[Git][security-tracker-team/security-tracker][master] auto-nfu: Add CNA entry for PaperCut

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 24 10:42:34 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5d97c428 by Moritz Muehlenhoff at 2026-09-24T11:41:44+02:00
auto-nfu: Add CNA entry for PaperCut

Total CVEs from PaperCut: 28
Total CVEs from PaperCut with packages assigned: 0

Scope: PaperCut MF, PaperCut NG, PaperCut Hive, PaperCut Pocket,
PaperCut Mobility Print, QRdoc, PaperCut Views, PaperCut Multiverse,
https://www.papercut.com, and all other PaperCut products and services

- - - - -


2 changed files:

- data/CVE/list
- data/packages/nfu.yaml


Changes:

=====================================
data/CVE/list
=====================================
@@ -508,7 +508,7 @@ CVE-2026-87898 (OS command injection in Plesk allows remote authenticated users
 CVE-2026-87848 (The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have a ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-87739 (An improper authentication vulnerability in PaperCut MF/NG allows an u ...)
-	TODO: check
+	NOT-FOR-US: PaperCut
 CVE-2026-87071 (The Forminator Forms WordPress plugin before 1.57.2.1 does not restric ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-87070 (The Forminator Forms WordPress plugin before 1.57.2.1 does not verify  ...)
@@ -618,7 +618,7 @@ CVE-2026-82356 (Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key p
 CVE-2026-82195 (The 10Web Booster  WordPress plugin before 2.34.0 does not restrict ac ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-82077 (An improper limitation of a pathname to a restricted directory (path t ...)
-	TODO: check
+	NOT-FOR-US: PaperCut
 CVE-2026-81645 (Out-of-bounds read vulnerability in the graphics module.Successful exp ...)
 	NOT-FOR-US: Huawei
 CVE-2026-81537 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
@@ -908,13 +908,13 @@ CVE-2026-15027 (CGServiSign developed by Changing has a OS Command Injection vul
 CVE-2026-14913 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.66 ...)
 	NOT-FOR-US: Zoho
 CVE-2026-14780 (A vulnerability exists in the PaperCut NG/MF platform's device-scripti ...)
-	TODO: check
+	NOT-FOR-US: PaperCut
 CVE-2026-12974 (A Security Policy Bypass vulnerability exists in Forcepoint Security E ...)
 	NOT-FOR-US: Forcepoint
 CVE-2026-12370 (ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configu ...)
 	NOT-FOR-US: Zoho
 CVE-2026-11744 (An input validation vulnerability exists in the PaperCut Hive embedded ...)
-	TODO: check
+	NOT-FOR-US: PaperCut
 CVE-2025-63564 (SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through  ...)
 	TODO: check
 CVE-2026-87022 (Improper handling of length parameter inconsistency vulnerability in A ...)


=====================================
data/packages/nfu.yaml
=====================================
@@ -221,6 +221,8 @@
   cna: Palantir
 - reason: Palo Alto Networks
   cna: palo_alto
+- reason: PaperCut
+  cna: PaperCut
 - reason: Payara
   cna: Payara
 - reason: Progress Software



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5d97c4284568b555b9c3de9c5804a1dccb28140a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5d97c4284568b555b9c3de9c5804a1dccb28140a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/22c0db07/attachment.htm>


More information about the debian-security-tracker-commits mailing list