CVE-2025-43737: Liferay Digital Experience Platform

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8 and 2025.Q1.0 through 2025.Q1.15 allows a remote authenticated user to inject JavaScript code via _com_liferay_journal_web_portlet_JournalPortlet_backURL parameter.

Affected products

  • Liferay Digital Experience Platform: from 2025.Q1.0, before 2025.Q1.16 (fixed in 2025.Q1.16); from 2025.Q2.0, before 2025.Q2.9 (fixed in 2025.Q2.9)
  • Liferay Liferay Portal: from 7.4.0, up to and including 7.4.3.132

Published 2025-08-19. Last modified 2026-06-17.