Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a44962e3 by Salvatore Bonaccorso at 2025-10-11T11:00:23+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -81,11 +81,11 @@ CVE-2025-11586 (A vulnerability was determined in Tenda AC7 
15.03.06.44. This af
 CVE-2025-11585 (A vulnerability was found in code-projects Project Monitoring 
System 1 ...)
        NOT-FOR-US: code-projects
 CVE-2025-11584 (A vulnerability has been found in code-projects Online Job 
Search Engi ...)
-       TODO: check
+       NOT-FOR-US: code-projects Online Job Search Engine
 CVE-2025-11583 (A flaw has been found in code-projects Online Job Search 
Engine 1.0. I ...)
-       TODO: check
+       NOT-FOR-US: code-projects Online Job Search Engine
 CVE-2025-11582 (A vulnerability was detected in code-projects Online Job 
Search Engine ...)
-       TODO: check
+       NOT-FOR-US: code-projects Online Job Search Engine
 CVE-2025-11533 (The WP Freeio plugin for WordPress is vulnerable to Privilege 
Escalati ...)
        NOT-FOR-US: WordPress plugin
 CVE-2025-11380 (The Everest Backup \u2013 WordPress Cloud Backup, Migration, 
Restore & ...)
@@ -168,7 +168,7 @@ CVE-2025-61319 (ReNgine thru 2.2.0 is vulnerable to a 
Stored Cross-Site Scriptin
 CVE-2025-61152 (python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be 
decoded ...)
        TODO: check
 CVE-2025-60880 (An authenticated stored XSS vulnerability exists in the 
Bagisto 2.3.6  ...)
-       TODO: check
+       NOT-FOR-US: Bagisto
 CVE-2025-60869 (Publii CMS v0.46.5 (build 17089) allows persistent Cross-Site 
Scriptin ...)
        NOT-FOR-US: Publii CMS
 CVE-2025-60868 (The Alt Redirect 1.6.3 addon for Statamic fails to 
consistently strip  ...)
@@ -210,7 +210,7 @@ CVE-2025-52625 (A vulnerability  Cacheable SSL Page Found 
vulnerability has been
 CVE-2025-52624 (A vulnerabilityBypass of the script allowlist configuration in 
HCL AIO ...)
        NOT-FOR-US: HCL
 CVE-2025-48043 (Incorrect Authorization vulnerability in ash-project ash 
allows Authen ...)
-       TODO: check
+       NOT-FOR-US: ash-project ash
 CVE-2025-41089 (Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from 
Xibo Sign ...)
        NOT-FOR-US: Xibo CMS
 CVE-2025-41088 (Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS 
v4.1.2, d ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a44962e33bcde724bd00bc3ecfac2929415bb798

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a44962e33bcde724bd00bc3ecfac2929415bb798
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to