[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Aug 9 08:14:52 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
41064808 by security tracker role at 2026-08-09T07:14:46+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -59,39 +59,39 @@ CVE-2026-19324 (A weakness has been identified in HelloGGX shadcn-vue-mcp up to
CVE-2026-19323 (A security flaw has been discovered in azer react-analyzer-mcp up to 3 ...)
TODO: check
CVE-2026-18603 (The PiWeb Cancel order / Refund request for WooCommerce WordPress plug ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18473 (The WP Directory Kit WordPress plugin before 1.5.5 does not properly s ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18465 (The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capab ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18464 (The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capab ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18357 (The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does n ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18037 (The Create WordPress plugin before 2.5.4 does not perform an authoriza ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18032 (The WP Data Access WordPress plugin before 5.5.79 does not validate t ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17044 (The Iptanus File Upload WordPress plugin before 5.1.8 does not properl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17017 (The CubeWP Framework WordPress plugin before 1.1.31 does not properly ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17014 (The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not pe ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17011 (The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16992 (The Create WordPress plugin before 2.5.4 does not perform an authoriza ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16988 (The GeoDirectory WordPress plugin before 2.8.169 does not perform any ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16965 (The Solace Extra WordPress plugin before 1.6.1 does not perform capabi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16957 (The Slim SEO WordPress plugin before 4.9.11 does not restrict a post- ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16032 (The LWS Optimize WordPress plugin before 4.1.2 does not properly esca ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15038 (The InfiniteWP Client WordPress plugin before 1.13.6 does not properly ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-11612
REJECTED
CVE-2026-10595 (A path traversal vulnerability exists in parisneo/lollms version 2.1.0 ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4106480875718ac59dbfda24f5f2fcb1a8434ed2
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4106480875718ac59dbfda24f5f2fcb1a8434ed2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260809/ed9e38ce/attachment.htm>
More information about the debian-security-tracker-commits
mailing list