[Git][security-tracker-team/security-tracker][master] Add new froxlor issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 26 20:57:38 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
663f2439 by Salvatore Bonaccorso at 2026-09-26T21:57:18+02:00
Add new froxlor issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -32,31 +32,31 @@ CVE-2026-82901 (The Ultra Addons for Contact Form 7 plugin for WordPress is vuln
CVE-2026-77203 (The Groups \u2013 Memberships and Access Control plugin for WordPress ...)
NOT-FOR-US: WordPress plugin
CVE-2026-100720 (Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site script ...)
- TODO: check
+ - froxlor <itp> (bug #581792)
CVE-2026-100719 (Froxlor versions before 2.3.12 contain a credential disclosure vulnera ...)
- TODO: check
+ - froxlor <itp> (bug #581792)
CVE-2026-100718 (Froxlor through 2.3.10 does not enforce the mail.allow_external_domain ...)
- TODO: check
+ - froxlor <itp> (bug #581792)
CVE-2026-100717 (froxlor is a server administration panel. In versions 2.3.10 and earli ...)
- TODO: check
+ - froxlor <itp> (bug #581792)
CVE-2026-100716 (Froxlor is a server administration panel. In versions 2.3.10 and earli ...)
- TODO: check
+ - froxlor <itp> (bug #581792)
CVE-2026-100715 (Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via sy ...)
- TODO: check
+ - froxlor <itp> (bug #581792)
CVE-2026-100714 (Froxlor before 2.3.12 does not restrict or escape the system.letsencry ...)
- TODO: check
+ - froxlor <itp> (bug #581792)
CVE-2026-100713 (Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU ...)
- TODO: check
+ - froxlor <itp> (bug #581792)
CVE-2026-100712 (froxlor through 2.3.10 disables a user's two-factor authentication imm ...)
- TODO: check
+ - froxlor <itp> (bug #581792)
CVE-2026-100711 (froxlor versions before 2.3.12 fail to invalidate existing panel sessi ...)
- TODO: check
+ - froxlor <itp> (bug #581792)
CVE-2026-100710 (Froxlor through 2.3.10 does not filter sensitive columns from API resp ...)
- TODO: check
+ - froxlor <itp> (bug #581792)
CVE-2026-100709 (Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA ...)
- TODO: check
+ - froxlor <itp> (bug #581792)
CVE-2026-100708 (Froxlor before 2.3.13 returns the ssl_key_file column \u2014 which sto ...)
- TODO: check
+ - froxlor <itp> (bug #581792)
CVE-2026-100707 (Kyverno before 1.19.1 contains a namespace isolation bypass in the api ...)
TODO: check
CVE-2026-100706 (kyverno before 1.19.1 fails to properly validate URL-encoded path segm ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/663f2439947064de6b8f6b2be3332a749ed4d310
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/663f2439947064de6b8f6b2be3332a749ed4d310
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260926/a73756f5/attachment.htm>
More information about the debian-security-tracker-commits
mailing list