Vulnerability Details CVE-2025-2536
Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 82 through update 92 in the Frontend JS module's layout-taglib/__liferay__/index.js allows remote attackers to inject arbitrary web script or HTML via toastData parameter
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.1%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2025-2536
-
cpe:2.3:a:liferay:digital_experience_platform:2023.q3.1
-
cpe:2.3:a:liferay:digital_experience_platform:2023.q3.10
-
cpe:2.3:a:liferay:digital_experience_platform:2023.q3.2
-
cpe:2.3:a:liferay:digital_experience_platform:2023.q3.3
-
cpe:2.3:a:liferay:digital_experience_platform:2023.q3.4
-
cpe:2.3:a:liferay:digital_experience_platform:2023.q3.5
-
cpe:2.3:a:liferay:digital_experience_platform:2023.q3.6
-
cpe:2.3:a:liferay:digital_experience_platform:2023.q3.7
-
cpe:2.3:a:liferay:digital_experience_platform:2023.q3.8
-
cpe:2.3:a:liferay:digital_experience_platform:2023.q3.9
-
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.0
-
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.1
-
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.10
-
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.2
-
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.3
-
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.4
-
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.5
-
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.6
-
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.7
-
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.8
-
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.9
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.1
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.10
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.11
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.12
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.2
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.3
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.4
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.5
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.6
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.7
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.8
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.9
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.0
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.1
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.10
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.11
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.12
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.13
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.2
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.3
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.4
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.5
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.6
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.7
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.8
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q2.9
-
cpe:2.3:a:liferay:digital_experience_platform:2024.q3.0
-
cpe:2.3:a:liferay:digital_experience_platform:7.4
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.100
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.101
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.102
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.103
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.104
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.105
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.106
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.107
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.108
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.109
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.110
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.111
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.112
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.113
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.114
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.115
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.116
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.117
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.118
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.119
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.120
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.121
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.122
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.123
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.124
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.125
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.126
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.127
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.128
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.82
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.83
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.84
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.85
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.86
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.87
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.88
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.89
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.90
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.91
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.92
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.94
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.95
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.96
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.97
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.98
-
cpe:2.3:a:liferay:liferay_portal:7.4.3.99