Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a307fb18 by security tracker role at 2026-08-16T07:13:43+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,183 @@
+CVE-2026-9767 (The The School Management \u2013 Education & Learning ERP 
plugin for W ...)
+       TODO: check
+CVE-2026-74767 (Pandora contains a denial-of-service vulnerability in its 
handling of  ...)
+       TODO: check
+CVE-2026-74764 (Pandora contains a path traversal vulnerability in its TAR 
archive ext ...)
+       TODO: check
+CVE-2026-73055 (Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to 
properly esca ...)
+       TODO: check
+CVE-2026-73054 (SiYuan versions before v3.7.4 contain an authentication bypass 
vulnera ...)
+       TODO: check
+CVE-2026-73053 (SiYuan versions before v3.7.4 contain a cross-site scripting 
vulnerabi ...)
+       TODO: check
+CVE-2026-73052 (SiYuan before v3.7.4 stores attribute-view field names without 
HTML es ...)
+       TODO: check
+CVE-2026-73050 (SiYuan versions before v3.7.4 fail to validate or escape the 
color fie ...)
+       TODO: check
+CVE-2026-73047 (siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a 
server-side templ ...)
+       TODO: check
+CVE-2026-73046 (SiYuan before v3.7.4 improperly restricts excessive 
authentication att ...)
+       TODO: check
+CVE-2026-73045 (SiYuan before 3.7.4 contains an improper restriction of 
excessive auth ...)
+       TODO: check
+CVE-2026-73044 (SiYuan versions before v3.7.4 fail to validate or escape table 
column  ...)
+       TODO: check
+CVE-2026-73043 (SiYuan versions before v3.7.4 contain a remote code execution 
vulnerab ...)
+       TODO: check
+CVE-2026-73042 (SiYuan before v3.7.4 fails to properly escape database menu 
metadata i ...)
+       TODO: check
+CVE-2026-73041 (SiYuan versions before v3.7.4 fail to validate or escape 
annotation fi ...)
+       TODO: check
+CVE-2026-2497 (The Gallery by BestWebSoft plugin for WordPress is vulnerable 
to SQL I ...)
+       TODO: check
+CVE-2026-2487 (The Admin Custom Login plugin for WordPress is vulnerable to 
Stored Cr ...)
+       TODO: check
+CVE-2026-2357 (The Bold Page Builder plugin for WordPress is vulnerable to 
Stored Cro ...)
+       TODO: check
+CVE-2026-2283 (The User Login History plugin for WordPress is vulnerable to 
SQL Injec ...)
+       TODO: check
+CVE-2026-19934 (A vulnerability has been found in itsourcecode Hospital 
Management Sys ...)
+       TODO: check
+CVE-2026-19933 (A weakness has been identified in DefaultFuction 
Customer-Relationship ...)
+       TODO: check
+CVE-2026-19932 (A security flaw has been discovered in DefaultFuction 
Notice-System-Ma ...)
+       TODO: check
+CVE-2026-19930 (A security flaw has been discovered in Dolibarr up to 23.0.3. 
Affected ...)
+       TODO: check
+CVE-2026-19929 (A vulnerability was identified in OpenBoxes up to 0.9.6. This 
impacts  ...)
+       TODO: check
+CVE-2026-19928 (A vulnerability was determined in OpenBoxes up to 0.9.7. This 
affects  ...)
+       TODO: check
+CVE-2026-19927 (A vulnerability was found in OpenBoxes up to 0.9.7. The 
impacted eleme ...)
+       TODO: check
+CVE-2026-19926 (A vulnerability has been found in Evergreen up to 
3.14.11/3.15.11/3.16 ...)
+       TODO: check
+CVE-2026-19925 (A vulnerability was detected in SourceCodester Stock 
Management System ...)
+       TODO: check
+CVE-2026-19924 (A security vulnerability has been detected in Tenda AC10 
16.03.10.09_m ...)
+       TODO: check
+CVE-2026-19923 (A weakness has been identified in code-projects Online 
Shopping System ...)
+       TODO: check
+CVE-2026-19922 (A security flaw has been discovered in code-projects Online 
Shopping S ...)
+       TODO: check
+CVE-2026-19921 (A vulnerability was identified in code-projects Online 
Shopping System ...)
+       TODO: check
+CVE-2026-19920 (A vulnerability was determined in code-projects Online 
Shopping System ...)
+       TODO: check
+CVE-2026-19919 (A vulnerability was found in code-projects Online Shopping 
System 1.0. ...)
+       TODO: check
+CVE-2026-19918 (A vulnerability has been found in SpaceX Starlink Router Gen 3 
2025.11 ...)
+       TODO: check
+CVE-2026-19917 (A flaw has been found in code-projects Online Food Order 
System 1.0. T ...)
+       TODO: check
+CVE-2026-19916 (A vulnerability was detected in code-projects Online Food 
Order System ...)
+       TODO: check
+CVE-2026-19728 (The Extra Product Options Builder for WooCommerce WordPress 
plugin bef ...)
+       TODO: check
+CVE-2026-19726 (The Visualizer  WordPress plugin before 4.0.7 does not 
properly author ...)
+       TODO: check
+CVE-2026-19725 (The WPvivid \u2014 Backup, Migration & Staging WordPress 
plugin before ...)
+       TODO: check
+CVE-2026-19717 (The CatFolders Document Gallery & PDF Library WordPress plugin 
before  ...)
+       TODO: check
+CVE-2026-19714 (The Simple JWT Login  WordPress plugin before 3.6.8 does not 
validate  ...)
+       TODO: check
+CVE-2026-19712 (The Masteriyo LMS  WordPress plugin before 2.3.3 does not 
sanitise and ...)
+       TODO: check
+CVE-2026-19711 (The Premium Packages  WordPress plugin before 7.0.7 does not 
validate  ...)
+       TODO: check
+CVE-2026-19613 (The ECS  WordPress plugin before 4.3.10 does not perform 
ownership or  ...)
+       TODO: check
+CVE-2026-18653 (The WP Directory Kit WordPress plugin before 1.5.7 does not 
sanitise a ...)
+       TODO: check
+CVE-2026-18432 (The Frontend Admin by DynamiApps plugin for WordPress is 
vulnerable to ...)
+       TODO: check
+CVE-2026-18402 (The SureDash \u2013 Community, Courses & Member Dashboard 
plugin for W ...)
+       TODO: check
+CVE-2026-18385 (The The Paid Membership Plugin, Ecommerce, User Registration 
Form, Log ...)
+       TODO: check
+CVE-2026-18347 (The Kirki \u2013 Freeform Page Builder, Website Builder & 
Customizer p ...)
+       TODO: check
+CVE-2026-18316 (The Solace Extra plugin for WordPress is vulnerable to 
unauthorized mo ...)
+       TODO: check
+CVE-2026-17608 (The WP Compress \u2013 Instant Performance & Speed 
Optimization plugin ...)
+       TODO: check
+CVE-2026-17604 (The Kirki \u2013 Freeform Page Builder, Website Builder & 
Customizer p ...)
+       TODO: check
+CVE-2026-17582 (The Slider Hero plugin for WordPress is vulnerable to 
second-order SQL ...)
+       TODO: check
+CVE-2026-17581 (The WCPOS \u2013 Point of Sale (POS) plugin for WooCommerce 
plugin for ...)
+       TODO: check
+CVE-2026-17533 (The All-in-One WP Migration and Backup WordPress plugin before 
7.108 d ...)
+       TODO: check
+CVE-2026-17123 (The Royal Elementor Addons plugin for WordPress is vulnerable 
to Serve ...)
+       TODO: check
+CVE-2026-17087 (The WP Travel Engine \u2013 Tour Booking Plugin \u2013 Tour 
Operator S ...)
+       TODO: check
+CVE-2026-16779 (The Kubio AI Page Builder plugin for WordPress is vulnerable 
to author ...)
+       TODO: check
+CVE-2026-16775 (The Smash Balloon Social Post Feed \u2013 Simple Social Feeds 
for Word ...)
+       TODO: check
+CVE-2026-16758 (The Snippet Shortcodes plugin for WordPress is vulnerable to 
Stored Cr ...)
+       TODO: check
+CVE-2026-16099 (The Podlove Podcast Publisher plugin for WordPress is 
vulnerable to ar ...)
+       TODO: check
+CVE-2026-16098 (The ProSolution WP Client plugin for WordPress is vulnerable 
to Arbitr ...)
+       TODO: check
+CVE-2026-16079 (The Fullscreen Galleria plugin for WordPress is vulnerable to 
generic  ...)
+       TODO: check
+CVE-2026-15963 (The Quiz and Survey Master (QSM) \u2013 Easy Quiz and Survey 
Maker plu ...)
+       TODO: check
+CVE-2026-15790 (The Youtube Showcase plugin for WordPress is vulnerable to 
Stored Cros ...)
+       TODO: check
+CVE-2026-15726 (The Serious Slider plugin for WordPress is vulnerable to 
Stored Cross- ...)
+       TODO: check
+CVE-2026-15604 (The Toocheke Companion plugin for WordPress is vulnerable to 
Stored Cr ...)
+       TODO: check
+CVE-2026-15602 (The NEX-Forms \u2013 Ultimate Forms Plugin for WordPress 
plugin for Wo ...)
+       TODO: check
+CVE-2026-15441 (The WC Product Table Lite plugin for WordPress is vulnerable 
to CSS In ...)
+       TODO: check
+CVE-2026-15384 (The Manual Image Crop WordPress plugin before 1.15 does not 
perform an ...)
+       TODO: check
+CVE-2026-15351 (The WC Vendors \u2013 WooCommerce Multivendor, WooCommerce 
Marketplace ...)
+       TODO: check
+CVE-2026-15345 (The ShortPixel Adaptive Images \u2013 WebP, AVIF, CDN, Image 
Optimizat ...)
+       TODO: check
+CVE-2026-15066 (The Loco Translate plugin for WordPress is vulnerable to 
Stored Cross- ...)
+       TODO: check
+CVE-2026-15056 (The StoreEngine \u2014 Complete eCommerce Solution with 
Memberships, L ...)
+       TODO: check
+CVE-2026-15009 (The Advanced File Manager \u2013 Ultimate File Manager for 
WordPress A ...)
+       TODO: check
+CVE-2026-15002 (The Platnosci Online Blue Media (Autopay) plugin for WordPress 
is vuln ...)
+       TODO: check
+CVE-2026-14524 (The ProSolution WP Client plugin for WordPress is vulnerable 
to arbitr ...)
+       TODO: check
+CVE-2026-14498 (The Query Wrangler plugin for WordPress is vulnerable to 
Remote Code E ...)
+       TODO: check
+CVE-2026-13712 (The Divi WordPress theme before 5.9.0 does not properly escape 
some of ...)
+       TODO: check
+CVE-2026-13424 (The Online Scheduling and Appointment Booking System \u2013 
Bookly plu ...)
+       TODO: check
+CVE-2026-13358 (The Appointment Booking Calendar \u2014 Simply Schedule 
Appointments B ...)
+       TODO: check
+CVE-2026-13167 (The Everest Forms \u2013 Contact Form, Payment Form, Quiz, 
Survey & Cu ...)
+       TODO: check
+CVE-2026-12998 (The Forminator Forms \u2013 Contact Form, Payment Form & 
Custom Form B ...)
+       TODO: check
+CVE-2026-12905 (The Bookly plugin for WordPress is vulnerable to Insecure 
Direct Objec ...)
+       TODO: check
+CVE-2026-12477 (The Gravity Booster \u2013 Styles & Layouts for Gravity Forms 
plugin f ...)
+       TODO: check
+CVE-2026-11780 (The Quiz and Survey Master (QSM) \u2013 Easy Quiz and Survey 
Maker plu ...)
+       TODO: check
+CVE-2026-10734 (The Infility Global plugin for WordPress is vulnerable to 
Stored Cross ...)
+       TODO: check
+CVE-2026-10035 (The Turnkey bbPress by WeaverTheme plugin for WordPress is 
vulnerable  ...)
+       TODO: check
+CVE-2025-10005 (The PPWP \u2013 Password Protect WordPress | #1 Most-Reviewed 
Password ...)
+       TODO: check
 CVE-2026-73635 (Allocation of resources without limits or throttling 
vulnerability in  ...)
        - libstruts1.2-java <removed>
        NOTE: https://cwiki.apache.org/confluence/display/WW/S2-074



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a307fb18c65c1a35ce0ae8471ceb722888266e0f

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a307fb18c65c1a35ce0ae8471ceb722888266e0f
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to