[Git][security-tracker-team/security-tracker][master] Process some more NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 13 09:24:20 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
55301f61 by Salvatore Bonaccorso at 2026-08-13T10:23:53+02:00
Process some more NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -49,85 +49,85 @@ CVE-2026-73418 (NextAuth.js provides authentication for Next.js. Prior to @auth/
 CVE-2026-73415 (jupyterlab is an extensible environment for interactive and reproducib ...)
 	TODO: check
 CVE-2026-73414 (Shescape is a simple shell escape library for JavaScript. Prior to 2.1 ...)
-	TODO: check
+	NOT-FOR-US: Shescape
 CVE-2026-73413 (Shescape is a simple shell escape library for JavaScript. From 2.1.11  ...)
-	TODO: check
+	NOT-FOR-US: Shescape
 CVE-2026-73412 (Shescape is a simple shell escape library for JavaScript. Prior to 2.1 ...)
-	TODO: check
+	NOT-FOR-US: Shescape
 CVE-2026-73411 (Shescape is a simple shell escape library for JavaScript. Prior to 2.1 ...)
-	TODO: check
+	NOT-FOR-US: Shescape
 CVE-2026-73409 (Budibase is an open-source low-code platform. Prior to 3.40.1, package ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-73407 (Budibase is an open-source low-code platform. Prior to 3.40.1, RestInt ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-73406 (Budibase is an open-source low-code platform. Prior to 3.39.32, GET /a ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-73332 (CamaleonCMS contains a stored cross-site scripting vulnerability in th ...)
-	TODO: check
+	NOT-FOR-US: CamaleonCMS
 CVE-2026-73331 (CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: CamaleonCMS
 CVE-2026-73330 (CamaleonCMS 2.9.1 contains a server-side template injection vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: CamaleonCMS
 CVE-2026-73329 (CamaleonCMS contains a stored cross-site scripting vulnerability that  ...)
-	TODO: check
+	NOT-FOR-US: CamaleonCMS
 CVE-2026-73326 (CamaleonCMS contains a missing authorization vulnerability that allows ...)
-	TODO: check
+	NOT-FOR-US: CamaleonCMS
 CVE-2026-73308 (Budibase is an open-source low-code platform. Prior to 3.39.25, packag ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-73307 (Budibase is an open-source low-code platform. Prior to 3.39.4, uploadU ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-73306 (Budibase is an open-source low-code platform. Prior to 3.39.25, POST / ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-73303 (Budibase is an open-source low-code platform. Prior to 3.40.0, POST /a ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-73269 (A flaw was found in the cluster-curator-controller component. A local  ...)
 	TODO: check
 CVE-2026-73268 (A flaw was found in the cluster-curator-controller component of multic ...)
 	TODO: check
 CVE-2026-72809 (SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authenticatio ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72808 (SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain a ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72807 (SiYuan versions before v3.7.4 contain a second-order SQL injection vul ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72806 (SiYuan versions before v3.7.4 contain an authentication bypass vulnera ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72805 (SiYuan versions before v3.7.4 fail to enforce publish-access checks on ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72804 (SiYuan versions before v3.7.4 fail to validate publish-password tier i ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72803 (SiYuan versions before v3.7.4 fail to enforce publish-access checks in ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72802 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72801 (SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivati ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72800 (SiYuan versions before v3.7.4 fail to apply publish-access filtering t ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72799 (SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-acce ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72798 (SiYuan versions before v3.7.4 fail to properly filter related-database ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72797 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72796 (SiYuan before v3.7.4 contains an access control bypass vulnerability w ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72795 (SiYuan versions before v3.7.4 fail to filter embedded block content by ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72794 (siyuan versions before v3.7.4 expose the session cookie signing key th ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72793 (SiYuan versions before v3.7.4 fail to mask sensitive configuration fie ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72792 (SiYuan before v3.7.4 contains an information disclosure vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72791 (SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not exist in s ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72790 (SiYuan before v3.7.4 contains an information disclosure vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72789 (SiYuan before v3.7.4 fails to properly validate publish access for enc ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72788 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-72787 (Craft CMS versions before 5.10.8 contain a stored cross-site scripting ...)
 	NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-72786 (Craft CMS versions before 5.10.8 contain an authentication bypass vuln ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/55301f61592194bfbf59ccbd320da9c74564067a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/55301f61592194bfbf59ccbd320da9c74564067a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260813/ee6bbb7a/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list