📦 Liferay Portal

by Liferay

🔍 What is Liferay Portal?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-43773

CRITICAL CVSS 9.1 Aug 29, 2025

This vulnerability in Liferay Portal and DXP allows improper access through the expandoTableLocalService, potentially enabling unauthorized data access or manipulation. It affects Liferay Portal 7.4.0...

CVE-2025-43766

CRITICAL CVSS 9.8 Aug 23, 2025

This vulnerability allows attackers to upload unrestricted files through Liferay's style books component, which are then processed within the environment, leading to arbitrary code execution. It affec...

CVE-2025-3594

CRITICAL CVSS 9.8 Jun 16, 2025

A path traversal vulnerability in Liferay Portal and DXP allows remote attackers to write arbitrary files to server locations and download/execute arbitrary files from a download server. This affects ...

CVE-2024-8980

CRITICAL CVSS 9.6 Oct 22, 2024

This CSRF vulnerability in Liferay's Script Console allows attackers to execute arbitrary Groovy code on affected servers by tricking authenticated administrators into clicking malicious links or thro...

CVE-2024-38002

CRITICAL CVSS 9.0 Oct 22, 2024

This vulnerability allows remote authenticated users to modify workflow definitions in Liferay Portal/DXP, leading to arbitrary code execution (RCE). It affects Liferay Portal 7.3.2 through 7.4.3.111 ...

CVE-2023-47795

CRITICAL CVSS 9.0 Feb 21, 2024

This stored XSS vulnerability allows authenticated attackers to inject malicious scripts into document titles in Liferay's Document and Media widget. When other users view these documents, the scripts...

CVE-2024-26266

CRITICAL CVSS 9.0 Feb 21, 2024

This CVE describes multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal and DXP. Authenticated attackers can inject malicious scripts into user profile name fields that then ex...

CVE-2023-42498

CRITICAL CVSS 9.6 Feb 21, 2024

This reflected cross-site scripting (XSS) vulnerability in Liferay Portal and DXP allows attackers to inject malicious scripts into the Language Override edit screen. When exploited, it can enable ses...

CVE-2023-40191

CRITICAL CVSS 9.0 Feb 21, 2024

This reflected cross-site scripting (XSS) vulnerability in Liferay Portal and DXP allows remote attackers to inject malicious scripts into the 'Blocked Email Domains' text field. When exploited, this ...

CVE-2024-25601

CRITICAL CVSS 9.0 Feb 21, 2024

This stored cross-site scripting (XSS) vulnerability in Liferay's Expando module allows authenticated attackers to inject malicious scripts into geolocation custom field names. When other users view p...

CVE-2024-25147

CRITICAL CVSS 9.6 Feb 21, 2024

This cross-site scripting (XSS) vulnerability in Liferay's HtmlUtil.escapeJsLink function allows attackers to inject malicious JavaScript or HTML through crafted javascript: links. Attackers can execu...

CVE-2024-25610

CRITICAL CVSS 9.0 Feb 20, 2024

This vulnerability allows remote authenticated users to inject malicious JavaScript or HTML into blog entries in Liferay Portal/DXP, leading to cross-site scripting (XSS) attacks. It affects Liferay P...

CVE-2024-25145

CRITICAL CVSS 9.6 Feb 7, 2024

This stored XSS vulnerability in Liferay's Portal Search module allows authenticated attackers to inject malicious scripts into search results when highlighting is disabled. Successful exploitation en...

CVE-2023-47797

CRITICAL CVSS 9.6 Nov 17, 2023

This reflected cross-site scripting (XSS) vulnerability in Liferay Portal allows remote attackers to inject malicious scripts or HTML via the p_l_back_url_title parameter on content edit pages. Succes...

CVE-2023-42627

CRITICAL CVSS 9.6 Oct 17, 2023

This vulnerability allows remote attackers to inject malicious scripts into multiple address fields in Liferay's Commerce module. When exploited, these stored XSS payloads execute in victims' browsers...

CVE-2023-42628

CRITICAL CVSS 9.0 Oct 17, 2023

This stored XSS vulnerability in Liferay Portal/DXP allows attackers to inject malicious scripts into wiki pages through the content field. When other users view the compromised wiki page, the script ...

CVE-2023-44310

CRITICAL CVSS 9.0 Oct 17, 2023

A stored cross-site scripting (XSS) vulnerability in Liferay Portal and DXP allows attackers to inject malicious scripts into page names. When users view affected pages, the scripts execute in their b...

CVE-2023-42629

CRITICAL CVSS 9.0 Oct 17, 2023

This stored cross-site scripting (XSS) vulnerability in Liferay Portal/DXP allows attackers to inject malicious scripts into vocabulary descriptions. When users view the affected vocabulary page, the ...

CVE-2023-42497

CRITICAL CVSS 9.6 Oct 17, 2023

This reflected cross-site scripting (XSS) vulnerability allows attackers to inject malicious scripts into the Export for Translation page of affected Liferay systems. When exploited, it can enable ses...

CVE-2025-62260

HIGH CVSS 7.5 Oct 27, 2025

This vulnerability allows remote attackers to perform denial-of-service attacks against Liferay Portal/DXP by sending Headless API requests that return excessive numbers of objects, overwhelming serve...

CVE-2025-62254

HIGH CVSS 7.5 Oct 23, 2025

This vulnerability in Liferay Portal and DXP allows remote attackers to trigger denial of service attacks by exploiting the ComboServlet's lack of limits on file combination. Attackers can craft reque...

CVE-2025-43813

HIGH CVSS 8.2 Sep 29, 2025

This vulnerability in Liferay Portal/DXP allows remote attackers to perform path traversal attacks via the ComboServlet, potentially accessing arbitrary CSS and JS files and causing denial-of-service ...

CVE-2025-43793

HIGH CVSS 7.5 Sep 15, 2025

This vulnerability allows attackers who control a website sharing the same top-level domain (TLD) to read cookies set by Liferay applications. It affects Liferay Portal and DXP versions through improp...

CVE-2025-43796

HIGH CVSS 7.5 Sep 12, 2025

This vulnerability allows remote attackers to perform denial-of-service attacks on Liferay Portal/DXP by exploiting GraphQL queries that return unlimited objects. Attackers can overwhelm server resour...

CVE-2025-43790

HIGH CVSS 8.1 Sep 11, 2025

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal and DXP that allows authenticated users to access, create, edit, and relate data across different virtual ...

CVE-2025-3586

HIGH CVSS 7.2 Sep 1, 2025

This vulnerability allows authenticated admin users with Instance Administrator role to execute arbitrary Groovy scripts through Object actions in Liferay Portal/DXP, leading to remote code execution....

CVE-2025-43768

HIGH CVSS 7.7 Aug 23, 2025

This vulnerability allows authenticated users without specific permissions to access sensitive information of admin users via JSONWS APIs in Liferay Portal and DXP. It affects Liferay Portal 7.4.0-7.4...

CVE-2025-4581

HIGH CVSS 8.6 Aug 9, 2025

This CVE describes a pre-authentication blind Server-Side Request Forgery (SSRF) vulnerability in Liferay Portal and DXP. Attackers can force vulnerable servers to make arbitrary HTTP requests to inte...

CVE-2025-3526

HIGH CVSS 7.5 Jun 16, 2025

This vulnerability in Liferay Portal and DXP allows remote attackers to cause denial-of-service by consuming system memory through crafted HTTP requests. Attackers can save unlimited request parameter...

CVE-2025-3602

HIGH CVSS 7.5 Jun 16, 2025

This vulnerability allows remote attackers to perform denial-of-service attacks on Liferay Portal/DXP by sending complex GraphQL queries that overwhelm system resources. Affected systems include Lifer...

CVE-2024-26271

HIGH CVSS 8.8 Oct 22, 2024

This CSRF vulnerability in Liferay Portal/DXP allows attackers to trick authenticated users into performing unauthorized actions by clicking malicious links. Attackers can change passwords, shut down ...

CVE-2024-26273

HIGH CVSS 8.8 Oct 22, 2024

A CSRF vulnerability in Liferay Portal and DXP allows attackers to trick authenticated administrators into performing unauthorized actions. Attackers can change user passwords, shut down servers, exec...

CVE-2024-25606

HIGH CVSS 8.0 Feb 20, 2024

This XXE vulnerability in Liferay Portal and DXP allows authenticated attackers with deployment permissions to read sensitive files or cause denial of service through XML parsing. It affects administr...

CVE-2021-38266

HIGH CVSS 7.5 Mar 2, 2022

This vulnerability in Liferay Portal's Portal Security module allows remote attackers to perform account lockout attacks by attempting to authenticate as users that exist in LDAP directories. This pre...

CVE-2020-28884

HIGH CVSS 7.2 Jan 28, 2022

CVE-2020-28884 is an OS command injection vulnerability in Liferay Portal Server that allows authenticated administrators to execute arbitrary operating system commands through Groovy script injection...

CVE-2021-33321

HIGH CVSS 7.5 Aug 3, 2021

This vulnerability allows remote attackers to enumerate user email addresses through Liferay's forgot password functionality due to an insecure default configuration. Affected systems include Liferay ...

CVE-2021-33323

HIGH CVSS 7.5 Aug 3, 2021

This vulnerability in Liferay Portal's Dynamic Data Mapping module allows unauthenticated remote attackers to view form values that were autosaved by other users. It affects Liferay Portal 7.1.0 throu...

CVE-2025-62275

MEDIUM CVSS 5.3 Nov 1, 2025

This vulnerability allows remote attackers to view images in blog entries without proper permission checks in Liferay Portal and DXP. Attackers can access restricted images via crafted URLs. Affected ...

CVE-2025-62276

MEDIUM CVSS 5.5 Nov 1, 2025

This vulnerability allows local users to access downloaded files via browser cache due to incorrect cache-control headers in Liferay's Document Library and Adaptive Media modules. It affects Liferay P...

CVE-2025-62267

MEDIUM CVSS 6.1 Oct 31, 2025

This CVE describes multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal and DXP that allow remote attackers to inject malicious scripts or HTML into user profile fields. Attackers can...

CVE-2025-62264

MEDIUM CVSS 6.1 Oct 31, 2025

This reflected cross-site scripting (XSS) vulnerability in Liferay Portal and DXP allows remote attackers to inject malicious scripts or HTML via a specific parameter. Attackers can steal session cook...

CVE-2025-62265

MEDIUM CVSS 5.4 Oct 30, 2025

This CVE describes a cross-site scripting (XSS) vulnerability in Liferay Portal and DXP's Blogs widget. Attackers can inject malicious <iframe> elements without sandbox attributes into blog content, a...

CVE-2025-62266

MEDIUM CVSS 6.1 Oct 30, 2025

This CVE describes a DNS rebinding vulnerability in Liferay Portal and DXP that allows attackers to redirect users to malicious external URLs. Affected systems include Liferay Portal 7.4.0-7.4.3.119 a...

CVE-2025-62258

MEDIUM CVSS 6.5 Oct 27, 2025

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Liferay Portal's Headless API that allows attackers to execute any Headless API endpoint via the 'endpoint' parameter. It affect...

CVE-2025-62259

MEDIUM CVSS 5.4 Oct 27, 2025

This vulnerability allows remote users to access and edit content via APIs in Liferay Portal and DXP before email verification, bypassing intended access controls. It affects Liferay Portal 7.4.0 thro...

CVE-2025-62262

MEDIUM CVSS 4.4 Oct 27, 2025

This vulnerability allows local users to view user email addresses in log files through the LDAP import feature in Liferay Portal and DXP. It affects Liferay Portal 7.4.0 through 7.4.3.97 and Liferay ...

CVE-2025-62253

MEDIUM CVSS 6.1 Oct 27, 2025

This open redirect vulnerability in Liferay Portal and DXP allows attackers to redirect authenticated users to malicious external websites by manipulating the redirect parameter in page administration...

CVE-2025-62255

MEDIUM CVSS 6.1 Oct 23, 2025

This CVE describes a self cross-site scripting (XSS) vulnerability in Liferay Portal and DXP that allows remote attackers to inject malicious scripts or HTML via specially crafted attachment filenames...

CVE-2025-62256

MEDIUM CVSS 5.3 Oct 23, 2025

This vulnerability allows remote attackers to access Liferay's OpenAPI YAML file through a crafted URL, potentially exposing API documentation and internal system details. It affects Liferay Portal 7....

CVE-2025-62247

MEDIUM CVSS 6.5 Oct 22, 2025

This vulnerability allows authenticated users in Liferay Portal/DXP to access and select unauthorized Blueprints through Collection Providers across instances due to missing authorization checks. It a...

CVE-2025-62248

MEDIUM CVSS 4.8 Oct 22, 2025

A reflected cross-site scripting (XSS) vulnerability in Liferay Portal and DXP allows authenticated attackers to inject malicious JavaScript via a specific parameter. When victims access crafted URLs ...

CVE-2025-62249

MEDIUM CVSS 6.1 Oct 21, 2025

A reflected cross-site scripting (XSS) vulnerability in Liferay Portal and DXP allows remote unauthenticated attackers to inject malicious JavaScript into the google_gadget component. This affects use...

CVE-2025-62246

MEDIUM CVSS 5.4 Oct 13, 2025

This CVE describes stored cross-site scripting (XSS) vulnerabilities in Liferay Portal and DXP where authenticated users can inject malicious scripts into various comment fields. When other users view...

CVE-2025-62252

MEDIUM CVSS 4.3 Oct 13, 2025

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal and DXP that allows authenticated users in one virtual instance to assign organizations to users in differ...

CVE-2025-62242

MEDIUM CVSS 4.3 Oct 13, 2025

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal and DXP that allows authenticated users to access other users' address information by manipulating the add...

CVE-2025-62245

MEDIUM CVSS 4.3 Oct 10, 2025

A CSRF vulnerability in Liferay Portal and DXP allows attackers to add or edit publication comments without user consent. This affects Liferay Portal 7.4.1-7.4.3.112 and Liferay DXP 2023.Q4.0-2023.Q4....

CVE-2025-62239

MEDIUM CVSS 5.4 Oct 10, 2025

This cross-site scripting (XSS) vulnerability in Liferay's workflow process builder allows authenticated attackers to inject malicious scripts or HTML into workflow definitions. The vulnerability affe...

CVE-2025-62237

MEDIUM CVSS 5.4 Oct 10, 2025

A stored cross-site scripting (XSS) vulnerability in Liferay's Commerce view order page allows attackers to inject malicious scripts into account name fields. When users view orders containing these m...

CVE-2025-62238

MEDIUM CVSS 5.4 Oct 10, 2025

This stored XSS vulnerability allows authenticated attackers to inject malicious scripts into the Account Name field on the Membership page in Liferay Portal/DXP. When other users view the affected pa...

CVE-2025-62240

MEDIUM CVSS 5.4 Oct 9, 2025

This CVE describes multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal and DXP calendar events. Attackers can inject malicious scripts into user name fields (First, Middle, Last) tha...

CVE-2025-43771

MEDIUM CVSS 5.4 Oct 8, 2025

This CVE describes multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal and DXP notifications widget. Attackers can inject malicious scripts into user profile fields and conten...

CVE-2025-43830

MEDIUM CVSS 6.1 Oct 8, 2025

A stored cross-site scripting (XSS) vulnerability in Liferay Portal and DXP allows attackers to inject malicious scripts into forms with rich text fields. When users view or interact with these compro...

CVE-2025-43829

MEDIUM CVSS 5.4 Oct 8, 2025

This stored cross-site scripting (XSS) vulnerability in Liferay's diagram type products allows remote attackers to inject malicious scripts or HTML via crafted SVG files. When exploited, it enables at...

CVE-2025-43822

MEDIUM CVSS 5.4 Oct 7, 2025

This CVE describes stored cross-site scripting (XSS) vulnerabilities in Liferay Portal and DXP where attackers can inject malicious scripts into Terms and Conditions fields. The injected scripts execu...

CVE-2025-43823

MEDIUM CVSS 5.4 Oct 7, 2025

This cross-site scripting (XSS) vulnerability allows remote attackers to inject malicious scripts into Commerce Product Name fields in Liferay Portal and DXP. When exploited, it can enable session hij...

CVE-2025-43824

MEDIUM CVSS 5.4 Oct 6, 2025

This vulnerability allows authenticated users to manipulate file extensions when downloading vCard files from the Profile widget in Liferay. Attackers could potentially deliver malicious files disguis...

CVE-2025-43825

MEDIUM CVSS 6.5 Oct 3, 2025

This vulnerability in Liferay Portal and DXP allows unauthorized actors to access sensitive user data through Freemarker templates. It affects multiple versions of Liferay Portal 7.4 and Liferay DXP f...