cbcvebase.

Liferay Portal vulnerabilities

207 known vulnerabilities affecting liferay/portal.

Total CVEs
207
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH26MEDIUM174LOW4

Vulnerabilities

Page 6 of 11
CVE-2025-43765P4MEDIUMCVSS 6.1≥ 7.4.3.0, ≤ 7.4.3.1312025-08-23
CVE-2025-43765 [MEDIUM] CWE-79 CVE-2025-43765: A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Lifer A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.13 and 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the text field from a web content.
nvd
CVE-2024-25610P4MEDIUMCVSS 5.4≥ 7.2.0, ≤ 7.4.3.122024-02-20
CVE-2024-25610 [MEDIUM] CWE-1188 CVE-2024-25610: In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions, the default configuration does not sanitize blog entries of JavaScript, which allows remote authenticated users to inject arbitrary web script or HTML (XSS) via a
nvd
CVE-2025-62276P4MEDIUMCVSS 5.5≥ 7.4.0, ≤ 7.4.3.1112025-11-01
CVE-2025-62276 [MEDIUM] CWE-525 CVE-2025-62276: The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and o The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions uses an incorrect cache-control header, which allows local users to obtain access to downlo
nvd
CVE-2025-62239P4MEDIUMCVSS 5.4≥ 7.4.3.21, ≤ 7.4.3.1112025-10-10
CVE-2025-62239 [MEDIUM] CWE-79 CVE-2025-62239: Cross-site scripting (XSS) vulnerability in workflow process builder in Liferay Portal 7.4.3.21 thro Cross-site scripting (XSS) vulnerability in workflow process builder in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 21 through update 92 allows remote authenticated attackers to inject arbitrary web script or HTML via the crafted input in a workflow definition.
nvd
CVE-2025-62237P4MEDIUMCVSS 5.4≥ 7.4.3.8, ≤ 7.4.3.1112025-10-10
CVE-2025-62237 [MEDIUM] CWE-79 CVE-2025-62237: Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4. Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 8 through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account’s “Name” t
nvd
CVE-2025-43822P4MEDIUMCVSS 5.4≥ 7.4.0, ≤ 7.4.3.1112025-10-07
CVE-2025-43822 [MEDIUM] CWE-79 CVE-2025-43822: Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3. Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 15 through update 92 allow remote attackers to inject arbitrary web script or HTML via crafted payload injected into a Terms and Condition's Name text field t
nvd
CVE-2025-43811P4MEDIUMCVSS 5.4≥ 7.4.3.50, ≤ 7.4.3.1112025-09-29
CVE-2025-43811 [MEDIUM] CWE-79 CVE-2025-43811: Multiple stored cross-site scripting (XSS) vulnerability in the related asset selector in Liferay Po Multiple stored cross-site scripting (XSS) vulnerability in the related asset selector in Liferay Portal 7.4.3.50 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.7, and 7.4 update 50 through update 92 allows remote authenticated attackers to inject arbitrary web script or HTML via a crafted payload injected i
nvd
CVE-2025-43740P4MEDIUMCVSS 5.4≥ 7.4.3.120, ≤ 7.4.3.1322025-08-19
CVE-2025-43740 [MEDIUM] CWE-79 CVE-2025-43740: A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and L A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13 and 2024.Q1.9 through 2024.Q1.19 allows an remote authenticated attacker to inject JavaScript
nvd
CVE-2025-43807P4MEDIUMCVSS 5.4≥ 7.4.0, ≤ 7.4.3.1122025-09-22
CVE-2025-43807 [MEDIUM] CWE-79 CVE-2025-43807: Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0 Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a publication’s “Name” text fie
nvd
CVE-2025-43787P4MEDIUMCVSS 5.4≥ 7.4.0, ≤ 7.4.3.1322025-09-12
CVE-2025-43787 [MEDIUM] CWE-79 CVE-2025-43787: A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Life A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q3.0, 2025.Q2.0 through 2025.Q2.12, 2025.Q1.0 through 2025.Q1.17, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20 allows an remote authenticated attacker to inject Java
nvd
CVE-2025-62246P4MEDIUMCVSS 5.4≥ 7.4.0, ≤ 7.4.3.1112025-10-13
CVE-2025-62246 [MEDIUM] CWE-79 CVE-2025-62246: Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.0 through 7.4.3.111 Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions allow remote authenticated users to inject arbitrary web script or HTML via a crafted p
nvd
CVE-2025-62265P4MEDIUMCVSS 5.4≥ 7.4.0, ≤ 7.4.3.1112025-10-30
CVE-2025-62265 [MEDIUM] CWE-79 CVE-2025-62265: Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.1 Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, 7.3 GA through update 36, and older unsupported versions allows remote attackers to inject arbitrary web script or
nvd
CVE-2025-43744P4MEDIUMCVSS 5.4≥ 7.4.0, ≤ 7.4.3.1322025-08-19
CVE-2025-43744 [MEDIUM] CWE-79 CVE-2025-43744: A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.13 A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.5, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 and 7.4 GA through update 92 exists in the Asset Publish
nvd
CVE-2025-43786P4MEDIUMCVSS 5.3≥ 7.4.0, ≤ 7.4.3.1282025-09-09
CVE-2025-43786 [MEDIUM] CWE-79 CVE-2025-43786: Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024 Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 and 7.4 GA through update 92 allow attackers to determine existent ERC in the application by exploit the time response.
nvd
CVE-2025-43777P4MEDIUMCVSS 5.3≥ 7.4.0, ≤ 7.4.3.1322025-09-09
CVE-2025-43777 [MEDIUM] CWE-209 CVE-2025-43777: Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 thro Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.19 exposes "Internal Server Error" in the response body when a login attempt is made with a deleted Client Secret.
nvd
CVE-2025-4655P4MEDIUMCVSS 5.0≥ 7.4.0, ≤ 7.4.3.1322025-08-09
CVE-2025-4655 [MEDIUM] CWE-918 CVE-2025-4655: SSRF vulnerability in FreeMarker templates in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DX SSRF vulnerability in FreeMarker templates in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 allows template editors to bypass access validations via crafted URLs.
nvd
CVE-2023-40191P4MEDIUMCVSS 6.1≥ 7.4.3.44, ≤ 7.4.3.972024-02-21
CVE-2023-40191 [MEDIUM] CWE-79 CVE-2023-40191: Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the “Blocked Email Domains” text field
nvd
CVE-2024-26269P4MEDIUMCVSS 6.1≥ 7.2.0, ≤ 7.4.3.372024-02-21
CVE-2024-26269 [MEDIUM] CWE-79 CVE-2024-26269: Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7. Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via the anchor (hash) part of a URL.
nvd
CVE-2024-25147P4MEDIUMCVSS 6.1≥ 7.2.0, ≤ 7.4.12024-02-21
CVE-2024-25147 [MEDIUM] CWE-79 CVE-2024-25147: Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7. Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via crafted javascript: style links.
nvd
CVE-2023-33944P4MEDIUMCVSS 6.1≥ 7.3.4, ≤ 7.4.3.682023-05-24
CVE-2023-33944 [MEDIUM] CWE-79 CVE-2023-33944: Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before update 24, and 7.4 before update 69 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a container type layout fragment's `URL` text field.
nvd
Liferay Portal vulnerabilities | cvebase