<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>Liferay Security Advisories</title>
  <link rel="alternate" href="https://liferay.dev/zh/portal/security/known-vulnerabilities" />
  <link rel="self" href="https://liferay.dev/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/rss" />
  <subtitle>Liferay Security Advisories</subtitle>
  <id>https://liferay.dev/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/rss</id>
  <updated>2026-04-17T17:29:42Z</updated>
  <dc:date>2026-04-17T17:29:42Z</dc:date>
  <entry>
    <title>CVE-2025-62267 Stored XSS in web content template's select structure page</title>
    <link rel="alternate" href="https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62267?p_r_p_assetEntryId=124566485&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62267&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124566485%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse" />
    <author>
      <name>Alex Candido</name>
    </author>
    <id>https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62267?p_r_p_assetEntryId=124566485&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62267&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124566485%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse</id>
    <updated>2025-10-31T18:17:30Z</updated>
    <published>2025-10-31T18:17:00Z</published>
    <summary type="html" />
    <dc:creator>Alex Candido</dc:creator>
    <dc:date>2025-10-31T18:17:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2025-62264 Reflected XSS with `selectedLanguageId` in Languauge Override</title>
    <link rel="alternate" href="https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62264?p_r_p_assetEntryId=124566240&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62264&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124566240%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse" />
    <author>
      <name>Alex Candido</name>
    </author>
    <id>https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62264?p_r_p_assetEntryId=124566240&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62264&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124566240%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse</id>
    <updated>2025-10-31T17:33:57Z</updated>
    <published>2025-10-31T17:33:00Z</published>
    <summary type="html" />
    <dc:creator>Alex Candido</dc:creator>
    <dc:date>2025-10-31T17:33:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2025-62275 Blogs images are visible to unauthenticated users</title>
    <link rel="alternate" href="https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62275-1?p_r_p_assetEntryId=124569821&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62275-1&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124569821%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse" />
    <author>
      <name>Alex Candido</name>
    </author>
    <id>https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62275-1?p_r_p_assetEntryId=124569821&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62275-1&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124569821%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse</id>
    <updated>2025-11-01T02:47:01Z</updated>
    <published>2025-10-31T14:44:00Z</published>
    <summary type="html" />
    <dc:creator>Alex Candido</dc:creator>
    <dc:date>2025-10-31T14:44:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2025-62276 Private Cache-Control header for DM and AM file download</title>
    <link rel="alternate" href="https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62276?p_r_p_assetEntryId=124568859&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62276&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124568859%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse" />
    <author>
      <name>Alex Candido</name>
    </author>
    <id>https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62276?p_r_p_assetEntryId=124568859&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62276&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124568859%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse</id>
    <updated>2025-10-31T23:38:18Z</updated>
    <published>2025-10-31T11:38:00Z</published>
    <summary type="html" />
    <dc:creator>Alex Candido</dc:creator>
    <dc:date>2025-10-31T11:38:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2025-62266 Insecure default for the property `redirect.url.security.mode`</title>
    <link rel="alternate" href="https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62266?p_r_p_assetEntryId=124555987&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62266&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124555987%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse" />
    <author>
      <name>Alex Candido</name>
    </author>
    <id>https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62266?p_r_p_assetEntryId=124555987&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62266&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124555987%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse</id>
    <updated>2025-10-30T17:38:24Z</updated>
    <published>2025-10-30T17:38:00Z</published>
    <summary type="html" />
    <dc:creator>Alex Candido</dc:creator>
    <dc:date>2025-10-30T17:38:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2025-62257 Lockout mechanism doesn't prevent password enumeration brute force attacks</title>
    <link rel="alternate" href="https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62257?p_r_p_assetEntryId=124547322&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62257&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124547322%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse" />
    <author>
      <name>Alex Candido</name>
    </author>
    <id>https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62257?p_r_p_assetEntryId=124547322&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62257&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124547322%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse</id>
    <updated>2025-10-29T23:25:31Z</updated>
    <published>2025-10-29T11:25:00Z</published>
    <summary type="html" />
    <dc:creator>Alex Candido</dc:creator>
    <dc:date>2025-10-29T11:25:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2025-62258 CSRF vulnerability with headless API</title>
    <link rel="alternate" href="https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62258?p_r_p_assetEntryId=124526129&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62258&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124526129%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse" />
    <author>
      <name>Alex Candido</name>
    </author>
    <id>https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62258?p_r_p_assetEntryId=124526129&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62258&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124526129%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse</id>
    <updated>2025-10-27T22:58:02Z</updated>
    <published>2025-10-27T10:44:00Z</published>
    <summary type="html" />
    <dc:creator>Alex Candido</dc:creator>
    <dc:date>2025-10-27T10:44:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2025-62260 Headless API does not limit page size</title>
    <link rel="alternate" href="https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62260?p_r_p_assetEntryId=124525549&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62260&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124525549%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse" />
    <author>
      <name>Alex Candido</name>
    </author>
    <id>https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62260?p_r_p_assetEntryId=124525549&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62260&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124525549%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse</id>
    <updated>2025-10-27T21:40:42Z</updated>
    <published>2025-10-27T09:40:00Z</published>
    <summary type="html" />
    <dc:creator>Alex Candido</dc:creator>
    <dc:date>2025-10-27T09:40:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2025-62261 Cleartext storage of password reset tickets</title>
    <link rel="alternate" href="https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62261?p_r_p_assetEntryId=124525242&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62261&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124525242%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse" />
    <author>
      <name>Alex Candido</name>
    </author>
    <id>https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62261?p_r_p_assetEntryId=124525242&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62261&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124525242%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse</id>
    <updated>2025-10-27T21:09:00Z</updated>
    <published>2025-10-27T09:09:00Z</published>
    <summary type="html" />
    <dc:creator>Alex Candido</dc:creator>
    <dc:date>2025-10-27T09:09:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2025-62262 Email address in LDAP import logs</title>
    <link rel="alternate" href="https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62262?p_r_p_assetEntryId=124524929&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62262&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124524929%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse" />
    <author>
      <name>Alex Candido</name>
    </author>
    <id>https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62262?p_r_p_assetEntryId=124524929&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62262&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124524929%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse</id>
    <updated>2025-10-27T20:35:05Z</updated>
    <published>2025-10-27T08:35:00Z</published>
    <summary type="html" />
    <dc:creator>Alex Candido</dc:creator>
    <dc:date>2025-10-27T08:35:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2025-62263 Stored XSS with account role and organization name</title>
    <link rel="alternate" href="https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62263?p_r_p_assetEntryId=124524310&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62263&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124524310%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse" />
    <author>
      <name>Alex Candido</name>
    </author>
    <id>https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62263?p_r_p_assetEntryId=124524310&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62263&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124524310%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse</id>
    <updated>2025-10-27T19:31:43Z</updated>
    <published>2025-10-27T07:31:00Z</published>
    <summary type="html" />
    <dc:creator>Alex Candido</dc:creator>
    <dc:date>2025-10-27T07:31:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2025-62255 Self-XSS with attachment file names in Knowledge Base</title>
    <link rel="alternate" href="https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62255?p_r_p_assetEntryId=124472916&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62255&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124472916%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse" />
    <author>
      <name>Alex Candido</name>
    </author>
    <id>https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62255?p_r_p_assetEntryId=124472916&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62255&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124472916%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse</id>
    <updated>2025-10-23T22:09:57Z</updated>
    <published>2025-10-23T18:43:00Z</published>
    <summary type="html" />
    <dc:creator>Alex Candido</dc:creator>
    <dc:date>2025-10-23T18:43:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2025-62256 OpenAPI authentication bypass</title>
    <link rel="alternate" href="https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62256?p_r_p_assetEntryId=124470237&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62256&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124470237%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse" />
    <author>
      <name>Alex Candido</name>
    </author>
    <id>https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62256?p_r_p_assetEntryId=124470237&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62256&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124470237%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse</id>
    <updated>2025-10-23T22:22:56Z</updated>
    <published>2025-10-23T13:32:00Z</published>
    <summary type="html" />
    <dc:creator>Alex Candido</dc:creator>
    <dc:date>2025-10-23T13:32:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2025-62254 Very large ComboServlet responses</title>
    <link rel="alternate" href="https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62254?p_r_p_assetEntryId=124474718&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62254&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124474718%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse" />
    <author>
      <name>Alex Candido</name>
    </author>
    <id>https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-62254?p_r_p_assetEntryId=124474718&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-62254&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124474718%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse</id>
    <updated>2025-10-23T22:22:44Z</updated>
    <published>2025-10-23T10:11:00Z</published>
    <summary type="html" />
    <dc:creator>Alex Candido</dc:creator>
    <dc:date>2025-10-23T10:11:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2025-43825 Sensible user data available to freemarker template</title>
    <link rel="alternate" href="https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-43825?p_r_p_assetEntryId=124203962&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-43825&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124203962%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse" />
    <author>
      <name>Alex Candido</name>
    </author>
    <id>https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-43825?p_r_p_assetEntryId=124203962&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-43825&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124203962%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse</id>
    <updated>2025-10-03T21:12:50Z</updated>
    <published>2025-10-03T09:08:00Z</published>
    <summary type="html" />
    <dc:creator>Alex Candido</dc:creator>
    <dc:date>2025-10-03T09:08:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2025-43816 Memory leak when consuming the headless API for StructuredContents</title>
    <link rel="alternate" href="https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-43816?p_r_p_assetEntryId=124064120&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-43816&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124064120%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse" />
    <author>
      <name>Alex Candido</name>
    </author>
    <id>https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-43816?p_r_p_assetEntryId=124064120&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-43816&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124064120%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse</id>
    <updated>2025-09-25T20:04:12Z</updated>
    <published>2025-09-25T08:04:00Z</published>
    <summary type="html" />
    <dc:creator>Alex Candido</dc:creator>
    <dc:date>2025-09-25T08:04:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2025-43819 User session is not killed by SLO API</title>
    <link rel="alternate" href="https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-43819?p_r_p_assetEntryId=124045658&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-43819&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124045658%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse" />
    <author>
      <name>Alex Candido</name>
    </author>
    <id>https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-43819?p_r_p_assetEntryId=124045658&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-43819&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124045658%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse</id>
    <updated>2025-09-24T01:32:16Z</updated>
    <published>2025-09-23T13:32:00Z</published>
    <summary type="html" />
    <dc:creator>Alex Candido</dc:creator>
    <dc:date>2025-09-23T13:32:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2025-43814 Password reminder answers recorded in audit events</title>
    <link rel="alternate" href="https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-43814?p_r_p_assetEntryId=124023142&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-43814&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124023142%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse" />
    <author>
      <name>Alex Candido</name>
    </author>
    <id>https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-43814?p_r_p_assetEntryId=124023142&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-43814&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124023142%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse</id>
    <updated>2025-09-22T22:57:13Z</updated>
    <published>2025-09-22T10:57:00Z</published>
    <summary type="html" />
    <dc:creator>Alex Candido</dc:creator>
    <dc:date>2025-09-22T10:57:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2025-43806 Unauthorized access to exported data from batch engine</title>
    <link rel="alternate" href="https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-43806?p_r_p_assetEntryId=124020233&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-43806&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124020233%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse" />
    <author>
      <name>Alex Candido</name>
    </author>
    <id>https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-43806?p_r_p_assetEntryId=124020233&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-43806&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D124020233%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse</id>
    <updated>2025-09-22T21:36:22Z</updated>
    <published>2025-09-22T09:36:00Z</published>
    <summary type="html" />
    <dc:creator>Alex Candido</dc:creator>
    <dc:date>2025-09-22T09:36:00Z</dc:date>
  </entry>
  <entry>
    <title>CVE-2025-43809 CSRF vulnerability with server (license) registration</title>
    <link rel="alternate" href="https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-43809?p_r_p_assetEntryId=123953324&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-43809&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D123953324%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse" />
    <author>
      <name>Alex Candido</name>
    </author>
    <id>https://liferay.dev:443/zh/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2025-43809?p_r_p_assetEntryId=123953324&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_type=content&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_urlTitle=cve-2025-43809&amp;_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fzh%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D123953324%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse</id>
    <updated>2025-09-19T19:23:41Z</updated>
    <published>2025-09-19T07:23:00Z</published>
    <summary type="html" />
    <dc:creator>Alex Candido</dc:creator>
    <dc:date>2025-09-19T07:23:00Z</dc:date>
  </entry>
</feed>
