{"id":"CVE-2025-43779","title":"A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 allows a remote authenticated attacker to inject JavaScript cod…","summary":"A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 allows a remote authenticated attacker to inject JavaScript cod…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"liferay","product":"digital_experience_platform","affected":["digital_experience_platform >= 2024.Q1.1, < 2024.Q1.19","digital_experience_platform = 7.4","liferay_portal >= 7.4.0, < 7.4.3.113"],"patched":["digital_experience_platform 2024.Q1.19","liferay_portal 7.4.3.113"],"published":"2025-09-24","updated":"2026-09-26","sourceUpdated":"2026-09-26T00:10:00.127","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-43779","references":[{"url":"https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-43779","label":"security@liferay.com"}],"tags":["nvd"],"epss":0.00232,"epssPercentile":0.12556,"ingestedAt":"2026-09-26T00:22:39.949Z","slug":"CVE-2025-43779","body":"## Overview\n\nA reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 allows a remote authenticated attacker to inject JavaScript code via _com_liferay_commerce_product_definitions_web_internal_portlet_CPDefinitionsPortlet_productTypeName parameter. This malicious payload is then reflected and executed within the user's browser.\n\n## Affected\n\n- `digital_experience_platform >= 2024.Q1.1, < 2024.Q1.19`\n- `digital_experience_platform = 7.4`\n- `liferay_portal >= 7.4.0, < 7.4.3.113`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `digital_experience_platform 2024.Q1.19`\n- `liferay_portal 7.4.3.113`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}