Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: wordpressPackages.plugins.webp-express

Found 3 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-93485
7.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
created 3 days, 19 hours ago Activity log
  • Created suggestion
WordPress core <= 7.1 - Unauth. Cross Site Scripting (XSS) vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.12; 6.0 through 6.0.14; 5.9 through 5.9.16; 5.8 through 5.8.15; 5.7 through 5.7.17; 5.6 through 5.6.19; 5.5 through 5.5.20; 5.4 through 5.4.21; 5.3 through 5.3.23; 5.2 through 5.2.26; 5.1 through 5.1.24; 5.0 through 5.0.27; 4.9 through 4.9.31; 4.8 through 4.8.30; and 4.7 through 4.7.35. The Unauthenticated Stored XSS vulnerability in the WordPress core can be reproduced on a default WordPress installation. Comment moderation is disabled by default, and the requirement for commenters to have a previously approved comment can be bypassed.

Affected products

WordPress
  • =<4.8.30
  • =<5.8.15
  • =<4.9.31
  • =<6.0.14
  • =<6.3.10
  • =<6.7.7
  • =<5.7.17
  • =<5.4.21
  • =<6.9.7
  • =<5.6.19
  • =<5.5.20
  • =<5.3.23
  • =<5.0.27
  • =<5.9.16
  • =<6.1.12
  • =<5.1.24
  • =<6.4.10
  • =<7.0.4
  • =<6.6.7
  • =<6.5.10
  • =<6.8.8
  • =<5.2.26
  • =<6.2.11
  • =<4.7.35
  • <7.1.1

Matching in nixpkgs

pkgs.wordpress

Open source software you can use to create a beautiful website, blog, or app

  • nixos-unstable -
    • nixos-unstable-small 7.1.1
  • nixos-26.05 -
    • nixos-26.05-small 6.9.8

pkgs.wordpress_6_9

Open source software you can use to create a beautiful website, blog, or app

  • nixos-unstable -
    • nixos-unstable-small 6.9.8
  • nixos-26.05 -
    • nixos-26.05-small 6.9.8

pkgs.wordpress_7_0

Open source software you can use to create a beautiful website, blog, or app

  • nixos-unstable -
    • nixos-unstable-small 7.0.5
  • nixos-26.05 -
    • nixos-26.05-small 7.0.5

pkgs.wordpress_7_1

Open source software you can use to create a beautiful website, blog, or app

  • nixos-unstable -
    • nixos-unstable-small 7.1.1
  • nixos-26.05 -
    • nixos-26.05-small 7.1.1

Package maintainers

Untriaged
Permalink CVE-2026-77550
10.0 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 3 weeks, 5 days ago Activity log
  • Created suggestion
A malicious actor with access to the network could exploit …

A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.

Affected products

Express
  • <4.0.17
Express 7
  • <5.1.31
Cloud Keys
  • <5.1.31
Dream Wall
  • <5.1.31
Dream Routers
  • <5.1.31
Cloud Gateways
  • <5.1.31
Dream Machines
  • <5.1.31
UniFi OS Server
  • <5.1.37
Network Video Recorders
  • <5.1.31
Enterprise Firewall Core
  • <5.1.31
Network Attached Storage
  • <5.1.32
Enterprise Fortress Gateway
  • <5.1.31
Enterprise Network Video Recorders
  • <5.1.31
Enterprise Network Attached Storage
  • <5.1.31

Matching in nixpkgs

pkgs.expressvpn

CLI client for ExpressVPN

  • nixos-unstable -
  • nixos-26.05 -

pkgs.opteeQemuAarch64

Trusted Execution Environment for ARM

  • nixos-unstable -
    • nixos-unstable-small 4.7.0
  • nixos-26.05 -
    • nixos-26.05-small 4.7.0

pkgs.expresslrs-configurator

Cross-platform build & configuration tool for ExpressLRS

  • nixos-unstable -
    • nixos-unstable-small 1.8.3
  • nixos-26.05 -

pkgs.haskellPackages.express

Dynamically-typed expressions involving function application and variables

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers

Untriaged
Permalink CVE-2026-77549
9.0 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 3 weeks, 5 days ago Activity log
  • Created suggestion
A malicious actor with access to the network and under …

A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.

Affected products

Express
  • <4.0.17
Express 7
  • <5.1.31
Cloud Keys
  • <5.1.31
Dream Wall
  • <5.1.31
Dream Routers
  • <5.1.31
Cloud Gateways
  • <5.1.31
Dream Machines
  • <5.1.31
UniFi OS Server
  • <5.1.37
Network Video Recorders
  • <5.1.31
Enterprise Firewall Core
  • <5.1.31
Network Attached Storage
  • <5.1.32
Enterprise Fortress Gateway
  • <5.1.31
Enterprise Network Video Recorders
  • <5.1.31
Enterprise Network Attached Storage
  • <5.1.31

Matching in nixpkgs

pkgs.expressvpn

CLI client for ExpressVPN

  • nixos-unstable -
  • nixos-26.05 -

pkgs.opteeQemuAarch64

Trusted Execution Environment for ARM

  • nixos-unstable -
    • nixos-unstable-small 4.7.0
  • nixos-26.05 -
    • nixos-26.05-small 4.7.0

pkgs.expresslrs-configurator

Cross-platform build & configuration tool for ExpressLRS

  • nixos-unstable -
    • nixos-unstable-small 1.8.3
  • nixos-26.05 -

pkgs.haskellPackages.express

Dynamically-typed expressions involving function application and variables

  • nixos-unstable -
  • nixos-26.05 -

Package maintainers