<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T14:16:26.722617+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0954</id>
    <title>certfr-2025-avi-0954 — De multiples vulnérabilités ont été découvertes dans Liferay. Elles permettent à un attaquant de provoquer une atteinte…</title>
    <updated>2026-10-05T14:16:26.779018+00:00</updated>
    <content>certfr-2025-avi-0954</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0954"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-254327</id>
    <title>EUVD-2026-254327</title>
    <updated>2026-10-05T14:16:26.779075+00:00</updated>
    <content>EUVD-2026-254327</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-254327"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-43824</id>
    <title>fkie_cve-2025-43824</title>
    <updated>2026-10-05T14:16:26.779103+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions uses a user’s name in the “Content-Disposition” header, which allows remote authenticated users to change the file extension when a vCard file is downloaded.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-43824"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pfxj-gvqg-mj44</id>
    <title>GHSA-pfxj-gvqg-mj44 — Liferay Profile Widget does not prevent vCard extension spoofing</title>
    <updated>2026-10-05T14:16:26.779151+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.liferay.portal:release.portal.bom</p>
<p>The Profile Widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions uses a user’s name in the “Content-Disposition” header, which allows remote authenticated users to change the file extension when a vCard file is downloaded.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pfxj-gvqg-mj44"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2214</id>
    <title>WID-SEC-W-2025-2214 — Liferay Portal: Schwachstelle ermöglicht Manipulation von Daten</title>
    <updated>2026-10-05T14:16:26.779191+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Liferay Portal und Liferay DXP ausnutzen, um Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2214"/>
  </entry>
</feed>
