cbcvebase.

Liferay Portal vulnerabilities

207 known vulnerabilities affecting liferay/portal.

Total CVEs
207
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH26MEDIUM174LOW4

Vulnerabilities

Page 3 of 11
CVE-2025-43772P3HIGHCVSS 7.1≥ 7.0.0, ≤ 7.4.3.52025-09-04
CVE-2025-43772 [HIGH] CWE-400 CVE-2025-43772: Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through up Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not restrict the saving of request parameters in the portlet session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP request.
nvd
CVE-2025-43763P3MEDIUMCVSS 6.5≥ 7.4.0, ≤ 7.4.3.1312025-09-09
CVE-2025-43763 [MEDIUM] CWE-918 CVE-2025-43763: A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3. A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20 that affects custom object attachment fields. This flaw allows an attacker to manipulate the application into m
nvd
CVE-2024-26265P3MEDIUMCVSS 6.5≥ 7.2.0, ≤ 7.4.3.152024-02-20
CVE-2024-26265 [MEDIUM] CWE-770 CVE-2024-26265: The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions relies on a request parameter to limit the size of files that can be uploaded, which allows remote authenticated users to upload arbitrari
nvd
CVE-2024-25604P3MEDIUMCVSS 6.5≥ 7.2.0, ≤ 7.4.3.42024-02-20
CVE-2024-25604 [MEDIUM] CWE-863 CVE-2024-25604: Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 be Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions does not properly check user permissions, which allows remote authenticated users with the VIEW user permission to edit their own permission via the User and Organizations sec
nvd
CVE-2025-43752P3MEDIUMCVSS 6.5≥ 7.4.3.0, ≤ 7.4.3.1322025-08-22
CVE-2025-43752 [MEDIUM] CWE-770 CVE-2025-43752: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 throu Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allow users to upload an unlimited amount of files through the object entries attachment fields, the files are stored i
nvd
CVE-2025-62251P3MEDIUMCVSS 6.5≥ 7.3.0, ≤ 7.4.3.1192025-10-13
CVE-2025-62251 [MEDIUM] CWE-732 CVE-2025-62251: Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 throu Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA through update 92 and 7.3 GA though update 36 shows content to users who do not have permission to view it via the Menu Display Widget. This security flaw could result in sensitive information being exposed to unauthorized users.
nvd
CVE-2025-43784P3MEDIUMCVSS 6.5≥ 7.4.0, ≤ 7.4.3.1242025-09-10
CVE-2025-43784 [MEDIUM] CWE-863 CVE-2025-43784: Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 20 Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.8, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows guest users to obtain object entries information via the API Builder.
nvd
CVE-2025-43762P3MEDIUMCVSS 6.5≥ 7.4.0, ≤ 7.4.3.1322025-08-22
CVE-2025-43762 [MEDIUM] CWE-770 CVE-2025-43762: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 throu Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allow users to upload an unlimited amount of files through the forms, the files are stored in the document_library allo
nvd
CVE-2025-43819P3MEDIUMCVSS 6.5≥ 7.4.3.121, ≤ 7.4.3.1312025-09-24
CVE-2025-43819 [MEDIUM] CWE-613 CVE-2025-43819: A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, a A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, and 2024.Q1.1 through 2024.Q1.12 is allow an remote non-authenticated attacker to reuse old user session by SLO API
nvd
CVE-2025-43764P4MEDIUMCVSS 6.5≥ 7.4.3.0, ≤ 7.4.3.1312025-08-23
CVE-2025-43764 [MEDIUM] CWE-1333 CVE-2025-43764: Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Design Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScript in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.1, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20 and 7.4 GA through update 92, which allows authenti
nvd
CVE-2025-62257P4MEDIUMCVSS 5.3≥ 7.4.0, ≤ 7.4.3.1192025-10-30
CVE-2025-62257 [MEDIUM] CWE-307 CVE-2025-62257: Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote attackers to determine a user’s password even if account lockout i
nvd
CVE-2025-62259P3MEDIUMCVSS 5.4≥ 7.4.0, ≤ 7.4.3.1092025-10-27
CVE-2025-62259 [MEDIUM] CWE-863 CVE-2025-62259: Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 th Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has verified their email address, which allows remote users to access and edit content via the API.
nvd
CVE-2025-62256P4MEDIUMCVSS 5.3≥ 7.4.0, ≤ 7.4.3.1092025-10-23
CVE-2025-62256 [MEDIUM] CWE-862 CVE-2025-62256: Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 throu Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not properly restrict access to OpenAPI in certain circumstances, which allows remote attackers to access the OpenAPI YAML file via a crafted URL.
nvd
CVE-2024-25144P4MEDIUMCVSS 6.5≥ 7.2.0, ≤ 7.4.3.262024-02-08
CVE-2024-25144 [MEDIUM] CWE-835 CVE-2024-25144: The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Life The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 6, 7.2 before fix pack 19, and older unsupported versions does not check the URL of the IFrame, which allows remote authenticated users to cause a denial-of-service (DoS) via a self referencing IFrame.
nvd
CVE-2025-43745P4MEDIUMCVSS 6.5≥ 7.4.0, ≤ 7.4.3.1322025-08-19
CVE-2025-43745 [MEDIUM] CWE-352 CVE-2025-43745: A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 20 A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 and 7.4 GA through update 92 allows remote attackers to performs cross-origin request on behal
nvd
CVE-2025-43792P4MEDIUMCVSS 5.3≥ 7.4.0, ≤ 7.4.3.1052025-09-15
CVE-2025-43792 [MEDIUM] CWE-15 CVE-2025-43792: Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Lifera Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not properly obtain the remote address of the live site from the database which, which allows remote authenticated use
nvd
CVE-2024-25143P4MEDIUMCVSS 6.5≥ 7.2.0, ≤ 7.3.62024-02-07
CVE-2024-25143 [MEDIUM] CWE-770 CVE-2024-25143: The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 13, and older unsupported versions, does not limit resource consumption when generating a preview image, which allows remote authenticated users to cause a denial of service (memory consu
nvd
CVE-2025-62266P4MEDIUMCVSS 6.1≥ 7.4.0, ≤ 7.4.3.1192025-10-30
CVE-2025-62266 [MEDIUM] CWE-601 CVE-2025-62266: By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions is vulnerable to DNS rebinding attacks, which allows remote attackers to redirect users to arbitrary exter
nvd
CVE-2025-62243P4MEDIUMCVSS 5.4≥ 7.4.1, ≤ 7.4.3.1122025-10-13
CVE-2025-62243 [MEDIUM] CWE-863 CVE-2025-62243: Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 throug Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticated attackers to view publication comments via the _com_liferay_change_tracking_web_portlet_PublicationsPortlet
nvd
CVE-2025-43808P4MEDIUMCVSS 5.3≥ 7.3.0, ≤ 7.4.3.1122025-09-19
CVE-2025-43808 [MEDIUM] CWE-732 CVE-2025-43808: The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and 7.3 service pack 3 through update 35 saves virtual products uploaded to Documents and Media with guest view permission, which allows remote attackers to access and download virtual
nvd
Liferay Portal vulnerabilities | cvebase