Liferay Portal Vulnerable to Cross-Site Scripting
Moderate severity
GitHub Reviewed
Published
Oct 27, 2025
to the GitHub Advisory Database
•
Updated Nov 15, 2025
Package
Affected versions
>= 2.0.0, < 2.0.108
Patched versions
2.0.108
Description
Published by the National Vulnerability Database
Oct 27, 2025
Published to the GitHub Advisory Database
Oct 27, 2025
Reviewed
Oct 29, 2025
Last updated
Nov 15, 2025
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 service pack 3 through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account Role’s “Title” text field to (1) view account role page, or (2) select account role page.
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 service pack 3 through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Organization’s “Name” text field to (1) view account page, (2) view account organization page, or (3) select account organization page.
References