<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T18:08:32.783260+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0815</id>
    <title>certfr-2025-avi-0815 — Une vulnérabilité a été découverte dans Liferay. Elle permet à un attaquant de provoquer un contournement de la politiq…</title>
    <updated>2026-10-07T18:08:32.786782+00:00</updated>
    <content>certfr-2025-avi-0815</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0815"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-253355</id>
    <title>EUVD-2026-253355</title>
    <updated>2026-10-07T18:08:32.786817+00:00</updated>
    <content>EUVD-2026-253355</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-253355"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-43819</id>
    <title>fkie_cve-2025-43819</title>
    <updated>2026-10-07T18:08:32.786832+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, and 2024.Q1.1 through 2024.Q1.12 is allow an remote non-authenticated attacker to reuse old user session by SLO API</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-43819"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rpx3-f938-xj5q</id>
    <title>GHSA-rpx3-f938-xj5q — Liferay Portal and DXP does not properly expire sessions</title>
    <updated>2026-10-07T18:08:32.786861+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.liferay:com.liferay.saml.impl</p>
<p>### Summary</p>
<p>Liferay Portal/DXP contains an Insufficient Session Expiration issue where the Single Logout (SLO) API may fail to invalidate a user’s previous session. An attacker can reuse a stale session via the SLO endpoint to gain an authenticated context.</p>
<p>### Affected Versions</p>
<p>The following platform versions are affected:</p>
<p>*   **Liferay Portal:**  
    *   `7.3.3.131` through `7.4.3.121`
*   **Liferay DXP:**
    *   `2024.Q4.0`–`2024.Q4.3`
    *   `2024.Q3.1`–`2024.Q3.13`
    *   `2024.Q2.0`–`2024.Q2.13`
    *   `2024.Q1.1`–`2024.Q1.12`</p>
<p>### Remediation</p>
<p>Update to the fixed builds and, for Maven consumers of the SAML module, upgrade `com.liferay:com.liferay.saml.impl` to **5.0.51** or later. After upgrading, ensure session invalidation policies are enforced and verify SLO behavior end-to-end.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rpx3-f938-xj5q"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2118</id>
    <title>WID-SEC-W-2025-2118 — Liferay Portal: Mehrere Schwachstellen</title>
    <updated>2026-10-07T18:08:32.786903+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Liferay Portal und Liferay DXP ausnutzen, um Cross Site Scripting durchzuführen und Benutzerrechte erlangen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2118"/>
  </entry>
</feed>
