[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 1 08:13:32 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
355418ac by security tracker role at 2026-08-01T07:13:25+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2026-9044 (An OS command injection vulnerability exists in the VPN module of TP-L ...)
-	TODO: check
+	NOT-FOR-US: TPLink
 CVE-2026-7623 (The SureForms \u2013 Contact Form, Payment Form & Other Custom Form Bu ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-68771 (ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in th ...)
 	TODO: check
 CVE-2026-68770 (sentence-transformers contains a security control bypass vulnerability ...)
@@ -55,7 +55,7 @@ CVE-2026-45330 (Decidim is a participatory democracy framework. Prior to 0.30.9,
 CVE-2026-45086 (Decidim is a participatory democracy framework. From 0.31.1 before 0.3 ...)
 	TODO: check
 CVE-2026-3141 (The FormGent plugin for WordPress is vulnerable to unauthorized arbitr ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-38713 (TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300  ...)
 	TODO: check
 CVE-2026-38711 (TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300  ...)
@@ -65,81 +65,81 @@ CVE-2026-38710 (TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a c
 CVE-2026-38708 (TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300  ...)
 	TODO: check
 CVE-2026-34641 (Premiere Pro is affected by an out-of-bounds write vulnerability that  ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-18394 (Incorrect authorization in the http_request tool in Strands Agents Too ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-15932 (The Support Genix  WordPress plugin before 1.4.48 does not prevent dir ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15414 (The Subscriptions for WooCommerce plugin for WordPress is vulnerable t ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15403 (The Pinpoint Booking System \u2013 Version 2 plugin for WordPress is v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15368 (The User Profile Builder  WordPress plugin before 3.16.4 does not corr ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15262 (The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does n ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15244 (The HUSKY  WordPress plugin before 1.4.1 does not sanitize a stored se ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15234 (The Codeless Page Builder WordPress plugin through 1.1.4 does not sani ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15006 (The Bit integrations \u2013 Form Integration, Webhook, Spreadsheets, C ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14840 (The YOP Poll WordPress plugin before 7.0.6 does not validate the conne ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14839 (The Mapster WP Maps WordPress plugin before 1.24.0 does not perform an ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14836 (The Login & Register Forms  WordPress plugin before 3.2.5 does not pro ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14823 (The Event Tickets and Registration WordPress plugin before 5.29.0.1 do ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14822 (The Event Tickets and Registration WordPress plugin before 5.29.0.1 do ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14596 (The DynamicKit for Elementor WordPress plugin before 1.0.3 does not va ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14561 (The Authora : Easy login with mobile number WordPress plugin before 1. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14315 (The Pixel Tag Manager for WooCommerce  WordPress plugin before 2.2.1 d ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14309 (The Chat On Desk Order Notifications  WordPress plugin before 1.0.9 do ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14292 (The Download Manager WordPress plugin before 3.3.66 does not properly  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14214 (The Booking for Appointments and Events Calendar  WordPress plugin bef ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14197 (The Fluent Support  WordPress plugin before 2.3.1 does not perform a p ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14195 (The Brizy  WordPress plugin before 2.8.18 does not properly verify aut ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13729 (The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not p ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13725 (The Dynamic Pricing With Discount Rules for WooCommerce WordPress plug ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13604 (The Pixelavo  WordPress plugin before 1.5.4 registers an unauthenticat ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13596 (The Participants Database WordPress plugin before 2.7.8.4 does not pro ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13362 (The SendPulse Email Marketing Newsletter plugin for WordPress is vulne ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13329 (The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13158 (The Everest Toolkit WordPress plugin through 1.2.3 does not validate t ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13157 (The  Demo Import WordPress plugin through 1.1.3 does not validate the  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12966 (The Direct Payments for WooCommerce  WordPress plugin before 2.5.3 doe ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12696 (The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and e ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11882 (The Builderall for WordPress plugin before 3.0.2 does not bind the sta ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-10827 (The Spectra Legacy  WordPress plugin before 2.20.0 does not validate o ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-69948 (SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL  ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2025-69946 (SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL  ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2025-15669 (The Bit Form  WordPress plugin before 3.1.4 does not sanitise one of i ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-56818
 	- netty <unfixed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2507476



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/355418ac25f22a8028d4d122ca0d25a9fe127391

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/355418ac25f22a8028d4d122ca0d25a9fe127391
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260801/02cee27b/attachment.htm>


More information about the debian-security-tracker-commits mailing list