Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
b84eb790 by security tracker role at 2026-09-01T07:13:40+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -33,7 +33,7 @@ CVE-2026-82905 (A vulnerability was detected in sdcb chats up
to 1.12.0. This af
CVE-2026-82882 (Devtron through 2.2.0 fails to enforce authorization checks on
the GET ...)
TODO: check
CVE-2026-82852 (Unauthenticated Server Side Request Forgery (SSRF) in MapSVG
<= 8.15.0 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-82835 (A weakness has been identified in caoqianming django-vue-admin
1.0. Th ...)
TODO: check
CVE-2026-82834 (A security flaw has been discovered in Doccano Open Source
Annotation ...)
@@ -95,19 +95,19 @@ CVE-2026-82393 (pnpm is a package manager. Prior to 10.34.5
and 11.11.0, pnpm ac
CVE-2026-82392 (pnpm is a package manager. Prior to 10.34.5 and from 11.0.0
until 11.1 ...)
TODO: check
CVE-2026-82346 (A potential security vulnerability has been identified in the
HP Image ...)
- TODO: check
+ NOT-FOR-US: HP
CVE-2026-82229 (Unauthenticated Cross Site Scripting (XSS) in WordPress Social
Login a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-82228 (Unauthenticated Bypass Vulnerability in SiteGround Security <=
1.6.6 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-82226 (Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-82225 (Unauthenticated Broken Authentication in RegistrationMagic <=
6.0.9.8 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-82224 (Unauthenticated Cross Site Scripting (XSS) in SliceWP <=
1.2.10 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-82221 (Unauthenticated Cross Site Scripting (XSS) in
RegistrationMagic <= 6.0 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81892 (EasyAdmin is a fast and modern admin generator for Symfony
application ...)
TODO: check
CVE-2026-81891 (elFinder is an open-source file manager for web, written in
JavaScript ...)
@@ -121,43 +121,43 @@ CVE-2026-81888 (@hono/oauth-providers is Authentication
middleware for Hono. Pri
CVE-2026-81887 (Livewire is a full-stack framework for Laravel. From
3.0.0-beta.1 unti ...)
TODO: check
CVE-2026-81780 (Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81779 (Improper Validation of Specified Quantity in Input
vulnerability in Si ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81778 (Subscriber Cross Site Scripting (XSS) in Kalles Addons <=
1.0.6 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81768 (Unauthenticated Cross Site Scripting (XSS) in Super Store
Finder <= 7. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81765 (Unauthenticated Cross Site Scripting (XSS) in Tailored Tools
<= 3.0.2 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81764 (Unauthenticated Cross Site Scripting (XSS) in Email Essentials
<= 6.0. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81763 (Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81762 (Subscriber Broken Access Control in Booking and Rental Manager
<= 2.7. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81758 (Subscriber Broken Access Control in OwnerRez API <= 1.2.6
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81756 (Unauthenticated SQL Injection in Smart Marketing SMS and
Newsletters F ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81298 (Unauthenticated Cross Site Scripting (XSS) in LeadConnector <=
4.0.5 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81297 (Subscriber Privilege Escalation in Fluent Forms Pro Add On
Pack <= 6.2 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81296 (Unauthenticated Broken Access Control in Fluent Forms Pro Add
On Pack ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81293 (Unauthenticated SQL Injection in WP Data Access <= 5.5.81
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81291 (Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7
version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81290 (Unauthenticated Cross Site Scripting (XSS) in Email
Subscribers & News ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81287 (Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81280 (Subscriber Sensitive Data Exposure in Print Barcode Labels for
your Wo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81278 (Missing Authorization vulnerability in WPExperts Post SMTP
allows Expl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81267 (A malicious webpage could stall a popup's cross-origin
navigation afte ...)
TODO: check
CVE-2026-79483 (FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable
to a No ...)
@@ -173,7 +173,7 @@ CVE-2026-77950 (Generation of Error Message Containing
Sensitive Information vul
CVE-2026-77856 (Allocation of Resources Without Limits or Throttling
vulnerability in ...)
TODO: check
CVE-2026-77823 (The LearnPress plugin for WordPress is vulnerable to SQL
Injection via ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77353 (Wallos is an open-source, self-hostable personal subscription
tracker. ...)
TODO: check
CVE-2026-77352 (Wallos is an open-source, self-hostable personal subscription
tracker. ...)
@@ -183,19 +183,19 @@ CVE-2026-77351 (Wallos is an open-source, self-hostable
personal subscription tr
CVE-2026-77348 (Wallos is an open-source, self-hostable personal subscription
tracker. ...)
TODO: check
CVE-2026-77189 (The Charitable \u2013 Donation & Fundraising Platform
(Donation Forms, ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-76006 (The Photo Gallery by Ays \u2013 Responsive Image Gallery
plugin for Wo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75980 (The BetterDocs \u2013 AI Documentation, Knowledge Base, Docs,
Wikis, F ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75965 (The User Profile Builder \u2013 Beautiful User Registration
Forms, Use ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75964 (The User Profile Builder \u2013 Beautiful User Registration
Forms, Use ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75921 (The Master Addons for Elementor \u2013 Elementor Addons,
Widgets, Mega ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75865 (The WPLP Cookie Consent \u2013 Cookie Banner & Consent
Management for ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75594 (Kirby is an open-source content management system. Prior to
4.9.5 and ...)
TODO: check
CVE-2026-75592 (Kirby is an open-source content management system. Prior to
4.9.5 and ...)
@@ -235,25 +235,25 @@ CVE-2026-54179 (backpack/crud provides Create, Read,
Update & Delete (CRUD) func
CVE-2026-52730 (Xibo is an open source digital signage platform with a web
content man ...)
TODO: check
CVE-2026-51740 (Incorrect access control in the killProcess function of
TOTOLINK T6 4. ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51739 (Incorrect access control in the CloudSrvVersionCheck function
of TOTOL ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51738 (Incorrect access control in the LoadDefSettings function of
TOTOLINK T ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51737 (Incorrect access control in the clearTracerouteLog function of
TOTOLIN ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51736 (Incorrect access control in the clearSyslog function of
TOTOLINK T6 4. ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51735 (Incorrect access control in the showSyslog function of
TOTOLINK T6 4.1 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51734 (Incorrect access control in the informSlaveUpdate function of
TOTOLINK ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51733 (Incorrect access control in the FirmwareUpgrade function of
TOTOLINK T ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51732 (Incorrect access control in the delWiFiScheduleCfg function of
TOTOLIN ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51731 (Incorrect access control in the delVlanCfg function of
TOTOLINK T6 4.1 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-50199 (Wallos is an open-source, self-hostable personal subscription
tracker. ...)
TODO: check
CVE-2026-50198 (Wallos is an open-source, self-hostable personal subscription
tracker. ...)
@@ -263,39 +263,39 @@ CVE-2026-4560
CVE-2026-48932 (A flaw in Node.js HTTP client can cause a request
desynchronization fo ...)
TODO: check
CVE-2026-38577 (Insecure hardcoded credentials in the Admin account of Tenda
HG21 V4.0 ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-19952 (The Frontend Admin by DynamiApps plugin for WordPress is
vulnerable to ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19948 (The Cozy Blocks \u2013 Page Builder for Gutenberg Editor & FSE
with 70 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19820 (A vulnerability in the Backblaze Client allows a local user to
make th ...)
TODO: check
CVE-2026-19806 (The Support Genix \u2013 Helpdesk, AI Chatbot, Knowledge Base
& Custom ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19796 (The Listdom: AI-powered Business Directory with Classifieds
Ads Listin ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19573 (The Affiliate Super Assistent plugin for WordPress is
vulnerable to St ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19032 (jackson-databind's deserializer for java.nio.file.Path
resolves an att ...)
TODO: check
CVE-2026-18752 (The Persistent Login plugin for WordPress is vulnerable to
generic SQL ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18743 (A flaw was found in popt. This vulnerability allows an
attacker to pro ...)
TODO: check
CVE-2026-18488 (The Blocksy Companion plugin for WordPress is vulnerable to
Stored Cro ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17589 (The Shopping Cart & eCommerce Store plugin for WordPress is
vulnerable ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16787 (The Live Composer \u2013 Free WordPress Website Builder plugin
for Wor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14697 (net_ipv6_send_ns() in subsys/net/ip/ipv6_nbr.c allocates a
transmit ne ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-13732 (A flaw was found in GDB's STABS debug format parser. The
read_member_f ...)
TODO: check
CVE-2026-13203 (The Live Composer \u2013 Free WordPress Website Builder plugin
for Wor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12747 (The Frontend Admin by DynamiApps plugin for WordPress is
vulnerable to ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2025-63607 (TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In
contact_ ...)
TODO: check
CVE-2026-XXXX [GHSA-g89c-p67h-r497: Heap buffer overflow in
`scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl`
items]
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b84eb790f49ec71c36aaf0db0dbd2173a76aba4d
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b84eb790f49ec71c36aaf0db0dbd2173a76aba4d
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits