Description
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.4, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.
Recommendation
Update the liferay-ckeditor package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.21.0-liferay.10
- Patched version(s): 4.21.0-liferay.10
References
- GHSA-3h7r-4xxj-3mfm
- liferay.dev
- liferay.atlassian.net
- CVE-2025-43761
- CWE-79
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- CKEditor 5 cross-site scripting (XSS) vulnerability in the clipboard package - CVE-2025-58064
- CKEditor 5 cross-site scripting (XSS) vulnerability in the clipboard package - ckeditor5 - CVE-2025-58064
- Cross-site scripting (XSS) in the CKEditor 5 real-time collaboration package - CVE-2025-25299
- Code Snippet GeSHi plugin in CKEditor 4 has reflected cross-site scripting (XSS) vulnerability - CVE-2024-43407
You might also like:
- Tags:
- npm
- liferay-ckeditor
Anything's wrong? Let us know Last updated on August 25, 2025


