[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 23 21:52:03 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0f20cdc6 by Salvatore Bonaccorso at 2026-07-23T22:51:35+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5,22 +5,22 @@ CVE-2026-9713 (The Lumise Product Designer for WooCommerce plugin for WordPress
 CVE-2026-9635 (The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-8287 (Allocation of resources without limits or throttling vulnerability in  ...)
-	TODO: check
+	NOT-FOR-US: Online Pre-Accounting Software
 CVE-2026-6516 (Zohocorp ManageEngine ADAudit Plus versionsbefore 8606 are affected by ...)
 	NOT-FOR-US: Zoho
 CVE-2026-65920 (Diffusers through 0.39.0, fixed in commit cee298c, contains a path tra ...)
-	TODO: check
+	NOT-FOR-US: Diffusers
 CVE-2026-65919 (Meshery before 1.0.57 contains an unauthenticated arbitrary file read  ...)
-	TODO: check
+	NOT-FOR-US: Meshery
 CVE-2026-65918 (PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains  ...)
 	- pytorch-vision <unfixed>
 	NOTE: https://github.com/pytorch/vision/issues/9551
 	NOTE: https://github.com/pytorch/vision/pull/9520
 	NOTE: Fixed by: https://github.com/pytorch/vision/commit/4e05dc22f5f050a9528cc0ea09ceca6cdaf8f4ed
 CVE-2026-65917 (CyberPanel through 1.9.1, fixed in commit b198460, contains an insecur ...)
-	TODO: check
+	NOT-FOR-US: CyberPanel
 CVE-2026-65916 (CyberPanel through 1.9.1, fixed in commit b198460, contains a missing  ...)
-	TODO: check
+	NOT-FOR-US: CyberPanel
 CVE-2026-65914 (DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sani ...)
 	- node-dompurify 3.3.2+dfsg-1
 	NOTE: https://github.com/cure53/DOMPurify/security/advisories/GHSA-h8r8-wccr-v5f2
@@ -62,11 +62,11 @@ CVE-2026-65898 (DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlis
 	- node-dompurify 3.4.12+dfsg-1
 	NOTE: https://github.com/cure53/DOMPurify/security/advisories/GHSA-cmwh-pvxp-8882
 CVE-2026-65897 (Grav API Plugin versions before 1.0.10 fail to validate the groups fie ...)
-	TODO: check
+	NOT-FOR-US: Grav API Plugin
 CVE-2026-65896 (Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0. ...)
-	TODO: check
+	NOT-FOR-US: Grav API Plugin
 CVE-2026-65895 (Grav API Plugin versions before 1.0.10 fail to restrict write access t ...)
-	TODO: check
+	NOT-FOR-US: Grav API Plugin
 CVE-2026-65763 (Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Map ...)
 	NOT-FOR-US: Joomla
 CVE-2026-65762 (Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Gue ...)
@@ -92,37 +92,37 @@ CVE-2026-65713 (Joomla Extension - regularlabs.com - Insecure path handling in M
 CVE-2026-65712 (Joomla Extension - regularlabs.com - Insecure path handling in CDN for ...)
 	NOT-FOR-US: Joomla
 CVE-2026-65702 (Vanna through 2.0.2 contains a path traversal vulnerability in the Fil ...)
-	TODO: check
+	NOT-FOR-US: Vanna
 CVE-2026-65701 (SoftVC VITS Singing Voice Conversion through commit 730930d contains a ...)
-	TODO: check
+	NOT-FOR-US: SoftVC VITS Singing Voice Conversion
 CVE-2026-65700 (h2oGPT through 0.2.1 contains a path traversal vulnerability in the Op ...)
-	TODO: check
+	NOT-FOR-US: h2oGPT
 CVE-2026-65699 (AgentGPT through 1.0.0 contains an authorization bypass through user-c ...)
-	TODO: check
+	NOT-FOR-US: AgentGPT
 CVE-2026-65698 (Void through 1.3.4 contains a path traversal vulnerability in the AI a ...)
-	TODO: check
+	NOT-FOR-US: Void
 CVE-2026-65697 (Fathom Lite through 1.3.1 contains a stored cross-site scripting vulne ...)
-	TODO: check
+	NOT-FOR-US: Fathom Lite
 CVE-2026-65696 (Overseerr through 1.35.0 contains an authorization bypass through user ...)
-	TODO: check
+	NOT-FOR-US: Overseerr
 CVE-2026-65695 (Office-Word-MCP-Server through 1.1.11 contains a path traversal vulner ...)
-	TODO: check
+	NOT-FOR-US: Office-Word-MCP-Server
 CVE-2026-65690 (Bold Reports Standalone Report Designer before 14.1.12 contains a miss ...)
-	TODO: check
+	NOT-FOR-US: Bold Reports
 CVE-2026-65689 (Bold Reports Standalone Report Designer before 14.1.12 contains a miss ...)
-	TODO: check
+	NOT-FOR-US: Bold Reports
 CVE-2026-65688 (Bold Reports Standalone Report Designer before 14.1.12 contains a miss ...)
-	TODO: check
+	NOT-FOR-US: Bold Reports
 CVE-2026-65687 (Bold Reports Standalone Report Designer before 14.1.12 contains a miss ...)
-	TODO: check
+	NOT-FOR-US: Bold Reports
 CVE-2026-65608 (Grav versions >= 1.7.0 and before 2.0.9 contain a remote code executio ...)
-	TODO: check
+	NOT-FOR-US: Grav CMS
 CVE-2026-65607 (SiYuan before v3.7.2 contains a path traversal vulnerability in the /e ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-65606 (SiYuan before v3.7.2 contains a cross-site scripting vulnerability in  ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-65605 (SiYuan before v3.7.2 contains a stored cross-site scripting vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-65550 (Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65540 (Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 wit ...)
@@ -292,7 +292,7 @@ CVE-2026-65431 (Joomla Extension - regularlabs.com - Zipslip in GeoIP extension
 CVE-2026-65430 (Joomla Extension - regularlabs.com - MaxMind Credential leakage in Geo ...)
 	NOT-FOR-US: Joomla
 CVE-2026-65010 (Datasets through 5.00, fixed in commit ad2d853, contains a symlink-fol ...)
-	TODO: check
+	NOT-FOR-US: Hugginface Datasets
 CVE-2026-64876 (Joomla Extension - regularlabs.com - Inconsistent CSRF token checks /  ...)
 	NOT-FOR-US: Joomla
 CVE-2026-64875 (Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoI ...)
@@ -340,7 +340,7 @@ CVE-2026-64799 (Joomla Extension - regularlabs.com - SSRF via remote image downl
 CVE-2026-64611 (A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() ...)
 	TODO: check
 CVE-2026-63765 (Chatwoot before 4.16.0 contains an authentication bypass vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Chatwoot
 CVE-2026-61981 (Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Direc ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61973 (Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.)
@@ -368,7 +368,7 @@ CVE-2026-61944 (Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 ver
 CVE-2026-61943 (Unauthenticated Broken Access Control in WPDM \u2013 Premium Packages  ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59678 (An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt  ...)
-	TODO: check
+	NOT-FOR-US: Linux-Gaming PortProtonQt
 CVE-2026-59677 (A Missing Authorization vulnerability in selinux policycoreutils seuns ...)
 	TODO: check
 CVE-2026-59555 (Unauthenticated Arbitrary File Deletion in Participants Database <= 2. ...)
@@ -456,35 +456,35 @@ CVE-2026-57367 (Subscriber Broken Access Control in WP Booking System < 5.12.8.1
 CVE-2026-52684 (If the auth responds very slowly and the records expire in between, th ...)
 	TODO: check
 CVE-2026-48539 (GFI Archiver before 15.13 contains a stored cross-site scripting vulne ...)
-	TODO: check
+	NOT-FOR-US: GFI Archiver
 CVE-2026-48538 (GFI Archiver before 15.13 contains a stored cross-site scripting vulne ...)
-	TODO: check
+	NOT-FOR-US: GFI Archiver
 CVE-2026-48537 (GFI Archiver before 15.13 contains a stored cross-site scripting vulne ...)
-	TODO: check
+	NOT-FOR-US: GFI Archiver
 CVE-2026-48536 (GFI Archiver before 15.13 contains a stored cross-site scripting vulne ...)
-	TODO: check
+	NOT-FOR-US: GFI Archiver
 CVE-2026-48535 (GFI Archiver before 15.13 contains a stored cross-site scripting vulne ...)
-	TODO: check
+	NOT-FOR-US: GFI Archiver
 CVE-2026-48534 (GFI Archiver before 15.13 contains a stored cross-site scripting vulne ...)
-	TODO: check
+	NOT-FOR-US: GFI Archiver
 CVE-2026-48533
 	REJECTED
 CVE-2026-48532 (GFI Archiver before 15.13 contains a stored cross-site scripting vulne ...)
-	TODO: check
+	NOT-FOR-US: GFI Archiver
 CVE-2026-48531 (GFI Archiver before 15.13 contains a stored cross-site scripting vulne ...)
-	TODO: check
+	NOT-FOR-US: GFI Archiver
 CVE-2026-48530 (GFI Archiver before 15.13 contains a stored cross-site scripting vulne ...)
-	TODO: check
+	NOT-FOR-US: GFI Archiver
 CVE-2026-47769 (APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generate ...)
-	TODO: check
+	NOT-FOR-US: APIFold
 CVE-2026-47755 (ITFlow provides an IT documentation, ticketing and accounting system f ...)
-	TODO: check
+	NOT-FOR-US: ITFlow
 CVE-2026-47752 (Tugtainer is a self-hosted app for automating updates of Docker contai ...)
-	TODO: check
+	NOT-FOR-US: Tugtainer
 CVE-2026-47743 (Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three re ...)
-	TODO: check
+	NOT-FOR-US: Shopper
 CVE-2026-47668 (DbGate is cross-platform database manager. In versions 7.1.8 and prior ...)
-	TODO: check
+	NOT-FOR-US: DbGate
 CVE-2026-44909 (Proxygen lacked a generalized slow-consumer detection mechanism in its ...)
 	NOT-FOR-US: Meta software not packaged in Debian
 CVE-2026-44210 (Kata Containers is an open source project focusing on a standard imple ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0f20cdc68cced1d74dacaa598731af1356ac53d6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0f20cdc68cced1d74dacaa598731af1356ac53d6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260723/e08787a6/attachment.htm>


More information about the debian-security-tracker-commits mailing list