Liferay Portal and Liferay DXP have a reflected cross-site scripting vulnerability
Moderate severity
GitHub Reviewed
Published
Aug 12, 2025
to the GitHub Advisory Database
•
Updated Aug 12, 2025
Package
Affected versions
>= 7.0.4, < 109.1.0
Patched versions
109.1.0
>= 2024.q4.0, <= 2024.q4.7
>= 2024.q3.0, <= 2024.q3.13
>= 2024.q2.0, <= 2024.q2.13
>= 2024.q1.0, < 2024.q1.13
<= 7.4.13.u92
2024.q1.13
Description
Published by the National Vulnerability Database
Aug 12, 2025
Published to the GitHub Advisory Database
Aug 12, 2025
Reviewed
Aug 12, 2025
Last updated
Aug 12, 2025
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the google_gadget.
References