Liferay Portal vulnerabilities

209 known vulnerabilities affecting liferay/portal.

Total CVEs
209
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
HIGH22MEDIUM177LOW10

Vulnerabilities

Page 1 of 11
CVE-2025-62276MEDIUMCVSS 4.6≥ 7.4.0, ≤ 7.4.3.1112025-11-01
CVE-2025-62276 [MEDIUM] CWE-525 CVE-2025-62276: The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and o The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions uses an incorrect cache-control header, which allows local users to obtain access to downlo
cvelistv5nvd
CVE-2025-62275MEDIUMCVSS 6.9≥ 7.4.0, ≤ 7.4.3.1112025-11-01
CVE-2025-62275 [MEDIUM] CWE-863 CVE-2025-62275: Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 202 Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions does not check permission of images in a blog entry, which allows remote attackers to view the images in a blog entry via crafted URL.
cvelistv5nvd
CVE-2025-62264MEDIUMCVSS 5.1≥ 7.4.3.8, ≤ 7.4.3.1112025-10-31
CVE-2025-62264 [MEDIUM] CWE-79 CVE-2025-62264: Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 t Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 update 4 through update 92 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_portal_language_override_web_internal_
cvelistv5nvd
CVE-2025-62267MEDIUMCVSS 4.6≥ 7.4.3.35, ≤ 7.4.3.1112025-10-31
CVE-2025-62267 [MEDIUM] CWE-79 CVE-2025-62267: Multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page Multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 35 through update 92 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a
cvelistv5nvd
CVE-2025-62265MEDIUMCVSS 4.8≥ 7.4.0, ≤ 7.4.3.1112025-10-30
CVE-2025-62265 [MEDIUM] CWE-79 CVE-2025-62265: Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.1 Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, 7.3 GA through update 36, and older unsupported versions allows remote attackers to inject arbitrary web script or
cvelistv5nvd
CVE-2025-62266MEDIUMCVSS 5.1≥ 7.4.0, ≤ 7.4.3.1192025-10-30
CVE-2025-62266 [MEDIUM] CWE-601 CVE-2025-62266: By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions is vulnerable to DNS rebinding attacks, which allows remote attackers to redirect users to arbitrary exter
cvelistv5nvd
CVE-2025-62257MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.3.1192025-10-30
CVE-2025-62257 [MEDIUM] CWE-307 CVE-2025-62257: Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote attackers to determine a user’s password even if account lockout i
cvelistv5nvd
CVE-2025-62260HIGHCVSS 7.1≥ 7.4.0, ≤ 7.4.3.992025-10-27
CVE-2025-62260 [HIGH] CWE-400 CVE-2025-62260: Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through u Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number of objects returned from Headless API requests, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing a reque
cvelistv5nvd
CVE-2025-62258HIGHCVSS 7.0≥ 7.4.0, ≤ 7.4.3.1072025-10-27
CVE-2025-62258 [HIGH] CWE-352 CVE-2025-62258: CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to execute any Headless API via the `endpoint` parameter.
cvelistv5nvd
CVE-2025-62263MEDIUMCVSS 4.8≥ 7.3.7, ≤ 7.4.3.1032025-10-27
CVE-2025-62263 [MEDIUM] CWE-79 CVE-2025-62263: Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and L Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 service pack 3 through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account Role’s “Title” text field to (1) view ac
cvelistv5nvd
CVE-2025-62261MEDIUMCVSS 6.9≥ 7.4.0, ≤ 7.4.3.992025-10-27
CVE-2025-62261 [MEDIUM] CWE-312 CVE-2025-62261: Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 thr Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 34, and older unsupported versions stores password reset tokens in plain text, which allows attackers with access to the database to obtain the token, reset a user’s password and take ove
cvelistv5nvd
CVE-2025-62259MEDIUMCVSS 6.9≥ 7.4.0, ≤ 7.4.3.1092025-10-27
CVE-2025-62259 [MEDIUM] CWE-863 CVE-2025-62259: Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 th Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has verified their email address, which allows remote users to access and edit content via the API.
cvelistv5nvd
CVE-2025-62253MEDIUMCVSS 6.9≥ 7.4.0, ≤ 7.4.3.972025-10-27
CVE-2025-62253 [MEDIUM] CWE-601 CVE-2025-62253: Open redirect vulnerability in page administration in Liferay Portal 7.4.0 through 7.4.3.97, and old Open redirect vulnerability in page administration in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary external URLs via the _com_lifer
cvelistv5nvd
CVE-2025-62262MEDIUMCVSS 4.6≥ 7.4.0, ≤ 7.4.3.972025-10-27
CVE-2025-62262 [MEDIUM] CWE-532 CVE-2025-62262: Information exposure through log file vulnerability in LDAP import feature in Liferay Portal 7.4.0 t Information exposure through log file vulnerability in LDAP import feature in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows local users to view user email address in the log files.
cvelistv5nvd
CVE-2025-62256MEDIUMCVSS 6.9≥ 7.4.0, ≤ 7.4.3.1092025-10-23
CVE-2025-62256 [MEDIUM] CWE-862 CVE-2025-62256: Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 throu Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not properly restrict access to OpenAPI in certain circumstances, which allows remote attackers to access the OpenAPI YAML file via a crafted URL.
cvelistv5nvd
CVE-2025-62254MEDIUMCVSS 6.9≥ 7.4.0, ≤ 7.4.3.1112025-10-23
CVE-2025-62254 [MEDIUM] CWE-22 CVE-2025-62254: The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Life The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number or size of the files it will combine, which allows remote attackers to create
cvelistv5nvd
CVE-2025-62255LOWCVSS 2.0≥ 7.4.0, ≤ 7.4.3.1012025-10-23
CVE-2025-62255 [LOW] CWE-79 CVE-2025-62255: Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Por Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Portal 7.4.0 through 7.4.3.101, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via a crafted payload injecte
cvelistv5nvd
CVE-2025-62248MEDIUMCVSS 4.8≥ 7.4.0, ≤ 7.4.3.1322025-10-22
CVE-2025-62248 [MEDIUM] CWE-79 CVE-2025-62248: A reflected cross-site scripting (XSS) vulnerability, resulting from a regression, has been identif A reflected cross-site scripting (XSS) vulnerability, resulting from a regression, has been identified in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 allows a remo
cvelistv5nvd
CVE-2025-62247LOWCVSS 2.0≥ 7.4.0, ≤ 7.4.3.1322025-10-22
CVE-2025-62247 [LOW] CWE-862 CVE-2025-62247: Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132 Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 allows instance users to read and select unauthorized Bluep
cvelistv5nvd
CVE-2025-62250MEDIUMCVSS 6.9≥ 7.4.0, ≤ 7.4.3.1322025-10-21
CVE-2025-62250 [MEDIUM] CWE-346 CVE-2025-62250: Improper Authentication in Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, a Improper Authentication in Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to send malicious data to the Liferay Portal 7.4.0 through 7.4.3.132, and older unsupport
cvelistv5nvd
1 / 11Next →
Liferay Portal vulnerabilities | cvebase