AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-3639

UNKNOWN · CVSS N/A EPSS 0.50%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-08-18 · Last synced 2026-08-04

CyberRota Analysis

This vulnerability has an unknown severity rating. Exploitation may require the attacker to be authenticated.

CVE
CVE-2025-3639
Severity
UNKNOWN
CVSS
N/A
EPSS
0.50%

Original NVD Description

Liferay Portal 7.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 and 7.3 GA through update 36 allows unauthenticated users with valid credentials to bypass the login process by changing the POST method to GET, once the site has MFA enabled.