Nixpkgs Security Tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for a revision.

updated 2 weeks ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    3 packages
    • nika-fonts
    • python312Packages.minikanren
    • python313Packages.minikanren
  • @LeSuisse dismissed
WordPress Nika theme <= 1.2.14 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Thembay Nika allows PHP Local File Inclusion.This issue affects Nika: from n/a through 1.2.14.

Affected products

Nika
  • =<1.2.14

Package maintainers

WP theme not present in nixpkgs
updated 2 weeks ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package emu2
  • @LeSuisse dismissed
WordPress Emu2 plugin <= 0.83b - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juergen Schulze Emu2 emu2-email-users-2 allows Reflected XSS.This issue affects Emu2: from n/a through <= 0.83b.

Affected products

emu2-email-users-2
  • =<<= 0.83b
WP plugin not present in nixpkgs
updated 2 weeks ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    5 packages
    • typstPackages.efilrst_0_3_2
    • typstPackages.efilrst_0_3_1
    • typstPackages.efilrst_0_3_0
    • typstPackages.efilrst_0_2_0
    • typstPackages.efilrst_0_1_0
  • @LeSuisse dismissed
WordPress Filr plugin <= 1.2.10 - Arbitrary File Deletion vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Chill Filr filr-protection allows Path Traversal.This issue affects Filr: from n/a through <= 1.2.10.

Affected products

filr-protection
  • =<<= 1.2.10

Package maintainers

WP plugin not present in nixpkgs
updated 2 weeks ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse dismissed
WordPress Wiremo plugin <= 1.4.99 - Broken Access Control vulnerability

Missing Authorization vulnerability in Wiremo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wiremo: from n/a through 1.4.99.

Affected products

woo-reviews-by-wiremo
  • =<1.4.99

Matching in nixpkgs

Package maintainers

WP plugin not present in nixpkgs
updated 2 weeks ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    3 packages
    • python312Packages.aioridwell
    • python313Packages.aioridwell
    • home-assistant-component-tests.ridwell
  • @LeSuisse dismissed
WordPress Dwell theme <= 1.7.0 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Dwell dwell allows PHP Local File Inclusion.This issue affects Dwell: from n/a through <= 1.7.0.

Affected products

dwell
  • =<<= 1.7.0

Package maintainers

WP theme note present in nixpkgs
updated 2 weeks ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package tests.haskell.upstreamStackHpackVersion
  • @LeSuisse dismissed
WordPress 777 theme <= 1.3 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes 777 triple-seven allows PHP Local File Inclusion.This issue affects 777: from n/a through <= 1.3.

Affected products

triple-seven
  • =<<= 1.3

Package maintainers

WP theme note present in nixpkgs
updated 2 weeks ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    10 packages
    • dsseries
    • git-series
    • python312Packages.eseries
    • python312Packages.pyseries
    • python313Packages.pyseries
    • haskellPackages.timezone-series
    • epson-workforce-635-nx625-series
    • pkgsRocm.python3Packages.pyseries
    • azure-cli-extensions.timeseriesinsights
    • epson-inkjet-printer-workforce-840-series
  • @LeSuisse dismissed
WordPress Series plugin <= 2.0.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Series allows Stored XSS.This issue affects Series: from n/a through 2.0.1.

Affected products

series
  • =<2.0.1

Package maintainers

WP plugin not present in nixpkgs
updated 2 weeks ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    37 packages
    • spago
    • etlegacy
    • spago-legacy
    • ifstat-legacy
    • libewf-legacy
    • geolite-legacy
    • etlegacy-assets
    • etlegacy-unwrapped
    • rquickshare-legacy
    • perlPackages.MenloLegacy
    • adwaita-icon-theme-legacy
    • perl538Packages.MenloLegacy
    • perl540Packages.MenloLegacy
    • haskellPackages.spago-legacy
    • python312Packages.legacy-cgi
    • python313Packages.legacy-cgi
    • intel-compute-runtime-legacy1
    • ocamlPackages.legacy_diffable
    • php81Extensions.openssl-legacy
    • php82Extensions.openssl-legacy
    • php83Extensions.openssl-legacy
    • php84Extensions.openssl-legacy
    • python312Packages.spacy-legacy
    • python313Packages.spacy-legacy
    • python312Packages.legacy-api-wrap
    • python313Packages.legacy-api-wrap
    • python312Packages.packaging-legacy
    • python312Packages.pyoppleio-legacy
    • python313Packages.packaging-legacy
    • python313Packages.pyoppleio-legacy
    • python312Packages.llama-index-legacy
    • python313Packages.llama-index-legacy
    • ocamlPackages.janeStreet.legacy_diffable
    • pkgsRocm.python3Packages.llama-index-legacy
    • python312Packages.azure-servicemanagement-legacy
    • python313Packages.azure-servicemanagement-legacy
    • gnomeExtensions.legacy-gtk3-theme-scheme-auto-switcher
  • @LeSuisse dismissed
WordPress Legacy theme <= 1.9 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Legacy legacy allows PHP Local File Inclusion.This issue affects Legacy: from n/a through <= 1.9.

Affected products

legacy
  • =<<= 1.9
WP theme not present in nixpkgs
updated 2 weeks ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    2 packages
    • sshuttle
    • cargo-shuttle
  • @LeSuisse dismissed
WordPress Shuttle theme <= 1.5.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shuttlethemes Shuttle allows Stored XSS.This issue affects Shuttle: from n/a through 1.5.0.

Affected products

shuttle
  • =<1.5.0

Package maintainers

WP theme not present in nixpkgs
updated 2 weeks ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    10 packages
    • pngoptimizer
    • meshoptimizer
    • openorbitaloptimizer
    • elmPackages.elm-optimize-level-2
    • akkuPackages.cyclone-iset-optimize
    • haskellPackages.amazonka-compute-optimizer
    • python312Packages.mypy-boto3-compute-optimizer
    • python313Packages.mypy-boto3-compute-optimizer
    • python312Packages.types-aiobotocore-compute-optimizer
    • python313Packages.types-aiobotocore-compute-optimizer
  • @LeSuisse dismissed
WordPress Optimize theme < 2.4 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Optimize optimizewp allows PHP Local File Inclusion.This issue affects Optimize: from n/a through < 2.4.

Affected products

optimizewp
  • =<< 2.4

Package maintainers

WP theme not present in nixpkgs