Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
71e990de by security tracker role at 2026-08-13T19:14:52+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -61,25 +61,25 @@ CVE-2026-73612 (File Browser before v2.63.22 fails to
validate access rules for
CVE-2026-73611 (File Browser versions from 2.50.0 through 2.63.21 fail to
validate JWT ...)
TODO: check
CVE-2026-73610 (SiYuan before v3.7.4 contains an information disclosure
vulnerability ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73609 (SiYuan versions before v3.7.4 contain an information
disclosure vulner ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73608 (SiYuan's development branch (endpoint introduced by commit
9b8e8956f, ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73607 (SiYuan versions before v3.7.4 contain an information
disclosure vulner ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73606 (SiYuan versions before v3.7.4 contain an information
disclosure vulner ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73605 (SiYuan versions before v3.7.4 contain a path traversal
vulnerability i ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73604 (Flowise before 3.1.3 contains an incomplete credential
redaction vulne ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-73603 (Flowise before 3.1.4 fails to validate chatflow visibility in
the unau ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-73602 (Flowise before 3.1.3 contains a sandbox escape vulnerability
in the vm ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-73601 (Flowise versions before 3.1.3 contain a remote code execution
vulnerab ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-73585 (A flaw was found in sblim-cmpi-base. Insecure temporary file
creation ...)
TODO: check
CVE-2026-73584 (A flaw was found in sblim-sfcb. A local, low-privileged
attacker can e ...)
@@ -87,19 +87,19 @@ CVE-2026-73584 (A flaw was found in sblim-sfcb. A local,
low-privileged attacker
CVE-2026-73583 (A flaw was found in sblim-sfcb. A local attacker with access
to the sy ...)
TODO: check
CVE-2026-73576 (In Zimbra Collaboration (ZCS) before 10.1.17,weak
cryptographic key ge ...)
- TODO: check
+ NOT-FOR-US: Zimbra
CVE-2026-73575 (In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site
Request For ...)
- TODO: check
+ NOT-FOR-US: Zimbra
CVE-2026-73574 (In Zimbra Collaboration before 10.1.17, a local file inclusion
(LFI) v ...)
- TODO: check
+ NOT-FOR-US: Zimbra
CVE-2026-73573 (In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal
vulnera ...)
- TODO: check
+ NOT-FOR-US: Zimbra
CVE-2026-73572 (In Zimbra Collaboration (ZCS) before 10.1.17, a stored
cross-site scri ...)
- TODO: check
+ NOT-FOR-US: Zimbra
CVE-2026-73571 (An authorization bypass vulnerability exists in Zimbra
Collaboration ( ...)
- TODO: check
+ NOT-FOR-US: Zimbra
CVE-2026-73570 (A remote code execution vulnerability exists in Zimbra
Collaboration ( ...)
- TODO: check
+ NOT-FOR-US: Zimbra
CVE-2026-73569 (fast-xml-parser allows users to process XML from JS object
without C/C ...)
TODO: check
CVE-2026-73568 (py-libp2p is the Python implementation of the libp2p
networking stack. ...)
@@ -147,41 +147,41 @@ CVE-2026-73506 (Oh My Posh is the most customisable and
low-latency cross platfo
CVE-2026-73505 (Oh My Posh is the most customisable and low-latency cross
platform/she ...)
TODO: check
CVE-2026-73488 (Flowise versions before 3.1.3 contain an insecure direct
object refere ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-73487 (Flowise before 3.1.3 contains a regex-based Python code
validator bypa ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-73486 (Flowise before 3.1.3 contains a code injection vulnerability
in the CS ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-73485 (Flowise before 3.1.3 contains a code injection vulnerability
in the Ai ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-73484 (Flowise before 3.1.3 contains a sandbox escape vulnerability
in python ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-73483 (Flowise (packages flowise and flowise-components) in versions
<= 3.1.2 ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-73482 (phpList before 3.7.0-RC5 contains a cross-site request forgery
(CSRF) ...)
TODO: check
CVE-2026-73481 (phpList before 3.7.0-RC5 fail to enforce CSRF token validation
on the ...)
TODO: check
CVE-2026-73403 (Unauthenticated Broken Access Control in User Registration <=
5.2.6 ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73401 (Unauthenticated Broken Access Control in InstaWP Connect <=
0.1.3.7 ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73357 (Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73353 (Unauthenticated Broken Access Control in Revolut Gateway for
WooCommer ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73349 (Unauthenticated Broken Access Control in GiveWP < 4.16.6
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73346 (Administrator SQL Injection in MailChimp For WooCommerce < 6.2
version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73344 (Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79
versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73340 (Contributor Cross Site Scripting (XSS) in Featured Image from
URL <= 5 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73266 (A flaw was found in the clusterclaims-controller component of
Multiclu ...)
TODO: check
CVE-2026-73188 (Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73038 (NodeBB before 4.15.0 contains a stored cross-site scripting
vulnerabil ...)
TODO: check
CVE-2026-73037 (Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected
cross-site s ...)
@@ -191,7 +191,7 @@ CVE-2026-72777 (Next AI Draw.io through 0.4.16 contains a
server-side request fo
CVE-2026-72741 (Rainbond through 6.9.7 contains a broken access control
vulnerability ...)
TODO: check
CVE-2026-6387 (A potential authentication bypass vulnerability was reported in
Lenovo ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-67991 (crmne/ruby_llm at commit
fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 cont ...)
TODO: check
CVE-2026-67990 (basecamp/upright at commit
efe4f2e5254ac6e57e45d2261804cca74dbbca3f di ...)
@@ -203,147 +203,147 @@ CVE-2026-67614 (CyberPanel before 3.0.0 contains a
hard-coded JWT secret vulnera
CVE-2026-67613 (CyberPanel before 3.0.0 contains a path traversal
vulnerability that a ...)
TODO: check
CVE-2026-66704 (Unauthenticated Server Side Request Forgery (SSRF) in
Gutenverse Compa ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66700 (Unauthenticated Cross Site Scripting (XSS) in Smart Online
Order for C ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66698 (Unauthenticated Cross Site Scripting (XSS) in SureDash <=
1.10.1 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66697 (Unauthenticated Cross Site Scripting (XSS) in Colissimo
Officiel : M\x ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66693 (Subscriber Broken Access Control in Motors <= 1.4.113
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66691 (Unauthenticated Broken Access Control in Nokri <= 1.6.6
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66689 (Unauthenticated Broken Access Control in Anti Spam and list
cleaner &# ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66687 (Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66661 (Subscriber Privilege Escalation in Directories Pro <= 2.0.5
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66660 (Unauthenticated Broken Access Control in Contact Form 7 \u2013
PayPal ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66658 (Subscriber SQL Injection in Reviewer <= 3.14.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66657 (Unauthenticated Local File Inclusion in Biagiotti Core <=
2.1.1 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66656 (Unauthenticated Local File Inclusion in Foton Core <= 1.1.1
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66655 (Unauthenticated Cross Site Scripting (XSS) in MultiParcels
Shipping Fo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66654 (Subscriber Server Side Request Forgery (SSRF) in Vehica Core
<= 1.0.10 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66653 (Unauthenticated Local File Inclusion in Barista <= 2.5.1
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66478 (Unauthenticated SQL Injection in Church Admin <= 5.1.1
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66472 (Unauthenticated SQL Injection in Everest Backup <= 2.3.12
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66471 (Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66469 (Unauthenticated Broken Access Control in Arvow AI SEO Writer
<= 1.5.3 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66468 (Unauthenticated Cross Site Scripting (XSS) in Local Delivery
Drivers f ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66467 (Subscriber Cross Site Scripting (XSS) in FluentCommunity <=
2.7.5 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66466 (Unauthenticated Broken Access Control in StoreGrowth: Smart
Sales Boos ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66465 (Unauthenticated Broken Authentication in Cartify <= 1.3.0.1
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66464 (Unauthenticated Broken Access Control in Internal Link
Optimiser <= 5. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66463 (Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66462 (Unauthenticated Sensitive Data Exposure in WooCommerce
Appointments <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66461 (Unauthenticated Broken Access Control in SMEPay: UPI Gateway
for WooCo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66460 (Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <=
1.18.1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66459 (Unauthenticated Broken Access Control in AI for SEO <= 2.4.2
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66458 (Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66456 (Subscriber Cross Site Scripting (XSS) in Profile Extra Fields
by BestW ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66455 (Subscriber Broken Access Control in ReactPress <= 3.4.0
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66454 (Unauthenticated Broken Access Control in WP Social Avatar <=
1.5 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66453 (Unauthenticated Broken Authentication in Salon booking system
<= 10.30 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66450 (Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18
version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66449 (Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <=
1.13.18 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66446 (Subscriber SQL Injection in If-So Dynamic Content
Personalization <= 1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66444 (Subscriber Sensitive Data Exposure in Payment Forms for
Paystack <= 4. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66443 (Unauthenticated Sensitive Data Exposure in REST API Log <=
1.7.1 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66441 (Unauthenticated Broken Access Control in MultiVendorX <=
5.0.10 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66436 (Unauthenticated SQL Injection in Active Products Tables for
WooCommerc ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66432 (Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66431 (Unauthenticated Broken Access Control in Bitcoin Lightning
Payment Gat ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66430 (Subscriber SQL Injection in Visitor Traffic Real Time
Statistics Pro < ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66429 (Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic
Real Tim ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66426 (Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56
version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66424 (Unauthenticated Privilege Escalation in SMS Alert Order
Notifications ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66256 (** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted
Data vuln ...)
TODO: check
CVE-2026-65936 (A malformed Bluetooth connection request message can cause the
RS9116W ...)
- TODO: check
+ NOT-FOR-US: Silicon Labs
CVE-2026-65935 (Passkey entry Bluetooth LE legacy pairing can be bypassed in
the RS911 ...)
- TODO: check
+ NOT-FOR-US: Silicon Labs
CVE-2026-65934 (An unencrypted 'pause encryption request' message causes a
denial of s ...)
- TODO: check
+ NOT-FOR-US: Silicon Labs
CVE-2026-65933 (A malformed Bluetooth connection request message can cause the
BT122 t ...)
- TODO: check
+ NOT-FOR-US: Silicon Labs
CVE-2026-65932 (The BT122 module stops advertising after receiving a plaintext
'pause ...)
- TODO: check
+ NOT-FOR-US: Silicon Labs
CVE-2026-65582 (Subscriber Arbitrary File Download in AI Hub <= 1.3.10
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65580 (Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0
versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-63426 (During an internal security assessment, a potential
vulnerability was ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-63425 (During an internal security assessment, a potential improper
permissio ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-63424 (During an internal security assessment, an improperly
protected key wa ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-63423 (During an internal security assessment, a potential
vulnerability was ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-61984 (Unauthenticated Broken Access Control in WPMobile.App <= 11.77
version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61980 (Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61979 (Unauthenticated Privilege Escalation in SAML SP Single Sign On
<= 5.4. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61978 (Unauthenticated Broken Access Control in Secure Card Gateway
for ePay ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61974 (Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <=
2.3.4 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61969 (Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61967 (Unauthenticated Privilege Escalation in miniorange otp
verification <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61966 (Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61965 (Unauthenticated Cross Site Scripting (XSS) in GeekyBot <=
1.2.6 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61962 (Unauthenticated Arbitrary Code Execution in WP BASE Booking <=
6.3.0 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61960 (Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe
Free <= 8 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59765 (SSRF via Migration Asset Downloads Bypasses hostmatcher \u2014
Reads I ...)
TODO: check
CVE-2026-59763 (Unbounded Arch package file metadata can cause resource
amplification ...)
@@ -447,11 +447,11 @@ CVE-2026-55984 (Null Pointer Dereference in AddTime API
Causes Authenticated Den
CVE-2026-55982 (OIDC userinfo Endpoint Returns Identity Claims Without
Enforcing API T ...)
TODO: check
CVE-2026-55402 (CVE-2026-55402 is an out of bounds read vulnerability in
Secure Access ...)
- TODO: check
+ NOT-FOR-US: Absolute Software
CVE-2026-55401 (CVE-2026-55401 is a null dereference vulnerability on the
load-balanci ...)
- TODO: check
+ NOT-FOR-US: Absolute Software
CVE-2026-55400 (CVE-2026-55400 is an integer underflow in Secure Access
servers prior ...)
- TODO: check
+ NOT-FOR-US: Absolute Software
CVE-2026-54481 (Internal API HTTP client hardcodes InsecureSkipVerify:true
with no con ...)
TODO: check
CVE-2026-50105 (RSS/Atom feed handlers bypass API-token scope & public-only
confinemen ...)
@@ -469,85 +469,85 @@ CVE-2026-45819 (baseline-browser-mapping 2.x before
2.11.0 calls process.exit()
CVE-2026-42931 (Denial of Service via Unbounded io.ReadAll in NPM Package Tag
Endpoint)
TODO: check
CVE-2026-3639 (The PPWP \u2013 Password Protect Pages plugin for WordPress is
vulnera ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-28189 (Unauthenticated Arbitrary File Deletion in Participants
Database <= 2. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28188 (Unauthenticated Broken Access Control in Hydra Booking <=
1.2.2 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28187 (Unauthenticated Cross Site Scripting (XSS) in Knowledge Base
for Docum ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28186 (Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1
version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28185 (Unauthenticated Broken Authentication in Log in with Google <=
1.4.2 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28184 (Subscriber SQL Injection in Form Maker by 10Web <= 1.15.44
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28182 (Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP
Newsletter <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28181 (Subscriber Broken Access Control in AcyMailing SMTP Newsletter
<= 10.1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28176 (Unauthenticated PHP Object Injection in Booking Activities <=
1.18.4 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28175 (Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic
Real Ti ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28174 (Customer Sensitive Data Exposure in WP Event SOlution <=
4.1.18 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28173 (Customer Arbitrary Content Deletion in WP Event SOlution <=
4.1.19 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28170 (Unauthenticated Cross Site Scripting (XSS) in Blog Floating
Button <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28168 (Subscriber SQL Injection in CubeWP <= 1.1.30 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28161 (Subscriber Privilege Escalation in Service Finder Booking <=
6.2 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28159 (Subscriber Broken Access Control in Service Finder Booking <=
6.2 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28158 (Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358
versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28157 (Subscriber Path Traversal in Do Lasso <= 358 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28156 (Subscriber SQL Injection in Do Lasso <= 358 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28155 (Unauthenticated Insecure Direct Object References (IDOR) in Do
Lasso < ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28154 (Improper Neutralization of Input During Web Page Generation
('Cross-si ...)
TODO: check
CVE-2026-28149 (Unauthenticated PHP Object Injection in Headless Single Sign
On <= 1.6 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28148 (Unauthenticated Bypass Vulnerability in Headless Single Sign
On <= 1.6 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28142 (Unauthenticated SQL Injection in Web Directory Free <= 1.7.13
versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28008 (Unauthenticated Broken Authentication in OAuth Single Sign On
\u2013 S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28004 (Unauthenticated Cross Site Scripting (XSS) in Business
Directory <= 6. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28003 (Unauthenticated Cross Site Scripting (XSS) in Maspik \u2013
Spam black ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28002 (Improper Neutralization of Special Elements used in an SQL
Command ('S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28001 (Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27999 (Subscriber Broken Access Control in Tourfic <= 2.23.1
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27544 (Unauthenticated Remote Code Execution (RCE) in QA Analytics <=
5.2.0.0 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27543 (Unauthenticated Privilege Escalation in MStore API <= 4.20.0
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27539 (Unauthenticated Cross Site Scripting (XSS) in Welcart
e-Commerce <= 2. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27538 (Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27537 (Unauthenticated Cross Site Scripting (XSS) in Popup by
Supsystic <= 1. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27536 (Unauthenticated Cross Site Scripting (XSS) in MailChimp
Subscribe Form ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27535 (Subscriber Broken Access Control in Solace Extra <= 1.6.0
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27380 (Editor PHP Object Injection in Car Rental Manager <= 1.3.9
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27345 (Unauthenticated Broken Access Control in Taxi Booking Manager
for WooC ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-24791 (Public-only tokens bypass private-resource restrictions on
`/api/v1/us ...)
TODO: check
CVE-2026-24059 (The GET /api/v1/user/actions/runners/registration-token
endpoint (and ...)
@@ -555,7 +555,7 @@ CVE-2026-24059 (The GET
/api/v1/user/actions/runners/registration-token endpoint
CVE-2026-23603 (Blind SSRF in OAuth2 avatar synchronization via unvalidated
OIDC pictu ...)
TODO: check
CVE-2026-21832 (HCL AION is affected by a vulnerability where indirect prompt
injectio ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-19744 (Cross-site Scripting in the Markdown renderer in maalfer
Pentestify be ...)
TODO: check
CVE-2026-19734 (Missing Authorization and Authorization Bypass Through
User-Controlled ...)
@@ -565,7 +565,7 @@ CVE-2026-19730 (The 'podman quadlet install --replace'
command opens the existin
CVE-2026-19716 (Stored Cross-site Scripting (CWE-79) in the user management
component ...)
TODO: check
CVE-2026-19710 (A vulnerability was found in SourceCodester Simple Student
Information ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-19696 (Ixia IxVeriWave and Vector Informatik BLF file parser crashes
in 4.6.0 ...)
TODO: check
CVE-2026-19695 (Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows
denial of ...)
@@ -579,63 +579,63 @@ CVE-2026-19484 (@fastify/busboy is a multipart form-data
parser. In versions 3.1
CVE-2026-19481 (@fastify/busboy is a multipart form-data parser. In versions
1.0.0 thr ...)
TODO: check
CVE-2026-19293 (SMP security request (from peripheral)does not include the
maximum enc ...)
- TODO: check
+ NOT-FOR-US: Silicon Labs
CVE-2026-19292 (Re-pairing with a legitimate device can use a lower security
level tha ...)
- TODO: check
+ NOT-FOR-US: Silicon Labs
CVE-2026-19291 (Bluetooth re-pairing with an existing device can use a lower
security ...)
- TODO: check
+ NOT-FOR-US: Silicon Labs
CVE-2026-18622 (Foxit PDF Editor/Reader inconsistently alerts users when
signature fie ...)
- TODO: check
+ NOT-FOR-US: Foxit
CVE-2026-18428 (A SQL query validation bypass in the Flint extension query
handler in ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-18368 (In Teltonika Networks RUTOS devices, a vulnerability exists in
modbusg ...)
- TODO: check
+ NOT-FOR-US: Teltonika Networks
CVE-2026-18071 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to
gain elev ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17220 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to
cause a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17197 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to
bypass s ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16459 (Padding oracle attack vulnerability in Oberon microsystem
AG\u2019s Ob ...)
TODO: check
CVE-2026-16458 (Padding oracle attack vulnerability in Oberon microsystem
AG\u2019s oc ...)
TODO: check
CVE-2026-16455 (In Teltonika Networks RUTOS devices running versions 7.07.1
through 7. ...)
- TODO: check
+ NOT-FOR-US: Teltonika Networks
CVE-2026-16101 (Spoofing an already bonded device can force either RS9116W or
SiWx917 ...)
- TODO: check
+ NOT-FOR-US: Silicon Labs
CVE-2026-15994 (During an internal security assessment, an improper link
following vul ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-15413 (The Link Factory WordPress plugin is a backdoor. Distributed
as a "hom ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14456 (Issue summary: When an OpenSSL QUIC server (Listener SSL
object) proce ...)
TODO: check
CVE-2026-14332 (The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress
plugin befor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14298 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x
<= 11.7 ...)
TODO: check
CVE-2026-14256 (ELAN reported a potential out-of-bounds write vulnerability in
the ELA ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-12908
REJECTED
CVE-2026-12263 (Zohocorp ManageEngine Password Manager Pro versions before
13232 and P ...)
- TODO: check
+ NOT-FOR-US: Zoho
CVE-2026-12236 (The Bluetooth host GATT client function
parse_read_std_char_desc() in ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-12036 (An improper link following vulnerability was reported in the
VantageCo ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-11970 (This vulnerability allows a normal (non-admin) user to disable
the For ...)
- TODO: check
+ NOT-FOR-US: Forcepoint
CVE-2026-11840 (Zohocorp ManageEngine Password Manager Pro versions before
13232 and M ...)
- TODO: check
+ NOT-FOR-US: Zoho
CVE-2025-62318 (HCL AION is affected by a vulnerability where JavaScript
responses con ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2025-62315 (HCL AION is affected by a vulnerability where certain input
fields do ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2025-62314 (HCL AION is affected by a vulnerability where certain
endpoints lack s ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2025-52640 (HCL AION is affected by a vulnerability where the shared
storage used ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2024-58374 (Hongjing e-HR contains an unauthenticated SQL injection
vulnerability ...)
TODO: check
CVE-2019-25765 (ASP-CMS contains a SQL injection vulnerability in the
commentList.asp ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71e990de0b782bc52d763127b7690421dc86b8a4
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71e990de0b782bc52d763127b7690421dc86b8a4
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits