<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 01:21:38 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-0800 — De multiples vulnérabilités ont été découvertes dans Liferay. Certaines d'entre elles permettent à un attaquant de prov…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0800</link>
      <description>certfr-2025-avi-0800</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0800</guid>
    </item>
    <item>
      <title>EUVD-2026-252853</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-252853</link>
      <description>EUVD-2026-252853</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-252853</guid>
    </item>
    <item>
      <title>fkie_cve-2025-43804</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-43804</link>
      <description>&lt;p&gt;Cross-site scripting (XSS) vulnerability in Search widget in Liferay Portal 7.4.3.93 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_search_web_portlet_SearchPortlet_userId parameter.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cross-site scripting (XSS) vulnerability in Search widget in Liferay Portal 7.4.3.93 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_search_web_portlet_SearchPortlet_userId parameter.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-43804</guid>
    </item>
    <item>
      <title>GHSA-ccrc-5vp5-vp5j — Liferay search widget vulnerable to Cross-site Scripting</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ccrc-5vp5-vp5j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.liferay:com.liferay.portal.search&lt;/p&gt;
&lt;p&gt;There is a Cross-site scripting (XSS) vulnerability in Liferay Portal&amp;#39;s Search widget . Versions 7.4.3.93 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 allow remote attackers to inject arbitrary web scripts or HTML via the `_com_liferay_portal_search_web_portlet_SearchPortlet_userId` parameter.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.liferay:com.liferay.portal.search&lt;/p&gt;
&lt;p&gt;There is a Cross-site scripting (XSS) vulnerability in Liferay Portal&amp;#39;s Search widget . Versions 7.4.3.93 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 allow remote attackers to inject arbitrary web scripts or HTML via the `_com_liferay_portal_search_web_portlet_SearchPortlet_userId` parameter.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ccrc-5vp5-vp5j</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2076 — Liferay Portal: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2076</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Liferay Portal und Liferay DXP ausnutzen, um einen Denial of Service oder Cross Site Scripting Angriff durchzuführen und Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Liferay Portal und Liferay DXP ausnutzen, um einen Denial of Service oder Cross Site Scripting Angriff durchzuführen und Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2076</guid>
    </item>
  </channel>
</rss>
