[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 13 20:14:58 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
71e990de by security tracker role at 2026-08-13T19:14:52+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -61,25 +61,25 @@ CVE-2026-73612 (File Browser before v2.63.22 fails to validate access rules for
CVE-2026-73611 (File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT ...)
TODO: check
CVE-2026-73610 (SiYuan before v3.7.4 contains an information disclosure vulnerability ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73609 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73608 (SiYuan's development branch (endpoint introduced by commit 9b8e8956f, ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73607 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73606 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73605 (SiYuan versions before v3.7.4 contain a path traversal vulnerability i ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73604 (Flowise before 3.1.3 contains an incomplete credential redaction vulne ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-73603 (Flowise before 3.1.4 fails to validate chatflow visibility in the unau ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-73602 (Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-73601 (Flowise versions before 3.1.3 contain a remote code execution vulnerab ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-73585 (A flaw was found in sblim-cmpi-base. Insecure temporary file creation ...)
TODO: check
CVE-2026-73584 (A flaw was found in sblim-sfcb. A local, low-privileged attacker can e ...)
@@ -87,19 +87,19 @@ CVE-2026-73584 (A flaw was found in sblim-sfcb. A local, low-privileged attacker
CVE-2026-73583 (A flaw was found in sblim-sfcb. A local attacker with access to the sy ...)
TODO: check
CVE-2026-73576 (In Zimbra Collaboration (ZCS) before 10.1.17,weak cryptographic key ge ...)
- TODO: check
+ NOT-FOR-US: Zimbra
CVE-2026-73575 (In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request For ...)
- TODO: check
+ NOT-FOR-US: Zimbra
CVE-2026-73574 (In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) v ...)
- TODO: check
+ NOT-FOR-US: Zimbra
CVE-2026-73573 (In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnera ...)
- TODO: check
+ NOT-FOR-US: Zimbra
CVE-2026-73572 (In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scri ...)
- TODO: check
+ NOT-FOR-US: Zimbra
CVE-2026-73571 (An authorization bypass vulnerability exists in Zimbra Collaboration ( ...)
- TODO: check
+ NOT-FOR-US: Zimbra
CVE-2026-73570 (A remote code execution vulnerability exists in Zimbra Collaboration ( ...)
- TODO: check
+ NOT-FOR-US: Zimbra
CVE-2026-73569 (fast-xml-parser allows users to process XML from JS object without C/C ...)
TODO: check
CVE-2026-73568 (py-libp2p is the Python implementation of the libp2p networking stack. ...)
@@ -147,41 +147,41 @@ CVE-2026-73506 (Oh My Posh is the most customisable and low-latency cross platfo
CVE-2026-73505 (Oh My Posh is the most customisable and low-latency cross platform/she ...)
TODO: check
CVE-2026-73488 (Flowise versions before 3.1.3 contain an insecure direct object refere ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-73487 (Flowise before 3.1.3 contains a regex-based Python code validator bypa ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-73486 (Flowise before 3.1.3 contains a code injection vulnerability in the CS ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-73485 (Flowise before 3.1.3 contains a code injection vulnerability in the Ai ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-73484 (Flowise before 3.1.3 contains a sandbox escape vulnerability in python ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-73483 (Flowise (packages flowise and flowise-components) in versions <= 3.1.2 ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-73482 (phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) ...)
TODO: check
CVE-2026-73481 (phpList before 3.7.0-RC5 fail to enforce CSRF token validation on the ...)
TODO: check
CVE-2026-73403 (Unauthenticated Broken Access Control in User Registration <= 5.2.6 ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73401 (Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73357 (Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73353 (Unauthenticated Broken Access Control in Revolut Gateway for WooCommer ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73349 (Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73346 (Administrator SQL Injection in MailChimp For WooCommerce < 6.2 version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73344 (Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73340 (Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73266 (A flaw was found in the clusterclaims-controller component of Multiclu ...)
TODO: check
CVE-2026-73188 (Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-73038 (NodeBB before 4.15.0 contains a stored cross-site scripting vulnerabil ...)
TODO: check
CVE-2026-73037 (Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site s ...)
@@ -191,7 +191,7 @@ CVE-2026-72777 (Next AI Draw.io through 0.4.16 contains a server-side request fo
CVE-2026-72741 (Rainbond through 6.9.7 contains a broken access control vulnerability ...)
TODO: check
CVE-2026-6387 (A potential authentication bypass vulnerability was reported in Lenovo ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-67991 (crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 cont ...)
TODO: check
CVE-2026-67990 (basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f di ...)
@@ -203,147 +203,147 @@ CVE-2026-67614 (CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnera
CVE-2026-67613 (CyberPanel before 3.0.0 contains a path traversal vulnerability that a ...)
TODO: check
CVE-2026-66704 (Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Compa ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66700 (Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for C ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66698 (Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66697 (Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : M\x ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66693 (Subscriber Broken Access Control in Motors <= 1.4.113 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66691 (Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66689 (Unauthenticated Broken Access Control in Anti Spam and list cleaner &# ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66687 (Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66661 (Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66660 (Unauthenticated Broken Access Control in Contact Form 7 \u2013 PayPal ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66658 (Subscriber SQL Injection in Reviewer <= 3.14.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66657 (Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66656 (Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66655 (Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping Fo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66654 (Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.10 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66653 (Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66478 (Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66472 (Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66471 (Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66469 (Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66468 (Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers f ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66467 (Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66466 (Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Boos ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66465 (Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66464 (Unauthenticated Broken Access Control in Internal Link Optimiser <= 5. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66463 (Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66462 (Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66461 (Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66460 (Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66459 (Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66458 (Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66456 (Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestW ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66455 (Subscriber Broken Access Control in ReactPress <= 3.4.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66454 (Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66453 (Unauthenticated Broken Authentication in Salon booking system <= 10.30 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66450 (Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66449 (Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.18 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66446 (Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66444 (Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66443 (Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66441 (Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66436 (Unauthenticated SQL Injection in Active Products Tables for WooCommerc ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66432 (Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66431 (Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gat ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66430 (Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro < ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66429 (Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Tim ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66426 (Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66424 (Unauthenticated Privilege Escalation in SMS Alert Order Notifications ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-66256 (** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vuln ...)
TODO: check
CVE-2026-65936 (A malformed Bluetooth connection request message can cause the RS9116W ...)
- TODO: check
+ NOT-FOR-US: Silicon Labs
CVE-2026-65935 (Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS911 ...)
- TODO: check
+ NOT-FOR-US: Silicon Labs
CVE-2026-65934 (An unencrypted 'pause encryption request' message causes a denial of s ...)
- TODO: check
+ NOT-FOR-US: Silicon Labs
CVE-2026-65933 (A malformed Bluetooth connection request message can cause the BT122 t ...)
- TODO: check
+ NOT-FOR-US: Silicon Labs
CVE-2026-65932 (The BT122 module stops advertising after receiving a plaintext 'pause ...)
- TODO: check
+ NOT-FOR-US: Silicon Labs
CVE-2026-65582 (Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65580 (Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-63426 (During an internal security assessment, a potential vulnerability was ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-63425 (During an internal security assessment, a potential improper permissio ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-63424 (During an internal security assessment, an improperly protected key wa ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-63423 (During an internal security assessment, a potential vulnerability was ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-61984 (Unauthenticated Broken Access Control in WPMobile.App <= 11.77 version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61980 (Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61979 (Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61978 (Unauthenticated Broken Access Control in Secure Card Gateway for ePay ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61974 (Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61969 (Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61967 (Unauthenticated Privilege Escalation in miniorange otp verification <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61966 (Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61965 (Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61962 (Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61960 (Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59765 (SSRF via Migration Asset Downloads Bypasses hostmatcher \u2014 Reads I ...)
TODO: check
CVE-2026-59763 (Unbounded Arch package file metadata can cause resource amplification ...)
@@ -447,11 +447,11 @@ CVE-2026-55984 (Null Pointer Dereference in AddTime API Causes Authenticated Den
CVE-2026-55982 (OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API T ...)
TODO: check
CVE-2026-55402 (CVE-2026-55402 is an out of bounds read vulnerability in Secure Access ...)
- TODO: check
+ NOT-FOR-US: Absolute Software
CVE-2026-55401 (CVE-2026-55401 is a null dereference vulnerability on the load-balanci ...)
- TODO: check
+ NOT-FOR-US: Absolute Software
CVE-2026-55400 (CVE-2026-55400 is an integer underflow in Secure Access servers prior ...)
- TODO: check
+ NOT-FOR-US: Absolute Software
CVE-2026-54481 (Internal API HTTP client hardcodes InsecureSkipVerify:true with no con ...)
TODO: check
CVE-2026-50105 (RSS/Atom feed handlers bypass API-token scope & public-only confinemen ...)
@@ -469,85 +469,85 @@ CVE-2026-45819 (baseline-browser-mapping 2.x before 2.11.0 calls process.exit()
CVE-2026-42931 (Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint)
TODO: check
CVE-2026-3639 (The PPWP \u2013 Password Protect Pages plugin for WordPress is vulnera ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-28189 (Unauthenticated Arbitrary File Deletion in Participants Database <= 2. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28188 (Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28187 (Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Docum ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28186 (Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28185 (Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28184 (Subscriber SQL Injection in Form Maker by 10Web <= 1.15.44 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28182 (Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28181 (Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28176 (Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28175 (Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Ti ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28174 (Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28173 (Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28170 (Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28168 (Subscriber SQL Injection in CubeWP <= 1.1.30 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28161 (Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28159 (Subscriber Broken Access Control in Service Finder Booking <= 6.2 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28158 (Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28157 (Subscriber Path Traversal in Do Lasso <= 358 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28156 (Subscriber SQL Injection in Do Lasso <= 358 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28155 (Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso < ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28154 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
TODO: check
CVE-2026-28149 (Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28148 (Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28142 (Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28008 (Unauthenticated Broken Authentication in OAuth Single Sign On \u2013 S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28004 (Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28003 (Unauthenticated Cross Site Scripting (XSS) in Maspik \u2013 Spam black ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28002 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28001 (Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27999 (Subscriber Broken Access Control in Tourfic <= 2.23.1 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27544 (Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27543 (Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27539 (Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27538 (Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27537 (Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27536 (Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Form ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27535 (Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27380 (Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27345 (Unauthenticated Broken Access Control in Taxi Booking Manager for WooC ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-24791 (Public-only tokens bypass private-resource restrictions on `/api/v1/us ...)
TODO: check
CVE-2026-24059 (The GET /api/v1/user/actions/runners/registration-token endpoint (and ...)
@@ -555,7 +555,7 @@ CVE-2026-24059 (The GET /api/v1/user/actions/runners/registration-token endpoint
CVE-2026-23603 (Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC pictu ...)
TODO: check
CVE-2026-21832 (HCL AION is affected by a vulnerability where indirect prompt injectio ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-19744 (Cross-site Scripting in the Markdown renderer in maalfer Pentestify be ...)
TODO: check
CVE-2026-19734 (Missing Authorization and Authorization Bypass Through User-Controlled ...)
@@ -565,7 +565,7 @@ CVE-2026-19730 (The 'podman quadlet install --replace' command opens the existin
CVE-2026-19716 (Stored Cross-site Scripting (CWE-79) in the user management component ...)
TODO: check
CVE-2026-19710 (A vulnerability was found in SourceCodester Simple Student Information ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-19696 (Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 ...)
TODO: check
CVE-2026-19695 (Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of ...)
@@ -579,63 +579,63 @@ CVE-2026-19484 (@fastify/busboy is a multipart form-data parser. In versions 3.1
CVE-2026-19481 (@fastify/busboy is a multipart form-data parser. In versions 1.0.0 thr ...)
TODO: check
CVE-2026-19293 (SMP security request (from peripheral)does not include the maximum enc ...)
- TODO: check
+ NOT-FOR-US: Silicon Labs
CVE-2026-19292 (Re-pairing with a legitimate device can use a lower security level tha ...)
- TODO: check
+ NOT-FOR-US: Silicon Labs
CVE-2026-19291 (Bluetooth re-pairing with an existing device can use a lower security ...)
- TODO: check
+ NOT-FOR-US: Silicon Labs
CVE-2026-18622 (Foxit PDF Editor/Reader inconsistently alerts users when signature fie ...)
- TODO: check
+ NOT-FOR-US: Foxit
CVE-2026-18428 (A SQL query validation bypass in the Flint extension query handler in ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-18368 (In Teltonika Networks RUTOS devices, a vulnerability exists in modbusg ...)
- TODO: check
+ NOT-FOR-US: Teltonika Networks
CVE-2026-18071 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elev ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17220 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17197 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass s ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16459 (Padding oracle attack vulnerability in Oberon microsystem AG\u2019s Ob ...)
TODO: check
CVE-2026-16458 (Padding oracle attack vulnerability in Oberon microsystem AG\u2019s oc ...)
TODO: check
CVE-2026-16455 (In Teltonika Networks RUTOS devices running versions 7.07.1 through 7. ...)
- TODO: check
+ NOT-FOR-US: Teltonika Networks
CVE-2026-16101 (Spoofing an already bonded device can force either RS9116W or SiWx917 ...)
- TODO: check
+ NOT-FOR-US: Silicon Labs
CVE-2026-15994 (During an internal security assessment, an improper link following vul ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-15413 (The Link Factory WordPress plugin is a backdoor. Distributed as a "hom ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14456 (Issue summary: When an OpenSSL QUIC server (Listener SSL object) proce ...)
TODO: check
CVE-2026-14332 (The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin befor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14298 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7 ...)
TODO: check
CVE-2026-14256 (ELAN reported a potential out-of-bounds write vulnerability in the ELA ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-12908
REJECTED
CVE-2026-12263 (Zohocorp ManageEngine Password Manager Pro versions before 13232 and P ...)
- TODO: check
+ NOT-FOR-US: Zoho
CVE-2026-12236 (The Bluetooth host GATT client function parse_read_std_char_desc() in ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-12036 (An improper link following vulnerability was reported in the VantageCo ...)
- TODO: check
+ NOT-FOR-US: Lenovo
CVE-2026-11970 (This vulnerability allows a normal (non-admin) user to disable the For ...)
- TODO: check
+ NOT-FOR-US: Forcepoint
CVE-2026-11840 (Zohocorp ManageEngine Password Manager Pro versions before 13232 and M ...)
- TODO: check
+ NOT-FOR-US: Zoho
CVE-2025-62318 (HCL AION is affected by a vulnerability where JavaScript responses con ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2025-62315 (HCL AION is affected by a vulnerability where certain input fields do ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2025-62314 (HCL AION is affected by a vulnerability where certain endpoints lack s ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2025-52640 (HCL AION is affected by a vulnerability where the shared storage used ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2024-58374 (Hongjing e-HR contains an unauthenticated SQL injection vulnerability ...)
TODO: check
CVE-2019-25765 (ASP-CMS contains a SQL injection vulnerability in the commentList.asp ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71e990de0b782bc52d763127b7690421dc86b8a4
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71e990de0b782bc52d763127b7690421dc86b8a4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260813/b2164440/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list