Nixpkgs Security Tracker

Login with GitHub

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Permalink CVE-2025-62759
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
updated 2 months ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    10 packages
    • dsseries
    • git-series
    • python312Packages.eseries
    • python312Packages.pyseries
    • python313Packages.pyseries
    • haskellPackages.timezone-series
    • epson-workforce-635-nx625-series
    • pkgsRocm.python3Packages.pyseries
    • azure-cli-extensions.timeseriesinsights
    • epson-inkjet-printer-workforce-840-series
  • @LeSuisse dismissed
WordPress Series plugin <= 2.0.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Series allows Stored XSS.This issue affects Series: from n/a through 2.0.1.

Affected products

series
  • =<2.0.1
WP plugin not present in nixpkgs
Permalink CVE-2025-58709
8.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
updated 2 months ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    37 packages
    • spago
    • etlegacy
    • spago-legacy
    • ifstat-legacy
    • libewf-legacy
    • geolite-legacy
    • etlegacy-assets
    • etlegacy-unwrapped
    • rquickshare-legacy
    • perlPackages.MenloLegacy
    • adwaita-icon-theme-legacy
    • perl538Packages.MenloLegacy
    • perl540Packages.MenloLegacy
    • haskellPackages.spago-legacy
    • python312Packages.legacy-cgi
    • python313Packages.legacy-cgi
    • intel-compute-runtime-legacy1
    • ocamlPackages.legacy_diffable
    • php81Extensions.openssl-legacy
    • php82Extensions.openssl-legacy
    • php83Extensions.openssl-legacy
    • php84Extensions.openssl-legacy
    • python312Packages.spacy-legacy
    • python313Packages.spacy-legacy
    • python312Packages.legacy-api-wrap
    • python313Packages.legacy-api-wrap
    • python312Packages.packaging-legacy
    • python312Packages.pyoppleio-legacy
    • python313Packages.packaging-legacy
    • python313Packages.pyoppleio-legacy
    • python312Packages.llama-index-legacy
    • python313Packages.llama-index-legacy
    • ocamlPackages.janeStreet.legacy_diffable
    • pkgsRocm.python3Packages.llama-index-legacy
    • python312Packages.azure-servicemanagement-legacy
    • python313Packages.azure-servicemanagement-legacy
    • gnomeExtensions.legacy-gtk3-theme-scheme-auto-switcher
  • @LeSuisse dismissed
WordPress Legacy theme <= 1.9 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Legacy legacy allows PHP Local File Inclusion.This issue affects Legacy: from n/a through <= 1.9.

Affected products

legacy
  • =<<= 1.9
WP theme not present in nixpkgs
Permalink CVE-2025-62137
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
updated 2 months ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    2 packages
    • sshuttle
    • cargo-shuttle
  • @LeSuisse dismissed
WordPress Shuttle theme <= 1.5.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shuttlethemes Shuttle allows Stored XSS.This issue affects Shuttle: from n/a through 1.5.0.

Affected products

shuttle
  • =<1.5.0
WP theme not present in nixpkgs
Permalink CVE-2025-67935
8.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
updated 2 months ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    10 packages
    • pngoptimizer
    • meshoptimizer
    • openorbitaloptimizer
    • elmPackages.elm-optimize-level-2
    • akkuPackages.cyclone-iset-optimize
    • haskellPackages.amazonka-compute-optimizer
    • python312Packages.mypy-boto3-compute-optimizer
    • python313Packages.mypy-boto3-compute-optimizer
    • python312Packages.types-aiobotocore-compute-optimizer
    • python313Packages.types-aiobotocore-compute-optimizer
  • @LeSuisse dismissed
WordPress Optimize theme < 2.4 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Optimize optimizewp allows PHP Local File Inclusion.This issue affects Optimize: from n/a through < 2.4.

Affected products

optimizewp
  • =<< 2.4
WP theme not present in nixpkgs
Permalink CVE-2025-60053
8.2 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
updated 2 months ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    3 packages
    • python312Packages.maxcube-api
    • python313Packages.maxcube-api
    • home-assistant-component-tests.maxcube
  • @LeSuisse dismissed
WordPress MaxCube theme <= 1.3.1 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes MaxCube maxcube allows PHP Local File Inclusion.This issue affects MaxCube: from n/a through <= 1.3.1.

Affected products

maxcube
  • =<<= 1.3.1
WP theme not present in nixpkgs
Permalink CVE-2025-67528
5.1 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): NONE
  • Availability impact (A): LOW
updated 2 months ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    31 packages
    • furnace
    • xournalpp
    • journalist
    • lazyjournal
    • qjournalctl
    • tui-journal
    • journalwatch
    • annapurna-sil
    • journaldriver
    • systemd-journal2gelf
    • kdePackages.kjournald
    • perlPackages.LogJournald
    • perl538Packages.LogJournald
    • perl540Packages.LogJournald
    • python312Packages.swh-journal
    • python313Packages.swh-journal
    • python312Packages.waterfurnace
    • typstPackages.starter-journal-article_0_4_0
    • typstPackages.starter-journal-article_0_3_3
    • typstPackages.starter-journal-article_0_3_2
    • typstPackages.starter-journal-article_0_3_1
    • typstPackages.starter-journal-article_0_3_0
    • typstPackages.starter-journal-article_0_2_0
    • typstPackages.starter-journal-article_0_1_1
    • haskellPackages.logging-facade-journald
    • typstPackages.starter-journal-article
    • python313Packages.logging-journald
    • python312Packages.logging-journald
    • haskellPackages.libsystemd-journal
    • haskellPackages.journalctl-stream
    • python313Packages.waterfurnace
  • @LeSuisse dismissed
WordPress Urna theme <= 2.5.12 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Urna urna allows PHP Local File Inclusion.This issue affects Urna: from n/a through <= 2.5.12.

Affected products

urna
  • =<<= 2.5.12
WP theme not present in nixpkgs
Permalink CVE-2025-52739
7.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
updated 2 months ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    4 packages
    • python313Packages.schema-salad
    • python312Packages.schema-salad
    • python313Packages.datasalad
    • python312Packages.datasalad
  • @LeSuisse dismissed
WordPress Sala theme <= 1.1.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Sala allows Reflected XSS.This issue affects Sala: from n/a through 1.1.3.

Affected products

Sala
  • =<1.1.3
WP theme not present in nixpkgs
Permalink CVE-2026-0906
9.8 CRITICAL
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
updated 2 months ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    25 packages
    • chromedriver
    • netflix
    • mkchromecast
    • chrome-export
    • go-chromecast
    • google-chrome
    • chrome-token-signing
    • chrome-pak-customizer
    • curl-impersonate-chrome
    • undetected-chromedriver
    • electron-chromedriver_33
    • grafanaPlugins.ventura-psychrometric-panel
    • python313Packages.undetected-chromedriver
    • python312Packages.undetected-chromedriver
    • python313Packages.pychromecast
    • python312Packages.pychromecast
    • noto-fonts-monochrome-emoji
    • ocamlPackages.chrome-trace
    • xorg.xf86videoopenchrome
    • electron-chromedriver_39
    • electron-chromedriver_38
    • electron-chromedriver_37
    • electron-chromedriver_36
    • electron-chromedriver_35
    • electron-chromedriver_34
  • @LeSuisse dismissed
Incorrect security UI in Google Chrome on Android prior to …

Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)

Affected products

Chrome
  • <144.0.7559.59
Seem to only impact Chrome on Android (and it's already upgrade in nixpkgs)
Permalink CVE-2025-62951
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
updated 2 months ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    7 packages
    • python312Packages.h5py
    • python313Packages.h5py
    • python312Packages.h5py-mpi
    • python313Packages.h5py-mpi
    • python312Packages.airtouch5py
    • python313Packages.airtouch5py
    • pkgsRocm.python3Packages.h5py-mpi
  • @LeSuisse dismissed
WordPress Interactive Content – H5P plugin <= 1.16.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icc0rz Interactive Content – H5P h5p allows Stored XSS.This issue affects Interactive Content – H5P: from n/a through <= 1.16.0.

Affected products

h5p
  • =<<= 1.16.0
WP plugin not present in nixpkgs
Permalink CVE-2025-68540
9.8 CRITICAL
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
updated 2 months ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    35 packages
    • grafana
    • grafanactl
    • mcp-grafana
    • grafana-loki
    • grafana-alloy
    • grafana-kiosk
    • grafana-to-ntfy
    • grafana-dash-n-grab
    • grafana-image-renderer
    • dhallPackages.dhall-grafana
    • terraform-providers.grafana
    • python312Packages.grafanalib
    • python313Packages.grafanalib
    • haskellPackages.amazonka-grafana
    • grafanaPlugins.grafana-oncall-app
    • grafanaPlugins.grafana-clock-panel
    • terraform-providers.grafana_grafana
    • grafanaPlugins.grafana-pyroscope-app
    • python312Packages.mypy-boto3-grafana
    • python313Packages.mypy-boto3-grafana
    • grafanaPlugins.grafana-piechart-panel
    • grafanaPlugins.grafana-polystat-panel
    • grafanaPlugins.grafana-worldmap-panel
    • grafanaPlugins.grafana-lokiexplore-app
    • grafanaPlugins.grafana-mqtt-datasource
    • grafanaPlugins.grafana-exploretraces-app
    • grafanaPlugins.grafana-github-datasource
    • grafanaPlugins.grafana-sentry-datasource
    • grafanaPlugins.grafana-discourse-datasource
    • grafanaPlugins.grafana-metricsdrilldown-app
    • python312Packages.types-aiobotocore-grafana
    • python313Packages.types-aiobotocore-grafana
    • grafanaPlugins.grafana-clickhouse-datasource
    • grafanaPlugins.grafana-opensearch-datasource
    • grafanaPlugins.grafana-googlesheets-datasource
  • @LeSuisse dismissed
WordPress Fana theme <= 1.1.35 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Fana fana allows PHP Local File Inclusion.This issue affects Fana: from n/a through <= 1.1.35.

Affected products

fana
  • =<<= 1.1.35
WP theme not present in nixpkgs