Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
43713131 by security tracker role at 2026-08-10T07:13:54+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5,7 +5,7 @@ CVE-2026-19389 (Multiple integer overflow and underflow 
vulnerabilities were fou
 CVE-2026-19387 (A heap out-of-bounds write vulnerability was found in the 
GStreamer gs ...)
        TODO: check
 CVE-2026-19384 (A weakness has been identified in SourceCodester Simple 
Doctors Appoin ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-19383 (A security vulnerability has been detected in 
saithink/saigroup SaiAdm ...)
        TODO: check
 CVE-2026-19382 (A weakness has been identified in Almico Speedfan 4.52. This 
affects t ...)
@@ -17,7 +17,7 @@ CVE-2026-19380 (A vulnerability was identified in Mullvad 
wireguard.sys 0.10.1.
 CVE-2026-19379 (A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. 
Impacted ...)
        TODO: check
 CVE-2026-19378 (A vulnerability was found in code-projects Task Management 
System 1.0. ...)
-       TODO: check
+       NOT-FOR-US: code-projects
 CVE-2026-19376 (A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. 
This vuln ...)
        TODO: check
 CVE-2026-19375 (A vulnerability was detected in dmitriiweb article-scraper-mcp 
1.0.0.  ...)
@@ -39,105 +39,105 @@ CVE-2026-19368 (A vulnerability was found in PV-Bhat 
gemsuite-mcp 1.0.0. Affecte
 CVE-2026-19367 (A vulnerability has been found in NocteDefensor LudusMCP 
1.0.24. Affec ...)
        TODO: check
 CVE-2026-19089 (The Product Input Fields for WooCommerce WordPress plugin 
before 2.0.2 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19077 (The Duplicate Post WordPress plugin before 1.5.5 does not 
perform per- ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19075 (All-in-One Video Gallery registers a public, unauthenticated 
file-down ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19074 (The Advanced Classifieds & Directory Pro Advanced Classifieds 
& Direct ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19053 (The ProSolution WP Client WordPress plugin before 2.0.6 does 
not sanit ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19049 (The ProSolution WP Client WordPress plugin before 2.0.9 does 
not sanit ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18960 (The Block User Account WordPress plugin before 2.0.1 does not 
enforce  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18946 (The Contact Form to Any API WordPress plugin before 3.0.7 does 
not use ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18934 (The RSS Aggregator by Feedzy  WordPress plugin before 5.2.6 
does not v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18786 (The CheckView  WordPress plugin before 2.3.2 does not restrict 
its RES ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18666 (The Library Management System WordPress plugin before 3.6.7 
does not s ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18470 (The Login & Register Forms  WordPress plugin before 4.0.2 does 
not ver ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18469 (The Login & Register Forms  WordPress plugin before 4.0.2 does 
not enf ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18468 (The Login & Register Forms  WordPress plugin before 4.0.2 does 
not bin ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18200 (The FoodBoxBooker WordPress plugin before 1.0.8 does not 
verify that t ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18030 (The BricksForge WordPress plugin before 3.1.8.8 does not 
verify the id ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17542 (The File Manager WordPress plugin before 6.9.1 does not 
perform any ca ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17541 (The File Manager WordPress plugin before 6.9.1 does not have 
authorisa ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17540 (The File Manager WordPress plugin before 6.9.1 does not 
properly autho ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17519
        REJECTED
 CVE-2026-17023 (The Salon Booking System  WordPress plugin through 10.30.33 
does not p ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17022 (The Salon Booking System  WordPress plugin through 10.30.33 
does not p ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17021 (The Salon Booking System  WordPress plugin through 10.30.33 
does not p ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17020 (The Salon Booking System  WordPress plugin through 10.30.33 
does not v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17019 (The JetEngine WordPress plugin before 3.8.13.1 does not 
sanitise uploa ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17018 (The CubeWP Framework WordPress plugin through 1.1.30 does not 
perform  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17016 (The Accept PayPal & Stripe with Subscriptions for WooCommerce 
WordPres ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17012 (The Accept PayPal & Stripe with Subscriptions for WooCommerce 
WordPres ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17010 (The Saitama Addon Pack WordPress plugin through 1.0.8 does not 
sanitis ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16985 (The Squeeze  WordPress plugin before 1.7.12 does not validate 
the file ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16949 (The Term Pages WordPress plugin before 2.0.0 does not properly 
sanitis ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16299 (The Single Sign On For TNG WordPress plugin before 2.2.0 does 
not prop ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16298 (The FoodBoxBooker WordPress plugin before 1.0.7 does not 
properly vali ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16257 (The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not 
properl ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15238 (The MotoPress Hotel Booking WordPress plugin before 6.2.3 does 
not ver ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15237 (The MotoPress Hotel Booking WordPress plugin before 6.2.3 does 
not per ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15229 (The Pinpoint Booking System  WordPress plugin through 
2.9.9.6.9 does n ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15047 (The s2Member  WordPress plugin before 260805 does not escape 
several s ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14941 (The Customer Reviews for WooCommerce WordPress plugin before 
5.116.0 d ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14860 (The Podcast Player  WordPress plugin before 8.3.1 does not 
validate th ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14293 (The Autopay WordPress plugin before 5.0.1 does not perform any 
capabil ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14238 (The vitepos WordPress plugin before 3.6.0 does not sanitize or 
paramet ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14237 (The vitepos WordPress plugin before 3.6.0, Vitepos  WordPress 
plugin b ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14211 (The Booking for Appointments and Events Calendar  WordPress 
plugin bef ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14206 (The HT Contact Form  WordPress plugin before 2.9.3 does not 
perform an ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13701 (The Advanced Excerpt WordPress plugin before 4.5 does not 
sanitise and ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13600 (The AutoNetTV Relay WordPress plugin before 3.0.14 does not 
perform an ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13170 (The Eventin  WordPress plugin before 4.1.20 does not properly 
validate ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13133 (A vulnerability has been identified in LineInst.exe (LINE for 
Windows) ...)
        TODO: check
 CVE-2026-12971 (The LearnPress  WordPress plugin before 4.4.4 does not 
validate a user ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12570 (A vulnerability in keras-team/keras versions <= 3.15.0 allows 
for a de ...)
        TODO: check
 CVE-2026-12372 (A Server-Side Request Forgery (SSRF) vulnerability exists in 
nltk/nltk ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/437131317fa4abdd779cbfd2b56575a8e8cdc616

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/437131317fa4abdd779cbfd2b56575a8e8cdc616
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to