CVE-2025-43774
Liferay Portal is vulnerable to XSS attack through its Style Book theme
Description
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.17 allows a remote authenticated user to inject JavaScript code via Style Book theme name. This malicious payload is then reflected and executed within the user's browser.
How to fix CVE-2025-43774
To remediate CVE-2025-43774, upgrade the affected package to a fixed version below.
- Maven/com.liferay:com.liferay.frontend.taglib.clay—upgrade to 15.2.1 or later
Is CVE-2025-43774 being exploited?
No exploitation signal available. Neither CISA KEV nor a current EPSS score has been published for CVE-2025-43774.
Affected packages (1)
- from 0, < 15.2.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N |