Technology · Maven
com.liferay.portal:release.portal.bom (Maven) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 92 vulnerabilities in com.liferay.portal:release.portal.bom (Maven): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-62264, was published on 31 October 2025.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest com.liferay.portal:release.portal.bom (Maven) vulnerabilities
- CVE-2025-62264: Liferay Portal Vulnerable to Reflected XSS via the selectedLanguageId ParameterlowCVSS 3.1EPSS 0.2%
- CVE-2025-62265: Liferay Portal is vulnerable to XSS in the Blogs widgetmediumCVSS 4EPSS 0.2%
- CVE-2025-62266: Liferay Portal is vulnerable to DNS rebinding attacksmediumCVSS 4EPSS 0.2%
- CVE-2025-62257: Liferay Portal vulnerable to password enumerationmediumCVSS 4EPSS 0.4%
- CVE-2025-62259: Liferay Portal Does Not Limit Access to APIs Before Email VerificationmediumCVSS 4EPSS 0.2%
- CVE-2025-62260: Liferay Portal Vulnerable to DoS via Crafted Headless API RequestmediumCVSS 4EPSS 0.4%
- CVE-2025-62258: Liferay Portal Vulnerable to CSRF in Headless APIsmediumCVSS 4EPSS 0.2%
- CVE-2025-62261: Liferay Portal Stores Password Reset Tokens in Plain TextmediumCVSS 4EPSS 0.3%
- CVE-2025-43830: Liferay Portal is vulnerable to Stored XSS through Forms text type fieldmediumCVSS 4EPSS 0.2%
- CVE-2025-43823: Liferay Portal is vulnerable to XSS through its Commerce Search Result widgetmediumCVSS 4EPSS 0.2%
- CVE-2025-43822: Liferay Portal has multiple Stored XSS vulnerabilities on its View Order pagemediumCVSS 4EPSS 0.2%
- CVE-2025-43824: Liferay Profile Widget does not prevent vCard extension spoofingmediumCVSS 4EPSS 0.2%
- CVE-2025-43826: Liferay Portal Vulnerable to XSS in Web Content translationmediumCVSS 4EPSS 0.2%
- CVE-2025-43812: Liferay Portal vulnerable to cross-site scripting in the web content templatemediumCVSS 4EPSS 0.2%
- CVE-2025-43813: Liferay Portal vulnerable to path traversal and denial-of-service in the ComboServletmediumCVSS 4EPSS 0.5%
- CVE-2025-43820: Liferay Portal vulnerable to cross-site scripting in the Calendar widgetmediumCVSS 4EPSS 0.2%
- CVE-2025-43817: Liferay Portal vulnerable to reflected cross-site scripting via the `redirect` parametermediumCVSS 4EPSS 0.2%
- CVE-2025-43799: Liferay Portal Uses Default PasswordmediumCVSS 4EPSS 0.3%
- CVE-2025-43760: Liferay Portal Reflected Cross-Site Scripting Vulnerability via PortalUtil.escapeRedirectmediumCVSS 4EPSS 0.3%
- CVE-2025-43752: Liferay Portal's Unlimited File Upload Could Result in DoSmediumCVSS 4EPSS 0.3%
- CVE-2025-43754: Liferay Portal Username Enumeration VulnerabilitymediumCVSS 4EPSS 0.3%
- CVE-2025-43756: Liferay Portal Reflected Cross-Site Scripting Vulnerability via snippet ParametermediumCVSS 4EPSS 0.2%
- CVE-2025-43757: Liferay Portal Vulnerable to Cross-Site Scripting via DDMPortlet_definition ParametermediumCVSS 4EPSS 0.2%
- CVE-2025-43746: Liferay Portal Vulnerable to Cross-Site Scripting in Dynamic Data MappingmediumCVSS 4EPSS 0.2%
- CVE-2025-43748: Liferay Portal Vulnerable to Cross-Site Request ForgerymediumCVSS 4EPSS 0.2%
Most severe com.liferay.portal:release.portal.bom (Maven) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-43813: Liferay Portal vulnerable to path traversal and denial-of-service in the ComboServletmediumCVSS 4EPSS 0.5%
- CVE-2025-3639: Liferay Portal Login Bypass VulnerabilitymediumCVSS 4EPSS 0.5%
- CVE-2025-62257: Liferay Portal vulnerable to password enumerationmediumCVSS 4EPSS 0.4%
- CVE-2025-62260: Liferay Portal Vulnerable to DoS via Crafted Headless API RequestmediumCVSS 4EPSS 0.4%
- CVE-2025-43752: Liferay Portal's Unlimited File Upload Could Result in DoSmediumCVSS 4EPSS 0.3%
- CVE-2025-43743: Liferay Portal Enumeration Discrepancy in CalendarsmediumCVSS 4EPSS 0.3%
- CVE-2025-62261: Liferay Portal Stores Password Reset Tokens in Plain TextmediumCVSS 4EPSS 0.3%
- CVE-2025-43799: Liferay Portal Uses Default PasswordmediumCVSS 4EPSS 0.3%
- CVE-2025-43760: Liferay Portal Reflected Cross-Site Scripting Vulnerability via PortalUtil.escapeRedirectmediumCVSS 4EPSS 0.3%
- CVE-2025-43749: Liferay Portal Unauthenticated File Access via URLmediumCVSS 4EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/com-liferay-portal-release-portal-bom.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "com.liferay.portal:release.portal.bom (Maven) vulnerabilities", https://junglewise.ai/threats/technologies/com-liferay-portal-release-portal-bom, 27 September 2026.