Liferay, Inc.

First CVE: May 24, 2023Active for: 3 years
210
CVEs Published
More CVEs Published than 80% of tracked CNAs
70.0
Avg CVEs / Year
More Avg CVEs / Year than 87% of tracked CNAs
5.9
Avg CVSS Score
Higher Avg CVSS Score than 8% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Liferay, Inc. as a CNA, 99.0% affect products that Liferay, Inc. develops as a vendor.

99.0%
Self-reported: 208Third-party: 2

Of all the CVEs published that affect products developed by Liferay, Inc., 61.5% are self-published by Liferay, Inc. as a CNA.

61.5%
38.5%
Self-published: 208Published by other CNAs: 130

Trends Over Time

The number and severity of CVEs published by Liferay, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 24, 2023
3 years ago
Most Recent CVE
Nov 1, 2025
265 days ago

Top CVEs

All CVEs published by Liferay, Inc. as a CNA, regardless of affected vendor or product.

210 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.
May 6, 20256.135NOYES
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q
Aug 8, 20256.132NOYES
The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through u
Aug 23, 20259.831NONO
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.
Aug 29, 20259.128NONO
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19,
Feb 20, 20246.128NOYES
Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 34, and older u
Jun 16, 20259.827NONO
Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.107, and older unsupported versions, and Liferay DXP 2023.Q4.0
Sep 29, 20258.226NONO
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q
Aug 9, 20258.626NONO
Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limi
Oct 27, 20257.525NONO
The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through
Oct 23, 20257.525NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA210 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local2 (1.0%)
Network208 (99.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low206 (98.1%)
High4 (1.9%)
Unknown0 (0.0%)
User Interaction
None89 (42.4%)
Unknown0 (0.0%)
Required120 (57.1%)
Privileges Required
Low99 (47.1%)
High10 (4.8%)
None101 (48.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (210 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
1.4% of CVEs· 83rd percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Liferay, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Liferay, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs