[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 7 08:14:31 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c07613ad by security tracker role at 2026-08-07T07:14:25+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,9 +1,9 @@
 CVE-2026-8325 (A maliciously crafted PDF file, when parsed through Autodesk Revit, ca ...)
-	TODO: check
+	NOT-FOR-US: Autodesk
 CVE-2026-7406 (A maliciously crafted BMP file, when parsed through certain Autodesk p ...)
-	TODO: check
+	NOT-FOR-US: Autodesk
 CVE-2026-7405 (A maliciously crafted TIF file, when parsed through certain Autodesk p ...)
-	TODO: check
+	NOT-FOR-US: Autodesk
 CVE-2026-71555 (PILOS (Platform for Interactive Live-Online Seminars) is a frontend fo ...)
 	TODO: check
 CVE-2026-71554 (h2 is a pure-Python implementation of a HTTP/2 protocol stack. Version ...)
@@ -57,7 +57,7 @@ CVE-2026-70639 (llama.cpp builds b1886 through b7445 contain a null pointer dere
 CVE-2026-70638 (llama.cpp builds b1886 through b7445 contain an integer overflow vulne ...)
 	TODO: check
 CVE-2026-70636 (Flowise through 3.1.4 contains an authentication bypass vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: Flowise
 CVE-2026-70635 (TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-o ...)
 	TODO: check
 CVE-2026-70634 (TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-o ...)
@@ -81,7 +81,7 @@ CVE-2026-70558 (Dinky's POST /download/uploadFromRsByLocal handler passes the ca
 CVE-2026-70557 (diboot-core's POST /common/load-related-data endpoint resolves caller- ...)
 	TODO: check
 CVE-2026-70332 (Server-side request forgery (ssrf) in Microsoft Office SharePoint allo ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-69125
 	REJECTED
 CVE-2026-69124
@@ -103,7 +103,7 @@ CVE-2026-68942
 CVE-2026-68941
 	REJECTED
 CVE-2026-68823 (Exposed dangerous method or function in Azure Confidential Ledger allo ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-67689 (SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker ...)
 	TODO: check
 CVE-2026-67688 (ICS-Park Smart Park Management System v2.0 contains an unrestricted fi ...)
@@ -111,19 +111,19 @@ CVE-2026-67688 (ICS-Park Smart Park Management System v2.0 contains an unrestric
 CVE-2026-67687 (Insecure Permissions vulnerability in ics-park v.2.0 allows a remote a ...)
 	TODO: check
 CVE-2026-67622 (Flowise through 3.1.4 contains an insecure direct object reference vul ...)
-	TODO: check
+	NOT-FOR-US: Flowise
 CVE-2026-67621 (Flowise through 3.1.4 contains a missing authorization vulnerability t ...)
-	TODO: check
+	NOT-FOR-US: Flowise
 CVE-2026-67434 (PHP_CodeSniffer tokenizes PHP files and detects violations of a define ...)
 	TODO: check
 CVE-2026-67422 (pymdown-extensions is a collection of extensions for the Python Markdo ...)
 	TODO: check
 CVE-2026-65668 (Improper access control in Microsoft Purview eDiscovery allows an auth ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-65667 (Missing authorization in Microsoft Teams allows an unauthorized attack ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-65400 (An authentication issue was addressed with improved state management.  ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-64677 (Anki is a program for creating and reviewing flashcards. Prior to 25.0 ...)
 	TODO: check
 CVE-2026-64665 (Statamic is a Laravel and Git powered content management system (CMS). ...)
@@ -147,19 +147,19 @@ CVE-2026-63725 (sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/
 CVE-2026-63637 (Dgraph is an open source distributed GraphQL database. Prior to 25.3.8 ...)
 	TODO: check
 CVE-2026-63508 (Missing authentication for critical function in Microsoft Planetary Co ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-62918 (Improper verification of cryptographic signature in Microsoft Teams al ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-62896 (Improper authentication in Microsoft Teams allows an authorized attack ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-62873 (Improper verification of cryptographic signature in Microsoft 365 Admi ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-62857 (Fedify is a TypeScript library for building federated server apps powe ...)
 	TODO: check
 CVE-2026-62836 (Improper restriction of communication channel to intended endpoints in ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-62830 (Missing authorization in Azure SRE Agent allows an authorized attacker ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-61632 (PyMdown Extensions is a set of extensions for the Python-Markdown mark ...)
 	TODO: check
 CVE-2026-5857 (Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt ...)
@@ -169,15 +169,15 @@ CVE-2026-5856 (Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/
 CVE-2026-5855 (Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lw ...)
 	TODO: check
 CVE-2026-5336 (The DataPress (Dataverse Integration) WordPress plugin before 2.91 doe ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-59118 (Improper authorization in Microsoft Power Apps allows an unauthorized  ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-59115 ('.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allow ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-56162 (Improper authentication in Azure SQL Database allows an unauthorized a ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-56161 (Improper access control in Azure Logic Apps allows an authorized attac ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-54717 (Silverstripe CMS is an open source content management system. Prior to ...)
 	TODO: check
 CVE-2026-53984 (Ground Station prior to0.6.0 contains an unauthenticated database-dest ...)
@@ -185,19 +185,19 @@ CVE-2026-53984 (Ground Station prior to0.6.0 contains an unauthenticated databas
 CVE-2026-53983 (Ground Station prior to0.6.0contains an unauthenticated blind server-s ...)
 	TODO: check
 CVE-2026-50515 (Deserialization of untrusted data in Azure Service Bus allows an autho ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-50481 (Modification of assumed-immutable data (maid) in Azure Active Director ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-50159 (Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...)
 	TODO: check
 CVE-2026-49746 (Software installed and run as a non-privileged user may conduct improp ...)
-	TODO: check
+	NOT-FOR-US: Imagination Technologies
 CVE-2026-49391 (Frappe is a full-stack web application framework. Prior to 16.19.0 and ...)
 	TODO: check
 CVE-2026-49163 (Improper limitation of a pathname to a restricted directory ('path tra ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-49005 (The root password hash of the device can be obtained through unencrypt ...)
-	TODO: check
+	NOT-FOR-US: ZTE
 CVE-2026-48088 (OpenReception's appointment booking software provides an end-to-end en ...)
 	TODO: check
 CVE-2026-48087 (OpenReception's appointment booking software provides an end-to-end en ...)
@@ -249,9 +249,9 @@ CVE-2026-45414 (Decidim is a participatory democracy framework. Prior to 0.31.5
 CVE-2026-45378 (Decidim is a participatory democracy framework. Prior to 0.30.9, from  ...)
 	TODO: check
 CVE-2026-45204 (Software installed and run as a non-privileged user may conduct improp ...)
-	TODO: check
+	NOT-FOR-US: Imagination Technologies
 CVE-2026-45198 (Kernel software from a non-secure operating system on a platform with  ...)
-	TODO: check
+	NOT-FOR-US: Imagination Technologies
 CVE-2026-43632 (llama.cpp builds b7492 through the latest b9060 contains a use-after-f ...)
 	TODO: check
 CVE-2026-43631 (llama.cpp builds b7492 through the latest b9060 contains a use-after-f ...)
@@ -267,15 +267,15 @@ CVE-2026-43627 (llama.cpp builds b1283 through b9058 contain an integer overflow
 CVE-2026-41861 (Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attack ...)
 	TODO: check
 CVE-2026-3418 (The System REST API accepts user-supplied file uploads without enforci ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2026-3415 (The XML and schema validation functionalities within the SchemaValidat ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2026-33181
 	REJECTED
 CVE-2026-1289 (A maliciously crafted PDF file, when parsed through Autodesk Revit, ca ...)
-	TODO: check
+	NOT-FOR-US: Autodesk
 CVE-2026-19196 (A vulnerability was found in SourceCodester Photo Share Website 1.0. T ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-19195 (A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. ...)
 	TODO: check
 CVE-2026-19193 (A flaw has been found in Jiangmin Antivirus 21. Impacted is the functi ...)
@@ -291,27 +291,27 @@ CVE-2026-19189 (A security flaw has been discovered in Power Sofware PowerISO 9.
 CVE-2026-19127 (An issue in the billing and license activation subsystem allows remote ...)
 	TODO: check
 CVE-2026-19111 (Insecure direct object reference in the mongodb_memory, elasticsearch_ ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-19110 (A vulnerability was determined in DataGear up to 5.0.0. The impacted e ...)
 	TODO: check
 CVE-2026-19108 (A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. Th ...)
 	TODO: check
 CVE-2026-19071 (A flaw has been found in itsourcecode Hospital Management System 1.0.  ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-19070 (A vulnerability was detected in itsourcecode Hospital Management Syste ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-19069 (A security vulnerability has been detected in itsourcecode Hospital Ma ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-19068 (A weakness has been identified in itsourcecode Hospital Management Sys ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-19067 (A security flaw has been discovered in itsourcecode Hospital Managemen ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-19066 (A vulnerability was identified in SourceCodester Online Examination &  ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-19065 (A vulnerability was determined in SourceCodester Online Examination &  ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-19064 (A vulnerability was found in SourceCodester Online Examination & Learn ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-19062 (A vulnerability has been found in chiuwingyan house up to dea6bcceaebe ...)
 	TODO: check
 CVE-2026-19061 (A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected ...)
@@ -327,33 +327,33 @@ CVE-2026-19054 (A vulnerability was detected in Lspace-io lspace-server up to 79
 CVE-2026-18487 (A flaw was found in Epiphany. An issue in how the browser reads web ad ...)
 	TODO: check
 CVE-2026-18367 (A privilege escalation vulnerability allows local users to execute arb ...)
-	TODO: check
+	NOT-FOR-US: Sophos
 CVE-2026-17264 (Opening a crafted DICOM file containing malicious JPEG-compressed pixe ...)
 	TODO: check
 CVE-2026-17032 (Multiple Supsystic Pro plugins were distributed with malicious code th ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16620 (The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16619 (The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly li ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16265 (The WP Maps  WordPress plugin before 4.9.7 does not perform a capabili ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16263 (The WP Maps  WordPress plugin before 4.9.7 does not perform a capabili ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16262 (The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16258 (The Ajax Search Lite  WordPress plugin before 4.14.5 does not prevent  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16067 (The Event Booking Manager for WooCommerce (Pro) WordPress plugin befor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16041 (The MStore API  WordPress plugin before 4.21.0 does not perform author ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16039 (The MStore API  WordPress plugin before 4.21.0 does not restrict its v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16038 (The MStore API  WordPress plugin before 4.21.0 does not verify the pay ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16030 (The MStore API  WordPress plugin before 4.21.0 does not correctly veri ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15805
 	REJECTED
 CVE-2026-15734 (A Server-Side Template Injection (SSTI) vulnerability in WGDashboard v ...)
@@ -363,87 +363,87 @@ CVE-2026-15733 (A Remote Code Execution (RCE) vulnerability exist in WGDashboard
 CVE-2026-15732 (A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboar ...)
 	TODO: check
 CVE-2026-15386 (The Meow Gallery WordPress plugin before 5.5.2 does not escape an atta ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15361 (The Content Views  WordPress plugin before 4.5 does not perform a capa ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15359 (The Templately  WordPress plugin before 3.7.1 does not have an authori ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15256 (The Ninja Forms WordPress plugin before 3.14.10 does not prevent user- ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15245 (The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15215 (The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does n ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15214 (The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does n ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15208 (The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15152 (The WP Hotel Booking WordPress plugin before 2.3.2 does not verify tha ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15149 (The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure tha ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15147 (The Five Star Restaurant Reservations WordPress plugin before 2.7.23 d ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15032 (The Comments  WordPress plugin before 7.6.60 does not properly escape  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14943 (The Password Protected \u2014 Lock Entire Site, Pages, Posts, Categori ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14936 (The Simple Membership WordPress plugin before 4.7.7 does not verify th ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14842 (The Events Made Easy WordPress plugin before 3.1.2 does not bind the p ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14831 (The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a b ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14812 (The Premium SEO WordPress plugin is malicious: it ships an unauthentic ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14365 (The TrueBooker \u2013 Appointment Booking and Scheduler System plugin  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14364 (The TrueBooker \u2013 Appointment Booking and Scheduler System plugin  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14331 (The Subscribe2  WordPress plugin before 10.46 does not properly escape ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14306 (The Tutor LMS WordPress plugin before 3.9.14 does not properly verify  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14225 (The Easy Appointments WordPress plugin through 3.12.26 does not correc ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14205 (The WP Events Manager WordPress plugin before 2.2.5 does not validate  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13399 (The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13342 (The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not c ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12901 (The GetPaid WordPress plugin before 2.8.55 does not verify the authent ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12801 (The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12584 (The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin bef ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12501 (The WP Travel Engine WordPress plugin before 6.8.2 does not verify tha ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12261 (A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 al ...)
 	TODO: check
 CVE-2026-11976 (The official MonsterInsights Pro update distribution bucket (`monster- ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11907 (The Stream plugin for WordPress is vulnerable to authorization bypass  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11803 (A maliciously crafted PDF file, when parsed through Autodesk Revit, ca ...)
-	TODO: check
+	NOT-FOR-US: Autodesk
 CVE-2026-11361 (The Formidable Forms WordPress plugin before 6.32.1 does not properly  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-10599 (The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-10524 (The CoCart WordPress plugin before 4.9.0 does not validate a user-supp ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-6508 (The Swagger UI Try-out console within the API Publisher documentation  ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2025-15674 (The Passster WordPress plugin before 4.3.7 does not restrict low-privi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-14561 (In multi-tenant deployments, the Publisher REST APIs fail to enforce t ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2025-12317 (When internal roles are removed from a user within the WSO2 product, t ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2024-6541 (The Class Mediator fails to correctly validate or sanitize `messageCon ...)
-	TODO: check
+	NOT-FOR-US: WSO2
 CVE-2024-39024 (In Packetfence 13.2.0, the WebGui interface setting allows authenticat ...)
 	TODO: check
 CVE-2026-18938



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c07613addc3812ecc8eefc270b79455d68bd8b1c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c07613addc3812ecc8eefc270b79455d68bd8b1c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260807/e0e196f2/attachment.htm>


More information about the debian-security-tracker-commits mailing list