[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 20 09:13:00 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
aaf3cfa5 by security tracker role at 2025-09-20T08:12:53+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,11 +1,11 @@
 CVE-2025-9949 (The Internal Links Manager plugin for WordPress is vulnerable to Cross ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-9887 (The Custom Login And Signup Widget plugin for WordPress is vulnerable  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-9883 (The Browser Sniff plugin for WordPress is vulnerable to Cross-Site Req ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-9882 (The osTicket WP Bridge plugin for WordPress is vulnerable to Cross-Sit ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-59727
 	REJECTED
 CVE-2025-59726
@@ -25,19 +25,19 @@ CVE-2025-59720
 CVE-2025-59689 (Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection  ...)
 	TODO: check
 CVE-2025-43808 (The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and  ...)
-	TODO: check
+	NOT-FOR-US: Liferay
 CVE-2025-10658 (The SupportCandy \u2013 Helpdesk & Customer Support Ticket System plug ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-10652 (The Robcore Netatmo plugin for WordPress is vulnerable to SQL Injectio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-10489 (The SureForms \u2013 Drag and Drop Contact Form Builder \u2013 Multi-s ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-10305 (The Secure Passkeys plugin for WordPress is vulnerable to unauthorized ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-10181 (The Draft List plugin for WordPress is vulnerable to Stored Cross-Site ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-10002 (The ClickWhale \u2013 Link Manager, Link Shortener and Click Tracker f ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-9969 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
 	NOT-FOR-US: Vizly Web Design Real Estate
 CVE-2025-9906 (The Keras Model.load_modelmethod can be exploited to achieve arbitrary ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/aaf3cfa5249e0bf4a8d6c7e20b04e6045a869e2e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/aaf3cfa5249e0bf4a8d6c7e20b04e6045a869e2e
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250920/68e13b19/attachment.htm>


More information about the debian-security-tracker-commits mailing list