[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Sep 2 10:09:34 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ddae56f6 by Moritz Muehlenhoff at 2026-09-02T11:08:57+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1469,39 +1469,39 @@ CVE-2026-75921 (The Master Addons for Elementor \u2013 Elementor Addons, Widgets
CVE-2026-75865 (The WPLP Cookie Consent \u2013 Cookie Banner & Consent Management for ...)
NOT-FOR-US: WordPress plugin
CVE-2026-75594 (Kirby is an open-source content management system. Prior to 4.9.5 and ...)
- TODO: check
+ NOT-FOR-US: Kirby CMS
CVE-2026-75592 (Kirby is an open-source content management system. Prior to 4.9.5 and ...)
- TODO: check
+ NOT-FOR-US: Kirby CMS
CVE-2026-75460 (XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation v ...)
- TODO: check
+ NOT-FOR-US: XueZhiSi Open Source Exam System
CVE-2026-75458 (The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhi ...)
- TODO: check
+ NOT-FOR-US: XueZhiSi Open Source Exam System
CVE-2026-74837 (Allocation of Resources Without Limits or Throttling vulnerability in ...)
TODO: check
CVE-2026-71415 (Kirby is an open-source content management system. From 5.0.0 until 5. ...)
- TODO: check
+ NOT-FOR-US: Kirby CMS
CVE-2026-67395 (A path traversal vulnerability exists in Sage Employee Self Service\u2 ...)
TODO: check
CVE-2026-67394 (A critical local privilege escalation via OS command injection vulnera ...)
TODO: check
CVE-2026-65643 (Eval injection in cPanel 11.138.0.0 and earlier allows remote authenti ...)
- TODO: check
+ NOT-FOR-US: cPanel
CVE-2026-62993 (Smarty is a template engine for PHP, facilitating the separation of pr ...)
TODO: check
CVE-2026-61641 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
- TODO: check
+ NOT-FOR-US: Wallos
CVE-2026-61640 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
- TODO: check
+ NOT-FOR-US: Wallos
CVE-2026-61639 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
- TODO: check
+ NOT-FOR-US: Wallos
CVE-2026-61638 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
- TODO: check
+ NOT-FOR-US: Wallos
CVE-2026-54600 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
- TODO: check
+ NOT-FOR-US: Wallos
CVE-2026-54599 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
- TODO: check
+ NOT-FOR-US: Wallos
CVE-2026-54598 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
- TODO: check
+ NOT-FOR-US: Wallos
CVE-2026-54179 (backpack/crud provides Create, Read, Update & Delete (CRUD) functions ...)
TODO: check
CVE-2026-52730 (Xibo is an open source digital signage platform with a web content man ...)
@@ -1527,9 +1527,9 @@ CVE-2026-51732 (Incorrect access control in the delWiFiScheduleCfg function of T
CVE-2026-51731 (Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1 ...)
NOT-FOR-US: TOTOLINK
CVE-2026-50199 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
- TODO: check
+ NOT-FOR-US: Wallos
CVE-2026-50198 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
- TODO: check
+ NOT-FOR-US: Wallos
CVE-2026-4560
REJECTED
CVE-2026-48932 (A flaw in Node.js HTTP client can cause a request desynchronization fo ...)
@@ -1822,15 +1822,15 @@ CVE-2026-76983 (Improper neutralization of input during web page generation in A
CVE-2026-76982 (Improper neutralization of input during web page generation in Apache ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-76763 (A flaw was found in SmallRye GraphQL. The number scalar coercion for B ...)
- TODO: check
+ NOT-FOR-US: SmallRye GraphQL
CVE-2026-76133 (The affectedEbyte product uses a deprecated hashing algorithm in an ...)
NOT-FOR-US: Ebyte
CVE-2026-75802 (AjaxEditableChoiceLabel in wicket-extensions, when constructed with a ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-75133 (Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensiti ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-75132 (WAPT Server versions 2.6.1.17834 and earlier contains a SQL injection ...)
- TODO: check
+ NOT-FOR-US: WAPT Server
CVE-2026-74010 (Missing Authorization vulnerability in John James Jacoby bbPress allow ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-73819 (The affectedEbyte product's vendor configuration utility permits acc ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ddae56f632d12c739ae4fcd65fef9ffdcfdad97f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ddae56f632d12c739ae4fcd65fef9ffdcfdad97f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260902/cdbe7cdf/attachment.htm>
More information about the debian-security-tracker-commits
mailing list