Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
71faffc8 by security tracker role at 2026-08-05T07:13:19+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,11 +1,11 @@
 CVE-2026-9273 (The Membership Plugin \u2013 Kadence Memberships plugin for 
WordPress  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-8790 (The Football Pool plugin for WordPress is vulnerable to 
Reflected Cros ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-8761 (The Dokan plugin for WordPress is vulnerable to Privilege 
Escalation i ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-7753 (The Cost Calculator Builder plugin for WordPress is vulnerable 
to unau ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-71201 (In OpenStack Ironic through 38.0.0, a project reader that 
makes a craf ...)
        TODO: check
 CVE-2026-71192 (In OpenStack Swift through 2.38.0, the S3API middleware does 
not sanit ...)
@@ -71,13 +71,13 @@ CVE-2026-70480 (Open WebUI is an extensible, feature-rich, 
and user-friendly sel
 CVE-2026-70479 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
        TODO: check
 CVE-2026-70478 (Flowise is a drag & drop user interface to build a customized 
large la ...)
-       TODO: check
+       NOT-FOR-US: Flowise
 CVE-2026-70477 (Flowise is a drag & drop user interface to build a customized 
large la ...)
-       TODO: check
+       NOT-FOR-US: Flowise
 CVE-2026-70476 (Flowise is a drag & drop user interface to build a customized 
large la ...)
-       TODO: check
+       NOT-FOR-US: Flowise
 CVE-2026-70475 (Flowise is a drag & drop user interface to build a customized 
large la ...)
-       TODO: check
+       NOT-FOR-US: Flowise
 CVE-2026-70375 (HashBrown CMS through 1.4.6 contains an OS Command Injection 
vulnerabi ...)
        TODO: check
 CVE-2026-70374 (HashBrown CMS through 1.4.6 contains an OS Command Injection 
vulnerabi ...)
@@ -155,7 +155,7 @@ CVE-2026-66257 (A pre-authentication attacker could 
leverage unbounded symbol va
 CVE-2026-65986 (CVAT is an open source interactive video and image annotation 
tool for ...)
        TODO: check
 CVE-2026-5062 (The PrettyLinks \u2013 Affiliate Links, Link Branding, Link 
Tracking,  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-54020 (Open WebUI is an extensible, feature-rich, and user-friendly 
self-host ...)
        TODO: check
 CVE-2026-52370 (A reflected cross-site scripting (XSS) vulnerability in the 
Forum post ...)
@@ -167,7 +167,7 @@ CVE-2026-51400 (An issue in Vim Project v9.2.0389 and 
earlier allows a local att
 CVE-2026-51144 (Cross Site Scripting vulnerability in Soliton Systems MailZen 
Manageme ...)
        TODO: check
 CVE-2026-49004 (The built-in PostgreSQL service on the mobile device suffers 
from misc ...)
-       TODO: check
+       NOT-FOR-US: ZTE
 CVE-2026-48154 (GoRest is a Golang starter kit built with the Gin framework 
for protot ...)
        TODO: check
 CVE-2026-47682 (CVAT is an open source interactive video and image annotation 
tool for ...)
@@ -189,7 +189,7 @@ CVE-2026-45100 (OpenSIPS is a Session Initiation Protocol 
(SIP) server implement
 CVE-2026-45084 (OpenSIPS is a Session Initiation Protocol (SIP) server 
implementation. ...)
        TODO: check
 CVE-2026-18907 (Path Traversal in Download File Feature in com.talpa.hibrowser 
2.23.1. ...)
-       TODO: check
+       NOT-FOR-US: TECNO Mobile
 CVE-2026-18903 (A vulnerability was determined in yeqifu warehouse up to 
aaf29962ba407 ...)
        TODO: check
 CVE-2026-18902 (A vulnerability was detected in H3C NX15 V100R017. Affected by 
this vu ...)
@@ -207,7 +207,7 @@ CVE-2026-18896 (A vulnerability was determined in 
lavkush-maurya Student-Registr
 CVE-2026-18895 (A vulnerability was found in UTT HiPER 1250GW up to 
3.2.7-210907-18053 ...)
        TODO: check
 CVE-2026-18859 (A vulnerability was identified in ESAFENET CDG up to 20260615. 
Affecte ...)
-       TODO: check
+       NOT-FOR-US: ESAFENET
 CVE-2026-18856 (A vulnerability was determined in Poesis Rhymix CMS up to 
2.1.33. This ...)
        TODO: check
 CVE-2026-18854 (A vulnerability has been found in Shandong Hoteam PDM Product 
Data Man ...)
@@ -235,77 +235,77 @@ CVE-2026-18811 (A vulnerability was detected in H3C NX15 
V100R017. The affected
 CVE-2026-18810 (A security vulnerability has been detected in H3C NX15 
V100R017. Impac ...)
        TODO: check
 CVE-2026-18657 (An uncontrolled search path element in Kiro CLI before version 
2.10.0  ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-18656 (An uncontrolled search path element in Kiro IDE before version 
1.0.228 ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-18322 (The Smart Popup by Supsystic plugin for WordPress is 
vulnerable to Pri ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18103 (A flaw was found in dhcp-server. A remote attacker with 
network access ...)
        TODO: check
 CVE-2026-17515 (The MLSImport: IDX Plugin & MLS Plugin for Real Estate 
Listings WordPr ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16993 (The DHL Shipping Germany for WooCommerce WordPress plugin 
before 4.0.1 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16981 (The DHL Shipping Germany for WooCommerce WordPress plugin 
before 4.0.1 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16968 (The GeoDirectory  WordPress plugin before 2.8.168 does not 
restrict a  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16942 (The WP Custom HTML Page WordPress plugin through 0.6.2 does 
not saniti ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16940 (The Custom Fields WordPress plugin before 1.5.1 does not 
validate a us ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16793 (An improper neutralization of special elements used in an 
operating sy ...)
-       TODO: check
+       NOT-FOR-US: Lenovo
 CVE-2026-16792 (An improper certificate validation vulnerability was reported 
in multi ...)
-       TODO: check
+       NOT-FOR-US: Lenovo
 CVE-2026-16791 (A temporary file creation vulnerability in the Linux version 
of Lenovo ...)
-       TODO: check
+       NOT-FOR-US: Lenovo
 CVE-2026-16746 (The MultiVendorX  WordPress plugin before 5.0.11 does not 
verify that  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16736 (The User Registration & Membership  WordPress plugin before 
5.2.6 does ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16613 (The GDPR Cookie Compliance  WordPress plugin before 5.1.0 
expires the  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16605 (The MultiVendorX  WordPress plugin before 5.0.11 does not 
verify that  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16604 (The Passster  WordPress plugin before 4.3.6 outputs 
password-protected ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16603 (The Passster  WordPress plugin before 4.3.6 does not enforce 
its categ ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16602 (The Passster  WordPress plugin before 4.3.6 does not perform a 
post-st ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16583 (The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie 
Notice, ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16573 (The Bit Form  WordPress plugin before 3.2.0 does not sanitize 
an uploa ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16561 (The Sunshine Photo Cart  WordPress plugin before 3.6.12 does 
not perfo ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16143 (The VikRentItems \u2013 Flexible Rental Management System 
plugin for W ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16055 (The Contest Gallery  WordPress plugin before 30.0.7 does not 
route its ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16036 (The miniOrange 2FA  WordPress plugin before 6.2.7 does not 
bind the se ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15941 (The plugin provides an Admin Search page that allows users 
with the `e ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15918 (VikAppointments Service Booking Calendar wordpress plugin is 
vulnerabl ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15372 (The WP 2FA  WordPress plugin before 4.1.0 does not validate 
the second ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15360 (The Ajax Load More  WordPress plugin before 8.0.1 does not 
properly sa ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15230 (The YayPricing  WordPress plugin before 3.5.7 does not perform 
capabil ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15210 (The OTP Login With Phone Number, OTP Verification WordPress 
plugin bef ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14553 (The zportals WordPress plugin before 6.3.4 does not properly 
validate  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13227 (An Improper Authorization vulnerability exists in ERPNext 
version <v16 ...)
        TODO: check
 CVE-2026-11421 (The ERP: Complete HR, Accounting & CRM Suite with WooCommerce 
CRM Supp ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-15677 (The GeoDirectory  WordPress plugin before 2.8.110 does not 
sanitise an ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-42170
        - gimp 3.2.4-1
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16161



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71faffc886c11e78f18912074dfa19993eeda64d

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71faffc886c11e78f18912074dfa19993eeda64d
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to