[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 5 10:58:42 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8ee77df6 by Salvatore Bonaccorso at 2026-09-05T11:58:15+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -403,15 +403,15 @@ CVE-2026-82911 (Cross-Site Request Forgery (CSRF) in the OrderConfirmController
 CVE-2026-82846 (The Masteriyo LMS  WordPress plugin before 3.4.0 does not sanitise and ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-82729 (Inefficient Algorithmic Complexity vulnerability in elixir-mint mint a ...)
-	TODO: check
+	NOT-FOR-US: elixir-mint Mint
 CVE-2026-82728 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
-	TODO: check
+	NOT-FOR-US: elixir-mint Mint
 CVE-2026-82712 (Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerab ...)
-	TODO: check
+	NOT-FOR-US: Tycon Systems TPDIN-Monitor-WEB3
 CVE-2026-82684 (Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerab ...)
-	TODO: check
+	NOT-FOR-US: Tycon Systems TPDIN-Monitor-WEB3
 CVE-2026-82538 (ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection v ...)
-	TODO: check
+	NOT-FOR-US: ILIAS
 CVE-2026-82304 (The Music Store  WordPress plugin before 1.4.5 does not sanitise and e ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-81939 (A Zip Slip vulnerability in the SonicWall Network Security Manager (NS ...)
@@ -433,49 +433,49 @@ CVE-2026-81404 (The IPGP Visitors Origin WordPress plugin before 1.6 does not sa
 CVE-2026-81348 (The My Private Site  WordPress plugin before 4.2.3 does not apply its  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-81302 (PALLET CONTROL products contain an incorrect default permission vulner ...)
-	TODO: check
+	NOT-FOR-US: PALLET CONTROL products
 CVE-2026-80190 (Apache Allura: stored XSS via SVN code repositories. Git repositories  ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-80119 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11. ...)
-	TODO: check
+	NOT-FOR-US: PassMark PerformanceTest
 CVE-2026-80118 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11. ...)
-	TODO: check
+	NOT-FOR-US: PassMark PerformanceTest
 CVE-2026-80117 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11. ...)
-	TODO: check
+	NOT-FOR-US: PassMark PerformanceTest
 CVE-2026-80116 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11. ...)
-	TODO: check
+	NOT-FOR-US: PassMark PerformanceTest
 CVE-2026-80115 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11. ...)
-	TODO: check
+	NOT-FOR-US: PassMark PerformanceTest
 CVE-2026-80114 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11. ...)
-	TODO: check
+	NOT-FOR-US: PassMark PerformanceTest
 CVE-2026-80113 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11. ...)
-	TODO: check
+	NOT-FOR-US: PassMark PerformanceTest
 CVE-2026-80112 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11. ...)
-	TODO: check
+	NOT-FOR-US: PassMark PerformanceTest
 CVE-2026-79707 (A Path Traversal vulnerability in the builder endpoint in Google Cloud ...)
-	TODO: check
+	NOT-FOR-US: adk-python
 CVE-2026-79426 (An arbitrary file deletion vulnerability in the /adminapi/file/video_d ...)
-	TODO: check
+	NOT-FOR-US: CRMEB
 CVE-2026-79423 (An authenticated remote code execution (RCE) vulnerability in the admi ...)
-	TODO: check
+	NOT-FOR-US: seacms
 CVE-2026-79419 (A reflected cross-site scripting (XSS) vulnerability exists in EMX Tec ...)
-	TODO: check
+	NOT-FOR-US: EMX Tecnologia Gestao X Business Suite
 CVE-2026-79418 (EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Sc ...)
-	TODO: check
+	NOT-FOR-US: EMX Tecnologia Gestao X
 CVE-2026-79391 (No authentication exists in the MQTT service of Trueview 6.0.23.4. The ...)
-	TODO: check
+	NOT-FOR-US: Trueview
 CVE-2026-79390 (Trueview TI8161 6.0.23.4 is vulnerable to information disclosure due t ...)
-	TODO: check
+	NOT-FOR-US: Trueview
 CVE-2026-79389 (Trueview T18161 S 6.0.23.4 contains an improper verification in MQTT c ...)
-	TODO: check
+	NOT-FOR-US: Trueview
 CVE-2026-78970 (JeecgBoot 3.9.2 and earlier contains an authorization bypass vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: JeecgBoot
 CVE-2026-78849 (Cross Site Scripting vulnerability in Netgate pfSense Plus software ve ...)
-	TODO: check
+	NOT-FOR-US: Netgate pfSense Plus
 CVE-2026-78839 (An arbitrary file upload vulnerability in AppNitro MachForm v30 allows ...)
-	TODO: check
+	NOT-FOR-US: AppNitro MachForm
 CVE-2026-78745 (An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allow ...)
-	TODO: check
+	NOT-FOR-US: HiDPT/ Weyon HiDPTAndroid
 CVE-2026-78658 (IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 through 7 ...)
 	NOT-FOR-US: IBM
 CVE-2026-78543 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thr ...)
@@ -493,7 +493,7 @@ CVE-2026-78150 (The Smart Post  WordPress plugin before 4.0.8 does not check the
 CVE-2026-78149 (The Smart Post  WordPress plugin before 4.0.8 does not check whether a ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-77847 (Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerab ...)
-	TODO: check
+	NOT-FOR-US: Tycon Systems TPDIN-Monitor-WEB3
 CVE-2026-77830 (The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordP ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-77826 (The RegistrationMagic  WordPress plugin before 6.0.9.9 does not verify ...)
@@ -501,9 +501,9 @@ CVE-2026-77826 (The RegistrationMagic  WordPress plugin before 6.0.9.9 does not
 CVE-2026-77822 (IBM ContextForge MCP Gateway could allow a remote authenticated attack ...)
 	NOT-FOR-US: IBM
 CVE-2026-77818 (Improper neutralization of input during web page generation ('cross-si ...)
-	TODO: check
+	NOT-FOR-US: Yordam Information Technology Consulting, Training and Electronic Systems
 CVE-2026-77393 (In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" s ...)
-	TODO: check
+	NOT-FOR-US: Ignition
 CVE-2026-77263 (The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + m ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-77233 (The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + m ...)
@@ -511,77 +511,77 @@ CVE-2026-77233 (The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Conse
 CVE-2026-76925 (A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) r ...)
 	TODO: check
 CVE-2026-76169 (fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL  ...)
-	TODO: check
+	NOT-FOR-US: fastify
 CVE-2026-75925 (Improper neutralization of CRLF sequences in IXON VPN Client before ve ...)
-	TODO: check
+	NOT-FOR-US: IXON VPN Client
 CVE-2026-75439 (An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial ...)
 	NOT-FOR-US: Free5GC
 CVE-2026-75438 (Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attack ...)
 	TODO: check
 CVE-2026-75431 (PowerJob Server version 5.1.2 (and likely earlier) uses a predictable  ...)
-	TODO: check
+	NOT-FOR-US: PowerJob Server
 CVE-2026-75430 (PowerJob Worker version 5.1.2 (and likely earlier versions) exposes th ...)
-	TODO: check
+	NOT-FOR-US: PowerJob
 CVE-2026-75429 (PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote  ...)
-	TODO: check
+	NOT-FOR-US: PowerJob
 CVE-2026-75171 (An issue in HubCore v.14.1.1 allows a remote attacker to escalate priv ...)
-	TODO: check
+	NOT-FOR-US: HubCore
 CVE-2026-75170 (Cross-site scripting (XSS) vulnerability in the /loginController/doLog ...)
-	TODO: check
+	NOT-FOR-US: HubCore
 CVE-2026-75169 (An arbitrary file upload vulnerability in /cgi-bin/ugwupload.cgi of MB ...)
-	TODO: check
+	NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
 CVE-2026-75168 (An issue in the ugw-editfile method of /cgi-bin/wwwugw.cgi in MBS-Solu ...)
-	TODO: check
+	NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
 CVE-2026-75167 (A broken access control vulnerability in the ugw-usr-edit method of /c ...)
-	TODO: check
+	NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
 CVE-2026-75166 (Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway fir ...)
-	TODO: check
+	NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
 CVE-2026-75165 (An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmw ...)
-	TODO: check
+	NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
 CVE-2026-75164 (An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MB ...)
-	TODO: check
+	NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
 CVE-2026-75163 (An information disclosure vulnerability in the ugw-deviceinfo method o ...)
-	TODO: check
+	NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
 CVE-2026-75162 (An information disclosure vulnerability in the opcua-configuration met ...)
-	TODO: check
+	NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
 CVE-2026-75161 (An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solut ...)
-	TODO: check
+	NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
 CVE-2026-75160 (An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker ...)
-	TODO: check
+	NOT-FOR-US: MBS-Solutions X-Serie Gateway firmware
 CVE-2026-74237 (GFI Exinda AI and ClearView before 7.6.5 contains an argument injectio ...)
-	TODO: check
+	NOT-FOR-US: GFI Exinda AI and ClearView
 CVE-2026-74236 (GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vul ...)
-	TODO: check
+	NOT-FOR-US: GFI Exinda AI and ClearView
 CVE-2026-74235 (GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vul ...)
-	TODO: check
+	NOT-FOR-US: GFI Exinda AI and ClearView
 CVE-2026-73848 (Emlog is an open source website building system. In versions 2.6.29 an ...)
 	NOT-FOR-US: Emlog
 CVE-2026-71626 (An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain  ...)
-	TODO: check
+	NOT-FOR-US: Invoice Ninja
 CVE-2026-71625 (An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to e ...)
-	TODO: check
+	NOT-FOR-US: slimkit plus ThinkSNS+
 CVE-2026-71624 (An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbi ...)
-	TODO: check
+	NOT-FOR-US: esoTalk
 CVE-2026-71622 (SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a r ...)
-	TODO: check
+	NOT-FOR-US: Zhao-github APiAdmin
 CVE-2026-71620 (File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a rem ...)
-	TODO: check
+	NOT-FOR-US: Zhao-github APiAdmin
 CVE-2026-6958 (Acunetix 25.11.251107123 for Windows contains a local privilege escala ...)
-	TODO: check
+	NOT-FOR-US: Acunetix
 CVE-2026-6217 (Use of a One-Way hash without a salt vulnerability in Pik Online Softw ...)
-	TODO: check
+	NOT-FOR-US: Pik Online Portal
 CVE-2026-63464 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN.  ...)
-	TODO: check
+	NOT-FOR-US: nebula-mesh
 CVE-2026-61699 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN.  ...)
-	TODO: check
+	NOT-FOR-US: nebula-mesh
 CVE-2026-61688 (SolidInvoice is an open-source invoicing platform. Prior to version 3. ...)
-	TODO: check
+	NOT-FOR-US: SolidInvoice
 CVE-2026-61686 (SolidInvoice is an open-source invoicing platform. Prior to version 3. ...)
-	TODO: check
+	NOT-FOR-US: SolidInvoice
 CVE-2026-61614 (SolidInvoice is an open-source invoicing platform. Prior to version 3. ...)
-	TODO: check
+	NOT-FOR-US: SolidInvoice
 CVE-2026-61608 (SolidInvoice is an open-source invoicing platform. Prior to version 3. ...)
-	TODO: check
+	NOT-FOR-US: SolidInvoice
 CVE-2026-5522 (IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-code ...)
 	NOT-FOR-US: IBM
 CVE-2026-57777 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
@@ -603,17 +603,17 @@ CVE-2026-57160 (PJSIP is a free and open source multimedia communication library
 CVE-2026-57159 (PJSIP is a free and open source multimedia communication library writt ...)
 	TODO: check
 CVE-2026-55513 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN.  ...)
-	TODO: check
+	NOT-FOR-US: nebula-mesh
 CVE-2026-55512 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN.  ...)
-	TODO: check
+	NOT-FOR-US: nebula-mesh
 CVE-2026-53932 (laravel-backup-restore restores database backups made with spatie/lara ...)
-	TODO: check
+	NOT-FOR-US: laravel-backup-restore
 CVE-2026-53769 (Avo is a framework to create admin panels for Ruby on Rails apps. From ...)
-	TODO: check
+	NOT-FOR-US: Avo
 CVE-2026-53761 (Frappe CRM is an open-source customer relationship management tool. Pr ...)
-	TODO: check
+	NOT-FOR-US: Frappe CRM
 CVE-2026-53760 (Admidio is an open-source user management solution. In versions 5.0.11 ...)
-	TODO: check
+	NOT-FOR-US: Admidio
 CVE-2026-53758 (Emlog is an open source website building system. In versions 2.6.29 an ...)
 	NOT-FOR-US: Emlog
 CVE-2026-53757 (Emlog is an open source website building system. In versions 2.6.29 an ...)
@@ -621,41 +621,41 @@ CVE-2026-53757 (Emlog is an open source website building system. In versions 2.6
 CVE-2026-53756 (Emlog is an open source website building system. Prior to version 2.6. ...)
 	NOT-FOR-US: Emlog
 CVE-2026-53604 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN.  ...)
-	TODO: check
+	NOT-FOR-US: nebula-mesh
 CVE-2026-53603 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN.  ...)
-	TODO: check
+	NOT-FOR-US: nebula-mesh
 CVE-2026-53602 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN.  ...)
-	TODO: check
+	NOT-FOR-US: nebula-mesh
 CVE-2026-52777 (YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there ...)
-	TODO: check
+	NOT-FOR-US: YesWiki
 CVE-2026-52775 (YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWi ...)
-	TODO: check
+	NOT-FOR-US: YesWiki
 CVE-2026-52774 (YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWi ...)
-	TODO: check
+	NOT-FOR-US: YesWiki
 CVE-2026-52773 (YesWiki is a wiki system written in PHP. From version 4.1.0 to before  ...)
-	TODO: check
+	NOT-FOR-US: YesWiki
 CVE-2026-52772 (YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar ...)
-	TODO: check
+	NOT-FOR-US: YesWiki
 CVE-2026-52771 (YesWiki is a wiki system written in PHP. From version 4.2.0 to before  ...)
-	TODO: check
+	NOT-FOR-US: YesWiki
 CVE-2026-52770 (YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWi ...)
-	TODO: check
+	NOT-FOR-US: YesWiki
 CVE-2026-52769 (YesWiki is a wiki system written in PHP. From version 4.6.2 to before  ...)
-	TODO: check
+	NOT-FOR-US: YesWiki
 CVE-2026-52767 (YesWiki is a wiki system written in PHP. From version 4.6.2 to before  ...)
-	TODO: check
+	NOT-FOR-US: YesWiki
 CVE-2026-52766 (YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the { ...)
-	TODO: check
+	NOT-FOR-US: YesWiki
 CVE-2026-52763 (YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the r ...)
-	TODO: check
+	NOT-FOR-US: YesWiki
 CVE-2026-52762 (YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWi ...)
-	TODO: check
+	NOT-FOR-US: YesWiki
 CVE-2026-52691 (** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Ele ...)
 	TODO: check
 CVE-2026-50894 (easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with D ...)
-	TODO: check
+	NOT-FOR-US: easyadmin
 CVE-2026-50553 (Note Mark is an open-source note-taking application. Prior to version  ...)
-	TODO: check
+	NOT-FOR-US: Note Mark
 CVE-2026-4644 (A Missing Authorization vulnerability in HTTP Connector in Google Clou ...)
 	TODO: check
 CVE-2026-4361 (The Divi theme for WordPress is vulnerable to Server-Side Request Forg ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8ee77df6b9a7ce0fbfdcc89e1e32174ff575781c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8ee77df6b9a7ce0fbfdcc89e1e32174ff575781c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/fb8d51ac/attachment.htm>


More information about the debian-security-tracker-commits mailing list