Liferay Security Vulnerabilities (CVEs)
Track 134 security vulnerabilities affecting Liferay products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.
This vulnerability allows remote attackers to view images in blog entries without proper permission checks in Liferay Portal and DXP. Attackers can ac...
Nov 1, 2025This vulnerability allows local users to access downloaded files via browser cache due to incorrect cache-control headers in Liferay's Document Librar...
Nov 1, 2025This CVE describes multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal and DXP that allow remote attackers to inject malicious scrip...
Oct 31, 2025This reflected cross-site scripting (XSS) vulnerability in Liferay Portal and DXP allows remote attackers to inject malicious scripts or HTML via a sp...
Oct 31, 2025This CVE describes a cross-site scripting (XSS) vulnerability in Liferay Portal and DXP's Blogs widget. Attackers can inject malicious <iframe> elemen...
Oct 30, 2025This CVE describes a DNS rebinding vulnerability in Liferay Portal and DXP that allows attackers to redirect users to malicious external URLs. Affecte...
Oct 30, 2025This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Liferay Portal's Headless API that allows attackers to execute any Headless AP...
Oct 27, 2025This vulnerability allows remote users to access and edit content via APIs in Liferay Portal and DXP before email verification, bypassing intended acc...
Oct 27, 2025This vulnerability allows remote attackers to perform denial-of-service attacks against Liferay Portal/DXP by sending Headless API requests that retur...
Oct 27, 2025This vulnerability allows local users to view user email addresses in log files through the LDAP import feature in Liferay Portal and DXP. It affects ...
Oct 27, 2025This open redirect vulnerability in Liferay Portal and DXP allows attackers to redirect authenticated users to malicious external websites by manipula...
Oct 27, 2025This vulnerability in Liferay Portal and DXP allows remote attackers to trigger denial of service attacks by exploiting the ComboServlet's lack of lim...
Oct 23, 2025This CVE describes a self cross-site scripting (XSS) vulnerability in Liferay Portal and DXP that allows remote attackers to inject malicious scripts ...
Oct 23, 2025This vulnerability allows remote attackers to access Liferay's OpenAPI YAML file through a crafted URL, potentially exposing API documentation and int...
Oct 23, 2025This vulnerability allows authenticated users in Liferay Portal/DXP to access and select unauthorized Blueprints through Collection Providers across i...
Oct 22, 2025A reflected cross-site scripting (XSS) vulnerability in Liferay Portal and DXP allows authenticated attackers to inject malicious JavaScript via a spe...
Oct 22, 2025A reflected cross-site scripting (XSS) vulnerability in Liferay Portal and DXP allows remote unauthenticated attackers to inject malicious JavaScript ...
Oct 21, 2025This CVE describes stored cross-site scripting (XSS) vulnerabilities in Liferay Portal and DXP where authenticated users can inject malicious scripts ...
Oct 13, 2025This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal and DXP that allows authenticated users in one virtual i...
Oct 13, 2025This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Liferay DXP that allows authenticated users from one virtual instance t...
Oct 13, 2025This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal and DXP that allows authenticated users to access other ...
Oct 13, 2025A CSRF vulnerability in Liferay Portal and DXP allows attackers to add or edit publication comments without user consent. This affects Liferay Portal ...
Oct 10, 2025This cross-site scripting (XSS) vulnerability in Liferay's workflow process builder allows authenticated attackers to inject malicious scripts or HTML...
Oct 10, 2025A stored cross-site scripting (XSS) vulnerability in Liferay's Commerce view order page allows attackers to inject malicious scripts into account name...
Oct 10, 2025This stored XSS vulnerability allows authenticated attackers to inject malicious scripts into the Account Name field on the Membership page in Liferay...
Oct 10, 2025This CVE describes multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal and DXP calendar events. Attackers can inject malicious scrip...
Oct 9, 2025This CVE describes multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal and DXP notifications widget. Attackers can inject mal...
Oct 8, 2025A stored cross-site scripting (XSS) vulnerability in Liferay Portal and DXP allows attackers to inject malicious scripts into forms with rich text fie...
Oct 8, 2025This stored cross-site scripting (XSS) vulnerability in Liferay's diagram type products allows remote attackers to inject malicious scripts or HTML vi...
Oct 8, 2025This CVE describes stored cross-site scripting (XSS) vulnerabilities in Liferay Portal and DXP where attackers can inject malicious scripts into Terms...
Oct 7, 2025This cross-site scripting (XSS) vulnerability allows remote attackers to inject malicious scripts into Commerce Product Name fields in Liferay Portal ...
Oct 7, 2025This vulnerability allows authenticated users to manipulate file extensions when downloading vCard files from the Profile widget in Liferay. Attackers...
Oct 6, 2025This vulnerability in Liferay Portal and DXP allows unauthorized actors to access sensitive user data through Freemarker templates. It affects multipl...
Oct 3, 2025This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal and DXP that allows authenticated users from one virtual...
Sep 30, 2025This cross-site scripting (XSS) vulnerability allows authenticated users to inject malicious scripts into web content templates in Liferay Portal and ...
Sep 29, 2025This vulnerability in Liferay Portal/DXP allows remote attackers to perform path traversal attacks via the ComboServlet, potentially accessing arbitra...
Sep 29, 2025This CVE describes multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal and DXP calendar widgets. Attackers can inject malicious scri...
Sep 29, 2025A reflected cross-site scripting (XSS) vulnerability in Liferay Portal and DXP allows attackers to inject malicious scripts via the backURLTitle param...
Sep 29, 2025A cross-site scripting (XSS) vulnerability in Liferay's Calendar widget allows attackers to inject malicious scripts or HTML via the Calendar Name fie...
Sep 29, 2025This vulnerability allows remote unauthenticated attackers to reuse expired user sessions through the Single Logout (SLO) API in affected Liferay vers...
Sep 24, 2025A reflected cross-site scripting vulnerability in Liferay Portal and DXP allows authenticated attackers to inject malicious JavaScript via a specific ...
Sep 24, 2025An Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal and DXP allows authenticated users from one virtual instance to add notes t...
Sep 22, 2025This vulnerability allows remote authenticated users to view password reminder answers through audit event logs in affected Liferay versions. This aff...
Sep 22, 2025This vulnerability allows remote authenticated users to bypass permission checks in Liferay's Batch Engine, enabling unauthorized access to exported d...
Sep 22, 2025A stored cross-site scripting (XSS) vulnerability in Liferay Portal and DXP allows attackers to inject malicious scripts into the notifications widget...
Sep 22, 2025This vulnerability allows remote attackers to access and download virtual products for free in Liferay Commerce by exploiting incorrect permission set...
Sep 19, 2025An insecure direct object reference (IDOR) vulnerability in Liferay's Contacts Center widget allows remote attackers to access contact information the...
Sep 19, 2025This is a reflected cross-site scripting (XSS) vulnerability in Liferay's Search widget that allows attackers to inject malicious scripts via the _com...
Sep 16, 2025This vulnerability allows remote attackers to view display page templates in Liferay Portal/DXP without proper authorization checks. Attackers can exp...
Sep 16, 2025This stored XSS vulnerability in Liferay Portal/DXP allows attackers to inject malicious scripts into the externalReferenceCode parameter of custom ob...
Sep 15, 2025Why Monitor Liferay Security Vulnerabilities?
Real-time CVE tracking: Our automated system monitors 134+ known vulnerabilities affecting Liferay products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.
Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Liferay packages in under 60 seconds. No agents required - completely agentless scanning that works across Liferay deployments.
Free vulnerability database: Access detailed information about every Liferay CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.
🚀 Get Started in 60 Seconds
- Register free account & add your servers
- Run one-time scan or schedule automatic monitoring (every 1-24 hours)
- Receive instant alerts when new Liferay CVEs affect your systems
- Access dashboard with severity breakdown & fix instructions