Liferay Portal vulnerabilities
207 known vulnerabilities affecting liferay/portal.
Total CVEs
207
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH26MEDIUM174LOW4
Vulnerabilities
Page 4 of 11
CVE-2025-43758P4MEDIUMCVSS 5.3≥ 7.4.0, ≤ 7.4.3.1322025-08-22
CVE-2025-43758 [MEDIUM] CWE-552 CVE-2025-43758: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 throu
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows unauthenticated users (guests) to access via URL files uploaded by object entry and stored in document_library
nvd
CVE-2025-62275P4MEDIUMCVSS 5.3≥ 7.4.0, ≤ 7.4.3.1112025-11-01
CVE-2025-62275 [MEDIUM] CWE-863 CVE-2025-62275: Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 202
Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions does not check permission of images in a blog entry, which allows remote attackers to view the images in a blog entry via crafted URL.
nvd
CVE-2025-43749P4MEDIUMCVSS 5.3≥ 7.4.0, ≤ 7.4.3.1322025-08-20
CVE-2025-43749 [MEDIUM] CWE-552 CVE-2025-43749: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 throu
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows unauthenticated users (guests) to access via URL files uploaded in the form and stored in document_library
nvd
CVE-2024-26268P4MEDIUMCVSS 5.3≥ 7.2.0, ≤ 7.4.3.262024-02-20
CVE-2024-26268 [MEDIUM] CWE-203 CVE-2024-26268: User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versi
User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 8, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to determine if an account exist in the application by comparing the request's response time.
nvd
CVE-2022-28977P4MEDIUMCVSS 6.1≥ 7.2.0, ≤ 7.4.3.122022-09-22
CVE-2022-28977 [MEDIUM] CWE-601 CVE-2022-28977: HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 throu
HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack 17 through 25, 7.2 fix pack 5 through 14, and 7.3 before service pack 3 can be circumvented by using multiple forward slashes, which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` param
nvd
CVE-2025-62253P4MEDIUMCVSS 6.1≥ 7.4.0, ≤ 7.4.3.972025-10-27
CVE-2025-62253 [MEDIUM] CWE-601 CVE-2025-62253: Open redirect vulnerability in page administration in Liferay Portal 7.4.0 through 7.4.3.97, and old
Open redirect vulnerability in page administration in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary external URLs via the _com_lifer
nvd
CVE-2025-43795P4MEDIUMCVSS 6.1≥ 7.1.0, ≤ 7.4.3.1012025-09-12
CVE-2025-43795 [MEDIUM] CWE-601 CVE-2025-43795: Open redirect vulnerability in the System Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Li
Open redirect vulnerability in the System Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4 , 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_configuration_admin_web_portlet_System
nvd
CVE-2024-25149P4MEDIUMCVSS 5.4≥ 7.2.0, ≤ 7.4.12024-02-20
CVE-2024-25149 [MEDIUM] CWE-863 CVE-2024-25149: Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before servi
Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not properly restrict membership of a child site when the "Limit membership to members of the parent site" option is enabled, which allows remote authenticated users to add users w
nvd
CVE-2025-43797P4MEDIUMCVSS 5.4≥ 7.1.0, ≤ 7.4.3.1112025-09-15
CVE-2025-43797 [MEDIUM] CWE-1188 CVE-2025-43797: In Liferay Portal 7.1.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7
In Liferay Portal 7.1.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions, the default membership type of a newly created site is “Open” which allows any registered users to become a member of the site. A remote attacker with site membership
nvd
CVE-2024-25605P4MEDIUMCVSS 5.3≥ 7.2.0, ≤ 7.4.3.42024-02-20
CVE-2024-25605 [MEDIUM] CWE-276 CVE-2024-25605: The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Life
The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions grants guest users view permission to web content templates by default, which allows remote attackers to view any template via the UI or API.
nvd
CVE-2025-43751P4MEDIUMCVSS 5.3≥ 7.4.0, ≤ 7.4.3.1322025-08-22
CVE-2025-43751 [MEDIUM] CWE-203 CVE-2025-43751: User enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0
User enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10 and 7.4 GA through update 92 allows remote attackers to determine if an account exis
nvd
CVE-2025-43805P4MEDIUMCVSS 5.3≥ 7.3.0, ≤ 7.4.3.1112025-09-16
CVE-2025-43805 [MEDIUM] CWE-862 CVE-2025-43805: Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4
Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, and 7.3 GA through update 35 does not perform an authorization check when users attempt to view a display page template, which allows remote attackers to view display page templates via crafted URLs.
nvd
CVE-2025-43748P4MEDIUMCVSS 6.8≥ 7.0.0, ≤ 7.4.3.1192025-08-20
CVE-2025-43748 [MEDIUM] CWE-352 CVE-2025-43748: Insufficient CSRF protection for omni-administrator users in Liferay Portal 7.0.0 through 7.4.3.119,
Insufficient CSRF protection for omni-administrator users in Liferay Portal 7.0.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.6, 2023.Q4.0 through 2023.Q4.9, 2023.Q3.1 through 2023.Q3.9, 7.4 GA through update 92, 7.3 GA through update 36, and older unsupported versions allows attackers to execute Cross-Site Request Forgery
nvd
CVE-2023-42627P4MEDIUMCVSS 5.4≥ 7.3.5, ≤ 7.4.3.912023-10-17
CVE-2023-42627 [MEDIUM] CWE-79 CVE-2023-42627: Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal
Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal 7.3.5 through 7.4.3.91, and Liferay DXP 7.3 update 33 and earlier, and 7.4 before update 92 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a (1) Shipping Name, (2) Shipping Phone Number, (3) Shipping Ad
nvd
CVE-2025-43830P4MEDIUMCVSS 6.1≥ 7.3.2, ≤ 7.4.3.1112025-10-08
CVE-2025-43830 [MEDIUM] CWE-79 CVE-2025-43830: Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111,
Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and 7.3 GA through update 35 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a form with a rich text t
nvd
CVE-2025-4604P4MEDIUMCVSS 6.1≥ 7.4.0, ≤ 7.4.3.1322025-08-04
CVE-2025-4604 [MEDIUM] CWE-79 CVE-2025-4604: The vulnerable code can bypass the Captcha check in Liferay Portal 7.4.3.80 through 7.4.3.132, and L
The vulnerable code can bypass the Captcha check in Liferay Portal 7.4.3.80 through 7.4.3.132, and Liferay DXP 2024.Q1.1 through 2024.Q1.19, 2024.Q2.0 through 2024.Q2.13, 2024.Q3.0 through 2024.Q3.13, 2024.Q4.0 through 2024.Q4.7, 2025.Q1.0 through 2025.Q1.15 and 7.4 update 80 through update 92 and then attackers can run scripts in the Gogo shell
nvd
CVE-2024-25146P4MEDIUMCVSS 5.3≥ 7.2.0, ≤ 7.4.12024-02-08
CVE-2024-25146 [MEDIUM] CWE-204 CVE-2024-25146: Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before servi
Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsupported versions returns with different responses depending on whether a site does not exist or if the user does not have permission to access the site, which allows remote attackers to discover the exi
nvd
CVE-2024-26267P4MEDIUMCVSS 5.3≥ 7.2.0, ≤ 7.4.3.252024-02-20
CVE-2024-26267 [MEDIUM] CWE-1188 CVE-2024-26267: In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before
In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix pack 19, and older unsupported versions the default value of the portal property `http.header.version.verbosity` is set to `full`, which allows remote attackers to easily identify the version of the app
nvd
CVE-2025-43824P4MEDIUMCVSS 5.4≥ 7.4.0, ≤ 7.4.3.1112025-10-06
CVE-2025-43824 [MEDIUM] CWE-79 CVE-2025-43824: The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Li
The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions uses a user’s name in the “Content-Disposition” header, which allows remote authenticated users to change the file extension wh
nvd
CVE-2025-62238P4MEDIUMCVSS 5.4≥ 7.4.3.21, ≤ 7.4.3.1112025-10-10
CVE-2025-62238 [MEDIUM] CWE-79 CVE-2025-62238: Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Lifera
Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 21 through update 92 allows remote authenticated attackers to inject arbitrary web script or HTML via a crafted payload inject
nvd