Liferay Portal vulnerabilities
319 known vulnerabilities affecting liferay/liferay_portal.
Total CVEs
319
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH47MEDIUM259LOW5
Vulnerabilities
Page 9 of 16
CVE-2024-26269P4MEDIUMCVSS 6.1≥ 7.2.0, < 7.4.3.382024-02-21
CVE-2024-26269 [MEDIUM] CWE-79 CVE-2024-26269: Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.
Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via the anchor (hash) part of a URL.
nvd
CVE-2024-25147P4MEDIUMCVSS 6.1fixed in 7.4.22024-02-21
CVE-2024-25147 [MEDIUM] CWE-79 CVE-2024-25147: Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.
Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via crafted javascript: style links.
nvd
CVE-2023-33944P4MEDIUMCVSS 6.1≥ 7.3.4, ≤ 7.3.72023-05-24
CVE-2023-33944 [MEDIUM] CWE-79 CVE-2023-33944: Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68,
Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before update 24, and 7.4 before update 69 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a container type layout fragment's `URL` text field.
nvd
CVE-2022-42116P4MEDIUMCVSS 6.1≥ 7.3.2, < 7.4.3.152022-10-18
CVE-2022-42116 [MEDIUM] CWE-79 CVE-2022-42116: A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor
A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14, and Liferay DXP 7.3 before update 6, and 7.4 before update 15 allows remote attackers to inject arbitrary web script or HTML via the (1) name, or (2) namespace parameter.
nvd
CVE-2023-3193P4MEDIUMCVSS 6.1≥ 7.4.3.70, < 7.4.3.742023-06-15
CVE-2023-3193 [MEDIUM] CWE-79 CVE-2023-3193: Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal
Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.73, and Liferay DXP 7.4 update 70 through 73 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.
nvd
CVE-2023-5190P4MEDIUMCVSS 6.1≥ 7.4.3.45, < 7.4.3.1022024-02-20
CVE-2023-5190 [MEDIUM] CWE-601 CVE-2023-5190: Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.4
Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 45 through 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_address_web_internal_portlet_CountriesManagementAdminPortlet_redirect par
nvd
CVE-2025-2536P4MEDIUMCVSS 6.1≥ 7.4.3.82, ≤ 7.4.3.1282025-03-19
CVE-2025-2536 [MEDIUM] CWE-79 CVE-2025-2536: Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay D
Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 82 through update 92 in the Frontend JS module's layout-taglib/__liferay__/index.js allows remote attackers t
nvd
CVE-2025-43783P4MEDIUMCVSS 6.1≥ 7.4.0, < 7.4.3.1292025-09-10
CVE-2025-43783 [MEDIUM] CWE-79 CVE-2025-43783: Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.73 through 7.4.3.128, and
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.73 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 7.4 update 73 through update 92 allows remote attackers to inject arbitrary web script or HTML via the /c/portal/comment/discussion/get_editor path.
nvd
CVE-2025-43815P4MEDIUMCVSS 6.1≥ 7.4.3.102, < 7.4.3.1112025-09-29
CVE-2025-43815 [MEDIUM] CWE-79 CVE-2025-43815: Reflected cross-site scripting (XSS) vulnerability on the page configuration page in Liferay Portal
Reflected cross-site scripting (XSS) vulnerability on the page configuration page in Liferay Portal 7.4.3.102 through 7.4.3.110, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, and 2023.Q3.5 allows remote attackers to inject arbitrary web script or HTML via the com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURLTitle parameter.
nvd
CVE-2025-43804P4MEDIUMCVSS 6.1≥ 7.4.3.93, < 7.4.3.1122025-09-16
CVE-2025-43804 [MEDIUM] CWE-79 CVE-2025-43804: Cross-site scripting (XSS) vulnerability in Search widget in Liferay Portal 7.4.3.93 through 7.4.3.1
Cross-site scripting (XSS) vulnerability in Search widget in Liferay Portal 7.4.3.93 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_search_web_portlet_SearchPortlet_userId parameter.
nvd
CVE-2025-43781P4MEDIUMCVSS 6.1≥ 7.4.0, < 7.4.3.1292025-09-09
CVE-2025-43781 [MEDIUM] CWE-79 CVE-2025-43781: Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.110 through 7.4.3.128, an
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.110 through 7.4.3.128, and Liferay DXP 2024.Q3.1 through 2024.Q3.8, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.12 allows remote attackers to inject arbitrary web script or HTML via the URL in search bar portlet
nvd
CVE-2024-8980P4MEDIUMCVSS 6.1≥ 7.0.0, < 7.0.6≥ 7.1.0, < 7.1.3+3 more2024-10-22
CVE-2024-8980 [MEDIUM] CWE-352 CVE-2024-8980: The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023
The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, 7.2 GA through fix pack 20, 7.1 GA through fix pack 28, 7.0 GA through fix pack 102 and 6.2 GA through fix pack 173
does not sufficiently protect against Cross-Site Request Forgery (CSRF) attack
nvd
CVE-2025-43800P4MEDIUMCVSS 6.1≥ 7.4.3.20, < 7.4.3.1122025-09-15
CVE-2025-43800 [MEDIUM] CWE-79 CVE-2025-43800: Cross-site scripting (XSS) vulnerability in Objects in Liferay Portal 7.4.3.20 through 7.4.3.111, an
Cross-site scripting (XSS) vulnerability in Objects in Liferay Portal 7.4.3.20 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an object with a rich text type field.
nvd
CVE-2025-43735P4MEDIUMCVSS 6.1≥ 7.4.0, ≤ 7.4.3.1312025-08-12
CVE-2025-43735 [MEDIUM] CWE-79 CVE-2025-43735: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131,
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the google_gadget.
nvd
CVE-2025-43791P4MEDIUMCVSS 6.1fixed in 7.4.3.1122025-09-15
CVE-2025-43791 [MEDIUM] CWE-79 CVE-2025-43791: Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.0 through 7.4.3.111, and L
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a "Rich Text" type field to (1) a web content str
nvd
CVE-2025-43770P4MEDIUMCVSS 6.1≥ 7.4.0, < 7.4.3.1322025-08-23
CVE-2025-43770 [MEDIUM] CWE-79 CVE-2025-43770: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131,
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the referer or FORWA
nvd
CVE-2025-43742P4MEDIUMCVSS 6.1≥ 7.4.0, ≤ 7.4.3.1322025-08-20
CVE-2025-43742 [MEDIUM] CWE-79 CVE-2025-43742: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132,
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.3, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScr
nvd
CVE-2025-43761P4MEDIUMCVSS 6.1≥ 7.4.0, < 7.4.3.1322025-08-22
CVE-2025-43761 [MEDIUM] CWE-79 CVE-2025-43761: A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131,
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.4, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the frontend-editor-
nvd
CVE-2021-29040P4MEDIUMCVSS 5.3≤ 7.3.42021-05-16
CVE-2021-29040 [MEDIUM] CWE-209 CVE-2021-29040: The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7
The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 20 and 7.2 before fix pack 10 may provide overly verbose error messages, which allows remote attackers to use the contents of error messages to help launch another, more focused attacks via crafted inputs.
nvd
CVE-2024-25602P4MEDIUMCVSS 5.4fixed in 7.4.3.42024-02-21
CVE-2024-25602 [MEDIUM] CWE-79 CVE-2024-25602: Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Po
Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload i
nvd