[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 24 08:57:27 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
f939d584 by Moritz Muehlenhoff at 2026-09-24T09:57:09+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -403,7 +403,7 @@ CVE-2026-91789 (Foxit PDF Editor/Reader\u2019s U3D/GIF texture decoding path con
CVE-2026-91788 (When implementing the JavaScript interface, Foxit PDF Editor/Reader di ...)
NOT-FOR-US: Foxit
CVE-2026-91775 (LimeSurvey fails to safely encode attacker-controlled content from a c ...)
- TODO: check
+ - limesurvey <itp> (bug #472802)
CVE-2026-90950 (The Paid Membership Subscriptions WordPress plugin before 3.1.0 does n ...)
NOT-FOR-US: WordPress plugin
CVE-2026-90905 (Joomla Extension - joomshaper.com - Missing CSRF and Access Control on ...)
@@ -429,7 +429,7 @@ CVE-2026-89004 (The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 do
CVE-2026-89002 (The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not ...)
NOT-FOR-US: WordPress plugin
CVE-2026-88974 (WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-88847 (The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 d ...)
NOT-FOR-US: WordPress plugin
CVE-2026-88846 (The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 d ...)
@@ -513,39 +513,39 @@ CVE-2026-84789 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 1
CVE-2026-84787 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.71 ...)
NOT-FOR-US: Zoho
CVE-2026-84724 (An argument-injection flaw was found in the Ansible Automation Platfor ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-84721 (A server-side request forgery flaw was found in the Ansible Automation ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-84720 (A flaw was found in the Ansible Automation Platform automation-control ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-84719 (A flaw was found in the Ansible Automation Platform automation-control ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-84718 (A flaw was found in the Ansible Automation Platform automation-control ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-84717 (A flaw was found in the Ansible Automation Platform automation-control ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-84716 (A flaw was found in the automation-controller instance ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-84714 (A flaw was found in the automation-controller input-validation ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-84713 (A flaw was found in the automation-controller notification ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-84712 (A flaw was found in the automation-controller API. The ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-84706 (A flaw was found in Ansible Automation Platform's automation-controlle ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-84691 (A flaw was found in Red Hat Ansible Automation Platform's automation- ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-84683 (A flaw was found in Red Hat Ansible Automation Platform's automation- ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-84502 (A flaw was found in Red Hat Ansible Automation Platform's automation- ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-84499 (A flaw was found in Red Hat Ansible Automation Platform's automation- ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-84486 (A flaw was found in Red Hat Ansible Automation Platform's automation- ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-84474 (A flaw was found in Red Hat Ansible Automation Platform's automation- ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-84151 (The Post Grid WordPress plugin before 7.9.5 does not limit an expansi ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84091 (The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0. ...)
@@ -601,15 +601,15 @@ CVE-2026-79616 (Out-of-bounds read while parsing untrusted SVG path strings in Q
CVE-2026-79310 (webpy web.py 0.76 is vulnerable to server-side template injection (SST ...)
TODO: check
CVE-2026-79306 (CyberPanel v1.9.1 contains a path traversal vulnerability in the compr ...)
- TODO: check
+ NOT-FOR-US: CyberPanel
CVE-2026-79304 (CyberPanel 1.9.1 contains a path traversal vulnerability in the readFi ...)
- TODO: check
+ NOT-FOR-US: CyberPanel
CVE-2026-78253 (Uncontrolled recursion in QXmlStreamReader::readElementText() in Qt Gr ...)
TODO: check
CVE-2026-77602 (OpenC3 COSMOS provides the functionality needed to send commands to an ...)
- TODO: check
+ NOT-FOR-US: OpenC3 COSMOS
CVE-2026-77601 (OpenC3 COSMOS provides the functionality needed to send commands to an ...)
- TODO: check
+ NOT-FOR-US: OpenC3 COSMOS
CVE-2026-77423 (JLine is a Java library for handling console input. From 3.0.0 until 3 ...)
TODO: check
CVE-2026-77422 (JLine is a Java library for handling console input. From 3.0.0 until 3 ...)
@@ -619,9 +619,9 @@ CVE-2026-77421 (JLine is a Java library for handling console input. From 3.0.0 u
CVE-2026-77420 (JLine is a Java library for handling console input. From 3.0.0 until 3 ...)
TODO: check
CVE-2026-77394 (OpenC3 COSMOS provides the functionality needed to send commands to an ...)
- TODO: check
+ NOT-FOR-US: OpenC3 COSMOS
CVE-2026-77285 (OpenBao is an open source identity-based secrets management system. Pr ...)
- TODO: check
+ - openbao <itp> (bug #1069794)
CVE-2026-77112 (Server-Side request forgery (SSRF) vulnerability in Global IT Informat ...)
TODO: check
CVE-2026-76980 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.70 ...)
@@ -639,9 +639,9 @@ CVE-2026-76087 (Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23
CVE-2026-76086 (Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3 ...)
NOT-FOR-US: Craft CMS or plugin for Craft CMS
CVE-2026-75887 (A flaw was found in the OpenShift console. An unauthenticated attacker ...)
- TODO: check
+ NOT-FOR-US: OpenShift
CVE-2026-75886 (A flaw was found in openshift/console. An unauthenticated remote attac ...)
- TODO: check
+ NOT-FOR-US: OpenShift
CVE-2026-75884 (A flaw was found in AWX. The container group pod_spec_override field u ...)
TODO: check
CVE-2026-75825 (ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the A ...)
@@ -759,17 +759,17 @@ CVE-2026-66068 (RabbitMQ is a messaging and streaming broker. Prior to versions
CVE-2026-66067 (RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 ...)
TODO: check
CVE-2026-63132 (OpenBao is an open source identity-based secrets management system. Pr ...)
- TODO: check
+ - openbao <itp> (bug #1069794)
CVE-2026-63131 (OpenBao is an open source identity-based secrets management system. Pr ...)
- TODO: check
+ - openbao <itp> (bug #1069794)
CVE-2026-63002 (REDAXO is a PHP-based content management system. Prior to 5.21.2, reda ...)
- TODO: check
+ NOT-FOR-US: REDAXO
CVE-2026-63001 (REDAXO is a PHP-based content management system. Prior to 5.21.2, the ...)
- TODO: check
+ NOT-FOR-US: REDAXO
CVE-2026-63000 (REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_ ...)
- TODO: check
+ NOT-FOR-US: REDAXO
CVE-2026-62998 (REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_ ...)
- TODO: check
+ NOT-FOR-US: REDAXO
CVE-2026-61834 (scim-patch is a library for applying SCIM patch operations. Prior to 0 ...)
TODO: check
CVE-2026-61814 (Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f939d584d563f09eab270c0d2aba59f51869262c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f939d584d563f09eab270c0d2aba59f51869262c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/37d42092/attachment.htm>
More information about the debian-security-tracker-commits
mailing list