Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
34ce78f4 by security tracker role at 2026-09-02T19:15:47+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
 CVE-2026-8151 (The Simple Membership MailChimp Integration WordPress plugin 
before 1. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84841 (A security flaw has been discovered in tsi-coop tsi-dpdp-cms 
up to 0.5 ...)
        TODO: check
 CVE-2026-84840 (A vulnerability was identified in tsi-coop tsi-dpdp-cms up to 
0.5.0. T ...)
@@ -11,7 +11,7 @@ CVE-2026-84838 (A flaw was found in rpmuncompress. This 
command injection vulner
 CVE-2026-84837 (A flaw was found in rpm. An attacker can exploit a command 
injection v ...)
        TODO: check
 CVE-2026-84835 (Missing Authorization vulnerability in DimaFreund Rentsyst 
allows Expl ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84833 (A vulnerability was found in ntegrals openbrowser up to 
067fc45d649baa ...)
        TODO: check
 CVE-2026-84811 (agentverus-scanner fails to analyze compiled Python bytecode 
files in  ...)
@@ -31,113 +31,113 @@ CVE-2026-84805 (Kimai versions from 2.61.0 before 2.63.0 
fail to disable admin-o
 CVE-2026-84804 (Kimai before 2.65.0 fails to properly validate permissions 
when removi ...)
        TODO: check
 CVE-2026-84803 (SiYuan before v3.8.2 contains a stored cross-site scripting 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-84802 (Craft CMS versions from 5.7.0 before 5.10.12 contain an 
information di ...)
-       TODO: check
+       NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-84801 (Craft CMS versions before 5.10.11 fail to validate admin 
status in the ...)
-       TODO: check
+       NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-84800 (Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a 
missing author ...)
-       TODO: check
+       NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-84799 (Craft CMS before 5.11.0 fails to enforce user-group scope 
filters on n ...)
-       TODO: check
+       NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-84798 (Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform 
an indep ...)
-       TODO: check
+       NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-84797 (Craft CMS versions before 5.10.11 contain an authorization 
bypass vuln ...)
-       TODO: check
+       NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-84796 (Craft CMS versions before 5.10.11 contain a site scope bypass 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-84795 (Craft CMS before 5.10.11 fails to validate the admin flag 
during user  ...)
-       TODO: check
+       NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-84794 (Craft CMS versions before 5.10.11 lack authorization checks in 
the ass ...)
-       TODO: check
+       NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-84793 (Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a 
stored cros ...)
-       TODO: check
+       NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-84792 (Craft CMS versions before 5.10.11 contain a broken access 
control vuln ...)
-       TODO: check
+       NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-84781 (Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks 
<= 1.3.4 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84780 (Unauthenticated Denial of Service Attack in WP Go Maps <= 
10.1.08 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84775 (Unauthenticated Denial of Service Attack in Really Simple SSL 
<= 9.8.0 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84772 (Editor Server Side Request Forgery (SSRF) in Broken Link 
Checker <= 2. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84771 (Unauthenticated Insecure Direct Object References (IDOR) in 
PublishPre ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84770 (Unauthenticated Cross Site Request Forgery (CSRF) in Mang 
Board WP <=  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84764 (Unauthenticated Cross Site Request Forgery (CSRF) in Simply 
Schedule A ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84760 (Unauthenticated Broken Access Control in Ultimate Gift Cards 
For WooCo ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84759 (Unauthenticated Cross Site Request Forgery (CSRF) in Activity 
Log <= 2 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84677 (Jenkins update-center2 3.18.3 and earlier does not escape 
plugin-provi ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84676 (Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier 
stores t ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84675 (OS command injection vulnerability in Jenkins TICS Plugin 
2025.1.1 and ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84674 (Missing permission checks in Jenkins XebiaLabs XL Deploy 
Plugin 26.1.0 ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84673 (Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and 
earlier al ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84672 (Jenkins Microsoft Entra ID (previously Azure AD) Plugin 
710.v0b_ff8e9c ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84671 (Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier 
allows w ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84670 (Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier 
does not r ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84669 (A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 
and ear ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84668 (Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows 
overwriti ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84667 (Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting 
the plu ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84666 (Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc 
and earl ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84665 (Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not 
limit URL ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84664 (Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting 
the global ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84663 (A cross-site request forgery (CSRF) vulnerability in Jenkins 
Pipeline: ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84662 (Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows 
connecti ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84661 (A missing permission check in Jenkins Pipeline: Build Step 
Plugin 599. ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84660 (A missing permission check in Jenkins Pipeline: Build Step 
Plugin 599. ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84659 (Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier 
does no ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84658 (Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier 
uses th ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84657 (In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the 
build CLI c ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84656 (A missing permission check in Jenkins 2.579 and earlier, LTS 
2.568.2 a ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84655 (Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not 
escape map ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84654 (In Stapler 2107.v8dfcb_e8ed317 and earlier, except 
2088.2093.vd7c3e580 ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84653 (Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 
through 2.56 ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84652 (In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins 
does no ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84651 (In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the 
REST API an ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84650 (In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, 
transient field ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84649 (In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 
(both inc ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84648 (In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the 
system log  ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84647 (In Stapler 2107.v8dfcb_e8ed317 and earlier, except 
2088.2093.vd7c3e580 ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84646 (In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user 
objects ca ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84645 (In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects 
of type ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-84382 (HTTPX2 is a next generation HTTP client for Python. Prior to 
2.12.0, t ...)
        TODO: check
 CVE-2026-84381 (HTTPX2 is a next generation HTTP client for Python. Prior to 
2.10.0, h ...)
@@ -153,21 +153,21 @@ CVE-2026-84377 (LiteLLM is a proxy server (AI Gateway) to 
call LLM APIs in OpenA
 CVE-2026-84376 (Astro is a web framework for content-driven websites. Prior to 
7.2.4,  ...)
        TODO: check
 CVE-2026-84217 (Missing Authorization vulnerability in Mamunur Rashid 
Classified Listi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84175 (In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service 
fetches W ...)
        TODO: check
 CVE-2026-83562 (Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 
3.8.2 ve ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-83547 (The Xpro Addons WordPress plugin before 1.7.4 does not 
properly escape ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-83533 (The WP Express Checkout WordPress plugin before 2.4.9 does not 
verify  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-82958 (In Eclipse Ditto versions [1.3.0, 3.9.6], the 
ImplicitThingCreationMes ...)
        TODO: check
 CVE-2026-82955 (In the current development version of Eclipse aeriOS, which 
has not ye ...)
        TODO: check
 CVE-2026-82884 (The All in One SEO WordPress plugin before 5.0.0.1 does not 
sanitise a ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-82522 (libjxl before 0.12 contains an integer underflow vulnerability 
in the  ...)
        TODO: check
 CVE-2026-82404 (TOON is a compact, human-readable serialization of JSON data 
for LLM p ...)
@@ -175,61 +175,61 @@ CVE-2026-82404 (TOON is a compact, human-readable 
serialization of JSON data for
 CVE-2026-82293 (Incorrect Authorization (CWE-863) in the Kibana machine 
learning featu ...)
        TODO: check
 CVE-2026-82223 (Unauthenticated Broken Access Control in WP Event SOlution <= 
4.1.22 v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81775 (Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81774 (Unauthenticated Sensitive Data Exposure in WooCommerce Product 
Attachm ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81772 (Unauthenticated PHP Object Injection in Ninja Forms - Layout & 
Styles  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81771 (Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 
1.2.5 ver ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81770 (Unauthenticated Cross Site Scripting (XSS) in Interactive Geo 
Maps <=  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81769 (Incorrect Privilege Assignment vulnerability in LiquidThemes 
Booking H ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81571 (The Brave WordPress plugin before 0.8.8 does not prevent a URL 
paramet ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-81294 (Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81289 (Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player 
for Mus ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81288 (Unauthenticated Cross Site Scripting (XSS) in Upsell Order 
Bump Offer  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81286 (Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81283 (Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 
versions ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81269 (Missing Authorization vulnerability in Drupal Data field 
allows Forcef ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-81205 (Improper Neutralization of Special Elements used in an LDAP 
Query ('LD ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-81201 (Improper Neutralization of Input During Web Page Generation 
("Cross-si ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-81168 (Authentication Bypass Using an Alternate Path or Channel 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-81167 (Improper Neutralization of Input During Web Page Generation 
("Cross-si ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-81166 (Missing Authorization vulnerability in Drupal Digital Signage 
Framewor ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-81165 (Incorrect Authorization vulnerability in Drupal Blazy allows 
Forceful  ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-81164 (Missing Authorization vulnerability in Drupal Entity PDF 
allows Forcef ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-81162 (Insertion of Sensitive Information Into Sent Data 
vulnerability in Dru ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-81161 (Privilege Defined With Unsafe Actions vulnerability in Drupal 
Content  ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-81160 (Improper Neutralization of Input During Web Page Generation 
("Cross-si ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-81159 (Observable Timing Discrepancy vulnerability in Drupal Commerce 
CyberSo ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-81158 (Incorrect Authorization vulnerability in Drupal Entity API 
allows Forc ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-79991 (Craft CMS GraphQL entry mutation resolvers 
(saveEntry,deleteEntry) rea ...)
-       TODO: check
+       NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-79990 (Craft CMS GraphQL entry mutation resolvers 
(saveEntry,deleteEntry) rea ...)
-       TODO: check
+       NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-79989 (The vulnerability allows any authenticated user to change 
their own pa ...)
        TODO: check
 CVE-2026-79756 (Nuclio is a "Serverless" framework for Real-Time Events and 
Data Proce ...)
@@ -277,57 +277,57 @@ CVE-2026-78408 (The nsenter --join-cgroup option opens 
the target cgroup.procs f
 CVE-2026-78222 (A vulnerability exists in NGINX JavaScript where a malformed 
HTTP resp ...)
        TODO: check
 CVE-2026-78153 (The Restrict User Access WordPress plugin before 2.8.1 does 
not normal ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77794 (The RegistrationMagic WordPress plugin before 6.0.9.9 does not 
validat ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77793 (The RegistrationMagic WordPress plugin before 6.0.9.9 does not 
validat ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77180 (When NGINX Ingress Controller is configured with Ingress 
annotations,  ...)
-       TODO: check
+       NOT-FOR-US: F5
 CVE-2026-77125 (A vulnerability was identified in Sonatype Nexus Repository 3 
in which ...)
-       TODO: check
+       NOT-FOR-US: Sonatype
 CVE-2026-77124 (In affected versions of Nexus Repository 3, the script 
execution endpo ...)
-       TODO: check
+       NOT-FOR-US: Sonatype
 CVE-2026-77123 (Nexus Repository 3 contains a sensitive information disclosure 
vulnera ...)
-       TODO: check
+       NOT-FOR-US: Sonatype
 CVE-2026-77122 (An authorization flaw in the REST API repository details 
endpoint (GET ...)
-       TODO: check
+       NOT-FOR-US: Sonatype
 CVE-2026-77121 (A user account with permission to deploy artifacts to a hosted 
Maven r ...)
-       TODO: check
+       NOT-FOR-US: Sonatype
 CVE-2026-77009 (The WatchMan-Site7 WordPress plugin through 4.2.0 does not 
restrict ac ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-76782 (Vulnerability in Drupal Screenshot. This issue affects 
Screenshot vers ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-76759 (Vulnerability in Drupal Screenshot. This issue affects 
Screenshot vers ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-76758 (Vulnerability in Drupal Link content parser. This issue 
affects Link c ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-76757 (Vulnerability in Drupal Gammu SMS Daemon. This issue affects 
Gammu SMS ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-76756 (Vulnerability in Drupal Gammu SMS Daemon. This issue affects 
Gammu SMS ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-76755 (Vulnerability in Drupal Gammu SMS Daemon. This issue affects 
Gammu SMS ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-75528 (The Broken Link Checker plugin for WordPress is vulnerable to 
Stored C ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-73478 (Incorrect Authorization vulnerability in Drupal Diff allows 
Forceful B ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-73477 (Incorrect Authorization vulnerability in Drupal Quick Tabs 
allows Forc ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-73476 (Improper Handling of Case Sensitivity vulnerability in Drupal 
External ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-73475 (Incorrect Authorization vulnerability in Drupal Commerce 
PayPal allows ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-73474 (Server-Side Request Forgery (SSRF) vulnerability in Drupal 
Entity Shar ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-66842 (BIG-IP has a vulnerability where an authenticated user of any 
role may ...)
        TODO: check
 CVE-2026-66652 (Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods 
Grand To ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66362 (Description: When NGINX Plus is configured as the data plane 
for NGINX ...)
        TODO: check
 CVE-2026-63020 (A vulnerability exists in an undisclosed BIG-IP Configuration 
utility  ...)
-       TODO: check
+       NOT-FOR-US: F5
 CVE-2026-55421 (Open edX Platform enables the authoring and delivery of online 
learnin ...)
        TODO: check
 CVE-2026-55221 (Boruta is a standalone authorization server that aims to 
implement OAu ...)
@@ -357,7 +357,7 @@ CVE-2026-52832 (Nuclio is a "Serverless" framework for 
Real-Time Events and Data
 CVE-2026-52831 (Nuclio is a "Serverless" framework for Real-Time Events and 
Data Proce ...)
        TODO: check
 CVE-2026-4357 (The Embed HTML5 Game WordPress plugin through 1.3 does not 
properly re ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-49833 (DSpace open source software is a repository application which 
provides ...)
        TODO: check
 CVE-2026-49832 (DSpace open source software is a repository application which 
provides ...)
@@ -371,11 +371,11 @@ CVE-2026-49249 (Boruta is a standalone authorization 
server that aims to impleme
 CVE-2026-45730 (Nuclio is a "Serverless" framework for Real-Time Events and 
Data Proce ...)
        TODO: check
 CVE-2026-32773 (There is a lack of XSS escaping in the Spark History Server 
prior to 3 ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-2811 (The Ajaxify Comments WordPress plugin before 3.2 is vulnerable 
to HTTP ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-2688 (The HIPAA FORMS WordPress plugin before 3.2.0 contains a 
hardcoded aut ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-23591
        REJECTED
 CVE-2026-23590
@@ -399,79 +399,79 @@ CVE-2026-20355 (Multiple vulnerabilities in the 
Secure/Multipurpose Internet Mai
 CVE-2026-20354 (Multiple vulnerabilities in the Secure/Multipurpose Internet 
Mail Exte ...)
        TODO: check
 CVE-2026-20281 (A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP 
Phone 7800 a ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20280 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20279 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20278 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20277 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20276 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20275 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20274 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20212 (A vulnerability in the Silicon One integration for Cisco Nexus 
9000 Se ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-19698 (The GutenKit WordPress plugin before 2.5.1 does not validate 
or escape ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19475 (An authenticated user with permission to query a SQL data 
source can b ...)
        TODO: check
 CVE-2026-19219 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.3.812, 
insuffic ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-19117 (Under specific conditions, an attacker can register an 
attacker-contro ...)
        TODO: check
 CVE-2026-18986 (Improper Neutralization of Input During Web Page Generation 
("Cross-si ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-18672 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.3.812, 
insuffic ...)
-       TODO: check
+       NOT-FOR-US: Progress Software
 CVE-2026-18329 (Description  NGINX JavaScript (njs)and QuickJS (qjs) 
engineshave a vul ...)
        TODO: check
 CVE-2026-18058 (The mobile Smart Connect dashboard UI was subject to 
manipulation by 3 ...)
-       TODO: check
+       NOT-FOR-US: Lenovo
 CVE-2026-17563 (The User Frontend WordPress plugin before 4.3.11 does not 
enforce its  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16647 (Authentication Bypass Using an Alternate Path or Channel 
vulnerability ...)
-       TODO: check
+       NOT-FOR-US: Drupal core and addons
 CVE-2026-14828 (Zohocorp ManageEngine Password Manager Pro versions before 
13235, PAM3 ...)
-       TODO: check
+       NOT-FOR-US: Zoho
 CVE-2026-14326 (The Timetics WordPress plugin through 1.0.61 does not enforce 
per-obje ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14255 (A maliciously crafted IFC file, when parsed through certain 
Autodesk p ...)
-       TODO: check
+       NOT-FOR-US: Autodesk
 CVE-2026-14199 (Only self-managed Grafana instances with Auth Proxy 
authentication and ...)
        TODO: check
 CVE-2026-12704 (When SAML IdP-initiated login is enabled in Grafana 
Enterprise, the SA ...)
-       TODO: check
+       NOT-FOR-US: Grafana Labs
 CVE-2026-10821 (The Yoast SEO Premium WordPress plugin before 27.6.1 does not 
sanitize ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-9314 (The Developer Tools WordPress plugin through 1.1.3 contains an 
unauthe ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-8945 (The Wp Edit Password Protected WordPress plugin before 1.3.5 
allows pr ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-7963 (The Easy Waveform Player plugin for WordPress is vulnerable to 
Stored  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-15692 (The Icegram Express WordPress plugin before 5.8.6 does not 
properly es ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-15490 (The Passster WordPress plugin before 4.2.26 has a flaw in its 
global p ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-15489 (The Passster WordPress plugin before 4.2.24 does not handle 
input prop ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-15485 (The Auto x LINE WordPress plugin through 1.0.0 does not have 
authoriza ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-15481 (The Notification Bar for WordPress plugin through 1.1.8 
exposes an una ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-13398
        REJECTED
 CVE-2024-7956 (A vulnerability exists in the affected products that allows a 
threat a ...)
-       TODO: check
+       NOT-FOR-US: Rockwell Automation
 CVE-2024-3773 (The LiveJournal Shortcode WordPress plugin through 1.1.1 does 
not vali ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2023-3360 (The Weaver Show Posts WordPress plugin before 1.8.1 
unserialises the c ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-9055 (The Booking for Appointments and Events Calendar \u2013 Amelia 
(Premiu ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-84715 (FeatherPanel versions before 1.3.7.10 fail to validate 
permissions in  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/34ce78f40338e2b030adbadafe786f39c3867424

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/34ce78f40338e2b030adbadafe786f39c3867424
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to