Liferay

Security Scorecard

Score

42F

Total CVEs

60

Patch Rate

0%

0 patched

Avg Response

-

days to patch

Critical Gaps

0

exploitable, no detection

Severity Breakdown

Critical1
High4
Medium55
Low0

Patch Status

Patched0 (0%)
Partial/Workaround2 (3%)
Unpatched58 (97%)

CVEs (60)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-43739Liferay Portal Phishing Email VulnerabilityMEDIUM4.3122dUnpatched
CVE-2025-43740Liferay Cross-Site Scripting VulnerabilityMEDIUM5.4122dUnpatched
CVE-2025-43733Liferay XSSMEDIUM5.4120dUnpatched
CVE-2025-43731Liferay Portal XSS VulnerabilityMEDIUM5.4123dUnpatched
CVE-2025-43736Liferay DOS VulnerabilityMEDIUM4.3126dUnpatched
CVE-2025-43735Liferay XSSMEDIUM6.1126dUnpatched
CVE-2025-4655Liferay SSRF VulnerabilityMEDIUM5.0132dUnpatched
CVE-2025-3602Liferay GraphQL Denial-of-Service VulnerabilityHIGH7.5183dUnpatched
CVE-2025-3526Liferay DoSHIGH7.5183dUnpatched
CVE-2025-4388Liferay XSSMEDIUM6.1224dUnpatched