Description
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.4, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.
Recommendation
Update the liferay-ckeditor package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.21.0-liferay.10
- Patched version(s): 4.21.0-liferay.10
References
Could your website be exposed too?
SmartScanner can check your website for Liferay Portal Reflected XSS in CKeditor 4.21.0 endpoint and gives you actionable findings to investigate.
Start a free scanRelated Issues
- CKEditor 5 cross-site scripting (XSS) vulnerability in the clipboard package - CVE-2025-58064
- CKEditor 5 cross-site scripting (XSS) vulnerability in the clipboard package - ckeditor5 - CVE-2025-58064
- Cross-site scripting (XSS) in the CKEditor 5 real-time collaboration package - CVE-2025-25299
- Code Snippet GeSHi plugin in CKEditor 4 has reflected cross-site scripting (XSS) vulnerability - CVE-2024-43407


