CVE-2025-4576
MEDIUM NUCLEILiferay Digital Experience Platform < 2024.q1.15 - XSS
Title source: ruleDescription
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the modules/apps/blogs/blogs-web/src/main/resources/META-INF/resources/blogs/entry_cover_image_caption.jsp
Nuclei Templates (1)
Liferay Portal & DXP - Cross-Site Scripting
MEDIUMVERIFIEDby xtr0nix
Scores
CVSS v3
6.1
EPSS
0.0558
EPSS Percentile
90.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
com.liferay/com.liferay.blogs.web
0 - 6.0.139Maven
liferay/digital_experience_platform
7.4 (49 CPE variants)
Published
Aug 08, 2025
Tracked Since
Feb 18, 2026