[Git][security-tracker-team/security-tracker][master] Add new froxlor issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 26 20:57:38 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
663f2439 by Salvatore Bonaccorso at 2026-09-26T21:57:18+02:00
Add new froxlor issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -32,31 +32,31 @@ CVE-2026-82901 (The Ultra Addons for Contact Form 7 plugin for WordPress is vuln
 CVE-2026-77203 (The Groups \u2013 Memberships and Access Control plugin for WordPress  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-100720 (Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site script ...)
-	TODO: check
+	- froxlor <itp> (bug #581792)
 CVE-2026-100719 (Froxlor versions before 2.3.12 contain a credential disclosure vulnera ...)
-	TODO: check
+	- froxlor <itp> (bug #581792)
 CVE-2026-100718 (Froxlor through 2.3.10 does not enforce the mail.allow_external_domain ...)
-	TODO: check
+	- froxlor <itp> (bug #581792)
 CVE-2026-100717 (froxlor is a server administration panel. In versions 2.3.10 and earli ...)
-	TODO: check
+	- froxlor <itp> (bug #581792)
 CVE-2026-100716 (Froxlor is a server administration panel. In versions 2.3.10 and earli ...)
-	TODO: check
+	- froxlor <itp> (bug #581792)
 CVE-2026-100715 (Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via sy ...)
-	TODO: check
+	- froxlor <itp> (bug #581792)
 CVE-2026-100714 (Froxlor before 2.3.12 does not restrict or escape the system.letsencry ...)
-	TODO: check
+	- froxlor <itp> (bug #581792)
 CVE-2026-100713 (Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU ...)
-	TODO: check
+	- froxlor <itp> (bug #581792)
 CVE-2026-100712 (froxlor through 2.3.10 disables a user's two-factor authentication imm ...)
-	TODO: check
+	- froxlor <itp> (bug #581792)
 CVE-2026-100711 (froxlor versions before 2.3.12 fail to invalidate existing panel sessi ...)
-	TODO: check
+	- froxlor <itp> (bug #581792)
 CVE-2026-100710 (Froxlor through 2.3.10 does not filter sensitive columns from API resp ...)
-	TODO: check
+	- froxlor <itp> (bug #581792)
 CVE-2026-100709 (Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA ...)
-	TODO: check
+	- froxlor <itp> (bug #581792)
 CVE-2026-100708 (Froxlor before 2.3.13 returns the ssl_key_file column \u2014 which sto ...)
-	TODO: check
+	- froxlor <itp> (bug #581792)
 CVE-2026-100707 (Kyverno before 1.19.1 contains a namespace isolation bypass in the api ...)
 	TODO: check
 CVE-2026-100706 (kyverno before 1.19.1 fails to properly validate URL-encoded path segm ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/663f2439947064de6b8f6b2be3332a749ed4d310

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/663f2439947064de6b8f6b2be3332a749ed4d310
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260926/a73756f5/attachment.htm>


More information about the debian-security-tracker-commits mailing list