<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:22:32.213329+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0800</id>
    <title>certfr-2025-avi-0800 — De multiples vulnérabilités ont été découvertes dans Liferay. Certaines d'entre elles permettent à un attaquant de prov…</title>
    <updated>2026-10-04T01:22:32.216325+00:00</updated>
    <content>certfr-2025-avi-0800</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0800"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-252853</id>
    <title>EUVD-2026-252853</title>
    <updated>2026-10-04T01:22:32.216372+00:00</updated>
    <content>EUVD-2026-252853</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-252853"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-43804</id>
    <title>fkie_cve-2025-43804</title>
    <updated>2026-10-04T01:22:32.216387+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cross-site scripting (XSS) vulnerability in Search widget in Liferay Portal 7.4.3.93 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_search_web_portlet_SearchPortlet_userId parameter.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-43804"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-ccrc-5vp5-vp5j</id>
    <title>GHSA-ccrc-5vp5-vp5j — Liferay search widget vulnerable to Cross-site Scripting</title>
    <updated>2026-10-04T01:22:32.216416+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.liferay:com.liferay.portal.search</p>
<p>There is a Cross-site scripting (XSS) vulnerability in Liferay Portal's Search widget . Versions 7.4.3.93 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 allow remote attackers to inject arbitrary web scripts or HTML via the `_com_liferay_portal_search_web_portlet_SearchPortlet_userId` parameter.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-ccrc-5vp5-vp5j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2076</id>
    <title>WID-SEC-W-2025-2076 — Liferay Portal: Mehrere Schwachstellen</title>
    <updated>2026-10-04T01:22:32.216441+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Liferay Portal und Liferay DXP ausnutzen, um einen Denial of Service oder Cross Site Scripting Angriff durchzuführen und Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2076"/>
  </entry>
</feed>
