CVE-2025-62275 Blogs images are visible to unauthenticated users
CVE-2025-62276 Private Cache-Control header for DM and AM file download
CVE-2025-62261 Cleartext storage of password reset tickets
CVE-2025-62262 Email address in LDAP import logs
CVE-2025-62255 Self-XSS with attachment file names in Knowledge Base
CVE-2025-62254 Very large ComboServlet responses
CVE-2025-43816 Memory leak when consuming the headless API for StructuredContents
CVE-2025-43809 CSRF vulnerability with server (license) registration
CVE-2025-62250 Portal fails to verify messages from the cluster network is trusted
CVE-2025-43799 Change password requirement bypass
CVE-2023-37940 XSS with "Service Class" in Service Access Policy
CVE-2025-62253 Open redirect in page administration
CVE-2025-3526 DoS vulnerability with SessionClicks
CVE-2025-3594 DoS vulnerability with SessionClicks
CVE-2025-43748 Insufficient CSRF protection for omni-administrator actions
CVE-2024-8980 Mitigate against simple XSS attacks against script console
CVE-2025-62259 Email address verification bypass
CVE-2023-42628 XSS with child wiki pages
CVE-2023-33949 Users do not have to verify their email address by default
Powered by Liferay™
Legal
Compliance
Privacy Policy
本网站使用 Cookie
我们使用 Cookie 来提供个性化内容、分析趋势、管理网站、跟踪用户在网站上的活动,以及收集有关我们整个用户群的受众信息。接受所有 Cookie 可在我们的网站上获得最佳体验或管理您的偏好设置。 访问我们的《隐私政策》