[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 28 20:15:08 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
efd784d9 by security tracker role at 2026-08-28T19:14:53+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
CVE-2026-9548 (An improper neutralization of input during web page generation ('Cross ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-9491 (A server-ide request forgery (SSRF) vulnerability in webhook in Synolo ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-82330 (A flaw was found in the file-pvr plugin in GIMP. When processing a spe ...)
TODO: check
CVE-2026-82328 (A flaw was found in the file-ico plugin in GIMP. When processing a spe ...)
@@ -65,15 +65,15 @@ CVE-2026-82236 (File Browser versions from 2.63.6 through 2.63.23 fail to clean
CVE-2026-82235 (filebrowser through 2.63.23 fails to validate named pipes in directory ...)
TODO: check
CVE-2026-82234 (SiYuan versions before v3.8.1 contain a server-side request forgery vu ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-82233 (SiYuan before v3.8.1 contains a path traversal vulnerability in the as ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-82227 (Contributor SQL Injection in WPBulky <= 1.2.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-82222 (Deserialization of Untrusted Data vulnerability in Liquid Web / Stella ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-82220 (Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-82181 (Medical Practice Management System developed by Le-yan has a Sensitive ...)
TODO: check
CVE-2026-82123 (Improper neutralization of input during web page generation ('cross-si ...)
@@ -85,17 +85,17 @@ CVE-2026-82111 (A vulnerability was detected in iswalle getnote-mcp up to 1.5.0.
CVE-2026-82078 (An unsafe dynamic class loading vulnerability exists in the database c ...)
TODO: check
CVE-2026-81777 (Authentication Bypass by Spoofing vulnerability in WPDeveloper Essenti ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81767 (Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81761 (Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81760 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81759 (Contributor Broken Access Control in WpEvently <= 5.5.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81757 (Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81733 (WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a ...)
TODO: check
CVE-2026-81732 (WWBN AVideo through version 30.0 fails to enforce authentication on th ...)
@@ -105,41 +105,41 @@ CVE-2026-81578 (An improper access control vulnerability exists in the web manag
CVE-2026-81341 (wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 ...)
TODO: check
CVE-2026-81299 (Subscriber Insecure Direct Object References (IDOR) in WP Job Portal < ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81285 (Unauthenticated Denial of Service Attack in Smush Image Compression an ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81284 (Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81020 (wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce on ...)
TODO: check
CVE-2026-81019 (wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce ...)
TODO: check
CVE-2026-79996 (The User Registration & Membership WordPress plugin before 5.2.6 does ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-79995 (The User Registration & Membership WordPress plugin before 5.2.5 does ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-79706 (The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a va ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-79615 (The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-78238 (SOY Gallery contains a cross-site scripting vulnerability. An arbitra ...)
TODO: check
CVE-2026-78073 (Joomla Extension - mrvinoth.com - Reflected XSS in All Video Share 1.0 ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-78072 (Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Po ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-78071 (Joomla Extension - digital-peak.com - Authenticated, privileged stored ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-78070 (Joomla Extension - digital-peak.com - Authenticated, privileged blind ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-78032 (SOY CMS contains an issue with deserialization of untrusted data. An ...)
TODO: check
CVE-2026-77838 (SOY Calendar contains a cross-site scripting vulnerability. An arbitra ...)
TODO: check
CVE-2026-77701 (The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-76581 (The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentic ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75758 (Uncontrolled Recursion vulnerability in the Elixir standard library al ...)
TODO: check
CVE-2026-73827 (SOY Calendar contains a cross-site scripting vulnerability. An arbitra ...)
@@ -149,27 +149,27 @@ CVE-2026-73209 (An attacker that has valid credentials can send crafted compress
CVE-2026-73208 (An attacker that holds a token intended for a different purpose can au ...)
TODO: check
CVE-2026-6286 (The Booking for Appointments and Events Calendar \u2013 Amelia plugin ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-6176 (The Customer Reviews for WooCommerce plugin for WordPress is vulnerabl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-6128 (The All-in-One WP Migration Unlimited Extension plugin for WordPress i ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-5953 (Improper neutralization of input during web page generation ('cross-si ...)
TODO: check
CVE-2026-5934 (The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-5800 (Improper neutralization of input during web page generation ('cross-si ...)
TODO: check
CVE-2026-5510 (The GiveWP \u2013 Donation Plugin and Fundraising Platform plugin for ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-5097 (The wpForo Forum plugin for WordPress is vulnerable to SQL Injection v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-5096 (The Everest Forms plugin for WordPress is vulnerable to Server-Side Re ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-58107 (CodeChecker'smassStoreRunprocessing path performs one-shot decompressi ...)
- TODO: check
+ NOT-FOR-US: Ericsson
CVE-2026-58106 (CVE-2025-40843 https://github.com/advisories/GHSA-5xf2-f6ch-6p8r was f ...)
- TODO: check
+ NOT-FOR-US: Ericsson
CVE-2026-56854 (The source-address critical option in the Permissions returned by an a ...)
TODO: check
CVE-2026-52687 (An attacker that has valid credentials can select a compression algori ...)
@@ -181,7 +181,7 @@ CVE-2026-50979 (A command injection vulnerability in the 'advanced/curl' compone
CVE-2026-4378 (Improper neutralization of input during web page generation ('cross-si ...)
TODO: check
CVE-2026-4246 (The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-42395 (A host listed as a trusted proxy can send forwarding information conta ...)
TODO: check
CVE-2026-42393 (The comparison used for the doveadm password and API key is not fully ...)
@@ -195,7 +195,7 @@ CVE-2026-42008 (Forwarding information received from a host listed as a trusted
CVE-2026-42007 (An attacker that has valid credentials can use a Sieve script with the ...)
TODO: check
CVE-2026-40541 (An improper neutralization of input during web page generation ('Cross ...)
- TODO: check
+ NOT-FOR-US: Synology
CVE-2026-40205 (An attacker that holds an OAuth2 token granting only part of the requi ...)
TODO: check
CVE-2026-40204 (None None None No publicly available exploits are known.)
@@ -215,7 +215,7 @@ CVE-2026-40014 (An attacker that can send mail to a user can craft a message hea
CVE-2026-40013 (An attacker that has valid credentials can submit a Sieve script conta ...)
TODO: check
CVE-2026-3423 (The Envira Gallery plugin for WordPress is vulnerable to Stored Cross- ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-38725 (xipblog module v2.0.1 and before for PrestaShop allows unauthenticated ...)
TODO: check
CVE-2026-38638 (An issue in the with_argv function (/unistd/mod.rs) of relibc commit 6 ...)
@@ -247,11 +247,11 @@ CVE-2026-33263 (When mail_max_userip_connections is set (default 10) and reached
CVE-2026-27852 (An attacker that can send mail to a user can craft a message whose hea ...)
TODO: check
CVE-2026-19423 (The Ultimate Member WordPress plugin before 2.13.0 does not validate ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19412 (This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to th ...)
TODO: check
CVE-2026-19084 (The shared-files-pro WordPress plugin before 1.7.70 does not validate ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18918 (In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization che ...)
TODO: check
CVE-2026-18393 (A flaw was found in FFmpeg. The tdsc_load_cursor() function writes bey ...)
@@ -261,15 +261,15 @@ CVE-2026-15603 (morgan is an HTTP request logger middleware for Node.js. In vers
CVE-2026-14942
REJECTED
CVE-2026-14567 (The User Frontend WordPress plugin before 4.3.10 does not restrict ac ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14558 (The User Frontend WordPress plugin before 4.3.10 does not properly va ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13761 (Pega Platform versions 7.1.0 through 25.1.2 are affected by an imprope ...)
TODO: check
CVE-2026-12514 (The Shared Files WordPress plugin before 1.7.67, shared-files-pro Wor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12513 (The Shared Files WordPress plugin before 1.7.67, shared-files-pro Wor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-80724 (In the Linux kernel, the following vulnerability has been resolved: p ...)
- linux 7.1.12-1
[trixie] - linux <not-affected> (Vulnerable code not present)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/efd784d994d97159ebfd052b679c709c1f441f09
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/efd784d994d97159ebfd052b679c709c1f441f09
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260828/b24b663c/attachment.htm>
More information about the debian-security-tracker-commits
mailing list