CVE-2025-43824
- EPSS 0.16%
- Veröffentlicht 06.10.2025 22:15:37
- Zuletzt bearbeitet 06.10.2025 22:15:37
The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions uses a user’s name in the...
CVE-2025-43825
- EPSS 0.04%
- Veröffentlicht 03.10.2025 21:16:28
- Zuletzt bearbeitet 06.10.2025 14:56:47
A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.1...
CVE-2025-43826
- EPSS 0.17%
- Veröffentlicht 30.09.2025 23:15:29
- Zuletzt bearbeitet 02.10.2025 19:12:17
Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 9...
CVE-2025-43827
- EPSS 0.14%
- Veröffentlicht 30.09.2025 19:15:37
- Zuletzt bearbeitet 02.10.2025 19:12:17
Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10...
CVE-2025-43812
- EPSS 0.17%
- Veröffentlicht 29.09.2025 23:15:31
- Zuletzt bearbeitet 02.10.2025 19:12:42
Cross-site scripting (XSS) vulnerability in web content template in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticated users to ...
CVE-2025-43813
- EPSS 0.24%
- Veröffentlicht 29.09.2025 23:15:31
- Zuletzt bearbeitet 02.10.2025 19:12:42
Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.107, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update...
CVE-2025-43817
- EPSS 0.17%
- Veröffentlicht 29.09.2025 23:15:31
- Zuletzt bearbeitet 02.10.2025 19:12:42
Multiple reflected cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.74 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.6, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 74 through update 92 allow remote attackers to inject...
CVE-2025-43820
- EPSS 0.17%
- Veröffentlicht 29.09.2025 22:15:36
- Zuletzt bearbeitet 02.10.2025 19:12:42
Multiple cross-site scripting (XSS) vulnerabilities in the Calendar widget when inviting users to a event in Liferay Portal 7.4.3.35 through 7.4.3.110, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.6, 7.4 update 35 through up...
CVE-2025-43815
- EPSS 0.2%
- Veröffentlicht 29.09.2025 22:15:35
- Zuletzt bearbeitet 02.10.2025 19:12:42
Reflected cross-site scripting (XSS) vulnerability on the page configuration page in Liferay Portal 7.4.3.102 through 7.4.3.110, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, and 2023.Q3.5 allows remote attackers to inject arbitrary web script or HTML...
CVE-2025-43818
- EPSS 0.17%
- Veröffentlicht 29.09.2025 22:15:35
- Zuletzt bearbeitet 02.10.2025 19:12:42
Cross-site scripting (XSS) vulnerability in the Calendar widget in Liferay Portal 7.4.3.35 through 7.4.3.110, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.6, 7.4 update 35 through update 92, and 7.3 update 25 through update ...