Digital Experience Platform
Vendor:
First CVE: Jul 20, 2020 · Active for 6 years
264
Total CVEs
More Total CVEs than 100% of tracked products
44.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 22% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Digital Experience Platform over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 20, 2020
6 years ago
Most Recent CVE
Nov 1, 2025
268 days ago
CVE Severity & Scoring
Digital Experience Platform264 CVEs
85%
13%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (0.8%)
Network262 (99.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low256 (97.0%)
High8 (3.0%)
Unknown0 (0.0%)
User Interaction
None118 (44.7%)
Unknown0 (0.0%)
Required146 (55.3%)
Privileges Required
Low120 (45.5%)
High12 (4.5%)
None132 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (264 CVEs).
264 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-4388MEDIUM A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024. | May 6, 2025 | 6.1 | 35 | NO | YES |
CVE-2022-42118MEDIUM A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7. | Nov 15, 2022 | 6.1 | 33 | NO | YES |
CVE-2025-4576MEDIUM A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q | Aug 8, 2025 | 6.1 | 32 | NO | YES |
CVE-2025-43766CRITICAL The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through u | Aug 23, 2025 | 9.8 | 31 | NO | NO |
CVE-2022-42121HIGH A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack | Nov 15, 2022 | 8.8 | 30 | NO | NO |
CVE-2025-43773CRITICAL Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024. | Aug 29, 2025 | 9.1 | 28 | NO | NO |
CVE-2024-25608MEDIUM HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, | Feb 20, 2024 | 6.1 | 28 | NO | YES |
CVE-2020-15841HIGH Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, does not safely test a connection to a LDAP server, which al | Jul 20, 2020 | 8.8 | 28 | NO | NO |
CVE-2025-3594CRITICAL Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 34, and older u | Jun 16, 2025 | 9.8 | 27 | NO | NO |
CVE-2022-42125HIGH Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows attackers to create or overwrite existing | Nov 15, 2022 | 7.5 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (264 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
1.5% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (264 CVEs).
Media Mentions
Signals from CVEs in this product scope (264 CVEs).
Top CNAs Publishing CVEs For Digital Experience Platform
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.4 | 170 | 5.9 | 0.3% | 0 | 3 |
| 7.3 | 84 | 6.4 | 0.3% | 0 | 1 |
| 7.2 | 79 | 6.0 | 0.6% | 0 | 2 |
| 7.1 | 43 | 6.0 | 0.8% | 0 | 1 |
| 7.0 | 23 | 6.0 | 1.0% | 0 | 0 |
| 2025.q3.0 | 1 | 5.4 | 0.2% | 0 | 0 |
| 2025.q2.0 | 2 | 7.3 | 0.2% | 0 | 0 |
| 2025.q1.0 | 1 | 2.7 | 0.3% | 0 | 0 |
| 2024.q4.0 | 2 | 8.0 | 0.3% | 0 | 0 |
| 2024.q3.4 | 1 | 5.4 | 0.2% | 0 | 0 |
| 2024.q3.3 | 1 | 5.4 | 0.2% | 0 | 0 |
| 2024.q3.2 | 1 | 5.4 | 0.2% | 0 | 0 |
| 2024.q3.1 | 1 | 5.4 | 0.2% | 0 | 0 |
| 2024.q3.0 | 2 | 5.2 | 0.3% | 0 | 0 |
| 2024.q1.5 | 1 | 5.3 | 0.4% | 0 | 0 |
| 2024.q1.4 | 1 | 5.3 | 0.4% | 0 | 0 |
| 2024.q1.3 | 1 | 5.3 | 0.4% | 0 | 0 |
| 2024.q1.2 | 1 | 5.3 | 0.4% | 0 | 0 |
| 2024.q1.1 | 1 | 5.3 | 0.4% | 0 | 0 |
| 2023.q4.9 | 5 | 5.7 | 0.2% | 0 | 0 |