 fix pack 28 and earlier, 7.2 fix pack 20 and earlier, 7.3 update 33 and earlier, and 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML into a parent wiki page v
nvd
CVE-2023-35029P4MEDIUMCVSS 6.1≥ 7.4.3.70, < 7.4.3.772023-06-15
CVE-2023-35029 [MEDIUM] CWE-601 CVE-2023-35029: Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 thro Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to redirect users to arbitrary external URLs via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.
nvd
CVE-2025-43802P4MEDIUMCVSS 6.1≥ 7.4.3.51, < 7.4.3.1102025-09-15
CVE-2025-43802 [MEDIUM] CWE-79 CVE-2025-43802: Stored cross-site scripting (XSS) vulnerability in a custom object’s /o/c/<object-name> API endpoint Stored cross-site scripting (XSS) vulnerability in a custom object’s /o/c/ API endpoint in Liferay Portal 7.4.3.51 through 7.4.3.109, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 update 51 through update 92, and 7.3 update 33 through update 35. allows remote attackers to inject arbitrary web script or HTML via the externalReferenceCode parameter.
nvd
CVE-2025-43830P4MEDIUMCVSS 6.1≥ 7.3.2, < 7.4.3.1122025-10-08
CVE-2025-43830 [MEDIUM] CWE-79 CVE-2025-43830: Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111, Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and 7.3 GA through update 35 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a form with a rich text t
nvd
CVE-2025-43778P4MEDIUMCVSS 6.1≥ 7.4.0, ≤ 7.4.3.1322025-09-09
CVE-2025-43778 [MEDIUM] CWE-79 CVE-2025-43778: A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Life A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.11, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20 allows an remote authenticated attacker to inject JavaScript thro
nvd
CVE-2025-62255P4MEDIUMCVSS 6.1fixed in 7.4.3.1022025-10-23
CVE-2025-62255 [MEDIUM] CWE-79 CVE-2025-62255: Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Por Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Portal 7.4.0 through 7.4.3.101, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via a crafted payload inje
nvd
CVE-2025-43767P4MEDIUMCVSS 6.1≥ 7.4.3.86, < 7.4.3.1322025-08-23
CVE-2025-43767 [MEDIUM] CWE-601 CVE-2025-43767: Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.8 Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.86 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 update 86 through update 92 allows an attacker to exploit this security vulnerability to redirect users to a malicious
nvd
CVE-2025-4599P4MEDIUMCVSS 6.1≥ 7.4.3.61, < 7.4.3.1322025-08-04
CVE-2025-4599 [MEDIUM] CWE-79 CVE-2025-4599: The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP 202 The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP 2024.Q4.1 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.13 and 7.4 update 61 through update 92 was found to be vulnerable to postMessage-based XSS because it allows a remote non-authenticated attack
nvd
CVE-2025-62238P4MEDIUMCVSS 5.4≥ 7.4.3.21, < 7.4.3.1122025-10-10
CVE-2025-62238 [MEDIUM] CWE-79 CVE-2025-62238: Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Lifera Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 21 through update 92 allows remote authenticated attackers to inject arbitrary web script or HTML via a crafted payload inject
nvd
CVE-2025-43829P4MEDIUMCVSS 5.4≥ 7.4.3.18, < 7.4.3.1122025-10-08
CVE-2025-43829 [MEDIUM] CWE-79 CVE-2025-43829: Stored cross-site scripting (XSS) vulnerability in diagram type products in Commerce in Liferay Port Stored cross-site scripting (XSS) vulnerability in diagram type products in Commerce in Liferay Portal 7.4.3.18 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 18 through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a SVG file.
nvd
CVE-2025-43826P4MEDIUMCVSS 5.4≥ 7.2.0, < 7.4.3.1132025-09-30
CVE-2025-43826 [MEDIUM] CWE-79 CVE-2025-43826: Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allow remote attackers to inject arbitrary web script or HTML via an
nvd
CVE-2025-43776P4MEDIUMCVSS 5.4≥ 7.4.0, ≤ 7.4.3.1322025-09-09
CVE-2025-43776 [MEDIUM] CWE-209 CVE-2025-43776: A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Life A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 and 7.4 GA through update 92 allows an remote authenticated attacker
nvd
CVE-2025-43754P4MEDIUMCVSS 5.3≥ 7.4.0, ≤ 7.4.3.1322025-08-21
CVE-2025-43754 [MEDIUM] CWE-208 CVE-2025-43754: Username enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q Username enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows attackers to determine if an account exist in the application by inspecting the server processing time
nvd
CVE-2025-43789P4MEDIUMCVSS 5.3≥ 7.4.0, < 7.4.3.1202025-09-12
CVE-2025-43789 [MEDIUM] CWE-863 CVE-2025-43789: JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024. JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.9, 7.4 GA through update 92 published to OSGi are registered and invoked directly as classes which allows Service Access Policies get executed.
nvd
CVE-2021-33331P4MEDIUMCVSS 6.1≥ 7.0.0, < 7.3.22021-08-03
CVE-2021-33331 [MEDIUM] CWE-601 CVE-2021-33331: Open redirect vulnerability in the Notifications module in Liferay Portal 7.0.0 through 7.3.1, and L Open redirect vulnerability in the Notifications module in Liferay Portal 7.0.0 through 7.3.1, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19 and 7.2 before fix pack 8, allows remote attackers to redirect users to arbitrary external URLs via the 'redirect' parameter.
nvd
CVE-2023-42629P4MEDIUMCVSS 5.4≥ 7.4.2, < 7.4.3.882023-10-17
CVE-2023-42629 [MEDIUM] CWE-79 CVE-2023-42629: Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4. Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Vocabulary's 'description' text field.
nvd
CVE-2025-62249P4MEDIUMCVSS 6.1≥ 7.4.0, < 7.4.3.1322025-10-21
CVE-2025-62249 [MEDIUM] CWE-79 CVE-2025-62249: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q3.0 through 2025.Q3.2, 2025.Q2.0 through 2025.Q2.12, 2025.Q1.0 through 2025.Q1.17, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20, and 2023.Q4.0 through 2023.Q4
nvd
CVE-2025-62264P4MEDIUMCVSS 6.1≥ 7.4.3.8, < 7.4.3.1122025-10-31
CVE-2025-62264 [MEDIUM] CWE-79 CVE-2025-62264: Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 t Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 update 4 through update 92 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_portal_language_override_web_internal_
nvd
CVE-2025-43769P4MEDIUMCVSS 6.1≥ 7.4.0, < 7.4.3.1322025-08-23
CVE-2025-43769 [MEDIUM] CWE-79 CVE-2025-43769: Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.131, and Lifer Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.8, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows remote attackers to execute arbitrary web script or HTML via components tab.
nvd
CVE-2025-43785P4MEDIUMCVSS 6.1≥ 7.4.3.45, < 7.4.3.1292025-09-10
CVE-2025-43785 [MEDIUM] CWE-79 CVE-2025-43785: Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45 through 7.4.3.128, and Li Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45 through 7.4.3.128, and Liferay DXP 2024 Q2.0 through 2024.Q2.9, 2024.Q1.1 through 2024.Q1.12, and 7.4 update 45 through update 92 allows remote attackers to execute an arbitrary web script or HTML in the My Workflow Tasks page.
nvd
Liferay Portal vulnerabilities | cvebase