AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-3526

HIGH · CVSS 7.5 EPSS 0.48%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-06-16 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It may be remotely exploitable. It may lead to a denial-of-service condition.

CVE
CVE-2025-3526
Severity
HIGH
CVSS
7.5
EPSS
0.48%

Original NVD Description

SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does not restrict the saving of request parameters in the HTTP session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP requests.

Related CVEs

Other vulnerabilities affecting the same vendor(s)