{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:62d0e970-1273-5709-8931-9fd00ba70cc2",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
      "type": "library",
      "group": "verbb",
      "name": "feed-me",
      "version": "3.1.17-p1+tuxcare",
      "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e2213917-fdde-5c2e-b2e7-4cceb81ff4c0",
      "id": "CVE-2022-37251",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-37251 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2022-37251 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c970a6ff-4938-595c-afb0-645ff3bb1cd5",
      "id": "CVE-2023-31144",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-31144 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2023-31144 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d009dcd-ba07-5833-a95a-5c3dda10aaf2",
      "id": "CVE-2023-33195",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33195 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2023-33195 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73aea92c-1e42-5544-8989-2b3c49d4f310",
      "id": "CVE-2023-33196",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33196 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2023-33196 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c5339b7-28de-550f-b5a7-248baa58aab4",
      "id": "CVE-2023-33197",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33197 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2023-33197 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56729dbd-9f12-5536-8bf2-8c4b67373f1c",
      "id": "CVE-2023-40035",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-40035 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2023-40035 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:033bcdc4-669e-56b2-bdb8-e06027250a70",
      "id": "CVE-2023-41892",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41892 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2023-41892 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c4c2d99-0843-570c-a174-b38f02270647",
      "id": "CVE-2024-21622",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-21622 is a false positive for verbb/feed-me 3.1.17-p1+tuxcare. false_positive \u2014 CVE-2024-21622 targets Craft CMS core (craftcms/cms), but this repository contains verbb/feed-me, a Craft CMS plugin. The affected component code (Craft CMS core) is absent from this repository. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a7e8cc6-a5c4-57b8-b9a0-96c1b86f1af7",
      "id": "CVE-2024-41800",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-41800 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2024-41800 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb99a99b-8b3c-5f53-9bc5-115fa63dc215",
      "id": "CVE-2024-52293",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-52293 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2024-52293 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:714b509b-97d7-5394-bb71-03051fc105dd",
      "id": "CVE-2025-23209",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-23209 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2025-23209 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b7988e5-f6eb-51ce-8589-572a96592ee7",
      "id": "CVE-2025-32432",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-32432 is a false positive for verbb/feed-me 3.1.17-p1+tuxcare. false_positive \u2014 CVE-2025-32432 concerns Craft CMS core (craftcms/cms) versions 3.0.0-RC1 to before 3.9.15. The target repository is Feed Me plugin (verbb/feed-me) version 3.1.17, a different product with independent versioning. This is a wrong-project match caused by version number collision between two separate products."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bce8974-40ab-5cb7-a76c-51522c4ed958",
      "id": "CVE-2025-46731",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-46731 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2025-46731 affects Craft CMS core versions 4.x (prior to 4.14.13) and 5.x (prior to 5.6.16). The target repository is the Feed Me plugin (verbb/feed-me) version 3.1.17, which depends on Craft CMS 3.x. The CVE does not mention Craft CMS 3.x as affected. While the plugin does use Twig template rendering via Craft CMS's renderObjectTemplate API with administrator-controlled input, the vulnerab..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2ece653-a4b1-529f-965d-cbdb493cba42",
      "id": "CVE-2025-57811",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-57811 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-57811. While the plugin does pass user-controlled feed data to Craft's renderObjectTemplate() method when parseTwig is enabled, the vulnerability only exists in Craft CMS versions 4.x and 5.x. Feed Me v3.1.17 is constrained to run exclusively on Craft CMS 3.x (per composer.json requirement: 'craftcms/cms': '^3.1.0'), which is not affected by th..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71b18da7-ed81-5551-b70a-252cd3d58008",
      "id": "CVE-2025-68436",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68436 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-68436. This vulnerability affects Craft CMS core versions 4.x and 5.x user profile photo functionality, while Feed Me is a plugin for Craft CMS 3.x that does not implement user profile photo management features. Feed Me only provides admin-only bulk import functionality for user data from feeds, which is architecturally different from the indiv..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b76d225-6b61-5384-a239-eeb27fbe96e2",
      "id": "CVE-2025-68454",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68454 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin is not affected by CVE-2025-68454. The vulnerability targets Craft CMS core features (Settings text fields and System Messages utility) that do not exist in the Feed Me plugin codebase. Feed Me's Twig processing serves a different purpose (processing external feed data) and does not expose the vulnerable attack vector described in the CVE."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfc4bf39-bc8a-5a23-a03e-410158a60d3e",
      "id": "CVE-2025-68455",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68455 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2025-68455 affects Craft CMS core's Behavior attachment functionality in versions 4.x and 5.x. The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that handles feed imports. Exhaustive analysis confirms the plugin does not implement, use, or interact with Craft's Behavior system. The vulnerability pattern (malicious Behavior attachment leading to RCE) does not apply b..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4db55a9-abcb-5f96-88fc-d98ed9e38b4c",
      "id": "CVE-2026-25491",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25491 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2026-25491 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83b90049-5916-58c7-9538-6582a4d98f86",
      "id": "CVE-2026-25493",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25493 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-25493 targets the saveAsset GraphQL mutation in Craft CMS core versions 4.x and 5.x. This repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that does not implement or use the vulnerable GraphQL mutation. The specific vulnerable component does not exist in this project."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9421d4f6-f281-56d3-8dd0-57068ee00545",
      "id": "CVE-2026-25494",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-25494 is a false positive for verbb/feed-me 3.1.17-p1+tuxcare. false_positive \u2014 CVE-2026-25494 concerns Craft CMS core (craftcms/cms versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.22), specifically the saveAsset GraphQL mutation. This repository is verbb/feed-me version 3.1.17-p1+tuxcare, a plugin FOR Craft CMS, not Craft CMS itself. The affected component (saveAsset GraphQL mutation with IP validation) does not exist in this plugin's codebase. This is a wron..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5ff0f16-195d-5f34-a23b-77fe8c905889",
      "id": "CVE-2026-25495",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25495 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17, a Craft CMS plugin) is not affected by CVE-2026-25495. The vulnerability exists in Craft CMS core's element-indexes/get-elements endpoint which processes criteria[orderBy] parameters. This endpoint does not exist in the plugin. While the plugin contains a getFeeds($orderBy) method with a similar unsanitized pattern, it is never exposed to user input..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:621085d5-09f4-5f1d-9059-9bf04daf9634",
      "id": "CVE-2026-25496",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25496 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin is not affected by CVE-2026-25496. The vulnerability concerns Craft CMS core's Number field type settings rendering (Prefix/Suffix with |md|raw filter), but Feed Me is a data import plugin that does not implement field settings UI, field rendering, or handle Number field Prefix/Suffix configuration. Feed Me only maps imported data values to existing Craft fields and never process..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b51517d-54c7-5534-84b8-2a71abac8b31",
      "id": "CVE-2026-25498",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25498 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The feed-me plugin v3.1.17 is not affected by CVE-2026-25498. The vulnerability exists in Craft CMS core (v4.0.0-RC1+ and v5.0.0-RC1+) in the assembleLayoutFromPost() function which does not exist in this plugin. While feed-me uses similar object creation functions (ComponentHelper::createComponent), these are only called with hardcoded class names from internal registries, never with user-cont..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ff3b749-75f2-5beb-9caf-239f364c9c2c",
      "id": "CVE-2026-27126",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27126 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2026-27126. The vulnerability exists in Craft CMS core's editableTable.twig component (versions 4.5.0+ and 5.0.0+), which Feed Me does not use, implement, or interact with. Feed Me is a data import plugin that operates at a different architectural layer than the vulnerable admin UI rendering component."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0416a2a-5089-5c4b-a2ec-0592e8745e93",
      "id": "CVE-2026-27128",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27128 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin for importing content from feeds. The CVE-2026-27128 vulnerability exists in Craft CMS core's token validation service (specifically the getTokenRoute() method's TOCTOU race condition). After exhaustive analysis, the plugin's codebase does not implement, use, or interact with Craft CMS's token validation service or impersonatio..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76b96f88-0d63-5d5c-a2ad-f7cc173ec5bd",
      "id": "CVE-2026-29113",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-29113 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin (verbb/feed-me v3.1.17) is not affected by CVE-2026-29113. The vulnerability exists in Craft CMS core's preview token endpoint (/actions/preview/create-token), which is part of the craftcms/cms package. This plugin does not implement, interact with, or depend on the vulnerable preview token creation functionality. The plugin's codebase focuses on feed import operations and does n..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d594765-c942-5490-960d-0e4f3e919b9b",
      "id": "CVE-2026-31857",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31857 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-31857 targets Craft CMS core's BaseElementSelectConditionRule class in versions 4.x and 5.x. The target repository is verbb/feed-me plugin v3.1.17, which depends on Craft CMS 3.1.5. The vulnerable conditions system and BaseElementSelectConditionRule class were introduced in Craft CMS 4.0 and do not exist in version 3.x. The plugin does not implement or use condition rules. Therefore, t..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d518f50c-f141-5447-8b1e-4fa79adc049d",
      "id": "CVE-2026-31858",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31858 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in Craft CMS core's ElementSearchController::actionSearch() endpoint. The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin, not Craft CMS core itself. The vulnerable endpoint and controller classes (ElementSearchController, ElementIndexesController) do not exist in this plugin's codebase. The vulnerability resides in the core..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ae0c4ef-4f7a-5105-89eb-efa489b3248b",
      "id": "CVE-2026-32262",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-32262 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The CVE-2026-32262 vulnerability exists in Craft CMS core's AssetsController->replaceFile() method. This repository is verbb/feed-me version 3.1.17, a Craft CMS plugin, not the CMS core itself. The plugin does not implement the vulnerable endpoint or replicate the vulnerable pattern. While the plugin processes filenames from feeds, all filenames are sanitized via AssetsHelper::prepareAssetName(..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf172815-efb7-5ae9-bb1d-c24192491550",
      "id": "CVE-2026-32263",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-32263 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2026-32263 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f041277-896d-518c-b889-7456d52f83b7",
      "id": "CVE-2026-32264",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-32264 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS. CVE-2026-32264 describes a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController, which are core Craft CMS controllers in the craftcms/cms package (versions 4.x and 5.x). This plugin does not contain these controllers, does not implement behavior injection patterns, and its dependency constra..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6009a738-8690-57af-a987-8fe3c4f4ce67",
      "id": "CVE-2026-32267",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-32267 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-32267 concerns Craft CMS core's UsersController->actionImpersonateWithToken privilege escalation vulnerability. The target repository is verbb/feed-me version 3.1.17, a Craft CMS plugin (not the CMS core itself). The plugin provides feed import functionality and does not contain the affected component (UsersController), does not implement any user impersonation functionality, and does ..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74c8d9d2-eeaa-5437-a3ed-eb23fc2253c8",
      "id": "CVE-2026-33051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33051 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2026-33051 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0c76895-8ca1-56ef-99bd-cea4bc5bb5e5",
      "id": "CVE-2026-33157",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33157 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-33157 affects Craft CMS core (versions 5.6.0 to 5.9.13), specifically ElementIndexesController::actionFilterHud() and FieldLayout::createFromConfig(). The target repository is verbb/feed-me 3.1.17, a Craft CMS plugin that requires craftcms/cms ^3.1.0. The plugin does not contain, invoke, or interact with the vulnerable Craft CMS core components. Type A1 analysis confirms the vulnerabil..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f27ed7b9-d118-52e1-8c40-35912016c689",
      "id": "CVE-2026-33158",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33158 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me plugin v3.1.17) is not affected by CVE-2026-33158. The vulnerability exists in Craft CMS core's assets/edit-image endpoint, which is not implemented by this plugin. The plugin's asset functionality is limited to importing assets from feeds and does not include any asset viewing or editing endpoints that could exhibit the authorization bypass vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:591691cb-ce8d-5460-a15c-ee364998aced",
      "id": "CVE-2026-33159",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33159 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 Target repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS core. CVE-2026-33159 concerns Craft CMS's Config Sync feature authentication bypass. This plugin does not implement, extend, or interact with Config Sync functionality."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0e436cc-ddc7-5133-b24e-dba4be22d8cf",
      "id": "CVE-2026-33160",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33160 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me (version 3.1.17), a Craft CMS plugin for importing content from feeds. CVE-2026-33160 concerns a vulnerability in Craft CMS core's assets/generate-transform endpoint. This plugin does not implement, extend, or interact with asset transformation functionality. The vulnerable code path exists only in Craft CMS core, not in this plugin repository."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9d34c15-13be-54d5-8005-282cad63e96c",
      "id": "CVE-2026-33161",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-33161 is a false positive for verbb/feed-me 3.1.17-p1+tuxcare. false_positive \u2014 CVE-2026-33161 is a false positive for this repository. The vulnerability concerns Craft CMS core's assets/image-editor endpoint, but this repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS itself. The vulnerable code does not exist in this codebase."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ad5b853-4ffc-5350-9cec-7d848d9e923b",
      "id": "CVE-2026-33162",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33162 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a plugin for Craft CMS that provides feed import functionality. The vulnerability CVE-2026-33162 affects the core Craft CMS product (craftcms/cms v5.3.0-5.9.13), specifically the /actions/entries/move-to-section endpoint in the EntriesController. This plugin does not implement, vendor, or bundle this vulnerable component. The plugin's own code do..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c705c461-a7a4-53de-8e69-c5c4c679c12f",
      "id": "CVE-2026-41129",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41129 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2026-41129 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf49e314-fea0-51d3-a576-2b55ff96c8e8",
      "id": "CVE-2026-41130",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41130 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me version 3.1.17, a plugin for Craft CMS, not Craft CMS core itself. CVE-2026-41130 affects the resource-js endpoint in Craft CMS core versions 4.x through 4.17.8 and 5.x through 5.9.14. This plugin targets Craft CMS 3.x (^3.1.0) and does not implement the vulnerable resource-js endpoint or any similar functionality that proxies JavaScript resources based on..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
    }
  ]
}