[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 6 20:14:33 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
71501bad by security tracker role at 2026-08-06T19:14:27+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -13,13 +13,13 @@ CVE-2026-68749 (Inefficient Regular Expression Complexity vulnerability in the C
 CVE-2026-68747 (Improper Neutralization of Special Elements in Output Used by a Downst ...)
 	TODO: check
 CVE-2026-68481 (In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tok ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-68079 (In Apache CXF's DefaultEncryptingCodeDataProvider,a captured authoriza ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-67261 (Dell Virtual Storage Integrator for VMware vSphere Client, versions pr ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-66909 (Apache CXF's JMS transport deserializes the body of any inbound JMS Ob ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-66843 (Inclusion of Functionality from Untrusted Control Sphere vulnerability ...)
 	TODO: check
 CVE-2026-66829 (URL Redirection to Untrusted Site ('Open Redirect') vulnerability in t ...)
@@ -29,197 +29,197 @@ CVE-2026-66733 (Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memor
 CVE-2026-66732 (Sonic 3 A.I.R. before commit 2492d18 contains a missing source address ...)
 	TODO: check
 CVE-2026-66712 (Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 ve ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66711 (Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Mu ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66710 (Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66709 (Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 version ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66708 (Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66707 (Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66706 (Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 ve ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66705 (Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress < ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66703 (Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66702 (Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66701 (Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 ver ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66699 (Custom role Broken Access Control in Dokan <= 5.0.10 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66696 (Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66695 (Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66694 (Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66692 (Customer Insecure Direct Object References (IDOR) in Colissimo Officie ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66690 (Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 version ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66688 (Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elemento ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66686 (Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage C ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66685 (Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66684 (Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66683 (Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript < ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66681 (Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66678 (Contributor Broken Access Control in Advanced Custom Fields: Font Awes ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66665 (Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66664 (Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66663 (Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66662 (Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps < ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66470 (Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66457 (Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66452 (Unauthenticated Broken Access Control in Legal Text Connector of the I ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66451 (Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 ve ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66447 (Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66440 (Unauthenticated Cross Site Scripting (XSS) in WPIDE \u2013 File Manage ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66439 (Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Fi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66425 (Unauthenticated Broken Authentication in Gutena Forms \u2013 Contact F ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66370 (URL Redirection to Untrusted Site ('Open Redirect') vulnerability in t ...)
 	TODO: check
 CVE-2026-65583 (Apache CXF\u2019s OIDC relying-party token validation could accept sel ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-65581 (Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65579 (Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65578 (Unauthenticated PHP Object Injection in Agora <= 1.9 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65577 (Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65576 (Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65575 (Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65574 (Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65573 (Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65572 (Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65571 (Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65570 (Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65569 (Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65565 (Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65560 (Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <=  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65559 (Shop manager Privilege Escalation in Order Delivery Date for WooCommer ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65556 (Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Sp ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65554 (Subscriber Broken Access Control in AnsPress \u2013 Question and answe ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65553 (Unauthenticated Remote Code Execution (RCE) in Spider Analyser – ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65552 (Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65551 (Missing Authorization vulnerability in Soflyy Breakdance allows Exploi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65549 (Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 version ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65548 (Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65547 (Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65546 (Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65545 (Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65544 (Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65543 (Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65542 (Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 ve ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65541 (Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65523 (Unauthenticated Insecure Direct Object References (IDOR) in Formidable ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65520 (Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65517 (Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Butt ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65515 (Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 ve ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65513 (Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointm ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65509 (Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 ve ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65508 (Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.1 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65507 (Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65504 (Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65502 (Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65432 (Apache CXF reads a top-level WSDL through its hardened StaxUtilspath,  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-64993 (Dell RVTools versions prior to 4.8.1, contains an improper certificate ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-64958 (An incomplete fix forCVE-2026-50645 means that it is still possible to ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-64640 (Apache Polaris did not consistently validate storage locations supplie ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-63687 (Apache CXF's JwtRequestCodeFilter copies all claims from a signed requ ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-61982 (Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61964 (Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 ve ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61963 (Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61961 (Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 vers ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61959 (Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61466 (In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the autho ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-5430 (The JWT authentication mechanism accepts tokens signed with algorithms ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2026-5423 (@neo4j/graphqllibrary versions prior to 7.5.6 fail to verify the authe ...)
 	TODO: check
 CVE-2026-5391 (The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-5158 (The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites \u20 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-5134 (Improper neutralization of special elements used in an SQL command ('S ...)
 	TODO: check
 CVE-2026-57819 (Apache CXF allows to set a limit on the number of form parameters in a ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-57818 (A race condition in JCacheCodeDataProvider allows an attacker to redee ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-57817 (The OpenID Connect Core 1.0 specification mandates that the RP MUST va ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-55980 (A denial-of-service vulnerability inCatchPulsecould allow an attacker  ...)
 	TODO: check
 CVE-2026-55979 (An improper access control check inCatchPulse'snamed pipe communicatio ...)
@@ -227,9 +227,9 @@ CVE-2026-55979 (An improper access control check inCatchPulse'snamed pipe commun
 CVE-2026-55978 (An improper access control vulnerability inCatchPulsecould allow a non ...)
 	TODO: check
 CVE-2026-54489 (Dell Virtual Storage Integrator for VMware vSphere Client, versions pr ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-54225 (Apache CXF allows to control the maximum attachment size via the"attac ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-53985 (Ground Station prior to 0.6.0contains an unauthenticated denial-of-ser ...)
 	TODO: check
 CVE-2026-53977 (OpenChamber 1.11.7 contains an authentication bypass vulnerability tha ...)
@@ -241,7 +241,7 @@ CVE-2026-53975 (OpenChamber 1.11.7 contains an unauthenticated remote code execu
 CVE-2026-43622 (llama.cpp builds b1886 through b7445 contain a double free vulnerabili ...)
 	TODO: check
 CVE-2026-3430 (The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not saniti ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-34502 (Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Ut ...)
 	TODO: check
 CVE-2026-34501 (Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Ut ...)
@@ -249,45 +249,45 @@ CVE-2026-34501 (Heap-based Buffer Overflow vulnerability in Apache Portable Runt
 CVE-2026-34191 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
 	TODO: check
 CVE-2026-32548 (Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32469 (Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32327 (A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion ...)
 	TODO: check
 CVE-2026-28183 (Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 ver ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28180 (Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pa ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28179 (Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28178 (Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28177 (Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 ve ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28172 (Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Man ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28169 (Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magni ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28146 (Contributor Arbitrary File Download in Unlimited Elements For Elemento ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28143 (Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 ver ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28141 (Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28140 (Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 ver ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28139 (Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 ver ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28111 (Contributor Privilege Escalation in Forminator <= 1.56.0 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28082 (Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 ve ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28005 (Unauthenticated Privilege Escalation in Kadence WooCommerce Email Desi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-25403 (Unauthenticated Broken Access Control in Ultimate Store Kit Elementor  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-1728 (Tokens issued to a low-privileged user are not sufficiently restricted ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2026-19047 (A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. T ...)
 	TODO: check
 CVE-2026-19046 (A security vulnerability has been detected in NocteDefensor LudusMCP u ...)
@@ -315,9 +315,9 @@ CVE-2026-19034 (A vulnerability was determined in Shibby Tomato 1.28.0000. Affec
 CVE-2026-19022 (A vulnerability was determined in OpenHands up to 0.62.0. The affected ...)
 	TODO: check
 CVE-2026-19021 (A security vulnerability has been detected in SourceCodester Computer  ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-19020 (A weakness has been identified in itsourcecode Hospital Management Sys ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-19019 (A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. ...)
 	TODO: check
 CVE-2026-19011 (A vulnerability was detected in TinyAGI 0.0.20. The affected element i ...)
@@ -333,9 +333,9 @@ CVE-2026-18915 (Invocation of process using visible sensitive information vulner
 CVE-2026-18649 (A flaw was found in the GStreamer gst-plugins-good package. The rtph26 ...)
 	TODO: check
 CVE-2026-18597 (The PDF creation feature of Foxit PDF Services API supports referencin ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-18501 (The UsersWP \u2013 Front-end login form, User Registration, User Profi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18427 (@fastify/static before version 10.1.3 contains an incomplete fix for a ...)
 	TODO: check
 CVE-2026-18359 (Server-side request forgery in the METS and IIIF import URI handling i ...)
@@ -357,41 +357,41 @@ CVE-2026-16315 (OMICRON StationGuard before version 4.10 contains a cryptographi
 CVE-2026-15599 (Unverified ownership vulnerability in T\xdcB\u0130TAK B\u0130LGEM Soft ...)
 	TODO: check
 CVE-2026-15246 (The RealHomes Memberships WordPress plugin before 3.1.0 does not verif ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12605 (In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in Downl ...)
-	TODO: check
+	NOT-FOR-US: Eclipse
 CVE-2026-11983 (The Ad Inserter \u2013 Ad Manager & AdSense Ads plugin for WordPress i ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-0673 (The Element Pack Addons for Elementor plugin for WordPress is vulnerab ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-0637 (When an Event Publisher output adapter is configured with irrelevant p ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2025-9266 (The Accelerate theme for WordPress is vulnerable to unauthorized modif ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-49506 (APR-util versions 1.6.3 (and earlier) function apr_password_validate() ...)
 	TODO: check
 CVE-2025-15039 (The Conditional Authentication (Adaptive Authentication) script does n ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2025-15028 (The FormGent \u2013 Next-Gen AI Form Builder for WordPress with Multi- ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-14779 (The Secret Type Management REST API does not correctly isolate access  ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2025-13909 (The system accepts authentication requests without sufficient validati ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2025-13736 (When Multi-Attribute Login is enabled, the login interface fails to co ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2025-13394 (The Ajax processor within the Carbon console fails to adequately prote ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2025-12627 (The user impersonation flow in WSO2 Identity Server fails to properly  ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2025-11850 (When secondary user stores are configured, the implicit-association re ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2024-8995 (Unused authorization codes issued to deleted users are not being prope ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2024-6832 (The account locking mechanism fails to trigger when secondary user sto ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2024-10302 (The user self-signup flow in multiple WSO2 products fails to adequatel ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2023-7355
 	REJECTED
 CVE-2023-7354



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71501bad0304e5c9132ef1f6ec225c32e5fdef3d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71501bad0304e5c9132ef1f6ec225c32e5fdef3d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260806/14195647/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list