CVE-2025-43737: Liferay Digital Experience Platform
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8 and 2025.Q1.0 through 2025.Q1.15 allows a remote authenticated user to inject JavaScript code via _com_liferay_journal_web_portlet_JournalPortlet_backURL parameter.
Affected products
- Liferay Digital Experience Platform: from 2025.Q1.0, before 2025.Q1.16 (fixed in 2025.Q1.16); from 2025.Q2.0, before 2025.Q2.9 (fixed in 2025.Q2.9)
- Liferay Liferay Portal: from 7.4.0, up to and including 7.4.3.132
Published 2025-08-19. Last modified 2026-06-17.