Liferay Portal and Liferay DXP Cross-Site Scripting Vulnerability in Notifications Widget

Vulnerability

Multiple cross-site scripting (XSS) vulnerabilities have been identified in the Notifications widget of Liferay Portal and Liferay DXP. These vulnerabilities allow remote attackers to inject arbitrary web scripts or HTML by exploiting specific text fields. The affected versions include Liferay Portal 7.4.3.102 through 7.4.3.111, Liferay DXP 2023.Q4.0 through 2023.Q4.5, and Liferay DXP 2023.Q3.1 through 2023.Q3.4.

Impact

Exploitation of these vulnerabilities allows for cross-site scripting, where injected scripts can be executed in the context of the user.

Remediation

Users can upgrade to Liferay Portal 7.4.3.112, Liferay DXP 2024.Q1.1, or Liferay DXP 2023.Q4.6 to address these vulnerabilities.

Added: Oct 8, 2025, 3:21 PM
Updated: Oct 8, 2025, 8:03 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
1.7
exploitability
5.0
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.