[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 20 08:14:26 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
44411d78 by security tracker role at 2026-07-20T07:14:19+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2026-9833 (The Tag Groups is the Advanced Way to Display Your Taxonomy Terms Word ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-8825 (The Elementor Website Builder  WordPress plugin before 4.1.4 does not  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-6656 (Crypt::Password versions through 0.28 for Perl are susceptible to timi ...)
 	TODO: check
 CVE-2026-45138 (CI4MS is a CodeIgniter 4-based content management system skeleton. Pri ...)
@@ -13,39 +13,39 @@ CVE-2026-42566 (Meshtastic is an open source mesh networking solution. Prior to
 CVE-2026-16235 (Crypt::Password versions through 0.28 for Perl generate insecure rando ...)
 	TODO: check
 CVE-2026-13432 (The ThumbPress  WordPress plugin before 6.2.2 does not perform a capab ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13156 (The MailerSend  WordPress plugin before 1.0.8 does not perform a nonce ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13147 (The Kirki  WordPress plugin before 6.0.12 does not validate a user-sup ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13142 (The Social Login, Passkeys, Magic Link & Email OTP  WordPress plugin b ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12973 (The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not per ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12972 (The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not per ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12970 (The LearnPress  WordPress plugin before 4.4.1 does not escape a search ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12898 (The All-in-One WP Migration and Backup WordPress plugin before 7.106 d ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12724 (The Kirki  WordPress plugin before 6.0.12 does not sanitise or escape  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12723 (The Kirki  WordPress plugin before 6.0.12 does not perform any authori ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12592 (The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12484 (A vulnerability in keras-team/keras version 3.15.0 allows unsafe deser ...)
 	TODO: check
 CVE-2026-11868 (The WP Travel  WordPress plugin before 11.7.1 does not perform capabil ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11349 (The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern E ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-10755 (The All in One SEO  WordPress plugin before 4.9.9 does not correctly r ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-10724 (The Reviews Feed  WordPress plugin before 2.6.5 does not neutralize Wo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-10081 (The Unlimited Elements For Elementor WordPress plugin before 2.0.11 do ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-57857 (The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulne ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-57848 (Stoat for Android exports the chat.stoat.activities.ShareTargetActivit ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/44411d781ef0bf7e340410a5b4587a74bec30c75

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/44411d781ef0bf7e340410a5b4587a74bec30c75
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260720/a9e213e5/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list