← Vulnerability feed

Vulnerability record · CVE-2025-62263 · published 27 October 2025

CVE-2025-62263: Liferay digital experience platform cross-site scripting vulnerability

Liferay · Digital Experience Platform

Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 service pack 3 through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account Role’s “Title” text field to (1) view account role page, or (2) select account role page. Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 service pack 3 through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Organization’s “Name” text field to (1) view account page, (2) view account organization page, or (3) select account organization page.

4.8 CVSS 4.0 Medium EPSS 0.21% · top 90.6% CWE-79 · Cross-site scripting
4.8CVSS 4.0 base score
0.21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 service pack 3 through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account Role’s “Title” text field to (1) view account role page, or (2) select account role page. Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 service pack 3 through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Organization’s “Name” text field to (1) view account page, (2) view account organization page, or (3) select account organization page.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-62263 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-7961Liferay Portal JSONWS deserialization allows remote code executionLiferay Portal before 7.2.1 CE GA2 deserializes untrusted data received through its JSON web services (JSONWS) endpoints. Because the input is not sa…KEVEPSS 100%analysed9.8CVE-2021-33990Liferay portal os command injection vulnerabilityLiferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue b…EPSS 12%9.8CVE-2022-42120Liferay dxp sql injection vulnerabilityA SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before up…EPSS 0.78%9.8CVE-2022-42122Liferay dxp sql injection vulnerabilityA SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to…EPSS 0.77%9.8CVE-2019-16891Liferay Portal CE JSON deserialization remote command executionLiferay Portal CE 6.2.5 deserializes untrusted JSON payloads, allowing an unauthenticated remote attacker to execute commands. The flaw is a CWE-502 …EPSS 45%analysed8.8CVE-2024-38002Liferay digital experience platform missing authorization vulnerabilityThe workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA th…EPSS 0.61%8.8CVE-2024-26271Liferay digital experience platform cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 thro…EPSS 0.36%8.8CVE-2024-26272Liferay digital experience platform cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 throu…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2025-62263), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.