Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
bbf0919e by security tracker role at 2026-09-12T07:14:01+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -35,7 +35,7 @@ CVE-2026-90444 (A file-transfer interface that requires valid
credentials accept
CVE-2026-90443 (A web interface reflects a portion of the request URL into a
script co ...)
TODO: check
CVE-2026-89332 (Inclusion of functionality from an untrusted control sphere in
the Kir ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-89268 (QloApps through 1.7.0 renders back-office list filter POST
parameters ...)
TODO: check
CVE-2026-89267 (starlette-admin versions 0.16.1 through 0.17.1 fail to enforce
the sea ...)
@@ -43,109 +43,109 @@ CVE-2026-89267 (starlette-admin versions 0.16.1 through
0.17.1 fail to enforce t
CVE-2026-89266 (stb_vorbis through 1.22 contains a heap buffer overflow in
start_decod ...)
TODO: check
CVE-2026-87919 (The Product XML Feed Manager for WooCommerce WordPress plugin
before ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87918 (The WPBot WordPress plugin before 8.5.7 does not perform any
authoriz ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87916 (The WPBot WordPress plugin before 8.6.0 does not perform any
capabili ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87894 (The Rox Appointment Booking WordPress plugin before 1.2.3
does not pe ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87892 (The Rox Appointment Booking WordPress plugin before 1.2.0
does not ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87891 (The Rox Appointment Booking WordPress plugin before 1.2.0
does not pe ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87888 (The YayPricing WordPress plugin before 3.5.7 does not perform
an auth ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87842 (The Zonify WordPress plugin before 1.0.5 does not perform any
capabil ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87797 (The Sprout Invoices WordPress plugin before 20.8.16 does not
perform ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87759 (The Add User Autocomplete WordPress plugin before 1.2 does not
perform ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87719 (GitLab has remediated an issue in GitLab EE affecting all
versions fro ...)
- TODO: check
+ NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-86790 (The WP Highlight Box WordPress plugin through 1.0 does not
escape some ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-85706 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
- TODO: check
+ NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-85681 (The WP Component WordPress plugin through 2.2.4 does not have
any capa ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84171 (The WP images upload on piclect WordPress plugin through 1.0
does not ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84099 (The wpstorecart WordPress plugin through 5.0.7 does not
prevent direct ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84047 (The Album Cover Finder WordPress plugin through 0.7.0 does not
properl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84025 (The BEAR WordPress plugin before 1.2.2 does not perform
ownership che ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84024 (The BEAR WordPress plugin before 1.2.2 does not verify a CSRF
nonce b ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84023 (The BEAR WordPress plugin before 1.2.2 does not verify a CSRF
nonce o ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-83532 (The Custom Menu Wizard Widget WordPress plugin through 3.3.1
does not ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-82851 (The Masteriyo LMS WordPress plugin before 3.4.1 does not
verify owner ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-82847 (The Masteriyo LMS WordPress plugin before 3.4.1 does not
sanitise and ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-82845 (The Masteriyo LMS WordPress plugin before 3.4.1 does not
prevent user ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-81918 (Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the
Date Form ...)
- TODO: check
+ NOT-FOR-US: Concrete CMS
CVE-2026-81917 (Concrete CMS below 9.5.3 does not apply HTML output escaping
to the fi ...)
- TODO: check
+ NOT-FOR-US: Concrete CMS
CVE-2026-81916 (Concrete CMS before 9.5.3 evaluated the authorization check
for an Exp ...)
- TODO: check
+ NOT-FOR-US: Concrete CMS
CVE-2026-81915 (Concrete CMS below 9.5.3 does not perform an object-level
authorizatio ...)
- TODO: check
+ NOT-FOR-US: Concrete CMS
CVE-2026-81913 (Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to
Open Redir ...)
- TODO: check
+ NOT-FOR-US: Concrete CMS
CVE-2026-81912 (Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request
Forgery ...)
- TODO: check
+ NOT-FOR-US: Concrete CMS
CVE-2026-81911 (Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored
XSS in Bo ...)
- TODO: check
+ NOT-FOR-US: Concrete CMS
CVE-2026-81907 (Concrete CMS 9.5.2 and below is vulnerable to Cross-Site
Request Forge ...)
- TODO: check
+ NOT-FOR-US: Concrete CMS
CVE-2026-81742 (The BE REST Endpoints WordPress plugin through 1.0.0 does not
perform ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-81429 (The Export & Import WPBakery Page Builder WordPress plugin
through 1.0 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-81402 (The DS Ad Rotator WordPress plugin through 0.8 does not
perform any ca ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-81090 (The Gpx2Graphics WordPress plugin through 0.3 does not perform
a CSRF ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-80494 (The Yogeta WP Cloud WordPress plugin through 1.0 does not
validate a u ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-80491 (The SAMO Forms WordPress plugin through 1.0.0 does not
properly saniti ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-79035 (A reflected cross-site scripting (XSS) vulnerability in the
p.rfihub.c ...)
TODO: check
CVE-2026-78547 (Out-of-bounds write vulnerability in Citrix Citrix Workspace
app for W ...)
- TODO: check
+ NOT-FOR-US: Citrix
CVE-2026-78546 (Out-of-bounds read vulnerability in Citirx Workspace app for
Windows. ...)
- TODO: check
+ NOT-FOR-US: Citrix
CVE-2026-78152 (The SureRank SEO WordPress plugin before 1.10.1 does not
exclude user ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77753 (The Temporary Login Without Password WordPress plugin before
1.9.9 doe ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77752 (The Temporary Login Without Password WordPress plugin before
1.9.9 doe ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77705 (The Booking for Appointments and Events Calendar WordPress
plugin bef ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77689 (The Booking for Appointments and Events Calendar WordPress
plugin bef ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77490 (Improper neutralization of input during web page generation
('cross-si ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-77006 (The WebTotem Backups WordPress plugin through 1.0.1 does not
validate ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77005 (The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1
does not va ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75800 (The Frontegg SAML SSO WordPress plugin through 1.0.1 does not
verify t ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-68535 (Concrete CMS Area API's block-create endpoint in versions
9.2.0 to 9.5 ...)
- TODO: check
+ NOT-FOR-US: Concrete CMS
CVE-2026-68526 (Concrete CMS before 9.5.3 did not validate an anti-CSRF token
in the C ...)
- TODO: check
+ NOT-FOR-US: Concrete CMS
CVE-2026-54258 (ZoneMinder is a free, open source closed-circuit television
software a ...)
TODO: check
CVE-2026-54248 (Doco-CD is a GitOps continuous delivery tool that
automatically deploy ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bbf0919e8adc909649f6ef4cadf0ad89cd5d1f29
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bbf0919e8adc909649f6ef4cadf0ad89cd5d1f29
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits