[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Aug 9 08:14:52 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
41064808 by security tracker role at 2026-08-09T07:14:46+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -59,39 +59,39 @@ CVE-2026-19324 (A weakness has been identified in HelloGGX shadcn-vue-mcp up to
 CVE-2026-19323 (A security flaw has been discovered in azer react-analyzer-mcp up to 3 ...)
 	TODO: check
 CVE-2026-18603 (The PiWeb Cancel order / Refund request for WooCommerce WordPress plug ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18473 (The WP Directory Kit WordPress plugin before 1.5.5 does not properly s ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18465 (The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capab ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18464 (The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capab ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18357 (The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does n ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18037 (The Create WordPress plugin before 2.5.4 does not perform an authoriza ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18032 (The WP Data Access  WordPress plugin before 5.5.79 does not validate t ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-17044 (The Iptanus File Upload WordPress plugin before 5.1.8 does not properl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-17017 (The CubeWP Framework WordPress plugin before 1.1.31 does not properly  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-17014 (The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not pe ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-17011 (The Nexter Blocks  WordPress plugin before 5.0.2 does not restrict who ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16992 (The Create WordPress plugin before 2.5.4 does not perform an authoriza ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16988 (The GeoDirectory  WordPress plugin before 2.8.169 does not perform any ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16965 (The Solace Extra WordPress plugin before 1.6.1 does not perform capabi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16957 (The Slim SEO  WordPress plugin before 4.9.11 does not restrict a post- ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16032 (The LWS Optimize  WordPress plugin before 4.1.2 does not properly esca ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15038 (The InfiniteWP Client WordPress plugin before 1.13.6 does not properly ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11612
 	REJECTED
 CVE-2026-10595 (A path traversal vulnerability exists in parisneo/lollms version 2.1.0 ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4106480875718ac59dbfda24f5f2fcb1a8434ed2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4106480875718ac59dbfda24f5f2fcb1a8434ed2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260809/ed9e38ce/attachment.htm>


More information about the debian-security-tracker-commits mailing list