com.liferay.portal:release.portal.bom Security Analysis
com.liferay.portal:release.portal.bom has 20 known security vulnerabilities in Maven (Java). Upgrade to version 7.4.3.112 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.
Low Immediate Risk
No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.
Recommended safe version: 7.4.3.112
Upgrading to 7.4.3.112 or later resolves all 20 known vulnerabilities in com.liferay.portal:release.portal.bom. Update your pom.xml or build.gradle to version 7.4.3.112.
Is com.liferay.portal:release.portal.bom in your project?
Check if you're affected and upgrade to 7.4.3.112 to stay secure.
Vulnerabilities
20 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.
| CVE / GHSA | Severity | Affected | Fixed In |
|---|---|---|---|
| CVE-2024-8980 Liferay Portal and Liferay DXP Vulnerable to CSRF in the Script Console | CRITICAL | 7.0.6, 7.0.6-1, 7.0.6-2, 7.1.0 (+129 more) | 7.4.3.102-GA102 |
| CVE-2024-26269 Liferay Portal Frontend JS module's portlet.js and Liferay DXP vulnerable to Cross-site Scripting | CRITICAL | 7.2.0, 7.2.1, 7.2.1-1, 7.3.0 (+52 more) | 7.4.3.38 |
| CVE-2023-42496 Liferay Portal and Liferay DXP vulnerable to reflected Cross-site Scripting | CRITICAL | 7.3.3, 7.3.3-1, 7.3.4, 7.3.5 (+107 more) | 7.4.3.98 |
| CVE-2024-25145 Liferay Portal stored cross-site scripting (XSS) vulnerability | CRITICAL | 7.0.6, 7.0.6-1, 7.0.6-2, 7.1.0 (+32 more) | 7.4.3.12 |
| CVE-2024-38002 Liferay Portal and Liferay DXP Workflow Component Does Not Check User Permissions | CRITICAL | 7.3.3, 7.3.3-1, 7.3.4, 7.3.5 (+118 more) | 7.4.3.112-ga112 |
| CVE-2023-42498 Liferay Portal Language Override edit screen and Liferay DXP vulnerable to reflected Cross-site Scripting | CRITICAL | 7.4.3.10, 7.4.3.11, 7.4.3.12, 7.4.3.13 (+92 more) | 7.4.3.98 |
| CVE-2024-25147 Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting | CRITICAL | 7.0.6, 7.0.6-1, 7.0.6-2, 7.1.0 (+21 more) | No fix available |
| CVE-2024-25610 Liferay Portal has a Stored XSS with Blog entries (Insecure defaults) | CRITICAL | 7.0.6, 7.0.6-1, 7.0.6-2, 7.1.0 (+33 more) | 7.4.3.13 |
| CVE-2022-42122 Liferay Portal and Liferay DXP Vulnerable to SQL Injection via Friendly URL Module | CRITICAL | 7.3.7, 7.4.0 | 7.4.0-ga1 |
| CVE-2024-25603 Liferay Portal's Dynamic Data Mapping module's DDMForm and Liferay DXP vulnerable to stored Cross-site Scripting | CRITICAL | 7.0.6, 7.0.6-1, 7.0.6-2, 7.1.0 (+25 more) | 7.4.3.5 |
| CVE-2024-26266 Liferay Portal and Liferay DXP vulnerable to stored Cross-site Scripting | CRITICAL | 7.0.6, 7.0.6-1, 7.0.6-2, 7.1.0 (+34 more) | 7.4.3.14 |
| CVE-2023-47797 Liferay Portal XSS with `p_l_back_url_title` on edit content page | CRITICAL | 7.4.3.94, 7.4.3.95, 7.4.3.95-1 | 7.4.3.96 |
| CVE-2023-47795 Liferay Portal Document and Media widget and Liferay DXP vulnerable to stored Cross-site Scripting | CRITICAL | 7.4.3.100, 7.4.3.101, 7.4.3.18, 7.4.3.19 (+86 more) | 7.4.3.102 |
| CVE-2023-40191 Liferay Portal and Liferay DXP vulnerable to reflected Cross-site Scripting | CRITICAL | 7.4.3.44, 7.4.3.45, 7.4.3.46, 7.4.3.47 (+54 more) | 7.4.3.98 |
| CVE-2024-25601 Liferay Portal Expando module and Liferay DXP vulnerable to stored Cross-site Scripting | CRITICAL | 7.0.6, 7.0.6-1, 7.0.6-2, 7.1.0 (+23 more) | No fix available |
| CVE-2024-25152 Liferay Portal Message Board widget and Liferay DXP vulnerable to stored Cross-site Scripting | CRITICAL | 7.0.6, 7.0.6-1, 7.0.6-2, 7.1.0 (+23 more) | No fix available |
| CVE-2024-25602 Liferay Portal and Liferay DXP's Users Admin module vulnerable to stored Cross-site Scripting | CRITICAL | 7.0.6, 7.0.6-1, 7.0.6-2, 7.1.0 (+23 more) | No fix available |
| CVE-2024-26271 Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the My Account Widget | HIGH | 7.4.3.100, 7.4.3.101, 7.4.3.102, 7.4.3.103 (+31 more) | 7.4.3.112 |
| CVE-2024-26273 Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the Content Page Editor | HIGH | 7.4.0, 7.4.1, 7.4.1-1, 7.4.2 (+107 more) | 7.4.3.104 |
| CVE-2024-26272 Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the Content Page Editor | HIGH | 7.3.2, 7.3.2-1, 7.3.3, 7.3.3-1 (+119 more) | 7.4.3.108 |
About This Data
Vulnerability data for com.liferay.portal:release.portal.bom is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.
CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Related Maven (Java) Packages
Other packages in this ecosystem, ranked by shared vulnerabilities where available.
Check Your Dependencies
Scan your project to check if you're using a vulnerable version of com.liferay.portal:release.portal.bom.