[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Jul 20 08:13:35 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2ba7ccf0 by security tracker role at 2026-07-20T07:13:29+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,51 @@
+CVE-2026-9833 (The Tag Groups is the Advanced Way to Display Your Taxonomy Terms Word ...)
+ TODO: check
+CVE-2026-8825 (The Elementor Website Builder WordPress plugin before 4.1.4 does not ...)
+ TODO: check
+CVE-2026-6656 (Crypt::Password versions through 0.28 for Perl are susceptible to timi ...)
+ TODO: check
+CVE-2026-45138 (CI4MS is a CodeIgniter 4-based content management system skeleton. Pri ...)
+ TODO: check
+CVE-2026-44359 (Meshtastic is an open source mesh networking solution. Prior to versio ...)
+ TODO: check
+CVE-2026-42566 (Meshtastic is an open source mesh networking solution. Prior to versio ...)
+ TODO: check
+CVE-2026-16235 (Crypt::Password versions through 0.28 for Perl generate insecure rando ...)
+ TODO: check
+CVE-2026-13432 (The ThumbPress WordPress plugin before 6.2.2 does not perform a capab ...)
+ TODO: check
+CVE-2026-13156 (The MailerSend WordPress plugin before 1.0.8 does not perform a nonce ...)
+ TODO: check
+CVE-2026-13147 (The Kirki WordPress plugin before 6.0.12 does not validate a user-sup ...)
+ TODO: check
+CVE-2026-13142 (The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin b ...)
+ TODO: check
+CVE-2026-12973 (The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not per ...)
+ TODO: check
+CVE-2026-12972 (The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not per ...)
+ TODO: check
+CVE-2026-12970 (The LearnPress WordPress plugin before 4.4.1 does not escape a search ...)
+ TODO: check
+CVE-2026-12898 (The All-in-One WP Migration and Backup WordPress plugin before 7.106 d ...)
+ TODO: check
+CVE-2026-12724 (The Kirki WordPress plugin before 6.0.12 does not sanitise or escape ...)
+ TODO: check
+CVE-2026-12723 (The Kirki WordPress plugin before 6.0.12 does not perform any authori ...)
+ TODO: check
+CVE-2026-12592 (The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a ...)
+ TODO: check
+CVE-2026-12484 (A vulnerability in keras-team/keras version 3.15.0 allows unsafe deser ...)
+ TODO: check
+CVE-2026-11868 (The WP Travel WordPress plugin before 11.7.1 does not perform capabil ...)
+ TODO: check
+CVE-2026-11349 (The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern E ...)
+ TODO: check
+CVE-2026-10755 (The All in One SEO WordPress plugin before 4.9.9 does not correctly r ...)
+ TODO: check
+CVE-2026-10724 (The Reviews Feed WordPress plugin before 2.6.5 does not neutralize Wo ...)
+ TODO: check
+CVE-2026-10081 (The Unlimited Elements For Elementor WordPress plugin before 2.0.11 do ...)
+ TODO: check
CVE-2026-57857 (The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulne ...)
NOT-FOR-US: WordPress plugin
CVE-2026-57848 (Stoat for Android exports the chat.stoat.activities.ShareTargetActivit ...)
@@ -7282,7 +7330,7 @@ CVE-2026-15531 (A vulnerability has been found in yashbhalgat HashNeRF-pytorch u
NOT-FOR-US: yashbhalgat HashNeRF-pytorch
CVE-2026-15530 (A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulner ...)
NOT-FOR-US: WuzhiCMS
-CVE-2026-15529 (A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affec ...)
+CVE-2026-15529 (A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is ...)
NOT-FOR-US: yzhao062 pyod
CVE-2026-15528 (A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1. This i ...)
NOT-FOR-US: lamaalrajih kicad-mcp
@@ -16041,13 +16089,13 @@ CVE-2026-58036 (Exposure of Sensitive Information to an Unauthorized Actor vulne
NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/core/+/1306035 (master)
CVE-2026-13766 (DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection v ...)
NOT-FOR-US: DBIx::QuickORM Perl module
-CVE-2026-57082 (Net::BitTorrent versions through 2.0.1 for Perl generate the MSE Diffi ...)
+CVE-2026-57082 (Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie ...)
NOT-FOR-US: Net::BitTorrent Perl module
-CVE-2026-57081 (Net::BitTorrent versions through 2.0.1 for Perl allow remote memory ex ...)
+CVE-2026-57081 (Net::BitTorrent versions through 2.1.0 for Perl allow remote memory ex ...)
NOT-FOR-US: Net::BitTorrent Perl module
-CVE-2026-57080 (Net::BitTorrent versions through 2.0.1 for Perl allow remote memory ex ...)
+CVE-2026-57080 (Net::BitTorrent versions through 2.1.0 for Perl allow remote memory ex ...)
NOT-FOR-US: Net::BitTorrent Perl module
-CVE-2026-57079 (Net::BitTorrent versions through 2.0.1 for Perl write files outside th ...)
+CVE-2026-57079 (Net::BitTorrent versions before 2.1.0 for Perl write files outside the ...)
NOT-FOR-US: Net::BitTorrent Perl module
CVE-2026-57964
- spice-vdagent <not-affected> (MacOS/BSD specific)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2ba7ccf01ababe5cdd26f1b84580876722f241b8
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2ba7ccf01ababe5cdd26f1b84580876722f241b8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260720/8bea716f/attachment.htm>
More information about the debian-security-tracker-commits
mailing list