There are 7 open security issues in trixie.
7 issues left for the package maintainer to handle:
- CVE-2025-3573:
(needs triaging)
Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This value will populate a message via $.validator.messages in a user localizable dictionary.
- CVE-2025-26843:
(needs triaging)
- CVE-2025-52204:
(needs triaging)
A Cross-Site Scripting (XSS) vulnerability exists in Znuny::ITSM 6.5.x in the customer.pl endpoint via the OTRSCustomerInterface parameter
- CVE-2025-59490:
(needs triaging)
- CVE-2026-50591:
(needs triaging)
In Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can occur via stored user preferences.
- CVE-2026-50592:
(needs triaging)
In Znuny LTS before 6.5.21 and Znuny before 7.3.3, there is reflected XSS in AdminCommunicationLog (aka the communication log administration view).
- TEMP-0000000-97F30C:
(needs triaging)
You can find information about how to handle these issues in the security team's documentation.