Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
71e990de by security tracker role at 2026-08-13T19:14:52+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -61,25 +61,25 @@ CVE-2026-73612 (File Browser before v2.63.22 fails to 
validate access rules for
 CVE-2026-73611 (File Browser versions from 2.50.0 through 2.63.21 fail to 
validate JWT ...)
        TODO: check
 CVE-2026-73610 (SiYuan before v3.7.4 contains an information disclosure 
vulnerability  ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-73609 (SiYuan versions before v3.7.4 contain an information 
disclosure vulner ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-73608 (SiYuan's development branch (endpoint introduced by commit 
9b8e8956f,  ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-73607 (SiYuan versions before v3.7.4 contain an information 
disclosure vulner ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-73606 (SiYuan versions before v3.7.4 contain an information 
disclosure vulner ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-73605 (SiYuan versions before v3.7.4 contain a path traversal 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-73604 (Flowise before 3.1.3 contains an incomplete credential 
redaction vulne ...)
-       TODO: check
+       NOT-FOR-US: Flowise
 CVE-2026-73603 (Flowise before 3.1.4 fails to validate chatflow visibility in 
the unau ...)
-       TODO: check
+       NOT-FOR-US: Flowise
 CVE-2026-73602 (Flowise before 3.1.3 contains a sandbox escape vulnerability 
in the vm ...)
-       TODO: check
+       NOT-FOR-US: Flowise
 CVE-2026-73601 (Flowise versions before 3.1.3 contain a remote code execution 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: Flowise
 CVE-2026-73585 (A flaw was found in sblim-cmpi-base. Insecure temporary file 
creation  ...)
        TODO: check
 CVE-2026-73584 (A flaw was found in sblim-sfcb. A local, low-privileged 
attacker can e ...)
@@ -87,19 +87,19 @@ CVE-2026-73584 (A flaw was found in sblim-sfcb. A local, 
low-privileged attacker
 CVE-2026-73583 (A flaw was found in sblim-sfcb. A local attacker with access 
to the sy ...)
        TODO: check
 CVE-2026-73576 (In Zimbra Collaboration (ZCS) before 10.1.17,weak 
cryptographic key ge ...)
-       TODO: check
+       NOT-FOR-US: Zimbra
 CVE-2026-73575 (In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site 
Request For ...)
-       TODO: check
+       NOT-FOR-US: Zimbra
 CVE-2026-73574 (In Zimbra Collaboration before 10.1.17, a local file inclusion 
(LFI) v ...)
-       TODO: check
+       NOT-FOR-US: Zimbra
 CVE-2026-73573 (In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal 
vulnera ...)
-       TODO: check
+       NOT-FOR-US: Zimbra
 CVE-2026-73572 (In Zimbra Collaboration (ZCS) before 10.1.17, a stored 
cross-site scri ...)
-       TODO: check
+       NOT-FOR-US: Zimbra
 CVE-2026-73571 (An authorization bypass vulnerability exists in Zimbra 
Collaboration ( ...)
-       TODO: check
+       NOT-FOR-US: Zimbra
 CVE-2026-73570 (A remote code execution vulnerability exists in Zimbra 
Collaboration ( ...)
-       TODO: check
+       NOT-FOR-US: Zimbra
 CVE-2026-73569 (fast-xml-parser allows users to process XML from JS object 
without C/C ...)
        TODO: check
 CVE-2026-73568 (py-libp2p is the Python implementation of the libp2p 
networking stack. ...)
@@ -147,41 +147,41 @@ CVE-2026-73506 (Oh My Posh is the most customisable and 
low-latency cross platfo
 CVE-2026-73505 (Oh My Posh is the most customisable and low-latency cross 
platform/she ...)
        TODO: check
 CVE-2026-73488 (Flowise versions before 3.1.3 contain an insecure direct 
object refere ...)
-       TODO: check
+       NOT-FOR-US: Flowise
 CVE-2026-73487 (Flowise before 3.1.3 contains a regex-based Python code 
validator bypa ...)
-       TODO: check
+       NOT-FOR-US: Flowise
 CVE-2026-73486 (Flowise before 3.1.3 contains a code injection vulnerability 
in the CS ...)
-       TODO: check
+       NOT-FOR-US: Flowise
 CVE-2026-73485 (Flowise before 3.1.3 contains a code injection vulnerability 
in the Ai ...)
-       TODO: check
+       NOT-FOR-US: Flowise
 CVE-2026-73484 (Flowise before 3.1.3 contains a sandbox escape vulnerability 
in python ...)
-       TODO: check
+       NOT-FOR-US: Flowise
 CVE-2026-73483 (Flowise (packages flowise and flowise-components) in versions 
<= 3.1.2 ...)
-       TODO: check
+       NOT-FOR-US: Flowise
 CVE-2026-73482 (phpList before 3.7.0-RC5 contains a cross-site request forgery 
(CSRF)  ...)
        TODO: check
 CVE-2026-73481 (phpList before 3.7.0-RC5 fail to enforce CSRF token validation 
on the  ...)
        TODO: check
 CVE-2026-73403 (Unauthenticated Broken Access Control in User Registration <= 
5.2.6 ve ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73401 (Unauthenticated Broken Access Control in InstaWP Connect <= 
0.1.3.7 ve ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73357 (Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73353 (Unauthenticated Broken Access Control in Revolut Gateway for 
WooCommer ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73349 (Unauthenticated Broken Access Control in GiveWP < 4.16.6 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73346 (Administrator SQL Injection in MailChimp For WooCommerce < 6.2 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73344 (Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 
versions ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73340 (Contributor Cross Site Scripting (XSS) in Featured Image from 
URL <= 5 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73266 (A flaw was found in the clusterclaims-controller component of 
Multiclu ...)
        TODO: check
 CVE-2026-73188 (Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73038 (NodeBB before 4.15.0 contains a stored cross-site scripting 
vulnerabil ...)
        TODO: check
 CVE-2026-73037 (Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected 
cross-site s ...)
@@ -191,7 +191,7 @@ CVE-2026-72777 (Next AI Draw.io through 0.4.16 contains a 
server-side request fo
 CVE-2026-72741 (Rainbond through 6.9.7 contains a broken access control 
vulnerability  ...)
        TODO: check
 CVE-2026-6387 (A potential authentication bypass vulnerability was reported in 
Lenovo ...)
-       TODO: check
+       NOT-FOR-US: Lenovo
 CVE-2026-67991 (crmne/ruby_llm at commit 
fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 cont ...)
        TODO: check
 CVE-2026-67990 (basecamp/upright at commit 
efe4f2e5254ac6e57e45d2261804cca74dbbca3f di ...)
@@ -203,147 +203,147 @@ CVE-2026-67614 (CyberPanel before 3.0.0 contains a 
hard-coded JWT secret vulnera
 CVE-2026-67613 (CyberPanel before 3.0.0 contains a path traversal 
vulnerability that a ...)
        TODO: check
 CVE-2026-66704 (Unauthenticated Server Side Request Forgery (SSRF) in 
Gutenverse Compa ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66700 (Unauthenticated Cross Site Scripting (XSS) in Smart Online 
Order for C ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66698 (Unauthenticated Cross Site Scripting (XSS) in SureDash <= 
1.10.1 versi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66697 (Unauthenticated Cross Site Scripting (XSS) in Colissimo 
Officiel : M\x ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66693 (Subscriber Broken Access Control in Motors <= 1.4.113 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66691 (Unauthenticated Broken Access Control in Nokri <= 1.6.6 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66689 (Unauthenticated Broken Access Control in Anti Spam and list 
cleaner &# ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66687 (Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66661 (Subscriber Privilege Escalation in Directories Pro <= 2.0.5 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66660 (Unauthenticated Broken Access Control in Contact Form 7 \u2013 
PayPal  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66658 (Subscriber SQL Injection in Reviewer <= 3.14.2 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66657 (Unauthenticated Local File Inclusion in Biagiotti Core <= 
2.1.1 versio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66656 (Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66655 (Unauthenticated Cross Site Scripting (XSS) in MultiParcels 
Shipping Fo ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66654 (Subscriber Server Side Request Forgery (SSRF) in Vehica Core 
<= 1.0.10 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66653 (Unauthenticated Local File Inclusion in Barista <= 2.5.1 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66478 (Unauthenticated SQL Injection in Church Admin <= 5.1.1 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66472 (Unauthenticated SQL Injection in Everest Backup <= 2.3.12 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66471 (Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66469 (Unauthenticated Broken Access Control in Arvow AI SEO Writer 
<= 1.5.3  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66468 (Unauthenticated Cross Site Scripting (XSS) in Local Delivery 
Drivers f ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66467 (Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 
2.7.5 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66466 (Unauthenticated Broken Access Control in StoreGrowth: Smart 
Sales Boos ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66465 (Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66464 (Unauthenticated Broken Access Control in Internal Link 
Optimiser <= 5. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66463 (Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66462 (Unauthenticated Sensitive Data Exposure in WooCommerce 
Appointments <= ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66461 (Unauthenticated Broken Access Control in SMEPay: UPI Gateway 
for WooCo ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66460 (Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 
1.18.1  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66459 (Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66458 (Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66456 (Subscriber Cross Site Scripting (XSS) in Profile Extra Fields 
by BestW ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66455 (Subscriber Broken Access Control in ReactPress <= 3.4.0 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66454 (Unauthenticated Broken Access Control in WP Social Avatar <= 
1.5 versi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66453 (Unauthenticated Broken Authentication in Salon booking system 
<= 10.30 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66450 (Unauthenticated Local File Inclusion in  Geo Mashup <= 1.13.18 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66449 (Unauthenticated Cross Site Scripting (XSS) in  Geo Mashup <= 
1.13.18 v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66446 (Subscriber SQL Injection in If-So Dynamic Content 
Personalization <= 1 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66444 (Subscriber Sensitive Data Exposure in Payment Forms for 
Paystack <= 4. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66443 (Unauthenticated Sensitive Data Exposure in REST API Log <= 
1.7.1 versi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66441 (Unauthenticated Broken Access Control in MultiVendorX <= 
5.0.10 versio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66436 (Unauthenticated SQL Injection in Active Products Tables for 
WooCommerc ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66432 (Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66431 (Unauthenticated Broken Access Control in Bitcoin Lightning 
Payment Gat ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66430 (Subscriber SQL Injection in Visitor Traffic Real Time 
Statistics Pro < ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66429 (Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic 
Real Tim ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66426 (Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66424 (Unauthenticated Privilege Escalation in SMS Alert Order 
Notifications  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66256 (** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted 
Data vuln ...)
        TODO: check
 CVE-2026-65936 (A malformed Bluetooth connection request message can cause the 
RS9116W ...)
-       TODO: check
+       NOT-FOR-US: Silicon Labs
 CVE-2026-65935 (Passkey entry Bluetooth LE legacy pairing can be bypassed in 
the RS911 ...)
-       TODO: check
+       NOT-FOR-US: Silicon Labs
 CVE-2026-65934 (An unencrypted 'pause encryption request' message causes a 
denial of s ...)
-       TODO: check
+       NOT-FOR-US: Silicon Labs
 CVE-2026-65933 (A malformed Bluetooth connection request message can cause the 
BT122 t ...)
-       TODO: check
+       NOT-FOR-US: Silicon Labs
 CVE-2026-65932 (The BT122 module stops advertising after receiving a plaintext 
'pause  ...)
-       TODO: check
+       NOT-FOR-US: Silicon Labs
 CVE-2026-65582 (Subscriber Arbitrary File Download in AI Hub <= 1.3.10 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65580 (Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 
versions ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-63426 (During an internal security assessment, a potential 
vulnerability was  ...)
-       TODO: check
+       NOT-FOR-US: Lenovo
 CVE-2026-63425 (During an internal security assessment, a potential improper 
permissio ...)
-       TODO: check
+       NOT-FOR-US: Lenovo
 CVE-2026-63424 (During an internal security assessment, an improperly 
protected key wa ...)
-       TODO: check
+       NOT-FOR-US: Lenovo
 CVE-2026-63423 (During an internal security assessment, a potential 
vulnerability was  ...)
-       TODO: check
+       NOT-FOR-US: Lenovo
 CVE-2026-61984 (Unauthenticated Broken Access Control in WPMobile.App <= 11.77 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61980 (Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61979 (Unauthenticated Privilege Escalation in SAML SP Single Sign On 
<= 5.4. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61978 (Unauthenticated Broken Access Control in Secure Card Gateway 
for ePay  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61974 (Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 
2.3.4 v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61969 (Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61967 (Unauthenticated Privilege Escalation in miniorange otp 
verification <= ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61966 (Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61965 (Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 
1.2.6 versio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61962 (Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 
6.3.0 v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61960 (Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe 
Free <= 8 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59765 (SSRF via Migration Asset Downloads Bypasses hostmatcher \u2014 
Reads I ...)
        TODO: check
 CVE-2026-59763 (Unbounded Arch package file metadata can cause resource 
amplification  ...)
@@ -447,11 +447,11 @@ CVE-2026-55984 (Null Pointer Dereference in AddTime API 
Causes Authenticated Den
 CVE-2026-55982 (OIDC userinfo Endpoint Returns Identity Claims Without 
Enforcing API T ...)
        TODO: check
 CVE-2026-55402 (CVE-2026-55402 is an out of bounds read vulnerability in 
Secure Access ...)
-       TODO: check
+       NOT-FOR-US: Absolute Software
 CVE-2026-55401 (CVE-2026-55401 is a null dereference vulnerability on the 
load-balanci ...)
-       TODO: check
+       NOT-FOR-US: Absolute Software
 CVE-2026-55400 (CVE-2026-55400 is an integer underflow in Secure Access 
servers prior  ...)
-       TODO: check
+       NOT-FOR-US: Absolute Software
 CVE-2026-54481 (Internal API HTTP client hardcodes InsecureSkipVerify:true 
with no con ...)
        TODO: check
 CVE-2026-50105 (RSS/Atom feed handlers bypass API-token scope & public-only 
confinemen ...)
@@ -469,85 +469,85 @@ CVE-2026-45819 (baseline-browser-mapping 2.x before 
2.11.0 calls process.exit()
 CVE-2026-42931 (Denial of Service via Unbounded io.ReadAll in NPM Package Tag 
Endpoint)
        TODO: check
 CVE-2026-3639 (The PPWP \u2013 Password Protect Pages plugin for WordPress is 
vulnera ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-28189 (Unauthenticated Arbitrary File Deletion in Participants 
Database <= 2. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28188 (Unauthenticated Broken Access Control in Hydra Booking <= 
1.2.2 versio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28187 (Unauthenticated Cross Site Scripting (XSS) in Knowledge Base 
for Docum ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28186 (Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28185 (Unauthenticated Broken Authentication in Log in with Google <= 
1.4.2 v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28184 (Subscriber SQL Injection in Form Maker by 10Web <= 1.15.44 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28182 (Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP 
Newsletter <= ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28181 (Subscriber Broken Access Control in AcyMailing SMTP Newsletter 
<= 10.1 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28176 (Unauthenticated PHP Object Injection in Booking Activities <= 
1.18.4 v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28175 (Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic 
Real Ti ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28174 (Customer Sensitive Data Exposure in WP Event SOlution <= 
4.1.18 versio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28173 (Customer Arbitrary Content Deletion in WP Event SOlution <= 
4.1.19 ver ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28170 (Unauthenticated Cross Site Scripting (XSS) in Blog Floating 
Button <=  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28168 (Subscriber SQL Injection in CubeWP <= 1.1.30 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28161 (Subscriber Privilege Escalation in Service Finder Booking <= 
6.2 versi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28159 (Subscriber Broken Access Control in Service Finder Booking <= 
6.2 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28158 (Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 
versions ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28157 (Subscriber Path Traversal in Do Lasso <= 358 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28156 (Subscriber SQL Injection in Do Lasso <= 358 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28155 (Unauthenticated Insecure Direct Object References (IDOR) in Do 
Lasso < ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28154 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
        TODO: check
 CVE-2026-28149 (Unauthenticated PHP Object Injection in Headless Single Sign 
On <= 1.6 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28148 (Unauthenticated Bypass Vulnerability in Headless Single Sign 
On <= 1.6 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28142 (Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 
versions ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28008 (Unauthenticated Broken Authentication in OAuth Single Sign On 
\u2013 S ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28004 (Unauthenticated Cross Site Scripting (XSS) in Business 
Directory <= 6. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28003 (Unauthenticated Cross Site Scripting (XSS) in Maspik \u2013 
Spam black ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28002 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28001 (Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27999 (Subscriber Broken Access Control in Tourfic <= 2.23.1 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27544 (Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 
5.2.0.0 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27543 (Unauthenticated Privilege Escalation in MStore API <= 4.20.0 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27539 (Unauthenticated Cross Site Scripting (XSS) in Welcart 
e-Commerce <= 2. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27538 (Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27537 (Unauthenticated Cross Site Scripting (XSS) in Popup by 
Supsystic <= 1. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27536 (Unauthenticated Cross Site Scripting (XSS) in MailChimp 
Subscribe Form ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27535 (Subscriber Broken Access Control in Solace Extra <= 1.6.0 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27380 (Editor PHP Object Injection in Car Rental Manager <= 1.3.9 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27345 (Unauthenticated Broken Access Control in Taxi Booking Manager 
for WooC ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-24791 (Public-only tokens bypass private-resource restrictions on 
`/api/v1/us ...)
        TODO: check
 CVE-2026-24059 (The GET /api/v1/user/actions/runners/registration-token 
endpoint (and  ...)
@@ -555,7 +555,7 @@ CVE-2026-24059 (The GET 
/api/v1/user/actions/runners/registration-token endpoint
 CVE-2026-23603 (Blind SSRF in OAuth2 avatar synchronization via unvalidated 
OIDC pictu ...)
        TODO: check
 CVE-2026-21832 (HCL AION is affected by a vulnerability where indirect prompt 
injectio ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2026-19744 (Cross-site Scripting in the Markdown renderer in maalfer 
Pentestify be ...)
        TODO: check
 CVE-2026-19734 (Missing Authorization and Authorization Bypass Through 
User-Controlled ...)
@@ -565,7 +565,7 @@ CVE-2026-19730 (The 'podman quadlet install --replace' 
command opens the existin
 CVE-2026-19716 (Stored Cross-site Scripting (CWE-79) in the user management 
component  ...)
        TODO: check
 CVE-2026-19710 (A vulnerability was found in SourceCodester Simple Student 
Information ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-19696 (Ixia IxVeriWave and Vector Informatik BLF file parser crashes 
in 4.6.0 ...)
        TODO: check
 CVE-2026-19695 (Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows 
denial of  ...)
@@ -579,63 +579,63 @@ CVE-2026-19484 (@fastify/busboy is a multipart form-data 
parser. In versions 3.1
 CVE-2026-19481 (@fastify/busboy is a multipart form-data parser. In versions 
1.0.0 thr ...)
        TODO: check
 CVE-2026-19293 (SMP security request (from peripheral)does not include the 
maximum enc ...)
-       TODO: check
+       NOT-FOR-US: Silicon Labs
 CVE-2026-19292 (Re-pairing with a legitimate device can use a lower security 
level tha ...)
-       TODO: check
+       NOT-FOR-US: Silicon Labs
 CVE-2026-19291 (Bluetooth re-pairing with an existing device can use a lower 
security  ...)
-       TODO: check
+       NOT-FOR-US: Silicon Labs
 CVE-2026-18622 (Foxit PDF Editor/Reader inconsistently alerts users when 
signature fie ...)
-       TODO: check
+       NOT-FOR-US: Foxit
 CVE-2026-18428 (A SQL query validation bypass in the Flint extension query 
handler in  ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-18368 (In Teltonika Networks RUTOS devices, a vulnerability exists in 
modbusg ...)
-       TODO: check
+       NOT-FOR-US: Teltonika Networks
 CVE-2026-18071 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to 
gain elev ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17220 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17197 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
bypass s ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16459 (Padding oracle attack vulnerability in Oberon microsystem 
AG\u2019s Ob ...)
        TODO: check
 CVE-2026-16458 (Padding oracle attack vulnerability in Oberon microsystem 
AG\u2019s oc ...)
        TODO: check
 CVE-2026-16455 (In Teltonika Networks RUTOS devices running versions 7.07.1 
through 7. ...)
-       TODO: check
+       NOT-FOR-US: Teltonika Networks
 CVE-2026-16101 (Spoofing an already bonded device can force either RS9116W or 
SiWx917  ...)
-       TODO: check
+       NOT-FOR-US: Silicon Labs
 CVE-2026-15994 (During an internal security assessment, an improper link 
following vul ...)
-       TODO: check
+       NOT-FOR-US: Lenovo
 CVE-2026-15413 (The Link Factory WordPress plugin is a backdoor. Distributed 
as a "hom ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14456 (Issue summary: When an OpenSSL QUIC server (Listener SSL 
object) proce ...)
        TODO: check
 CVE-2026-14332 (The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress 
plugin befor ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14298 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x 
<= 11.7 ...)
        TODO: check
 CVE-2026-14256 (ELAN reported a potential out-of-bounds write vulnerability in 
the ELA ...)
-       TODO: check
+       NOT-FOR-US: Lenovo
 CVE-2026-12908
        REJECTED
 CVE-2026-12263 (Zohocorp ManageEngine Password Manager Pro versions before 
13232 and P ...)
-       TODO: check
+       NOT-FOR-US: Zoho
 CVE-2026-12236 (The Bluetooth host GATT client function 
parse_read_std_char_desc() in  ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12036 (An improper link following vulnerability was reported in the 
VantageCo ...)
-       TODO: check
+       NOT-FOR-US: Lenovo
 CVE-2026-11970 (This vulnerability allows a normal (non-admin) user to disable 
the For ...)
-       TODO: check
+       NOT-FOR-US: Forcepoint
 CVE-2026-11840 (Zohocorp ManageEngine Password Manager Pro versions before 
13232 and M ...)
-       TODO: check
+       NOT-FOR-US: Zoho
 CVE-2025-62318 (HCL AION is affected by a vulnerability where JavaScript 
responses con ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2025-62315 (HCL AION is affected by a vulnerability where certain input 
fields do  ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2025-62314 (HCL AION is affected by a vulnerability where certain 
endpoints lack s ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2025-52640 (HCL AION is affected by a vulnerability where the shared 
storage used  ...)
-       TODO: check
+       NOT-FOR-US: HCL
 CVE-2024-58374 (Hongjing e-HR contains an unauthenticated SQL injection 
vulnerability  ...)
        TODO: check
 CVE-2019-25765 (ASP-CMS contains a SQL injection vulnerability in the 
commentList.asp  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71e990de0b782bc52d763127b7690421dc86b8a4

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71e990de0b782bc52d763127b7690421dc86b8a4
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to