[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 13 08:14:08 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5f2d72e1 by security tracker role at 2026-07-13T07:14:02+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -9,19 +9,19 @@ CVE-2026-15552 (Enterprise Cloud Database developed by Ragic has a Stored Cross-
 CVE-2026-15551 (Integer overflow or wraparound vulnerability in Samsung Open Source rl ...)
 	TODO: check
 CVE-2026-15539 (A security vulnerability has been detected in SourceCodester Online Bo ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-15538 (A weakness has been identified in primefaces primereact up to 10.9.8.  ...)
 	TODO: check
 CVE-2026-15537 (A security flaw has been discovered in SourceCodester Online Book Stor ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-15536 (A vulnerability was identified in itsourcecode Hospital Management Sys ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-15535 (A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48 ...)
 	TODO: check
 CVE-2026-15533 (A security flaw has been discovered in DedeCMS 5.7.118. Impacted is an ...)
-	TODO: check
+	NOT-FOR-US: DedeCMS
 CVE-2026-15532 (A vulnerability was identified in SourceCodester Online Book Store Sys ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-15531 (A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 8 ...)
 	TODO: check
 CVE-2026-15530 (A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulner ...)
@@ -39,11 +39,11 @@ CVE-2026-15525 (A vulnerability was detected in kLOsk adloop up to 0.9.0. This v
 CVE-2026-15524 (A security vulnerability has been detected in alioshr memory-bank-mcp  ...)
 	TODO: check
 CVE-2026-15523 (A weakness has been identified in CodeAstro Simple Online Leave Manage ...)
-	TODO: check
+	NOT-FOR-US: CodeAstro
 CVE-2026-15522 (A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0 ...)
 	TODO: check
 CVE-2026-15521 (A vulnerability was identified in makafeli n8n-workflow-builder up to  ...)
-	TODO: check
+	NOT-FOR-US: n8n
 CVE-2026-15520 (A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035. T ...)
 	TODO: check
 CVE-2026-15519 (A vulnerability was found in usestrix strix up to 1.0.2. This affects  ...)
@@ -59,7 +59,7 @@ CVE-2026-15515 (A security vulnerability has been detected in Tencent PC Manager
 CVE-2026-15514 (A weakness has been identified in Metasoft \u7f8e\u7279\u8f6f\u4ef6 Me ...)
 	TODO: check
 CVE-2026-15513 (A security flaw has been discovered in Wavlink WL-NU516U1 260515. This ...)
-	TODO: check
+	NOT-FOR-US: Wavlink
 CVE-2026-15512 (A vulnerability was identified in pig-mesh Pig up to 3.9.2. Affected b ...)
 	TODO: check
 CVE-2026-15511 (A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. ...)
@@ -77,27 +77,27 @@ CVE-2026-15506 (A security vulnerability has been detected in SecureAge CatchPul
 CVE-2026-15505 (A weakness has been identified in vnotex vnote up to 3.20.1. Impacted  ...)
 	TODO: check
 CVE-2026-12582 (The Library Management System WordPress plugin before 3.5.8 does not s ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12397 (The WP Job Portal  WordPress plugin before 2.5.5 does not verify owner ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12396 (The WP Job Portal  WordPress plugin before 2.5.5 does not perform capa ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12275 (The Tutor LMS  WordPress plugin before 3.9.13 does not, in its Droip a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12274 (The Tutor LMS  WordPress plugin before 3.9.13 does not verify that the ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12273 (The Tutor LMS  WordPress plugin before 3.9.13 does not perform any aut ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12271 (The Tutor LMS  WordPress plugin before 3.9.13 does not verify ownershi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12081 (The Database for Contact Form 7, WPforms, Elementor forms WordPress pl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11964 (The User Registration & Membership  WordPress plugin before 5.2.2 does ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11963 (The User Registration & Membership  WordPress plugin before 5.2.2 does ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-10551 (The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauth ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-61876 (LuCI versions fail to properly encode DHCPv6 lease hostnames before re ...)
 	NOT-FOR-US: LuCI
 CVE-2026-61875 (luci-app-upnp contains a stored cross-site scripting vulnerability tha ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f2d72e1471a2ce70b6640c52724103a13f44f48

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f2d72e1471a2ce70b6640c52724103a13f44f48
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260713/a272cd07/attachment.htm>


More information about the debian-security-tracker-commits mailing list