[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 16 07:45:24 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e8781b77 by Salvatore Bonaccorso at 2026-09-16T08:45:02+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -280,31 +280,31 @@ CVE-2026-89308 (An unauthenticated OS command injection vulnerability exists in
 CVE-2026-89307 (The "Firma Circolare" feature in the "Design Scuole Italia" WordPress  ...)
 	NOT-FOR-US: WordPress theme
 CVE-2026-89026 (The Issabel Framework, the web framework supporting Issabel PBX softwa ...)
-	TODO: check
+	NOT-FOR-US: Issabel Framework
 CVE-2026-89025 (Hirschmann HiOS Switch Platform devices contain a denial-of-service vu ...)
-	TODO: check
+	NOT-FOR-US: Hirschmann HiOS Switch Platform devices
 CVE-2026-89022 (BookStack before 26.05.5 contains an authentication bypass vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: BookStack
 CVE-2026-88765 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-88621 (OneNav v1.2.4 contains an authenticated arbitrary file deletion vulner ...)
-	TODO: check
+	NOT-FOR-US: OneNav
 CVE-2026-88620 (SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper  ...)
-	TODO: check
+	NOT-FOR-US: SmartAdmin API Java17 SpringBoot3
 CVE-2026-88619 (1024-lab SmartAdmin v3.30.0 contains a missing authorization vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: 1024-lab SmartAdmin
 CVE-2026-88618 (1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vul ...)
-	TODO: check
+	NOT-FOR-US: 1024-lab SmartAdmin
 CVE-2026-88617 (SmartAdmin v3.30.0 contains an authorization flaw in the configuration ...)
-	TODO: check
+	NOT-FOR-US: 1024-lab SmartAdmin
 CVE-2026-88616 (An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute a ...)
-	TODO: check
+	NOT-FOR-US: RuoYi-Vue-Plus
 CVE-2026-87793 (The "Design Scuole Italia" WordPress theme is affected by a Reflected  ...)
-	TODO: check
+	NOT-FOR-US: WordPress theme
 CVE-2026-87792 (The "Design Scuole Italia" WordPress theme is affected by multiple Aut ...)
-	TODO: check
+	NOT-FOR-US: WordPress theme
 CVE-2026-87791 (A path traversal vulnerability exists in the reserved_file_check funct ...)
-	TODO: check
+	NOT-FOR-US: WordPress theme
 CVE-2026-87730
 	REJECTED
 CVE-2026-86818 (fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by ...)
@@ -1508,7 +1508,7 @@ CVE-2026-86870 (A heap buffer overflow was addressed with improved bounds checki
 CVE-2026-86869 (An out-of-bounds write issue was addressed with improved bounds checki ...)
 	NOT-FOR-US: Apple
 CVE-2026-86701 (Android application "ManabiPocket for Parents" contains an improper ac ...)
-	TODO: check
+	NOT-FOR-US: Android application "ManabiPocket for Parents"
 CVE-2026-85657 (The Co-Authors, Multiple Authors and Guest Authors in an Author Box wi ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-85575 (The ShopEngine Elementor WooCommerce Builder Addon \u2013 All in One W ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e8781b77065e3f18184fe6d9e637433b30075f5d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e8781b77065e3f18184fe6d9e637433b30075f5d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/1dc56585/attachment.htm>


More information about the debian-security-tracker-commits mailing list