6.1
CVE-2025-55054 -
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
6.5
CVE-2025-55053 -
CWE-328: Use of Weak Hash
6.9
CVE-2025-43786 -
Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 and 7.4 GA through update 92 allow attackers to determine existent ERC in the application by exploit theβ¦
4.3
CVE-2025-55052 -
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
10
CVE-2025-55051 -
CWE-1392: Use of Default Credentials
9.8
CVE-2025-55050 -
CWE-1242: Inclusion of Undocumented Features
10
CVE-2025-55730 - XWiki Remote Macros vulnerable to remote code execution using the confluence paste code macro
XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the title in the confluence paste code macro allows remote code execution for any user who can edit any page. The clasβ¦
9.1
CVE-2025-55049 -
Use of Default Cryptographic Key (CWE-1394)
10
CVE-2025-55729 - XWiki Remote Macros vulnerable to remote code execution using the ConfluenceLayoutSection macro
XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the ac:type in the ConfluenceLayoutSection macro allows remote code execution for any user who can edit any page The cβ¦
5.3
CVE-2025-43781 -
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.110 through 7.4.3.128, and Liferay DXP 2024.Q3.1 through 2024.Q3.8, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.12 allows remote attackers to inject arbitrary web script or HTML via the URL in search bar portlβ¦