Liferay Portal vulnerabilities
319 known vulnerabilities affecting liferay/liferay_portal.
Total CVEs
319
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH47MEDIUM259LOW5
Vulnerabilities
Page 9 of 16
CVE-2025-62276P4MEDIUMCVSS 5.5≥ 7.4.0, < 7.4.3.1122025-11-01
CVE-2025-62276 [MEDIUM] CWE-525 CVE-2025-62276: The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and o
The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions uses an incorrect cache-control header, which allows local users to obtain access to downlo
nvd
CVE-2025-43755P4MEDIUMCVSS 5.4≥ 7.4.0, ≤ 7.4.3.1322025-08-21
CVE-2025-43755 [MEDIUM] CWE-79 CVE-2025-43755: A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 t through 7.4.3.132, and Lif
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 t through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.13, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.17 and 7.4 GA through update 92 allows an remote authenticated attacker to inject JavaS
nvd
CVE-2025-43740P4MEDIUMCVSS 5.4≥ 7.4.3.120, ≤ 7.4.3.1322025-08-19
CVE-2025-43740 [MEDIUM] CWE-79 CVE-2025-43740: A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and L
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13 and 2024.Q1.9 through 2024.Q1.19 allows an remote authenticated attacker to inject JavaScript
nvd
CVE-2025-62239P4MEDIUMCVSS 5.4≥ 7.4.3.21, < 7.4.3.1122025-10-10
CVE-2025-62239 [MEDIUM] CWE-79 CVE-2025-62239: Cross-site scripting (XSS) vulnerability in workflow process builder in Liferay Portal 7.4.3.21 thro
Cross-site scripting (XSS) vulnerability in workflow process builder in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 21 through update 92 allows remote authenticated attackers to inject arbitrary web script or HTML via the crafted input in a workflow definition.
nvd
CVE-2025-62263P4MEDIUMCVSS 5.4≥ 7.3.7, < 7.4.3.1042025-10-27
CVE-2025-62263 [MEDIUM] CWE-79 CVE-2025-62263: Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and L
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 service pack 3 through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account Role’s “Title” text field to (1) view ac
nvd
CVE-2025-43822P4MEDIUMCVSS 5.4≥ 7.4.3.15, < 7.4.3.1122025-10-07
CVE-2025-43822 [MEDIUM] CWE-79 CVE-2025-43822: Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3.
Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 15 through update 92 allow remote attackers to inject arbitrary web script or HTML via crafted payload injected into a Terms and Condition's Name text field t
nvd
CVE-2025-43811P4MEDIUMCVSS 5.4≥ 7.4.3.50, < 7.4.3.1122025-09-29
CVE-2025-43811 [MEDIUM] CWE-79 CVE-2025-43811: Multiple stored cross-site scripting (XSS) vulnerability in the related asset selector in Liferay Po
Multiple stored cross-site scripting (XSS) vulnerability in the related asset selector in Liferay Portal 7.4.3.50 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.7, and 7.4 update 50 through update 92 allows remote authenticated attackers to inject arbitrary web script or HTML via a crafted payload injected i
nvd
CVE-2025-43775P4MEDIUMCVSS 5.4≥ 7.4.0, < 7.4.3.1292025-09-09
CVE-2025-43775 [MEDIUM] CWE-79 CVE-2025-43775: Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Lifer
Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.5, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via remote app title field.
nvd
CVE-2025-43807P4MEDIUMCVSS 5.4≥ 7.4.0, < 7.4.3.1132025-09-22
CVE-2025-43807 [MEDIUM] CWE-79 CVE-2025-43807: Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0
Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a publication’s “Name” text fie
nvd
CVE-2025-43787P4MEDIUMCVSS 5.4≥ 7.4.0, ≤ 7.4.3.1322025-09-12
CVE-2025-43787 [MEDIUM] CWE-79 CVE-2025-43787: A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Life
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q3.0, 2025.Q2.0 through 2025.Q2.12, 2025.Q1.0 through 2025.Q1.17, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20 allows an remote authenticated attacker to inject Java
nvd
CVE-2025-43744P4MEDIUMCVSS 5.4≥ 7.4.0, ≤ 7.4.3.1322025-08-19
CVE-2025-43744 [MEDIUM] CWE-79 CVE-2025-43744: A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.13
A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.5, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 and 7.4 GA through update 92 exists in the Asset Publish
nvd
CVE-2025-43786P4MEDIUMCVSS 5.3≥ 7.4.0, < 7.4.3.1292025-09-09
CVE-2025-43786 [MEDIUM] CWE-79 CVE-2025-43786: Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024
Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 and 7.4 GA through update 92 allow attackers to determine existent ERC in the application by exploit the time response.
nvd
CVE-2020-25476P4MEDIUMCVSS 6.1v7.1.3v7.2.12021-01-07
CVE-2020-25476 [MEDIUM] CWE-79 CVE-2020-25476: Liferay CMS Portal version 7.1.3 and 7.2.1 have a blind persistent cross-site scripting (XSS) vulner
Liferay CMS Portal version 7.1.3 and 7.2.1 have a blind persistent cross-site scripting (XSS) vulnerability in the user name parameter to Calendar. An attacker can insert the malicious payload on the username, lastname or surname fields of its own profile, and the malicious payload will be injected and reflected in the calendar of the user who submit
nvd
CVE-2023-40191P4MEDIUMCVSS 6.1≥ 7.4.3.44, < 7.4.3.982024-02-21
CVE-2023-40191 [MEDIUM] CWE-79 CVE-2023-40191: Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay
Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the “Blocked Email Domains” text field
nvd
CVE-2023-42496P4MEDIUMCVSS 6.1≥ 7.3.3, < 7.4.3.982024-02-21
CVE-2023-42496 [MEDIUM] CWE-79 CVE-2023-42496: Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Po
Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_roles_admin_web_portlet_RolesAdminPortlet_tabs2
nvd
CVE-2023-42498P4MEDIUMCVSS 6.1≥ 7.4.3.8, < 7.4.3.982024-02-21
CVE-2023-42498 [MEDIUM] CWE-79 CVE-2023-42498: Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay P
Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_language_override_web_internal_portlet_PLOPortlet_key paramet
nvd
CVE-2023-33944P4MEDIUMCVSS 6.1≥ 7.3.4, ≤ 7.3.72023-05-24
CVE-2023-33944 [MEDIUM] CWE-79 CVE-2023-33944: Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68,
Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before update 24, and 7.4 before update 69 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a container type layout fragment's `URL` text field.
nvd
CVE-2022-42116P4MEDIUMCVSS 6.1≥ 7.3.2, < 7.4.3.152022-10-18
CVE-2022-42116 [MEDIUM] CWE-79 CVE-2022-42116: A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor
A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14, and Liferay DXP 7.3 before update 6, and 7.4 before update 15 allows remote attackers to inject arbitrary web script or HTML via the (1) name, or (2) namespace parameter.
nvd
CVE-2023-3193P4MEDIUMCVSS 6.1≥ 7.4.3.70, < 7.4.3.742023-06-15
CVE-2023-3193 [MEDIUM] CWE-79 CVE-2023-3193: Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal
Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.73, and Liferay DXP 7.4 update 70 through 73 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.
nvd
CVE-2023-5190P4MEDIUMCVSS 6.1≥ 7.4.3.45, < 7.4.3.1022024-02-20
CVE-2023-5190 [MEDIUM] CWE-601 CVE-2023-5190: Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.4
Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 45 through 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_address_web_internal_portlet_CountriesManagementAdminPortlet_redirect par
nvd