[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Oct 11 10:00:45 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a44962e3 by Salvatore Bonaccorso at 2025-10-11T11:00:23+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -81,11 +81,11 @@ CVE-2025-11586 (A vulnerability was determined in Tenda AC7 15.03.06.44. This af
 CVE-2025-11585 (A vulnerability was found in code-projects Project Monitoring System 1 ...)
 	NOT-FOR-US: code-projects
 CVE-2025-11584 (A vulnerability has been found in code-projects Online Job Search Engi ...)
-	TODO: check
+	NOT-FOR-US: code-projects Online Job Search Engine
 CVE-2025-11583 (A flaw has been found in code-projects Online Job Search Engine 1.0. I ...)
-	TODO: check
+	NOT-FOR-US: code-projects Online Job Search Engine
 CVE-2025-11582 (A vulnerability was detected in code-projects Online Job Search Engine ...)
-	TODO: check
+	NOT-FOR-US: code-projects Online Job Search Engine
 CVE-2025-11533 (The WP Freeio plugin for WordPress is vulnerable to Privilege Escalati ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-11380 (The Everest Backup \u2013 WordPress Cloud Backup, Migration, Restore & ...)
@@ -168,7 +168,7 @@ CVE-2025-61319 (ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scriptin
 CVE-2025-61152 (python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded ...)
 	TODO: check
 CVE-2025-60880 (An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6  ...)
-	TODO: check
+	NOT-FOR-US: Bagisto
 CVE-2025-60869 (Publii CMS v0.46.5 (build 17089) allows persistent Cross-Site Scriptin ...)
 	NOT-FOR-US: Publii CMS
 CVE-2025-60868 (The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip  ...)
@@ -210,7 +210,7 @@ CVE-2025-52625 (A vulnerability  Cacheable SSL Page Found vulnerability has been
 CVE-2025-52624 (A vulnerabilityBypass of the script allowlist configuration in HCL AIO ...)
 	NOT-FOR-US: HCL
 CVE-2025-48043 (Incorrect Authorization vulnerability in ash-project ash allows Authen ...)
-	TODO: check
+	NOT-FOR-US: ash-project ash
 CVE-2025-41089 (Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Sign ...)
 	NOT-FOR-US: Xibo CMS
 CVE-2025-41088 (Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, d ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a44962e33bcde724bd00bc3ecfac2929415bb798

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a44962e33bcde724bd00bc3ecfac2929415bb798
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251011/9b6c785d/attachment.htm>


More information about the debian-security-tracker-commits mailing list