Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
0f20cdc6 by Salvatore Bonaccorso at 2026-07-23T22:51:35+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -5,22 +5,22 @@ CVE-2026-9713 (The Lumise Product Designer for WooCommerce
plugin for WordPress
CVE-2026-9635 (The WP Shortcode by MyThemeShop plugin for WordPress is
vulnerable to ...)
NOT-FOR-US: WordPress plugin
CVE-2026-8287 (Allocation of resources without limits or throttling
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: Online Pre-Accounting Software
CVE-2026-6516 (Zohocorp ManageEngine ADAudit Plus versionsbefore 8606 are
affected by ...)
NOT-FOR-US: Zoho
CVE-2026-65920 (Diffusers through 0.39.0, fixed in commit cee298c, contains a
path tra ...)
- TODO: check
+ NOT-FOR-US: Diffusers
CVE-2026-65919 (Meshery before 1.0.57 contains an unauthenticated arbitrary
file read ...)
- TODO: check
+ NOT-FOR-US: Meshery
CVE-2026-65918 (PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2,
contains ...)
- pytorch-vision <unfixed>
NOTE: https://github.com/pytorch/vision/issues/9551
NOTE: https://github.com/pytorch/vision/pull/9520
NOTE: Fixed by:
https://github.com/pytorch/vision/commit/4e05dc22f5f050a9528cc0ea09ceca6cdaf8f4ed
CVE-2026-65917 (CyberPanel through 1.9.1, fixed in commit b198460, contains an
insecur ...)
- TODO: check
+ NOT-FOR-US: CyberPanel
CVE-2026-65916 (CyberPanel through 1.9.1, fixed in commit b198460, contains a
missing ...)
- TODO: check
+ NOT-FOR-US: CyberPanel
CVE-2026-65914 (DOMPurify before 3.3.2 contains a mutation-XSS vulnerability
when sani ...)
- node-dompurify 3.3.2+dfsg-1
NOTE:
https://github.com/cure53/DOMPurify/security/advisories/GHSA-h8r8-wccr-v5f2
@@ -62,11 +62,11 @@ CVE-2026-65898 (DOMPurify before 3.4.11 fails to clone the
ALLOWED_ATTR allowlis
- node-dompurify 3.4.12+dfsg-1
NOTE:
https://github.com/cure53/DOMPurify/security/advisories/GHSA-cmwh-pvxp-8882
CVE-2026-65897 (Grav API Plugin versions before 1.0.10 fail to validate the
groups fie ...)
- TODO: check
+ NOT-FOR-US: Grav API Plugin
CVE-2026-65896 (Grav API Plugin (Composer package getgrav/grav-plugin-api)
before 1.0. ...)
- TODO: check
+ NOT-FOR-US: Grav API Plugin
CVE-2026-65895 (Grav API Plugin versions before 1.0.10 fail to restrict write
access t ...)
- TODO: check
+ NOT-FOR-US: Grav API Plugin
CVE-2026-65763 (Joomla Extension - phoca.cz - Reflected XSS vulnerability in
Phoca Map ...)
NOT-FOR-US: Joomla
CVE-2026-65762 (Joomla Extension - phoca.cz - Reflected XSS vulnerability in
Phoca Gue ...)
@@ -92,37 +92,37 @@ CVE-2026-65713 (Joomla Extension - regularlabs.com -
Insecure path handling in M
CVE-2026-65712 (Joomla Extension - regularlabs.com - Insecure path handling in
CDN for ...)
NOT-FOR-US: Joomla
CVE-2026-65702 (Vanna through 2.0.2 contains a path traversal vulnerability in
the Fil ...)
- TODO: check
+ NOT-FOR-US: Vanna
CVE-2026-65701 (SoftVC VITS Singing Voice Conversion through commit 730930d
contains a ...)
- TODO: check
+ NOT-FOR-US: SoftVC VITS Singing Voice Conversion
CVE-2026-65700 (h2oGPT through 0.2.1 contains a path traversal vulnerability
in the Op ...)
- TODO: check
+ NOT-FOR-US: h2oGPT
CVE-2026-65699 (AgentGPT through 1.0.0 contains an authorization bypass
through user-c ...)
- TODO: check
+ NOT-FOR-US: AgentGPT
CVE-2026-65698 (Void through 1.3.4 contains a path traversal vulnerability in
the AI a ...)
- TODO: check
+ NOT-FOR-US: Void
CVE-2026-65697 (Fathom Lite through 1.3.1 contains a stored cross-site
scripting vulne ...)
- TODO: check
+ NOT-FOR-US: Fathom Lite
CVE-2026-65696 (Overseerr through 1.35.0 contains an authorization bypass
through user ...)
- TODO: check
+ NOT-FOR-US: Overseerr
CVE-2026-65695 (Office-Word-MCP-Server through 1.1.11 contains a path
traversal vulner ...)
- TODO: check
+ NOT-FOR-US: Office-Word-MCP-Server
CVE-2026-65690 (Bold Reports Standalone Report Designer before 14.1.12
contains a miss ...)
- TODO: check
+ NOT-FOR-US: Bold Reports
CVE-2026-65689 (Bold Reports Standalone Report Designer before 14.1.12
contains a miss ...)
- TODO: check
+ NOT-FOR-US: Bold Reports
CVE-2026-65688 (Bold Reports Standalone Report Designer before 14.1.12
contains a miss ...)
- TODO: check
+ NOT-FOR-US: Bold Reports
CVE-2026-65687 (Bold Reports Standalone Report Designer before 14.1.12
contains a miss ...)
- TODO: check
+ NOT-FOR-US: Bold Reports
CVE-2026-65608 (Grav versions >= 1.7.0 and before 2.0.9 contain a remote code
executio ...)
- TODO: check
+ NOT-FOR-US: Grav CMS
CVE-2026-65607 (SiYuan before v3.7.2 contains a path traversal vulnerability
in the /e ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-65606 (SiYuan before v3.7.2 contains a cross-site scripting
vulnerability in ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-65605 (SiYuan before v3.7.2 contains a stored cross-site scripting
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-65550 (Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5
versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-65540 (Unauthenticated Cross Site Request Forgery (CSRF) in Popup for
CF7 wit ...)
@@ -292,7 +292,7 @@ CVE-2026-65431 (Joomla Extension - regularlabs.com -
Zipslip in GeoIP extension
CVE-2026-65430 (Joomla Extension - regularlabs.com - MaxMind Credential
leakage in Geo ...)
NOT-FOR-US: Joomla
CVE-2026-65010 (Datasets through 5.00, fixed in commit ad2d853, contains a
symlink-fol ...)
- TODO: check
+ NOT-FOR-US: Hugginface Datasets
CVE-2026-64876 (Joomla Extension - regularlabs.com - Inconsistent CSRF token
checks / ...)
NOT-FOR-US: Joomla
CVE-2026-64875 (Joomla Extension - regularlabs.com - IP spoofing vulnerability
in GeoI ...)
@@ -340,7 +340,7 @@ CVE-2026-64799 (Joomla Extension - regularlabs.com - SSRF
via remote image downl
CVE-2026-64611 (A flaw was found in libcupsfilters. The
cfIEEE1284NormalizeMakeModel() ...)
TODO: check
CVE-2026-63765 (Chatwoot before 4.16.0 contains an authentication bypass
vulnerability ...)
- TODO: check
+ NOT-FOR-US: Chatwoot
CVE-2026-61981 (Unauthenticated Cross Site Request Forgery (CSRF) in Simple
Link Direc ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-61973 (Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5
versions.)
@@ -368,7 +368,7 @@ CVE-2026-61944 (Unauthenticated Cross Site Scripting (XSS)
in Bookly <= 27.7 ver
CVE-2026-61943 (Unauthenticated Broken Access Control in WPDM \u2013 Premium
Packages ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-59678 (An Incorrect Authorization vulnerability in Linux-Gaming
PortProtonQt ...)
- TODO: check
+ NOT-FOR-US: Linux-Gaming PortProtonQt
CVE-2026-59677 (A Missing Authorization vulnerability in selinux
policycoreutils seuns ...)
TODO: check
CVE-2026-59555 (Unauthenticated Arbitrary File Deletion in Participants
Database <= 2. ...)
@@ -456,35 +456,35 @@ CVE-2026-57367 (Subscriber Broken Access Control in WP
Booking System < 5.12.8.1
CVE-2026-52684 (If the auth responds very slowly and the records expire in
between, th ...)
TODO: check
CVE-2026-48539 (GFI Archiver before 15.13 contains a stored cross-site
scripting vulne ...)
- TODO: check
+ NOT-FOR-US: GFI Archiver
CVE-2026-48538 (GFI Archiver before 15.13 contains a stored cross-site
scripting vulne ...)
- TODO: check
+ NOT-FOR-US: GFI Archiver
CVE-2026-48537 (GFI Archiver before 15.13 contains a stored cross-site
scripting vulne ...)
- TODO: check
+ NOT-FOR-US: GFI Archiver
CVE-2026-48536 (GFI Archiver before 15.13 contains a stored cross-site
scripting vulne ...)
- TODO: check
+ NOT-FOR-US: GFI Archiver
CVE-2026-48535 (GFI Archiver before 15.13 contains a stored cross-site
scripting vulne ...)
- TODO: check
+ NOT-FOR-US: GFI Archiver
CVE-2026-48534 (GFI Archiver before 15.13 contains a stored cross-site
scripting vulne ...)
- TODO: check
+ NOT-FOR-US: GFI Archiver
CVE-2026-48533
REJECTED
CVE-2026-48532 (GFI Archiver before 15.13 contains a stored cross-site
scripting vulne ...)
- TODO: check
+ NOT-FOR-US: GFI Archiver
CVE-2026-48531 (GFI Archiver before 15.13 contains a stored cross-site
scripting vulne ...)
- TODO: check
+ NOT-FOR-US: GFI Archiver
CVE-2026-48530 (GFI Archiver before 15.13 contains a stored cross-site
scripting vulne ...)
- TODO: check
+ NOT-FOR-US: GFI Archiver
CVE-2026-47769 (APIFold reads an OpenAPI 3.x or Swagger 2.x specification and
generate ...)
- TODO: check
+ NOT-FOR-US: APIFold
CVE-2026-47755 (ITFlow provides an IT documentation, ticketing and accounting
system f ...)
- TODO: check
+ NOT-FOR-US: ITFlow
CVE-2026-47752 (Tugtainer is a self-hosted app for automating updates of
Docker contai ...)
- TODO: check
+ NOT-FOR-US: Tugtainer
CVE-2026-47743 (Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0,
three re ...)
- TODO: check
+ NOT-FOR-US: Shopper
CVE-2026-47668 (DbGate is cross-platform database manager. In versions 7.1.8
and prior ...)
- TODO: check
+ NOT-FOR-US: DbGate
CVE-2026-44909 (Proxygen lacked a generalized slow-consumer detection
mechanism in its ...)
NOT-FOR-US: Meta software not packaged in Debian
CVE-2026-44210 (Kata Containers is an open source project focusing on a
standard imple ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0f20cdc68cced1d74dacaa598731af1356ac53d6
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0f20cdc68cced1d74dacaa598731af1356ac53d6
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits