[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 26 20:14:24 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1c738641 by security tracker role at 2026-09-26T19:14:17+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,23 +1,23 @@
 CVE-2026-97163 (Joomla Extension - lomart.fr - Unauthenticated remote code installatio ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-97162 (Joomla Extension - lomart.fr - Various SQL injection vectors in UP plu ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-97161 (Joomla Extension - lomart.fr - Various path traversal / file access ve ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-97160 (Joomla Extension - lomart.fr - Authenticated, privileged PHP command i ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-94132 (Joomla Extension - acymailing.com - Remote Code Execution vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-94131 (Joomla Extension - acymailing.com - Unauthenticated arbitrary file del ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-94130 (Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in Y ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-85984 (The miniOrange OTP Login, Verification and SMS Notifications plugin fo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-82901 (The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77203 (The Groups \u2013 Memberships and Access Control plugin for WordPress  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-100720 (Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site script ...)
 	TODO: check
 CVE-2026-100719 (Froxlor versions before 2.3.12 contain a credential disclosure vulnera ...)
@@ -167,39 +167,39 @@ CVE-2026-100648 (vllm before 0.29.0 fails to enforce VLLM_MAX_AUDIO_CLIP_FILESIZ
 CVE-2026-100647 (vLLM versions before 0.29.0 contain a denial-of-service vulnerability  ...)
 	TODO: check
 CVE-2026-100646 (SiYuan is a self-hosted personal knowledge management system. In versi ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-100645 (SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripti ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-100644 (SiYuan before v3.8.4 contains a SQL injection vulnerability in the gra ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-100643 (SiYuan versions before v3.8.4 fail to properly escape four stored Attr ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-100642 (SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-100641 (SiYuan before v3.8.4 does not HTML-escape stored flashcard block conte ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-100640 (SiYuan before v3.8.4 contains an authorization omission in the siyuan- ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-100639 (SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when gen ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-100638 (SiYuan versions before v3.8.4 contain a path traversal vulnerability i ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-100637 (SiYuan versions before v3.8.4 contain a path traversal vulnerability i ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-100636 (SiYuan versions before v3.8.4 contain a path traversal vulnerability i ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-100635 (SiYuan before v3.8.4 contains an authentication bypass vulnerability i ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-100634 (SiYuan before v3.8.4 does not validate the sender or restrict recipien ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-100633 (SiYuan is a self-hosted personal knowledge management system. In versi ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-100632 (Parse Server is an open-source backend server. In versions >= 9.0.0 an ...)
-	TODO: check
+	NOT-FOR-US: Parse Server
 CVE-2026-100631 (Parse Server is an open source backend server. In versions prior to 8. ...)
-	TODO: check
+	NOT-FOR-US: Parse Server
 CVE-2026-100630 (AVideo contains a stored cross-site scripting vulnerability in the vid ...)
-	TODO: check
+	NOT-FOR-US: WWBN AVideo
 CVE-2026-100629 (Capgo (capgo.app backend) before 12.127.5 contains an authorization fl ...)
 	TODO: check
 CVE-2026-100628 (capgo.app before 12.128.12 fails to enforce an organization's API key  ...)
@@ -239,27 +239,27 @@ CVE-2026-100612 (Capgo (capgo.app) through version 12.261.0 contains an incomple
 CVE-2026-100611 (Capgo (capgo.app backend, versions \u2264 12.261.0) improperly restric ...)
 	TODO: check
 CVE-2026-100610 (Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH ...)
-	TODO: check
+	NOT-FOR-US: Flowise
 CVE-2026-100609 (Flowise (npm packages `flowise` and `flowise-components`) through 3.1. ...)
-	TODO: check
+	NOT-FOR-US: Flowise
 CVE-2026-100608 (Flowise through 3.1.4 does not enforce authorization on the BullMQ adm ...)
-	TODO: check
+	NOT-FOR-US: Flowise
 CVE-2026-100607 (Flowise through 3.1.4 resolves SSO and local-password users solely by  ...)
-	TODO: check
+	NOT-FOR-US: Flowise
 CVE-2026-100606 (Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) cont ...)
-	TODO: check
+	NOT-FOR-US: Flowise
 CVE-2026-100605 (Flowise through 3.1.4 contains missing route-level RBAC checks on chat ...)
-	TODO: check
+	NOT-FOR-US: Flowise
 CVE-2026-100604 (ClawHub (openclaw/clawhub) contains an incorrect authorization vulnera ...)
-	TODO: check
+	NOT-FOR-US: OpenClaw
 CVE-2026-100603 (ClawHub (openclaw/clawhub) application/backend contains a flaw in the  ...)
-	TODO: check
+	NOT-FOR-US: OpenClaw
 CVE-2026-100602 (ClawHub (openclaw/clawhub application/backend) contains a missing auth ...)
-	TODO: check
+	NOT-FOR-US: OpenClaw
 CVE-2026-100601 (ClawHub (openclaw/clawhub) application/backend contains a server-side  ...)
-	TODO: check
+	NOT-FOR-US: OpenClaw
 CVE-2026-100600 (ClawHub (the openclaw/clawhub application/backend) does not bind anony ...)
-	TODO: check
+	NOT-FOR-US: OpenClaw
 CVE-2026-100315 (A vulnerability was detected in mathurvishal CloudClassroom-PHP-Projec ...)
 	TODO: check
 CVE-2026-100314 (A security vulnerability has been detected in mathurvishal CloudClassr ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1c738641bc5207ab764225f0632652409cc1ad84

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1c738641bc5207ab764225f0632652409cc1ad84
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260926/ded8f0cc/attachment.htm>


More information about the debian-security-tracker-commits mailing list