<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 21:40:35 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-0954 — De multiples vulnérabilités ont été découvertes dans Liferay. Elles permettent à un attaquant de provoquer une atteinte…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0954</link>
      <description>certfr-2025-avi-0954</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0954</guid>
    </item>
    <item>
      <title>EUVD-2026-202133</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-202133</link>
      <description>EUVD-2026-202133</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-202133</guid>
    </item>
    <item>
      <title>fkie_cve-2021-29038</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-29038</link>
      <description>&lt;p&gt;Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attackers to use man-in-the-middle or shoulder surfing attacks to steal user&amp;#39;s password reminder answers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attackers to use man-in-the-middle or shoulder surfing attacks to steal user&amp;#39;s password reminder answers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-29038</guid>
    </item>
    <item>
      <title>GHSA-mwhf-6mjm-6w3h — Liferay Portal and Liferay DXP Does Not Obfuscate Password Reminder Answers</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mwhf-6mjm-6w3h</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.liferay.portal:portal-impl, Maven: com.liferay:com.liferay.users.admin.web, Maven: com.liferay:com.liferay.login.web, Maven: com.liferay.commerce:com.liferay.commerce.account.web, Maven: com.liferay.portal:release.dxp.bom&lt;/p&gt;
&lt;p&gt;In Liferay Impl before 5.18.4, Liferay Users Admin Web before 5.0.33, Liferay Login Web before 5.0.18, and Liferay Commerce Account Web before 3.0.7 from Liferay Portal (7.2.0 through 7.3.5), and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attackers to use man-in-the-middle or shoulder surfing attacks to steal user&amp;#39;s password reminder answers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.liferay.portal:portal-impl, Maven: com.liferay:com.liferay.users.admin.web, Maven: com.liferay:com.liferay.login.web, Maven: com.liferay.commerce:com.liferay.commerce.account.web, Maven: com.liferay.portal:release.dxp.bom&lt;/p&gt;
&lt;p&gt;In Liferay Impl before 5.18.4, Liferay Users Admin Web before 5.0.33, Liferay Login Web before 5.0.18, and Liferay Commerce Account Web before 3.0.7 from Liferay Portal (7.2.0 through 7.3.5), and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attackers to use man-in-the-middle or shoulder surfing attacks to steal user&amp;#39;s password reminder answers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mwhf-6mjm-6w3h</guid>
    </item>
    <item>
      <title>gsd-2021-29038</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-29038</link>
      <description>gsd-2021-29038</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-29038</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0323 — Liferay Liferay Portal und DXP: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0323</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Liferay Liferay Portal und Liferay Liferay DXP ausnutzen, um Informationen offenzulegen, Cross-Site-Scripting (XSS)-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Liferay Liferay Portal und Liferay Liferay DXP ausnutzen, um Informationen offenzulegen, Cross-Site-Scripting (XSS)-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0323</guid>
    </item>
  </channel>
</rss>
