Proactive Insights and Support For Open-Source Applications
  • Applications
  • Platform
  • Support
  • Resources
    • 2025 OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
Book a demo
Book a demo
  • Applications
  • Platform
  • Support
  • Resources
    • 2025 OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
  • Home
  • Knowledge Base
  • Newsflash
  • Business and Enterprise Solutions

Business and Enterprise Solutions

All OSSpediaArticlesHow ToNewsflashCase Studies
Don't Miss out!
Join our newsletter for exclusive updates on open source innovations.

    Selected category
    • Communication
      • Communication
    • Communication and Collaboration
      • Utility
      • Communication and Collaboration
      • Communication
    • Specialized Software
      • Educational
      • Graphic Design
    • Business and Enterprise Solutions
      • Customer Service
      • Productivity
      • Supply Chain Management (SCM)
      • CRM
      • E-commerce
      • CMS
      • Marketing Automation
      • ERP
    • Project and Agile Management
      • Project Management
      • IT Business Management
    • Infrastructure and Network
      • CMS
      • Networking
      • Storage
      • Security
    • DevOps
      • DevOps
      • Mobile App Development
      • Backup and Recovery
      • Data Analytics
      • Web Development
      • Developer Stacks
      • Cloud Computing
      • Monitoring
      • Application Development
      • Developer Tools
    • Data Management and Analytics
      • Communication
      • Application Development
      • Analytics
      • Machine Learning
      • Database
      • Data Analytics
    31 Oct 2025 Business and Enterprise Solutions
    Liferay: Password Enumeration Vulnerability via Brute Force Attack

    In Liferay Portal versions 7.4.0 through 7.4.3.119 and Liferay DXP versions 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions a medium severity vulnerability CVE-2025-62257 was detected. This vulnerability allows remote attackers to determine a user’s password through brute force attacks, even when account lockout protection is enabled. To fix this vulnerability, users should upgrade to Liferay Portal 7.4.3.120, Liferay DXP 2024.Q4.0, 2024.Q3.0, 2024.Q2.0, or 2024.Q1.6. For more details, visit https://avd.aquasec.com/nvd/2025/cve-2025-62257.

    Read more
    CMS
    31 Oct 2025 Business and Enterprise Solutions
    Liferay: DNS Rebinding Vulnerability Allows Remote URL Redirection

    In Liferay Portal versions 7.4.0 through 7.4.3.119 and older unsupported versions, and Liferay DXP versions 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions a medium severity vulnerability CVE‑2025‑62266 was detected. This vulnerability allows remote attackers to redirect users to arbitrary external URLs due to DNS rebinding attacks. To fix this vulnerability, users should upgrade to Liferay Portal 7.4.3.120, Liferay DXP 2024.Q4.0, 2024.Q3.0, 2024.Q2.0, or 2024.Q1.6. For more details, visit https://avd.aquasec.com/nvd/2025/cve-2025-62266.

    Read more
    CMS
    31 Oct 2025 Business and Enterprise Solutions
    Liferay: XSS Vulnerability in Blogs Widget via iframe Injection

    In Liferay Portal versions 7.4.0 through 7.4.3.111 and older unsupported versions, and Liferay DXP versions 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and 7.3 GA through update 36 a medium severity vulnerability CVE‑2025‑62265 was detected. This vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted <iframe> tag in a blog entry’s “Content” text field, due to the Blogs widget not applying the sandbox attribute to <iframe> elements. To fix this vulnerability, users should upgrade to Liferay Portal 7.4.3.112 or Liferay DXP 2024.Q1.1 or 2023.Q3.9. For more details, visit https://avd.aquasec.com/nvd/2025/cve-2025-62265.

    Read more
    CMS
    30 Oct 2025 Business and Enterprise Solutions
    SuiteCRM: Reflected XSS via HTTP Referer Header

    In SuiteCRM version 7.14.1 a medium severity vulnerability CVE‑2025‑41384 was detected. This vulnerability allows an attacker to execute JavaScript code by modifying the HTTP Referer header to include an arbitrary domain with malicious JavaScript at the end; the server will attempt to block the arbitrary domain but still allow the JavaScript code to execute. To address this issue, users should upgrade SuiteCRM to version 7.14.7 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-41384.

    Read more
    CRM
    30 Oct 2025 Business and Enterprise Solutions
    Liferay: Headless API Denial-of-Service via Unrestricted Object Returns

    In Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions a high severity vulnerability CVE-2025-62260 was detected. This vulnerability allows remote attackers to perform denial-of-service attacks by executing Headless API requests that return a large number of objects. To fix this issue, users should upgrade to Liferay Portal 7.4.3.100, Liferay DXP 2024.Q1.1, Liferay DXP 2023.Q4.0, Liferay DXP 2023.Q3.5, or Liferay DXP 7.3 U36. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62260.

    Read more
    CMS
    30 Oct 2025 Business and Enterprise Solutions
    Liferay: API Access Without Email Verification

    In Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions a medium severity vulnerability CVE-2025-62259 was detected. This vulnerability allows remote users to access and edit content via the API before verifying their email address. To fix this issue, users should upgrade to Liferay Portal 7.4.3.110, Liferay DXP 2024.Q1.1, Liferay DXP 2023.Q4.0, Liferay DXP 2023.Q3.5, or Liferay DXP 7.3 Update 36. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62259.

    Read more
    CMS
    30 Oct 2025 Business and Enterprise Solutions
    Liferay: Headless API CSRF Allows Remote Execution

    In Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions a high severity vulnerability CVE-2025-62258 was detected. This vulnerability allows remote attackers to execute any Headless API via the `endpoint` parameter. To fix this issue, users should upgrade to Liferay Portal 7.4.3.108, Liferay DXP 2024.Q1.1, Liferay DXP 2023.Q4.1, Liferay DXP 2023.Q3.5, or Liferay DXP 7.3 U36. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62258.

    Read more
    CMS
    29 Oct 2025 Business and Enterprise Solutions
    Liferay: Multiple Stored XSS Vulnerabilities in Account Role and Organization Name Fields

    In Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 service pack 3 through update 36 a medium severity vulnerability CVE-2025-62263 was detected. This vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account Role’s “Title” text field and an Organization’s “Name” text field, potentially leading to stored cross-site scripting (XSS) on multiple pages. To fix this issue, users should upgrade to Liferay Portal 7.4.3.104, Liferay DXP 2024.Q1.1, Liferay DXP 2023.Q4.0, or Liferay DXP 2023.Q3.5. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62263.

    Read more
    CMS
    29 Oct 2025 Business and Enterprise Solutions
    Liferay: LDAP Import Log File Information Exposure

    In Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 service pack 3 through update 36 a medium severity vulnerability CVE-2025-62263 was detected. This vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account Role’s “Title” text field and an Organization’s “Name” text field, potentially leading to stored cross-site scripting (XSS) on multiple pages. To fix this issue, users should upgrade to Liferay Portal 7.4.3.104, Liferay DXP 2024.Q1.1, Liferay DXP 2023.Q4.0, or Liferay DXP 2023.Q3.5. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62263.

    Read more
    CMS
    Proactive Insights and Support For Open-Source Applications
    Contact us: Whatsapp
    Company
    • About Hossted
    • Data Processing Addendum
    Solutions
    • Applications
    • Support Plans
    • About Solution
    Resources
    • FAQ
    • Knowledge Base

    © HOSSTED 2026 All rights reserved

    • Privacy Policy
    • Terms and Conditions
    • Cookies Policy
    Manage Consent

    We use cookies to measure marketing efforts and improve our services. Please review the cookie settings and confirm your choice.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}