CVE-2025-2536 | Liferay Portal/DXP Frontend JS index.js toastData cross site scripting (Nessus ID 233193)
A vulnerability was found in Liferay Portal and DXP. It has been declared as problematic. This vulnerability affects unknown code in the library layout-taglib/__liferay__/index.js of the component Frontend JS Module. The manipulation of the argument toastData results in cross site scripting.
This vulnerability was named CVE-2025-2536. The attack may be performed from remote. There is no available exploit.