[Git][security-tracker-team/security-tracker][master] Add new piwigo issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 25 20:36:16 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
05a92f93 by Salvatore Bonaccorso at 2026-09-25T21:35:47+02:00
Add new piwigo issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -239,7 +239,7 @@ CVE-2026-87118 (The Botslab G980H dash camera firmware contains an out of bounds
CVE-2026-86837 (The Bookly WordPress plugin before 28.3 does not properly verify a cus ...)
NOT-FOR-US: WordPress plugin
CVE-2026-85750 (Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote ...)
- TODO: check
+ - piwigo <removed>
CVE-2026-85542 (IBM Guardium Data Protection 12.2 is affected by a command injection v ...)
NOT-FOR-US: IBM
CVE-2026-85496 (The Botslab G980H dash camera firmware generates session identifiers u ...)
@@ -423,7 +423,7 @@ CVE-2026-63204 (Zammad is a web based open source helpdesk/customer support syst
CVE-2026-63006 (Zammad is a web based open source helpdesk/customer support system. Pr ...)
- zammad <itp> (bug #841355)
CVE-2026-62262 (Piwigo is a full featured open source photo gallery application for th ...)
- TODO: check
+ - piwigo <removed>
CVE-2026-62062 (Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website B ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-61855 (Zammad is a web based open source helpdesk/customer support system. In ...)
@@ -519,13 +519,13 @@ CVE-2026-47679 (GLPI is a free asset and IT management software package. From 10
CVE-2026-45801 (GLPI is a free asset and IT management software package. From 0.72 unt ...)
- glpi <removed>
CVE-2026-44642 (Piwigo is a full featured open source photo gallery application for th ...)
- TODO: check
+ - piwigo <removed>
CVE-2026-42324 (Piwigo is a full featured open source photo gallery application for th ...)
- TODO: check
+ - piwigo <removed>
CVE-2026-42323 (Piwigo is a full featured open source photo gallery application for th ...)
- TODO: check
+ - piwigo <removed>
CVE-2026-42322 (Piwigo is a full featured open source photo gallery application for th ...)
- TODO: check
+ - piwigo <removed>
CVE-2026-39372 (InvoicePlane is a self-hosted open source application for managing inv ...)
TODO: check
CVE-2026-39353 (InvoicePlane is a self-hosted open source application for managing inv ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/05a92f933e84aa50d14675c8755c2078b1f6509e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/05a92f933e84aa50d14675c8755c2078b1f6509e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/508feb21/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list