Vulnerabilidades en Liferay

210 resultados
Análisis Vexday

O portfólio de vulnerabilidades do Liferay acumula 210 CVEs catalogadas, das quais 23 são de severidade crítica e 3 contam com prova de conceito pública disponível — fatores que elevam o risco de exploração mesmo na ausência de registros ativos no catálogo CISA KEV. A taxa de exploração ativa de 0,0% posiciona o vendor abaixo da média geral do catálogo, o que representa um indicador positivo, mas não elimina a necessidade de atenção às falhas críticas existentes. O tipo de falha mais prevalente é CWE-79 (Cross-Site Scripting), historicamente associado a ataques de injeção de conteúdo em aplicações web, como portais corporativos — segmento central no ecossistema Liferay. A CVE mais perigosa em observação no momento é CVE-2025-4388, com escore EPSS de 0,0345, sinalizando probabilidade ainda baixa de exploração em larga escala, mas que deve ser monitorada dado o contexto recente de sua catalogação.

CVE-2025-43749MEDIUMLiferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.EPSS 0.3%CVE-2025-43788MEDIUMThe organization selector in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q1.1 through 2024.Q1.12 and 7.4 update 81 through EPSS 0.3%CVE-2025-43799MEDIUMLiferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA throuEPSS 0.3%CVE-2025-43802MEDIUMStored cross-site scripting (XSS) vulnerability in a custom object’s /o/c/<object-name> API endpoint in Liferay Portal 7.4.3.51 through 7.4.EPSS 0.3%CVE-2025-43784MEDIUMImproper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.8, 2024.Q1.1 thrEPSS 0.3%CVE-2025-43754MEDIUMUsername enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 throughEPSS 0.3%CVE-2025-43806MEDIUMBatch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.10, and 7.4 GEPSS 0.3%CVE-2025-43732MEDIUMLiferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3EPSS 0.2%CVE-2025-62249MEDIUMA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q3.0 through 2025.QEPSS 0.2%CVE-2025-43745MEDIUMA CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2EPSS 0.2%CVE-2025-43797MEDIUMIn Liferay Portal 7.1.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through EPSS 0.2%CVE-2025-43783MEDIUMReflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.73 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1EPSS 0.2%CVE-2025-43830MEDIUMStored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.QEPSS 0.2%CVE-2025-62243MEDIUMInsecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 tEPSS 0.2%CVE-2025-43815MEDIUMReflected cross-site scripting (XSS) vulnerability on the page configuration page in Liferay Portal 7.4.3.102 through 7.4.3.110, and LiferayEPSS 0.2%CVE-2025-62248MEDIUMA reflected cross-site scripting (XSS) vulnerability, resulting from a regression, has been identified in Liferay Portal 7.4.0 through 7.4.EPSS 0.2%CVE-2025-43795MEDIUMOpen redirect vulnerability in the System Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4 , EPSS 0.2%CVE-2025-43824MEDIUMThe Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2EPSS 0.2%CVE-2025-43794MEDIUMStored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2EPSS 0.2%CVE-2025-62253MEDIUMOpen redirect vulnerability in page administration in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXPEPSS 0.2%