CVE-2025-43798: Liferay Digital Experience Platform
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time password (TOTP) to be used multiple times during the validity period, which allows attackers with access to a user’s TOTP to authenticate as the user.
Affected products
- Liferay Digital Experience Platform: from 2023.q3.1, before 2023.q3.5 (fixed in 2023.q3.5); version 7.3 only; version 7.4 only; version 2023.q4.0 only
Published 2025-09-15. Last modified 2026-06-17.