[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 22 15:48:51 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2e7b6083 by Salvatore Bonaccorso at 2026-09-22T16:48:27+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -209,51 +209,51 @@ CVE-2026-88806 (A malicious X server could exploit a buffer overflow in libX11 b
 CVE-2026-88788 (The Text Styler WordPress plugin through 1.1.1 does not sanitise and e ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-88756 (Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQ ...)
-	TODO: check
+	NOT-FOR-US: Pagekit CMS
 CVE-2026-88746 (idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/mak ...)
-	TODO: check
+	NOT-FOR-US: idccms
 CVE-2026-88745 (EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers t ...)
-	TODO: check
+	NOT-FOR-US: EMLOG Pro
 CVE-2026-88738 (Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upl ...)
-	TODO: check
+	NOT-FOR-US: Jazzware RT1000 Edge webUI
 CVE-2026-88467 (CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verif ...)
-	TODO: check
+	NOT-FOR-US: CRMEB Knowledge-Paid System
 CVE-2026-88412 (An integer overflow in the _BulkInsert_ReadProperty component (/bulk_i ...)
-	TODO: check
+	NOT-FOR-US: FalkorDB
 CVE-2026-88411 (Improper error handling in the GRAPH.EFFECT component (/effects/effect ...)
-	TODO: check
+	NOT-FOR-US: FalkorDB
 CVE-2026-88410 (The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not reg ...)
-	TODO: check
+	NOT-FOR-US: FalkorDB
 CVE-2026-88409 (FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a ...)
-	TODO: check
+	NOT-FOR-US: FalkorDB
 CVE-2026-88408 (FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a ...)
-	TODO: check
+	NOT-FOR-US: FalkorDB
 CVE-2026-88407 (An out-of-bounds read in the node_token_count/relation_token_count com ...)
-	TODO: check
+	NOT-FOR-US: FalkorDB
 CVE-2026-88406 (FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a ...)
-	TODO: check
+	NOT-FOR-US: FalkorDB
 CVE-2026-88405 (A remote code execution (RCE) vulnerability in the RemoteRegisterFunct ...)
 	TODO: check
 CVE-2026-88404 (A remote code execution (RCE) vulnerability in the UniscriptExecutionS ...)
 	TODO: check
 CVE-2026-88403 (A Server-Side Request Forgery (SSRF) in the serverRequest function of  ...)
-	TODO: check
+	NOT-FOR-US: nocobase
 CVE-2026-88402 (A SQL injection vulnerability in the checkSQL function of nocobase v2. ...)
-	TODO: check
+	NOT-FOR-US: nocobase
 CVE-2026-87858 (Temporal Server decided whether a Workflow completion callback was int ...)
-	TODO: check
+	NOT-FOR-US: Temporal Server
 CVE-2026-86802 (The To Do List Member WordPress plugin through 1.6 does not have autho ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-86473 (Apache Airflow: the Core API logout endpoint revokes only a session to ...)
 	- airflow <itp> (bug #819700)
 CVE-2026-85751 (Mailu is a mail server distributed as a set of Docker images. From Mai ...)
-	TODO: check
+	NOT-FOR-US: Mailu
 CVE-2026-85653 (The Contextual Related Posts plugin for WordPress is vulnerable to Sto ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-85220 (A vulnerability in the Thinkst Canary honeypot Redis service allows an ...)
-	TODO: check
+	NOT-FOR-US: Thinkst Canary honeypot Redis service
 CVE-2026-85219 (Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 ...)
-	TODO: check
+	NOT-FOR-US: OpenCanary
 CVE-2026-85113 (The GiveWP WordPress plugin before 4.16.9 does not remove shortcode de ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-85010 (The RestroPress WordPress plugin before 3.4.6 does not validate a clie ...)
@@ -261,7 +261,7 @@ CVE-2026-85010 (The RestroPress WordPress plugin before 3.4.6 does not validate
 CVE-2026-84990 (ntopng is a web-based network traffic monitoring application. Prior to ...)
 	TODO: check
 CVE-2026-84298 (Hatchet is a platform for orchestrating background tasks, AI agents, a ...)
-	TODO: check
+	NOT-FOR-US: Hatchet
 CVE-2026-84285 (An OS Command Injection vulnerability affecting Tuleap Enterprise Edit ...)
 	NOT-FOR-US: Dassault Systemes
 CVE-2026-83621 (ntopng is a web-based network traffic monitoring application. Prior to ...)
@@ -279,23 +279,23 @@ CVE-2026-81469 (Dell Inventory Collector Client, versions prior to 15.0.0, conta
 CVE-2026-79920 (Ajenti is a Linux & BSD modular server admin panel. Prior to version 2 ...)
 	TODO: check
 CVE-2026-79919 (MaxKB is an open-source AI assistant for enterprise. Prior to version  ...)
-	TODO: check
+	NOT-FOR-US: MaxKB
 CVE-2026-79918 (MaxKB is an open-source AI assistant for enterprise. Prior to version  ...)
-	TODO: check
+	NOT-FOR-US: MaxKB
 CVE-2026-79917 (MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through  ...)
-	TODO: check
+	NOT-FOR-US: MaxKB
 CVE-2026-79916 (MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-l ...)
-	TODO: check
+	NOT-FOR-US: MaxKB
 CVE-2026-79320 (Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vu ...)
-	TODO: check
+	NOT-FOR-US: Stencil
 CVE-2026-79319 (Stencil core 4.43.5 is vulnerable to Incorrect Access Control.)
-	TODO: check
+	NOT-FOR-US: Stencil
 CVE-2026-79318 (web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d)  ...)
 	TODO: check
 CVE-2026-79317 (A session invalidation flaw exists in x-ui 0.3.2. The full user object ...)
-	TODO: check
+	NOT-FOR-US: x-ui
 CVE-2026-79316 (An improper access control vulnerability exists in x-ui 0.3.2. Any aut ...)
-	TODO: check
+	NOT-FOR-US: x-ui
 CVE-2026-79079 (An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execu ...)
 	- xiphos 4.4.0+dfsg1-1
 	NOTE: https://github.com/crosswire/xiphos/pull/1314



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2e7b60831e7dba7afe081bed3982bb8224486c9a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2e7b60831e7dba7afe081bed3982bb8224486c9a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/5cb56f36/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list