CVE-2025-43779: Liferay Digital Experience Platform

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 allows a remote authenticated attacker to inject JavaScript code via _com_liferay_commerce_product_definitions_web_internal_portlet_CPDefinitionsPortlet_productTypeName parameter. This malicious payload is then reflected and executed within the user's browser.

Affected products

  • Liferay Digital Experience Platform: from 2024.Q1.1, before 2024.Q1.19 (fixed in 2024.Q1.19); version 7.4 only
  • Liferay Liferay Portal: from 7.4.0, before 7.4.3.113 (fixed in 7.4.3.113)

Published 2025-09-24. Last modified 2026-09-26.