Exposição de Liferay

CMS
152
score de exposição
6.183
sites usam
0
em exploração
23
críticos
Análise Vexday

Com 210 CVEs catalogadas e 23 classificadas como críticas, o Liferay apresenta um histórico de vulnerabilidades que merece atenção em ambientes corporativos, especialmente por tratar-se de uma plataforma de portal amplamente utilizada. Nenhuma CVE do Liferay consta atualmente no catálogo KEV da CISA, indicando taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão imediata de ataques confirmados, mas não elimina o risco potencial. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que tende a favorecer ataques de injeção de conteúdo e comprometimento de sessões em ambientes com controles de saída insuficientes. A CVE mais relevante no momento, CVE-2025-4388, registra um índice EPSS de aproximadamente 0,03, indicando probabilidade de exploração ainda baixa, mas que deve ser monitorada dado o perfil crítico da plataforma.

CVEs

210 resultados
CVE-2025-43809MEDIUMCross-Site Request Forgery (CSRF) vulnerability in the server (license) registration page in Liferay Portal 7.4.0 through 7.4.3.111, and oldEPSS 0.2%CVE-2025-43819MEDIUMA Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4EPSS 0.2%CVE-2025-43798LOWLiferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time passwEPSS 0.2%CVE-2025-4599LOWThe fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP 2024.Q4.1 through 2024.Q4.5, 2024.Q3.1 throEPSS 0.2%CVE-2025-62250MEDIUMImproper Authentication in Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 throEPSS 0.2%CVE-2025-62258HIGHCSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through upEPSS 0.2%CVE-2025-43748HIGHInsufficient CSRF protection for omni-administrator users in Liferay Portal 7.0.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.EPSS 0.2%CVE-2025-4604MEDIUMThe vulnerable code can bypass the Captcha check in Liferay Portal 7.4.3.80 through 7.4.3.132, and Liferay DXP 2024.Q1.1 through 2024.Q1.19,EPSS 0.2%CVE-2025-62262MEDIUMInformation exposure through log file vulnerability in LDAP import feature in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported vEPSS 0.1%CVE-2025-62276MEDIUMThe Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DEPSS 0.1%