CVE-2025-43810
- EPSS 0.14%
- Veröffentlicht 22.09.2025 23:15:37
- Zuletzt bearbeitet 24.09.2025 18:11:34
Insecure Direct Object Reference (IDOR) vulnerability with commerce order notes in Liferay Portal 7.3.5 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote authentic...
CVE-2025-43814
- EPSS 0.18%
- Veröffentlicht 22.09.2025 23:15:37
- Zuletzt bearbeitet 24.09.2025 18:11:34
In Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions the audit events records a user’s password ...
CVE-2025-43806
- EPSS 0.15%
- Veröffentlicht 22.09.2025 22:15:43
- Zuletzt bearbeitet 24.09.2025 18:11:34
Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 does not properly check permission with import and export tasks, which allows remote authe...
CVE-2025-43807
- EPSS 0.17%
- Veröffentlicht 22.09.2025 16:17:24
- Zuletzt bearbeitet 22.09.2025 21:22:33
Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote attackers to ...
CVE-2025-43808
- EPSS 0.19%
- Veröffentlicht 19.09.2025 20:37:22
- Zuletzt bearbeitet 22.09.2025 21:23:01
The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and 7.3 service pack 3 through update 35 saves virtual products uploaded to Documen...
CVE-2025-43809
- EPSS 0.06%
- Veröffentlicht 19.09.2025 19:15:50
- Zuletzt bearbeitet 22.09.2025 21:23:01
Cross-Site Request Forgery (CSRF) vulnerability in the server (license) registration page in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.9, 7.4 GA thro...
CVE-2025-43803
- EPSS 0.17%
- Veröffentlicht 19.09.2025 18:50:09
- Zuletzt bearbeitet 22.09.2025 21:23:01
Insecure direct object reference (IDOR) vulnerability in the Contacts Center widget in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.6, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through u...
CVE-2025-43804
- EPSS 0.2%
- Veröffentlicht 16.09.2025 22:23:13
- Zuletzt bearbeitet 17.09.2025 14:18:55
Cross-site scripting (XSS) vulnerability in Search widget in Liferay Portal 7.4.3.93 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_...
CVE-2025-43805
- EPSS 0.19%
- Veröffentlicht 16.09.2025 21:33:50
- Zuletzt bearbeitet 17.09.2025 14:18:55
Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, and 7.3 GA through update 35 does not perform an authorization check when users attempt to view a display page template, which a...
CVE-2025-43801
- EPSS 0.23%
- Veröffentlicht 16.09.2025 16:09:05
- Zuletzt bearbeitet 17.09.2025 14:18:55
Unchecked input for loop condition vulnerability in XML-RPC in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and old...