Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
d180240c by Salvatore Bonaccorso at 2026-09-25T22:22:44+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -37,7 +37,7 @@ CVE-2026-97865 (A security flaw has been discovered in
Open-Web-Analytics up to
CVE-2026-97864 (A vulnerability has been found in GibbonEdu Gibbon up to
30.0.01. The ...)
NOT-FOR-US: GibbonEdu Gibbon
CVE-2026-97863 (The cisco_firesight_manager_ACL_rule_export module in
misp-modules gen ...)
- TODO: check
+ NOT-FOR-US: misp-modules
CVE-2026-97846 (Keycloak provides a feature called mTLS holder-of-key binding
which en ...)
- keycloak <itp> (bug #1088287)
CVE-2026-97818 (phpIPAM through 1.8.3 has incorrect authorization for
id=="admins" and ...)
@@ -164,27 +164,27 @@ CVE-2026-93654 (The Premium Packages \u2013 Sell Digital
Products Securely plugi
CVE-2026-93647 (An unauthenticated calendar sender can place active markup in
a COUNTE ...)
NOT-FOR-US: Zimbra
CVE-2026-93643 (When OnlyOffice/Document Editing is available, an
unauthenticated remo ...)
- TODO: check
+ NOT-FOR-US: Zimbra
CVE-2026-93642 (An unauthenticated sender can forge a share notification that
triggers ...)
NOT-FOR-US: Zimbra
CVE-2026-93641 (An unauthenticated sender can forge a share notification that
triggers ...)
NOT-FOR-US: Zimbra
CVE-2026-93477 (Improperly Controlled Modification of Dynamically-Determined
Object At ...)
- TODO: check
+ NOT-FOR-US: ash-project
CVE-2026-93399 (The Bookly plugin for WordPress is vulnerable to Insecure
Direct Objec ...)
NOT-FOR-US: WordPress plugin
CVE-2026-93366 (Bludit CMS through 3.22.0 contains an authorization bypass
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: Bludit CMS
CVE-2026-93365 (Bludit CMS through 3.22.0 contains a missing authorization
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: Bludit CMS
CVE-2026-93364 (Bludit CMS through 3.22.0 contains a mass assignment
vulnerability tha ...)
- TODO: check
+ NOT-FOR-US: Bludit CMS
CVE-2026-93363 (The @payloadcms/storage-vercel-blob storage adapter for
Payload contai ...)
- TODO: check
+ NOT-FOR-US: storage-vercel-blob storage adapter for Payload
CVE-2026-93354 (Taskview Community before 1.56.0 contains a missing
authentication vul ...)
- TODO: check
+ NOT-FOR-US: Taskview Community
CVE-2026-93353 (copyparty contains a volume restriction bypass vulnerability
in its SF ...)
- TODO: check
+ NOT-FOR-US: copyparty
CVE-2026-93306 (IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00
through FW1 ...)
NOT-FOR-US: IBM
CVE-2026-93303 (The HT Contact Form \u2013 Drag & Drop Form Builder for
WordPress plug ...)
@@ -192,9 +192,9 @@ CVE-2026-93303 (The HT Contact Form \u2013 Drag & Drop Form
Builder for WordPres
CVE-2026-93291 (Omni C20 lacks proper certificate validation which could allow
an atta ...)
TODO: check
CVE-2026-93290 (Omni C20 uses hard-coded credentials that could allow an
attacker to m ...)
- TODO: check
+ NOT-FOR-US: Omni C20
CVE-2026-93289 (The affected products are vulnerable to command injection
attack that ...)
- TODO: check
+ NOT-FOR-US: Omni C20
CVE-2026-93030 (FTM 4.x ALL could allow a remote authenticated attacker to
obtain sens ...)
NOT-FOR-US: IBM
CVE-2026-92829 (The Blog2Social: Social Media Auto Post & Scheduler plugin for
WordPre ...)
@@ -208,9 +208,9 @@ CVE-2026-92713 (The Modula Image Gallery \u2013 Photo Grid
& Video Gallery plugi
CVE-2026-92212 (The JetFormBuilder \u2014 Dynamic Blocks Form Builder plugin
for WordP ...)
NOT-FOR-US: WordPress plugin
CVE-2026-92161 (FriendsOfFlarum OAuth allows users to log in to Flarum with
GitHub, Tw ...)
- TODO: check
+ NOT-FOR-US: FriendsOfFlarum OAuth
CVE-2026-92106 (Improper Neutralization of Input During Web Page Generation
('Cross-si ...)
- TODO: check
+ NOT-FOR-US: dashbitco lazy_html
CVE-2026-89426 (The Knit Pay \u2013 Cashfree, Instamojo, Razorpay, PayPal and
more plu ...)
NOT-FOR-US: WordPress plugin
CVE-2026-89406 (The Modula Image Gallery \u2013 Photo Grid & Video Gallery
plugin for ...)
@@ -218,23 +218,23 @@ CVE-2026-89406 (The Modula Image Gallery \u2013 Photo
Grid & Video Gallery plugi
CVE-2026-89055 (The Customer Reviews for WooCommerce plugin for WordPress is
vulnerabl ...)
NOT-FOR-US: WordPress plugin
CVE-2026-89032 (BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant
isolation bypass ...)
- TODO: check
+ NOT-FOR-US: BerriAI LiteLLM
CVE-2026-88996 (The WPForms \u2013 AI Form Builder for WordPress \u2013
Contact Forms, ...)
NOT-FOR-US: WordPress plugin
CVE-2026-88956 (The Botslab G980H dash camera firmware contains an
authentication vuln ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-88848 (The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50
does not v ...)
NOT-FOR-US: WordPress plugin
CVE-2026-88761 (The Botslab G980H dash camera firmware generates the default
WiFi pass ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-88421 (Incorrect access control in the BlogPage.get_entries()
component of AP ...)
- TODO: check
+ NOT-FOR-US: APSL puput
CVE-2026-88420 (A reflected cross-site scripting (XSS) vulnerability in the
EntryAbstr ...)
- TODO: check
+ NOT-FOR-US: APSL puput
CVE-2026-88389 (Espruino 2v29 (commit bffc6d0) contains a NULL pointer
dereference vul ...)
- TODO: check
+ NOT-FOR-US: Espruino
CVE-2026-88388 (Espruino 2v29 (commit bffc6d0) contains a stack-based buffer
overflow ...)
- TODO: check
+ NOT-FOR-US: Espruino
CVE-2026-88387 (LibRaw 0.22.0 contains an incorrect numeric conversion
vulnerability i ...)
TODO: check
CVE-2026-88386 (libsndfile 1.2.2 contains a misaligned memory access issue in
psf_binh ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d180240ce7b2621fa2408484e35ae5fb26206e77
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d180240ce7b2621fa2408484e35ae5fb26206e77
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits