Liferay Portal 7.4.0 through 7.4.3.133 and Liferay DXP 2024.Q1.1 through 2025.Q1.4 contain a reflected XSS caused by improper sanitization in entry_cover_image_caption.jsp, letting remote non-authenticated attackers inject JavaScript.
id: CVE-2025-4576
info:
name: Liferay Portal & DXP - Cross-Site Scripting
author: xtr0nix
sev
...