<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 04:07:29 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-0954 — De multiples vulnérabilités ont été découvertes dans Liferay. Elles permettent à un attaquant de provoquer une atteinte…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0954</link>
      <description>certfr-2025-avi-0954</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0954</guid>
    </item>
    <item>
      <title>EUVD-2026-4178</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-4178</link>
      <description>EUVD-2026-4178</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-4178</guid>
    </item>
    <item>
      <title>fkie_cve-2024-25150</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-25150</link>
      <description>&lt;p&gt;Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions allows remote authenticated users to obtain a user&amp;#39;s full name from the page&amp;#39;s title by enumerating user screen names.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions allows remote authenticated users to obtain a user&amp;#39;s full name from the page&amp;#39;s title by enumerating user screen names.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-25150</guid>
    </item>
    <item>
      <title>GHSA-4585-28v2-8h46 — Liferay Portal and Liferay DXP Information Disclosure Vulnerability in the Control Panel</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4585-28v2-8h46</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.liferay.portal:release.portal.bom, Maven: com.liferay.portal:release.dxp.bom&lt;/p&gt;
&lt;p&gt;Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions allows remote authenticated users to obtain a user&amp;#39;s full name from the page&amp;#39;s title by enumerating user screen names.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.liferay.portal:release.portal.bom, Maven: com.liferay.portal:release.dxp.bom&lt;/p&gt;
&lt;p&gt;Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions allows remote authenticated users to obtain a user&amp;#39;s full name from the page&amp;#39;s title by enumerating user screen names.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4585-28v2-8h46</guid>
    </item>
    <item>
      <title>gsd-2024-25150</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-25150</link>
      <description>gsd-2024-25150</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-25150</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0428 — Liferay Portal und DXP: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0428</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Liferay Liferay DXP und Liferay Liferay Portal ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen oder seine Privilegien zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Liferay Liferay DXP und Liferay Liferay Portal ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen oder seine Privilegien zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0428</guid>
    </item>
  </channel>
</rss>
