---
id: CVE-2025-43785
title: >-
  Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45
  through 7.4.3.128, and Liferay DXP 2024 Q2.0 through 2024.Q2.9, 2024.Q1.1
  through 2024.Q1.12, and 7.4 update 45 through update 92 allows remote
  attackers to execu…
summary: >-
  Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45
  through 7.4.3.128, and Liferay DXP 2024 Q2.0 through 2024.Q2.9, 2024.Q1.1
  through 2024.Q1.12, and 7.4 update 45 through update 92 allows remote
  attackers to execu…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: liferay
product: digital_experience_platform
affected:
  - 'digital_experience_platform >= 2024.Q1.1, < 2024.Q1.13'
  - 'digital_experience_platform >= 2024.Q2.0, <= 2024.Q2.9'
  - digital_experience_platform = 7.4
  - 'liferay_portal >= 7.4.3.45, < 7.4.3.129'
patched:
  - digital_experience_platform 2024.Q1.13
  - liferay_portal 7.4.3.129
published: '2025-09-10'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-43785'
references:
  - url: >-
      https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-43785
    label: security@liferay.com
tags:
  - nvd
epss: 0.00224
epssPercentile: 0.11639
ingestedAt: '2026-09-26T00:22:39.915Z'
---

## Overview

Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45 through 7.4.3.128, and Liferay DXP 2024 Q2.0 through 2024.Q2.9, 2024.Q1.1 through 2024.Q1.12, and 7.4 update 45 through update 92 allows remote attackers to execute an arbitrary web script or HTML in the My Workflow Tasks page.

## Affected

- `digital_experience_platform >= 2024.Q1.1, < 2024.Q1.13`
- `digital_experience_platform >= 2024.Q2.0, <= 2024.Q2.9`
- `digital_experience_platform = 7.4`
- `liferay_portal >= 7.4.3.45, < 7.4.3.129`

## Remediation

Upgrade past the affected range:

- `digital_experience_platform 2024.Q1.13`
- `liferay_portal 7.4.3.129`
