There are 11 open security issues in trixie.
11 issues left for the package maintainer to handle:
- CVE-2025-3573:
(needs triaging)
Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This value will populate a message via $.validator.messages in a user localizable dictionary.
- CVE-2025-25977:
(needs triaging)
An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code via the Constructor of the class StyleElement.
- CVE-2025-26843:
(needs triaging)
- CVE-2025-52204:
(needs triaging)
A Cross-Site Scripting (XSS) vulnerability exists in Znuny::ITSM 6.5.x in the customer.pl endpoint via the OTRSCustomerInterface parameter
- CVE-2025-59490:
(needs triaging)
- CVE-2026-48188:
(needs triaging)
An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to an authentication bypass. This issue only affects the system if the MySQL/MariaDB server is configured with the NO_BACKSLASH_ESCAPES SQL mode. This issue affects OTRS: * 7.0.X * 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X before 2026.4.X * (OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected
- CVE-2026-50591:
(needs triaging)
In Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can occur via stored user preferences.
- CVE-2026-50592:
(needs triaging)
In Znuny LTS before 6.5.21 and Znuny before 7.3.3, there is reflected XSS in AdminCommunicationLog (aka the communication log administration view).
- CVE-2026-77506:
(needs triaging)
Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.
- TEMP-0000000-7B2A47:
(needs triaging)
- TEMP-0000000-AE9A03:
(needs triaging)
You can find information about how to handle these issues in the security team's documentation.