Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Liferay — Vulnerabilities & Security Advisories 210

Browse all 210 CVE security advisories affecting Liferay. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Liferay is an enterprise open-source platform primarily utilized for building digital experiences, including websites, portals, and intranets. Its extensive feature set and Java-based architecture have historically attracted significant security scrutiny, resulting in over 210 recorded Common Vulnerabilities and Exposures. The most prevalent vulnerability classes involve remote code execution, cross-site scripting, and privilege escalation, often stemming from insecure deserialization flaws or improper access controls within its portal components. Notable incidents include critical RCE vulnerabilities that allowed unauthenticated attackers to execute arbitrary commands on affected servers, highlighting risks associated with default configurations and legacy code paths. While the platform offers robust enterprise-grade features, its complexity necessitates rigorous patch management and secure configuration practices to mitigate the high volume of identified security defects.

Top products by Liferay: Portal DXP
CVE IDTitleCVSSSeverityPublished
CVE-2025-62238 Liferay Portal和Liferay DXP 跨站脚本漏洞 — PortalCWE-79 5.4AIMediumAI2025-10-10
CVE-2025-62239 Liferay Portal和Liferay DXP 跨站脚本漏洞 — PortalCWE-79 5.4AIMediumAI2025-10-10
CVE-2025-62240 Liferay Portal和Liferay DXP 跨站脚本漏洞 — PortalCWE-79 5.4AIMediumAI2025-10-09
CVE-2025-43771 Liferay Portal和Liferay DXP 跨站脚本漏洞 — PortalCWE-79 5.4AIMediumAI2025-10-08
CVE-2025-43829 Liferay Portal和Liferay DXP 跨站脚本漏洞 — PortalCWE-79 5.4AIMediumAI2025-10-08
CVE-2025-43830 Liferay Portal和Liferay DXP 跨站脚本漏洞 — PortalCWE-79 5.4AIMediumAI2025-10-08
CVE-2025-43821 Liferay Portal和Liferay DXP 跨站脚本漏洞 — PortalCWE-79 5.4AIMediumAI2025-10-08
CVE-2025-43822 Liferay Portal和Liferay DXP 跨站脚本漏洞 — PortalCWE-79 5.4AIMediumAI2025-10-07
CVE-2025-43823 Liferay Portal和Liferay DXP 跨站脚本漏洞 — PortalCWE-79 5.4AIMediumAI2025-10-07
CVE-2025-43824 Liferay Portal和Liferay DXP 跨站脚本漏洞 — PortalCWE-79 3.5AILowAI2025-10-06
CVE-2025-43825 Liferay Portal和Liferay DXP 安全漏洞 — PortalCWE-201 9.1AICriticalAI2025-10-03
CVE-2025-43826 Liferay Portal和Liferay DXP 跨站脚本漏洞 — PortalCWE-79 6.1AIMediumAI2025-09-30
CVE-2025-43827 Liferay Portal和Liferay DXP 安全漏洞 — PortalCWE-639 6.5AIMediumAI2025-09-30
CVE-2025-43817 Liferay Portal和Liferay DXP 跨站脚本漏洞 — PortalCWE-79 6.1AIMediumAI2025-09-29
CVE-2025-43813 Liferay Portal和Liferay DXP 路径遍历漏洞 — PortalCWE-22 8.2AIHighAI2025-09-29
CVE-2025-43812 Liferay Portal和Liferay DXP 跨站脚本漏洞 — PortalCWE-79 5.4AIMediumAI2025-09-29
CVE-2025-43811 Liferay Portal和Liferay DXP 跨站脚本漏洞 — PortalCWE-79 5.4AIMediumAI2025-09-29
CVE-2025-43820 Liferay Portal和Liferay DXP 跨站脚本漏洞 — PortalCWE-79 5.4AIMediumAI2025-09-29
CVE-2025-43818 Liferay Portal和Liferay DXP 跨站脚本漏洞 — PortalCWE-79 5.4AIMediumAI2025-09-29
CVE-2025-43815 Liferay Portal和Liferay DXP 跨站脚本漏洞 — PortalCWE-79 6.1AIMediumAI2025-09-29
CVE-2025-43816 Liferay Portal和Liferay DXP 安全漏洞 — PortalCWE-401 7.5AIHighAI2025-09-25
CVE-2025-43819 Liferay Portal和Liferay DXP 代码问题漏洞 — PortalCWE-613 8.2AIHighAI2025-09-24
CVE-2025-43779 Liferay Portal和Liferay DXP 跨站脚本漏洞 — PortalCWE-79 5.4AIMediumAI2025-09-24
CVE-2025-43814 Liferay Portal和Liferay DXP 安全漏洞 — PortalCWE-201 4.3AIMediumAI2025-09-22
CVE-2025-43810 Liferay Portal和Liferay DXP 安全漏洞 — PortalCWE-639 4.3AIMediumAI2025-09-22
CVE-2025-43806 Liferay Portal和Liferay DXP 安全漏洞 — PortalCWE-863 6.5AIMediumAI2025-09-22
CVE-2025-43807 Liferay Portal和Liferay DXP 跨站脚本漏洞 — PortalCWE-79 5.4AIMediumAI2025-09-22
CVE-2025-43808 Liferay Portal和Liferay DXP 安全漏洞 — PortalCWE-732 7.5 -2025-09-19
CVE-2025-43809 Liferay Portal和Liferay DXP 安全漏洞 — PortalCWE-352 6.5 -2025-09-19
CVE-2025-43803 Liferay Portal和Liferay DXP 安全漏洞 — PortalCWE-639 5.3 -2025-09-19

This page lists every published CVE security advisory associated with Liferay. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.