liferay

340 tracked vulnerabilities.

CVE-2025-62275 MEDIUM
Liferay DXP 7.4.0-7.4.3.111 & 2023.Q4.0-2023.Q4.10 - Unauthenticated Image Access
Nov 01, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-62276 MEDIUM
Liferay Portal <7.4.3.111 - Info Disclosure
Nov 01, 2025
CVSS 5.5
EPSS 0.00
CVE-2025-62267 MEDIUM
Liferay Digital Experience Platform < 7.4.3.112 - XSS
Oct 31, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-62264 MEDIUM
Liferay Digital Experience Platform < 7.4.3.112 - XSS
Oct 31, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-62265 MEDIUM
Liferay Digital Experience Platform < 7.4 - Stored Cross-Site Scripting in Blogs Widget via iframe Injection
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-62266 MEDIUM
Liferay Digital Experience Platform < 7.4.3.110 - Open Redirect
Oct 30, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-62257 MEDIUM
Liferay Portal 7.4.0-7.4.3.119 and DXP 2024.Q1.1-2024.Q1.5 - Password Enumeration via Brute Force Attack
Oct 30, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-62259 MEDIUM
Liferay Portal 7.4.0-7.4.3.109 & DXP 2023.Q3.1-2023.Q3.4 - Unauthenticated API Access
Oct 27, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-62258 MEDIUM
Liferay DXP 7.4.0-7.4.3.107, 2023.Q3.1-2023.Q3.4, 7.4 GA-92, 7.3 GA-35 - CSRF via Headless API
Oct 27, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-62261 MEDIUM
Liferay Portal 7.4.0-7.4.3.99 & DXP 2023.Q3.1-2023.Q3.4, 7.4 GA-92, 7.3 GA-34 - Cleartext Password Reset Tokens
Oct 27, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-62260 HIGH
Liferay Portal 7.4.0-7.4.3.99 & DXP 2023.Q3.1-2023.Q3.4, 7.4 GA-92, 7.3 GA-35 - DoS via Headless API
Oct 27, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-62262 MEDIUM
Liferay DXP 7.4.0-7.4.3.97 & 2023.Q3.1-2023.Q3.4 - Information Exposure via LDAP Logs
Oct 27, 2025
CVSS 4.4
EPSS 0.00
CVE-2025-62263 MEDIUM
Liferay Digital Experience Platform < 7.4.3.104 - XSS
Oct 27, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-62253 MEDIUM
Liferay Digital Experience Platform < 7.3 and 7.4.0-7.4.3.97 - Open Redirect via GroupPagesPortlet Redirect Parameter
Oct 27, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-62254 HIGH
Liferay Digital Experience Platform - Denial of Service via ComboServlet Query String
Oct 23, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-62255 MEDIUM
Liferay DXP <7.3 & 7.4.0-7.4.3.101 - Stored XSS via Knowledge Base Attachment
Oct 23, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-62256 MEDIUM
Liferay Portal 7.4.0-7.4.3.109 & DXP Unauthenticated OpenAPI YAML Access
Oct 23, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-62247 MEDIUM
Liferay Portal 7.4.0-7.4.3.132 and Liferay DXP 2024.Q1.1-2024.Q1.19 - Missing Authorization in Collection Provider
Oct 22, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-62248 MEDIUM
Liferay Portal 7.4.0-7.4.3.132 & DXP 2024.Q1.1-2024.Q1.19 - Authenticated XSS via DDMPortlet Definition Parameter
Oct 22, 2025
CVSS 4.8
EPSS 0.00
CVE-2025-62249 MEDIUM
Liferay Portal 7.4.0-7.4.3.132 and Liferay DXP 2023.Q4.0-2023.Q4.10 - Unauthenticated Reflected Cross-Site Scripting
Oct 21, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-62250 MEDIUM
Liferay Digital Experience Platform < 7.3 - Improper Authentication via Unauthenticated Cluster Messages
Oct 21, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-62251 MEDIUM
Liferay Portal 7.3.0-7.4.3.119 & DXP < 2023.Q3.9/2023.Q4.6/7.4 GA-92/7.3 GA-36 - Unauthorized Information Disclosure
Oct 13, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-62252 MEDIUM
Liferay Portal 7.4.0-7.4.3.111 & DXP 2023.Q4.0-2023.Q4.5 IDOR via UsersAdminPortlet
Oct 13, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-62246 MEDIUM
Liferay Portal 7.4.0-7.4.3.111 and DXP < 2023.Q4.6 - Authenticated Stored Cross-Site Scripting via User Name Field
Oct 13, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-62242 MEDIUM
Liferay Portal 7.4.3.4-7.4.3.111 & DXP 2023.Q4.0-2023.Q4.5, 2023.Q3.1-2023.Q3.8, 7.4 GA-92 - IDOR via Account Address
Oct 13, 2025
CVSS 4.3
EPSS 0.00