[Git][security-tracker-team/security-tracker][master] Add new jspwiki issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 30 21:34:24 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
75f1c174 by Salvatore Bonaccorso at 2026-07-30T22:33:50+02:00
Add new jspwiki issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -93,7 +93,7 @@ CVE-2026-51272 (In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overfl
 CVE-2026-4978 (Improper neutralization of special elements used in an SQL command ('S ...)
 	NOT-FOR-US: Traffic Analysis System
 CVE-2026-48910 (A carefully crafted editing request could trigger an XSS vulnerability ...)
-	TODO: check
+	- jspwiki <removed>
 CVE-2026-48499 (Activepieces is an open source AI workflow automation platform. Prior  ...)
 	NOT-FOR-US: Activepieces
 CVE-2026-47876 (VMware ESX contains an out-of-bounds write vulnerability in the VMXNET ...)
@@ -145,13 +145,13 @@ CVE-2026-41187 (Calico's apiserver wraps tier-scoped resources so that every ope
 CVE-2026-41186 (When Calico's shared debug server is enabled (disabled by default), th ...)
 	NOT-FOR-US: Calico
 CVE-2026-28814 (Arbitrary Wiki Markup rendering due to lack of authentication in Apach ...)
-	TODO: check
+	- jspwiki <removed>
 CVE-2026-28813 (Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which l ...)
-	TODO: check
+	- jspwiki <removed>
 CVE-2026-28812 (UserManager lack of checks allows impersonation in Apache JSPWiki up t ...)
-	TODO: check
+	- jspwiki <removed>
 CVE-2026-28811 (Debug Messages Revealing Unnecessary Information in Apache JSPWiki up  ...)
-	TODO: check
+	- jspwiki <removed>
 CVE-2026-28323 (SolarWinds Web Help Desk is found to be affected by a SAML authenticat ...)
 	NOT-FOR-US: SolarWinds
 CVE-2026-22622 (Improper input validation in one of the session management interface o ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/75f1c174323685e3add54c3c25d29392818144a6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/75f1c174323685e3add54c3c25d29392818144a6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260730/f72108dd/attachment.htm>


More information about the debian-security-tracker-commits mailing list