Junglewise Threat Intelligence

CVE-2025-62245: Liferay Portal is vulnerable to CSRF through publication comments

CVE-2025-62245 · Severity: medium · CVSS 4 · Published 2025-10-10

Technologies: com.liferay:com.liferay.change.tracking.web (Maven). Vendors: Maven.

Executive brief

Liferay Portal is vulnerable to CSRF through publication comments

Affected products

  • Maven com.liferay:com.liferay.change.tracking.web

Related threats