CVE-2025-3639

Liferay Portal 7.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 and 7.3 GA through update 36 allows unauthenticated users with valid credentials to bypass the login process by changing the POST method to GET, once the site has MFA enabled.


We have discovered 494 live websites that are affected by CVE-2025-3639.

Run a Free Instant Scan




Affected Software

Product  Liferay
Category Content Management System
Vulnerable Domains494 live websites (100% of Liferay install base)
Vulnerable Versions
  • from 7.3 through 7.4.3.132
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-288 Authentication Bypass Using an Alternate Path or Channel



Details

  • Published - Aug 18, 2025
  • Updated - Aug 18, 2025

Website Distribution by Country

Number of websites using CVE-2025-3639
United States50 websites



Spain102 websites
Iran52 websites
Italy37 websites
Germany30 websites
Namibia30 websites
Mexico30 websites
Netherlands15 websites
France15 websites
Saudi Arabia12 websites

Website Distribution by TLD

Number of websites using CVE-2025-3639
.com73 websites
.es50 websites
.it31 websites
.org22 websites
.de19 websites
.nl16 websites
.net10 websites
.ca8 websites
.pl8 websites
.fr7 websites

Websites affected by CVE-2025-3639

Top websites that are affected by CVE-2025-3639. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.it Italy**,***
***.sk Slovakia**,***
******.es Spain**,***
********.***.ro Romania**,***
***.com United States**,***
*****.mx Mexico***,***
****************.org France***,***
**.****.***.cn China***,***
***.**.ca Canada***,***
***.com United States***,***
See full domain list

FAQ

CVE-2025-3639 is Authentication Bypass Using an Alternate Path or Channel in Liferay
A total of 494 websites have been identified as vulnerable to CVE-2025-3639, based on global website indexing conducted by WebTechSurvey.
The Liferay is affected by the CVE-2025-3639 vulnerability.
Liferay versions up to and including 7.4.3.132 are vulnerable to CVE-2025-3639.