Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
29a025a1 by security tracker role at 2026-08-18T19:13:58+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -17,7 +17,7 @@ CVE-2026-75904 (libmodplug through 0.8.9.1 contains an 
out-of-bounds read in pat
 CVE-2026-75898 (RAGFlow before 0.26.3 contains a server-side request forgery 
vulnerabi ...)
        TODO: check
 CVE-2026-75897 (Improper input validation in the capabilities route handler in 
OpenSea ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-75890
        REJECTED
 CVE-2026-75874 (Sandbox escape in the Remote Settings Client component. This 
vulnerabi ...)
@@ -85,11 +85,11 @@ CVE-2026-75828 (Grav before 2.0.15 contains a stored 
cross-site scripting vulner
 CVE-2026-75827 (Grav before 2.0.15 contains an arbitrary file write 
vulnerability in t ...)
        TODO: check
 CVE-2026-75784 (A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. 
Affecte ...)
-       TODO: check
+       NOT-FOR-US: TRENDnet
 CVE-2026-75783 (A security vulnerability has been detected in TRENDnet 
TEW-WLC100P 12. ...)
-       TODO: check
+       NOT-FOR-US: TRENDnet
 CVE-2026-75778 (A vulnerability was identified in code-projects Task 
Management System ...)
-       TODO: check
+       NOT-FOR-US: code-projects
 CVE-2026-75774 (A vulnerability was determined in karakeep-app karakeep up to 
0.32.0.  ...)
        TODO: check
 CVE-2026-75773 (A vulnerability was found in karakeep-app karakeep up to 
0.32.0. The a ...)
@@ -227,15 +227,15 @@ CVE-2026-74908 (Grav plugin-api before 1.0.15 contains a 
script injection vulner
 CVE-2026-74907 (Grav before 2.0.15 contains a path traversal vulnerability in 
the stat ...)
        TODO: check
 CVE-2026-74906 (SiYuan before v3.7.4 contains an incorrect authorization 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-74905 (SiYuan before v3.7.4 contains a server-side request forgery 
(SSRF) vul ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-74904 (SiYuan before v3.7.4 is missing authorization checks in 17 
block metad ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-74903 (SiYuan before v3.7.4 contains an insufficient access control 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-74902 (SiYuan before v3.7.4 contains a cross-site scripting 
vulnerability in  ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-74046 (Wazuh 4.4.0 before 4.14.7 contains a denial of service 
vulnerability i ...)
        TODO: check
 CVE-2026-74044 (Wazuh 4.0.0 before 4.14.6 contains a path traversal 
vulnerability that ...)
@@ -245,29 +245,29 @@ CVE-2026-74039 (Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 
contain a denial of se
 CVE-2026-74038 (Wazuh 4.0.0 before 4.14.6 contains a path traversal 
vulnerability that ...)
        TODO: check
 CVE-2026-74015 (Unauthenticated SQL Injection in Readabler < 2.0.18 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74012 (Editor PHP Object Injection in TaxoPress <= 3.51.0 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74009 (Unauthenticated Insecure Direct Object References (IDOR) in 
Razorpay f ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74008 (Unauthenticated Sensitive Data Exposure in Shortcodes and 
extra featur ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74007 (Unauthenticated Sensitive Data Exposure in 3D FlipBook \u2013 
PDF Flip ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74006 (Contributor Broken Access Control in WP Table Builder <= 2.2.0 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74004 (Subscriber Broken Access Control in Gravity Booster &#8211; 
Styles &am ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74003 (Contributor Broken Access Control in RomethemeForm For 
Elementor <= 1. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73997 (Unauthenticated Denial of Service Attack in Starter Templates 
by Kaden ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73996 (Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 
2.3.2 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73995 (Subscriber Broken Authentication in User Registration <= 5.2.6 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73994 (Unauthenticated Broken Access Control in Charitable <= 
1.8.11.3 versio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73834 (A flaw was found in the must-gather component of Red Hat 
Advanced Clus ...)
        TODO: check
 CVE-2026-73692
@@ -277,105 +277,105 @@ CVE-2026-73502 (kin-openapi is a Go project for 
handling OpenAPI files. From 0.2
 CVE-2026-73426 (Trix is a what-you-see-is-what-you-get rich text editor for 
everyday w ...)
        TODO: check
 CVE-2026-73404 (Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 
versions ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73400 (Unauthenticated Local File Inclusion in Restaurant Menu by 
MotoPress < ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73399 (Unauthenticated Broken Authentication in Flutterwave 
WooCommerce <= 3. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73398 (Unauthenticated Broken Authentication in Piraeus Bank 
WooCommerce Paym ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73397 (Unauthenticated Deserialization of untrusted data in Youzify 
<= 1.3.7  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73396 (Subscriber Broken Authentication in MWB HubSpot for 
WooCommerce <= 1.6 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73395 (Unauthenticated Insecure Direct Object References (IDOR) in 
Booking ca ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73393 (Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 
10.46 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73392 (Unauthenticated SQL Injection in Super Store Finder <= 7.8 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73383 (Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73382 (Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 
8.2.0 ve ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73381 (Unauthenticated Broken Authentication in Popup by Supsystic <= 
1.13.0  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73380 (Unauthenticated PHP Object Injection in Popup by Supsystic <= 
1.13.0 v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73379 (Unauthenticated Bypass Vulnerability in Contact Form by 
Supsystic < 1. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73378 (Unauthenticated Cross Site Scripting (XSS) in Contact Form by 
Supsysti ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73377 (Unauthenticated Broken Access Control in Ultimate Maps by 
Supsystic <  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73376 (Unauthenticated PHP Object Injection in Ultimate Maps by 
Supsystic < 1 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73375 (Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by 
Supsyst ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73373 (Joomla! Core - [20260810] - Unrestricted uploads of SHTML 
files in Joo ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-73372 (Joomla! Core - [20260809] - Improper ACL checks when injection 
schema. ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-73371 (Joomla! Core - [20260808] - Improper ACL checks for batch copy 
actions ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-73367 (Unauthenticated Remote File Inclusion in Easy Google Maps < 
1.14.2 ver ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73366 (Unauthenticated PHP Object Injection in Easy Google Maps <= 
1.13.0 ver ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73365 (Unauthenticated SQL Injection in JetAppointment <= 2.5.2 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73362 (Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 
2.5.0 ve ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73361 (Unauthenticated Cross Site Scripting (XSS) in Recipe Card 
Blocks for G ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73360 (Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 
3.5.8 versi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73359 (Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for 
GDPR, CC ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73358 (Unauthenticated Cross Site Scripting (XSS) in Affiliates 
Manager <= 2. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73356 (Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73355 (Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 
versions ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73352 (Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73351 (Unauthenticated Cross Site Scripting (XSS) in WordPress Social 
Login a ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73350 (Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73348 (Unauthenticated Broken Access Control in GiveWP < 4.16.6 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73345 (Customer SQL Injection in License Manager for WooCommerce <= 
3.0.18 ve ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73343 (Unauthenticated Remote Code Execution (RCE) in WP Compress < 
7.20.01 v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73342 (Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 
2.4.31 v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73341 (Unauthenticated PHP Object Injection in RegistrationMagic <= 
6.0.9.7 v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73339 (Unauthenticated SQL Injection in Modern Events Calendar < 
7.35.0 versi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73338 (Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73337 (Joomla! Core - [20260807] - MFA Authentication Bypass in 
Joomla 4.0.0- ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-73336 (Joomla! Core - [20260806] - XSS through schema.org outputs in 
Joomla 5 ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-73190 (Unauthenticated Cross Site Scripting (XSS) in WPDM \u2013 
Premium Pack ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73189 (Subscriber Insecure Direct Object References (IDOR) in WP 
Crowdfunding ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73187 (Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73181 (Unauthenticated Arbitrary File Download in Extra Product 
Options & Add ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73073 (Vim is an open source, command line text editor. Prior to 
9.2.0845, St ...)
        TODO: check
 CVE-2026-72532 (Joomla! Core - [20260806] - Improper ACL checks for category 
webservic ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-72531 (Joomla! Core - [20260804] - Improper ACL checks for custom 
fields webs ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-71880 (Interpretation of untrusted input in template engine in GBIF 
Integrate ...)
        TODO: check
 CVE-2026-71879 (Missing authentication in initial setup functionality left 
exposed unt ...)
@@ -383,15 +383,15 @@ CVE-2026-71879 (Missing authentication in initial setup 
functionality left expos
 CVE-2026-71878 (Missing authentication in initial setup functionality left 
exposed aft ...)
        TODO: check
 CVE-2026-71574 (Joomla! Core - [20260803] - Inconsistent ACL checks for 
mutating webse ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-71573 (Joomla! Core - [20260802] - Improper CORS origin validation in 
Joomla  ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-71572 (Joomla! Core - [20260801] - Response header injection in 
download view ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-71551 (Super Productivity is an advanced todo list app with 
integrated timebo ...)
        TODO: check
 CVE-2026-71539 (n8n is an open source workflow automation platform. Prior to 
1.123.64, ...)
-       TODO: check
+       NOT-FOR-US: n8n
 CVE-2026-71477 (mise manages dev tools like node, python, cmake, and 
terraform. Prior  ...)
        TODO: check
 CVE-2026-71365 (A server-side request forgery (SSRF) vulnerability was found 
in AWX's  ...)
@@ -401,7 +401,7 @@ CVE-2026-70667 (Lemur manages TLS certificate creation. 
Prior to 1.9.3, _validat
 CVE-2026-70657 (Copyparty is a portable file server. Prior to 1.20.17, 
copyparty volum ...)
        TODO: check
 CVE-2026-70415 (Dell PowerStore SDNAS contains a Buffer Copy without Checking 
Size of  ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-69220 (The RabbitMQ Java client library allows Java and JVM-based 
application ...)
        TODO: check
 CVE-2026-69219 (The RabbitMQ Java client library allows Java and JVM-based 
application ...)
@@ -421,11 +421,11 @@ CVE-2026-68923 (MobSF is a mobile application security 
testing tool used. Prior
 CVE-2026-68922 (MobSF is a mobile application security testing tool used. 
Prior to 4.5 ...)
        TODO: check
 CVE-2026-68568 (Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-68567 (Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 
1.0.1 ver ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-68565 (Contributor Cross Site Scripting (XSS) in GeoDirectory <= 
2.8.172 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-67921 (Cross-Site Request Forgery (CSRF) vulnerability exists in Halo 
CMS ver ...)
        TODO: check
 CVE-2026-67920 (An issue in Halo 2.25.4 allows a remote attacker to execute 
arbitrary  ...)
@@ -433,9 +433,9 @@ CVE-2026-67920 (An issue in Halo 2.25.4 allows a remote 
attacker to execute arbi
 CVE-2026-67846 (Berkeley Out-of-Order Machine (BOOM) commit 
5223e44cfeb26f41380057a2eb ...)
        TODO: check
 CVE-2026-67271 (Dell PowerStore SDNAS, contains an Out-of-bounds Write 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-67262 (Dell PowerStore contains a Missing Authorization 
vulnerability. An att ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-66793 (A flaw was found in the governance-policy-addon-controller 
component o ...)
        TODO: check
 CVE-2026-66783 (A flaw was found in the `submariner-operator` component of Red 
Hat Adv ...)
@@ -447,47 +447,47 @@ CVE-2026-66781 (A flaw was found in the Submariner 
operator. The Submariner Cust
 CVE-2026-66780 (A flaw was found in the submariner-operator component. The 
`submariner ...)
        TODO: check
 CVE-2026-66679 (Unauthenticated Broken Access Control in Appointment Hour 
Booking <= 1 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66667 (Unauthenticated Cross Site Scripting (XSS) in Templately <= 
3.7.1 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66651 (Unauthenticated Broken Access Control in MultiVendorX <= 
5.0.14 versio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66646 (Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 
1.2.11 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66645 (Contributor Cross Site Scripting (XSS) in Table Of Contents 
Block <= 1 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66644 (Contributor Cross Site Scripting (XSS) in Typing Effect <= 
1.3.7 versi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66643 (Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 
1.55 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66641 (Contributor Cross Site Scripting (XSS) in Video Conferencing 
with Zoom ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66640 (Contributor Cross Site Scripting (XSS) in Login With Ajax <= 
4.5.1 ver ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66639 (Contributor Cross Site Scripting (XSS) in WPZOOM Forms \u2013 
Contact  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66638 (Contributor Cross Site Scripting (XSS) in Frontend Admin by 
DynamiApps ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66637 (Contributor Cross Site Scripting (XSS) in Featured Video Plus 
<= 2.3.3 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66636 (Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66635 (Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 
10Web < ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66634 (Subscriber Insecure Direct Object References (IDOR) in Modal 
Survey <= ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66633 (Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro 
Add On  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66629 (Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66627 (Contributor Arbitrary File Upload in GP Premium <= 2.5.5 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66622 (Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66621 (Unauthenticated Cross Site Scripting (XSS) in Ultimate 
Dashboard <= 3. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66620 (Editor PHP Object Injection in OptionTree <= 2.7.3 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66046 (Expat through 2.8.3 contains a denial of service vulnerability 
caused  ...)
        TODO: check
 CVE-2026-65959 (Vitess is a database clustering system for horizontal scaling 
of MySQL ...)
@@ -523,7 +523,7 @@ CVE-2026-61634 (The RabbitMQ Java client library allows 
Java and JVM-based appli
 CVE-2026-61574 (authentik is an open-source identity provider. Prior to 
2026.2.6 and 2 ...)
        TODO: check
 CVE-2026-61407 (Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain 
an Expose ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-5224 (Cleartext storage of sensitive information vulnerability in 
Kriptok Cr ...)
        TODO: check
 CVE-2026-59949 (yawkat LZ4 Java provides LZ4 compression for Java. Prior to 
1.11.1, JN ...)
@@ -617,113 +617,113 @@ CVE-2026-48744 (Saleor is an e-commerce platform. From 
3.14.67 until 3.21.67, 3.
 CVE-2026-48508 (Lemur manages TLS certificate creation. Prior to 1.9.1, 
StrictRolePerm ...)
        TODO: check
 CVE-2026-47630 (NVIDIA Triton Inference Server for Linux contains a 
vulnerability wher ...)
-       TODO: check
+       NOT-FOR-US: NVIDIA
 CVE-2026-47629 (NVIDIA Triton Inference Server for Linux contains a 
vulnerability wher ...)
-       TODO: check
+       NOT-FOR-US: NVIDIA
 CVE-2026-47628 (NVIDIA Triton Inference Server for Linux contains a 
vulnerability wher ...)
-       TODO: check
+       NOT-FOR-US: NVIDIA
 CVE-2026-47627 (NVIDIA Triton Inference Server for Linux contains a 
vulnerability wher ...)
-       TODO: check
+       NOT-FOR-US: NVIDIA
 CVE-2026-47606 (NVIDIA Triton Inference Server for Linux contains a 
vulnerability wher ...)
-       TODO: check
+       NOT-FOR-US: NVIDIA
 CVE-2026-47245 (MyBB is free and open source forum software. Prior to 1.8.40, 
the User ...)
-       TODO: check
+       NOT-FOR-US: MyBB
 CVE-2026-46482 (### Impact The registration component does not validate the 
text-based ...)
-       TODO: check
+       NOT-FOR-US: MyBB
 CVE-2026-45734 (MyBB is free and open source forum software. Prior to 1.8.40, 
the buil ...)
-       TODO: check
+       NOT-FOR-US: MyBB
 CVE-2026-45733 (Trilium Notes is a cross-platform, hierarchical note taking 
applicatio ...)
        TODO: check
 CVE-2026-45532 (DataEase is an open source data visualization and analysis 
tool. Versi ...)
-       TODO: check
+       NOT-FOR-US: DataEase
 CVE-2026-45129 (MyBB is free and open source forum software. Prior to 1.8.40, 
the Admi ...)
-       TODO: check
+       NOT-FOR-US: MyBB
 CVE-2026-45128 (MyBB is free and open source forum software. Prior to 1.8.40, 
the ACP  ...)
-       TODO: check
+       NOT-FOR-US: MyBB
 CVE-2026-45127 (MyBB is free and open source forum software. Prior to 1.8.40, 
the ACP  ...)
-       TODO: check
+       NOT-FOR-US: MyBB
 CVE-2026-45126 (MyBB is free and open source forum software. Prior to 1.8.40, 
the Admi ...)
-       TODO: check
+       NOT-FOR-US: MyBB
 CVE-2026-45125 (MyBB is free and open source forum software. Prior to 1.8.40, 
the Emai ...)
-       TODO: check
+       NOT-FOR-US: MyBB
 CVE-2026-45124 (MyBB is free and open source forum software. Prior to 1.8.40, 
the Mod  ...)
-       TODO: check
+       NOT-FOR-US: MyBB
 CVE-2026-45123 (MyBB is free and open source forum software. Prior to 1.8.40, 
the remo ...)
-       TODO: check
+       NOT-FOR-US: MyBB
 CVE-2026-45122 (MyBB is free and open source forum software. Prior to 1.8.40, 
the cale ...)
-       TODO: check
+       NOT-FOR-US: MyBB
 CVE-2026-45121 (MyBB is free and open source forum software. Prior to 1.8.40, 
the cale ...)
-       TODO: check
+       NOT-FOR-US: MyBB
 CVE-2026-45120 (MyBB is free and open source forum software. Prior to 1.8.40, 
the cale ...)
-       TODO: check
+       NOT-FOR-US: MyBB
 CVE-2026-45119 (MyBB is free and open source forum software. Prior to 1.8.40, 
the Admi ...)
-       TODO: check
+       NOT-FOR-US: MyBB
 CVE-2026-45118 (MyBB is free and open source forum software. Prior to 1.8.40, 
the Cont ...)
-       TODO: check
+       NOT-FOR-US: MyBB
 CVE-2026-45117 (MyBB is free and open source forum software. From 1.8.13 until 
1.8.40, ...)
-       TODO: check
+       NOT-FOR-US: MyBB
 CVE-2026-45116 (MyBB is free and open source forum software. Prior to 1.8.40, 
the user ...)
-       TODO: check
+       NOT-FOR-US: MyBB
 CVE-2026-45115 (MyBB is free and open source forum software. Prior to 1.8.40, 
the Budd ...)
-       TODO: check
+       NOT-FOR-US: MyBB
 CVE-2026-44472 (Saleor is an e-commerce platform. From 2.10.0rc1 until 
3.21.67, 3.22.6 ...)
        TODO: check
 CVE-2026-43971 (Improper Encoding or Escaping of Output vulnerability in 
ninenines cow ...)
        TODO: check
 CVE-2026-34884 (SSRF via set_skywalking_url Tool and GraphQL expression 
injection vuln ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-32657 (Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, 
Dell UCC  ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-32553 (Unauthenticated Server Side Request Forgery (SSRF) in OttoKit 
<= 1.1.3 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32549 (Unauthenticated Broken Access Control in ThumbPress < 6.5 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32547 (Unauthenticated Cross Site Scripting (XSS) in BP Better 
Messages <= 2. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32481 (Unauthenticated Broken Authentication in Ezoic <= 2.22.11 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32474 (Contributor Arbitrary File Upload in Templatiq <= 0.2.5 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32473 (Unauthenticated Server Side Request Forgery (SSRF) in PDF 
Smart Viewer ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32472 (Unauthenticated Broken Access Control in Online Contact Widget 
<= 1.3. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32470 (Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32468 (Unauthenticated Sensitive Data Exposure in Duitku Payment 
Gateway <= 2 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32467 (Subscriber Server Side Request Forgery (SSRF) in [Aotuman] 
Grab WeChat ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32466 (Subscriber SQL Injection in Gravity Forms Bookings premium <= 
2.1 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32465 (Customer PHP Object Injection in Essential Real Estate <= 
5.3.3 versio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32464 (Unauthenticated Local File Inclusion in Theme Test Drive <= 
2.9.1 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32463 (Contributor Arbitrary File Upload in Sync Post With Other Site 
<= 1.9. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32444 (Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32333 (Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 
5.4.7 ve ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-30250 (Cross-site scripting vulnerability in the user documentation 
field in  ...)
        TODO: check
 CVE-2026-28571 (Unauthenticated Broken Access Control in FormyChat <= 2.15.7 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28570 (Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28569 (Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 
4.7.43 versio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28568 (Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 
5.7.1 ver ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28567 (Unauthenticated Broken Access Control in WP Sort Order <= 
1.3.5 versio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28192 (Unauthenticated Arbitrary File Upload in Piotnet Addons For 
Elementor  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28191 (Subscriber Privilege Escalation in The Grid <= 2.7.9.1 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-24301 (Improper neutralization of special elements used in a command 
('comman ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-24185 (NVIDIA NVOS for network switches contains a vulnerability in 
the secur ...)
        TODO: check
 CVE-2026-24184 (NVIDIA Cumulus Linux contains a vulnerability in the Link 
Layer Discov ...)
@@ -765,7 +765,7 @@ CVE-2026-18963 (A flaw was found in the reset-credentials 
flow of the keycloak-s
 CVE-2026-18929 (Carbone is vulnerable to Denial of Service due to lack of 
protection a ...)
        TODO: check
 CVE-2026-18751 (External control of file name or path vulnerability in Citrix 
WorkSpac ...)
-       TODO: check
+       NOT-FOR-US: Citrix
 CVE-2026-18534 (ArcSearch for iOS versions prior to 1.48.0 could keep the 
address bar  ...)
        TODO: check
 CVE-2026-18392



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/29a025a1789d61171a7c19af1e6d09ace8d79307

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/29a025a1789d61171a7c19af1e6d09ace8d79307
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to