Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
b84eb790 by security tracker role at 2026-09-01T07:13:40+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -33,7 +33,7 @@ CVE-2026-82905 (A vulnerability was detected in sdcb chats up 
to 1.12.0. This af
 CVE-2026-82882 (Devtron through 2.2.0 fails to enforce authorization checks on 
the GET ...)
        TODO: check
 CVE-2026-82852 (Unauthenticated Server Side Request Forgery (SSRF) in MapSVG 
<= 8.15.0 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-82835 (A weakness has been identified in caoqianming django-vue-admin 
1.0. Th ...)
        TODO: check
 CVE-2026-82834 (A security flaw has been discovered in Doccano Open Source 
Annotation  ...)
@@ -95,19 +95,19 @@ CVE-2026-82393 (pnpm is a package manager. Prior to 10.34.5 
and 11.11.0, pnpm ac
 CVE-2026-82392 (pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 
until 11.1 ...)
        TODO: check
 CVE-2026-82346 (A potential security vulnerability has been identified in the 
HP Image ...)
-       TODO: check
+       NOT-FOR-US: HP
 CVE-2026-82229 (Unauthenticated Cross Site Scripting (XSS) in WordPress Social 
Login a ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-82228 (Unauthenticated Bypass Vulnerability in SiteGround Security <= 
1.6.6 v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-82226 (Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-82225 (Unauthenticated Broken Authentication in RegistrationMagic <= 
6.0.9.8  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-82224 (Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 
1.2.10 versio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-82221 (Unauthenticated Cross Site Scripting (XSS) in 
RegistrationMagic <= 6.0 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81892 (EasyAdmin is a fast and modern admin generator for Symfony 
application ...)
        TODO: check
 CVE-2026-81891 (elFinder is an open-source file manager for web, written in 
JavaScript ...)
@@ -121,43 +121,43 @@ CVE-2026-81888 (@hono/oauth-providers is Authentication 
middleware for Hono. Pri
 CVE-2026-81887 (Livewire is a full-stack framework for Laravel. From 
3.0.0-beta.1 unti ...)
        TODO: check
 CVE-2026-81780 (Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81779 (Improper Validation of Specified Quantity in Input 
vulnerability in Si ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81778 (Subscriber Cross Site Scripting (XSS) in Kalles Addons <= 
1.0.6 versio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81768 (Unauthenticated Cross Site Scripting (XSS) in Super Store 
Finder <= 7. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81765 (Unauthenticated Cross Site Scripting (XSS) in Tailored Tools 
<= 3.0.2  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81764 (Unauthenticated Cross Site Scripting (XSS) in Email Essentials 
<= 6.0. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81763 (Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81762 (Subscriber Broken Access Control in Booking and Rental Manager 
<= 2.7. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81758 (Subscriber Broken Access Control in OwnerRez API <= 1.2.6 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81756 (Unauthenticated SQL Injection in Smart Marketing SMS and 
Newsletters F ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81298 (Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 
4.0.5 v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81297 (Subscriber Privilege Escalation in Fluent Forms Pro Add On 
Pack <= 6.2 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81296 (Unauthenticated Broken Access Control in Fluent Forms Pro Add 
On Pack  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81293 (Unauthenticated SQL Injection in WP Data Access <= 5.5.81 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81291 (Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81290 (Unauthenticated Cross Site Scripting (XSS) in Email 
Subscribers & News ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81287 (Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81280 (Subscriber Sensitive Data Exposure in Print Barcode Labels for 
your Wo ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81278 (Missing Authorization vulnerability in WPExperts Post SMTP 
allows Expl ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81267 (A malicious webpage could stall a popup's cross-origin 
navigation afte ...)
        TODO: check
 CVE-2026-79483 (FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable 
to a No ...)
@@ -173,7 +173,7 @@ CVE-2026-77950 (Generation of Error Message Containing 
Sensitive Information vul
 CVE-2026-77856 (Allocation of Resources Without Limits or Throttling 
vulnerability in  ...)
        TODO: check
 CVE-2026-77823 (The LearnPress plugin for WordPress is vulnerable to SQL 
Injection via ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77353 (Wallos is an open-source, self-hostable personal subscription 
tracker. ...)
        TODO: check
 CVE-2026-77352 (Wallos is an open-source, self-hostable personal subscription 
tracker. ...)
@@ -183,19 +183,19 @@ CVE-2026-77351 (Wallos is an open-source, self-hostable 
personal subscription tr
 CVE-2026-77348 (Wallos is an open-source, self-hostable personal subscription 
tracker. ...)
        TODO: check
 CVE-2026-77189 (The Charitable \u2013 Donation & Fundraising Platform 
(Donation Forms, ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-76006 (The Photo Gallery by Ays \u2013 Responsive Image Gallery 
plugin for Wo ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-75980 (The BetterDocs \u2013 AI Documentation, Knowledge Base, Docs, 
Wikis, F ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-75965 (The User Profile Builder \u2013 Beautiful User Registration 
Forms, Use ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-75964 (The User Profile Builder \u2013 Beautiful User Registration 
Forms, Use ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-75921 (The Master Addons for Elementor \u2013 Elementor Addons, 
Widgets, Mega ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-75865 (The WPLP Cookie Consent \u2013 Cookie Banner & Consent 
Management for  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-75594 (Kirby is an open-source content management system. Prior to 
4.9.5 and  ...)
        TODO: check
 CVE-2026-75592 (Kirby is an open-source content management system. Prior to 
4.9.5 and  ...)
@@ -235,25 +235,25 @@ CVE-2026-54179 (backpack/crud provides Create, Read, 
Update & Delete (CRUD) func
 CVE-2026-52730 (Xibo is an open source digital signage platform with a web 
content man ...)
        TODO: check
 CVE-2026-51740 (Incorrect access control in the killProcess function of 
TOTOLINK T6 4. ...)
-       TODO: check
+       NOT-FOR-US: TOTOLINK
 CVE-2026-51739 (Incorrect access control in the CloudSrvVersionCheck function 
of TOTOL ...)
-       TODO: check
+       NOT-FOR-US: TOTOLINK
 CVE-2026-51738 (Incorrect access control in the LoadDefSettings function of 
TOTOLINK T ...)
-       TODO: check
+       NOT-FOR-US: TOTOLINK
 CVE-2026-51737 (Incorrect access control in the clearTracerouteLog function of 
TOTOLIN ...)
-       TODO: check
+       NOT-FOR-US: TOTOLINK
 CVE-2026-51736 (Incorrect access control in the clearSyslog function of 
TOTOLINK T6 4. ...)
-       TODO: check
+       NOT-FOR-US: TOTOLINK
 CVE-2026-51735 (Incorrect access control in the showSyslog function of 
TOTOLINK T6 4.1 ...)
-       TODO: check
+       NOT-FOR-US: TOTOLINK
 CVE-2026-51734 (Incorrect access control in the informSlaveUpdate function of 
TOTOLINK ...)
-       TODO: check
+       NOT-FOR-US: TOTOLINK
 CVE-2026-51733 (Incorrect access control in the FirmwareUpgrade function of 
TOTOLINK T ...)
-       TODO: check
+       NOT-FOR-US: TOTOLINK
 CVE-2026-51732 (Incorrect access control in the delWiFiScheduleCfg function of 
TOTOLIN ...)
-       TODO: check
+       NOT-FOR-US: TOTOLINK
 CVE-2026-51731 (Incorrect access control in the delVlanCfg function of 
TOTOLINK T6 4.1 ...)
-       TODO: check
+       NOT-FOR-US: TOTOLINK
 CVE-2026-50199 (Wallos is an open-source, self-hostable personal subscription 
tracker. ...)
        TODO: check
 CVE-2026-50198 (Wallos is an open-source, self-hostable personal subscription 
tracker. ...)
@@ -263,39 +263,39 @@ CVE-2026-4560
 CVE-2026-48932 (A flaw in Node.js HTTP client can cause a request 
desynchronization fo ...)
        TODO: check
 CVE-2026-38577 (Insecure hardcoded credentials in the Admin account of Tenda 
HG21 V4.0 ...)
-       TODO: check
+       NOT-FOR-US: Tenda
 CVE-2026-19952 (The Frontend Admin by DynamiApps plugin for WordPress is 
vulnerable to ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19948 (The Cozy Blocks \u2013 Page Builder for Gutenberg Editor & FSE 
with 70 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19820 (A vulnerability in the Backblaze Client allows a local user to 
make th ...)
        TODO: check
 CVE-2026-19806 (The Support Genix \u2013 Helpdesk, AI Chatbot, Knowledge Base 
& Custom ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19796 (The Listdom: AI-powered Business Directory with Classifieds 
Ads Listin ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19573 (The Affiliate Super Assistent plugin for WordPress is 
vulnerable to St ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19032 (jackson-databind's deserializer for java.nio.file.Path 
resolves an att ...)
        TODO: check
 CVE-2026-18752 (The Persistent Login plugin for WordPress is vulnerable to 
generic SQL ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18743 (A flaw was found in popt. This vulnerability allows an 
attacker to pro ...)
        TODO: check
 CVE-2026-18488 (The Blocksy Companion plugin for WordPress is vulnerable to 
Stored Cro ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-17589 (The Shopping Cart & eCommerce Store plugin for WordPress is 
vulnerable ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16787 (The Live Composer \u2013 Free WordPress Website Builder plugin 
for Wor ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14697 (net_ipv6_send_ns() in subsys/net/ip/ipv6_nbr.c allocates a 
transmit ne ...)
-       TODO: check
+       NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-13732 (A flaw was found in GDB's STABS debug format parser. The 
read_member_f ...)
        TODO: check
 CVE-2026-13203 (The Live Composer \u2013 Free WordPress Website Builder plugin 
for Wor ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12747 (The Frontend Admin by DynamiApps plugin for WordPress is 
vulnerable to ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-63607 (TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In 
contact_ ...)
        TODO: check
 CVE-2026-XXXX [GHSA-g89c-p67h-r497: Heap buffer overflow in 
`scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` 
items]



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b84eb790f49ec71c36aaf0db0dbd2173a76aba4d

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b84eb790f49ec71c36aaf0db0dbd2173a76aba4d
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to