[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 17 19:46:06 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
359959ad by Moritz Muehlenhoff at 2026-09-17T20:45:48+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2906,9 +2906,9 @@ CVE-2026-92091 (A flaw was found in jwcrypto. The JWK.import_key() function vali
 CVE-2026-92087 (@fastify/auth is a Fastify plugin that composes multiple authenticatio ...)
 	NOT-FOR-US: Fastify plugin
 CVE-2026-92081 (fastify is a fast and low-overhead web framework for Node.js. In versi ...)
-	TODO: check
+	NOT-FOR-US: Node fastify
 CVE-2026-91939 (Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unseriali ...)
-	TODO: check
+	NOT-FOR-US: Cotonti
 CVE-2026-91843 (A stack overflow during the unauthenticated login process may allow an ...)
 	TODO: check
 CVE-2026-91106 (HP has identified and remediated multiple externally reported vulnerab ...)
@@ -2948,7 +2948,7 @@ CVE-2026-89327 (The FluentBoards  WordPress plugin before 2.0.15 does not verify
 CVE-2026-89207 (A vulnerability has been identified in WTV676-HB6035 Web Interface (Al ...)
 	NOT-FOR-US: Siemens
 CVE-2026-89186 (Use of Cache Containing Sensitive Information in ZenHive mpp allows a  ...)
-	TODO: check
+	NOT-FOR-US: ZenHive mpp
 CVE-2026-89063 (The Online Scheduling and Appointment Booking System \u2013 Bookly plu ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-89040 (Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthe ...)
@@ -2962,9 +2962,9 @@ CVE-2026-89029 (Adenion Blog2Social plugin for WordPress before 9.1.0 allows low
 CVE-2026-89028 (MikroTik RouterOS before 7.24 contains a heap memory corruption vulner ...)
 	NOT-FOR-US: MikroTik
 CVE-2026-89027 (miniOrange JWT Authentication for WP REST APIs plugin for WordPress be ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-88976 (Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, a ...)
-	TODO: check
+	NOT-FOR-US: Plate
 CVE-2026-88975 (Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1. ...)
 	NOT-FOR-US: Http4s
 CVE-2026-88922 (The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to  ...)
@@ -2972,21 +2972,21 @@ CVE-2026-88922 (The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerab
 CVE-2026-88910 (The kboard WordPress plugin before 6.7 does not verify ownership or co ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-88817 (An authenticated, non-guest user of Curiosity Workspace could enroll t ...)
-	TODO: check
+	NOT-FOR-US: Curiosity Workspace
 CVE-2026-88743 (Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting ( ...)
-	TODO: check
+	NOT-FOR-US: Bacularis
 CVE-2026-88742 (Bacularis 1.0.0 - 6.5.0 is vulnerable to Stored cross-site scripting ( ...)
-	TODO: check
+	NOT-FOR-US: Bacularis
 CVE-2026-88593 (kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePre ...)
-	TODO: check
+	NOT-FOR-US: kkFileView
 CVE-2026-88263 (XikeStor Layer3 switches miss authentication for downloading configura ...)
-	TODO: check
+	NOT-FOR-US: XikeStor Layer3 switches
 CVE-2026-88255 (Improper Validation of Unsafe Equivalence in Input in ZenHive mpp allo ...)
-	TODO: check
+	NOT-FOR-US: ZenHive mpp
 CVE-2026-88065 (`tts-be` is a backend for a timetable selector that aims to help stude ...)
-	TODO: check
+	NOT-FOR-US: tts-be
 CVE-2026-88064 (Backstage is an open framework for building developer portals. Prior t ...)
-	TODO: check
+	NOT-FOR-US: Backstage
 CVE-2026-87959 (The WPBot  WordPress plugin before 8.7.6 does not perform a capability ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-87907 (The Rox Appointment Booking  WordPress plugin before 1.2.8 does not pe ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/359959ad88a483f268bfa5b9f9e561ebcf4d0bcc

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/359959ad88a483f268bfa5b9f9e561ebcf4d0bcc
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260917/72a2699c/attachment.htm>


More information about the debian-security-tracker-commits mailing list