[Git][security-tracker-team/security-tracker][master] Process some more NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 13 09:24:20 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
55301f61 by Salvatore Bonaccorso at 2026-08-13T10:23:53+02:00
Process some more NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -49,85 +49,85 @@ CVE-2026-73418 (NextAuth.js provides authentication for Next.js. Prior to @auth/
CVE-2026-73415 (jupyterlab is an extensible environment for interactive and reproducib ...)
TODO: check
CVE-2026-73414 (Shescape is a simple shell escape library for JavaScript. Prior to 2.1 ...)
- TODO: check
+ NOT-FOR-US: Shescape
CVE-2026-73413 (Shescape is a simple shell escape library for JavaScript. From 2.1.11 ...)
- TODO: check
+ NOT-FOR-US: Shescape
CVE-2026-73412 (Shescape is a simple shell escape library for JavaScript. Prior to 2.1 ...)
- TODO: check
+ NOT-FOR-US: Shescape
CVE-2026-73411 (Shescape is a simple shell escape library for JavaScript. Prior to 2.1 ...)
- TODO: check
+ NOT-FOR-US: Shescape
CVE-2026-73409 (Budibase is an open-source low-code platform. Prior to 3.40.1, package ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-73407 (Budibase is an open-source low-code platform. Prior to 3.40.1, RestInt ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-73406 (Budibase is an open-source low-code platform. Prior to 3.39.32, GET /a ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-73332 (CamaleonCMS contains a stored cross-site scripting vulnerability in th ...)
- TODO: check
+ NOT-FOR-US: CamaleonCMS
CVE-2026-73331 (CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: CamaleonCMS
CVE-2026-73330 (CamaleonCMS 2.9.1 contains a server-side template injection vulnerabil ...)
- TODO: check
+ NOT-FOR-US: CamaleonCMS
CVE-2026-73329 (CamaleonCMS contains a stored cross-site scripting vulnerability that ...)
- TODO: check
+ NOT-FOR-US: CamaleonCMS
CVE-2026-73326 (CamaleonCMS contains a missing authorization vulnerability that allows ...)
- TODO: check
+ NOT-FOR-US: CamaleonCMS
CVE-2026-73308 (Budibase is an open-source low-code platform. Prior to 3.39.25, packag ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-73307 (Budibase is an open-source low-code platform. Prior to 3.39.4, uploadU ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-73306 (Budibase is an open-source low-code platform. Prior to 3.39.25, POST / ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-73303 (Budibase is an open-source low-code platform. Prior to 3.40.0, POST /a ...)
- TODO: check
+ NOT-FOR-US: Budibase
CVE-2026-73269 (A flaw was found in the cluster-curator-controller component. A local ...)
TODO: check
CVE-2026-73268 (A flaw was found in the cluster-curator-controller component of multic ...)
TODO: check
CVE-2026-72809 (SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authenticatio ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72808 (SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain a ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72807 (SiYuan versions before v3.7.4 contain a second-order SQL injection vul ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72806 (SiYuan versions before v3.7.4 contain an authentication bypass vulnera ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72805 (SiYuan versions before v3.7.4 fail to enforce publish-access checks on ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72804 (SiYuan versions before v3.7.4 fail to validate publish-password tier i ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72803 (SiYuan versions before v3.7.4 fail to enforce publish-access checks in ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72802 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72801 (SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivati ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72800 (SiYuan versions before v3.7.4 fail to apply publish-access filtering t ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72799 (SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-acce ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72798 (SiYuan versions before v3.7.4 fail to properly filter related-database ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72797 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72796 (SiYuan before v3.7.4 contains an access control bypass vulnerability w ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72795 (SiYuan versions before v3.7.4 fail to filter embedded block content by ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72794 (siyuan versions before v3.7.4 expose the session cookie signing key th ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72793 (SiYuan versions before v3.7.4 fail to mask sensitive configuration fie ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72792 (SiYuan before v3.7.4 contains an information disclosure vulnerability ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72791 (SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not exist in s ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72790 (SiYuan before v3.7.4 contains an information disclosure vulnerability ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72789 (SiYuan before v3.7.4 fails to properly validate publish access for enc ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72788 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-72787 (Craft CMS versions before 5.10.8 contain a stored cross-site scripting ...)
NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-72786 (Craft CMS versions before 5.10.8 contain an authentication bypass vuln ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/55301f61592194bfbf59ccbd320da9c74564067a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/55301f61592194bfbf59ccbd320da9c74564067a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260813/ee6bbb7a/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list