S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 30, 2026

CVE-2025-4576 Scanner

CVE-2025-4576 Scanner - Cross-Site Scripting (XSS) vulnerability in Liferay Portal & DXP

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
6k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-4576
6.9
CVSSmedium
Exploitable remotely over the internet · no authentication required.

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 allows an remote non-authenticated attacker to inject JavaScript into the modules/apps/blogs/blogs-web/src/main/resources/META-INF/resources/blogs/entry_cover_image_caption.jsp

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Portalby Liferay
7.4.0
DXPby Liferay
7.4.13
Updated Sep 9, 2026View on NVD →
Detail

Liferay Portal & DXP is a widely used open-source enterprise software solution designed for creating web experiences, such as websites, portals, and intranets. It is used by businesses and developers to manage and build digital environments with features like content management and collaboration tools.

The detected vulnerability is a Cross-Site Scripting (XSS) issue affecting certain versions of Liferay Portal & DXP. XSS vulnerabilities allow an attacker to inject malicious scripts into web pages viewed by other users. This specific vulnerability is caused by improper sanitization in the `entry_cover_image_caption.jsp` file, which potentially lets remote non-authenticated attackers execute JavaScript code in the context of other users.

The vulnerability specifically affects the `entry_cover_image_caption.jsp` endpoint in the Liferay software. Attackers can exploit this endpoint by injecting scripts that execute in the victim's browser, allowing them to perform actions such as displaying pop-up alerts and accessing session information. Exploiting this vulnerability does not require prior authentication or special user privileges.

If exploited, this vulnerability can lead to several malicious outcomes, including session hijacking, unauthorized actions performed on behalf of a user, and redirection to malicious websites. Once the attacker injects the script, they gain the ability to manipulate the client's browser behavior, potentially leading to further security breaches.

REFERENCES

Solution Advice
  • Update Liferay Portal & DXP to the latest version beyond 7.4.3.133 and 2025.Q1.4 to mitigate the vulnerability.
  • Employ web application firewalls that can detect and prevent XSS attacks.
  • Regularly audit and sanitize any user input fields within your application.
  • Implement Content Security Policy (CSP) headers to restrict the execution of untrusted scripts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2025-4576 Scanner - Cross-Site Scripting (XSS) vulnerability in Liferay Portal & DXP | S4E