Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
4aa827ac by security tracker role at 2026-08-22T07:14:25+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,9 +1,9 @@
 CVE-2026-9052
        REJECTED
 CVE-2026-77811 (Improper input validation in the dashboards-observability 
plugin in Op ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-77810 (In the Neptune connector, a user with access to Neptune 
through Athena ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-77415 (JSONata is a JSON query and transformation language. Prior to 
1.8.8 an ...)
        TODO: check
 CVE-2026-77414 (JSONata is a JSON query and transformation language. Prior to 
1.8.8 an ...)
@@ -17,11 +17,11 @@ CVE-2026-77220 (PDFio before 1.6.5 contains a dangling 
pointer vulnerability in
 CVE-2026-77219 (GNU Emacs before 31.0.91 contains an integer overflow in the 
PBM/PPM/P ...)
        TODO: check
 CVE-2026-77002 (The SmilePass Selfie Login WordPress plugin through 1.0.2 does 
not per ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77001 (The Social Login & Sharing buttons with Analytics By SoClever 
WordPres ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77000 (The WP Social Media Login WordPress plugin through 1.0.6 does 
not veri ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-76905 (kin-openapi is a Go project for handling OpenAPI files. From 
0.10.0 un ...)
        TODO: check
 CVE-2026-76904 (GeoTools is an open source Java library that provides tools 
for geospa ...)
@@ -29,61 +29,61 @@ CVE-2026-76904 (GeoTools is an open source Java library 
that provides tools for
 CVE-2026-76876 (Craftplan before 0.5.1 contains a broken access control 
vulnerability  ...)
        TODO: check
 CVE-2026-76793 (The Firebase Authentication WordPress plugin before 1.7.1 does 
not req ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-76789 (The Slider Hero with Video Background, Animation WordPress 
plugin befo ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-76074 (The AutomatorWP \u2013 Automator plugin for no-code 
automations, webho ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-76069
        REJECTED
 CVE-2026-76057 (The AutomatorWP \u2013 Automator plugin for no-code 
automations, webho ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-75027 (The Themify Builder plugin for WordPress is vulnerable to 
authorizatio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-74252 (Joomla Extension - j2commerce.com - Stored XSS in Guest 
checkout in J2 ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-73323
        REJECTED
 CVE-2026-69238 (There is an HTML injection vulnerability in Esri Portal for 
ArcGIS ver ...)
-       TODO: check
+       NOT-FOR-US: Esri
 CVE-2026-69237 (There is an HTML injection vulnerability in Esri Portal for 
ArcGIS ver ...)
-       TODO: check
+       NOT-FOR-US: Esri
 CVE-2026-69236 (There is a stored cross site scripting issue in Esri Portal 
for ArcGIS ...)
-       TODO: check
+       NOT-FOR-US: Esri
 CVE-2026-69235 (There is a stored cross site scripting issue in Esri Portal 
for ArcGIS ...)
-       TODO: check
+       NOT-FOR-US: Esri
 CVE-2026-69234 (There is a reflected cross site scripting vulnerability in 
Esri Portal ...)
-       TODO: check
+       NOT-FOR-US: Esri
 CVE-2026-69233 (There is a stored cross site scripting issue in Esri Portal 
for ArcGIS ...)
-       TODO: check
+       NOT-FOR-US: Esri
 CVE-2026-69232 (There is a stored cross site scripting issue in Esri Portal 
for ArcGIS ...)
-       TODO: check
+       NOT-FOR-US: Esri
 CVE-2026-69231 (There is a stored cross site scripting issue in Esri Portal 
for ArcGIS ...)
-       TODO: check
+       NOT-FOR-US: Esri
 CVE-2026-69230 (There is a stored cross site scripting issue in Esri Portal 
for ArcGIS ...)
-       TODO: check
+       NOT-FOR-US: Esri
 CVE-2026-69229 (There is an HTML injection vulnerability in Esri Portal for 
ArcGIS ver ...)
-       TODO: check
+       NOT-FOR-US: Esri
 CVE-2026-69228 (There is a missing authentication vulnerability in Esri Portal 
for Arc ...)
-       TODO: check
+       NOT-FOR-US: Esri
 CVE-2026-69225 (There is an information disclosure vulnerability in Esri 
Portal for Ar ...)
-       TODO: check
+       NOT-FOR-US: Esri
 CVE-2026-69224 (There is an information disclosure vulnerability in Esri 
Portal for Ar ...)
-       TODO: check
+       NOT-FOR-US: Esri
 CVE-2026-68508 (Hydra is a framework for elegantly configuring complex 
applications. P ...)
        TODO: check
 CVE-2026-67619
        REJECTED
 CVE-2026-67362 (Joomla Extension - j2commerce.com - Open redirect in cart 
controller i ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-67361 (Joomla Extension - j2commerce.com - Unauthenticated file 
upload with m ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-67360 (Joomla Extension - j2commerce.com - Cross-customer order 
replication i ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-67359 (Joomla Extension - j2commerce.com - Order content disclosure 
J2Store 1 ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-67358 (Joomla Extension - j2commerce.com - Download quota 
manipulation in J2S ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-64679 (Atlantis is a self-hosted golang application that listens for 
Terrafor ...)
        TODO: check
 CVE-2026-63421 (Keystone is a content management system for Node.js. Prior to 
6.5.3, t ...)
@@ -193,23 +193,23 @@ CVE-2026-27463 (Combodo iTop is a web based IT service 
management tool. Prior to
 CVE-2026-27462 (Combodo iTop is a web based IT service management tool. Prior 
to 3.2.3 ...)
        TODO: check
 CVE-2026-19883 (The WPeMatico RSS Feed Fetcher plugin for WordPress is 
vulnerable to u ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19222 (The Forminator Forms  WordPress plugin before 1.57.0.7 does 
not consis ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19221 (The Forminator Forms  WordPress plugin before 1.57.0.5 does 
not restri ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19093 (The Tutor LMS  WordPress plugin before 4.0.6 does not validate 
a store ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18052 (The ManageWP Worker WordPress plugin before 4.9.37 does not 
bind the a ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16738 (The Conekta Payment Gateway WordPress plugin before 6.2.2 does 
not ver ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16612 (The FiboSearch  WordPress plugin before 1.34.1 does not 
consistently e ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16260 (The Post Grid, Slider & Carousel Ultimate  WordPress plugin 
before 1.8 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14187 (The Tutor LMS  WordPress plugin before 4.0.6 does not enforce 
per-obje ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-11805
        REJECTED
 CVE-2026-11615



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4aa827ac583f5034123fb97b18fd2a4c07c3c576

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4aa827ac583f5034123fb97b18fd2a4c07c3c576
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to