[Git][security-tracker-team/security-tracker][master] auto-nfu: Add rulefor Craft CMS
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Jul 2 08:56:25 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
be8778f4 by Moritz Muehlenhoff at 2026-07-02T09:55:53+02:00
auto-nfu: Add rulefor Craft CMS
- - - - -
2 changed files:
- data/CVE/list
- data/packages/nfu.yaml
Changes:
=====================================
data/CVE/list
=====================================
@@ -43,15 +43,15 @@ CVE-2026-57264 (GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentati
CVE-2026-55886 (Jodit Editor is a WYSIWYG editor with written in pure TypeScript file ...)
NOT-FOR-US: Jodit Editor
CVE-2026-55794 (Craft CMS is a content management system (CMS). In versions 5.9.0 and ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-55793 (Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-55792 (Craft CMS is a content management system (CMS). In versions starting f ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-55791 (Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-55790 (Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-55688 (The AsyncHttpClient (AHC) library allows Java applications to easily e ...)
- async-http-client <unfixed>
NOTE: https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-m452-q8c9-rg2f
@@ -97,13 +97,13 @@ CVE-2026-52186 (SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-
CVE-2026-50521 (Use after free in Microsoft Edge (Chromium-based) allows an authorized ...)
NOT-FOR-US: Microsoft
CVE-2026-50284 (Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-50283 (Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 thr ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-50280 (Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-50279 (Craft CMS is a content management system (CMS). IN versions 5.0.0-RC1 ...)
- TODO: check
+ NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-49858 (API Platform Core is a system to create hypermedia-driven REST and Gra ...)
TODO: check
CVE-2026-38891 (An improper input validation in the gazebo_ros_diff_drive.cpp componen ...)
=====================================
data/packages/nfu.yaml
=====================================
@@ -875,12 +875,14 @@
description: '.*\bBelkin\b.*'
- reason: Bento4
description: '.*\bBento4\b.*'
+- reason: Campcodes
+ description: '.*\b(?i:campcodes)\s.*\s(?i:(system|portal))\b.*'
- reason: Chamilo LMS
description: '.*\b(?i:Chamilo LMS)\b.*'
- reason: CodeAstro
description: '.*\b(?i:Code\s?Astro)\s.*\s(?i:(system))\b.*'
-- reason: Campcodes
- description: '.*\b(?i:campcodes)\s.*\s(?i:(system|portal))\b.*'
+- reason: Craft CMS or plugin for Craft CMS
+ description: '.*\b(?i:Craft CMS)\b.*'
- reason: ChurchCRM
description: '.*\b(?i:ChurchCRM)\b.*'
- reason: code-projects
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/be8778f40d0312c49fd76541ae5f42e842b8d5f2
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/be8778f40d0312c49fd76541ae5f42e842b8d5f2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260702/41e3e436/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list