[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 27 20:14:37 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
fa22ab95 by security tracker role at 2026-08-27T19:14:31+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -153,19 +153,19 @@ CVE-2026-81335 (Baserow dispatches an Application Builder data source without ac
 CVE-2026-81334 (darknet subscripts its layer array with an index taken from a configur ...)
 	TODO: check
 CVE-2026-81279 (Subscriber Broken Access Control in Push Notification for Post and Bud ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81277 (Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81276 (Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81274 (Subscriber Broken Access Control in Ditty <= 3.1.67 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81273 (Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81272 (Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81271 (Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81102 (The Dash MCP server bound its listener to the loopback address but nev ...)
 	TODO: check
 CVE-2026-81101 (The configure command accepted any endpoint URL and stored it beside t ...)
@@ -191,7 +191,7 @@ CVE-2026-81092 (mcp-go accepted requests on its HTTP transports without checking
 CVE-2026-81091 (The proxy middleware in mcp-use's inspector forwards requests to a des ...)
 	TODO: check
 CVE-2026-80433 (Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-80213 (An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resol ...)
 	TODO: check
 CVE-2026-80212 (An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resol ...)
@@ -207,7 +207,7 @@ CVE-2026-80208 (APITable through 1.13.0-beta.1 annotates both getUserHistories a
 CVE-2026-80207 (APITable through 1.13.0-beta.1 annotates the create handler of Interna ...)
 	TODO: check
 CVE-2026-79988 (The Twig sandbox mechanism in Craft CMS is configured to allow dangero ...)
-	TODO: check
+	NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-79720 (Reflected XSS in Netron versions <=9.1.2 on desktop application throug ...)
 	TODO: check
 CVE-2026-79719 (Reflected XSS in Netron versions <=9.1.2 on desktop application throug ...)
@@ -217,37 +217,37 @@ CVE-2026-79718 (Reflected XSS in Netron versions <=9.1.2 on desktop application
 CVE-2026-79653 (In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if t ...)
 	TODO: check
 CVE-2026-78293 (Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78292 (Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78289 (Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78288 (Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78286 (Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78285 (Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78283 (Unauthenticated Cross Site Scripting (XSS) in Music Player for WooComm ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78281 (Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78276 (Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78275 (Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78274 (Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78273 (Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78271 (Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78261 (Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plu ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78260 (Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78257 (Contributor PHP Object Injection in Booking and Rental Manager <= 2.7. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78002 (A flaw was found in rsyslog. An unauthenticated remote attacker can tr ...)
 	TODO: check
 CVE-2026-75871 (GitLab has remediated a vulnerability in the GitLab AI Gateway compone ...)
@@ -259,11 +259,11 @@ CVE-2026-75357 (An issue in Bilibili Desktop v.1.17.9 allows a remote attacker t
 CVE-2026-75159 (An unauthenticated client that can reach a MongoDB Connector for BI de ...)
 	TODO: check
 CVE-2026-75020 (Improper Neutralization of Special Elements used in an LDAP Query ('LD ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-75005 (Inefficient Algorithmic Complexity vulnerability in Apache APISIX.   A ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-74848 (Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response S ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-74233 (Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, ...)
 	TODO: check
 CVE-2026-74232 (Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.110 ...)
@@ -273,9 +273,9 @@ CVE-2026-71402 (An out-of-bounds read was found in the DHCPv4 packet capture cod
 CVE-2026-71401 (An integer underflow was found in the DHCPv4 packet capture code of wi ...)
 	TODO: check
 CVE-2026-66155 (A vulnerability has been identified in Element maps-ng V47 (All versio ...)
-	TODO: check
+	NOT-FOR-US: Siemens
 CVE-2026-64896 (Debug and Test Interface With Improper Access Control vulnerability in ...)
-	TODO: check
+	NOT-FOR-US: Johnson Controls
 CVE-2026-5738 (Improper neutralization of input during web page generation ('cross-si ...)
 	TODO: check
 CVE-2026-5680 (A flaw was found in Undertow. A remote attacker could exploit this vul ...)
@@ -289,7 +289,7 @@ CVE-2026-59354 (In versions of Spring Security's OAuth2 Authorization Server mod
 CVE-2026-59280 (Applications using Spring Framework's FreeMarker integration may be vu ...)
 	TODO: check
 CVE-2026-59272 (Any application shipping logs to RabbitMQ over TLS via the Log4j2 appe ...)
-	TODO: check
+	NOT-FOR-US: VMware
 CVE-2026-57499 (Liman is open source server management software. Prior to 2.2.2 - 1103 ...)
 	TODO: check
 CVE-2026-56652 (Dool in versions up to 1.3.8 is vulnerable to a CSV injection vulnerab ...)
@@ -299,15 +299,15 @@ CVE-2026-56651 (Dool in versions up to 1.3.8 is vulnerable tosymlink following w
 CVE-2026-40526 (Volmarg Personal Management System contains a path traversal vulnerabi ...)
 	TODO: check
 CVE-2026-34674 (Substance3D - Sampler versions 5.1.3 and earlier are affected by a Hea ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-32566 (Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32564 (Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32550 (Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-32479 (Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-30073 (An issue in the NssaiAvailabilitySubscriptionCreate component of free5 ...)
 	TODO: check
 CVE-2026-30072 (A NULL pointer dereference in the CDR processing path of free5gc v4.0. ...)
@@ -349,7 +349,7 @@ CVE-2026-30046 (A reachable assertion vulnerability in the NUDM-UECM interface o
 CVE-2026-30045 (An integer overflow in the /nnrf-disc/v1/nf-instances component of ope ...)
 	TODO: check
 CVE-2026-27330 (Unauthenticated Broken Access Control in Mobile App for WooCommerce <= ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-26899 (An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15  ...)
 	TODO: check
 CVE-2026-26897 (An issue in EcoOnline EHS (com.airsweb.v10) application for Android, v ...)
@@ -371,15 +371,15 @@ CVE-2026-19854 (When the ClickHouse plugin uses Native protocol (the default) wi
 CVE-2026-17562 (Authorization bypass through User-Controlled key vulnerability in Summ ...)
 	TODO: check
 CVE-2026-16279 (An Improper Authorization vulnerability affecting 3DPassport in 3DSwym ...)
-	TODO: check
+	NOT-FOR-US: Dassault Systemes
 CVE-2026-11754 (Observable discrepancy vulnerability in Seres Software syWEB allows Ac ...)
 	TODO: check
 CVE-2026-11747 (Improper neutralization of input during web page generation ('cross-si ...)
 	TODO: check
 CVE-2025-62343 (HCL IntelliOps Event Management (IEM) is affected by an Admin Session  ...)
-	TODO: check
+	NOT-FOR-US: HCL
 CVE-2025-62342 (HCL IntelliOps Event Management (IEM) is affected by a Session Deletio ...)
-	TODO: check
+	NOT-FOR-US: HCL
 CVE-2023-49720
 	REJECTED
 CVE-2023-49605



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fa22ab95ca61e3973db2e2f5f0a3ecd2a9a3e98f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fa22ab95ca61e3973db2e2f5f0a3ecd2a9a3e98f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/641bd21a/attachment.htm>


More information about the debian-security-tracker-commits mailing list