Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Liferay, Inc.

First CVE: May 22, 2004Active for: 22 yearsTotal CVEs: 338
46.7
VTI Score
High

Liferay, Inc. maintains a Digital Experience Platform (DXP) and associated portal products that serve as enterprise web-content management and portal infrastructure for large organizations, concentrating its vulnerability footprint in a narrow product line deployed across a broad user base. The vendor's disclosures recur consistently around web-application input handling and access-control weaknesses—cross-site scripting, cross-site request forgery, open redirects, and authorization bypass—that are characteristic of large, feature-rich portal systems handling user-generated content and complex permission models. A moderate share of its vulnerabilities acquire public exploit code, making timely patching operationally important for organizations running internet-exposed portal instances. The structural role of these products in web-facing identity and content systems means that flaws in input sanitization and session management directly expose downstream business applications and user data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
338
Total CVEs
More Total CVEs than 100% of tracked vendors
2.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 28% of tracked vendors
0.3%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Liferay, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 22, 2004
22 years ago
Most Recent CVE
Nov 1, 2025
265 days ago

Self-Reporting Analysis

Of all the CVEs published by Liferay, Inc. as a CNA, 99.0% affect products that Liferay, Inc. develops as a vendor.

99.0%
Self-reported: 208 (99.0%)
Third-party: 2 (1.0%)

Of all the CVEs published that affect products developed by Liferay, Inc., 61.5% are self-published by Liferay, Inc. as a CNA.

61.5%
38.5%
Self-published: 208 (61.5%)
Other CNAs: 130 (38.5%)

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (338 CVEs).

338 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-7961CRITICAL
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
Mar 20, 20209.899YESYES
CVE-2019-16891CRITICAL
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
Oct 4, 20199.858NONO
CVE-2021-33990CRITICAL
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference li
Apr 16, 20239.848NOYES
CVE-2019-11444HIGH
An issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script console to execute OS commands. Commands can be executed via a [command].execute
Apr 22, 20197.240NOYES
CVE-2011-1571MEDIUM
Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote attackers to ex
May 7, 20116.837NOYES
CVE-2025-4388MEDIUM
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.
May 6, 20256.135NOYES
CVE-2022-42120CRITICAL
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to exe
Nov 15, 20229.833NONO
CVE-2022-42118MEDIUM
A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.
Nov 15, 20226.133NOYES
CVE-2025-4576MEDIUM
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q
Aug 8, 20256.132NOYES
CVE-2022-42122CRITICAL
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands
Nov 15, 20229.832NONO
View all 338 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products338 CVEs
81%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (0.6%)
Network317 (93.8%)
Unknown19 (5.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low310 (91.7%)
High9 (2.7%)
Unknown19 (5.6%)
User Interaction
None140 (41.4%)
Unknown19 (5.6%)
Required179 (53.0%)
Privileges Required
Low134 (39.6%)
High15 (4.4%)
None170 (50.3%)
Unknown19 (5.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (338 CVEs).

CISA KEV
1 CVE
0.3% of CVEs· 99th percentile
Metasploit
1 CVE
0.3% of CVEs· 97th percentile
Nuclei
5 CVEs
1.5% of CVEs· 95th percentile
ExploitDB
13 CVEs
3.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Liferay, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Liferay, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Liferay, Inc.'s Products

View all 4 CNAs →

Top CWEs