CVE-2025-62275
- EPSS 0.06%
- Veröffentlicht 01.11.2025 02:42:50
- Zuletzt bearbeitet 10.11.2025 16:20:40
Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions does not check permission of images ...
CVE-2025-62276
- EPSS 0.02%
- Veröffentlicht 31.10.2025 23:34:20
- Zuletzt bearbeitet 10.11.2025 16:29:02
The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported...
CVE-2025-62267
- EPSS 0.04%
- Veröffentlicht 31.10.2025 18:12:50
- Zuletzt bearbeitet 10.11.2025 17:04:42
Multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 35 through update...
CVE-2025-62264
- EPSS 0.04%
- Veröffentlicht 31.10.2025 17:32:01
- Zuletzt bearbeitet 10.11.2025 17:11:02
Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 update 4 through update 92 allows remote attacke...
CVE-2025-62265
- EPSS 0.04%
- Veröffentlicht 30.10.2025 18:30:35
- Zuletzt bearbeitet 11.11.2025 01:58:54
Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, 7.3 GA throug...
CVE-2025-62266
- EPSS 0.04%
- Veröffentlicht 30.10.2025 17:37:21
- Zuletzt bearbeitet 11.11.2025 01:58:06
By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions is v...
CVE-2025-62257
- EPSS 0.02%
- Veröffentlicht 29.10.2025 23:24:42
- Zuletzt bearbeitet 10.11.2025 21:37:25
Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older...
CVE-2025-62258
- EPSS 0.02%
- Veröffentlicht 27.10.2025 22:56:21
- Zuletzt bearbeitet 10.11.2025 21:39:01
CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to execute any Headl...
CVE-2025-62259
- EPSS 0.05%
- Veröffentlicht 27.10.2025 22:13:35
- Zuletzt bearbeitet 08.12.2025 14:36:32
Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has ve...
CVE-2025-62260
- EPSS 0.14%
- Veröffentlicht 27.10.2025 21:44:08
- Zuletzt bearbeitet 10.11.2025 21:56:20
Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number of objects returned from Headless API requests, which all...