Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
efd784d9 by security tracker role at 2026-08-28T19:14:53+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2026-9548 (An improper neutralization of input during web page generation 
('Cross ...)
-       TODO: check
+       NOT-FOR-US: Synology
 CVE-2026-9491 (A server-ide request forgery (SSRF) vulnerability in webhook in 
Synolo ...)
-       TODO: check
+       NOT-FOR-US: Synology
 CVE-2026-82330 (A flaw was found in the file-pvr plugin in GIMP. When 
processing a spe ...)
        TODO: check
 CVE-2026-82328 (A flaw was found in the file-ico plugin in GIMP. When 
processing a spe ...)
@@ -65,15 +65,15 @@ CVE-2026-82236 (File Browser versions from 2.63.6 through 
2.63.23 fail to clean
 CVE-2026-82235 (filebrowser through 2.63.23 fails to validate named pipes in 
directory ...)
        TODO: check
 CVE-2026-82234 (SiYuan versions before v3.8.1 contain a server-side request 
forgery vu ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-82233 (SiYuan before v3.8.1 contains a path traversal vulnerability 
in the as ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-82227 (Contributor SQL Injection in WPBulky <= 1.2.2 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-82222 (Deserialization of Untrusted Data vulnerability in Liquid Web 
/ Stella ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-82220 (Unauthenticated Other Vulnerability Type in Forminator <= 
1.57.1 versi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-82181 (Medical Practice Management System developed by Le-yan has a 
Sensitive ...)
        TODO: check
 CVE-2026-82123 (Improper neutralization of input during web page generation 
('cross-si ...)
@@ -85,17 +85,17 @@ CVE-2026-82111 (A vulnerability was detected in iswalle 
getnote-mcp up to 1.5.0.
 CVE-2026-82078 (An unsafe dynamic class loading vulnerability exists in the 
database c ...)
        TODO: check
 CVE-2026-81777 (Authentication Bypass by Spoofing vulnerability in WPDeveloper 
Essenti ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81767 (Unauthenticated Broken Access Control in Simple Payment <= 
2.5.2 versi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81761 (Subscriber Broken Access Control in WpEvently <= 5.5.0 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81760 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81759 (Contributor Broken Access Control in WpEvently <= 5.5.0 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81757 (Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81733 (WWBN AVideo through 30.0 (and master up to commit 4cb576e) 
contains a  ...)
        TODO: check
 CVE-2026-81732 (WWBN AVideo through version 30.0 fails to enforce 
authentication on th ...)
@@ -105,41 +105,41 @@ CVE-2026-81578 (An improper access control vulnerability 
exists in the web manag
 CVE-2026-81341 (wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for 
TLS 1.2 ...)
        TODO: check
 CVE-2026-81299 (Subscriber Insecure Direct Object References (IDOR) in WP Job 
Portal < ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81285 (Unauthenticated Denial of Service Attack in Smush Image 
Compression an ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81284 (Contributor Broken Access Control in ACF Extended <= 0.9.2.6 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81020 (wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM 
nonce on ...)
        TODO: check
 CVE-2026-81019 (wolfProvider before 1.2.2 generates the 8-byte explicit 
AES-GCM nonce  ...)
        TODO: check
 CVE-2026-79996 (The User Registration & Membership  WordPress plugin before 
5.2.6 does ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-79995 (The User Registration & Membership  WordPress plugin before 
5.2.5 does ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-79706 (The Breeze Cache WordPress plugin before 2.5.13 does not 
sanitise a va ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-79615 (The Quiz and Survey Master (QSM)  WordPress plugin before 
11.2.4 does  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-78238 (SOY Gallery  contains a cross-site scripting vulnerability. An 
arbitra ...)
        TODO: check
 CVE-2026-78073 (Joomla Extension - mrvinoth.com - Reflected XSS in All Video 
Share 1.0 ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-78072 (Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in 
Sexy Po ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-78071 (Joomla Extension - digital-peak.com - Authenticated, 
privileged stored ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-78070 (Joomla Extension - digital-peak.com - Authenticated, 
privileged blind  ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-78032 (SOY CMS  contains an issue with deserialization of untrusted 
data. An  ...)
        TODO: check
 CVE-2026-77838 (SOY Calendar contains a cross-site scripting vulnerability. An 
arbitra ...)
        TODO: check
 CVE-2026-77701 (The WCFM Marketplace  WordPress plugin before 3.8.2 does not 
correctly ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-76581 (The WPMU DEV Dashboard plugin for WordPress is vulnerable to 
Authentic ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-75758 (Uncontrolled Recursion vulnerability in the Elixir standard 
library al ...)
        TODO: check
 CVE-2026-73827 (SOY Calendar contains a cross-site scripting vulnerability. An 
arbitra ...)
@@ -149,27 +149,27 @@ CVE-2026-73209 (An attacker that has valid credentials 
can send crafted compress
 CVE-2026-73208 (An attacker that holds a token intended for a different 
purpose can au ...)
        TODO: check
 CVE-2026-6286 (The Booking for Appointments and Events Calendar \u2013 Amelia 
plugin  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-6176 (The Customer Reviews for WooCommerce plugin for WordPress is 
vulnerabl ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-6128 (The All-in-One WP Migration Unlimited Extension plugin for 
WordPress i ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-5953 (Improper neutralization of input during web page generation 
('cross-si ...)
        TODO: check
 CVE-2026-5934 (The WP Rocket plugin for WordPress is vulnerable to Stored 
Cross-Site  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-5800 (Improper neutralization of input during web page generation 
('cross-si ...)
        TODO: check
 CVE-2026-5510 (The GiveWP \u2013 Donation Plugin and Fundraising Platform 
plugin for  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-5097 (The wpForo Forum plugin for WordPress is vulnerable to SQL 
Injection v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-5096 (The Everest Forms plugin for WordPress is vulnerable to 
Server-Side Re ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-58107 (CodeChecker'smassStoreRunprocessing path performs one-shot 
decompressi ...)
-       TODO: check
+       NOT-FOR-US: Ericsson
 CVE-2026-58106 (CVE-2025-40843 
https://github.com/advisories/GHSA-5xf2-f6ch-6p8r was f ...)
-       TODO: check
+       NOT-FOR-US: Ericsson
 CVE-2026-56854 (The source-address critical option in the Permissions returned 
by an a ...)
        TODO: check
 CVE-2026-52687 (An attacker that has valid credentials can select a 
compression algori ...)
@@ -181,7 +181,7 @@ CVE-2026-50979 (A command injection vulnerability in the 
'advanced/curl' compone
 CVE-2026-4378 (Improper neutralization of input during web page generation 
('cross-si ...)
        TODO: check
 CVE-2026-4246 (The ElementsKit Pro plugin for WordPress is vulnerable to 
Stored Cross ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-42395 (A host listed as a trusted proxy can send forwarding 
information conta ...)
        TODO: check
 CVE-2026-42393 (The comparison used for the doveadm password and API key is 
not fully  ...)
@@ -195,7 +195,7 @@ CVE-2026-42008 (Forwarding information received from a host 
listed as a trusted
 CVE-2026-42007 (An attacker that has valid credentials can use a Sieve script 
with the ...)
        TODO: check
 CVE-2026-40541 (An improper neutralization of input during web page generation 
('Cross ...)
-       TODO: check
+       NOT-FOR-US: Synology
 CVE-2026-40205 (An attacker that holds an OAuth2 token granting only part of 
the requi ...)
        TODO: check
 CVE-2026-40204 (None None None No publicly available exploits are known.)
@@ -215,7 +215,7 @@ CVE-2026-40014 (An attacker that can send mail to a user 
can craft a message hea
 CVE-2026-40013 (An attacker that has valid credentials can submit a Sieve 
script conta ...)
        TODO: check
 CVE-2026-3423 (The Envira Gallery plugin for WordPress is vulnerable to Stored 
Cross- ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-38725 (xipblog module v2.0.1 and before for PrestaShop allows 
unauthenticated ...)
        TODO: check
 CVE-2026-38638 (An issue in the with_argv function (/unistd/mod.rs) of relibc 
commit 6 ...)
@@ -247,11 +247,11 @@ CVE-2026-33263 (When mail_max_userip_connections is set 
(default 10) and reached
 CVE-2026-27852 (An attacker that can send mail to a user can craft a message 
whose hea ...)
        TODO: check
 CVE-2026-19423 (The Ultimate Member  WordPress plugin before 2.13.0 does not 
validate  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19412 (This vulnerability exists in the CP Plus CP-XR-DE21-S Router 
due to th ...)
        TODO: check
 CVE-2026-19084 (The shared-files-pro WordPress plugin before 1.7.70 does not 
validate  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18918 (In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server 
authorization che ...)
        TODO: check
 CVE-2026-18393 (A flaw was found in FFmpeg. The tdsc_load_cursor() function 
writes bey ...)
@@ -261,15 +261,15 @@ CVE-2026-15603 (morgan is an HTTP request logger 
middleware for Node.js. In vers
 CVE-2026-14942
        REJECTED
 CVE-2026-14567 (The User Frontend  WordPress plugin before 4.3.10 does not 
restrict ac ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14558 (The User Frontend  WordPress plugin before 4.3.10 does not 
properly va ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13761 (Pega Platform versions 7.1.0 through 25.1.2 are affected by an 
imprope ...)
        TODO: check
 CVE-2026-12514 (The Shared Files  WordPress plugin before 1.7.67, 
shared-files-pro Wor ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12513 (The Shared Files  WordPress plugin before 1.7.67, 
shared-files-pro Wor ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-80724 (In the Linux kernel, the following vulnerability has been 
resolved:  p ...)
        - linux 7.1.12-1
        [trixie] - linux <not-affected> (Vulnerable code not present)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/efd784d994d97159ebfd052b679c709c1f441f09

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/efd784d994d97159ebfd052b679c709c1f441f09
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to