[Git][security-tracker-team/security-tracker][master] auto-nfu: Add rule for Concrete CMS

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Sep 11 10:58:37 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
07085ae1 by Moritz Muehlenhoff at 2026-09-11T11:58:12+02:00
auto-nfu: Add rule for Concrete CMS

- - - - -


2 changed files:

- data/CVE/list
- data/packages/nfu.yaml


Changes:

=====================================
data/CVE/list
=====================================
@@ -239,7 +239,7 @@ CVE-2026-18562 (The HUSKY \u2013 Products Filter Professional for WooCommerce pl
 CVE-2026-18561 (The Unlimited Elements For Elementor plugin for WordPress is vulnerabl ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-18121 (Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass  ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-17176 (An OS command injection vulnerability in the TDDP module of Deco BE110 ...)
 	NOT-FOR-US: TPLink
 CVE-2026-16174 (Netskope was notified about a potential gap in Netskope Endpoint DLP ( ...)
@@ -776,7 +776,7 @@ CVE-2026-73693 (FileRun before 2026.3.0 contains an OS command injection vulnera
 CVE-2026-6285 (Weak Password Recovery Mechanism for Forgotten Password vulnerability  ...)
 	TODO: check
 CVE-2026-68527 (Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to an authori ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-68488 (A Time-of-check Time-of-use (TOCTOU) race condition leading to insecur ...)
 	TODO: check
 CVE-2026-68487 (Path traversal in Plesk's Backup Manager causes arbitrary file write a ...)


=====================================
data/packages/nfu.yaml
=====================================
@@ -77,6 +77,8 @@
   cna: Citrix
 - reason: Commvault
   cna: Commvault
+- reason: Concrete CMS
+  cna: ConcreteCMS
 - reason: ConnectWise
   cna: ConnectWise
 - reason: Crestron



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/07085ae13a8e6ae394c748ac006a1a1e5bfb3b9e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/07085ae13a8e6ae394c748ac006a1a1e5bfb3b9e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260911/099056af/attachment.htm>


More information about the debian-security-tracker-commits mailing list