[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 5 08:13:26 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
71faffc8 by security tracker role at 2026-08-05T07:13:19+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,11 +1,11 @@
CVE-2026-9273 (The Membership Plugin \u2013 Kadence Memberships plugin for WordPress ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-8790 (The Football Pool plugin for WordPress is vulnerable to Reflected Cros ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-8761 (The Dokan plugin for WordPress is vulnerable to Privilege Escalation i ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-7753 (The Cost Calculator Builder plugin for WordPress is vulnerable to unau ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-71201 (In OpenStack Ironic through 38.0.0, a project reader that makes a craf ...)
TODO: check
CVE-2026-71192 (In OpenStack Swift through 2.38.0, the S3API middleware does not sanit ...)
@@ -71,13 +71,13 @@ CVE-2026-70480 (Open WebUI is an extensible, feature-rich, and user-friendly sel
CVE-2026-70479 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
TODO: check
CVE-2026-70478 (Flowise is a drag & drop user interface to build a customized large la ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-70477 (Flowise is a drag & drop user interface to build a customized large la ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-70476 (Flowise is a drag & drop user interface to build a customized large la ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-70475 (Flowise is a drag & drop user interface to build a customized large la ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-70375 (HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerabi ...)
TODO: check
CVE-2026-70374 (HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerabi ...)
@@ -155,7 +155,7 @@ CVE-2026-66257 (A pre-authentication attacker could leverage unbounded symbol va
CVE-2026-65986 (CVAT is an open source interactive video and image annotation tool for ...)
TODO: check
CVE-2026-5062 (The PrettyLinks \u2013 Affiliate Links, Link Branding, Link Tracking, ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-54020 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
TODO: check
CVE-2026-52370 (A reflected cross-site scripting (XSS) vulnerability in the Forum post ...)
@@ -167,7 +167,7 @@ CVE-2026-51400 (An issue in Vim Project v9.2.0389 and earlier allows a local att
CVE-2026-51144 (Cross Site Scripting vulnerability in Soliton Systems MailZen Manageme ...)
TODO: check
CVE-2026-49004 (The built-in PostgreSQL service on the mobile device suffers from misc ...)
- TODO: check
+ NOT-FOR-US: ZTE
CVE-2026-48154 (GoRest is a Golang starter kit built with the Gin framework for protot ...)
TODO: check
CVE-2026-47682 (CVAT is an open source interactive video and image annotation tool for ...)
@@ -189,7 +189,7 @@ CVE-2026-45100 (OpenSIPS is a Session Initiation Protocol (SIP) server implement
CVE-2026-45084 (OpenSIPS is a Session Initiation Protocol (SIP) server implementation. ...)
TODO: check
CVE-2026-18907 (Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1. ...)
- TODO: check
+ NOT-FOR-US: TECNO Mobile
CVE-2026-18903 (A vulnerability was determined in yeqifu warehouse up to aaf29962ba407 ...)
TODO: check
CVE-2026-18902 (A vulnerability was detected in H3C NX15 V100R017. Affected by this vu ...)
@@ -207,7 +207,7 @@ CVE-2026-18896 (A vulnerability was determined in lavkush-maurya Student-Registr
CVE-2026-18895 (A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-18053 ...)
TODO: check
CVE-2026-18859 (A vulnerability was identified in ESAFENET CDG up to 20260615. Affecte ...)
- TODO: check
+ NOT-FOR-US: ESAFENET
CVE-2026-18856 (A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This ...)
TODO: check
CVE-2026-18854 (A vulnerability has been found in Shandong Hoteam PDM Product Data Man ...)
@@ -235,77 +235,77 @@ CVE-2026-18811 (A vulnerability was detected in H3C NX15 V100R017. The affected
CVE-2026-18810 (A security vulnerability has been detected in H3C NX15 V100R017. Impac ...)
TODO: check
CVE-2026-18657 (An uncontrolled search path element in Kiro CLI before version 2.10.0 ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-18656 (An uncontrolled search path element in Kiro IDE before version 1.0.228 ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-18322 (The Smart Popup by Supsystic plugin for WordPress is vulnerable to Pri ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18103 (A flaw was found in dhcp-server. A remote attacker with network access ...)
TODO: check
CVE-2026-17515 (The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16993 (The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16981 (The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16968 (The GeoDirectory WordPress plugin before 2.8.168 does not restrict a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16942 (The WP Custom HTML Page WordPress plugin through 0.6.2 does not saniti ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16940 (The Custom Fields WordPress plugin before 1.5.1 does not validate a us ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16793 (An improper neutralization of special elements used in an operating sy ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-16792 (An improper certificate validation vulnerability was reported in multi ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-16791 (A temporary file creation vulnerability in the Linux version of Lenovo ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-16746 (The MultiVendorX WordPress plugin before 5.0.11 does not verify that ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16736 (The User Registration & Membership WordPress plugin before 5.2.6 does ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16613 (The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16605 (The MultiVendorX WordPress plugin before 5.0.11 does not verify that ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16604 (The Passster WordPress plugin before 4.3.6 outputs password-protected ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16603 (The Passster WordPress plugin before 4.3.6 does not enforce its categ ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16602 (The Passster WordPress plugin before 4.3.6 does not perform a post-st ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16583 (The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16573 (The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploa ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16561 (The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perfo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16143 (The VikRentItems \u2013 Flexible Rental Management System plugin for W ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16055 (The Contest Gallery WordPress plugin before 30.0.7 does not route its ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16036 (The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the se ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15941 (The plugin provides an Admin Search page that allows users with the `e ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15918 (VikAppointments Service Booking Calendar wordpress plugin is vulnerabl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15372 (The WP 2FA WordPress plugin before 4.1.0 does not validate the second ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15360 (The Ajax Load More WordPress plugin before 8.0.1 does not properly sa ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15230 (The YayPricing WordPress plugin before 3.5.7 does not perform capabil ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15210 (The OTP Login With Phone Number, OTP Verification WordPress plugin bef ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14553 (The zportals WordPress plugin before 6.3.4 does not properly validate ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13227 (An Improper Authorization vulnerability exists in ERPNext version <v16 ...)
TODO: check
CVE-2026-11421 (The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Supp ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2025-15677 (The GeoDirectory WordPress plugin before 2.8.110 does not sanitise an ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-42170
- gimp 3.2.4-1
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16161
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71faffc886c11e78f18912074dfa19993eeda64d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71faffc886c11e78f18912074dfa19993eeda64d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/b1fc6cb7/attachment.htm>
More information about the debian-security-tracker-commits
mailing list