Digital Experience Platform

Vendor:

First CVE: Jul 20, 2020 · Active for 6 years

264
Total CVEs
More Total CVEs than 100% of tracked products
44.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 22% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Digital Experience Platform over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 20, 2020
6 years ago
Most Recent CVE
Nov 1, 2025
268 days ago

CVE Severity & Scoring

Digital Experience Platform264 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local2 (0.8%)
Network262 (99.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low256 (97.0%)
High8 (3.0%)
Unknown0 (0.0%)
User Interaction
None118 (44.7%)
Unknown0 (0.0%)
Required146 (55.3%)
Privileges Required
Low120 (45.5%)
High12 (4.5%)
None132 (50.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (264 CVEs).

264 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.
May 6, 20256.135NOYES
A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.
Nov 15, 20226.133NOYES
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q
Aug 8, 20256.132NOYES
The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through u
Aug 23, 20259.831NONO
A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack
Nov 15, 20228.830NONO
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.
Aug 29, 20259.128NONO
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19,
Feb 20, 20246.128NOYES
Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, does not safely test a connection to a LDAP server, which al
Jul 20, 20208.828NONO
Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 34, and older u
Jun 16, 20259.827NONO
Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows attackers to create or overwrite existing
Nov 15, 20227.527NONO

Exploit Exposure

Signals from CVEs in this product scope (264 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
1.5% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (264 CVEs).

Media Mentions

Signals from CVEs in this product scope (264 CVEs).

Top CNAs Publishing CVEs For Digital Experience Platform

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.41705.90.3%03
7.3846.40.3%01
7.2796.00.6%02
7.1436.00.8%01
7.0236.01.0%00
2025.q3.015.40.2%00
2025.q2.027.30.2%00
2025.q1.012.70.3%00
2024.q4.028.00.3%00
2024.q3.415.40.2%00
2024.q3.315.40.2%00
2024.q3.215.40.2%00
2024.q3.115.40.2%00
2024.q3.025.20.3%00
2024.q1.515.30.4%00
2024.q1.415.30.4%00
2024.q1.315.30.4%00
2024.q1.215.30.4%00
2024.q1.115.30.4%00
2023.q4.955.70.2%00