Vulnerabilities/

Liferay Portal Reflected XSS in CKeditor 4.21.0 endpoint

Severity:
Medium

Description

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.4, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.

Recommendation

Update the liferay-ckeditor package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
liferay-ckeditor
Anything's wrong? Let us know Last updated on August 25, 2025