FAIL › dossier
liferay portal
PRODUCT· dossier confidence 20%
Liferay Portal is a major open-source CMS/DXP vendor with a history of critical RCE vulnerabilities in core modules, including SQL injection flaws in 2022 and deserialization RCEs in 2021.
PROFILE
CategoryEnterprise Software / CMSWhat they doLiferay Portal is an open-source enterprise content management system (CMS) and digital experience platform (DXP) used for building web applications and intranets.
Websitehttps://www.liferay.com ↗
SECURITY POSTURE
High-risk track record with multiple critical RCE vulnerabilities in recent years, including SQL injection flaws in core modules.
Notable failures
- CVE-2020-7961: High severity RCE via deserialization of untrusted data
- CVE-2022-42122: Critical SQL injection in Friendly Url module
- CVE-2022-42120: Critical SQL injection in Fragment module
Patterns: Repeated unpatched edge-module RCEs; SQL injection in core DXP modules
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2020-7961 | high | Liferay Portal suffered a deserialization of untrusted data vulnerability allowing remote code execution via JSON web services. |
| 2022-11-15 | CVE-2022-42122 | critical | A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL. |
| 2022-11-15 | CVE-2022-42120 | critical | A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute. |
DOSSIER SOURCES
- listing directory /tools/ide/3.10.5/ - releases.liferay.com · releases.liferay.com
- listing directory / · releases.liferay.com
- CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
Open questions: Current patch cadence for critical vulnerabilities · Third-party vendor security posture
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-30 03:46:09.198865+00:00