A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8 and 2025.Q1.0 through 2025.Q1.15 allows a remote authenticated user to inject JavaScript code via comliferayjournalwebportletJournalPortlet_backURL parameter.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "2025.Q1.0"
},
{
"fixed": "2025.Q1.16"
},
{
"introduced": "2025.Q2.0"
},
{
"fixed": "2025.Q2.9"
}
],
"vendor_product": "liferay:digital_experience_platform",
"source": "CPE_RANGE"
}
]
}