Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
f9ad5eb5 by security tracker role at 2026-09-11T19:13:55+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -89,19 +89,19 @@ CVE-2026-89146 (libp2p-rendezvous through 0.17.1 fails to 
validate registration
 CVE-2026-89099 (A race condition in the document value layer of MongoDB Server 
can all ...)
        TODO: check
 CVE-2026-89090 (An unrecovered panic in the event stream header decoder in 
Amazon AWS  ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-89066 (Improper neutralization of special elements used in an OS 
command in t ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-89065 (Relative path traversal in the generated file manifest cleanup 
compone ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-89013 (Dolibarr 23.0.4 before 24.0.1 ontains an authorization bypass 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: Dolibarr
 CVE-2026-89012 (Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive 
denylist bypas ...)
-       TODO: check
+       NOT-FOR-US: Dolibarr
 CVE-2026-89010 (WAVLINK WN535M1 and WN535M3 routers running firmware prior to 
M35M1_V2 ...)
-       TODO: check
+       NOT-FOR-US: Wavlink
 CVE-2026-89009 (WAVLINK WN535M1 and WN535M3 routers running firmware prior to 
M35M1_V2 ...)
-       TODO: check
+       NOT-FOR-US: Wavlink
 CVE-2026-87988 (An arbitrary file access vulnerability in Mistral Vibe allows 
an attac ...)
        TODO: check
 CVE-2026-87987 (An arbitrary code execution vulnerability in Mistral Vibe 
allows an at ...)
@@ -129,19 +129,19 @@ CVE-2026-87122
 CVE-2026-87020 (An integer overflow in a specified pitch and buffer-size 
computation l ...)
        TODO: check
 CVE-2026-86813 (The MetForm WordPress plugin before 4.1.9 does not properly 
neutralize ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86809 (The Persian Elementor WordPress plugin from 2.7.10 before 
2.8.2 does n ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86793 (SGLang allows unauthenticated pickle deserialization through 
/update_w ...)
        TODO: check
 CVE-2026-85979 (Affected versions of Puppet Enterprise contain a command 
injection vul ...)
        TODO: check
 CVE-2026-85116 (The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin 
from 1.2 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-85083 (The ANJIA AJL33PC0801 IP camera uses a hard-coded credential 
for bootl ...)
        TODO: check
 CVE-2026-84390 (A inclusion of sensitive information in source code 
vulnerability in F ...)
-       TODO: check
+       NOT-FOR-US: Fortinet
 CVE-2026-82617 (The two built-in name-finder patterns exposed by 
opennlp.tools.namefin ...)
        TODO: check
 CVE-2026-82583 (NextGen Connect (Mirth Connect) versions 4.7.1 and earlier 
allow an au ...)
@@ -149,23 +149,23 @@ CVE-2026-82583 (NextGen Connect (Mirth Connect) versions 
4.7.1 and earlier allow
 CVE-2026-82578 (When XML batch processing is turned on and the XPath option is 
selecte ...)
        TODO: check
 CVE-2026-82535 (Chamilo LMS before 1.11.42 and 3.0.0 contains a stored 
cross-site scri ...)
-       TODO: check
+       NOT-FOR-US: Chamilo LMS
 CVE-2026-82215 (The Payment Gateway PayPay for WooCommerce WordPress plugin 
from 0.5 t ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-82213 (The Nexi XPay Build WordPress plugin from 7.6.1 to 7.6.2 does 
not veri ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-81910 (Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side 
Template Inj ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-81909 (Concrete CMS 9 through 9.5.2 is vulnerable to Missing 
Authorization in ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-81908 (Concrete CMS 9.2.0 to 9.5.2 contain a missing authorization 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-81861 (CWE-522: Insufficiently Protected Credentials vulnerability 
that could ...)
-       TODO: check
+       NOT-FOR-US: Schneider Electric
 CVE-2026-80469 (An attacker may achieve arbitrary code execution on a target 
system by ...)
-       TODO: check
+       NOT-FOR-US: SICK AG
 CVE-2026-80462 (A vulnerability in the Chef Automate API gateway and identity 
validati ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-7863 (Improper neutralization of special elements used in an OS 
command ('OS ...)
        TODO: check
 CVE-2026-7298 (Improper neutralization of input during web page generation 
('cross-si ...)
@@ -201,63 +201,63 @@ CVE-2026-71641 (An issue in ZJU-FAST-Lab EGO-Planner-v2 
All versions up to commi
 CVE-2026-71416 (Headroom compresses data before the data reaches a large 
language mode ...)
        TODO: check
 CVE-2026-70341 (Use after free in Microsoft Edge (Chromium-based) allows an 
authorized ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-6642 (The Media Library Assistant plugin for WordPress is vulnerable 
to Stor ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-6641 (The Media Library Assistant plugin for WordPress is vulnerable 
to Stor ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-6640 (The Media Library Assistant plugin for WordPress is vulnerable 
to Stor ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-68528 (Concrete CMS RSS Displayer block below version 9.5.3  rendered 
remote  ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-68497 (jackson-databind binds a JSON string to a 
javax.xml.datatype.Duration  ...)
        TODO: check
 CVE-2026-67211 (OOM Denial of Service via Unbounded Map Pre-Sizing in Apache 
OpenNLP S ...)
        TODO: check
 CVE-2026-62140 (Unauthenticated Insecure Direct Object References (IDOR) in 
Quiz And S ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62139 (Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit 
by Googl ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62138 (Contributor Cross Site Scripting (XSS) in Visual Composer 
Website Buil ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62137 (Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62136 (Unauthenticated Broken Access Control in Flexible Quantity 
\u2013 Meas ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62135 (Unauthenticated Broken Access Control in Booktics <= 1.0.24 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62134 (Contributor Insecure Direct Object References (IDOR) in 
Starter Templa ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62133 (Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 
2.1.5 versio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62132 (Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62114 (Unauthenticated Broken Access Control in Passster <= 4.3.13 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62113 (Contributor Insecure Direct Object References (IDOR) in Slim 
SEO <= 4. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62112 (Editor SQL Injection in Amelia <= 2.4.9 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62111 (Contributor Cross Site Scripting (XSS) in Simple Payment <= 
2.5.4 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62110 (Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 
5.9.9 v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62109 (Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62107 (Unauthenticated PHP Object Injection in Masteriyo - LMS <= 
3.4.0 versi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62106 (Subscriber Privilege Escalation in SMS Alert Order 
Notifications <= 3. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62105 (Unauthenticated PHP Object Injection in ThemeREX Addons < 
2.45.0 versi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62103 (Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62102 (Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62089 (Missing Authorization vulnerability in Pixar Labs Master 
Addons for El ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62088 (Insertion of Sensitive Information Into Sent Data 
vulnerability in 10u ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57843 (NetBSD contains an information disclosure vulnerability in 
mm_open() w ...)
        TODO: check
 CVE-2026-57842 (NetBSD contains a use-after-free and double-free vulnerability 
in msg_ ...)
@@ -269,27 +269,27 @@ CVE-2026-54047 (Laci Synchroni is a decentralized mod and 
appearance sync server
 CVE-2026-47839 (A vulnerability allows users authenticating through a 
federated OIDC p ...)
        TODO: check
 CVE-2026-3869 (CWE-303 : Incorrect Implementation of Authentication Algorithm 
vulnera ...)
-       TODO: check
+       NOT-FOR-US: Schneider Electric
 CVE-2026-38058 (The endpoint on the iDirect iQ200 VSAT terminal returns the 
complete d ...)
        TODO: check
 CVE-2026-38056 (A local privilege escalation vulnerability exists in the 
iDirect iQ200 ...)
        TODO: check
 CVE-2026-27378 (Unauthenticated Broken Access Control in Deposits and Partial 
Payments ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-19486 (A Server-Side Request Forgery (SSRF) vulnerability in Google 
Cloud Gem ...)
        TODO: check
 CVE-2026-18495 (A flaw was found in libtiff. A heap-buffer overflow 
vulnerability exis ...)
        TODO: check
 CVE-2026-18122 (Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint 
exposes res ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-18061 (Improper restriction of XML external entity references in the 
RemoteQu ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-17037 (The Kirki \u2013 Freeform Page Builder, Website Builder & 
Customizer p ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15710 (An information leakage vulnerability exists in the Endpoint 
DLP compon ...)
-       TODO: check
+       NOT-FOR-US: Netskope
 CVE-2026-15439 (The GamiPress plugin for WordPress is vulnerable to 
authenticated (Sub ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-11765 (Improper neutralization of argument delimiters in a command 
('argument ...)
        TODO: check
 CVE-2025-69904 (Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, 
which al ...)
@@ -297,7 +297,7 @@ CVE-2025-69904 (Linkstack v4.8.4 and earlier is vulnerable 
to Path Traversal, wh
 CVE-2025-15679 (Under certain circumstances such as reset to factory default 
operation ...)
        TODO: check
 CVE-2024-12145 (The BuddyPress plugin for WordPress is vulnerable to Insecure 
Direct O ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-9768
        REJECTED
 CVE-2026-9667 (IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to 
server- ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f9ad5eb523caf4d10da88c0d43dc8d7f75f5200b

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f9ad5eb523caf4d10da88c0d43dc8d7f75f5200b
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to