If you disable a ruleset group and press save, this rules still triggers. It looks like suricata reload doesn't deactivate disabled rulesets.
Fix has been sent to the development mailing list: https://patchwork.ipfire.org/patch/2871/
https://git.ipfire.org/?p=ipfire-2.x.git;a=commit;h=af8e5145fa969f0c99c9650c16e05bc71d7297b1
https://blog.ipfire.org/post/ipfire-2-25-core-update-143-is-available-for-testing
https://blog.ipfire.org/post/ipfire-2-25-core-update-143-released