PT-2025-36920 · Liferay · Liferay Portal+1

Published

2025-09-09

·

Updated

2025-12-16

·

CVE-2025-43781

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Liferay Portal versions 7.4.3.110 through 7.4.3.128 Liferay DXP versions 2024.Q1.1 through 2024.Q1.12 Liferay DXP versions 2024.Q2.0 through 2024.Q2.13 Liferay DXP versions 2024.Q3.1 through 2024.Q3.8
Description: A reflected cross-site scripting (XSS) vulnerability exists. This allows remote attackers to inject arbitrary web script or HTML via the URL in the search bar portlet.
Recommendations: Liferay Portal versions 7.4.3.110 through 7.4.3.128: Update to a newer version. Liferay DXP versions 2024.Q1.1 through 2024.Q1.12: Update to a newer version. Liferay DXP versions 2024.Q2.0 through 2024.Q2.13: Update to a newer version. Liferay DXP versions 2024.Q3.1 through 2024.Q3.8: Update to a newer version.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-43781
GHSA-X5FW-8XGX-Q6C9

Affected Products

Liferay Dxp
Liferay Portal