Exposición de Liferay

CMS
152
score de exposición
6183
sitios usan
0
en explotación
23
críticos
Análisis Vexday

Com 210 CVEs catalogadas e 23 classificadas como críticas, o Liferay apresenta um histórico de vulnerabilidades que merece atenção em ambientes corporativos, especialmente por tratar-se de uma plataforma de portal amplamente utilizada. Nenhuma CVE do Liferay consta atualmente no catálogo KEV da CISA, indicando taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão imediata de ataques confirmados, mas não elimina o risco potencial. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que tende a favorecer ataques de injeção de conteúdo e comprometimento de sessões em ambientes com controles de saída insuficientes. A CVE mais relevante no momento, CVE-2025-4388, registra um índice EPSS de aproximadamente 0,03, indicando probabilidade de exploração ainda baixa, mas que deve ser monitorada dado o perfil crítico da plataforma.

CVEs

210 resultados
CVE-2025-62237MEDIUMStored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2EPSS 0.2%CVE-2025-62238MEDIUMStored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 through 7.4.3.111, andEPSS 0.2%CVE-2025-62240MEDIUMMultiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.EPSS 0.2%CVE-2025-62246MEDIUMMultiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and LiEPSS 0.2%CVE-2025-62263MEDIUMMultiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, EPSS 0.2%CVE-2025-43811MEDIUMMultiple stored cross-site scripting (XSS) vulnerability in the related asset selector in Liferay Portal 7.4.3.50 through 7.4.3.111, and LifEPSS 0.2%CVE-2025-62265MEDIUMCross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and EPSS 0.2%CVE-2025-43731MEDIUMA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.QEPSS 0.2%CVE-2025-43756MEDIUM<!--td {border: 1px solid #cccccc;}br {mso-data-placement:same-cell;}-->A reflected cross-site scripting (XSS) vulnerability in the Liferay EPSS 0.2%CVE-2025-43734MEDIUMA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.QEPSS 0.2%CVE-2025-62267MEDIUMMultiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page in Liferay Portal 7.4.3.35 through 7.4.3EPSS 0.2%CVE-2025-43735MEDIUMA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.QEPSS 0.2%CVE-2025-43738MEDIUMA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.QEPSS 0.2%CVE-2025-43741MEDIUMA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.QEPSS 0.2%CVE-2025-43746MEDIUMA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.QEPSS 0.2%CVE-2025-43757MEDIUMA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.QEPSS 0.2%CVE-2025-43775MEDIUMStored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.5, 2024EPSS 0.2%CVE-2025-43733LOWA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7 allows a rEPSS 0.2%CVE-2025-43755MEDIUMA Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 t through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 20EPSS 0.2%CVE-2025-43740MEDIUMA Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8, EPSS 0.2%