[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 18 20:14:03 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
29a025a1 by security tracker role at 2026-08-18T19:13:58+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -17,7 +17,7 @@ CVE-2026-75904 (libmodplug through 0.8.9.1 contains an out-of-bounds read in pat
 CVE-2026-75898 (RAGFlow before 0.26.3 contains a server-side request forgery vulnerabi ...)
 	TODO: check
 CVE-2026-75897 (Improper input validation in the capabilities route handler in OpenSea ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-75890
 	REJECTED
 CVE-2026-75874 (Sandbox escape in the Remote Settings Client component. This vulnerabi ...)
@@ -85,11 +85,11 @@ CVE-2026-75828 (Grav before 2.0.15 contains a stored cross-site scripting vulner
 CVE-2026-75827 (Grav before 2.0.15 contains an arbitrary file write vulnerability in t ...)
 	TODO: check
 CVE-2026-75784 (A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affecte ...)
-	TODO: check
+	NOT-FOR-US: TRENDnet
 CVE-2026-75783 (A security vulnerability has been detected in TRENDnet TEW-WLC100P 12. ...)
-	TODO: check
+	NOT-FOR-US: TRENDnet
 CVE-2026-75778 (A vulnerability was identified in code-projects Task Management System ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-75774 (A vulnerability was determined in karakeep-app karakeep up to 0.32.0.  ...)
 	TODO: check
 CVE-2026-75773 (A vulnerability was found in karakeep-app karakeep up to 0.32.0. The a ...)
@@ -227,15 +227,15 @@ CVE-2026-74908 (Grav plugin-api before 1.0.15 contains a script injection vulner
 CVE-2026-74907 (Grav before 2.0.15 contains a path traversal vulnerability in the stat ...)
 	TODO: check
 CVE-2026-74906 (SiYuan before v3.7.4 contains an incorrect authorization vulnerability ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-74905 (SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vul ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-74904 (SiYuan before v3.7.4 is missing authorization checks in 17 block metad ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-74903 (SiYuan before v3.7.4 contains an insufficient access control vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-74902 (SiYuan before v3.7.4 contains a cross-site scripting vulnerability in  ...)
-	TODO: check
+	NOT-FOR-US: SiYuan
 CVE-2026-74046 (Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability i ...)
 	TODO: check
 CVE-2026-74044 (Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that ...)
@@ -245,29 +245,29 @@ CVE-2026-74039 (Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of se
 CVE-2026-74038 (Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that ...)
 	TODO: check
 CVE-2026-74015 (Unauthenticated SQL Injection in Readabler < 2.0.18 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74012 (Editor PHP Object Injection in TaxoPress <= 3.51.0 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74009 (Unauthenticated Insecure Direct Object References (IDOR) in Razorpay f ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74008 (Unauthenticated Sensitive Data Exposure in Shortcodes and extra featur ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74007 (Unauthenticated Sensitive Data Exposure in 3D FlipBook \u2013 PDF Flip ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74006 (Contributor Broken Access Control in WP Table Builder <= 2.2.0 version ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74004 (Subscriber Broken Access Control in Gravity Booster – Styles &am ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-74003 (Contributor Broken Access Control in RomethemeForm For Elementor <= 1. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73997 (Unauthenticated Denial of Service Attack in Starter Templates by Kaden ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73996 (Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 vers ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73995 (Subscriber Broken Authentication in User Registration <= 5.2.6 version ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73994 (Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73834 (A flaw was found in the must-gather component of Red Hat Advanced Clus ...)
 	TODO: check
 CVE-2026-73692
@@ -277,105 +277,105 @@ CVE-2026-73502 (kin-openapi is a Go project for handling OpenAPI files. From 0.2
 CVE-2026-73426 (Trix is a what-you-see-is-what-you-get rich text editor for everyday w ...)
 	TODO: check
 CVE-2026-73404 (Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73400 (Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress < ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73399 (Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73398 (Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Paym ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73397 (Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73396 (Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73395 (Unauthenticated Insecure Direct Object References (IDOR) in Booking ca ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73393 (Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 vers ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73392 (Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73383 (Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73382 (Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 ve ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73381 (Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73380 (Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73379 (Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73378 (Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsysti ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73377 (Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73376 (Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73375 (Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsyst ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73373 (Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joo ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-73372 (Joomla! Core - [20260809] - Improper ACL checks when injection schema. ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-73371 (Joomla! Core - [20260808] - Improper ACL checks for batch copy actions ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-73367 (Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 ver ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73366 (Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 ver ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73365 (Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73362 (Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 ve ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73361 (Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for G ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73360 (Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73359 (Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CC ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73358 (Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73356 (Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 version ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73355 (Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73352 (Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73351 (Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73350 (Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 version ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73348 (Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73345 (Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 ve ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73343 (Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73342 (Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73341 (Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73339 (Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73338 (Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 version ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73337 (Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0- ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-73336 (Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5 ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-73190 (Unauthenticated Cross Site Scripting (XSS) in WPDM \u2013 Premium Pack ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73189 (Subscriber Insecure Direct Object References (IDOR) in WP Crowdfunding ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73187 (Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73181 (Unauthenticated Arbitrary File Download in Extra Product Options & Add ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-73073 (Vim is an open source, command line text editor. Prior to 9.2.0845, St ...)
 	TODO: check
 CVE-2026-72532 (Joomla! Core - [20260806] - Improper ACL checks for category webservic ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-72531 (Joomla! Core - [20260804] - Improper ACL checks for custom fields webs ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-71880 (Interpretation of untrusted input in template engine in GBIF Integrate ...)
 	TODO: check
 CVE-2026-71879 (Missing authentication in initial setup functionality left exposed unt ...)
@@ -383,15 +383,15 @@ CVE-2026-71879 (Missing authentication in initial setup functionality left expos
 CVE-2026-71878 (Missing authentication in initial setup functionality left exposed aft ...)
 	TODO: check
 CVE-2026-71574 (Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webse ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-71573 (Joomla! Core - [20260802] - Improper CORS origin validation in Joomla  ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-71572 (Joomla! Core - [20260801] - Response header injection in download view ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-71551 (Super Productivity is an advanced todo list app with integrated timebo ...)
 	TODO: check
 CVE-2026-71539 (n8n is an open source workflow automation platform. Prior to 1.123.64, ...)
-	TODO: check
+	NOT-FOR-US: n8n
 CVE-2026-71477 (mise manages dev tools like node, python, cmake, and terraform. Prior  ...)
 	TODO: check
 CVE-2026-71365 (A server-side request forgery (SSRF) vulnerability was found in AWX's  ...)
@@ -401,7 +401,7 @@ CVE-2026-70667 (Lemur manages TLS certificate creation. Prior to 1.9.3, _validat
 CVE-2026-70657 (Copyparty is a portable file server. Prior to 1.20.17, copyparty volum ...)
 	TODO: check
 CVE-2026-70415 (Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-69220 (The RabbitMQ Java client library allows Java and JVM-based application ...)
 	TODO: check
 CVE-2026-69219 (The RabbitMQ Java client library allows Java and JVM-based application ...)
@@ -421,11 +421,11 @@ CVE-2026-68923 (MobSF is a mobile application security testing tool used. Prior
 CVE-2026-68922 (MobSF is a mobile application security testing tool used. Prior to 4.5 ...)
 	TODO: check
 CVE-2026-68568 (Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-68567 (Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 ver ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-68565 (Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 vers ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-67921 (Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS ver ...)
 	TODO: check
 CVE-2026-67920 (An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary  ...)
@@ -433,9 +433,9 @@ CVE-2026-67920 (An issue in Halo 2.25.4 allows a remote attacker to execute arbi
 CVE-2026-67846 (Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb ...)
 	TODO: check
 CVE-2026-67271 (Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability i ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-67262 (Dell PowerStore contains a Missing Authorization vulnerability. An att ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-66793 (A flaw was found in the governance-policy-addon-controller component o ...)
 	TODO: check
 CVE-2026-66783 (A flaw was found in the `submariner-operator` component of Red Hat Adv ...)
@@ -447,47 +447,47 @@ CVE-2026-66781 (A flaw was found in the Submariner operator. The Submariner Cust
 CVE-2026-66780 (A flaw was found in the submariner-operator component. The `submariner ...)
 	TODO: check
 CVE-2026-66679 (Unauthenticated Broken Access Control in Appointment Hour Booking <= 1 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66667 (Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 vers ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66651 (Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66646 (Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 vers ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66645 (Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66644 (Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66643 (Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 vers ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66641 (Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66640 (Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 ver ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66639 (Contributor Cross Site Scripting (XSS) in WPZOOM Forms \u2013 Contact  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66638 (Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66637 (Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66636 (Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66635 (Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web < ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66634 (Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66633 (Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66629 (Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66627 (Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66622 (Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66621 (Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66620 (Editor PHP Object Injection in OptionTree <= 2.7.3 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66046 (Expat through 2.8.3 contains a denial of service vulnerability caused  ...)
 	TODO: check
 CVE-2026-65959 (Vitess is a database clustering system for horizontal scaling of MySQL ...)
@@ -523,7 +523,7 @@ CVE-2026-61634 (The RabbitMQ Java client library allows Java and JVM-based appli
 CVE-2026-61574 (authentik is an open-source identity provider. Prior to 2026.2.6 and 2 ...)
 	TODO: check
 CVE-2026-61407 (Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Expose ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-5224 (Cleartext storage of sensitive information vulnerability in Kriptok Cr ...)
 	TODO: check
 CVE-2026-59949 (yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JN ...)
@@ -617,113 +617,113 @@ CVE-2026-48744 (Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.
 CVE-2026-48508 (Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePerm ...)
 	TODO: check
 CVE-2026-47630 (NVIDIA Triton Inference Server for Linux contains a vulnerability wher ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-47629 (NVIDIA Triton Inference Server for Linux contains a vulnerability wher ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-47628 (NVIDIA Triton Inference Server for Linux contains a vulnerability wher ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-47627 (NVIDIA Triton Inference Server for Linux contains a vulnerability wher ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-47606 (NVIDIA Triton Inference Server for Linux contains a vulnerability wher ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-47245 (MyBB is free and open source forum software. Prior to 1.8.40, the User ...)
-	TODO: check
+	NOT-FOR-US: MyBB
 CVE-2026-46482 (### Impact The registration component does not validate the text-based ...)
-	TODO: check
+	NOT-FOR-US: MyBB
 CVE-2026-45734 (MyBB is free and open source forum software. Prior to 1.8.40, the buil ...)
-	TODO: check
+	NOT-FOR-US: MyBB
 CVE-2026-45733 (Trilium Notes is a cross-platform, hierarchical note taking applicatio ...)
 	TODO: check
 CVE-2026-45532 (DataEase is an open source data visualization and analysis tool. Versi ...)
-	TODO: check
+	NOT-FOR-US: DataEase
 CVE-2026-45129 (MyBB is free and open source forum software. Prior to 1.8.40, the Admi ...)
-	TODO: check
+	NOT-FOR-US: MyBB
 CVE-2026-45128 (MyBB is free and open source forum software. Prior to 1.8.40, the ACP  ...)
-	TODO: check
+	NOT-FOR-US: MyBB
 CVE-2026-45127 (MyBB is free and open source forum software. Prior to 1.8.40, the ACP  ...)
-	TODO: check
+	NOT-FOR-US: MyBB
 CVE-2026-45126 (MyBB is free and open source forum software. Prior to 1.8.40, the Admi ...)
-	TODO: check
+	NOT-FOR-US: MyBB
 CVE-2026-45125 (MyBB is free and open source forum software. Prior to 1.8.40, the Emai ...)
-	TODO: check
+	NOT-FOR-US: MyBB
 CVE-2026-45124 (MyBB is free and open source forum software. Prior to 1.8.40, the Mod  ...)
-	TODO: check
+	NOT-FOR-US: MyBB
 CVE-2026-45123 (MyBB is free and open source forum software. Prior to 1.8.40, the remo ...)
-	TODO: check
+	NOT-FOR-US: MyBB
 CVE-2026-45122 (MyBB is free and open source forum software. Prior to 1.8.40, the cale ...)
-	TODO: check
+	NOT-FOR-US: MyBB
 CVE-2026-45121 (MyBB is free and open source forum software. Prior to 1.8.40, the cale ...)
-	TODO: check
+	NOT-FOR-US: MyBB
 CVE-2026-45120 (MyBB is free and open source forum software. Prior to 1.8.40, the cale ...)
-	TODO: check
+	NOT-FOR-US: MyBB
 CVE-2026-45119 (MyBB is free and open source forum software. Prior to 1.8.40, the Admi ...)
-	TODO: check
+	NOT-FOR-US: MyBB
 CVE-2026-45118 (MyBB is free and open source forum software. Prior to 1.8.40, the Cont ...)
-	TODO: check
+	NOT-FOR-US: MyBB
 CVE-2026-45117 (MyBB is free and open source forum software. From 1.8.13 until 1.8.40, ...)
-	TODO: check
+	NOT-FOR-US: MyBB
 CVE-2026-45116 (MyBB is free and open source forum software. Prior to 1.8.40, the user ...)
-	TODO: check
+	NOT-FOR-US: MyBB
 CVE-2026-45115 (MyBB is free and open source forum software. Prior to 1.8.40, the Budd ...)
-	TODO: check
+	NOT-FOR-US: MyBB
 CVE-2026-44472 (Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.6 ...)
 	TODO: check
 CVE-2026-43971 (Improper Encoding or Escaping of Output vulnerability in ninenines cow ...)
 	TODO: check
 CVE-2026-34884 (SSRF via set_skywalking_url Tool and GraphQL expression injection vuln ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-32657 (Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-32553 (Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.3 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32549 (Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32547 (Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32481 (Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32474 (Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32473 (Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32472 (Unauthenticated Broken Access Control in Online Contact Widget <= 1.3. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32470 (Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32468 (Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32467 (Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32466 (Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 vers ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32465 (Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32464 (Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 vers ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32463 (Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32444 (Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32333 (Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 ve ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-30250 (Cross-site scripting vulnerability in the user documentation field in  ...)
 	TODO: check
 CVE-2026-28571 (Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28570 (Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28569 (Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28568 (Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 ver ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28567 (Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28192 (Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28191 (Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-24301 (Improper neutralization of special elements used in a command ('comman ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-24185 (NVIDIA NVOS for network switches contains a vulnerability in the secur ...)
 	TODO: check
 CVE-2026-24184 (NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discov ...)
@@ -765,7 +765,7 @@ CVE-2026-18963 (A flaw was found in the reset-credentials flow of the keycloak-s
 CVE-2026-18929 (Carbone is vulnerable to Denial of Service due to lack of protection a ...)
 	TODO: check
 CVE-2026-18751 (External control of file name or path vulnerability in Citrix WorkSpac ...)
-	TODO: check
+	NOT-FOR-US: Citrix
 CVE-2026-18534 (ArcSearch for iOS versions prior to 1.48.0 could keep the address bar  ...)
 	TODO: check
 CVE-2026-18392



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/29a025a1789d61171a7c19af1e6d09ace8d79307

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/29a025a1789d61171a7c19af1e6d09ace8d79307
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260818/e49fc5fc/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list