Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
4775c20b by security tracker role at 2026-07-31T07:13:21+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
 CVE-2026-8155 (The BuddyPress WordPress plugin before 14.5.0 does not properly 
enforc ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-6890
        REJECTED
 CVE-2026-6889
@@ -37,7 +37,7 @@ CVE-2026-67207 (Wolf CMS through 0.8.3.1 contains an 
authorization bypass vulner
 CVE-2026-67206 (Wolf CMS through 0.8.3.1 contains a remote code execution 
vulnerabilit ...)
        TODO: check
 CVE-2026-66803 (Improper access control in Azure Cosmos DB allows an 
unauthorized atta ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-66756 (Improper Protection of Alternate Path vulnerability in Apache 
Tika.  T ...)
        TODO: check
 CVE-2026-66755 (Relative Path Traversal in the ISA-Tab parser in Apache 
Software Found ...)
@@ -45,11 +45,11 @@ CVE-2026-66755 (Relative Path Traversal in the ISA-Tab 
parser in Apache Software
 CVE-2026-66720 (The GOOSE subscriber component improperly validates the UTC 
timestamp  ...)
        TODO: check
 CVE-2026-66421 (OpenClaw Dashboard contains a stored cross-site scripting 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: OpenClaw
 CVE-2026-66420 (MeshCentral 1.1.21 contains a cross-site WebSocket hijacking 
protectio ...)
        TODO: check
 CVE-2026-66418 (OpenClaw Dashboard v3.0.0 contains a stored cross-site 
scripting vulne ...)
-       TODO: check
+       NOT-FOR-US: OpenClaw
 CVE-2026-66369 (The GOOSE parser contains an off-by-one boundary-handling flaw 
that ca ...)
        TODO: check
 CVE-2026-66364 (The GOOSE payload parser contains a boundary handling flaw 
that can be ...)
@@ -147,49 +147,49 @@ CVE-2026-18157 (A flaw was found in 
yggdrasil-worker-package-manager. A local at
 CVE-2026-18064 (An incomplete fix for CVE-2026-15352 in the NASA core Flight 
System  ( ...)
        TODO: check
 CVE-2026-16236 (The Realtyna Organic IDX plugin for WordPress is vulnerable to 
Arbitra ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15381 (The WP Go Maps  WordPress plugin before 10.1.04 does not 
properly sani ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15258 (The Product Feed Manager For WooCommerce  WordPress plugin 
before 7.6. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15209 (The JS Help Desk  WordPress plugin before 3.1.5 does not 
verify that t ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15048 (The Geeky Bot  WordPress plugin before 1.2.8 does not perform 
an autho ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14931 (The JS Help Desk  WordPress plugin before 3.1.4 grants a 
support-agent ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14930 (The JS Help Desk  WordPress plugin before 3.1.4 does not 
perform any a ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14929 (The JS Help Desk  WordPress plugin before 3.1.4 does not 
verify owners ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14928 (The JS Help Desk  WordPress plugin before 3.1.4 does not 
perform autho ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14927 (The FluentCart A New Era of eCommerce  WordPress plugin before 
1.5.3 d ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14922 (WP Photo Album Plus is vulnerable to stored Cross-Site 
Scripting in al ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14921 (The Ultimate Addons for WPBakery Page Builder WordPress plugin 
before  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14919 (The ShopMonitor.io  WordPress plugin before 1.2.0 does not 
properly re ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14862 (The Support Genix  WordPress plugin before 1.4.48 does not 
properly au ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14849 (The Paid Membership Subscriptions  WordPress plugin before 
3.0.7 does  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14847 (The Paid Membership Subscriptions  WordPress plugin before 
3.0.7 does  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14845 (The NewStatPress WordPress plugin before 1.4.5 does not 
sanitise and e ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14843 (The Events Made Easy WordPress plugin before 3.1.4 does not 
verify tha ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14834 (The Mailgun for WordPress plugin before 2.2.1 does not perform 
any cap ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14833 (The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 
does not sa ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14830 (The FlxWoo WordPress plugin before 3.1.1 does not verify with 
the paym ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14554 (The Check & Log Email  WordPress plugin before 2.0.15 does not 
properl ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14541 (An authentication bypass and audience confusion vulnerability 
exists i ...)
        TODO: check
 CVE-2026-14540 (A Server-Side Request Forgery (SSRF) vulnerability exists in 
the gener ...)
@@ -201,63 +201,63 @@ CVE-2026-14538 (An improper authorization and 
security-boundary bypass vulnerabi
 CVE-2026-14537 (Incorrect Authorization in the direct HTTP API tool invocation 
endpoin ...)
        TODO: check
 CVE-2026-14483 (The Realtyna Organic IDX plugin + WPL Real Estate plugin for 
WordPress ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14333 (The Demi  WordPress plugin before 0.0.7 stores its full-site 
backup ar ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14319 (The GiveWP  WordPress plugin before 4.16.3 does not properly 
restrict  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14317 (The GiveWP  WordPress plugin before 4.16.3 does not restrict 
the set o ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13609 (The Frontend Admin by DynamiApps WordPress plugin before 
3.29.9 decode ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13393 (The ElementsKit Elementor Addons  WordPress plugin before 
3.10.01 does ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13392 (The ElementsKit Elementor Addons  WordPress plugin before 
3.10.01 does ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12946 (IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote 
attacker to ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-12721 (The Kirki  WordPress plugin before 6.0.13 does not properly 
sanitise a ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12720 (The Kirki  WordPress plugin before 6.0.13 does not restrict 
which clas ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12697 (The wpForo Forum WordPress plugin before 3.1.2 does not verify 
that an ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12695 (The miniOrange 2FA  WordPress plugin before 6.2.6 does not 
validate th ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12562 (The RCU II+ and Multiload II+ are vulnerable to an 
unauthenticated  se ...)
        TODO: check
 CVE-2026-12376 (The Academy LMS WordPress plugin through 3.8.2 does not 
restrict acces ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12251 (The Ultimate Member  WordPress plugin before 2.12.1 does not 
filter ad ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-11536 (IBM WebSphere Application Server 9.0, and 8.5 is affected by a 
remote  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-10569 (IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 
through 7 ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-10031 (SFTPGo prior to 2.7.4 contains a permission bypass 
vulnerability that  ...)
        TODO: check
 CVE-2025-69947 (SourceCodester Tailor Management System 1.0 is vulnerable to 
SQL Injec ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2025-69941 (SourceCodester Tailor Management System 1.0 is vulnerable to 
SQL Injec ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2025-69938 (CodeAstro Membership Management System 1.0 is vulnerable to 
SQL Inject ...)
-       TODO: check
+       NOT-FOR-US: CodeAstro
 CVE-2025-69937 (CodeAstro Membership Management System 1.0 is vulnerable to 
SQL Inject ...)
-       TODO: check
+       NOT-FOR-US: CodeAstro
 CVE-2025-69936 (CodeAstro Membership Management System 1.0 is vulnerable to 
SQL Inject ...)
-       TODO: check
+       NOT-FOR-US: CodeAstro
 CVE-2025-69935 (CodeAstro Membership Management System 1.0 is vulnerale to SQL 
Injecti ...)
-       TODO: check
+       NOT-FOR-US: CodeAstro
 CVE-2025-69934 (CodeAstro Membership Management System 1.0 is vulnerable to 
SQL Inject ...)
-       TODO: check
+       NOT-FOR-US: CodeAstro
 CVE-2025-69933 (CodeAstro Membership Management System 1.0 is vulnerable to 
SQL Inject ...)
-       TODO: check
+       NOT-FOR-US: CodeAstro
 CVE-2025-69931 (CodeAstro Membership Management System 1.0 is vulnerable to 
SQL Inject ...)
-       TODO: check
+       NOT-FOR-US: CodeAstro
 CVE-2025-69930 (CodeAstro Membership Management System 1.0 is vulnerable to 
SQL Inject ...)
-       TODO: check
+       NOT-FOR-US: CodeAstro
 CVE-2025-65342 (code-projects Blood System 1.0 is vulnerable to Cross Site 
Scripting ( ...)
-       TODO: check
+       NOT-FOR-US: code-projects
 CVE-2025-65341 (Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site 
Scripting (XSS) ...)
        TODO: check
 CVE-2025-65336 (Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is 
vulnerable t ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4775c20b326c48c1583aaea2536296ae53686c27

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4775c20b326c48c1583aaea2536296ae53686c27
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to