In Liferay Portal versions 7.4.0 through 7.4.3.132, and Liferay DXP versions 2025.Q1.0 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.16 and 7.4 GA through update 92 a medium severity vulnerability CVE-2025-43739 was detected. This vulnerability allows an authenticated attacker to modify the content of emails sent through the calendar portlet, which enables them to send phishing emails to other users in the same organization. To address this issue, users should upgrade Liferay Portal to master branch and Liferay DXP to versions 2025.Q2.0 or 2025.Q1.7. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-43739.
Read more E-commerceIn Liferay Portal versions 7.4.0 through 7.4.3.132, and Liferay DXP versions 2025.Q2.0 through 2025.Q2.8, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.19 a medium severity vulnerability CVE-2025-43738 was detected. This vulnerability allows an authenticated attacker to inject JavaScript code via the _com_liferay_expando_web_portlet_ExpandoPortlet_displayType parameter. To address this issue, users should upgrade Liferay Portal to master branch and Liferay DXP to versions 2025.Q1.6 or 2025.Q2.9. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-43738.
Read more E-commerceIn Liferay Portal versions 7.4.0 through 7.4.3.132, and Liferay DXP versions 2025.Q1.0 through 2025.Q1.3, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 a medium severity vulnerability CVE-2025-43742 was detected. This vulnerability allows attackers to inject JavaScript into web content for friendly URLs. To address this issue, users should upgrade Liferay Portal to master branch and Liferay DXP to versions 2024.Q1.15, 2025.Q1.4 or 2025.Q2.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-43742.
Read more E-commerceIn Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier a high severity vulnerability CVE-2025-49558 was detected. This vulnerability allows attackers to bypass security features by exploiting a Time-of-check Time-of-use (TOCTOU) Race Condition, enabling unauthorized write access. To address this issue, users should upgrade Magento to versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14 or 2.4.4-p15. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49558.
Read more E-commerceIn Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier a high severity vulnerability CVE-2025-49554 was detected. This vulnerability allows attackers to cause a denial-of-service (DoS) condition by providing specially crafted input, leading the application to crash or become unresponsive. To address this issue, users should upgrade Adobe Commerce to versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14 or 2.4.4-p15. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49554.
Read more E-commerceIn Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier a high severity vulnerability CVE-2025-49555 was detected. This vulnerability allows attackers to escalate privileges through CSRF by tricking authenticated users into performing unintended actions, potentially enabling unauthorized access or modification of sensitive data. Currently, there is no fix version for this vulnerability. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49555.
Read more E-commerceIn Adobe Commerce versions 2.4.9-alpha1 and earlier a high severity vulnerability CVE-2025-49556 was detected. This vulnerability allows attackers to bypass security measures and gain unauthorized read access. To address this issue, users should upgrade Adobe Commerce to versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14 or 2.4.4-p15. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49556.
Read more E-commerceIn Adobe Commerce versions 2.4.9-alpha1 and earlier a high severity vulnerability CVE-2025-49557 was detected. This vulnerability allows low-privileged attackers to inject malicious scripts into form fields, potentially escalating privileges or compromising sensitive user data. Exploitation requires user interaction by visiting the vulnerable page. To address this issue, users should upgrade Adobe Commerce to versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14 or 2.4.4-p15. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49557.
Read more E-commerceIn WooCommerce Support Ticket System plugin for WordPress, versions 17.8 and prior a medium severity vulnerability CVE-2024-13775 was detected. This allows attackers with Subscriber-level access or higher to delete posts and access user data. To address this issue, users should upgrade WooCommerce Support Ticket System plugin to version 17.9 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-13775.
Read more E-commerce