Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
d180240c by Salvatore Bonaccorso at 2026-09-25T22:22:44+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -37,7 +37,7 @@ CVE-2026-97865 (A security flaw has been discovered in 
Open-Web-Analytics up to
 CVE-2026-97864 (A vulnerability has been found in GibbonEdu Gibbon up to 
30.0.01. The  ...)
        NOT-FOR-US: GibbonEdu Gibbon
 CVE-2026-97863 (The cisco_firesight_manager_ACL_rule_export module in 
misp-modules gen ...)
-       TODO: check
+       NOT-FOR-US: misp-modules
 CVE-2026-97846 (Keycloak provides a feature called mTLS holder-of-key binding 
which en ...)
        - keycloak <itp> (bug #1088287)
 CVE-2026-97818 (phpIPAM through 1.8.3 has incorrect authorization for 
id=="admins" and ...)
@@ -164,27 +164,27 @@ CVE-2026-93654 (The Premium Packages \u2013 Sell Digital 
Products Securely plugi
 CVE-2026-93647 (An unauthenticated calendar sender can place active markup in 
a COUNTE ...)
        NOT-FOR-US: Zimbra
 CVE-2026-93643 (When OnlyOffice/Document Editing is available, an 
unauthenticated remo ...)
-       TODO: check
+       NOT-FOR-US: Zimbra
 CVE-2026-93642 (An unauthenticated sender can forge a share notification that 
triggers ...)
        NOT-FOR-US: Zimbra
 CVE-2026-93641 (An unauthenticated sender can forge a share notification that 
triggers ...)
        NOT-FOR-US: Zimbra
 CVE-2026-93477 (Improperly Controlled Modification of Dynamically-Determined 
Object At ...)
-       TODO: check
+       NOT-FOR-US: ash-project
 CVE-2026-93399 (The Bookly plugin for WordPress is vulnerable to Insecure 
Direct Objec ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-93366 (Bludit CMS through 3.22.0 contains an authorization bypass 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: Bludit CMS
 CVE-2026-93365 (Bludit CMS through 3.22.0 contains a missing authorization 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: Bludit CMS
 CVE-2026-93364 (Bludit CMS through 3.22.0 contains a mass assignment 
vulnerability tha ...)
-       TODO: check
+       NOT-FOR-US: Bludit CMS
 CVE-2026-93363 (The @payloadcms/storage-vercel-blob storage adapter for 
Payload contai ...)
-       TODO: check
+       NOT-FOR-US: storage-vercel-blob storage adapter for Payload
 CVE-2026-93354 (Taskview Community before 1.56.0 contains a missing 
authentication vul ...)
-       TODO: check
+       NOT-FOR-US: Taskview Community
 CVE-2026-93353 (copyparty contains a volume restriction bypass vulnerability 
in its SF ...)
-       TODO: check
+       NOT-FOR-US: copyparty
 CVE-2026-93306 (IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 
through FW1 ...)
        NOT-FOR-US: IBM
 CVE-2026-93303 (The HT Contact Form \u2013 Drag & Drop Form Builder for 
WordPress plug ...)
@@ -192,9 +192,9 @@ CVE-2026-93303 (The HT Contact Form \u2013 Drag & Drop Form 
Builder for WordPres
 CVE-2026-93291 (Omni C20 lacks proper certificate validation which could allow 
an atta ...)
        TODO: check
 CVE-2026-93290 (Omni C20 uses hard-coded credentials that could allow an 
attacker to m ...)
-       TODO: check
+       NOT-FOR-US: Omni C20
 CVE-2026-93289 (The affected products are vulnerable to command injection 
attack that  ...)
-       TODO: check
+       NOT-FOR-US: Omni C20
 CVE-2026-93030 (FTM 4.x ALL could allow a remote authenticated attacker to 
obtain sens ...)
        NOT-FOR-US: IBM
 CVE-2026-92829 (The Blog2Social: Social Media Auto Post & Scheduler plugin for 
WordPre ...)
@@ -208,9 +208,9 @@ CVE-2026-92713 (The Modula Image Gallery \u2013 Photo Grid 
& Video Gallery plugi
 CVE-2026-92212 (The JetFormBuilder \u2014 Dynamic Blocks Form Builder plugin 
for WordP ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-92161 (FriendsOfFlarum OAuth allows users to log in to Flarum with 
GitHub, Tw ...)
-       TODO: check
+       NOT-FOR-US: FriendsOfFlarum OAuth
 CVE-2026-92106 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
-       TODO: check
+       NOT-FOR-US: dashbitco lazy_html
 CVE-2026-89426 (The Knit Pay \u2013 Cashfree, Instamojo, Razorpay, PayPal and 
more plu ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-89406 (The Modula Image Gallery \u2013 Photo Grid & Video Gallery 
plugin for  ...)
@@ -218,23 +218,23 @@ CVE-2026-89406 (The Modula Image Gallery \u2013 Photo 
Grid & Video Gallery plugi
 CVE-2026-89055 (The Customer Reviews for WooCommerce plugin for WordPress is 
vulnerabl ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-89032 (BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant 
isolation bypass ...)
-       TODO: check
+       NOT-FOR-US: BerriAI LiteLLM
 CVE-2026-88996 (The WPForms \u2013 AI Form Builder for WordPress \u2013 
Contact Forms, ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-88956 (The Botslab G980H dash camera firmware contains an 
authentication vuln ...)
-       TODO: check
+       NOT-FOR-US: Botslab G980H dash camera firmware
 CVE-2026-88848 (The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 
does not v ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-88761 (The Botslab G980H dash camera firmware generates the default 
WiFi pass ...)
-       TODO: check
+       NOT-FOR-US: Botslab G980H dash camera firmware
 CVE-2026-88421 (Incorrect access control in the BlogPage.get_entries() 
component of AP ...)
-       TODO: check
+       NOT-FOR-US: APSL puput
 CVE-2026-88420 (A reflected cross-site scripting (XSS) vulnerability in the 
EntryAbstr ...)
-       TODO: check
+       NOT-FOR-US: APSL puput
 CVE-2026-88389 (Espruino 2v29 (commit bffc6d0) contains a NULL pointer 
dereference vul ...)
-       TODO: check
+       NOT-FOR-US: Espruino
 CVE-2026-88388 (Espruino 2v29 (commit bffc6d0) contains a stack-based buffer 
overflow  ...)
-       TODO: check
+       NOT-FOR-US: Espruino
 CVE-2026-88387 (LibRaw 0.22.0 contains an incorrect numeric conversion 
vulnerability i ...)
        TODO: check
 CVE-2026-88386 (libsndfile 1.2.2 contains a misaligned memory access issue in 
psf_binh ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d180240ce7b2621fa2408484e35ae5fb26206e77

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d180240ce7b2621fa2408484e35ae5fb26206e77
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to