[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Sep 16 07:45:24 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e8781b77 by Salvatore Bonaccorso at 2026-09-16T08:45:02+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -280,31 +280,31 @@ CVE-2026-89308 (An unauthenticated OS command injection vulnerability exists in
CVE-2026-89307 (The "Firma Circolare" feature in the "Design Scuole Italia" WordPress ...)
NOT-FOR-US: WordPress theme
CVE-2026-89026 (The Issabel Framework, the web framework supporting Issabel PBX softwa ...)
- TODO: check
+ NOT-FOR-US: Issabel Framework
CVE-2026-89025 (Hirschmann HiOS Switch Platform devices contain a denial-of-service vu ...)
- TODO: check
+ NOT-FOR-US: Hirschmann HiOS Switch Platform devices
CVE-2026-89022 (BookStack before 26.05.5 contains an authentication bypass vulnerabili ...)
- TODO: check
+ NOT-FOR-US: BookStack
CVE-2026-88765 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-88621 (OneNav v1.2.4 contains an authenticated arbitrary file deletion vulner ...)
- TODO: check
+ NOT-FOR-US: OneNav
CVE-2026-88620 (SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper ...)
- TODO: check
+ NOT-FOR-US: SmartAdmin API Java17 SpringBoot3
CVE-2026-88619 (1024-lab SmartAdmin v3.30.0 contains a missing authorization vulnerabi ...)
- TODO: check
+ NOT-FOR-US: 1024-lab SmartAdmin
CVE-2026-88618 (1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vul ...)
- TODO: check
+ NOT-FOR-US: 1024-lab SmartAdmin
CVE-2026-88617 (SmartAdmin v3.30.0 contains an authorization flaw in the configuration ...)
- TODO: check
+ NOT-FOR-US: 1024-lab SmartAdmin
CVE-2026-88616 (An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute a ...)
- TODO: check
+ NOT-FOR-US: RuoYi-Vue-Plus
CVE-2026-87793 (The "Design Scuole Italia" WordPress theme is affected by a Reflected ...)
- TODO: check
+ NOT-FOR-US: WordPress theme
CVE-2026-87792 (The "Design Scuole Italia" WordPress theme is affected by multiple Aut ...)
- TODO: check
+ NOT-FOR-US: WordPress theme
CVE-2026-87791 (A path traversal vulnerability exists in the reserved_file_check funct ...)
- TODO: check
+ NOT-FOR-US: WordPress theme
CVE-2026-87730
REJECTED
CVE-2026-86818 (fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by ...)
@@ -1508,7 +1508,7 @@ CVE-2026-86870 (A heap buffer overflow was addressed with improved bounds checki
CVE-2026-86869 (An out-of-bounds write issue was addressed with improved bounds checki ...)
NOT-FOR-US: Apple
CVE-2026-86701 (Android application "ManabiPocket for Parents" contains an improper ac ...)
- TODO: check
+ NOT-FOR-US: Android application "ManabiPocket for Parents"
CVE-2026-85657 (The Co-Authors, Multiple Authors and Guest Authors in an Author Box wi ...)
NOT-FOR-US: WordPress plugin
CVE-2026-85575 (The ShopEngine Elementor WooCommerce Builder Addon \u2013 All in One W ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e8781b77065e3f18184fe6d9e637433b30075f5d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e8781b77065e3f18184fe6d9e637433b30075f5d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/1dc56585/attachment.htm>
More information about the debian-security-tracker-commits
mailing list