Skip to content
COOEY

FAIL › dossier

liferay portal

PRODUCT

· dossier confidence 20%

Liferay Portal is a major open-source CMS/DXP vendor with a history of critical RCE vulnerabilities in core modules, including SQL injection flaws in 2022 and deserialization RCEs in 2021.

PROFILE
CategoryEnterprise Software / CMSWhat they doLiferay Portal is an open-source enterprise content management system (CMS) and digital experience platform (DXP) used for building web applications and intranets. Websitehttps://www.liferay.com ↗
SECURITY POSTURE

High-risk track record with multiple critical RCE vulnerabilities in recent years, including SQL injection flaws in core modules.

Notable failures
  • CVE-2020-7961: High severity RCE via deserialization of untrusted data
  • CVE-2022-42122: Critical SQL injection in Friendly Url module
  • CVE-2022-42120: Critical SQL injection in Fragment module
Patterns: Repeated unpatched edge-module RCEs; SQL injection in core DXP modules
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2020-7961 high Liferay Portal suffered a deserialization of untrusted data vulnerability allowing remote code execution via JSON web services.
2022-11-15 CVE-2022-42122 critical A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.
2022-11-15 CVE-2022-42120 critical A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.
DOSSIER SOURCES
Open questions: Current patch cadence for critical vulnerabilities · Third-party vendor security posture
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-30 03:46:09.198865+00:00