Vulnerability library
Security checkAugust 25, 2025

Liferay Portal Reflected XSS in CKeditor 4.21.0 endpoint

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpmliferay-ckeditor

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.4, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.

Recommendation

Update the liferay-ckeditor package to the latest compatible version. Followings are version details:

  • Affected version(s): < 4.21.0-liferay.10
  • Patched version(s): 4.21.0-liferay.10

References

Could your website be exposed too?

SmartScanner can check your website for Liferay Portal Reflected XSS in CKeditor 4.21.0 endpoint and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated August 25, 2025