[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 22 10:17:51 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5fe95bc9 by Salvatore Bonaccorso at 2026-09-22T11:17:25+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -81,7 +81,7 @@ CVE-2026-94394 (When a regular user adds a reference between objects or attribut
 CVE-2026-94393 (When a user creates or edits a report inside an event, MISP can identi ...)
 	- misp <itp> (bug #1144317)
 CVE-2026-94387 (Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnera ...)
-	TODO: check
+	NOT-FOR-US: Aureus ERP
 CVE-2026-94383 (The MISP blocklist workflow module accepted a user-supplied blocklist  ...)
 	- misp <itp> (bug #1144317)
 CVE-2026-94382 (Beszel before 0.19.0 contains an insecure direct object reference vuln ...)
@@ -99,31 +99,31 @@ CVE-2026-94372 (MISP contains a stored cross-site scripting (XSS) vulnerability
 CVE-2026-94277 (MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxy ...)
 	- misp <itp> (bug #1144317)
 CVE-2026-94216 (A vulnerability was determined in ST Engineering iDirect Evolution and ...)
-	TODO: check
+	NOT-FOR-US: ST Engineering iDirect Evolution and Velocity WebServer Evolution
 CVE-2026-94214 (A vulnerability was found in ST Engineering iDirect Evolution and Velo ...)
-	TODO: check
+	NOT-FOR-US: ST Engineering iDirect Evolution and Velocity WebServer Evolution
 CVE-2026-94211 (A vulnerability has been found in Hyve5 Leantime up to 3.9.8. Affected ...)
-	TODO: check
+	NOT-FOR-US: Hyve5 Leantime
 CVE-2026-94210 (A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this  ...)
-	TODO: check
+	NOT-FOR-US: Hyve5 Leantime
 CVE-2026-94152 (A security vulnerability has been detected in Omega Solution FBP Fulfi ...)
-	TODO: check
+	NOT-FOR-US: Omega Solution FBP Fulfillment by People
 CVE-2026-94151 (A weakness has been identified in Omega Solution HRM OS up to 20260717 ...)
-	TODO: check
+	NOT-FOR-US: Omega Solution HRM OS
 CVE-2026-94150 (A security flaw has been discovered in Omega Solution HRM OS up to 202 ...)
-	TODO: check
+	NOT-FOR-US: Omega Solution HRM OS
 CVE-2026-94149 (A vulnerability was identified in Omega Solution HRM OS up to 20260717 ...)
-	TODO: check
+	NOT-FOR-US: Omega Solution HRM OS
 CVE-2026-94148 (A vulnerability was determined in ScadaBR up to 1.1. Impacted is the f ...)
-	TODO: check
+	NOT-FOR-US: ScadaBR
 CVE-2026-93884
 	REJECTED
 CVE-2026-93655 (The Booking Calendar plugin for WordPress is vulnerable to Reflected C ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-93340 (Gladys Assistant before 5.1.0 contains a password reset link poisoning ...)
-	TODO: check
+	NOT-FOR-US: Gladys Assistant
 CVE-2026-93339 (Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a  ...)
-	TODO: check
+	NOT-FOR-US: Metaphor Creations Ditty (ditty-news-ticker)
 CVE-2026-92612 (In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exp ...)
 	TODO: check
 CVE-2026-92438 (The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form ...)
@@ -131,7 +131,7 @@ CVE-2026-92438 (The Ninja Forms WordPress plugin 3.15.3 does not escape submitte
 CVE-2026-92400 (The Payment Gateway for PayPal on WooCommerce WordPress plugin before  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-91921 (Cross-Site Scripting (XSS) vulnerability due to inadequate input sanit ...)
-	TODO: check
+	NOT-FOR-US: 1millionbot AI Chat Platform
 CVE-2026-91867 (When Neethi fetches a remote policy reference, it only limits the time ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-91866 (A specially crafted pair of WS-Policy documents can force Neethi's pol ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5fe95bc912b62a093344a1b2f0f56ca9a8d2f1b4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5fe95bc912b62a093344a1b2f0f56ca9a8d2f1b4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/d92c5a9c/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list