[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 15 08:13:42 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7d0ed139 by security tracker role at 2026-08-15T07:13:36+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
 CVE-2026-8840 (The Booking calendar, Appointment Booking System plugin for WordPress  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-74250 (In OpenStack Ironic before 38.0.1, the autodetect deploy interface may ...)
 	TODO: check
 CVE-2026-74248 (OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) p ...)
@@ -29,23 +29,23 @@ CVE-2026-73679 (ImpressCMS contains an authenticated remote code execution vulne
 CVE-2026-73678 (MindsDB Minds Platform version 26.1.0 and earlier contains an unauthen ...)
 	TODO: check
 CVE-2026-71571 (Joomla Extension - icagenda.com -  Authenticated SQL injection via une ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-71570 (Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user e ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-69414 (Microsoft is aware of an elevation of privilege in the Microsoft Malwa ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-67366 (Joomla Extension - icagenda.com - CSRF on frontend registration action ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-67365 (Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCa ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-64887 (Use of hard-coded cryptographic key vulnerability in Johnson Controls  ...)
-	TODO: check
+	NOT-FOR-US: Johnson Controls
 CVE-2026-63650 (OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authentic ...)
 	TODO: check
 CVE-2026-63649 (The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2. ...)
 	TODO: check
 CVE-2026-50523 (Improper neutralization of special elements used in a command ('comman ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-50029 (js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the i ...)
 	TODO: check
 CVE-2026-50027 (mcp-memory-service is a semantic memory layer for AI applications. Pri ...)
@@ -53,9 +53,9 @@ CVE-2026-50027 (mcp-memory-service is a semantic memory layer for AI application
 CVE-2026-39925
 	REJECTED
 CVE-2026-34492 (External control of file name or path vulnerability in Johnson Control ...)
-	TODO: check
+	NOT-FOR-US: Johnson Controls
 CVE-2026-27871 (Cwe-327 Use of a Broken or Risky Cryptographic Algorithm vulnerability ...)
-	TODO: check
+	NOT-FOR-US: Johnson Controls
 CVE-2026-19910 (PAX Technology Q80 Application Installer Signature Verification Bypass ...)
 	TODO: check
 CVE-2026-19909 (PAX Technology Q80 AIP File Parsing Link Following Remote Code Executi ...)
@@ -65,99 +65,99 @@ CVE-2026-19908 (PAX Technology Q80 XCB Daemon Missing Authentication Vulnerabili
 CVE-2026-18932
 	REJECTED
 CVE-2026-18807 (The ECS  WordPress plugin before 4.3.8 does not have capability or own ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18554 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authentica ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18387 (The Groundhogg \u2014 CRM, Newsletters, and Marketing Automation plugi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18216 (The Backup Migration WordPress plugin before 2.1.7 does not properly r ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18178 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authentica ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17227 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authentica ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17209 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authentica ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17186 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker t ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17184 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker t ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17182 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker t ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17181 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker t ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17179 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authentica ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17177 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker t ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17175 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authentica ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17173 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authentica ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17090 (The Beaver Builder Page Builder \u2013 Drag and Drop Website Builder p ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-17081 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker t ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17079 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authentica ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16915 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authentica ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16905 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authentica ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16879 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authentica ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16708 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker t ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16611 (The Product Feed PRO for WooCommerce by AdTribes  WordPress plugin bef ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16586 (The Contest Gallery \u2013 Upload & Vote Photos, Media, Sell with PayP ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16541 (The Simply Schedule Appointments WordPress plugin before 1.6.12.17 doe ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16146 (The Invisible Anti-Spam & CAPTCHA \u2014 reCAPTCHA Alternative for All ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16145 (The Invisible Anti-Spam & CAPTCHA \u2014 reCAPTCHA Alternative for All ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16094 (The Invisible Anti-Spam & CAPTCHA \u2014 reCAPTCHA Alternative for All ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16080 (The Image Uploader for Welcart plugin for WordPress is vulnerable to g ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16007 (AppFlowy's qcuiknote feature is affected by a SQL injection vulnerabil ...)
 	TODO: check
 CVE-2026-15993 (The Form Maker by 10Web \u2013 Mobile-Friendly Drag & Drop Contact For ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15965 (The MaxUpload \u2013 Big File Uploads \u2013 Increase Maximum File Upl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15948 (The Hydra Booking \u2014 Appointment Scheduling & Booking Calendar plu ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15826 (The User Profile Builder plugin for WordPress is vulnerable to Authent ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15453 (The KiviCare \u2013 Clinic & Patient Management System (EHR) plugin fo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15341 (The User Session Synchronizer plugin for WordPress is vulnerable to Au ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15312 (The Propovoice: All-in-One Client Management System plugin for WordPre ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15303 (The 6Storage Rentals plugin for WordPress is vulnerable to authenticat ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15162 (The Object Sync for Salesforce plugin is vulnerable to unauthenticated ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15001 (The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vul ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14484 (The RapiSafe \u2013 Secure Multi File Upload for Contact Form 7 plugin ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14433 (The Online Booking & Scheduling Calendar for WordPress by vcita plugin ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14279 (The Wholesale Market plugin for WordPress is vulnerable to privilege e ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14230 (The ECS  WordPress plugin before 4.3.8 does not perform capability or  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14229 (The ECS  WordPress plugin before 4.3.8 does not check the post status  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13360 (The Cookie Banner for GDPR / CCPA \u2013 WPLP Cookie Consent plugin fo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12128 (The Pinpoint Booking System \u2013 Version 2 plugin for WordPress is v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19720
 	- inetutils <unfixed>
 	[trixie] - inetutils <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7d0ed139ee263b79354579dc927863d5a37a0b0e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7d0ed139ee263b79354579dc927863d5a37a0b0e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260815/9b67d1a8/attachment.htm>


More information about the debian-security-tracker-commits mailing list