[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 5 20:25:06 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e9807efd by Salvatore Bonaccorso at 2026-08-05T21:24:35+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -69,55 +69,55 @@ CVE-2026-7326 (A cross-site request forgery vulnerability in the Admin UI of Pro
CVE-2026-7105 (The Xpro Addons plugin for WordPress is vulnerable to unauthorized cre ...)
NOT-FOR-US: WordPress plugin
CVE-2026-71294 (Cotonti CMS's Comments plugin deserializes user-supplied data without ...)
- TODO: check
+ NOT-FOR-US: Cotonti CMS
CVE-2026-71293 (Statamic CMS's user-augmentation resolver, AugmentedUser::get() in src ...)
- TODO: check
+ NOT-FOR-US: Statamic CMS
CVE-2026-71292 (Subrion CMS's admin grid sorting helper, _gridGetSorting() in includes ...)
- TODO: check
+ NOT-FOR-US: Subrion CMS
CVE-2026-71291 (Bolt CMS renders content field values through Twig's full application- ...)
- TODO: check
+ NOT-FOR-US: Bolt CMS
CVE-2026-71289 (The NASA-AMMOS Asynchronous Network Management System (ANMS) reference ...)
- TODO: check
+ NOT-FOR-US: NASA-AMMOS
CVE-2026-71288 (Koha's guided report builder (reports/guided_reports.pl) reads the `or ...)
- TODO: check
+ NOT-FOR-US: Koha Library Management System
CVE-2026-71287 (Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-suppl ...)
TODO: check
CVE-2026-71286 (The render-template component of ember-dynamic-render-template (addon/ ...)
- TODO: check
+ NOT-FOR-US: ember-dynamic-render-template
CVE-2026-71285 (Uptime Kuma's Matomo analytics integration (server/analytics/matomo-an ...)
- TODO: check
+ NOT-FOR-US: Uptime Kuma
CVE-2026-71284 (Fledge's backup-restore upload handler, upload_backup() (python/fledge ...)
- TODO: check
+ NOT-FOR-US: Fledge
CVE-2026-71283 (Fledge's backup-restore upload handler, upload_backup() (python/fledge ...)
- TODO: check
+ NOT-FOR-US: Fledge
CVE-2026-71282 (ChirpStack's SQLite-backend device tag filtering (chirpstack/src/stora ...)
- TODO: check
+ NOT-FOR-US: ChirpStack
CVE-2026-71281 (Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft ...)
- TODO: check
+ NOT-FOR-US: Hugging Face peft
CVE-2026-71280 (go-shiori's DownloadBookmark() (internal/core/download.go) fetches a c ...)
- TODO: check
+ NOT-FOR-US: go-shiori
CVE-2026-71279 (Zigbee2MQTT's ExternalJSExtension.getFilePath() (lib/extension/externa ...)
- TODO: check
+ NOT-FOR-US: Zigbee2MQTT
CVE-2026-71278 (rust-iot-platform allows creating a "calc rule" via POST /calc-rule/cr ...)
- TODO: check
+ NOT-FOR-US: rust-iot-platform
CVE-2026-71277 (rust-iot-platform's AuthToken request-guard implementation (api/src/ma ...)
- TODO: check
+ NOT-FOR-US: rust-iot-platform
CVE-2026-71276 (Magistrala (formerly Mainflux)'s message-readers API reads a `format` ...)
- TODO: check
+ NOT-FOR-US: Magistrala
CVE-2026-71275 (OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects ...)
- TODO: check
+ NOT-FOR-US: OpenBK7231T
CVE-2026-71274 (OpenBK7231T's CHANNEL_SetLabel() (src/cmnds/cmd_channels.c) stores cha ...)
- TODO: check
+ NOT-FOR-US: OpenBK7231T
CVE-2026-71273 (OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accep ...)
- TODO: check
+ NOT-FOR-US: OpenBK7231T
CVE-2026-71272 (Memos' webhook dispatch function safeDialContext() (internal/webhook/w ...)
- TODO: check
+ NOT-FOR-US: Memos
CVE-2026-71271 (Memos' webhook URL validation, isReservedIP() (internal/webhook/valida ...)
- TODO: check
+ NOT-FOR-US: Memos
CVE-2026-71270 (Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteTo ...)
- TODO: check
+ NOT-FOR-US: Stirling-PDF
CVE-2026-71269 (Node-RED's local-filesystem library storage module (getLibraryEntry() ...)
- TODO: check
+ NOT-FOR-US: Node-RED
CVE-2026-71268 (OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) ...)
TODO: check
CVE-2026-71267 (microtar's mtar_write_file_header() and mtar_write_dir_header() functi ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e9807efd477d7e3968dca194825176e401045234
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e9807efd477d7e3968dca194825176e401045234
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/56ad7de3/attachment.htm>
More information about the debian-security-tracker-commits
mailing list