Liferay, Inc. maintains a Digital Experience Platform (DXP) and associated portal products that serve as enterprise web-content management and portal infrastructure for large organizations, concentrating its vulnerability footprint in a narrow product line deployed across a broad user base. The vendor's disclosures recur consistently around web-application input handling and access-control weaknesses—cross-site scripting, cross-site request forgery, open redirects, and authorization bypass—that are characteristic of large, feature-rich portal systems handling user-generated content and complex permission models. A moderate share of its vulnerabilities acquire public exploit code, making timely patching operationally important for organizations running internet-exposed portal instances. The structural role of these products in web-facing identity and content systems means that flaws in input sanitization and session management directly expose downstream business applications and user data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Liferay, Inc. over time
Of all the CVEs published by Liferay, Inc. as a CNA, 99.0% affect products that Liferay, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Liferay, Inc., 61.5% are self-published by Liferay, Inc. as a CNA.
Signals from CVEs in this vendor scope (338 CVEs).
338 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7961CRITICAL Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS). | Mar 20, 2020 | 9.8 | 99 | YES | YES |
CVE-2019-16891CRITICAL Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload. | Oct 4, 2019 | 9.8 | 58 | NO | NO |
CVE-2021-33990CRITICAL Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference li | Apr 16, 2023 | 9.8 | 48 | NO | YES |
CVE-2019-11444HIGH An issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script console to execute OS commands. Commands can be executed via a [command].execute | Apr 22, 2019 | 7.2 | 40 | NO | YES |
CVE-2011-1571MEDIUM Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote attackers to ex | May 7, 2011 | 6.8 | 37 | NO | YES |
CVE-2025-4388MEDIUM A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024. | May 6, 2025 | 6.1 | 35 | NO | YES |
CVE-2022-42120CRITICAL A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to exe | Nov 15, 2022 | 9.8 | 33 | NO | NO |
CVE-2022-42118MEDIUM A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7. | Nov 15, 2022 | 6.1 | 33 | NO | YES |
CVE-2025-4576MEDIUM A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q | Aug 8, 2025 | 6.1 | 32 | NO | YES |
CVE-2022-42122CRITICAL A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands | Nov 15, 2022 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (338 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Liferay, Inc..
Media articles that mention a CVE ID that affects a product developed by Liferay, Inc. — matched by CVE ID, not by vendor name.