Exposição de Liferay

CMS
152
score de exposição
6.183
sites usam
0
em exploração
23
críticos
Análise Vexday

Com 210 CVEs catalogadas e 23 classificadas como críticas, o Liferay apresenta um histórico de vulnerabilidades que merece atenção em ambientes corporativos, especialmente por tratar-se de uma plataforma de portal amplamente utilizada. Nenhuma CVE do Liferay consta atualmente no catálogo KEV da CISA, indicando taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão imediata de ataques confirmados, mas não elimina o risco potencial. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que tende a favorecer ataques de injeção de conteúdo e comprometimento de sessões em ambientes com controles de saída insuficientes. A CVE mais relevante no momento, CVE-2025-4388, registra um índice EPSS de aproximadamente 0,03, indicando probabilidade de exploração ainda baixa, mas que deve ser monitorada dado o perfil crítico da plataforma.

CVEs

210 resultados
CVE-2025-62266MEDIUMBy default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 tEPSS 0.2%CVE-2025-43807MEDIUMStored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.EPSS 0.2%CVE-2025-43787MEDIUMA Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q3.0, 2025.Q2.0 through 202EPSS 0.2%CVE-2025-43771MEDIUMMultiple cross-site scripting (XSS) vulnerabilities in the Notifications widget in Liferay Portal 7.4.3.102 through 7.4.3.111, and Liferay DEPSS 0.2%CVE-2025-43812MEDIUMCross-site scripting (XSS) vulnerability in web content template in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 2023.Q4.0 throEPSS 0.2%CVE-2025-43820MEDIUMMultiple cross-site scripting (XSS) vulnerabilities in the Calendar widget when inviting users to a event in Liferay Portal 7.4.3.35 throughEPSS 0.2%CVE-2025-43789LOWJSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.9, 7.4 GA through update 92 publishedEPSS 0.2%CVE-2025-62259MEDIUMLiferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 9EPSS 0.2%CVE-2025-62263MEDIUMMultiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, EPSS 0.2%CVE-2025-62265MEDIUMCross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and EPSS 0.2%CVE-2025-43753LOWA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.32 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 202EPSS 0.2%CVE-2025-62255LOWSelf Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Portal 7.4.0 through 7.4.3.101, and older uEPSS 0.2%CVE-2025-43770MEDIUMA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.QEPSS 0.2%CVE-2025-43763MEDIUMA server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2EPSS 0.2%CVE-2025-43742MEDIUMA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.QEPSS 0.2%CVE-2025-43765MEDIUMA Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024EPSS 0.2%CVE-2025-43761MEDIUMA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.QEPSS 0.2%CVE-2025-62245MEDIUMCross-site request forgery (CSRF) vulnerability in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023EPSS 0.2%CVE-2025-43767MEDIUMOpen Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.86 through 7.4.3.131, and Liferay DXP 202EPSS 0.2%CVE-2025-43744MEDIUMA stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 202EPSS 0.2%