---
id: CVE-2021-38264
title: >-
  Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in
  Liferay Portal 7.4.0 and 7.4.1 allows remote attackers to inject arbitrary web
  script or HTML into the management toolbar search via the `keywords` parameter
summary: >-
  Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in
  Liferay Portal 7.4.0 and 7.4.1 allows remote attackers to inject arbitrary web
  script or HTML into the management toolbar search via the `keywords`
  parameter. This…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: liferay
product: liferay_portal
affected:
  - liferay_portal = 7.4.0
  - liferay_portal = 7.4.1
published: '2022-03-03'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-38264'
references:
  - url: >-
      https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2021-38264-reflected-xss-with-keywords-in-search
    label: cve@mitre.org
  - url: 'http://liferay.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2021-38264-reflected-xss-with-keywords-in-search
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00728
epssPercentile: 0.52166
ingestedAt: '2026-07-06T17:03:23.923Z'
---

## Overview

Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7.4.1 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter. This issue is caused by an incomplete fix in CVE-2021-35463.

## Affected

- `liferay_portal = 7.4.0`
- `liferay_portal = 7.4.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
