[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 5 20:14:59 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
3e2f532f by security tracker role at 2026-08-05T19:14:53+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,73 +1,73 @@
 CVE-2026-9205 (IBM Langflow OSS contains a weak cryptographic key derivation vulnerab ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-9203 (A server-side request forgery vulnerability in Progress MarkLogic Serv ...)
-	TODO: check
+	NOT-FOR-US: Progress Software
 CVE-2026-9201 (IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-9196 (IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-9195 (A cross-site scripting vulnerability in the Query Console of Progress  ...)
-	TODO: check
+	NOT-FOR-US: Progress Software
 CVE-2026-9193 (An improper privilege management vulnerability in the Hadoop integrati ...)
-	TODO: check
+	NOT-FOR-US: Progress Software
 CVE-2026-9192 (An authentication bypass vulnerability in the ODBC App Server of Progr ...)
-	TODO: check
+	NOT-FOR-US: Progress Software
 CVE-2026-9190 (An HTTP request smuggling vulnerability in the HTTP App Server of Prog ...)
-	TODO: check
+	NOT-FOR-US: Progress Software
 CVE-2026-9130 (IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-9081 (IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contai ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-9077 (IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authentic ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-8709 (An improper privilege management vulnerability in the REST API documen ...)
-	TODO: check
+	NOT-FOR-US: Progress Software
 CVE-2026-8478 (IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-8470 (IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 thr ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-8446 (IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-8400 (IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Applic ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-8183 (IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 thr ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-8182 (IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on th ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-8029 (The ZTE Smart Life app contains an SQL injection vulnerability that al ...)
-	TODO: check
+	NOT-FOR-US: ZTE
 CVE-2026-7869 (IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-7726 (The Layouts for WPBakery plugin for WordPress is vulnerable to unautho ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-7693 (The Backup Migration plugin for WordPress is vulnerable to OS Command  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-7658 (IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the u ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-7657 (IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-7646 (IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary f ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-7557 (An improper verification of cryptographic signature vulnerability in t ...)
-	TODO: check
+	NOT-FOR-US: Progress Software
 CVE-2026-7529 (The wiseCampaign \u2013 WooCommerce Conversions Made Easy plugin for W ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-7520 (The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-7456 (The Udimi Tools plugin for WordPress is vulnerable to unauthorized mod ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-7444 (The Search Analytics for WP plugin for WordPress is vulnerable to Cros ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-7441 (The Simple Yearly Archive plugin for WordPress is vulnerable to Stored ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-7329 (An improper privilege management vulnerability in the SQL, SPARQL, and ...)
-	TODO: check
+	NOT-FOR-US: Progress Software
 CVE-2026-7327 (An improper privilege management vulnerability in the REST API documen ...)
-	TODO: check
+	NOT-FOR-US: Progress Software
 CVE-2026-7326 (A cross-site request forgery vulnerability in the Admin UI of Progress ...)
-	TODO: check
+	NOT-FOR-US: Progress Software
 CVE-2026-7105 (The Xpro Addons plugin for WordPress is vulnerable to unauthorized cre ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-71294 (Cotonti CMS's Comments plugin deserializes user-supplied data without  ...)
 	TODO: check
 CVE-2026-71293 (Statamic CMS's user-augmentation resolver, AugmentedUser::get() in src ...)
@@ -203,7 +203,7 @@ CVE-2026-71213 (Typemill's login endpoint (POST /tm/login, ControllerWebAuth::lo
 CVE-2026-71212 (xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line in ...)
 	TODO: check
 CVE-2026-71211 (MLflow's AI Gateway accepts an auth_config.api_base value when creatin ...)
-	TODO: check
+	NOT-FOR-US: mlflow
 CVE-2026-71210 (Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport ...)
 	TODO: check
 CVE-2026-71209 (audiobookshelf's authentication-exemption check (server/routers/Auth.j ...)
@@ -259,51 +259,51 @@ CVE-2026-70596 (Ghost is a Node.js content management system. From 4.9.0 until 6
 CVE-2026-70595 (Ghost is a Node.js content management system. From 6.26.0 until 6.54.1 ...)
 	TODO: check
 CVE-2026-70448 (Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML p ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70447 (Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and ear ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70446 (Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlie ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70445 (Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and e ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70444 (A missing permission check in Jenkins Violation Comments to GitLab Plu ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70443 (Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70442 (Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70441 (Jenkins Summary Display Plugin 1.15 and earlier does not escape the jo ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70440 (Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70439 (Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform  ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70438 (A missing permission check in Jenkins Parameterized Remote Trigger Plu ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70437 (Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 a ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70436 (Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not p ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70435 (A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and ea ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70434 (A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manag ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70433 (Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earl ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70432 (A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob  ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70431 (Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groov ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70430 (Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict t ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70429 (Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insens ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70428 (Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifi ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70427 (Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely han ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70426 (In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c99 ...)
-	TODO: check
+	NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-70378 (imagecli's `carve <ratio>` pipeline operation (Carve::apply() in src/i ...)
 	TODO: check
 CVE-2026-70377 (imagecli's `scale <ratio>` pipeline operation (Scale::apply() in src/i ...)
@@ -311,25 +311,25 @@ CVE-2026-70377 (imagecli's `scale <ratio>` pipeline operation (Scale::apply() in
 CVE-2026-70376 (Pluck CMS's admin panel relies solely on a Referer-header comparison ( ...)
 	TODO: check
 CVE-2026-6972 (The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-6639 (The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-6627 (The WPFormify \u2013 Stripe Payments with Form and Checkout plugin for ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-6147 (The LightSync Pro plugin for WordPress is vulnerable to arbitrary file ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-6079 (The Material Dashboard plugin for WordPress is vulnerable to unauthori ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-6020 (The ShopLentor plugin for WordPress is vulnerable to arbitrary functio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-67623 (Mistral Vibe before 2.23.3 contains a remote code execution vulnerabil ...)
 	TODO: check
 CVE-2026-66747 (Zbtlink router firmware ships an embedded remote-control implant, ENDL ...)
 	TODO: check
 CVE-2026-63457 (A potential denial of service vulnerability exists in HPE Integrated L ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-61891 (In Eclipse Theia versions up to and including 1.73.1, the `@theia/file ...)
-	TODO: check
+	NOT-FOR-US: Eclipse
 CVE-2026-61486 (** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerabil ...)
 	TODO: check
 CVE-2026-61485 (** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size  ...)
@@ -339,25 +339,25 @@ CVE-2026-61484 (** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Dat
 CVE-2026-61483 (** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability i ...)
 	TODO: check
 CVE-2026-60053 (Insufficient Session Expiration vulnerability in Apache Answer.  This  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-60023 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-60009 (In Eclipse Theia versions up to and including 1.73.1, the `@theia/file ...)
-	TODO: check
+	NOT-FOR-US: Eclipse
 CVE-2026-5651 (The Askeet plugin for WordPress is vulnerable to SQL Injection via the ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-5581 (The Multi Uploader for Gravity Forms plugin for WordPress is vulnerabl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-5116 (The Contact Form 7 \u2013 Dynamic Text Extension plugin for WordPress  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-5108 (The Super Progressive Web Apps plugin for WordPress is vulnerable to S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-59675 (When API audit logging is enabled, the middleware reads the entire HTT ...)
 	TODO: check
 CVE-2026-55998 (The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster ...)
 	TODO: check
 CVE-2026-55997 (Rancher issues long-lived registration tokens to authenticate nodes an ...)
-	TODO: check
+	NOT-FOR-US: SUSE
 CVE-2026-55996 (A denial-of-service vulnerability was identified in multiple TLS liste ...)
 	TODO: check
 CVE-2026-55747 (The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow  ...)
@@ -371,17 +371,17 @@ CVE-2026-54416 (Pluck CMS through 4.7.21 restricts dangerous file uploads in its
 CVE-2026-53992 (ProjectSend r2029 contains a reflected cross-site scripting vulnerabil ...)
 	TODO: check
 CVE-2026-50749 (Improper Authorization vulnerability in Apache Answer.  This issue aff ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-4431 (The Easy Post Submission plugin for WordPress is vulnerable to unautho ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-49331 (A flaw was found in openshift/oauth-proxy. On paths configured to bypa ...)
 	TODO: check
 CVE-2026-48912 (Improper Input Validation vulnerability in Apache Answer.  This issue  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-48911 (Insufficient Verification of Data Authenticity vulnerability in Apache ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-48834 (Improper Handling of Length Parameter Inconsistency vulnerability in A ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-48168 (PraisonAI is a multi-agent teams system. In versions prior to 4.6.40,  ...)
 	TODO: check
 CVE-2026-46581 (In Eclipse Mojarra versions 2.3 and following, URL handing in `Default ...)
@@ -401,11 +401,11 @@ CVE-2026-20313 (As part of Cisco's ongoing commitment to proactive security and
 CVE-2026-20312 (As part of Cisco's ongoing commitment to proactive security and produc ...)
 	TODO: check
 CVE-2026-20311 (A vulnerability in the web-based management interface of Cisco IOS XE  ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20310 (As part of Cisco's ongoing commitment to proactive security and produc ...)
 	TODO: check
 CVE-2026-20308 (A vulnerability in the web-based management interface of Cisco IOS XE  ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20304 (As part of Cisco's ongoing commitment to proactive security and produc ...)
 	TODO: check
 CVE-2026-20303 (As part of Cisco's ongoing commitment to proactive security and produc ...)
@@ -413,33 +413,33 @@ CVE-2026-20303 (As part of Cisco's ongoing commitment to proactive security and
 CVE-2026-20301 (A vulnerability in the Extensible Messaging Client Protocol (XMCP), al ...)
 	TODO: check
 CVE-2026-20294 (A vulnerability in the web-based management interface of Cisco Catalys ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20289 (A vulnerability in the logging subsystem of Cisco RoomOS could allow a ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20288 (A vulnerability in the web-based management interface of Cisco IMC cou ...)
 	TODO: check
 CVE-2026-20273 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20272 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20271 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20270 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20269 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20268 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20267 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20263 (A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feat ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20200 (A vulnerability in the web-based management interface of Cisco IMC cou ...)
 	TODO: check
 CVE-2026-20198 (A vulnerability in the web-based management interface of Cisco Integra ...)
 	TODO: check
 CVE-2026-20124 (A vulnerability in the Simple Network Management Protocol (SNMP) subsy ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20028 (A vulnerability in the network driver of Cisco Terminal Service (TS) A ...)
 	TODO: check
 CVE-2026-18933 (The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affe ...)
@@ -447,37 +447,37 @@ CVE-2026-18933 (The wp-downloadmanager WordPress plugin, in version 1.68.11 (als
 CVE-2026-18927 (A vulnerability was determined in imranrisal-dev Student-Management-Sy ...)
 	TODO: check
 CVE-2026-18881 (The TableOn \u2013 WordPress Posts Table Filterable plugin for WordPre ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18531 (IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote at ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18485 (There is a local privilege escalation vulnerability recently discovere ...)
-	TODO: check
+	NOT-FOR-US: National Instruments
 CVE-2026-17633 (IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticat ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17632 (IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticat ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17630 (IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17626 (IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenti ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17625 (IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 thr ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17624 (IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 thr ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17623 (IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticat ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17617 (IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to S ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17613 (Penpot\u2019s ::import-binfile RPC command lacks authorization on the  ...)
 	TODO: check
 CVE-2026-17578 (Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enfor ...)
 	TODO: check
 CVE-2026-17532 (The Seraphinite Accelerator plugin for WordPress is vulnerable to Refl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-17506 (The Independent Analytics plugin for WordPress is vulnerable to Stored ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-17505 (The Translate Multilingual sites \u2013 TranslatePress plugin for Word ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16443 (A flaw was found in the SAML metadata import functionality of the keyc ...)
 	TODO: check
 CVE-2026-16442 (A flaw was found in the SAML broker component of Keycloak, which is us ...)
@@ -491,9 +491,9 @@ CVE-2026-16071 (A flaw was found in the LDAP storage provider of Keycloak, which
 CVE-2026-16022 (@oblique/cli 15.4.0 contains an OS command injection vulnerability in  ...)
 	TODO: check
 CVE-2026-15979 (The Content Egg \u2013 Affiliate Product Importer & Price Comparison p ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15656 (IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-15587 (Improper Privilege Management in Google SecOps (Chronicle SOAR) versio ...)
 	TODO: check
 CVE-2026-15573 (A flaw was found in Keycloak's Authorization Services. The component r ...)
@@ -501,51 +501,51 @@ CVE-2026-15573 (A flaw was found in Keycloak's Authorization Services. The compo
 CVE-2026-15572 (A flaw was found in Keycloak's Dynamic Client Registration (DCR) secur ...)
 	TODO: check
 CVE-2026-15452 (The Smash Balloon Social Photo Feed \u2013 Easy Social Feeds Plugin pl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15281 (The User Access Manager plugin for WordPress is vulnerable to Second-O ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14587 (Neo4j's Bolt modern handshake decoder treats an overlong capability bi ...)
 	TODO: check
 CVE-2026-14574 (In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `Pr ...)
-	TODO: check
+	NOT-FOR-US: Eclipse
 CVE-2026-14304 (In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 ( ...)
 	TODO: check
 CVE-2026-13477 (IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Inte ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12762 (IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12730 (IBM Business Automation Workflow containers and traditional 26.0.0, 25 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-12609 (In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@ ...)
-	TODO: check
+	NOT-FOR-US: Eclipse
 CVE-2026-12410 (Link following vulnerability in the Uninstaller component in CCleaner  ...)
 	TODO: check
 CVE-2026-12000 (The Page and Post Restriction plugin for WordPress is vulnerable to Se ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11977 (The WP Post Author \u2013 Author Box, Multiple Authors, Guest Authors  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11969 (The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11920 (The JoomSport \u2013 for Sports: Team & League, Football, Hockey & mor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11454 (The Groundhogg \u2014 CRM, Newsletters, and Marketing Automation plugi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-10716 (Directus contains an authenticated SQL injection vulnerability in the  ...)
-	TODO: check
+	NOT-FOR-US: Directus
 CVE-2026-10547 (IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate owner ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-10128 (IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can e ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-10090 (A flaw was found in the Application Subscription controller (multiclus ...)
 	TODO: check
 CVE-2026-10059 (A flaw was found in the Multicluster Engine for Kubernetes ClusterCura ...)
 	TODO: check
 CVE-2026-10025 (IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Inte ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-0931 (Denial-of-service vulnerability in M-Files Server versions before26.5. ...)
-	TODO: check
+	NOT-FOR-US: M-Files
 CVE-2026-0516 (A improper neutralization of HTTP Headers for Scripting Syntax vulnera ...)
-	TODO: check
+	NOT-FOR-US: SonicWall
 CVE-2025-70962 (Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Contro ...)
 	TODO: check
 CVE-2026-54876 (Issue summary: A malicious TLS server can cause a memory leak in a TLS ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3e2f532fe33f56322fc70edba9ef8cc5ec7884ed

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3e2f532fe33f56322fc70edba9ef8cc5ec7884ed
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/fb833710/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list