Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 15 through update 92 allow remote attackers to inject arbitrary web script or HTML via crafted payload injected into a Terms and Condition's Name text field to (1) Payment Terms, or (2) the Delivery Term on the view order page.
Use CWE-79, Liferay vendor hub and Digital Experience Platform product page to widen CVE-2025-43822 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-62260, CVE-2025-62258 and CVE-2025-62275 for nearby disclosures in the same product family.