[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Sep 2 10:09:34 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ddae56f6 by Moritz Muehlenhoff at 2026-09-02T11:08:57+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1469,39 +1469,39 @@ CVE-2026-75921 (The Master Addons for Elementor \u2013 Elementor Addons, Widgets
 CVE-2026-75865 (The WPLP Cookie Consent \u2013 Cookie Banner & Consent Management for  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-75594 (Kirby is an open-source content management system. Prior to 4.9.5 and  ...)
-	TODO: check
+	NOT-FOR-US: Kirby CMS
 CVE-2026-75592 (Kirby is an open-source content management system. Prior to 4.9.5 and  ...)
-	TODO: check
+	NOT-FOR-US: Kirby CMS
 CVE-2026-75460 (XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation v ...)
-	TODO: check
+	NOT-FOR-US: XueZhiSi Open Source Exam System
 CVE-2026-75458 (The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhi ...)
-	TODO: check
+	NOT-FOR-US: XueZhiSi Open Source Exam System
 CVE-2026-74837 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
 	TODO: check
 CVE-2026-71415 (Kirby is an open-source content management system. From 5.0.0 until 5. ...)
-	TODO: check
+	NOT-FOR-US: Kirby CMS
 CVE-2026-67395 (A path traversal vulnerability exists in Sage Employee Self Service\u2 ...)
 	TODO: check
 CVE-2026-67394 (A critical local privilege escalation via OS command injection vulnera ...)
 	TODO: check
 CVE-2026-65643 (Eval injection in cPanel 11.138.0.0 and earlier allows remote authenti ...)
-	TODO: check
+	NOT-FOR-US: cPanel
 CVE-2026-62993 (Smarty is a template engine for PHP, facilitating the separation of pr ...)
 	TODO: check
 CVE-2026-61641 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
-	TODO: check
+	NOT-FOR-US: Wallos
 CVE-2026-61640 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
-	TODO: check
+	NOT-FOR-US: Wallos
 CVE-2026-61639 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
-	TODO: check
+	NOT-FOR-US: Wallos
 CVE-2026-61638 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
-	TODO: check
+	NOT-FOR-US: Wallos
 CVE-2026-54600 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
-	TODO: check
+	NOT-FOR-US: Wallos
 CVE-2026-54599 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
-	TODO: check
+	NOT-FOR-US: Wallos
 CVE-2026-54598 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
-	TODO: check
+	NOT-FOR-US: Wallos
 CVE-2026-54179 (backpack/crud provides Create, Read, Update & Delete (CRUD) functions  ...)
 	TODO: check
 CVE-2026-52730 (Xibo is an open source digital signage platform with a web content man ...)
@@ -1527,9 +1527,9 @@ CVE-2026-51732 (Incorrect access control in the delWiFiScheduleCfg function of T
 CVE-2026-51731 (Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1 ...)
 	NOT-FOR-US: TOTOLINK
 CVE-2026-50199 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
-	TODO: check
+	NOT-FOR-US: Wallos
 CVE-2026-50198 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
-	TODO: check
+	NOT-FOR-US: Wallos
 CVE-2026-4560
 	REJECTED
 CVE-2026-48932 (A flaw in Node.js HTTP client can cause a request desynchronization fo ...)
@@ -1822,15 +1822,15 @@ CVE-2026-76983 (Improper neutralization of input during web page generation in A
 CVE-2026-76982 (Improper neutralization of input during web page generation in Apache  ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-76763 (A flaw was found in SmallRye GraphQL. The number scalar coercion for B ...)
-	TODO: check
+	NOT-FOR-US: SmallRye GraphQL
 CVE-2026-76133 (The affectedEbyte   product  uses a deprecated hashing algorithm in an ...)
 	NOT-FOR-US: Ebyte
 CVE-2026-75802 (AjaxEditableChoiceLabel in wicket-extensions, when constructed with a  ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-75133 (Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensiti ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-75132 (WAPT Server versions 2.6.1.17834 and earlier contains a SQL injection  ...)
-	TODO: check
+	NOT-FOR-US: WAPT Server
 CVE-2026-74010 (Missing Authorization vulnerability in John James Jacoby bbPress allow ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73819 (The affectedEbyte   product's vendor configuration utility permits acc ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ddae56f632d12c739ae4fcd65fef9ffdcfdad97f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ddae56f632d12c739ae4fcd65fef9ffdcfdad97f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260902/cdbe7cdf/attachment.htm>


More information about the debian-security-tracker-commits mailing list