Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
7b1db5db by Salvatore Bonaccorso at 2026-06-20T21:36:44+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -51,7 +51,7 @@ CVE-2026-48909 (SP LMS (com_splms) < 4.1.4 by JoomShaper 
deserializes user-contr
 CVE-2026-48908 (A vulnerability in the SP Page Builder for Joomla allows the 
upload of ...)
        NOT-FOR-US: Joomla
 CVE-2026-12673 (Liquidfiles versions before 4.2.12 are affected by a broken 
access con ...)
-       TODO: check
+       NOT-FOR-US: Liquidfiles
 CVE-2026-12119 (The Simple File List plugin for WordPress is vulnerable to 
unauthorize ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-11912 (The Simple File List plugin for WordPress is vulnerable to 
arbitrary f ...)
@@ -61,15 +61,15 @@ CVE-2026-11911 (The Simple File List plugin for WordPress 
is vulnerable to arbit
 CVE-2025-71379 (vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular 
expression ...)
        TODO: check
 CVE-2025-71331 (Flowise before 3.0.8 contains a cross-site scripting (XSS) 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: Flowise
 CVE-2024-58351 (Flowise before 2.1.4 allows configuration to be injected into 
the Chai ...)
-       TODO: check
+       NOT-FOR-US: Flowise
 CVE-2022-50972 (WooCommerce 7.1.0 contains a remote code execution 
vulnerability that  ...)
-       TODO: check
+       NOT-FOR-US: WooCommerce
 CVE-2020-37255 (WordPress Time Capsule Plugin 1.21.16 contains an 
authentication bypas ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2019-25763 (WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains 
an authe ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-9843 (The Database for Contact Form 7, WPforms, Elementor forms 
plugin for W ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-9375 (urllib3 version 2.6.3 is vulnerable to a decompression bomb 
bypass in  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7b1db5db8947c01484c4880ee2f8f3dad6affb38

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7b1db5db8947c01484c4880ee2f8f3dad6affb38
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to