---
id: CVE-2022-26594
title: >-
  Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5
  through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote
  attackers to inject arbitrary web script or HTML via a form field's help text
  to (1) Forms …
summary: >-
  Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5
  through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote
  attackers to inject arbitrary web script or HTML via a form field's help text
  to (1) Forms …
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: liferay
product: liferay_portal
affected:
  - 'liferay_portal >= 7.3.5, < 7.3.7'
  - liferay_portal = 7.4.0
patched:
  - liferay_portal 7.3.7
published: '2022-04-15'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-26594'
references:
  - url: >-
      https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-26594-xss-vulnerability-with-form-field-help-text
    label: cve@mitre.org
  - url: 'http://liferay.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-26594-xss-vulnerability-with-form-field-help-text
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00728
epssPercentile: 0.52232
ingestedAt: '2026-07-06T17:03:24.156Z'
---

## Overview

Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote attackers to inject arbitrary web script or HTML via a form field's help text to (1) Forms module's form builder, or (2) App Builder module's object form view's form builder.

## Affected

- `liferay_portal >= 7.3.5, < 7.3.7`
- `liferay_portal = 7.4.0`

## Remediation

Upgrade past the affected range:

- `liferay_portal 7.3.7`
