[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Aug 16 08:14:41 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
56517421 by security tracker role at 2026-08-16T07:14:35+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
CVE-2026-9767 (The The School Management \u2013 Education & Learning ERP plugin for W ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-74767 (Pandora contains a denial-of-service vulnerability in its handling of ...)
TODO: check
CVE-2026-74764 (Pandora contains a path traversal vulnerability in its TAR archive ext ...)
@@ -7,43 +7,43 @@ CVE-2026-74764 (Pandora contains a path traversal vulnerability in its TAR archi
CVE-2026-73055 (Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly esca ...)
TODO: check
CVE-2026-73054 (SiYuan versions before v3.7.4 contain an authentication bypass vulnera ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73053 (SiYuan versions before v3.7.4 contain a cross-site scripting vulnerabi ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73052 (SiYuan before v3.7.4 stores attribute-view field names without HTML es ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73050 (SiYuan versions before v3.7.4 fail to validate or escape the color fie ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73047 (siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side templ ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73046 (SiYuan before v3.7.4 improperly restricts excessive authentication att ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73045 (SiYuan before 3.7.4 contains an improper restriction of excessive auth ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73044 (SiYuan versions before v3.7.4 fail to validate or escape table column ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73043 (SiYuan versions before v3.7.4 contain a remote code execution vulnerab ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73042 (SiYuan before v3.7.4 fails to properly escape database menu metadata i ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-73041 (SiYuan versions before v3.7.4 fail to validate or escape annotation fi ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-2497 (The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL I ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-2487 (The Admin Custom Login plugin for WordPress is vulnerable to Stored Cr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-2357 (The Bold Page Builder plugin for WordPress is vulnerable to Stored Cro ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-2283 (The User Login History plugin for WordPress is vulnerable to SQL Injec ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19934 (A vulnerability has been found in itsourcecode Hospital Management Sys ...)
- TODO: check
+ NOT-FOR-US: itsourcecode System
CVE-2026-19933 (A weakness has been identified in DefaultFuction Customer-Relationship ...)
TODO: check
CVE-2026-19932 (A security flaw has been discovered in DefaultFuction Notice-System-Ma ...)
TODO: check
CVE-2026-19930 (A security flaw has been discovered in Dolibarr up to 23.0.3. Affected ...)
- TODO: check
+ NOT-FOR-US: Dolibarr
CVE-2026-19929 (A vulnerability was identified in OpenBoxes up to 0.9.6. This impacts ...)
TODO: check
CVE-2026-19928 (A vulnerability was determined in OpenBoxes up to 0.9.7. This affects ...)
@@ -53,131 +53,131 @@ CVE-2026-19927 (A vulnerability was found in OpenBoxes up to 0.9.7. The impacted
CVE-2026-19926 (A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16 ...)
TODO: check
CVE-2026-19925 (A vulnerability was detected in SourceCodester Stock Management System ...)
- TODO: check
+ NOT-FOR-US: SourceCodester
CVE-2026-19924 (A security vulnerability has been detected in Tenda AC10 16.03.10.09_m ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-19923 (A weakness has been identified in code-projects Online Shopping System ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-19922 (A security flaw has been discovered in code-projects Online Shopping S ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-19921 (A vulnerability was identified in code-projects Online Shopping System ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-19920 (A vulnerability was determined in code-projects Online Shopping System ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-19919 (A vulnerability was found in code-projects Online Shopping System 1.0. ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-19918 (A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11 ...)
TODO: check
CVE-2026-19917 (A flaw has been found in code-projects Online Food Order System 1.0. T ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-19916 (A vulnerability was detected in code-projects Online Food Order System ...)
- TODO: check
+ NOT-FOR-US: code-projects
CVE-2026-19728 (The Extra Product Options Builder for WooCommerce WordPress plugin bef ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19726 (The Visualizer WordPress plugin before 4.0.7 does not properly author ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19725 (The WPvivid \u2014 Backup, Migration & Staging WordPress plugin before ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19717 (The CatFolders Document Gallery & PDF Library WordPress plugin before ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19714 (The Simple JWT Login WordPress plugin before 3.6.8 does not validate ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19712 (The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19711 (The Premium Packages WordPress plugin before 7.0.7 does not validate ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19613 (The ECS WordPress plugin before 4.3.10 does not perform ownership or ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18653 (The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18432 (The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18402 (The SureDash \u2013 Community, Courses & Member Dashboard plugin for W ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18385 (The The Paid Membership Plugin, Ecommerce, User Registration Form, Log ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18347 (The Kirki \u2013 Freeform Page Builder, Website Builder & Customizer p ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18316 (The Solace Extra plugin for WordPress is vulnerable to unauthorized mo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17608 (The WP Compress \u2013 Instant Performance & Speed Optimization plugin ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17604 (The Kirki \u2013 Freeform Page Builder, Website Builder & Customizer p ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17582 (The Slider Hero plugin for WordPress is vulnerable to second-order SQL ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17581 (The WCPOS \u2013 Point of Sale (POS) plugin for WooCommerce plugin for ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17533 (The All-in-One WP Migration and Backup WordPress plugin before 7.108 d ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17123 (The Royal Elementor Addons plugin for WordPress is vulnerable to Serve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17087 (The WP Travel Engine \u2013 Tour Booking Plugin \u2013 Tour Operator S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16779 (The Kubio AI Page Builder plugin for WordPress is vulnerable to author ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16775 (The Smash Balloon Social Post Feed \u2013 Simple Social Feeds for Word ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16758 (The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16099 (The Podlove Podcast Publisher plugin for WordPress is vulnerable to ar ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16098 (The ProSolution WP Client plugin for WordPress is vulnerable to Arbitr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16079 (The Fullscreen Galleria plugin for WordPress is vulnerable to generic ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15963 (The Quiz and Survey Master (QSM) \u2013 Easy Quiz and Survey Maker plu ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15790 (The Youtube Showcase plugin for WordPress is vulnerable to Stored Cros ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15726 (The Serious Slider plugin for WordPress is vulnerable to Stored Cross- ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15604 (The Toocheke Companion plugin for WordPress is vulnerable to Stored Cr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15602 (The NEX-Forms \u2013 Ultimate Forms Plugin for WordPress plugin for Wo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15441 (The WC Product Table Lite plugin for WordPress is vulnerable to CSS In ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15384 (The Manual Image Crop WordPress plugin before 1.15 does not perform an ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15351 (The WC Vendors \u2013 WooCommerce Multivendor, WooCommerce Marketplace ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15345 (The ShortPixel Adaptive Images \u2013 WebP, AVIF, CDN, Image Optimizat ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15066 (The Loco Translate plugin for WordPress is vulnerable to Stored Cross- ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15056 (The StoreEngine \u2014 Complete eCommerce Solution with Memberships, L ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15009 (The Advanced File Manager \u2013 Ultimate File Manager for WordPress A ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15002 (The Platnosci Online Blue Media (Autopay) plugin for WordPress is vuln ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14524 (The ProSolution WP Client plugin for WordPress is vulnerable to arbitr ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14498 (The Query Wrangler plugin for WordPress is vulnerable to Remote Code E ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13712 (The Divi WordPress theme before 5.9.0 does not properly escape some of ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13424 (The Online Scheduling and Appointment Booking System \u2013 Bookly plu ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13358 (The Appointment Booking Calendar \u2014 Simply Schedule Appointments B ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13167 (The Everest Forms \u2013 Contact Form, Payment Form, Quiz, Survey & Cu ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12998 (The Forminator Forms \u2013 Contact Form, Payment Form & Custom Form B ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12905 (The Bookly plugin for WordPress is vulnerable to Insecure Direct Objec ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12477 (The Gravity Booster \u2013 Styles & Layouts for Gravity Forms plugin f ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-11780 (The Quiz and Survey Master (QSM) \u2013 Easy Quiz and Survey Maker plu ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-10734 (The Infility Global plugin for WordPress is vulnerable to Stored Cross ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-10035 (The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2025-10005 (The PPWP \u2013 Password Protect WordPress | #1 Most-Reviewed Password ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-73635 (Allocation of resources without limits or throttling vulnerability in ...)
- libstruts1.2-java <removed>
NOTE: https://cwiki.apache.org/confluence/display/WW/S2-074
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5651742136aff182feb9eefd7d0ae9a3cd6dbdb5
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5651742136aff182feb9eefd7d0ae9a3cd6dbdb5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260816/a0d2d801/attachment.htm>
More information about the debian-security-tracker-commits
mailing list