v25.11.3 - Security - 03 Dec 2025
VDB 20251202 update: New vulnerability detections for Drupal, Piwigo, ReviveAdserver & MoveItTransfer. Enhanced password leak, DOM XSS, and chatbot detection.
Security check
- Updated the Vulnerability Database (VDB) to version 20251202
- Improved severity ratings for ReviveAdserver versions 5.3.0, 5.3.1, 5.4.0, 5.4.1, 5.5.0, 5.5.1, 5.5.2 from Medium to High
- Added vulnerability detection for Drupal:
- CVE-2025-13080 (Medium)
- CVE-2025-13081 (Medium)
- CVE-2025-13082 (Medium)
- CVE-2025-13083 (Low)
- Added vulnerability detection for Piwigo:
- CVE-2025-62406 (High)
- Added vulnerability detection for ReviveAdserver:
- CVE-2025-48986 (High)
- CVE-2025-48987 (Medium)
- CVE-2025-55124 (Medium)
- Added vulnerability detection for MoveItTransfer:
- CVE-2025-13147 (Medium)
Improvements
- Improved password detection when leaked in responses
- Enhanced detection of DOM XSS vulnerabilities
Resolved issues
- Improved detection of chatbots