Liferay Portal, Cross-Site Scripting (XSS), CVE-2025-21800 (Moderate)

Listen to this Post

The CVE-2025-21800 vulnerability is a Cross-Site Scripting (XSS) flaw within the Blogs widget of Liferay Portal and Liferay DXP. The vulnerability exists because the application fails to properly sanitize user-supplied input within a blog entry’s “Content” text field. Specifically, the widget does not apply a `sandbox` attribute to `