Exposição de Liferay

CMS
152
score de exposição
6.183
sites usam
0
em exploração
23
críticos
Análise Vexday

Com 210 CVEs catalogadas e 23 classificadas como críticas, o Liferay apresenta um histórico de vulnerabilidades que merece atenção em ambientes corporativos, especialmente por tratar-se de uma plataforma de portal amplamente utilizada. Nenhuma CVE do Liferay consta atualmente no catálogo KEV da CISA, indicando taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão imediata de ataques confirmados, mas não elimina o risco potencial. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que tende a favorecer ataques de injeção de conteúdo e comprometimento de sessões em ambientes com controles de saída insuficientes. A CVE mais relevante no momento, CVE-2025-4388, registra um índice EPSS de aproximadamente 0,03, indicando probabilidade de exploração ainda baixa, mas que deve ser monitorada dado o perfil crítico da plataforma.

CVEs

210 resultados
CVE-2025-43773MEDIUMLiferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 thrEPSS 0.3%CVE-2025-2536MEDIUMCross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.EPSS 0.3%CVE-2025-43743MEDIUMLiferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.EPSS 0.3%CVE-2025-62244MEDIUMInsecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.3.1 through 7.4.3.111, and Liferay DXP 2023.Q4.0 tEPSS 0.3%CVE-2025-43736MEDIUMA Denial Of Service via File Upload (DOS) vulnerability in the Liferay Portal 7.4.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2EPSS 0.3%CVE-2025-43737MEDIUMA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8 and 2025.QEPSS 0.3%CVE-2025-43739MEDIUMLiferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.EPSS 0.3%CVE-2025-43759MEDIUMLiferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 throEPSS 0.3%CVE-2025-43803MEDIUMInsecure direct object reference (IDOR) vulnerability in the Contacts Center widget in Liferay Portal 7.4.0 through 7.4.3.119, and older unsEPSS 0.3%CVE-2025-62241MEDIUMInsecure Direct Object Reference (IDOR) vulnerability with shipment addresses in Liferay DXP 2023.Q4.1 through 2023.Q4.5 allows remote autheEPSS 0.3%CVE-2025-62261MEDIUMLiferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92EPSS 0.3%CVE-2025-62275MEDIUMBlogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 thrEPSS 0.3%CVE-2025-43810MEDIUMInsecure Direct Object Reference (IDOR) vulnerability with commerce order notes in Liferay Portal 7.3.5 through 7.4.3.112, and Liferay DXP 2EPSS 0.3%CVE-2025-62251MEDIUMLiferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA through update 92 aEPSS 0.3%CVE-2023-37940MEDIUMCross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87, and Liferay DXP 7.EPSS 0.3%CVE-2025-62252MEDIUMInsecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and LiferayEPSS 0.3%CVE-2025-3760MEDIUMA stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Liferay Portal 7.2.0 through 7.4.3.129, andEPSS 0.3%CVE-2025-2565MEDIUMThe data exposure vulnerability in Liferay Portal 7.4.0 through 7.4.3.126, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.EPSS 0.3%CVE-2025-62247LOWMissing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025EPSS 0.3%CVE-2025-43760MEDIUMA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.QEPSS 0.3%