[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 28 20:54:17 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2089f738 by Salvatore Bonaccorso at 2026-08-28T21:53:53+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -22,17 +22,17 @@ CVE-2026-82324 (A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16584
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/2fba61f28efaebdc170e951e499e42820fbf633a
 CVE-2026-82261 (SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experime ...)
-	TODO: check
+	NOT-FOR-US: SvelteKit
 CVE-2026-82260 (SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experime ...)
-	TODO: check
+	NOT-FOR-US: SvelteKit
 CVE-2026-82259 (SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contai ...)
-	TODO: check
+	NOT-FOR-US: SvelteKit
 CVE-2026-82258 (SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition  ...)
-	TODO: check
+	NOT-FOR-US: SvelteKit
 CVE-2026-82257 (SvelteKit versions before 2.69.1 contain a prototype pollution vulnera ...)
-	TODO: check
+	NOT-FOR-US: SvelteKit
 CVE-2026-82256 (SvelteKit before 2.69.1 fails to properly validate remote form functio ...)
-	TODO: check
+	NOT-FOR-US: SvelteKit
 CVE-2026-82255 (gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerab ...)
 	TODO: check
 CVE-2026-82254 (gitoxide before 0.69.0 contains unchecked array indexing in delta appl ...)
@@ -52,29 +52,29 @@ CVE-2026-82248 (gix-worktree-state before 0.33.0 (part of gitoxide) allows writi
 CVE-2026-82247 (gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-roll ...)
 	TODO: check
 CVE-2026-82246 (Budibase Server before 3.41.3 contains a server-side request forgery v ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-82245 (Budibase before 3.41.3 fails to enforce role-based authorization on li ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-82244 (Budibase versions before 3.41.3 contain a remote code execution vulner ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-82243 (Budibase Server before 3.41.3 contains a server-side request forgery v ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-82242 (Budibase versions before 3.41.3 contain a missing authorization vulner ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-82241 (Budibase backend-core (@budibase/backend-core, as used by @budibase/se ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-82240 (Budibase before 3.41.3 fails to validate app-scoped builder role assig ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-82239 (Budibase before 3.41.3 fails to enforce per-table role restrictions on ...)
-	TODO: check
+	NOT-FOR-US: Budibase
 CVE-2026-82238 (filebrowser from version 2.24.0 contains a race condition in the TUS u ...)
-	TODO: check
+	NOT-FOR-US: filebrowser
 CVE-2026-82237 (filebrowser through 2.63.23 does not remove share records when a share ...)
-	TODO: check
+	NOT-FOR-US: filebrowser
 CVE-2026-82236 (File Browser versions from 2.63.6 through 2.63.23 fail to clean up pub ...)
-	TODO: check
+	NOT-FOR-US: filebrowser
 CVE-2026-82235 (filebrowser through 2.63.23 fails to validate named pipes in directory ...)
-	TODO: check
+	NOT-FOR-US: filebrowser
 CVE-2026-82234 (SiYuan versions before v3.8.1 contain a server-side request forgery vu ...)
 	NOT-FOR-US: SiYuan
 CVE-2026-82233 (SiYuan before v3.8.1 contains a path traversal vulnerability in the as ...)
@@ -86,15 +86,15 @@ CVE-2026-82222 (Deserialization of Untrusted Data vulnerability in Liquid Web /
 CVE-2026-82220 (Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versi ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-82181 (Medical Practice Management System developed by Le-yan has a Sensitive ...)
-	TODO: check
+	NOT-FOR-US: Medical Practice Management System
 CVE-2026-82123 (Improper neutralization of input during web page generation ('cross-si ...)
 	TODO: check
 CVE-2026-82112 (A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impac ...)
-	TODO: check
+	NOT-FOR-US: houtini-ai houtini-lm
 CVE-2026-82111 (A vulnerability was detected in iswalle getnote-mcp up to 1.5.0. The a ...)
-	TODO: check
+	NOT-FOR-US: iswalle getnote-mcp
 CVE-2026-82078 (An unsafe dynamic class loading vulnerability exists in the database c ...)
-	TODO: check
+	NOT-FOR-US: PaperCut
 CVE-2026-81777 (Authentication Bypass by Spoofing vulnerability in WPDeveloper Essenti ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81767 (Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versi ...)
@@ -108,13 +108,13 @@ CVE-2026-81759 (Contributor Broken Access Control in WpEvently <= 5.5.0 versions
 CVE-2026-81757 (Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 version ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81733 (WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a  ...)
-	TODO: check
+	NOT-FOR-US: WWBN AVideo
 CVE-2026-81732 (WWBN AVideo through version 30.0 fails to enforce authentication on th ...)
-	TODO: check
+	NOT-FOR-US: WWBN AVideo
 CVE-2026-81578 (An improper access control vulnerability exists in the web management  ...)
-	TODO: check
+	NOT-FOR-US: PaperCut
 CVE-2026-81341 (wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 ...)
-	TODO: check
+	NOT-FOR-US: wolfEngine
 CVE-2026-81299 (Subscriber Insecure Direct Object References (IDOR) in WP Job Portal < ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81285 (Unauthenticated Denial of Service Attack in Smush Image Compression an ...)
@@ -122,9 +122,9 @@ CVE-2026-81285 (Unauthenticated Denial of Service Attack in Smush Image Compress
 CVE-2026-81284 (Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81020 (wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce on ...)
-	TODO: check
+	NOT-FOR-US: wolfEngine
 CVE-2026-81019 (wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce  ...)
-	TODO: check
+	NOT-FOR-US: wolfProvider
 CVE-2026-79996 (The User Registration & Membership  WordPress plugin before 5.2.6 does ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-79995 (The User Registration & Membership  WordPress plugin before 5.2.5 does ...)
@@ -134,7 +134,7 @@ CVE-2026-79706 (The Breeze Cache WordPress plugin before 2.5.13 does not sanitis
 CVE-2026-79615 (The Quiz and Survey Master (QSM)  WordPress plugin before 11.2.4 does  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-78238 (SOY Gallery  contains a cross-site scripting vulnerability. An arbitra ...)
-	TODO: check
+	NOT-FOR-US: SOY Gallery
 CVE-2026-78073 (Joomla Extension - mrvinoth.com - Reflected XSS in All Video Share 1.0 ...)
 	NOT-FOR-US: Joomla
 CVE-2026-78072 (Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Po ...)
@@ -144,9 +144,9 @@ CVE-2026-78071 (Joomla Extension - digital-peak.com - Authenticated, privileged
 CVE-2026-78070 (Joomla Extension - digital-peak.com - Authenticated, privileged blind  ...)
 	NOT-FOR-US: Joomla
 CVE-2026-78032 (SOY CMS  contains an issue with deserialization of untrusted data. An  ...)
-	TODO: check
+	NOT-FOR-US: SOY CMS
 CVE-2026-77838 (SOY Calendar contains a cross-site scripting vulnerability. An arbitra ...)
-	TODO: check
+	NOT-FOR-US: SOY
 CVE-2026-77701 (The WCFM Marketplace  WordPress plugin before 3.8.2 does not correctly ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-76581 (The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentic ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2089f738fbc8f7685e92bb3df2bcab608acb38a0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2089f738fbc8f7685e92bb3df2bcab608acb38a0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260828/4dca5600/attachment.htm>


More information about the debian-security-tracker-commits mailing list