<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T01:38:00.787685+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0954</id>
    <title>certfr-2025-avi-0954 — De multiples vulnérabilités ont été découvertes dans Liferay. Elles permettent à un attaquant de provoquer une atteinte…</title>
    <updated>2026-10-07T01:38:00.792658+00:00</updated>
    <content>certfr-2025-avi-0954</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0954"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-202133</id>
    <title>EUVD-2026-202133</title>
    <updated>2026-10-07T01:38:00.792719+00:00</updated>
    <content>EUVD-2026-202133</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-202133"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-29038</id>
    <title>fkie_cve-2021-29038</title>
    <updated>2026-10-07T01:38:00.792745+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attackers to use man-in-the-middle or shoulder surfing attacks to steal user's password reminder answers.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-29038"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mwhf-6mjm-6w3h</id>
    <title>GHSA-mwhf-6mjm-6w3h — Liferay Portal and Liferay DXP Does Not Obfuscate Password Reminder Answers</title>
    <updated>2026-10-07T01:38:00.792795+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.liferay.portal:portal-impl, Maven: com.liferay:com.liferay.users.admin.web, Maven: com.liferay:com.liferay.login.web, Maven: com.liferay.commerce:com.liferay.commerce.account.web, Maven: com.liferay.portal:release.dxp.bom</p>
<p>In Liferay Impl before 5.18.4, Liferay Users Admin Web before 5.0.33, Liferay Login Web before 5.0.18, and Liferay Commerce Account Web before 3.0.7 from Liferay Portal (7.2.0 through 7.3.5), and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attackers to use man-in-the-middle or shoulder surfing attacks to steal user's password reminder answers.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mwhf-6mjm-6w3h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-29038</id>
    <title>gsd-2021-29038</title>
    <updated>2026-10-07T01:38:00.792856+00:00</updated>
    <content>gsd-2021-29038</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-29038"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0323</id>
    <title>WID-SEC-W-2024-0323 — Liferay Liferay Portal und DXP: Mehrere Schwachstellen</title>
    <updated>2026-10-07T01:38:00.792880+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen in Liferay Liferay Portal und Liferay Liferay DXP ausnutzen, um Informationen offenzulegen, Cross-Site-Scripting (XSS)-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0323"/>
  </entry>
</feed>
