[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 26 20:14:24 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1c738641 by security tracker role at 2026-09-26T19:14:17+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,23 +1,23 @@
CVE-2026-97163 (Joomla Extension - lomart.fr - Unauthenticated remote code installatio ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-97162 (Joomla Extension - lomart.fr - Various SQL injection vectors in UP plu ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-97161 (Joomla Extension - lomart.fr - Various path traversal / file access ve ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-97160 (Joomla Extension - lomart.fr - Authenticated, privileged PHP command i ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-94132 (Joomla Extension - acymailing.com - Remote Code Execution vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-94131 (Joomla Extension - acymailing.com - Unauthenticated arbitrary file del ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-94130 (Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in Y ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-85984 (The miniOrange OTP Login, Verification and SMS Notifications plugin fo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-82901 (The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77203 (The Groups \u2013 Memberships and Access Control plugin for WordPress ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-100720 (Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site script ...)
TODO: check
CVE-2026-100719 (Froxlor versions before 2.3.12 contain a credential disclosure vulnera ...)
@@ -167,39 +167,39 @@ CVE-2026-100648 (vllm before 0.29.0 fails to enforce VLLM_MAX_AUDIO_CLIP_FILESIZ
CVE-2026-100647 (vLLM versions before 0.29.0 contain a denial-of-service vulnerability ...)
TODO: check
CVE-2026-100646 (SiYuan is a self-hosted personal knowledge management system. In versi ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-100645 (SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripti ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-100644 (SiYuan before v3.8.4 contains a SQL injection vulnerability in the gra ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-100643 (SiYuan versions before v3.8.4 fail to properly escape four stored Attr ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-100642 (SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-100641 (SiYuan before v3.8.4 does not HTML-escape stored flashcard block conte ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-100640 (SiYuan before v3.8.4 contains an authorization omission in the siyuan- ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-100639 (SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when gen ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-100638 (SiYuan versions before v3.8.4 contain a path traversal vulnerability i ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-100637 (SiYuan versions before v3.8.4 contain a path traversal vulnerability i ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-100636 (SiYuan versions before v3.8.4 contain a path traversal vulnerability i ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-100635 (SiYuan before v3.8.4 contains an authentication bypass vulnerability i ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-100634 (SiYuan before v3.8.4 does not validate the sender or restrict recipien ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-100633 (SiYuan is a self-hosted personal knowledge management system. In versi ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-100632 (Parse Server is an open-source backend server. In versions >= 9.0.0 an ...)
- TODO: check
+ NOT-FOR-US: Parse Server
CVE-2026-100631 (Parse Server is an open source backend server. In versions prior to 8. ...)
- TODO: check
+ NOT-FOR-US: Parse Server
CVE-2026-100630 (AVideo contains a stored cross-site scripting vulnerability in the vid ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-100629 (Capgo (capgo.app backend) before 12.127.5 contains an authorization fl ...)
TODO: check
CVE-2026-100628 (capgo.app before 12.128.12 fails to enforce an organization's API key ...)
@@ -239,27 +239,27 @@ CVE-2026-100612 (Capgo (capgo.app) through version 12.261.0 contains an incomple
CVE-2026-100611 (Capgo (capgo.app backend, versions \u2264 12.261.0) improperly restric ...)
TODO: check
CVE-2026-100610 (Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-100609 (Flowise (npm packages `flowise` and `flowise-components`) through 3.1. ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-100608 (Flowise through 3.1.4 does not enforce authorization on the BullMQ adm ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-100607 (Flowise through 3.1.4 resolves SSO and local-password users solely by ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-100606 (Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) cont ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-100605 (Flowise through 3.1.4 contains missing route-level RBAC checks on chat ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-100604 (ClawHub (openclaw/clawhub) contains an incorrect authorization vulnera ...)
- TODO: check
+ NOT-FOR-US: OpenClaw
CVE-2026-100603 (ClawHub (openclaw/clawhub) application/backend contains a flaw in the ...)
- TODO: check
+ NOT-FOR-US: OpenClaw
CVE-2026-100602 (ClawHub (openclaw/clawhub application/backend) contains a missing auth ...)
- TODO: check
+ NOT-FOR-US: OpenClaw
CVE-2026-100601 (ClawHub (openclaw/clawhub) application/backend contains a server-side ...)
- TODO: check
+ NOT-FOR-US: OpenClaw
CVE-2026-100600 (ClawHub (the openclaw/clawhub application/backend) does not bind anony ...)
- TODO: check
+ NOT-FOR-US: OpenClaw
CVE-2026-100315 (A vulnerability was detected in mathurvishal CloudClassroom-PHP-Projec ...)
TODO: check
CVE-2026-100314 (A security vulnerability has been detected in mathurvishal CloudClassr ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1c738641bc5207ab764225f0632652409cc1ad84
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1c738641bc5207ab764225f0632652409cc1ad84
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260926/ded8f0cc/attachment.htm>
More information about the debian-security-tracker-commits
mailing list