Exposição de Liferay

CMS
152
score de exposição
6.183
sites usam
0
em exploração
23
críticos
Análise Vexday

Com 210 CVEs catalogadas e 23 classificadas como críticas, o Liferay apresenta um histórico de vulnerabilidades que merece atenção em ambientes corporativos, especialmente por tratar-se de uma plataforma de portal amplamente utilizada. Nenhuma CVE do Liferay consta atualmente no catálogo KEV da CISA, indicando taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão imediata de ataques confirmados, mas não elimina o risco potencial. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que tende a favorecer ataques de injeção de conteúdo e comprometimento de sessões em ambientes com controles de saída insuficientes. A CVE mais relevante no momento, CVE-2025-4388, registra um índice EPSS de aproximadamente 0,03, indicando probabilidade de exploração ainda baixa, mas que deve ser monitorada dado o perfil crítico da plataforma.

CVEs

210 resultados
CVE-2025-43779MEDIUMA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024.Q1.1 through 2024.QEPSS 0.2%CVE-2025-43781MEDIUMReflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.110 through 7.4.3.128, and Liferay DXP 2024.Q3.1 through 2024.Q3.EPSS 0.2%CVE-2025-43777MEDIUMLiferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.QEPSS 0.2%CVE-2025-43804MEDIUMCross-site scripting (XSS) vulnerability in Search widget in Liferay Portal 7.4.3.93 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1EPSS 0.2%CVE-2025-62264MEDIUMReflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.QEPSS 0.2%CVE-2025-4655MEDIUMSSRF vulnerability in FreeMarker templates in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0EPSS 0.2%CVE-2025-43778MEDIUMA Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.11, 20EPSS 0.2%CVE-2025-43769MEDIUMStored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.8, 2024EPSS 0.2%CVE-2025-62239MEDIUMCross-site scripting (XSS) vulnerability in workflow process builder in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0EPSS 0.2%CVE-2025-43785MEDIUMStored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45 through 7.4.3.128, and Liferay DXP 2024 Q2.0 through 2024.Q2.9, 2EPSS 0.2%CVE-2024-8980CRITICALThe Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA EPSS 0.2%CVE-2025-43821MEDIUMCross-site scripting (XSS) vulnerability in the Commerce Product Comparison Table widget in Liferay Portal 7.4.0 through 7.4.3.111, and LifeEPSS 0.2%CVE-2025-43800MEDIUMCross-site scripting (XSS) vulnerability in Objects in Liferay Portal 7.4.3.20 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 throuEPSS 0.2%CVE-2025-43818MEDIUMCross-site scripting (XSS) vulnerability in the Calendar widget in Liferay Portal 7.4.3.35 through 7.4.3.110, and Liferay DXP 2023.Q4.0 throEPSS 0.2%CVE-2025-43822MEDIUMMultiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2EPSS 0.2%CVE-2025-43823MEDIUMCross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 202EPSS 0.2%CVE-2025-43826MEDIUMStored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 through 7.4.3.112, and older unsupporteEPSS 0.2%CVE-2025-43829MEDIUMStored cross-site scripting (XSS) vulnerability in diagram type products in Commerce in Liferay Portal 7.4.3.18 through 7.4.3.111, and LiferEPSS 0.2%CVE-2025-62237MEDIUMStored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2EPSS 0.2%CVE-2025-62238MEDIUMStored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 through 7.4.3.111, andEPSS 0.2%