Liferay Portal, Stored XSS, CVE-2025-XXXXX (Moderate)

Listen to this Post

This CVE describes a Stored Cross-Site Scripting vulnerability within the Liferay Portal Commerce module, specifically affecting products of the ‘diagram’ type. The attack vector is a crafted SVG file uploaded to the platform. SVG files can contain JavaScript code within `

Scroll to Top