[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 25 21:23:19 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d180240c by Salvatore Bonaccorso at 2026-09-25T22:22:44+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -37,7 +37,7 @@ CVE-2026-97865 (A security flaw has been discovered in Open-Web-Analytics up to
CVE-2026-97864 (A vulnerability has been found in GibbonEdu Gibbon up to 30.0.01. The ...)
NOT-FOR-US: GibbonEdu Gibbon
CVE-2026-97863 (The cisco_firesight_manager_ACL_rule_export module in misp-modules gen ...)
- TODO: check
+ NOT-FOR-US: misp-modules
CVE-2026-97846 (Keycloak provides a feature called mTLS holder-of-key binding which en ...)
- keycloak <itp> (bug #1088287)
CVE-2026-97818 (phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and ...)
@@ -164,27 +164,27 @@ CVE-2026-93654 (The Premium Packages \u2013 Sell Digital Products Securely plugi
CVE-2026-93647 (An unauthenticated calendar sender can place active markup in a COUNTE ...)
NOT-FOR-US: Zimbra
CVE-2026-93643 (When OnlyOffice/Document Editing is available, an unauthenticated remo ...)
- TODO: check
+ NOT-FOR-US: Zimbra
CVE-2026-93642 (An unauthenticated sender can forge a share notification that triggers ...)
NOT-FOR-US: Zimbra
CVE-2026-93641 (An unauthenticated sender can forge a share notification that triggers ...)
NOT-FOR-US: Zimbra
CVE-2026-93477 (Improperly Controlled Modification of Dynamically-Determined Object At ...)
- TODO: check
+ NOT-FOR-US: ash-project
CVE-2026-93399 (The Bookly plugin for WordPress is vulnerable to Insecure Direct Objec ...)
NOT-FOR-US: WordPress plugin
CVE-2026-93366 (Bludit CMS through 3.22.0 contains an authorization bypass vulnerabili ...)
- TODO: check
+ NOT-FOR-US: Bludit CMS
CVE-2026-93365 (Bludit CMS through 3.22.0 contains a missing authorization vulnerabili ...)
- TODO: check
+ NOT-FOR-US: Bludit CMS
CVE-2026-93364 (Bludit CMS through 3.22.0 contains a mass assignment vulnerability tha ...)
- TODO: check
+ NOT-FOR-US: Bludit CMS
CVE-2026-93363 (The @payloadcms/storage-vercel-blob storage adapter for Payload contai ...)
- TODO: check
+ NOT-FOR-US: storage-vercel-blob storage adapter for Payload
CVE-2026-93354 (Taskview Community before 1.56.0 contains a missing authentication vul ...)
- TODO: check
+ NOT-FOR-US: Taskview Community
CVE-2026-93353 (copyparty contains a volume restriction bypass vulnerability in its SF ...)
- TODO: check
+ NOT-FOR-US: copyparty
CVE-2026-93306 (IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1 ...)
NOT-FOR-US: IBM
CVE-2026-93303 (The HT Contact Form \u2013 Drag & Drop Form Builder for WordPress plug ...)
@@ -192,9 +192,9 @@ CVE-2026-93303 (The HT Contact Form \u2013 Drag & Drop Form Builder for WordPres
CVE-2026-93291 (Omni C20 lacks proper certificate validation which could allow an atta ...)
TODO: check
CVE-2026-93290 (Omni C20 uses hard-coded credentials that could allow an attacker to m ...)
- TODO: check
+ NOT-FOR-US: Omni C20
CVE-2026-93289 (The affected products are vulnerable to command injection attack that ...)
- TODO: check
+ NOT-FOR-US: Omni C20
CVE-2026-93030 (FTM 4.x ALL could allow a remote authenticated attacker to obtain sens ...)
NOT-FOR-US: IBM
CVE-2026-92829 (The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPre ...)
@@ -208,9 +208,9 @@ CVE-2026-92713 (The Modula Image Gallery \u2013 Photo Grid & Video Gallery plugi
CVE-2026-92212 (The JetFormBuilder \u2014 Dynamic Blocks Form Builder plugin for WordP ...)
NOT-FOR-US: WordPress plugin
CVE-2026-92161 (FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Tw ...)
- TODO: check
+ NOT-FOR-US: FriendsOfFlarum OAuth
CVE-2026-92106 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
- TODO: check
+ NOT-FOR-US: dashbitco lazy_html
CVE-2026-89426 (The Knit Pay \u2013 Cashfree, Instamojo, Razorpay, PayPal and more plu ...)
NOT-FOR-US: WordPress plugin
CVE-2026-89406 (The Modula Image Gallery \u2013 Photo Grid & Video Gallery plugin for ...)
@@ -218,23 +218,23 @@ CVE-2026-89406 (The Modula Image Gallery \u2013 Photo Grid & Video Gallery plugi
CVE-2026-89055 (The Customer Reviews for WooCommerce plugin for WordPress is vulnerabl ...)
NOT-FOR-US: WordPress plugin
CVE-2026-89032 (BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass ...)
- TODO: check
+ NOT-FOR-US: BerriAI LiteLLM
CVE-2026-88996 (The WPForms \u2013 AI Form Builder for WordPress \u2013 Contact Forms, ...)
NOT-FOR-US: WordPress plugin
CVE-2026-88956 (The Botslab G980H dash camera firmware contains an authentication vuln ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-88848 (The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not v ...)
NOT-FOR-US: WordPress plugin
CVE-2026-88761 (The Botslab G980H dash camera firmware generates the default WiFi pass ...)
- TODO: check
+ NOT-FOR-US: Botslab G980H dash camera firmware
CVE-2026-88421 (Incorrect access control in the BlogPage.get_entries() component of AP ...)
- TODO: check
+ NOT-FOR-US: APSL puput
CVE-2026-88420 (A reflected cross-site scripting (XSS) vulnerability in the EntryAbstr ...)
- TODO: check
+ NOT-FOR-US: APSL puput
CVE-2026-88389 (Espruino 2v29 (commit bffc6d0) contains a NULL pointer dereference vul ...)
- TODO: check
+ NOT-FOR-US: Espruino
CVE-2026-88388 (Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow ...)
- TODO: check
+ NOT-FOR-US: Espruino
CVE-2026-88387 (LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability i ...)
TODO: check
CVE-2026-88386 (libsndfile 1.2.2 contains a misaligned memory access issue in psf_binh ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d180240ce7b2621fa2408484e35ae5fb26206e77
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d180240ce7b2621fa2408484e35ae5fb26206e77
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/9445d971/attachment.htm>
More information about the debian-security-tracker-commits
mailing list