cbcvebase.

Liferay Portal vulnerabilities

207 known vulnerabilities affecting liferay/portal.

Total CVEs
207
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH26MEDIUM174LOW4

Vulnerabilities

Page 2 of 11
CVE-2025-62254P3HIGHCVSS 7.5≥ 7.4.0, ≤ 7.4.3.1112025-10-23
CVE-2025-62254 [HIGH] CWE-22 CVE-2025-62254: The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Life The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number or size of the files it will combine, which allows remote attackers to create v
nvd
CVE-2024-26273P3HIGHCVSS 8.8≥ 7.4.0, ≤ 7.4.3.1032024-10-22
CVE-2024-26273 [HIGH] CWE-352 CVE-2024-26273: Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 t Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 update 29 through update 35 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrar
nvd
CVE-2025-43768P3HIGHCVSS 7.7≥ 7.4.0, ≤ 7.4.3.1312025-08-23
CVE-2025-43768 [HIGH] CWE-201 CVE-2025-43768: Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 throu Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows authenticated users without any permissions to access sensitive information of admin users using JSONWS APIs.
nvd
CVE-2025-43816P3HIGHCVSS 7.5≥ 7.4.0, ≤ 7.4.3.1192025-09-25
CVE-2025-43816 [HIGH] CWE-401 CVE-2025-43816: A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2024.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows an attacker to cause server unavailability (denial of
nvd
CVE-2025-43801P3HIGHCVSS 7.5≥ 7.4.0, ≤ 7.4.3.1112025-09-16
CVE-2025-43801 [HIGH] CWE-606 CVE-2025-43801: Unchecked input for loop condition vulnerability in XML-RPC in Liferay Portal 7.4.0 through 7.4.3.11 Unchecked input for loop condition vulnerability in XML-RPC in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to perform a denial-of-service (DoS) attacks via a craf
nvd
CVE-2025-62250P3MEDIUMCVSS 6.5≥ 7.4.0, ≤ 7.4.3.1322025-10-21
CVE-2025-62250 [MEDIUM] CWE-346 CVE-2025-62250: Improper Authentication in Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, a Improper Authentication in Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to send malicious data to the Liferay Portal 7.4.0 through 7.4.3.132, and older unsupport
nvd
CVE-2023-35030P3HIGHCVSS 8.8≥ 7.4.3.70, ≤ 7.4.3.762023-06-15
CVE-2023-35030 [HIGH] CWE-352 CVE-2023-35030: Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to execute arbitrary code in the scripting console via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.
nvd
CVE-2023-33950P3HIGHCVSS 7.5≥ 7.4.3.48, ≤ 7.4.3.762023-05-24
CVE-2023-33950 [HIGH] CWE-1333 CVE-2023-33950: Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions that are vulnerable to ReDoS attacks to be used as patterns, which allows remote attackers to consume an excessive amount of server resources via crafted request URLs.
nvd
CVE-2025-3526P3HIGHCVSS 7.5≥ 7.0.0, ≤ 7.4.3.212025-06-16
CVE-2025-3526 [HIGH] CWE-400 CVE-2025-3526: SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does not restrict the saving of request parameters in the HTTP session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP requests.
nvd
CVE-2025-62260P3HIGHCVSS 7.5≥ 7.4.0, ≤ 7.4.3.992025-10-27
CVE-2025-62260 [HIGH] CWE-400 CVE-2025-62260: Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through u Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number of objects returned from Headless API requests, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing a reque
nvd
CVE-2025-43814P3MEDIUMCVSS 6.5≥ 7.4.0, ≤ 7.4.3.1122025-09-22
CVE-2025-43814 [MEDIUM] CWE-201 CVE-2025-43814: In Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 In Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions the audit events records a user’s password reminder answer, which allows remote authenticated users to obtain a user’s password reminder answer
nvd
CVE-2025-43799P3MEDIUMCVSS 6.5≥ 7.4.0, ≤ 7.4.3.1112025-09-15
CVE-2025-43799 [MEDIUM] CWE-1393 CVE-2025-43799: Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2 Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has changed their initial password, which allows remote users to access and edit content via
nvd
CVE-2025-62261P3MEDIUMCVSS 6.5≥ 7.4.0, ≤ 7.4.3.992025-10-27
CVE-2025-62261 [MEDIUM] CWE-312 CVE-2025-62261: Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 thr Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 34, and older unsupported versions stores password reset tokens in plain text, which allows attackers with access to the database to obtain the token, reset a user’s password and take ove
nvd
CVE-2025-3602P3HIGHCVSS 7.5≥ 7.4.0, ≤ 7.4.3.972025-06-16
CVE-2025-3602 [HIGH] CWE-400 CVE-2025-3602: Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through u Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through update 35, and 7.2 fix pack 8 through fix pack 20 does not limit the depth of a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing complex queries.
nvd
CVE-2025-43796P3HIGHCVSS 7.5≥ 7.4.0, ≤ 7.4.3.1012025-09-12
CVE-2025-43796 [HIGH] CWE-400 CVE-2025-43796: Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA though update 35 does not limit the number of objects returned from a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing queries that return a large number of obj
nvd
CVE-2025-43750P3MEDIUMCVSS 6.5≥ 7.4.0, ≤ 7.4.3.1322025-08-20
CVE-2025-43750 [MEDIUM] CWE-434 CVE-2025-43750: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 throu Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows remote unauthenticated users (guests) to upload files via the form attachment field without proper validation, e
nvd
CVE-2025-43825P3MEDIUMCVSS 6.5≥ 7.4.0, ≤ 7.4.3.1322025-10-03
CVE-2025-43825 [MEDIUM] CWE-201 CVE-2025-43825: A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1 A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows sensitive user data to be includ
nvd
CVE-2025-62247P3MEDIUMCVSS 6.5≥ 7.4.0, ≤ 7.4.3.1322025-10-22
CVE-2025-62247 [MEDIUM] CWE-862 CVE-2025-62247: Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132 Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 allows instance users to read and select unauthorized Bl
nvd
CVE-2025-62258P3MEDIUMCVSS 6.5≥ 7.4.0, ≤ 7.4.3.1072025-10-27
CVE-2025-62258 [MEDIUM] CWE-352 CVE-2025-62258: CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to execute any Headless API via the `endpoint` parameter.
nvd
CVE-2007-6055P4MEDIUMCVSS 4.3PoCv4.1.0v4.1.12007-11-20
CVE-2007-6055 [MEDIUM] CWE-79 CVE-2007-6055: Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay Portal 4.1.0 and 4.1.1 allows Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay Portal 4.1.0 and 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter. NOTE: this issue reportedly exists because of a regression that followed a fix at an unspecified earlier date.
nvd
Liferay Portal vulnerabilities | cvebase