Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
0d1457d7 by security tracker role at 2026-07-23T19:14:44+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,13 +1,13 @@
CVE-2026-9729 (The Webpushr Push Notifications plugin for WordPress is
vulnerable to ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-9713 (The Lumise Product Designer for WooCommerce plugin for
WordPress is vu ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-9635 (The WP Shortcode by MyThemeShop plugin for WordPress is
vulnerable to ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-8287 (Allocation of resources without limits or throttling
vulnerability in ...)
TODO: check
CVE-2026-6516 (Zohocorp ManageEngine ADAudit Plus versionsbefore 8606 are
affected by ...)
- TODO: check
+ NOT-FOR-US: Zoho
CVE-2026-65920 (Diffusers through 0.39.0, fixed in commit cee298c, contains a
path tra ...)
TODO: check
CVE-2026-65919 (Meshery before 1.0.57 contains an unauthenticated arbitrary
file read ...)
@@ -27,11 +27,11 @@ CVE-2026-65912 (DOMPurify before 3.3.2 contains a URI
validation bypass vulnerab
CVE-2026-65911 (In DOMPurify through 3.3.3, function predicates supplied via
ADD_ATTR ...)
TODO: check
CVE-2026-65908 (In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code
execution ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-65907 (In JetBrains TeamCity before 2026.1.2, 2025.11.6 code
execution in Git ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-65906 (In JetBrains TeamCity before 2026.1.2, 2025.11.6 \u0441ode
execution v ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-65904 (DOMPurify through 3.3.3 fails to sanitize DOM elements passed
via IN_P ...)
TODO: check
CVE-2026-65903 (DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS
function ...)
@@ -53,29 +53,29 @@ CVE-2026-65896 (Grav API Plugin (Composer package
getgrav/grav-plugin-api) befor
CVE-2026-65895 (Grav API Plugin versions before 1.0.10 fail to restrict write
access t ...)
TODO: check
CVE-2026-65763 (Joomla Extension - phoca.cz - Reflected XSS vulnerability in
Phoca Map ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65762 (Joomla Extension - phoca.cz - Reflected XSS vulnerability in
Phoca Gue ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65761 (Joomla Extension - joomshaper.com - Unauthenticated SQL
injection in E ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65760 (Joomla Extension - joomshaper.com - cross-customer order and
personal ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65759 (Joomla Extension - joomshaper.com - unauthenticated
payment/order forg ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65758 (Joomla Extension - tassos.gr - Sensitive data exposure in
Convert Form ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65757 (Joomla Extension - regularlabs.com - Inconsistent CSRF token
checks / ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65756 (Joomla Extension - regularlabs.com - XSS vector in Keyboard
Shortcuts ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65755 (Joomla Extension - regularlabs.com - Date-sensitive
query-cache leakag ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65754 (Joomla Extension - regularlabs.com - Insecure path handling in
ReRepla ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65713 (Joomla Extension - regularlabs.com - Insecure path handling in
Modals ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65712 (Joomla Extension - regularlabs.com - Insecure path handling in
CDN for ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65702 (Vanna through 2.0.2 contains a path traversal vulnerability in
the Fil ...)
TODO: check
CVE-2026-65701 (SoftVC VITS Singing Voice Conversion through commit 730930d
contains a ...)
@@ -109,187 +109,187 @@ CVE-2026-65606 (SiYuan before v3.7.2 contains a
cross-site scripting vulnerabili
CVE-2026-65605 (SiYuan before v3.7.2 contains a stored cross-site scripting
vulnerabil ...)
TODO: check
CVE-2026-65550 (Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65540 (Unauthenticated Cross Site Request Forgery (CSRF) in Popup for
CF7 wit ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65539 (Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy
HTML Sitema ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65538 (Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65537 (Subscriber Broken Access Control in Cyr to Lat reloaded \u2013
transli ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65536 (Unauthenticated Cross Site Request Forgery (CSRF) in
\u0627\u0641\u063 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65535 (Contributor Sensitive Data Exposure in TinyMCE Templates <=
4.8.1 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65534 (Author Cross Site Scripting (XSS) in Custom links in Elementor
Image C ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65533 (Contributor Cross Site Scripting (XSS) in Smart SEO Tool <=
4.1.2 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65532 (Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2
version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65531 (Unauthenticated Broken Access Control in Qubely <= 1.8.14
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65530 (Subscriber Broken Access Control in TemplateSpare <= 4.2.2
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65529 (Unauthenticated Broken Access Control in Graphina <= 3.1.12
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65528 (Contributor Cross Site Scripting (XSS) in BSK PDF Manager <=
3.8 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65527 (Contributor Cross Site Scripting (XSS) in LIQUID SPEECH
BALLOON <= 1.2 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65526 (Contributor SQL Injection in Visualizer <= 4.0.6 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65525 (Unauthenticated Broken Access Control in Civi Framework <=
2.2.0 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65524 (Contributor Broken Access Control in Avada Custom Branding <=
1.2 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65522 (Contributor Cross Site Scripting (XSS) in Manual -
Documentation, Know ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65521 (Unauthenticated Sensitive Data Exposure in WP Social Ninja <=
4.3.0 ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65519 (Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29
version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65518 (Contributor Cross Site Scripting (XSS) in Accept Donations
with PayPal ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65516 (Unauthenticated Server Side Request Forgery (SSRF) in PeproDev
Ultimat ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65514 (Contributor Cross Site Scripting (XSS) in Appointment Hour
Booking <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65512 (Unauthenticated Cross Site Request Forgery (CSRF) in WP
Activity Log < ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65511 (Unauthenticated Cross Site Scripting (XSS) in Manual -
Documentation, ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65510 (Unauthenticated Cross Site Scripting (XSS) in PeproDev
Ultimate Invoic ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65506 (Unauthenticated Broken Access Control in MP3 Audio Player for
Music, R ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65505 (Unauthenticated Sensitive Data Exposure in Ultimate Store Kit
Elemento ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65503 (Contributor Cross Site Scripting (XSS) in Ultimate Store Kit
Elementor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65501 (Unauthenticated Insecure Direct Object References (IDOR) in
Shiptastic ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65500 (Unauthenticated Broken Access Control in Manual -
Documentation, Knowl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65499 (Unauthenticated Broken Access Control in PeproDev Ultimate
Invoice <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65498 (Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0
versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65497 (Administrator PHP Object Injection in Complianz <= 7.5.0
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65496 (Author Server Side Request Forgery (SSRF) in Complianz <=
7.5.0 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65495 (Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65494 (Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65493 (Subscriber PHP Object Injection in Dokan Pro <= 5.0.2
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65492 (Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <=
5.0.0 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65491 (Subscriber Broken Access Control in Query Wrangler <= 1.5.57
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65490 (Unauthenticated Sensitive Data Exposure in Create by Mediavine
<= 2.5. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65489 (Unauthenticated Broken Access Control in LA-Studio Element Kit
for Ele ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65488 (Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio
Element ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65487 (Unauthenticated Broken Access Control in Photography <= 7.7.6
versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65486 (Unauthenticated Broken Access Control in Event post <= 6.0.1
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65485 (Unauthenticated Broken Access Control in Content Control <=
2.6.5 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65484 (Contributor Broken Access Control in Style Kits <= 2.6.5
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65483 (Author Cross Site Scripting (XSS) in HashThemes Demo Importer
<= 1.4.2 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65482 (Contributor Cross Site Scripting (XSS) in LA-Studio Element
Kit for El ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65481 (Contributor Local File Inclusion in Vino <= 1.9 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65480 (Contributor Cross Site Scripting (XSS) in TheGem <= 5.11.1
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65479 (Subscriber Broken Access Control in Reviewer <= 3.14.2
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65478 (Subscriber Broken Access Control in ListingPro <= 2.9.10
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65477 (Contributor Local File Inclusion in Tonda Core <= 2.1.2
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65476 (Unauthenticated Broken Access Control in Civi <= 2.2.4
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65475 (Improper Neutralization of Input During Web Page Generation
('Cross-si ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65474 (Unauthenticated Sensitive Data Exposure in Ninja Tables <=
5.2.10 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65473 (Contributor Cross Site Scripting (XSS) in
Virtue/Ascend/Pinnacle Toolk ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65472 (Unauthenticated Broken Access Control in Kit (formerly
ConvertKit) <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65471 (Unauthenticated Cross Site Request Forgery (CSRF) in Avada
Core <= 5.1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65470 (Contributor Cross Site Scripting (XSS) in Fluent Support <=
2.3.0 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65469 (Unauthenticated Broken Access Control in AWP Classifieds <=
4.4.7 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65468 (Unauthenticated Broken Access Control in JetBooking <= 4.1.2
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65467 (Contributor Server Side Request Forgery (SSRF) in JetEngine <=
3.8.11 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65466 (Custom role Server Side Request Forgery (SSRF) in JetBooking
<= 4.1.2 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65465 (Contributor Cross Site Scripting (XSS) in JetElements For
Elementor <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65464 (Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <=
4.16.3 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65463 (Subscriber Insecure Direct Object References (IDOR) in
Masteriyo - LMS ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65462 (Administrator SQL Injection in Uncanny Automator <= 7.3.2
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65461 (Administrator Arbitrary File Upload in Really Simple CSV
Importer <= 1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65460 (Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal
Gateway ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65458 (Contributor Sensitive Data Exposure in Polylang <= 3.8.5
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65457 (Subscriber Broken Access Control in \u042eKassa
\u0434\u043b\u044f Woo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65456 (Contributor Insecure Direct Object References (IDOR) in
Product Slider ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65455 (Administrator Arbitrary File Upload in MapSVG <= 8.14.0
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65454 (Contributor SQL Injection in Quiz And Survey Master <= 11.2.0
versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65453 (Unauthenticated Broken Access Control in Ebook Store <= 6.19
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65452 (Unauthenticated Broken Access Control in Ebook Store <= 6.19
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65451 (Contributor SQL Injection in MapSVG <= 8.14.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65450 (Contributor SQL Injection in MapSVG <= 8.14.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65449 (Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65431 (Joomla Extension - regularlabs.com - Zipslip in GeoIP
extension - Geo ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65430 (Joomla Extension - regularlabs.com - MaxMind Credential
leakage in Geo ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65010 (Datasets through 5.00, fixed in commit ad2d853, contains a
symlink-fol ...)
TODO: check
CVE-2026-64876 (Joomla Extension - regularlabs.com - Inconsistent CSRF token
checks / ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-64875 (Joomla Extension - regularlabs.com - IP spoofing vulnerability
in GeoI ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-64874 (Joomla Extension - regularlabs.com - CDN Credential leakage
Cache Clea ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-64873 (Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro
extensi ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-64872 (Joomla Extension - regularlabs.com - Path traversal in Cache
Cleaner P ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-64871 (Joomla Extension - regularlabs.com - Inconsistent CSRF token
checks / ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-64815 (In JetBrains IntelliJ IDEA before 2026.2 arbitrary code
injection was ...)
TODO: check
CVE-2026-64814 (In JetBrains IntelliJ IDEA before 2026.2 unauthorized file
access was ...)
@@ -303,141 +303,141 @@ CVE-2026-64811 (In JetBrains IntelliJ IDEA before
2026.2 arbitrary code executio
CVE-2026-64810 (In JetBrains IntelliJ IDEA before 2026.2 hTML injection was
possible i ...)
TODO: check
CVE-2026-64809 (In JetBrains PhpStorm before 2026.2 arbitrary code execution
was possi ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-64808 (In JetBrains PhpStorm before 2026.2 arbitrary code execution
was possi ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-64807 (In JetBrains WebStorm before 2026.2 arbitrary code execution
was possi ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-64806 (In JetBrains WebStorm before 2026.2 arbitrary code execution
was possi ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-64805 (In JetBrains WebStorm before 2026.2 arbitrary code execution
was possi ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-64804 (In JetBrains WebStorm before 2026.2 arbitrary code execution
was possi ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-64803 (In JetBrains GoLand before 2026.2 arbitrary code execution was
possibl ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-64802 (In JetBrains GoLand before 2026.2 arbitrary code execution was
possibl ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-64800 (In JetBrains GoLand before 2026.2 sensitive configuration
values writt ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-64799 (Joomla Extension - regularlabs.com - SSRF via remote image
downloads i ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-64611 (A flaw was found in libcupsfilters. The
cfIEEE1284NormalizeMakeModel() ...)
TODO: check
CVE-2026-63765 (Chatwoot before 4.16.0 contains an authentication bypass
vulnerability ...)
TODO: check
CVE-2026-61981 (Unauthenticated Cross Site Request Forgery (CSRF) in Simple
Link Direc ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61973 (Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61972 (Unauthenticated Broken Access Control in ShopLentor Pro <=
2.8.5 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61954 (Unauthenticated Broken Access Control in PayU India <= 3.8.9
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61951 (Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61950 (Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61949 (Unauthenticated SQL Injection in Bookly <= 27.7 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61948 (Unauthenticated SQL Injection in WPDM \u2013 Premium Packages
<= 6.2.0 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61947 (Unauthenticated Cross Site Scripting (XSS) in Form Vibes
\u2013 Databa ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61946 (Unauthenticated Insecure Direct Object References (IDOR) in
Easy Appoi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61945 (Exposure of Sensitive System Information to an Unauthorized
Control Sp ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61944 (Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61943 (Unauthenticated Broken Access Control in WPDM \u2013 Premium
Packages ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59678 (An Incorrect Authorization vulnerability in Linux-Gaming
PortProtonQt ...)
TODO: check
CVE-2026-59677 (A Missing Authorization vulnerability in selinux
policycoreutils seuns ...)
TODO: check
CVE-2026-59555 (Unauthenticated Arbitrary File Deletion in Participants
Database <= 2. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59554 (Unauthenticated Broken Authentication in Ziina <= 1.2.21
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59547 (Unauthenticated Broken Access Control in Payment Gateway for
PayPal on ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59545 (Unauthenticated Broken Authentication in miniOrange Discord
Integratio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59544 (Unauthenticated PHP Object Injection in Thrive Quiz Builder <=
10.9.3. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59543 (Subscriber Remote Code Execution (RCE) in Advanced Views <=
3.8.11 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59542 (Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59541 (Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59540 (Unauthenticated Privilege Escalation in SMS Alert Order
Notifications ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59526 (Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59525 (Unauthenticated SQL Injection in Participants Database <=
2.7.8.3 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59524 (Unauthenticated Broken Authentication in Easy Digital
Downloads <= 3.6 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59522 (Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59517 (Unauthenticated Cross Site Scripting (XSS) in Easy Form
Builder <= 4.0 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59514 (Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59513 (Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <=
2.3.0 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59512 (Unauthenticated Cross Site Scripting (XSS) in Product Enquiry
for WooC ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57809 (Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <=
2.34.0 ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57808 (Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57785 (Unauthenticated Cross Site Request Forgery (CSRF) in
ApusListing <= 1. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57784 (Unauthenticated Cross Site Request Forgery (CSRF) in Ninja
Forms File ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57769 (Unauthenticated Cross Site Scripting (XSS) in Grand
Photography <= 5.7 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57767 (Unauthenticated Cross Site Scripting (XSS) in WP Google Maps
Pro <= 10 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57735 (Unauthenticated Cross Site Scripting (XSS) in Breakdance <=
2.7.1 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57717 (Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57716 (Unauthenticated Arbitrary File Deletion in Broadcast Live
Video <= 7.2 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57704 (Unauthenticated Cross Site Scripting (XSS) in Smart Manager <=
8.90.0 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57703 (Subscriber Broken Access Control in Sunshine Photo Cart <=
3.6.10.1 ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57701 (Unauthenticated Cross Site Scripting (XSS) in Real Estate
Manager Pro ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57699 (Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13
versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57696 (Contributor Arbitrary File Deletion in Picture Gallery <=
1.6.5 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57626 (Cross-Site Request Forgery (CSRF) vulnerability in MailPoet
allows Cro ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57428 (Unauthenticated Cross Site Scripting (XSS) in Sprout Clients
<= 3.2.3 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57427 (Unauthenticated Cross Site Scripting (XSS) in Download Monitor
- WPFor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57425 (Unauthenticated Broken Access Control in Autopay dla
WooCommerce <= 2. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57397 (Unauthenticated Cross Site Scripting (XSS) in Coaching <=
3.9.2 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57384 (Subscriber Cross Site Scripting (XSS) in WishList Member X <=
3.32.0 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57374 (Unauthenticated Cross Site Scripting (XSS) in Funnel Kit
Funnel Builde ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57373 (Customer Cross Site Scripting (XSS) in Funnel Kit Funnel
Builder PRO < ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57370 (Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic
Real Tim ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57367 (Subscriber Broken Access Control in WP Booking System <
5.12.8.1 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-52684 (If the auth responds very slowly and the records expire in
between, th ...)
TODO: check
CVE-2026-48539 (GFI Archiver before 15.13 contains a stored cross-site
scripting vulne ...)
@@ -471,55 +471,55 @@ CVE-2026-47743 (Shopper is a Headless e-commerce Admin
Panel. Prior to 2.8.0, th
CVE-2026-47668 (DbGate is cross-platform database manager. In versions 7.1.8
and prior ...)
TODO: check
CVE-2026-44909 (Proxygen lacked a generalized slow-consumer detection
mechanism in its ...)
- TODO: check
+ NOT-FOR-US: Meta software not packaged in Debian
CVE-2026-44210 (Kata Containers is an open source project focusing on a
standard imple ...)
TODO: check
CVE-2026-43823 (When initializing an RSA public key from DER or PEM bytes
throws an er ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-43820 (NIOSSLCertificate._subjectAlternativeNames provides access to
the raw ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-27423 (Subscriber Broken Access Control in Participants Database <=
2.7.8.4 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27422 (Unauthenticated Broken Access Control in YT Player <= 2.0.9
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27418 (Unauthenticated Broken Access Control in WP Fast Total Search
<= 1.81. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27403 (Contributor Cross Site Scripting (XSS) in Hubbub Lite <=
1.36.3 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27399 (Unauthenticated Broken Access Control in MarketKing <= 2.1.40
versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27392 (Contributor Broken Access Control in uListing <= 2.2.0
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27391 (Subscriber Broken Access Control in uListing <= 2.2.0
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27377 (Booking Agent Broken Access Control in QuickCal - Appointment
Booking ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27372 (Unauthenticated Sensitive Data Exposure in PeproDev Ultimate
Invoice < ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27355 (Unauthenticated Broken Access Control in Ditty <= 3.1.66
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27064 (Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-25466 (Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04
version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-25427 (Subscriber Broken Access Control in eRoom <= 1.7.1 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-25424 (Contributor Broken Access Control in Mediavine Control Panel
<= 2.10.1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-25405 (Contributor SQL Injection in eRoom <= 1.7.1 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-24639 (Author Server Side Request Forgery (SSRF) in Photo Block <=
1.7.1 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-24628 (Administrator Cross Site Scripting (XSS) in Photo Gallery by
Supsystic ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-24552 (Contributor SQL Injection in Create by Mediavine <= 2.5.3
versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-24537 (Unauthenticated Cross Site Request Forgery (CSRF) in WP
Accessibility ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-16768 (A flaw was found in gdk-pixbuf. When parsing a specially
crafted ICO f ...)
TODO: check
CVE-2026-16756 (Missing connection and header-read timeouts and the absence of
a concu ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-16745 (A flaw was found in odh-dashboard, the web console component
of Red Ha ...)
TODO: check
CVE-2026-16735 (A security vulnerability has been detected in release-it
conventional- ...)
@@ -529,27 +529,27 @@ CVE-2026-16733 (A weakness has been identified in
bahmutov find-cypress-specs up
CVE-2026-16723 (A remote code execution (RCE) vulnerability exists in fastjson
1.2.68 ...)
TODO: check
CVE-2026-16584 (Improper handling of an initialization failure in AWS API MCP
Server f ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-16287 (Improper neutralization of special elements used in an OS
command ('OS ...)
TODO: check
CVE-2026-16078 (The WCPOS \u2013 Point of Sale (POS) plugin for WooCommerce
plugin for ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15906 (The Premium Packages \u2013 Sell Digital Products Securely
plugin for ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15827 (The GutenKit Blocks plugin for WordPress is vulnerable to
unauthorized ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15794 (The Grid/List View for WooCommerce plugin for WordPress is
vulnerable ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15786 (The WP Encryption \u2013 One Click Free SSL Certificate & SSL
/ HTTPS ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15761 (The Tickera \u2013 Sell Tickets & Manage Events plugin for
WordPress i ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15687 (A security issue was discovered in the Kubernetes Java client
library ...)
TODO: check
CVE-2026-15647 (The Brands for WooCommerce plugin for WordPress is vulnerable
to Store ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15646 (The Brands for WooCommerce plugin for WordPress is vulnerable
to Store ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15617 (Logto performs principal lookup without normalizing email and
identifi ...)
TODO: check
CVE-2026-15616 (Logto does not enforce locally configured MFA during SSO
authenticatio ...)
@@ -563,41 +563,41 @@ CVE-2026-15612 (Logto bypasses OIDC nonce validation when
the nonce claim is abs
CVE-2026-15611 (Logto allows unverified email-based SSO account linking,
enabling an a ...)
TODO: check
CVE-2026-15448 (The Tickera \u2013 Sell Tickets & Manage Events plugin for
WordPress i ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15404 (The Lpagery plugin for WordPress is vulnerable to Stored
Cross-Site Sc ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15394 (The Header Footer Script Adder \u2013 Insert Code in Header,
Body & Fo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15348 (The Premium Packages \u2013 Sell Digital Products Securely
plugin for ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15037 (Improper output neutralization (XML injection) in QDom
comment, CDATA, ...)
TODO: check
CVE-2026-15017 (The MDJM Event Management plugin for WordPress is vulnerable
to Privil ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15015 (The MountDev AI MCP Connector for WordPress plugin for
WordPress is vu ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15011 (The Customer Support Ticket System & Helpdesk plugin for
WordPress is ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14481 (The Equalize Digital Accessibility Checker \u2013 WCAG, ADA,
EAA and S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14282 (The GoDAM \u2013 Organize WordPress Media Library & File
Manager with ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14257 (brace-expansion through 5.0.7 is vulnerable to denial of
service via m ...)
TODO: check
CVE-2026-13119 (The Registrations For The Events Calendar plugin for WordPress
is vuln ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13009 (The AI Copilot \u2013 Content Generator plugin for WordPress
is vulner ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12421 (The ARforms plugin for WordPress is vulnerable to Stored
Cross-Site Sc ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-11804 (Improper handling of insufficient permissions or privileges
vulnerabil ...)
- TODO: check
+ NOT-FOR-US: Honeywell
CVE-2025-68081 (Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3
version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2024-58330 (A missing authentication check in Bosch IP cameras of families
CPP13 a ...)
- TODO: check
+ NOT-FOR-US: Bosch
CVE-2024-58023 (Information disclosure in Bosch Configuration Manager in
Version 7.72. ...)
- TODO: check
+ NOT-FOR-US: Bosch
CVE-2026-9737 (During query planning when reading the sort pattern in raw
BSONObj for ...)
- mongodb <removed>
NOTE: https://jira.mongodb.org/browse/SERVER-128341
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0d1457d7507ab6178925f6bffff96f9f491433c6
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0d1457d7507ab6178925f6bffff96f9f491433c6
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits