[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Aug 2 08:13:24 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b875c773 by security tracker role at 2026-08-02T07:13:17+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,77 @@
+CVE-2026-9335 (A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrar ...)
+ TODO: check
+CVE-2026-8457 (The WooCommerce - Social Login plugin for WordPress is vulnerable to A ...)
+ TODO: check
+CVE-2026-18573 (A flaw was found in the keycloak-services component of Keycloak, which ...)
+ TODO: check
+CVE-2026-18572 (Keycloak provides authorization services that allow administrators to ...)
+ TODO: check
+CVE-2026-18571 (A flaw was found in the user creation component of Keycloak when Fine- ...)
+ TODO: check
+CVE-2026-18570 (A flaw was found in the full-scope-disabled client-policy executor wit ...)
+ TODO: check
+CVE-2026-18556 (Authentication bypass using an alternate path or channel vulnerability ...)
+ TODO: check
+CVE-2026-18352 (The User Access Manager plugin for WordPress is vulnerable to Director ...)
+ TODO: check
+CVE-2026-17002
+ REJECTED
+CVE-2026-16540 (The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does ...)
+ TODO: check
+CVE-2026-16292 (The Frontend File Manager Plugin WordPress plugin through 23.6 does no ...)
+ TODO: check
+CVE-2026-16291 (The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that ...)
+ TODO: check
+CVE-2026-16285 (The Product Attachment for WooCommerce WordPress plugin before 2.3.3 d ...)
+ TODO: check
+CVE-2026-16273 (The Narrative Publisher WordPress plugin through 1.0.7 does not restri ...)
+ TODO: check
+CVE-2026-16261 (The login-social WordPress plugin through 1.0.4 does not validate pass ...)
+ TODO: check
+CVE-2026-16256 (The POUCO Import Users WordPress plugin through 1.0.0 does not perform ...)
+ TODO: check
+CVE-2026-16064 (The Event Booking Manager for WooCommerce WordPress plugin before 5.3 ...)
+ TODO: check
+CVE-2026-16063 (The Event Booking Manager for WooCommerce WordPress plugin before 5.3 ...)
+ TODO: check
+CVE-2026-16062 (The Event Booking Manager for WooCommerce WordPress plugin before 5.3 ...)
+ TODO: check
+CVE-2026-16042 (The LWS Optimize WordPress plugin before 3.4 does not perform a capab ...)
+ TODO: check
+CVE-2026-15939 (The Simple Restrict WordPress plugin before 1.2.9 does not enforce its ...)
+ TODO: check
+CVE-2026-15385 (The RT Mega Menu WordPress plugin before 1.5.2 does not perform a cap ...)
+ TODO: check
+CVE-2026-15248 (The Meta Box WordPress plugin before 5.13.1 does not verify that a use ...)
+ TODO: check
+CVE-2026-15241 (The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not ...)
+ TODO: check
+CVE-2026-15236 (The Gallery for Google Photos WordPress plugin before 1.2.1 does not ...)
+ TODO: check
+CVE-2026-15206 (The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile ...)
+ TODO: check
+CVE-2026-15151 (The Five Star Restaurant Reservations WordPress plugin before 2.7.23 ...)
+ TODO: check
+CVE-2026-14938 (The FluentBoards WordPress plugin before 1.95.3 does not verify that ...)
+ TODO: check
+CVE-2026-14920 (## Summary)
+ TODO: check
+CVE-2026-14864 (The JetEngine WordPress plugin before 3.8.12 does not escape a post me ...)
+ TODO: check
+CVE-2026-14841 (The King Addons for Elementor WordPress plugin before 51.1.76 does no ...)
+ TODO: check
+CVE-2026-14817 (The Element Pack Addons for Elementor WordPress plugin before 8.7.13 ...)
+ TODO: check
+CVE-2026-13389 (The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not pe ...)
+ TODO: check
+CVE-2026-13339 (The CubeWP Framework plugin for WordPress is vulnerable to Directory T ...)
+ TODO: check
+CVE-2026-12586 (The Lenxel WP WordPress theme through 1.0.31 does not perform any auth ...)
+ TODO: check
+CVE-2026-11872 (The Clever Mega Menu for Visual Composer WordPress plugin through 1.0. ...)
+ TODO: check
+CVE-2025-15675 (The Charitable WordPress plugin before 1.8.5.3 does not sanitise and ...)
+ TODO: check
CVE-2026-6453 (The CubeWP Framework plugin for WordPress is vulnerable to SQL Injecti ...)
NOT-FOR-US: WordPress plugin
CVE-2026-67355 (guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only co ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b875c773a5c59dda4cb9d52060501f4362bf22b6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b875c773a5c59dda4cb9d52060501f4362bf22b6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260802/47636d21/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list