[Git][security-tracker-team/security-tracker][master] Add new piwigo issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 25 20:36:16 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
05a92f93 by Salvatore Bonaccorso at 2026-09-25T21:35:47+02:00
Add new piwigo issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -239,7 +239,7 @@ CVE-2026-87118 (The Botslab G980H dash camera firmware contains an out of bounds
 CVE-2026-86837 (The Bookly WordPress plugin before 28.3 does not properly verify a cus ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-85750 (Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote  ...)
-	TODO: check
+	- piwigo <removed>
 CVE-2026-85542 (IBM Guardium Data Protection 12.2 is affected by a command injection v ...)
 	NOT-FOR-US: IBM
 CVE-2026-85496 (The Botslab G980H dash camera firmware generates session identifiers u ...)
@@ -423,7 +423,7 @@ CVE-2026-63204 (Zammad is a web based open source helpdesk/customer support syst
 CVE-2026-63006 (Zammad is a web based open source helpdesk/customer support system. Pr ...)
 	- zammad <itp> (bug #841355)
 CVE-2026-62262 (Piwigo is a full featured open source photo gallery application for th ...)
-	TODO: check
+	- piwigo <removed>
 CVE-2026-62062 (Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website B ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61855 (Zammad is a web based open source helpdesk/customer support system. In ...)
@@ -519,13 +519,13 @@ CVE-2026-47679 (GLPI is a free asset and IT management software package. From 10
 CVE-2026-45801 (GLPI is a free asset and IT management software package. From 0.72 unt ...)
 	- glpi <removed>
 CVE-2026-44642 (Piwigo is a full featured open source photo gallery application for th ...)
-	TODO: check
+	- piwigo <removed>
 CVE-2026-42324 (Piwigo is a full featured open source photo gallery application for th ...)
-	TODO: check
+	- piwigo <removed>
 CVE-2026-42323 (Piwigo is a full featured open source photo gallery application for th ...)
-	TODO: check
+	- piwigo <removed>
 CVE-2026-42322 (Piwigo is a full featured open source photo gallery application for th ...)
-	TODO: check
+	- piwigo <removed>
 CVE-2026-39372 (InvoicePlane is a self-hosted open source application for managing inv ...)
 	TODO: check
 CVE-2026-39353 (InvoicePlane is a self-hosted open source application for managing inv ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/05a92f933e84aa50d14675c8755c2078b1f6509e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/05a92f933e84aa50d14675c8755c2078b1f6509e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/508feb21/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list