CVE-2025-62260
- Published: 1761603341
- Last modified: 1761603341
CVE-2025-62260 — Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number of objects returned from Headless API requests, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by…
Related CVE by CWE
No related CWE found.
Top CVE for Vendor
No vendor taxonomy on this entry.
Recently Exploited Similar Vulnerabilities
No recent KEV-listed items for this vendor/product.
Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number of objects returned from Headless API requests, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing a request that returns a large number of objects.
🧠 Explainer: What this vulnerability means
Summary: the product from the vendor is impacted (CWE: unspecified).
Impact: Attackers could gain unauthorized access, execute code, or disrupt services.
Mitigation: Apply the latest vendor patch or update to a fixed version; disable vulnerable modules where possible.
No vendor/product data yet.
No explicit mitigation/advisory links found in references.