[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 6 08:13:27 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0c07b4ba by security tracker role at 2026-08-06T07:13:21+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -75,7 +75,7 @@ CVE-2026-52466 (Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to
 CVE-2026-34966 (Gitea prior to 1.27.0 contains a server-side request forgery vulnerabi ...)
 	TODO: check
 CVE-2026-21766 (The default login portlet in HCL Digital Experience and Digital Experi ...)
-	TODO: check
+	NOT-FOR-US: HCL
 CVE-2026-19028 (H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 comput ...)
 	TODO: check
 CVE-2026-19027 (The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype,  ...)
@@ -133,79 +133,79 @@ CVE-2026-18959 (A flaw has been found in yushine InnoShop up to 0.8.2. Affected
 CVE-2026-18958 (A vulnerability was detected in imranrisal-dev Student-Management-Syst ...)
 	TODO: check
 CVE-2026-18954 (Incorrect authorization in the aggregation pipeline tool in Amazon AWS ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-18953 (Improper limitation of a pathname to a restricted directory in the get ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-18909 (A stack-based buffer overflow vulnerability exists in ELAN Microelectr ...)
 	TODO: check
 CVE-2026-18839 (An integer underflow was found in the popt library when formatting hel ...)
 	TODO: check
 CVE-2026-18510 (The TranslatePress \u2013 Translate Multilingual sites with AI Transla ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18411 (The KARR Security System and SWDS dealer-installed automotive anti-the ...)
 	TODO: check
 CVE-2026-18400 (The Slider, Gallery, and Carousel by MetaSlider \u2013 Image Slider, V ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18395 (The Child Pages Card WordPress plugin before 1.09 does not sanitise an ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18325 (The Forminator Forms \u2013 Contact Form, Payment Form & Custom Form B ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18050 (The Events Manager  WordPress plugin before 7.4 does not perform any a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-17583 (The affected  Thermo Fisher Applied Biosystems Genetic Analyzers arevu ...)
 	TODO: check
 CVE-2026-17556 (A path traversal vulnerability was identified in GitHub Enterprise Ser ...)
-	TODO: check
+	NOT-FOR-US: Github Enterprise Server
 CVE-2026-16954 (The AI Engine  WordPress plugin before 3.6.4 does not redact secret co ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16734 (The Stripe Payment Forms by WP Full Pay  WordPress plugin before 8.5.2 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16636 (The FluentSMTP \u2013 WP SMTP Plugin with Amazon SES, SendGrid, MailGu ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16537 (The Slick Slider WordPress plugin before 0.5.3 does not sanitize and e ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16290 (The ProfileGrid  WordPress plugin before 6.0.0.0 does not perform auth ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16268 (The Newsletters WordPress plugin before 4.16 does not authenticate or  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16065 (The Welcart e-Commerce WordPress plugin before 2.11.32 does not proper ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16054 (The Drag and Drop Multiple File Upload for WooCommerce WordPress plugi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15996 (A denial of service vulnerability was identified in GitHub Enterprise  ...)
-	TODO: check
+	NOT-FOR-US: Github Enterprise Server
 CVE-2026-15991 (The File Manager plugin for WordPress is vulnerable to arbitrary file  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15459 (The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentic ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14829 (The Checkimate \u2014 WooCommerce Checkout, Abandoned Cart Recovery &  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14547 (The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14314 (The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14313 (PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Up ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14240 (The tourmaster WordPress plugin before 5.4.9 writes its order/booking  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14204 (The Google Authenticator WordPress plugin before 0.56 does not verify  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13703 (The SEO Redirection Plugin  WordPress plugin before 9.19 does not perf ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13154 (The Gutenberg Essential Blocks  WordPress plugin before 6.4.0 does not ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13153 (The Gutenberg Essential Blocks  WordPress plugin before 6.4.0 does not ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12713 (The WPCargo Track & Trace WordPress plugin before 8.0.4 does not prope ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11588 (The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform an ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-63823 (My Safetipin Android Application 5.2.1 contains Hardcoded credentials  ...)
 	TODO: check
 CVE-2025-63822 (SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access ...)
 	TODO: check
 CVE-2025-15678 (The Nexter Blocks  WordPress plugin before 5.0.2 does not sanitize upl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2023-54389
 	REJECTED
 CVE-2023-54388



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0c07b4baf8724ba06825c52de1508a12e5cc6ae7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0c07b4baf8724ba06825c52de1508a12e5cc6ae7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260806/c4fb121c/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list