There is 1 open security issue in bookworm.
1 issue left for the package maintainer to handle:
- CVE-2025-3573:
(needs triaging)
Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This value will populate a message via $.validator.messages in a user localizable dictionary.
You can find information about how to handle this issue in the security team's documentation.
2 issues that should be fixed with the next stable update:
- CVE-2025-24529:
An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the Insert tab.
- CVE-2025-24530:
An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the check tables feature. A crafted table or database name could be used for XSS.