[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 20 09:12:04 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
02dec156 by security tracker role at 2025-09-20T08:11:56+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,43 @@
+CVE-2025-9949 (The Internal Links Manager plugin for WordPress is vulnerable to Cross ...)
+	TODO: check
+CVE-2025-9887 (The Custom Login And Signup Widget plugin for WordPress is vulnerable  ...)
+	TODO: check
+CVE-2025-9883 (The Browser Sniff plugin for WordPress is vulnerable to Cross-Site Req ...)
+	TODO: check
+CVE-2025-9882 (The osTicket WP Bridge plugin for WordPress is vulnerable to Cross-Sit ...)
+	TODO: check
+CVE-2025-59727
+	REJECTED
+CVE-2025-59726
+	REJECTED
+CVE-2025-59725
+	REJECTED
+CVE-2025-59724
+	REJECTED
+CVE-2025-59723
+	REJECTED
+CVE-2025-59722
+	REJECTED
+CVE-2025-59721
+	REJECTED
+CVE-2025-59720
+	REJECTED
+CVE-2025-59689 (Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection  ...)
+	TODO: check
+CVE-2025-43808 (The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and  ...)
+	TODO: check
+CVE-2025-10658 (The SupportCandy \u2013 Helpdesk & Customer Support Ticket System plug ...)
+	TODO: check
+CVE-2025-10652 (The Robcore Netatmo plugin for WordPress is vulnerable to SQL Injectio ...)
+	TODO: check
+CVE-2025-10489 (The SureForms \u2013 Drag and Drop Contact Form Builder \u2013 Multi-s ...)
+	TODO: check
+CVE-2025-10305 (The Secure Passkeys plugin for WordPress is vulnerable to unauthorized ...)
+	TODO: check
+CVE-2025-10181 (The Draft List plugin for WordPress is vulnerable to Stored Cross-Site ...)
+	TODO: check
+CVE-2025-10002 (The ClickWhale \u2013 Link Manager, Link Shortener and Click Tracker f ...)
+	TODO: check
 CVE-2025-9969 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
 	NOT-FOR-US: Vizly Web Design Real Estate
 CVE-2025-9906 (The Keras Model.load_modelmethod can be exploited to achieve arbitrary ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/02dec1565a546e699bbb032d8ac2fa553f0059d9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/02dec1565a546e699bbb032d8ac2fa553f0059d9
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250920/66e40a46/attachment.htm>


More information about the debian-security-tracker-commits mailing list