[Git][security-tracker-team/security-tracker][master] Associate some CVEs with koha, itp'ed
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 11 21:35:33 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
86bad094 by Salvatore Bonaccorso at 2026-08-11T22:31:50+02:00
Associate some CVEs with koha, itp'ed
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -6812,7 +6812,7 @@ CVE-2026-71291 (Bolt CMS renders content field values through Twig's full applic
CVE-2026-71289 (The NASA-AMMOS Asynchronous Network Management System (ANMS) reference ...)
NOT-FOR-US: NASA-AMMOS
CVE-2026-71288 (Koha's guided report builder (reports/guided_reports.pl) reads the CGI ...)
- NOT-FOR-US: Koha Library Management System
+ - koha <itp> (bug #702134)
CVE-2026-71287 (Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplie ...)
- cacti <undetermined>
TODO: check, assigned from "Turan Security" CNA without further detailed references
@@ -7724,15 +7724,15 @@ CVE-2026-70471 (Flowise is a drag-and-drop user interface for building customize
CVE-2026-70470 (Flowise is a drag & drop user interface to build a customized large la ...)
NOT-FOR-US: Flowise
CVE-2026-70373 (Koha's reports/issues_stats.pl (the circulation statistics report) bui ...)
- NOT-FOR-US: Koha Library Management System
+ - koha <itp> (bug #702134)
CVE-2026-70372 (Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate b ...)
- NOT-FOR-US: Koha Library Management System
+ - koha <itp> (bug #702134)
CVE-2026-70371 (Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate ...)
- NOT-FOR-US: Koha Library Management System
+ - koha <itp> (bug #702134)
CVE-2026-70370 (Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate ...)
- NOT-FOR-US: Koha Library Management System
+ - koha <itp> (bug #702134)
CVE-2026-70369 (Koha's reports/acquisitions_stats.pl builds its per-cell statistics qu ...)
- NOT-FOR-US: Koha Library Management System
+ - koha <itp> (bug #702134)
CVE-2026-70368 (A stack-based out-of-bounds read vulnerability exists in the "s_vlog" ...)
- stunnel 3:5.80-1
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462029
@@ -40295,11 +40295,11 @@ CVE-2026-52780 (OpenProject is open-source, web-based project management softwar
CVE-2026-52779 (OpenProject is open-source, web-based project management software. Pri ...)
NOT-FOR-US: OpenProject
CVE-2026-50767 (A stored cross-site scripting (XSS) vulnerability in the item type adm ...)
- NOT-FOR-US: Koha Library Management System
+ - koha <itp> (bug #702134)
CVE-2026-50766 (A stored cross-site scripting (XSS) vulnerability in the OPAC item det ...)
- NOT-FOR-US: Koha Library Management System
+ - koha <itp> (bug #702134)
CVE-2026-50765 (A stored cross-site scripting (XSS) vulnerability in the patron restri ...)
- NOT-FOR-US: Koha Library Management System
+ - koha <itp> (bug #702134)
CVE-2026-50137 (Budibase is an open-source low-code platform. Prior to 3.39.0, an anon ...)
NOT-FOR-US: Budibase
CVE-2026-50136 (Budibase is an open-source low-code platform. Prior to 3.39.3, the app ...)
@@ -197018,7 +197018,7 @@ CVE-2025-52447 (Authorization Bypass Through User-Controlled Key vulnerability i
CVE-2025-52446 (Authorization Bypass Through User-Controlled Key vulnerability in Sale ...)
NOT-FOR-US: Salesforce
CVE-2025-52360 (A Cross-Site Scripting (XSS) vulnerability exists in the OPAC search f ...)
- NOT-FOR-US: Koha Library Management System
+ - koha <itp> (bug #702134)
CVE-2025-51411 (A reflected cross-site scripting (XSS) vulnerability exists in Institu ...)
NOT-FOR-US: Institute-of-Current-Students
CVE-2025-46199 (Cross Site Scripting vulnerability in grav v.1.7.48 and before allows ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/86bad094fc6573ad07b461979fc0448f4d1fd88b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/86bad094fc6573ad07b461979fc0448f4d1fd88b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260811/35a4decd/attachment.htm>
More information about the debian-security-tracker-commits
mailing list