In Liferay Portal versions 7.4.1 through 7.4.3.112 and Liferay DXP versions 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 a medium severity vulnerability CVE-2025-62243 was detected. Insecure direct object reference (IDOR) flaws in the Publications module allow remote authenticated users to view publication comments via the _com_liferay_change_tracking_web_portlet_PublicationsPortlet_value parameter and edit them through crafted URLs due to missing permission checks. To address this issue, users should upgrade to Liferay Portal 7.4.3.113, Liferay DXP 2024.Q2.0, 2024.Q1.1, 2023.Q4.6, or 2023.Q3.9. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62243.
Read more CMSIn Liferay Portal versions 7.4.3.4 through 7.4.3.111 and Liferay DXP versions 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 a medium severity vulnerability CVE-2025-62242 was detected. An insecure direct object reference (IDOR) flaw in the Account module allows authenticated users from one account to access address information belonging to a different account via the _com_liferay_account_admin_web_internal_portlet_AccountEntriesAdminPortlet_addressId parameter. To address this issue, users should upgrade to Liferay Portal 7.4.3.113, Liferay DXP 2024.Q1.1, or 2023.Q4.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62242.
Read more CMSIn SonarQube versions prior to 25.6, 2025.3 Commercial, and 2025.1.3 LTA a medium severity vulnerability CVE-2025-62292 was detected. Authenticated low-privileged users can query the /api/v2/users-management/users endpoint and access user fields intended for administrators only, including the email addresses of other accounts. To address this issue, users should upgrade SonarQube to versions 25.6, 2025.3 Commercial, 2025.1.3 LTA or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62292.
Read more Developer ToolsIn Mattermost Desktop App versions up to 5.13.0 a medium severity vulnerability CVE-2025-58084 was detected. The application fails to validate URLs external to the configured Mattermost servers, allowing an attacker on a configured server to crash the user’s application by sending a malformed URL. To address this issue, users should upgrade the Mattermost Desktop App to version 5.13.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-58084.
Read more CommunicationIn Liferay Portal versions 7.4.0 through 7.4.3.111 and older unsupported versions, and Liferay DXP versions 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions a medium severity vulnerability CVE-2025-62252 was detected. An insecure direct object reference (IDOR) flaw allows remote authenticated users in one virtual instance to assign an organization to a user in a different virtual instance via the _com_liferay_users_admin_web_portlet_UsersAdminPortlet_addUserIds parameter. To address this issue, users should upgrade to Liferay Portal 7.4.3.112, Liferay DXP 2024.Q1.1, or 2023.Q4.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62252.
Read more CMSIn Liferay Portal versions 7.3.0 through 7.4.3.119 and Liferay DXP versions 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA through update 92, and 7.3 GA through update 36 a medium severity vulnerability CVE-2025-62251 was detected. The Menu Display Widget can expose content to users who do not have permission to view it, potentially disclosing sensitive information. To address this issue, users should upgrade to Liferay Portal 7.4.3.120, Liferay DXP 2024.Q2.0, 2024.Q1.1, 2023.Q4.6, or 2023.Q3.9. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62251.
Read more CMSIn Liferay Portal versions 7.3.0 through 7.4.3.119 and Liferay DXP versions 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA through update 92, and 7.3 GA through update 36 a medium severity vulnerability CVE-2025-62251 was detected. The Menu Display Widget can expose content to users who do not have permission to view it, potentially disclosing sensitive information. To address this issue, users should upgrade to Liferay Portal 7.4.3.120, Liferay DXP 2024.Q2.0, 2024.Q1.1, 2023.Q4.6, or 2023.Q3.9. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62251.
Read more CMSIn Kibana versions prior to 8.18.8, 8.19.5, 9.0.8, and 9.1.5 a high severity vulnerability CVE-2025-25018 was detected. Improper neutralization of input during web page generation allows an attacker to inject and store malicious scripts, leading to stored Cross-Site Scripting. To address this issue, users should upgrade Kibana to versions 8.18.8, 8.19.5, 9.0.8, or 9.1.5. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-25018.
Read more Data AnalyticsIn Liferay Portal versions 7.4.1 through 7.4.3.112 and Liferay DXP versions 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 a medium severity vulnerability CVE-2025-62245 was detected. A cross-site request forgery (CSRF) flaw allows remote attackers to add or edit publication comments without proper authorization. To address this issue, users should upgrade to Liferay Portal 7.4.3.113, Liferay DXP 2024.Q1.1, or 2023.Q4.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62245.
Read more CMS