← Vulnerability feed

Vulnerability record · CVE-2025-62258 · published 27 October 2025

CVE-2025-62258: Liferay digital experience platform cross-site request forgery vulnerability

Liferay · Digital Experience Platform

CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to execute any Headless API via the `endpoint` parameter.

7.0 CVSS 4.0 High EPSS 0.17% · top 94.4% CWE-352 · Cross-site request forgery
7.0CVSS 4.0 base score
0.17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to execute any Headless API via the `endpoint` parameter.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-62258 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-7961Liferay Portal JSONWS deserialization allows remote code executionLiferay Portal before 7.2.1 CE GA2 deserializes untrusted data received through its JSON web services (JSONWS) endpoints. Because the input is not sa…KEVEPSS 100%analysed9.8CVE-2021-33990Liferay portal os command injection vulnerabilityLiferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue b…EPSS 12%9.8CVE-2022-42120Liferay dxp sql injection vulnerabilityA SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before up…EPSS 0.78%9.8CVE-2022-42122Liferay dxp sql injection vulnerabilityA SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to…EPSS 0.77%9.8CVE-2019-16891Liferay Portal CE JSON deserialization remote command executionLiferay Portal CE 6.2.5 deserializes untrusted JSON payloads, allowing an unauthenticated remote attacker to execute commands. The flaw is a CWE-502 …EPSS 45%analysed8.8CVE-2024-38002Liferay digital experience platform missing authorization vulnerabilityThe workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA th…EPSS 0.61%8.8CVE-2024-26271Liferay digital experience platform cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 thro…EPSS 0.36%8.8CVE-2024-26272Liferay digital experience platform cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 throu…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2025-62258), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.