[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 12 08:14:34 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
88d407cb by security tracker role at 2026-08-12T07:14:28+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -61,9 +61,9 @@ CVE-2026-71290 (Improper TLS hostname verification vulnerability in Apache HttpC
 CVE-2026-70398 (A flaw was found in multicloud-integrations, a component of Red Hat Ad ...)
 	TODO: check
 CVE-2026-70339 (Access of resource using incompatible type ('type confusion') in Micro ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-6484 (In an UEFI, Lack of verified boot to certain FV may cause arbitrary co ...)
-	TODO: check
+	NOT-FOR-US: Insyde
 CVE-2026-68067 (The login endpoint on the Mira cloud API accepts any format-valid stri ...)
 	TODO: check
 CVE-2026-67568 (The distributed Mira Android APK v4.5.15.4 allows an attacker read/wri ...)
@@ -77,23 +77,23 @@ CVE-2026-66875 (In the Mira hormone monitor device firmware v1.7.1.47 build 0107
 CVE-2026-66832 (When the Mira Android app opens in-app WebView content (e.g., shop red ...)
 	TODO: check
 CVE-2026-66659 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66340 (The Mira cloud authentication endpoints do not enforce per-account rat ...)
 	TODO: check
 CVE-2026-66154 (An insufficient certificate validation in a privileged communication w ...)
-	TODO: check
+	NOT-FOR-US: SonicWall
 CVE-2026-66150 (Improper Control of Generation of Code ('Code Injection') Vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: SonicWall
 CVE-2026-66149 (Improper Control of Generation of Code ('Code Injection') Vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: SonicWall
 CVE-2026-66148 (An authenticated command injection vulnerability was identified in GMS ...)
-	TODO: check
+	NOT-FOR-US: SonicWall
 CVE-2026-66147 (An unauthenticated command injection vulnerability was identified in t ...)
-	TODO: check
+	NOT-FOR-US: SonicWall
 CVE-2026-66146 (Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in ...)
-	TODO: check
+	NOT-FOR-US: SonicWall
 CVE-2026-66145 (An unauthenticated remote code execution vulnerability was identified  ...)
-	TODO: check
+	NOT-FOR-US: SonicWall
 CVE-2026-66098 (The Mira hormone monitor device firmware accepts a 0x01 write from any ...)
 	TODO: check
 CVE-2026-65655 (When OAuth authentication is enabled and browser-facing TLS terminates ...)
@@ -141,105 +141,105 @@ CVE-2026-19579 (Snipe-IT before 8.6.0 contains an authorization bypass (insecure
 CVE-2026-19550 (A flaw was found in FreeIPA. The trust-fetch-domains command is gated  ...)
 	TODO: check
 CVE-2026-19217 (The Royal Addons for Elementor  WordPress plugin before 1.7.1065 does  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19091 (The GeoDirectory \u2013 WP Business Directory Plugin and Classified Li ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19073 (The Order Sync with Zendesk for WooCommerce WordPress plugin before 2. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19052 (The ProSolution WP Client WordPress plugin before 2.0.9 does not perfo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19050 (The ProSolution WP Client WordPress plugin before 2.0.9 does not valid ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18962 (The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not ch ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18961 (The Social Login, Passkeys, Magic Link & Email OTP \u2013 Passwordless ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18943 (The WPC Admin Columns WordPress plugin before 2.3.4 does not have auth ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18844 (The firmware of thePulsetto Vagus Nerve Stimulatoraccepts several undi ...)
 	TODO: check
 CVE-2026-18789 (The Ezoic WordPress plugin before 2.23.1 does not properly restrict ac ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18710 (A MongoDB driver component could write sensitive configuration informa ...)
 	TODO: check
 CVE-2026-18634 (An insecure handling of serialized objects vulnerability was found in  ...)
-	TODO: check
+	NOT-FOR-US: SonicWall
 CVE-2026-18474 (The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18391 (The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18366 (The Events Manager  WordPress plugin before 7.4.1 does not properly sc ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18230 (The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18057 (The Events Manager  WordPress plugin before 7.4.1 does not sanitise an ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18049 (The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not pe ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18048 (The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not va ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18046 (The Cookie Consent  WordPress plugin before 0.0.10 does not correctly  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18035 (The User Access Manager WordPress plugin before 2.3.15 does not apply  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-17013 (The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sa ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16977 (The Form Maker by 10Web  WordPress plugin before 1.15.45 does not prop ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16737 (The WP Travel Engine  WordPress plugin before 6.8.5 does not perform a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16538 (The Wallet for WooCommerce WordPress plugin before 1.6.10 does not ver ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16294 (The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16253 (The Total Upkeep  WordPress plugin before 1.17.3 does not adequately p ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16230 (The Formidable Digital Signatures plugin for WordPress is vulnerable t ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16066 (The Welcart e-Commerce WordPress plugin before 2.11.34 does not saniti ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16051 (The wpmudev-updates WordPress plugin before 5.0.1 does not verify the  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15606 (The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15388 (The Cookie Consent  WordPress plugin before 0.0.10 does not correctly  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15249 (The Patterns Kit WordPress plugin through 1.0.3 does not escape a link ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15039 (The giftware WordPress plugin before 4.2.10 does not validate the type ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14925 (The Import WP  WordPress plugin before 2.14.23 does not perform any au ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14863 (FileRun up to and including version 2026.2.0 contains an OS command in ...)
 	TODO: check
 CVE-2026-14859 (The WP Crowdfunding WordPress plugin before 2.2.1 does not check the c ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14858 (The WP Crowdfunding WordPress plugin before 2.2.1 does not verify orde ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14857 (The WP Crowdfunding WordPress plugin before 2.2.1 does not verify owne ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13613 (The KiviCare  WordPress plugin before 4.5.2 does not properly sanitise ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13612 (The KiviCare  WordPress plugin before 4.5.2 does not verify that the r ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13457 (The InstaWP Connect \u2013 1-click WP Staging & Migration plugin for W ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13177 (The Eventin  WordPress plugin before 4.1.20 does not properly restrict ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13171 (The Eventin  WordPress plugin before 4.1.20 does not perform an author ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13168 (The Eventin  WordPress plugin before 4.1.20 does not properly restrict ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12976 (The LearnPress  WordPress plugin before 4.4.4 does not verify that a u ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12235 (The Linkable Loadable Extensions (llext) subsystem mis-handles PLT/REL ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12234 (The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsoc ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12233 (The PSA Protected Storage credential backend (subsys/net/lib/tls_crede ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12232 (The Intel ALH digital-audio-interface driver function dai_alh_get_prop ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2025-15687 (A security flaw has been discovered in Open5GS up to 2.7.6. Impacted i ...)
 	TODO: check
 CVE-2025-15686 (A vulnerability has been found in Open5GS up to 2.7.6. Affected by thi ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88d407cba39e71fd571f2810cfbef51cf6a74022

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88d407cba39e71fd571f2810cfbef51cf6a74022
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/c851d7fe/attachment.htm>


More information about the debian-security-tracker-commits mailing list