[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Jan 17 10:09:28 GMT 2025



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0e479413 by Moritz Muehlenhoff at 2025-01-17T11:09:00+01:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,241 +1,241 @@
 CVE-2025-23965 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23963 (Missing Authorization vulnerability in Sven Hofmann & Michael Schoenro ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23962 (Missing Authorization vulnerability in Goldstar Goldstar allows Exploi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23961 (Missing Authorization vulnerability in WP Tasker WordPress Graphs & Ch ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23957 (Missing Authorization vulnerability in Sur.ly Sur.ly allows Exploiting ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23955 (Missing Authorization vulnerability in xola.com Xola allows Exploiting ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23954 (Missing Authorization vulnerability in AWcode & KingfisherFox Salvador ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23951 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23950 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23947 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23946 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23943 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23941 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23940 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23939 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23936 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23935 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23934 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23933 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23930 (Missing Authorization vulnerability in iTechArt-Group PayPal Marketing ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23929 (Missing Authorization vulnerability in wishfulthemes Email Capture & L ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23928 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23927 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23926 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23925 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23924 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23922 (Cross-Site Request Forgery (CSRF) vulnerability in Harsh iSpring Embed ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23919 (Improper Neutralization of Script-Related HTML Tags in a Web Page (Bas ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23917 (Missing Authorization vulnerability in Chandrika Guntur, Morgan Kay Ch ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23916 (Missing Authorization vulnerability in Nuanced Media WP Meetup allows  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23915 (Improper Control of Filename for Include/Require Statement in PHP Prog ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23913 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23912 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23911 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23909 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23908 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23907 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23902 (Cross-Site Request Forgery (CSRF) vulnerability in Taras Dashkevych Er ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23901 (Cross-Site Request Forgery (CSRF) vulnerability in Oliver Schaal Grava ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23900 (Cross-Site Request Forgery (CSRF) vulnerability in Genkisan Genki Anno ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23899 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23898 (Cross-Site Request Forgery (CSRF) vulnerability in Ivo Brett \u2013 Ap ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23897 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23896 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23895 (Cross-Site Request Forgery (CSRF) vulnerability in Dan Cameron Add RSS ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23893 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23892 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23891 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23890 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23887 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23886 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23884 (Cross-Site Request Forgery (CSRF) vulnerability in Chris Roberts Annie ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23880 (Cross-Site Request Forgery (CSRF) vulnerability in anmari amr personal ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23878 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23877 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23876 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23875 (Cross-Site Request Forgery (CSRF) vulnerability in Tim Ridgway Better  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23873 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23872 (Cross-Site Request Forgery (CSRF) vulnerability in PayForm PayForm all ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23871 (Cross-Site Request Forgery (CSRF) vulnerability in Bas Matthee LSD Goo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23870 (Cross-Site Request Forgery (CSRF) vulnerability in Robert Nicholson Co ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23869 (Cross-Site Request Forgery (CSRF) vulnerability in Shibu Lijack a.k.a  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23868 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23865 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23864 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23863 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23862 (Missing Authorization vulnerability in SzMake Contact Form 7 Anti Spam ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23861 (Cross-Site Request Forgery (CSRF) vulnerability in Katz Web Services,  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23860 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23859 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23856 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23854 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23848 (Cross-Site Request Forgery (CSRF) vulnerability in Daniel Powney Hotsp ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23844 (Cross-Site Request Forgery (CSRF) vulnerability in wellwisher Custom W ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23842 (Cross-Site Request Forgery (CSRF) vulnerability in Nilesh Shiragave Wo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23841 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23833 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23832 (Cross-Site Request Forgery (CSRF) vulnerability in Matt Gibbs Admin Cl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23831 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23830 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23828 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23827 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23826 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23825 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23824 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23823 (Cross-Site Request Forgery (CSRF) vulnerability in jprintf CNZZ&51LA f ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23822 (Cross-Site Request Forgery (CSRF) vulnerability in Cornea Alexandru Ca ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23821 (Cross-Site Request Forgery (CSRF) vulnerability in Aleapp WP Cookies A ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23820 (Cross-Site Request Forgery (CSRF) vulnerability in Laxman Thapa Conten ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23818 (Cross-Site Request Forgery (CSRF) vulnerability in Peggy Kuo More Link ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23817 (Cross-Site Request Forgery (CSRF) vulnerability in Mahadir Ahmad MHR-C ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23816 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23815 (Cross-Site Request Forgery (CSRF) vulnerability in linickx root Cookie ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23810 (Cross-Site Request Forgery (CSRF) vulnerability in Igor Sazonov Len Sl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23808 (Cross-Site Request Forgery (CSRF) vulnerability in Matt van Andel Cust ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23807 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23805 (Cross-Site Request Forgery (CSRF) vulnerability in SEOReseller Team SE ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23804 (Cross-Site Request Forgery (CSRF) vulnerability in Shiv Prakash Tiwari ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23802 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23801 (Cross-Site Request Forgery (CSRF) vulnerability in Benjamin Guy Style  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23800 (Cross-Site Request Forgery (CSRF) vulnerability in David Hamilton Oran ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23797 (Cross-Site Request Forgery (CSRF) vulnerability in Mike Selander WP Op ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23796 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23795 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23794 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23793 (Cross-Site Request Forgery (CSRF) vulnerability in Turcu Ciprian Auto  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23791 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23785 (Missing Authorization vulnerability in August Infotech AI Responsive G ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23780 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23779 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23778 (Missing Authorization vulnerability in Pravin Durugkar User Sync Activ ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23777 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23776 (Missing Authorization vulnerability in Thorn Technologies LLC Cache Sn ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23775 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23772 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23765 (Cross-Site Request Forgery (CSRF) vulnerability in W3speedster W3SPEED ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23764 (Missing Authorization vulnerability in Ujjaval Jani Copy Move Posts al ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23761 (Missing Authorization vulnerability in Alex Volkov Woo Tuner allows Ex ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23760 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-23201 (librenms is a community-based GPL-licensed network monitoring system.  ...)
 	TODO: check
 CVE-2025-23200 (librenms is a community-based GPL-licensed network monitoring system.  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0e479413f81a2c96c247d7865d64839720bb3816

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0e479413f81a2c96c247d7865d64839720bb3816
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250117/f85ac0b8/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list