CVE-2025-3261

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: 2025-11-27 Last update: 2025-12-16 Assigner: 596c5446-0ce5-4ba2-aa66-48b3b757a647 Source: 596c5446-0ce5-4ba2-aa66-48b3b757a647

Conclusion & alert: This CVE is rejected; it is not tracked as an active vulnerability. Mandatory action: Do not treat as an active exposure for patching queues—follow the CVE record status and authoritative vendor or program statements only.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2025-3261

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-12-04 0.07% 0.03% -0.04%
2 2025-11-28 0.07%

Full EPSS history (2 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2025-3261

CVSS metrics for this CVE.

No CVSS data in dataset for this CVE.

Weakness enumeration for CVE-2025-3261

GitHub Security Advisory for CVE-2025-3261

GHSA-5p82-2q3r-wj3m · Severity: medium · Ecosystem: maven — ThingsBoard allows an authenticated user to upload malicious SVG images

Affected software / configurations for CVE-2025-3261

Vendor Product Version Raw CPE
No affected products in dataset.

References for CVE-2025-3261

URL Tags
No references in dataset.
cvelogic Threat Intelligence