[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 1 20:14:49 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e0993811 by security tracker role at 2026-08-01T19:14:43+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
 CVE-2026-6453 (The CubeWP Framework plugin for WordPress is vulnerable to SQL Injecti ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-67355 (guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only co ...)
 	TODO: check
 CVE-2026-67354 (guzzlehttp/guzzle versions before 7.15.1 contain an information disclo ...)
@@ -135,73 +135,73 @@ CVE-2026-55733 (Allocation of Resources Without Limits or Throttling in ueberaut
 CVE-2026-54894 (Allocation of Resources Without Limits or Throttling in ueberauth guar ...)
 	TODO: check
 CVE-2026-2916 (The Jeg Kit for Elementor plugin for WordPress is vulnerable to Sensit ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-2411 (Zephyr's Bluetooth host declares a GATT characteristic as two consecut ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-18435 (The Kadence Blocks \u2014 Page Builder Toolkit for Gutenberg Editor pl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18344 (The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18062 (The Kadence Blocks \u2014 Page Builder Toolkit for Gutenberg Editor pl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18059 (The PixelYourSite \u2013 Your smart PIXEL (TAG) & API Manager plugin f ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-17605 (The Payment forms, Buy now buttons, and Invoicing System | GetPaid plu ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-17580 (The Advanced Views \u2013 Display Custom Fields (ACF, Pods, MetaBox),  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-17571 (The Fluent Forms \u2013 Customizable Contact Forms, Survey, Quiz, & Co ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-17555 (The WPvivid Backup & Migration plugin for WordPress is vulnerable to S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16685 (The Download Manager plugin for WordPress is vulnerable to Stored Cros ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16684 (The Easy Property Listings plugin for WordPress is vulnerable to Store ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16635 (The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escal ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16614 (The GSheetConnector \u2013 CF7 Google Sheets Connector with Real-Time  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16144 (The Kali Forms \u2014 Contact Form & Drag-and-Drop Builder plugin for  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16091 (The GamiPress \u2013 Gamification plugin to reward points, achievement ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16090 (The GamiPress \u2013 Gamification plugin to reward points, achievement ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16087 (The Icegram Engage \u2013 Popups, Optins, CTAs & Lead Generation plugi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15988 (The AI Engine \u2013 The Chatbot, AI Framework & MCP for WordPress plu ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15964 (The Single Sign On For TNG plugin for WordPress is vulnerable to Authe ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15951 (The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15950 (The Cozy Blocks \u2013 Page Builder for Gutenberg Editor & FSE with 60 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15662 (The Advanced Woo Labels \u2013 Product Labels & Badges for WooCommerce ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15649 (The Powerkit \u2013 Supercharge your WordPress Site plugin for WordPre ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15645 (The Powerkit \u2013 Supercharge your WordPress Site plugin for WordPre ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15644 (The Powerkit \u2013 Supercharge your WordPress Site plugin for WordPre ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15601 (The Kirki \u2013 Freeform Page Builder, Website Builder & Customizer p ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15450 (The Nex Forms \u2013 Ultimate Form Builder \u2013 Lite plugin for Word ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15052 (The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Build ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15018 (The Database Collation Fix plugin for WordPress is vulnerable to time- ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13458 (The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross- ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11995 (The Gutena Forms \u2013 Contact Form, Survey Form, Feedback Form, Book ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-10782 (The RealHomes Memberships plugin for WordPress is vulnerable to author ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-10773 (The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/ ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-10772
 	REJECTED
 CVE-2025-71404 (better-auth versions after v0.0.2 and before 1.1.16 contain a reflecte ...)
@@ -211,9 +211,9 @@ CVE-2025-71403 (better-auth versions before 1.1.20 contain a bypass vulnerabilit
 CVE-2025-71402 (better-auth versions greater than 1.3.34 and before 1.4.0 contain a vu ...)
 	TODO: check
 CVE-2025-14469 (The Theme Editor plugin for WordPress is vulnerable to Cross-Site Requ ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-14073 (The WooCommerce PayPal Payments plugin for WordPress is vulnerable to  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18536 (Data::Entropy versions before 0.010 for Perl read remote entropy sourc ...)
 	- libdata-entropy-perl <unfixed> (bug #1143264)
 	[trixie] - libdata-entropy-perl <no-dsa> (Minor issue; module is deprecated in favour of better options)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e09938111d9b4ee36cf352d565eac4fdd01deb8c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e09938111d9b4ee36cf352d565eac4fdd01deb8c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260801/caedbfe3/attachment.htm>


More information about the debian-security-tracker-commits mailing list