Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
208a2809 by security tracker role at 2026-09-05T07:13:27+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,15 +1,15 @@
 CVE-2026-9317 (Nango before 0.71.6 contains a missing authentication 
vulnerability in ...)
        TODO: check
 CVE-2026-9186 (IBM Langflow OSS 1.0.0 through 1.11.2 allows remote 
authenticated atta ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-9138 (IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an 
authenti ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-8625 (The Dear Flipbook \u2013 PDF Flipbook, 3D Flipbook, PDF embed, 
PDF vie ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-8623 (The Dear Flipbook \u2013 PDF Flipbook, 3D Flipbook, PDF embed, 
PDF vie ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-8447 (IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored 
cross-site  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-86145 (PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds 
write becaus ...)
        TODO: check
 CVE-2026-86144 (In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and 
xmlXInclu ...)
@@ -43,11 +43,11 @@ CVE-2026-86091 (ntopng before 6.7.260717 fails to check 
user privileges in the p
 CVE-2026-86090 (ntopng before 6.7.260717 fails to perform authorization checks 
in the  ...)
        TODO: check
 CVE-2026-85787 (An incomplete list of disallowed inputs in the SQL validation 
componen ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-85786 (Improper handling of highly compressed data in Amazon ion-java 
before  ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-85781 (Unverified ownership of a storage access point in the volume 
deletion  ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-85769 (A flaw was found in libtpms, a library that provides software 
TPM 2.0  ...)
        TODO: check
 CVE-2026-85730 (smol-toml is a small, fast, and correct TOML parser and 
serializer. Pr ...)
@@ -129,9 +129,9 @@ CVE-2026-85661 (excel-mcp-server 0.1.8 fails to enforce 
path confinement in stdi
 CVE-2026-85660 (cli-mcp-server 0.2.5 contains a command allowlist bypass 
vulnerability ...)
        TODO: check
 CVE-2026-85656 (An OS command injection issue in the 
log4j-cve-2021-44228-hotpatch pac ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-85654 (Improper neutralization of special elements used in a template 
engine  ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-85651 (Trigger.dev versions before 4.5.2 fail to validate environment 
members ...)
        TODO: check
 CVE-2026-85650 (Trigger.dev before 4.5.2 contains a server-side request 
forgery vulner ...)
@@ -139,7 +139,7 @@ CVE-2026-85650 (Trigger.dev before 4.5.2 contains a 
server-side request forgery
 CVE-2026-85649 ((Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier 
contains a fa ...)
        TODO: check
 CVE-2026-85643 (A flaw has been found in code-projects Online Shopping System 
1.0. Imp ...)
-       TODO: check
+       NOT-FOR-US: code-projects
 CVE-2026-85639 (A security vulnerability has been detected in jofpin trape 
2.0. This v ...)
        TODO: check
 CVE-2026-85638 (A weakness has been identified in jofpin trape 2.0. This 
affects an un ...)
@@ -231,21 +231,21 @@ CVE-2026-85587 (phpMyFAQ before 4.1.8 enforces incorrect 
permission checks on ad
 CVE-2026-85586 (phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when 
the store ...)
        TODO: check
 CVE-2026-85585 (SiYuan before v3.8.2 contains an unbounded resource 
consumption vulner ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-85584 (SiYuan versions before v3.8.2 contain a denial of service 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-85583 (SiYuan versions before v3.8.2 contain a path traversal 
vulnerability i ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-85582 (SiYuan versions before v3.8.2 contain an unbounded session 
creation vu ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-85581 (SiYuan before v3.8.2 contains a denial of service 
vulnerability in the ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-85580 (SiYuan versions before v3.8.2 contain a path guard bypass 
vulnerabilit ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-85579 (SiYuan is affected by an information disclosure vulnerability 
(confirm ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-85578 (SiYuan through 3.8.1 contains an authorization bypass 
vulnerability in ...)
-       TODO: check
+       NOT-FOR-US: SiYuan
 CVE-2026-85577 (AVideo through commit c91b5975d contains a reflected 
cross-site script ...)
        TODO: check
 CVE-2026-85547 (A cross-site request forgery (CSRF) vulnerability exists in 
MISP due t ...)
@@ -269,19 +269,19 @@ CVE-2026-85525 (Improper OCSP response validation in the 
Snowflake Python, Go, J
 CVE-2026-85522 (A vulnerability was detected in valkey-io valkey up to 
9.5.4/9.1.0. Af ...)
        TODO: check
 CVE-2026-85517 (A flaw has been found in code-projects Vehicle Management 
System 1.0.  ...)
-       TODO: check
+       NOT-FOR-US: code-projects
 CVE-2026-85516 (A vulnerability was detected in code-projects Vehicle 
Management Syste ...)
-       TODO: check
+       NOT-FOR-US: code-projects
 CVE-2026-85514 (A security vulnerability has been detected in StackStorm st2 
up to 3.9 ...)
        TODO: check
 CVE-2026-85513 (A weakness has been identified in StackStorm st2 up to 3.9.0. 
This iss ...)
        TODO: check
 CVE-2026-85512 (A security flaw has been discovered in SourceCodester Class 
and Exam T ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-85311 (Missing Authorization vulnerability in Kings Plugins 
MarketKing allows ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-85229 (** UNSUPPORTED WHEN ASSIGNED **Improper neutralization of 
input during ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-85197 (A flaw was found in libsoup. A malicious HTTP/2 server or a 
Man-in-the ...)
        TODO: check
 CVE-2026-85184 (@fastify/middie versions >= 9.1.0 and before 9.3.4 decide 
whether to r ...)
@@ -299,35 +299,35 @@ CVE-2026-84961 (undici's BalancedPool constructor passes 
its entire options obje
 CVE-2026-84947 (undici's dump interceptor reads and discards a response body 
up to a c ...)
        TODO: check
 CVE-2026-84937 (The Video Player for YouTube  WordPress plugin before 2.1.0 
does not p ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84936 (The EmbedPress  WordPress plugin before 4.6.4 does not have 
proper aut ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84935 (The HT Menu  WordPress plugin before 1.2.7 does not perform 
any capabi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84934 (The JCH Optimize WordPress plugin before 6.0.1 does not 
perform a capa ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84933 (undici's cache interceptor does not handle the Set-Cookie 
response hea ...)
        TODO: check
 CVE-2026-84931 (The Joli Table Of Contents WordPress plugin before 3.0.3 does 
not sani ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84930 (The CatFolders Document Gallery & PDF Library WordPress plugin 
before  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84927 (The EmbedPress  WordPress plugin before 4.6.4 does not perform 
a suffi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84926 (The EmbedPress  WordPress plugin before 4.6.4 does not 
correctly restr ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84901 (The Eventin  WordPress plugin before 4.1.22 does not properly 
check au ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84899 (The VikWidgetsLoader  WordPress plugin before 1.12.0 does not 
sanitise ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84898 (The Eventin  WordPress plugin before 4.1.21 does not properly 
validate ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84896 (The King Addons for Elementor  WordPress plugin before 51.1.77 
does no ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84890 (undici's decompress interceptor decompresses response bodies 
according ...)
        TODO: check
 CVE-2026-84745 (The Events Calendar WordPress plugin before 6.17.3.1 does not 
restrict ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84504 (fastify versions before 5.12.2 treat the object resolved by a 
successf ...)
        TODO: check
 CVE-2026-84469 (fastify versions before 5.12.2 decide whether to compile a 
request sch ...)
@@ -335,33 +335,33 @@ CVE-2026-84469 (fastify versions before 5.12.2 decide 
whether to compile a reque
 CVE-2026-84428 (fastify versions before 5.12.2 implement the case-insensitive 
nature o ...)
        TODO: check
 CVE-2026-84225 (The Kirki  WordPress plugin before 6.3.0 does not check that a 
user is ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84221 (The Kirki  WordPress plugin before 6.3.0 does not escape a 
user-suppli ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84045 (The E-cab Taxi Booking Manager for Woocommerce WordPress 
plugin before ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84044 (The Restaurant Menu and Food Ordering WordPress plugin before 
2.4.12 d ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84043 (The ePayco Payment Gateway for WooCommerce WordPress plugin 
before 8.4 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84022 (The Bold Page Builder WordPress plugin before 5.9.8 does not 
sanitise  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84021 (The Bold Page Builder WordPress plugin before 5.9.8 does not 
properly  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-83628 (The Theme My Login plugin for WordPress is vulnerable to 
Missing Autho ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-83627 (The Hummingbird \u2013 Speed Optimization, Caching, Minify, 
Compress & ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-83544 (The Greenshift  WordPress plugin before 13.2.0 does not 
properly escap ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-83543 (The Greenshift  WordPress plugin before 13.2.0 does not 
validate a use ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-82923 (The AI Website Builder WordPress plugin (GitHub build) 1.0.0 
does not  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-82911 (Cross-Site Request Forgery (CSRF) in the 
OrderConfirmController at GET ...)
        TODO: check
 CVE-2026-82846 (The Masteriyo LMS  WordPress plugin before 3.4.0 does not 
sanitise and ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-82729 (Inefficient Algorithmic Complexity vulnerability in 
elixir-mint mint a ...)
        TODO: check
 CVE-2026-82728 (Allocation of Resources Without Limits or Throttling 
vulnerability in  ...)
@@ -373,29 +373,29 @@ CVE-2026-82684 (Tycon Systems TPDIN-Monitor-WEB3 versions 
2.2.9 and prior are vu
 CVE-2026-82538 (ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL 
injection v ...)
        TODO: check
 CVE-2026-82304 (The Music Store  WordPress plugin before 1.4.5 does not 
sanitise and e ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-81939 (A Zip Slip vulnerability in the SonicWall Network Security 
Manager (NS ...)
-       TODO: check
+       NOT-FOR-US: SonicWall
 CVE-2026-81859 (CP4BA - IBM Enterprise Records could allow a local attacker to 
obtain  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-81832 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 
12.0.1.0 thr ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-81666 (An integer overflow was found in Corosync's handling of 
membership com ...)
        TODO: check
 CVE-2026-81665 (A heap-based buffer overflow was found in Corosync's Totem 
Process Gro ...)
        TODO: check
 CVE-2026-81424 (The Accept Stripe Payments WordPress plugin before 2.1.4 does 
not veri ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-81423 (The Accept Stripe Payments WordPress plugin before 2.1.4 does 
not vali ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-81404 (The IPGP Visitors Origin WordPress plugin before 1.6 does not 
sanitise ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-81348 (The My Private Site  WordPress plugin before 4.2.3 does not 
apply its  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-81302 (PALLET CONTROL products contain an incorrect default 
permission vulner ...)
        TODO: check
 CVE-2026-80190 (Apache Allura: stored XSS via SVN code repositories. Git 
repositories  ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-80119 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest 
before 11. ...)
        TODO: check
 CVE-2026-80118 (PassMark PerformanceTest before 11.1 build 1012, BurnInTest 
before 11. ...)
@@ -437,37 +437,37 @@ CVE-2026-78839 (An arbitrary file upload vulnerability in 
AppNitro MachForm v30
 CVE-2026-78745 (An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 
Hi3751V352E_DMO allow ...)
        TODO: check
 CVE-2026-78658 (IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 
through 7 ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-78543 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 
12.0.1.0 thr ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-78438 (The W3 Total Cache plugin for WordPress is vulnerable to 
Stored Cross- ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-78362 (The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does 
not corr ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-78328 (A missing authorization vulnerability in the SonicWall Network 
Securit ...)
-       TODO: check
+       NOT-FOR-US: SonicWall
 CVE-2026-78327 (An Improper Neutralization of Special Elements used in an OS 
Command ( ...)
-       TODO: check
+       NOT-FOR-US: SonicWall
 CVE-2026-78150 (The Smart Post  WordPress plugin before 4.0.8 does not check 
the type, ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-78149 (The Smart Post  WordPress plugin before 4.0.8 does not check 
whether a ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77847 (Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are 
vulnerab ...)
        TODO: check
 CVE-2026-77830 (The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin 
for WordP ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77826 (The RegistrationMagic  WordPress plugin before 6.0.9.9 does 
not verify ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77822 (IBM ContextForge MCP Gateway could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-77818 (Improper neutralization of input during web page generation 
('cross-si ...)
        TODO: check
 CVE-2026-77393 (In Ignition 8.1.53 and earlier, the Gateway "Create Project 
Role(s)" s ...)
        TODO: check
 CVE-2026-77263 (The iubenda | All-in-one Compliance for GDPR / CCPA Cookie 
Consent + m ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77233 (The iubenda | All-in-one Compliance for GDPR / CCPA Cookie 
Consent + m ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-76925 (A flaw was found in Flatpak. A Time-of-check to time-of-use 
(TOCTOU) r ...)
        TODO: check
 CVE-2026-76169 (fastify versions >= 4.0.0 and before 5.12.2 can route a 
malformed URL  ...)
@@ -475,7 +475,7 @@ CVE-2026-76169 (fastify versions >= 4.0.0 and before 5.12.2 
can route a malforme
 CVE-2026-75925 (Improper neutralization of CRLF sequences in IXON VPN Client 
before ve ...)
        TODO: check
 CVE-2026-75439 (An issue in Free5GC v.4.2.2 allows a remote attacker to cause 
a denial ...)
-       TODO: check
+       NOT-FOR-US: Free5GC
 CVE-2026-75438 (Buffer Overflow vulnerability in Open5GS v2.7.7 allows a 
remote attack ...)
        TODO: check
 CVE-2026-75431 (PowerJob Server version 5.1.2 (and likely earlier) uses a 
predictable  ...)
@@ -515,7 +515,7 @@ CVE-2026-74236 (GFI Exinda AI and ClearView before 7.6.5 
contains a path travers
 CVE-2026-74235 (GFI Exinda AI and ClearView before 7.6.5 contains a path 
traversal vul ...)
        TODO: check
 CVE-2026-73848 (Emlog is an open source website building system. In versions 
2.6.29 an ...)
-       TODO: check
+       NOT-FOR-US: Emlog
 CVE-2026-71626 (An issue in Invoice Ninja v5.13.24 allows a remote attacker to 
obtain  ...)
        TODO: check
 CVE-2026-71625 (An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote 
attacker to e ...)
@@ -543,9 +543,9 @@ CVE-2026-61614 (SolidInvoice is an open-source invoicing 
platform. Prior to vers
 CVE-2026-61608 (SolidInvoice is an open-source invoicing platform. Prior to 
version 3. ...)
        TODO: check
 CVE-2026-5522 (IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains 
hard-code ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-57777 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57166 (PJSIP is a free and open source multimedia communication 
library writt ...)
        TODO: check
 CVE-2026-57165 (PJSIP is a free and open source multimedia communication 
library writt ...)
@@ -575,11 +575,11 @@ CVE-2026-53761 (Frappe CRM is an open-source customer 
relationship management to
 CVE-2026-53760 (Admidio is an open-source user management solution. In 
versions 5.0.11 ...)
        TODO: check
 CVE-2026-53758 (Emlog is an open source website building system. In versions 
2.6.29 an ...)
-       TODO: check
+       NOT-FOR-US: Emlog
 CVE-2026-53757 (Emlog is an open source website building system. In versions 
2.6.29 an ...)
-       TODO: check
+       NOT-FOR-US: Emlog
 CVE-2026-53756 (Emlog is an open source website building system. Prior to 
version 2.6. ...)
-       TODO: check
+       NOT-FOR-US: Emlog
 CVE-2026-53604 (nebula-mesh is a self-hosted control plane for Slack Nebula 
mesh VPN.  ...)
        TODO: check
 CVE-2026-53603 (nebula-mesh is a self-hosted control plane for Slack Nebula 
mesh VPN.  ...)
@@ -619,61 +619,61 @@ CVE-2026-50553 (Note Mark is an open-source note-taking 
application. Prior to ve
 CVE-2026-4644 (A Missing Authorization vulnerability in HTTP Connector in 
Google Clou ...)
        TODO: check
 CVE-2026-4361 (The Divi theme for WordPress is vulnerable to Server-Side 
Request Forg ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-44402 (Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated 
remote co ...)
        TODO: check
 CVE-2026-3853 (The Divi theme for WordPress is vulnerable to DOM-Based Stored 
Cross-S ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-38961 (Cross-Site Scripting (XSS) vulnerability in the RSS Widget of 
Netgate  ...)
        TODO: check
 CVE-2026-32480 (Missing Authorization vulnerability in WC Lovers WCFM 
Membership allow ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-31020 (In DocsGPT 0.15.0 and below, the application provides a custom 
prompt  ...)
        TODO: check
 CVE-2026-27432 (Authorization Bypass Through User-Controlled Key vulnerability 
in sc I ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27347 (Missing Authorization vulnerability in Crocoblock JetPopup 
allows Expl ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27086 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-19887 (The Welcart e-Commerce plugin for WordPress is vulnerable to 
PHP Objec ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19861 (The JetFormBuilder \u2014 Dynamic Blocks Form Builder 
WordPress plugin ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19858 (The JetFormBuilder \u2014 Dynamic Blocks Form Builder 
WordPress plugin ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19769 (The Ninja Forms \u2013 The Contact Form Builder That Grows 
With You pl ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19727 (Improper neutralization of input during web page generation 
('cross-si ...)
        TODO: check
 CVE-2026-19649 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 
12.0.1.0 thr ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-19645 (IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An 
authenticated user  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-19534 (undici's WebSocket client crashes the whole Node.js process 
during the ...)
        TODO: check
 CVE-2026-19306 (IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated 
attacker ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-19305 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote 
attacker to ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-19304 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-19303 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-19302 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-19301 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-19300 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote 
attacker to ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-19299 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-19298 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-19283 (IBM Observability with Instana (Agent) Build 1.0.303 through 
1.0.323 I ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-19274 (IBM Observability with Instana (Agent) Build 1.0.303 through 
1.0.323 I ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-19205 (Observable response discrepancy vulnerability in GastroMenum 
GastroMen ...)
        TODO: check
 CVE-2026-19081 (Missing Authorization vulnerability in Gastromenum Gastromenum 
Ticket  ...)
@@ -689,129 +689,129 @@ CVE-2026-19043 (Missing Authorization vulnerability in 
Menulux Software Inc. Men
 CVE-2026-18957 (Improper neutralization of input during web page generation 
('cross-si ...)
        TODO: check
 CVE-2026-18905 (IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= 
v1.0.6 MC ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18887 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated 
attacker to  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18858 (IBM i 7.6, and 7.5 could allow a local authenticated attacker 
to obtai ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18843 (The Beaver Builder Plugin (Starter Version) plugin for 
WordPress is vu ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18745
        REJECTED
 CVE-2026-18658 (IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 
8.11.0.1, ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18567 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local 
attacker to ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18540 (undici's retry interceptor can append the body of a ranged 
retry respo ...)
        TODO: check
 CVE-2026-18489 (IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP 
Context  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18486 (IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could 
allow a ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18406 (The SureForms \u2013 Contact Form Builder, AI Forms, Payment 
Form, Sur ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18404 (The Social Chat \u2013 Click To Chat App Button plugin for 
WordPress i ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18341 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18221 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
gain una ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18198 (Improper neutralization of special elements used in an SQL 
command ('S ...)
        TODO: check
 CVE-2026-18175 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
manipula ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18149 (undici's retry handler can leave an already-exposed response 
body pend ...)
        TODO: check
 CVE-2026-18078 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18076 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-18073 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated 
attacke ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17631 (IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17627 (IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17622 (IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17621 (IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote 
attacker to ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17499 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to 
execute a ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17483 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a 
local attac ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17470 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17469 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated 
attacke ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17444 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 
12.0.1.0 thr ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17443 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 
12.0.1.0 thr ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17442 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 
12.0.1.0 thr ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17440 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 
12.0.1.0 thr ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17274 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17273 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17270 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to 
cause a d ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17259 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17255 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17207 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-17057 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to 
cause a  ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16941 (IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated 
attacker to ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16892 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16826 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to 
execute a ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16693 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote 
authenticated attack ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16689 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 
12.0.1.0 thr ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16660 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote 
attacker t ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-16649 (The Gravity Forms plugin for WordPress is vulnerable to Stored 
Cross-S ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-16180 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 
12.0.1.0 thr ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-15984 (The QuickCal plugin for WordPress is vulnerable to Stored 
Cross-Site S ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15937 (Improper certificate validation in Checkmk <2.5.0p10 allows a 
relay an ...)
        TODO: check
 CVE-2026-15247 (The Search Atlas SEO  WordPress plugin before 2.6.24 does not 
perform  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14975 (The WP File Download plugin for WordPress is vulnerable to 
Directory T ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14470 (IBM Langflow OSS 1.0.0 through 1.10.2 could allow an 
authenticated att ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-14466 (It\u2019s possible to run a stored XSS in Stormshield\u2019s 
web admin ...)
        TODO: check
 CVE-2026-14350 (IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 
could a ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-13447 (The Mstore Api plugin for WordPress is vulnerable to 
Authentication By ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13297 (IBM Verify Identity Access Advanced Access Control may be 
vulnerable t ...)
-       TODO: check
+       NOT-FOR-US: IBM
 CVE-2026-13148 (Missing release of memory after effective lifetime 
vulnerability in So ...)
-       TODO: check
+       NOT-FOR-US: Softing
 CVE-2026-12483 (The LearnDash LMS plugin for WordPress is vulnerable to 
Unrestricted F ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-67066 (SQL Injection vulnerability in oasys sysoa version 1.0 allows 
a remote ...)
        TODO: check
 CVE-2025-15694 (The Joli Table Of Contents WordPress plugin before 2.8.1 does 
not sani ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-15693 (The JCH Optimize WordPress plugin before 5.0.1 does not 
properly restr ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-14945 (The Events Manager - Calendar, Bookings, Tickets, and more! 
plugin for ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-82309 (Robots::Validate versions from 0.3.2 before 0.3.11 for Perl 
allow unbo ...)
        NOT-FOR-US: Robots::Validate Perl module
 CVE-2026-80911 (In the Linux kernel, the following vulnerability has been 
resolved:  A ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/208a280977dd46352d779df6b0c25da3b6dc2f4b

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/208a280977dd46352d779df6b0c25da3b6dc2f4b
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to