CVE-2025-43826: XSS
Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allow remote attackers to inject arbitrary web script or HTML via any rich text field in a web content article.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43826?
CVE-2025-43826 is classified as a high severity vulnerability due to its potential impact on users through stored cross-site scripting.
How do I fix CVE-2025-43826?
To fix CVE-2025-43826, users should upgrade to Liferay Portal version 7.4.3.113 or later, and for Liferay DXP, upgrade to versions above 2023.Q4.8 and 2023.Q3.10.
What versions of Liferay are affected by CVE-2025-43826?
CVE-2025-43826 affects Liferay Portal versions 7.4.0 to 7.4.3.112 and older unsupported versions, as well as Liferay DXP versions from 2023.Q4.0 to 2023.Q4.8 and 2023.Q3.1 to 2023.Q3.10.
What type of attack can CVE-2025-43826 be exploited for?
CVE-2025-43826 can be exploited for stored cross-site scripting attacks, allowing remote attackers to execute arbitrary JavaScript in the context of a user's browser.
Is CVE-2025-43826 a critical vulnerability?
While CVE-2025-43826 is serious, it is not classified as critical, but organizations should prioritize remediation due to the nature of the XSS attack.