Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
bbf0919e by security tracker role at 2026-09-12T07:14:01+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -35,7 +35,7 @@ CVE-2026-90444 (A file-transfer interface that requires valid 
credentials accept
 CVE-2026-90443 (A web interface reflects a portion of the request URL into a 
script co ...)
        TODO: check
 CVE-2026-89332 (Inclusion of functionality from an untrusted control sphere in 
the Kir ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-89268 (QloApps through 1.7.0 renders back-office list filter POST 
parameters  ...)
        TODO: check
 CVE-2026-89267 (starlette-admin versions 0.16.1 through 0.17.1 fail to enforce 
the sea ...)
@@ -43,109 +43,109 @@ CVE-2026-89267 (starlette-admin versions 0.16.1 through 
0.17.1 fail to enforce t
 CVE-2026-89266 (stb_vorbis through 1.22 contains a heap buffer overflow in 
start_decod ...)
        TODO: check
 CVE-2026-87919 (The Product XML Feed Manager for WooCommerce  WordPress plugin 
before  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-87918 (The WPBot  WordPress plugin before 8.5.7 does not perform any 
authoriz ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-87916 (The WPBot  WordPress plugin before 8.6.0 does not perform any 
capabili ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-87894 (The Rox Appointment Booking  WordPress plugin before 1.2.3 
does not pe ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-87892 (The Rox Appointment Booking  WordPress plugin before 1.2.0 
does not ve ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-87891 (The Rox Appointment Booking  WordPress plugin before 1.2.0 
does not pe ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-87888 (The YayPricing  WordPress plugin before 3.5.7 does not perform 
an auth ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-87842 (The Zonify  WordPress plugin before 1.0.5 does not perform any 
capabil ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-87797 (The Sprout Invoices  WordPress plugin before 20.8.16 does not 
perform  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-87759 (The Add User Autocomplete WordPress plugin before 1.2 does not 
perform ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-87719 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-86790 (The WP Highlight Box WordPress plugin through 1.0 does not 
escape some ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-85706 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-85681 (The WP Component WordPress plugin through 2.2.4 does not have 
any capa ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84171 (The WP images upload on piclect WordPress plugin through 1.0 
does not  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84099 (The wpstorecart WordPress plugin through 5.0.7 does not 
prevent direct ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84047 (The Album Cover Finder WordPress plugin through 0.7.0 does not 
properl ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84025 (The BEAR  WordPress plugin before 1.2.2 does not perform 
ownership che ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84024 (The BEAR  WordPress plugin before 1.2.2 does not verify a CSRF 
nonce b ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84023 (The BEAR  WordPress plugin before 1.2.2 does not verify a CSRF 
nonce o ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-83532 (The Custom Menu Wizard Widget WordPress plugin through 3.3.1 
does not  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-82851 (The Masteriyo LMS  WordPress plugin before 3.4.1 does not 
verify owner ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-82847 (The Masteriyo LMS  WordPress plugin before 3.4.1 does not 
sanitise and ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-82845 (The Masteriyo LMS  WordPress plugin before 3.4.1 does not 
prevent user ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-81918 (Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the 
Date Form ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-81917 (Concrete CMS below 9.5.3 does not apply HTML output escaping 
to the fi ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-81916 (Concrete CMS before 9.5.3 evaluated the authorization check 
for an Exp ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-81915 (Concrete CMS below 9.5.3 does not perform an object-level 
authorizatio ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-81913 (Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to 
Open Redir ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-81912 (Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request 
Forgery  ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-81911 (Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored 
XSS in Bo ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-81907 (Concrete CMS 9.5.2 and below is vulnerable to Cross-Site 
Request Forge ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-81742 (The BE REST Endpoints WordPress plugin through 1.0.0 does not 
perform  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-81429 (The Export & Import WPBakery Page Builder WordPress plugin 
through 1.0 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-81402 (The DS Ad Rotator WordPress plugin through 0.8 does not 
perform any ca ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-81090 (The Gpx2Graphics WordPress plugin through 0.3 does not perform 
a CSRF  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-80494 (The Yogeta WP Cloud WordPress plugin through 1.0 does not 
validate a u ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-80491 (The SAMO Forms WordPress plugin through 1.0.0 does not 
properly saniti ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-79035 (A reflected cross-site scripting (XSS) vulnerability in the 
p.rfihub.c ...)
        TODO: check
 CVE-2026-78547 (Out-of-bounds write vulnerability in Citrix Citrix Workspace 
app for W ...)
-       TODO: check
+       NOT-FOR-US: Citrix
 CVE-2026-78546 (Out-of-bounds read vulnerability in Citirx Workspace app for 
Windows.  ...)
-       TODO: check
+       NOT-FOR-US: Citrix
 CVE-2026-78152 (The SureRank SEO  WordPress plugin before 1.10.1 does not 
exclude user ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77753 (The Temporary Login Without Password WordPress plugin before 
1.9.9 doe ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77752 (The Temporary Login Without Password WordPress plugin before 
1.9.9 doe ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77705 (The Booking for Appointments and Events Calendar  WordPress 
plugin bef ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77689 (The Booking for Appointments and Events Calendar  WordPress 
plugin bef ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77490 (Improper neutralization of input during web page generation 
('cross-si ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-77006 (The WebTotem Backups WordPress plugin through 1.0.1 does not 
validate  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77005 (The CODE MONKEYS PROPOSALS  WordPress plugin through 1.0.1 
does not va ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-75800 (The Frontegg SAML SSO WordPress plugin through 1.0.1 does not 
verify t ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-68535 (Concrete CMS Area API's block-create endpoint in versions 
9.2.0 to 9.5 ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-68526 (Concrete CMS before 9.5.3 did not validate an anti-CSRF token 
in the C ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-54258 (ZoneMinder is a free, open source closed-circuit television 
software a ...)
        TODO: check
 CVE-2026-54248 (Doco-CD is a GitOps continuous delivery tool that 
automatically deploy ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bbf0919e8adc909649f6ef4cadf0ad89cd5d1f29

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bbf0919e8adc909649f6ef4cadf0ad89cd5d1f29
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to