com.liferay.portal:release.portal.bom
Maven159 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting com.liferay.portal:release.portal.bompage 4 of 4
- CVE-2025-4655MEDIUMCVSS 5.0EG 5.02025-08-09
vulnerable: 7.4.0 ... 7.4.3.99 (123 versions)
SSRF vulnerability in FreeMarker templates in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2…
- CVE-2025-62257MEDIUMCVSS 5.3EG 5.3✓ Fixed in 7.4.3.1202025-10-30
vulnerable: 7.4.1 ... 7.4.3.99 (116 versions)
Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92…
- CVE-2025-62258MEDIUMCVSS 6.5EG 6.5✓ Fixed in 7.4.3.1082025-10-27
vulnerable: 7.4.1 ... 7.4.3.99 (114 versions)
CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to execut…
- CVE-2025-62259MEDIUMCVSS 5.4EG 5.4✓ Fixed in 7.4.3.1102025-10-27
vulnerable: 7.4.1 ... 7.4.3.99 (114 versions)
Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a …
- CVE-2025-62260HIGHCVSS 7.5EG 7.5✓ Fixed in 7.4.3.1002025-10-27
vulnerable: 7.4.1 ... 7.4.3.99 (106 versions)
Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number of objects returned from Headless API requests…
- CVE-2025-62261MEDIUMCVSS 6.5EG 6.5✓ Fixed in 7.4.3.1002025-10-27
vulnerable: 7.4.1 ... 7.4.3.99 (106 versions)
Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 34, and older unsupported versions stores password reset tokens in plain te…
- CVE-2025-62264MEDIUMCVSS 6.1EG 6.1✓ Fixed in 7.4.3.112-ga1122025-10-31
vulnerable: 7.4.3.10 ... 7.4.3.99 (107 versions)
Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 update 4 through update 92 allows rem…
- CVE-2025-62265MEDIUMCVSS 5.4EG 5.4✓ Fixed in 7.4.3.112-ga1122025-10-30
vulnerable: 7.4.1 ... 7.4.3.99 (115 versions)
Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, 7.…
- CVE-2025-62266MEDIUMCVSS 6.1EG 6.1✓ Fixed in 7.4.3.1102025-10-30
vulnerable: 7.4.1 ... 7.4.3.99 (114 versions)
By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported ve…
Check whether com.liferay.portal:release.portal.bom is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for com.liferay.portal:release.portal.bom CVEs against the assets you own.
Start Free Scan →