Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
ef0702c9 by security tracker role at 2026-08-02T07:14:03+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2026-9335 (A vulnerability in keras-team/keras versions <= 3.14.0 allows 
arbitrar ...)
        TODO: check
 CVE-2026-8457 (The WooCommerce - Social Login plugin for WordPress is 
vulnerable to A ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18573 (A flaw was found in the keycloak-services component of 
Keycloak, which ...)
        TODO: check
 CVE-2026-18572 (Keycloak provides authorization services that allow 
administrators to  ...)
@@ -13,65 +13,65 @@ CVE-2026-18570 (A flaw was found in the full-scope-disabled 
client-policy execut
 CVE-2026-18556 (Authentication bypass using an alternate path or channel 
vulnerability ...)
        TODO: check
 CVE-2026-18352 (The User Access Manager plugin for WordPress is vulnerable to 
Director ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17002
        REJECTED
 CVE-2026-16540 (The Simply Schedule Appointments WordPress plugin before 
1.6.12.6 does ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16292 (The Frontend File Manager Plugin WordPress plugin through 23.6 
does no ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16291 (The ProfileGrid  WordPress plugin before 5.9.9.8 does not 
verify that  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16285 (The Product Attachment for WooCommerce WordPress plugin before 
2.3.3 d ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16273 (The Narrative Publisher WordPress plugin through 1.0.7 does 
not restri ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16261 (The login-social WordPress plugin through 1.0.4 does not 
validate pass ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16256 (The POUCO Import Users WordPress plugin through 1.0.0 does not 
perform ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16064 (The Event Booking Manager for WooCommerce  WordPress plugin 
before 5.3 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16063 (The Event Booking Manager for WooCommerce  WordPress plugin 
before 5.3 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16062 (The Event Booking Manager for WooCommerce  WordPress plugin 
before 5.3 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16042 (The LWS Optimize  WordPress plugin before 3.4 does not perform 
a capab ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15939 (The Simple Restrict WordPress plugin before 1.2.9 does not 
enforce its ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15385 (The RT Mega Menu  WordPress plugin before 1.5.2 does not 
perform a cap ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15248 (The Meta Box WordPress plugin before 5.13.1 does not verify 
that a use ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15241 (The AI ChatBot for WooCommerce  WordPress plugin before 4.8.4 
does not ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15236 (The Gallery for Google Photos  WordPress plugin before 1.2.1 
does not  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15206 (The SMS Alert  WordPress plugin before 3.9.8 does not bind its 
"mobile ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15151 (The Five Star Restaurant Reservations  WordPress plugin before 
2.7.23  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14938 (The FluentBoards  WordPress plugin before 1.95.3 does not 
verify that  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14920 (## Summary)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14864 (The JetEngine WordPress plugin before 3.8.12 does not escape a 
post me ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14841 (The King Addons for Elementor  WordPress plugin before 51.1.76 
does no ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14817 (The Element Pack Addons for Elementor  WordPress plugin before 
8.7.13  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13389 (The webtoffee-cookie-consent WordPress plugin before 3.5.3 
does not pe ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13339 (The CubeWP Framework plugin for WordPress is vulnerable to 
Directory T ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12586 (The Lenxel WP WordPress theme through 1.0.31 does not perform 
any auth ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-11872 (The Clever Mega Menu for Visual Composer WordPress plugin 
through 1.0. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-15675 (The Charitable  WordPress plugin before 1.8.5.3 does not 
sanitise and  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-6453 (The CubeWP Framework plugin for WordPress is vulnerable to SQL 
Injecti ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-67355 (guzzlehttp/guzzle versions before 7.15.1 fail to preserve 
host-only co ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ef0702c9e7cabb6c174ef69c6af3edf0e50f2c2c

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ef0702c9e7cabb6c174ef69c6af3edf0e50f2c2c
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to