[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Aug 22 08:14:33 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4aa827ac by security tracker role at 2026-08-22T07:14:25+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,9 +1,9 @@
CVE-2026-9052
REJECTED
CVE-2026-77811 (Improper input validation in the dashboards-observability plugin in Op ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-77810 (In the Neptune connector, a user with access to Neptune through Athena ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-77415 (JSONata is a JSON query and transformation language. Prior to 1.8.8 an ...)
TODO: check
CVE-2026-77414 (JSONata is a JSON query and transformation language. Prior to 1.8.8 an ...)
@@ -17,11 +17,11 @@ CVE-2026-77220 (PDFio before 1.6.5 contains a dangling pointer vulnerability in
CVE-2026-77219 (GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/P ...)
TODO: check
CVE-2026-77002 (The SmilePass Selfie Login WordPress plugin through 1.0.2 does not per ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77001 (The Social Login & Sharing buttons with Analytics By SoClever WordPres ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77000 (The WP Social Media Login WordPress plugin through 1.0.6 does not veri ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-76905 (kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 un ...)
TODO: check
CVE-2026-76904 (GeoTools is an open source Java library that provides tools for geospa ...)
@@ -29,61 +29,61 @@ CVE-2026-76904 (GeoTools is an open source Java library that provides tools for
CVE-2026-76876 (Craftplan before 0.5.1 contains a broken access control vulnerability ...)
TODO: check
CVE-2026-76793 (The Firebase Authentication WordPress plugin before 1.7.1 does not req ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-76789 (The Slider Hero with Video Background, Animation WordPress plugin befo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-76074 (The AutomatorWP \u2013 Automator plugin for no-code automations, webho ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-76069
REJECTED
CVE-2026-76057 (The AutomatorWP \u2013 Automator plugin for no-code automations, webho ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75027 (The Themify Builder plugin for WordPress is vulnerable to authorizatio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-74252 (Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2 ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-73323
REJECTED
CVE-2026-69238 (There is an HTML injection vulnerability in Esri Portal for ArcGIS ver ...)
- TODO: check
+ NOT-FOR-US: Esri
CVE-2026-69237 (There is an HTML injection vulnerability in Esri Portal for ArcGIS ver ...)
- TODO: check
+ NOT-FOR-US: Esri
CVE-2026-69236 (There is a stored cross site scripting issue in Esri Portal for ArcGIS ...)
- TODO: check
+ NOT-FOR-US: Esri
CVE-2026-69235 (There is a stored cross site scripting issue in Esri Portal for ArcGIS ...)
- TODO: check
+ NOT-FOR-US: Esri
CVE-2026-69234 (There is a reflected cross site scripting vulnerability in Esri Portal ...)
- TODO: check
+ NOT-FOR-US: Esri
CVE-2026-69233 (There is a stored cross site scripting issue in Esri Portal for ArcGIS ...)
- TODO: check
+ NOT-FOR-US: Esri
CVE-2026-69232 (There is a stored cross site scripting issue in Esri Portal for ArcGIS ...)
- TODO: check
+ NOT-FOR-US: Esri
CVE-2026-69231 (There is a stored cross site scripting issue in Esri Portal for ArcGIS ...)
- TODO: check
+ NOT-FOR-US: Esri
CVE-2026-69230 (There is a stored cross site scripting issue in Esri Portal for ArcGIS ...)
- TODO: check
+ NOT-FOR-US: Esri
CVE-2026-69229 (There is an HTML injection vulnerability in Esri Portal for ArcGIS ver ...)
- TODO: check
+ NOT-FOR-US: Esri
CVE-2026-69228 (There is a missing authentication vulnerability in Esri Portal for Arc ...)
- TODO: check
+ NOT-FOR-US: Esri
CVE-2026-69225 (There is an information disclosure vulnerability in Esri Portal for Ar ...)
- TODO: check
+ NOT-FOR-US: Esri
CVE-2026-69224 (There is an information disclosure vulnerability in Esri Portal for Ar ...)
- TODO: check
+ NOT-FOR-US: Esri
CVE-2026-68508 (Hydra is a framework for elegantly configuring complex applications. P ...)
TODO: check
CVE-2026-67619
REJECTED
CVE-2026-67362 (Joomla Extension - j2commerce.com - Open redirect in cart controller i ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-67361 (Joomla Extension - j2commerce.com - Unauthenticated file upload with m ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-67360 (Joomla Extension - j2commerce.com - Cross-customer order replication i ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-67359 (Joomla Extension - j2commerce.com - Order content disclosure J2Store 1 ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-67358 (Joomla Extension - j2commerce.com - Download quota manipulation in J2S ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-64679 (Atlantis is a self-hosted golang application that listens for Terrafor ...)
TODO: check
CVE-2026-63421 (Keystone is a content management system for Node.js. Prior to 6.5.3, t ...)
@@ -193,23 +193,23 @@ CVE-2026-27463 (Combodo iTop is a web based IT service management tool. Prior to
CVE-2026-27462 (Combodo iTop is a web based IT service management tool. Prior to 3.2.3 ...)
TODO: check
CVE-2026-19883 (The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to u ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19222 (The Forminator Forms WordPress plugin before 1.57.0.7 does not consis ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19221 (The Forminator Forms WordPress plugin before 1.57.0.5 does not restri ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19093 (The Tutor LMS WordPress plugin before 4.0.6 does not validate a store ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18052 (The ManageWP Worker WordPress plugin before 4.9.37 does not bind the a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16738 (The Conekta Payment Gateway WordPress plugin before 6.2.2 does not ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16612 (The FiboSearch WordPress plugin before 1.34.1 does not consistently e ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16260 (The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14187 (The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-obje ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-11805
REJECTED
CVE-2026-11615
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4aa827ac583f5034123fb97b18fd2a4c07c3c576
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4aa827ac583f5034123fb97b18fd2a4c07c3c576
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260822/a58ac258/attachment.htm>
More information about the debian-security-tracker-commits
mailing list