In Liferay Portal versions 7.4.0 through 7.4.3.119 and Liferay DXP versions 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions a medium severity vulnerability CVE-2025-62257 was detected. This vulnerability allows remote attackers to determine a user’s password through brute force attacks, even when account lockout protection is enabled. To fix this vulnerability, users should upgrade to Liferay Portal 7.4.3.120, Liferay DXP 2024.Q4.0, 2024.Q3.0, 2024.Q2.0, or 2024.Q1.6. For more details, visit https://avd.aquasec.com/nvd/2025/cve-2025-62257.
Read more CMSIn Liferay Portal versions 7.4.0 through 7.4.3.119 and older unsupported versions, and Liferay DXP versions 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions a medium severity vulnerability CVE‑2025‑62266 was detected. This vulnerability allows remote attackers to redirect users to arbitrary external URLs due to DNS rebinding attacks. To fix this vulnerability, users should upgrade to Liferay Portal 7.4.3.120, Liferay DXP 2024.Q4.0, 2024.Q3.0, 2024.Q2.0, or 2024.Q1.6. For more details, visit https://avd.aquasec.com/nvd/2025/cve-2025-62266.
Read more CMSIn Liferay Portal versions 7.4.0 through 7.4.3.111 and older unsupported versions, and Liferay DXP versions 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and 7.3 GA through update 36 a medium severity vulnerability CVE‑2025‑62265 was detected. This vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted <iframe> tag in a blog entry’s “Content” text field, due to the Blogs widget not applying the sandbox attribute to <iframe> elements. To fix this vulnerability, users should upgrade to Liferay Portal 7.4.3.112 or Liferay DXP 2024.Q1.1 or 2023.Q3.9. For more details, visit https://avd.aquasec.com/nvd/2025/cve-2025-62265.
Read more CMSIn SuiteCRM version 7.14.1 a medium severity vulnerability CVE‑2025‑41384 was detected. This vulnerability allows an attacker to execute JavaScript code by modifying the HTTP Referer header to include an arbitrary domain with malicious JavaScript at the end; the server will attempt to block the arbitrary domain but still allow the JavaScript code to execute. To address this issue, users should upgrade SuiteCRM to version 7.14.7 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-41384.
Read more CRMIn Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions a high severity vulnerability CVE-2025-62260 was detected. This vulnerability allows remote attackers to perform denial-of-service attacks by executing Headless API requests that return a large number of objects. To fix this issue, users should upgrade to Liferay Portal 7.4.3.100, Liferay DXP 2024.Q1.1, Liferay DXP 2023.Q4.0, Liferay DXP 2023.Q3.5, or Liferay DXP 7.3 U36. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62260.
Read more CMSIn Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions a medium severity vulnerability CVE-2025-62259 was detected. This vulnerability allows remote users to access and edit content via the API before verifying their email address. To fix this issue, users should upgrade to Liferay Portal 7.4.3.110, Liferay DXP 2024.Q1.1, Liferay DXP 2023.Q4.0, Liferay DXP 2023.Q3.5, or Liferay DXP 7.3 Update 36. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62259.
Read more CMSIn Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions a high severity vulnerability CVE-2025-62258 was detected. This vulnerability allows remote attackers to execute any Headless API via the `endpoint` parameter. To fix this issue, users should upgrade to Liferay Portal 7.4.3.108, Liferay DXP 2024.Q1.1, Liferay DXP 2023.Q4.1, Liferay DXP 2023.Q3.5, or Liferay DXP 7.3 U36. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62258.
Read more CMSIn Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 service pack 3 through update 36 a medium severity vulnerability CVE-2025-62263 was detected. This vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account Role’s “Title” text field and an Organization’s “Name” text field, potentially leading to stored cross-site scripting (XSS) on multiple pages. To fix this issue, users should upgrade to Liferay Portal 7.4.3.104, Liferay DXP 2024.Q1.1, Liferay DXP 2023.Q4.0, or Liferay DXP 2023.Q3.5. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62263.
Read more CMSIn Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 service pack 3 through update 36 a medium severity vulnerability CVE-2025-62263 was detected. This vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account Role’s “Title” text field and an Organization’s “Name” text field, potentially leading to stored cross-site scripting (XSS) on multiple pages. To fix this issue, users should upgrade to Liferay Portal 7.4.3.104, Liferay DXP 2024.Q1.1, Liferay DXP 2023.Q4.0, or Liferay DXP 2023.Q3.5. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62263.
Read more CMS