com.liferay.portal:release.portal.bom
Maven159 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting com.liferay.portal:release.portal.bompage 3 of 4
- CVE-2024-25606HIGHCVSS 8.0EG 8.0✓ Fixed in 7.4.3.82024-02-20
vulnerable: 7.0.6 ... 7.4.3.7 (32 versions)
XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12, 7.2 before fix pack 20, and older unsupported versions allows attackers with permission t…
- CVE-2024-25607HIGHCVSS 8.1EG 8.1✓ Fixed in 7.4.3.142024-02-20
vulnerable: 7.0.6 ... 7.4.3.9 (38 versions)
The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported ve…
- CVE-2024-25608MEDIUMCVSS 6.1EG 6.1✓ Fixed in 7.4.3.19-ga192024-02-20
vulnerable: 7.2.0 ... 7.4.3.9 (36 versions)
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be circumvented by usin…
- CVE-2024-25609MEDIUMCVSS 6.1EG 6.1✓ Fixed in 7.4.3.13-ga132024-02-20
vulnerable: 7.2.0 ... 7.4.3.9 (30 versions)
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 service pack 3, 7.2 fix pack 15 through 18, and older unsupported versions can be circumvented by us…
- CVE-2024-25610CRITICALCVSS 9.0EG 9.0✓ Fixed in 7.4.3.132024-02-20
vulnerable: 7.0.6 ... 7.4.3.9 (37 versions)
In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions, the default configuration does not sanitize blog en…
- CVE-2024-26265MEDIUMCVSS 5.0EG 5.0✓ Fixed in 7.4.3.162024-02-20
vulnerable: 7.0.6 ... 7.4.3.9 (40 versions)
The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions relies on a request param…
- CVE-2024-26266CRITICALCVSS 9.0EG 9.0✓ Fixed in 7.4.3.142024-02-21
vulnerable: 7.0.6 ... 7.4.3.9 (38 versions)
Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupported versions, and Liferay DXP 7.4 before update 10, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported v…
- CVE-2024-26267MEDIUMCVSS 5.3EG 5.3✓ Fixed in 7.4.3.26-ga262024-02-20
vulnerable: 7.2.0 ... 7.4.3.9 (45 versions)
In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix pack 19, and older unsupported versions the default value of the portal property `http.head…
- CVE-2024-26268MEDIUMCVSS 5.3EG 5.3✓ Fixed in 7.4.3.27-ga272024-02-20
vulnerable: 7.2.0 ... 7.4.3.9 (46 versions)
User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 8, 7.2 before fix pack 20, and older unsupported versions allows remote attack…
- CVE-2024-26269CRITICALCVSS 9.6EG 9.6✓ Fixed in 7.4.3.382024-02-21
vulnerable: 7.2.0 ... 7.4.3.9 (56 versions)
Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions al…
- CVE-2024-26270MEDIUMCVSS 6.5EG 6.5✓ Fixed in 7.4.3.1002024-02-20
vulnerable: 7.4.3.76 ... 7.4.3.99 (26 versions)
The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 76 through 92 embeds the user’s hashed password in the page’s HTML source, which allows man-in-the-middle att…
- CVE-2024-26271HIGHCVSS 8.8EG 8.8✓ Fixed in 7.4.3.1122024-10-22
vulnerable: 7.4.3.100 ... 7.4.3.99 (35 versions)
Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 update 75 through update 92 and 7.3 update…
- CVE-2024-26272HIGHCVSS 8.8EG 8.8✓ Fixed in 7.4.3.1082024-10-22
vulnerable: 7.3.2 ... 7.4.3.99 (123 versions)
Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 GA through upd…
- CVE-2024-26273HIGHCVSS 8.8EG 8.8✓ Fixed in 7.4.3.1042024-10-22
vulnerable: 7.4.0 ... 7.4.3.99 (111 versions)
Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 update 29 thro…
- CVE-2024-38002CRITICALCVSS 9.0EG 9.0✓ Fixed in 7.4.3.112-ga1122024-10-22
vulnerable: 7.3.3 ... 7.4.3.99 (122 versions)
The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does not properly check user permissions befo…
- CVE-2024-8980CRITICALCVSS 9.6EG 9.6✓ Fixed in 7.4.3.102-GA1022024-10-22
vulnerable: 7.0.6 ... 7.4.3.99 (133 versions)
The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, 7.2 GA through fix pack 20, 7.1 GA through fix pack 28, 7.0 GA through fix pack …
- CVE-2025-2536MEDIUMCVSS 6.1EG 6.1✓ Fixed in 7.4.3.1292025-03-19
vulnerable: 7.4.3.100 ... 7.4.3.99 (34 versions)
Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 u…
- CVE-2025-2565MEDIUMCVSS 4.3EG 4.3✓ Fixed in 7.4.3.1292025-03-20
vulnerable: 7.4.0 ... 7.4.3.99 (121 versions)
The data exposure vulnerability in Liferay Portal 7.4.0 through 7.4.3.126, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through up…
- CVE-2025-3639LOWCVSS 2.0EG 2.02025-08-18
vulnerable: 7.3.0-1 ... 7.4.3.99 (134 versions)
Liferay Portal 7.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 and 7.3 GA t…
- CVE-2025-3760MEDIUMCVSS 5.4EG 5.4✓ Fixed in 7.4.3.1322025-04-17
vulnerable: 7.2.0 ... 7.4.3.99 (137 versions)
A stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Liferay Portal 7.2.0 through 7.4.3.129, and Liferay DXP 2024.Q4.1 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13…
- CVE-2025-43731MEDIUMCVSS 5.4EG 5.42025-08-18
vulnerable: 7.4.1 ... 7.4.3.99 (122 versions)
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.8, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.…
- CVE-2025-43734MEDIUMCVSS 5.4EG 5.42025-08-12
vulnerable: 7.4.0 ... 7.4.3.99 (123 versions)
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024…
- CVE-2025-43735MEDIUMCVSS 6.1EG 6.1✓ Fixed in 7.4.3.1322025-08-12
vulnerable: 7.4.0 ... 7.4.3.99 (122 versions)
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7…
- CVE-2025-43736MEDIUMCVSS 4.3EG 4.32025-08-12
vulnerable: 7.4.3.10 ... 7.4.3.99 (118 versions)
A Denial Of Service via File Upload (DOS) vulnerability in the Liferay Portal 7.4.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.8, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, …
- CVE-2025-43740MEDIUMCVSS 5.4EG 5.42025-08-19
vulnerable: 7.4.3.120-ga120, 7.4.3.125, 7.4.3.125-ga125, 7.4.3.129, 7.4.3.132
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 …
- CVE-2025-43741MEDIUMCVSS 5.4EG 5.42025-08-20
vulnerable: 7.4.1 ... 7.4.3.99 (122 versions)
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.3, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.…
- CVE-2025-43743MEDIUMCVSS 4.3EG 4.32025-08-19
vulnerable: 7.4.1 ... 7.4.3.99 (122 versions)
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows …
- CVE-2025-43744MEDIUMCVSS 5.4EG 5.42025-08-19
vulnerable: 7.4.1 ... 7.4.3.99 (122 versions)
A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.5, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 20…
- CVE-2025-43745MEDIUMCVSS 6.5EG 6.52025-08-19
vulnerable: 7.4.1 ... 7.4.3.99 (122 versions)
A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 t…
- CVE-2025-43746MEDIUMCVSS 5.4EG 5.42025-08-20
vulnerable: 7.4.1 ... 7.4.3.99 (122 versions)
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.2, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.…
- CVE-2025-43748MEDIUMCVSS 6.8EG 6.8✓ Fixed in 7.4.3.120-ga1202025-08-20
vulnerable: 7.0.6 ... 7.4.3.99 (141 versions)
Insufficient CSRF protection for omni-administrator users in Liferay Portal 7.0.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.6, 2023.Q4.0 through 2023.Q4.9, 2023.Q3.1 through 2023.Q3.9, 7.4 GA through update 92, 7.3 GA th…
- CVE-2025-43749MEDIUMCVSS 5.3EG 5.32025-08-20
vulnerable: 7.4.1 ... 7.4.3.99 (122 versions)
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows …
- CVE-2025-43752MEDIUMCVSS 6.5EG 6.52025-08-22
vulnerable: 7.4.1 ... 7.4.3.99 (122 versions)
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allow u…
- CVE-2025-43754MEDIUMCVSS 5.3EG 5.32025-08-21
vulnerable: 7.4.1 ... 7.4.3.99 (122 versions)
Username enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 9…
- CVE-2025-43756MEDIUMCVSS 5.4EG 5.42025-08-21
vulnerable: 7.4.3.132-ga132
<!--td {border: 1px solid #cccccc;}br {mso-data-placement:same-cell;}-->A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.15, 2025.Q2.0 through 2025.Q2.2 and 202…
- CVE-2025-43757MEDIUMCVSS 5.4EG 5.42025-08-20
vulnerable: 7.4.1 ... 7.4.3.99 (122 versions)
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.2, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.…
- CVE-2025-43760MEDIUMCVSS 5.4EG 5.42025-08-22
vulnerable: 7.4.1 ... 7.4.3.99 (122 versions)
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.6, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.…
- CVE-2025-43776MEDIUMCVSS 5.4EG 5.42025-09-09
vulnerable: 7.4.0 ... 7.4.3.99 (123 versions)
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 thr…
- CVE-2025-43785MEDIUMCVSS 6.1EG 6.1✓ Fixed in 7.4.3.1292025-09-10
vulnerable: 7.4.3.100 ... 7.4.3.99 (73 versions)
Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45 through 7.4.3.128, and Liferay DXP 2024 Q2.0 through 2024.Q2.9, 2024.Q1.1 through 2024.Q1.12, and 7.4 update 45 through update 92 allows remote attackers to execute…
- CVE-2025-43799MEDIUMCVSS 6.5EG 6.5✓ Fixed in 7.4.3.1122025-09-15
vulnerable: 7.4.0 ... 7.4.3.99 (115 versions)
Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35, and older unsupported versions does not limit access to …
- CVE-2025-43812MEDIUMCVSS 5.4EG 5.4✓ Fixed in 7.4.3.112-ga1122025-09-29
vulnerable: 7.4.3.10 ... 7.4.3.99 (110 versions)
Cross-site scripting (XSS) vulnerability in web content template in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticate…
- CVE-2025-43813HIGHCVSS 8.2EG 8.2✓ Fixed in 7.4.3.108-ga1082025-09-29
vulnerable: 7.4.1 ... 7.4.3.99 (114 versions)
Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.107, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.8, 7.4 GA thr…
- CVE-2025-43817MEDIUMCVSS 6.1EG 6.1✓ Fixed in 7.4.3.112-ga1122025-09-29
vulnerable: 7.4.3.100 ... 7.4.3.99 (36 versions)
Multiple reflected cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.74 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.6, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 74 through update 92 allow remote attacker…
- CVE-2025-43820MEDIUMCVSS 5.4EG 5.4✓ Fixed in 7.4.3.111-ga1112025-09-29
vulnerable: 7.4.3.100 ... 7.4.3.99 (76 versions)
Multiple cross-site scripting (XSS) vulnerabilities in the Calendar widget when inviting users to a event in Liferay Portal 7.4.3.35 through 7.4.3.110, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.6, 7.4 update 35…
- CVE-2025-43822MEDIUMCVSS 5.4EG 5.4✓ Fixed in 7.4.3.112-ga1122025-10-07
vulnerable: 7.4.3.100 ... 7.4.3.99 (100 versions)
Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 15 through update 92 allow remote attackers t…
- CVE-2025-43823MEDIUMCVSS 5.4EG 5.4✓ Fixed in 7.4.3.112-ga1122025-10-07
vulnerable: 7.4.0 ... 7.4.3.99 (116 versions)
Cross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 2023.Q4 before patch 6, 2023.Q3 before patch 9, and 7.4 GA through update 92 allows remote attackers t…
- CVE-2025-43824MEDIUMCVSS 5.4EG 5.4✓ Fixed in 7.4.3.112-ga1122025-10-06
vulnerable: 7.4.1 ... 7.4.3.99 (115 versions)
The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions uses a user’…
- CVE-2025-43826MEDIUMCVSS 5.4EG 5.4✓ Fixed in 7.4.3.113-ga1132025-09-30
vulnerable: 7.4.1 ... 7.4.3.99 (116 versions)
Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA throu…
- CVE-2025-43830MEDIUMCVSS 6.1EG 6.1✓ Fixed in 7.4.3.112-ga1122025-10-08
vulnerable: 7.3.2 ... 7.4.3.99 (124 versions)
Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and 7.3 GA through update 35 allows rem…
- CVE-2025-4581HIGHCVSS 8.6EG 8.62025-08-09
vulnerable: 7.4.0 ... 7.4.3.99 (123 versions)
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 allows a p…
Check whether com.liferay.portal:release.portal.bom is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for com.liferay.portal:release.portal.bom CVEs against the assets you own.
Start Free Scan →