Aggregator
hplip-3.26.6-1.fc44
- hplip-3.26.6-1.fc44
3.26.6, fixes CVE-2026-91105,CVE-2026-91103,CVE-2026-91102,CVE-2026-91101,
CVE-2026-91100,CVE-2026-91099,CVE-2026-91098,CVE-2026-91097
hplip-3.26.6-1.fc45
- hplip-3.26.6-1.fc45
3.26.6, fixes CVE-2026-91105,CVE-2026-91103,CVE-2026-91102,CVE-2026-91101,
CVE-2026-91100,CVE-2026-91099,CVE-2026-91098,CVE-2026-91097
freerdp-3.32.0-1.fc45
- freerdp-3.32.0-1.fc45
Update to 3.32.0
freerdp-3.32.0-1.fc44
- freerdp-3.32.0-1.fc44
Update to 3.32.0
freerdp-3.32.0-1.fc43
- freerdp-3.32.0-1.fc43
Update to 3.32.0
fetchmail-6.6.8-1.fc43
- fetchmail-6.6.8-1.fc43
Update to fetchmail-6.6.8 (CVE-2026-94184)
Update to fetchmail-6.6.7
fetchmail-6.6.8-1.fc44
- fetchmail-6.6.8-1.fc44
Update to fetchmail-6.6.8 (CVE-2026-94184)
Update to fetchmail-6.6.7
rust-librsvg-2.63.2-1.fc46 rust-xml5ever-0.39.0-1.fc46
- rust-librsvg-2.63.2-1.fc46
- rust-xml5ever-0.39.0-1.fc46
- Update the librsvg crate to version 2.63.2.
- Update the xml5ever crate to version 0.39.0.
This includes fixes for RUSTSEC-2026-0305.
fetchmail-6.6.8-1.fc45
- fetchmail-6.6.8-1.fc45
Update to fetchmail-6.6.8 (CVE-2026-94184)
Update to fetchmail-6.6.7
slurm-22.05.11-2.el9
- slurm-22.05.11-2.el9
update changelog
slurm-26.05.4-1.fc45
- slurm-26.05.4-1.fc45
Update to 26.05.4
wordpress-6.9.9-1.fc44
- wordpress-6.9.9-1.fc44
Security updates included in this release
- Unauthenticated path traversal in page-template resolution leading to conditional RCE CVE-2026-87902
Security updates included in this release
- Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
- HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
- Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
- Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
- Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
- Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
- XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
- Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
- Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
- Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
- Comments, including notes, can be reparented by any authenticated user, reported by viridis.
wordpress-6.9.9-1.el10_2
- wordpress-6.9.9-1.el10_2
Security updates included in this release
- Unauthenticated path traversal in page-template resolution leading to conditional RCE CVE-2026-87902
Security updates included in this release
- Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
- HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
- Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
- Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
- Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
- Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
- XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
- Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
- Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
- Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
- Comments, including notes, can be reparented by any authenticated user, reported by viridis.
wordpress-6.9.9-1.fc43
- wordpress-6.9.9-1.fc43
Security updates included in this release
- Unauthenticated path traversal in page-template resolution leading to conditional RCE CVE-2026-87902
Security updates included in this release
- Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
- HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
- Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
- Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
- Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
- Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
- XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
- Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
- Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
- Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
- Comments, including notes, can be reparented by any authenticated user, reported by viridis.
wordpress-6.9.9-1.el9
- wordpress-6.9.9-1.el9
Security updates included in this release
- Unauthenticated path traversal in page-template resolution leading to conditional RCE CVE-2026-87902
Security updates included in this release
- Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
- HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
- Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
- Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
- Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
- Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
- XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
- Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
- Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
- Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
- Comments, including notes, can be reparented by any authenticated user, reported by viridis.
wordpress-7.1.2-1.el10_3
- wordpress-7.1.2-1.el10_3
Security updates included in this release
- Unauthenticated path traversal in page-template resolution leading to conditional RCE CVE-2026-87902
Security updates included in this release
- Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
- HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
- Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
- Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
- Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
- Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
- XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
- Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
- Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
- Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
- Comments, including notes, can be reparented by any authenticated user, reported by viridis.
wordpress-7.1.2-1.fc45
- wordpress-7.1.2-1.fc45
Security updates included in this release
- Unauthenticated path traversal in page-template resolution leading to conditional RCE CVE-2026-87902
Security updates included in this release
- Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
- HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
- Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
- Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
- Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
- Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
- XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
- Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
- Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
- Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
- Comments, including notes, can be reparented by any authenticated user, reported by viridis.
wordpress-7.1.2-1.el10_4
- wordpress-7.1.2-1.el10_4
Security updates included in this release
- Unauthenticated path traversal in page-template resolution leading to conditional RCE CVE-2026-87902
Security updates included in this release
- Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
- HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
- Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
- Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
- Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
- Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
- XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
- Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
- Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
- Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
- Comments, including notes, can be reparented by any authenticated user, reported by viridis.