[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 23 08:15:11 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
93d2e085 by security tracker role at 2026-07-23T07:14:47+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,13 +1,13 @@
 CVE-2026-9737 (During query planning when reading the sort pattern in raw BSONObj for ...)
 	TODO: check
 CVE-2026-9577 (The Post Status Notifier Lite WordPress plugin before 1.13.0 does not  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-9066 (The WP Compress  WordPress plugin before 7.10.04 does not validate the ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-7534 (The SUMO Reward Points plugin for WordPress is vulnerable to Unauthent ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-7232 (The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-7120 (@fastify/static evaluates the allowedPath callback before normalizing  ...)
 	TODO: check
 CVE-2026-6390 (A flaw was found in GNU nano's multi-buffer error message handling. Wh ...)
@@ -15,33 +15,33 @@ CVE-2026-6390 (A flaw was found in GNU nano's multi-buffer error message handlin
 CVE-2026-64829 (Question2Answer through 1.8.8 contains a session invalidation vulnerab ...)
 	TODO: check
 CVE-2026-64798 (Persistent URL login keys were also generated using a non-cryptographi ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-64797 (IP Login trusted forwarded client-IP headers without requiring a confi ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-64796 (Free did not require both the article creator and last modifier to be  ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-64795 (Tag-provided custom HTML, module content/title overrides and decoded m ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-64794 (User tags, filters and conditions allowed access to insufficiently res ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-64793 (Content tags could use ignore flags or property overrides to render re ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-64792 (Smart Search indexing could render generated content using the indexin ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-64791 (Administrator routes and install/update/uninstall processing did not c ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-63685 (Administrator routes and replacement requests did not consistently req ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-63684 (Administrator actions, editor popups and import/export requests lacked ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-63683 (IP and GeoIP conditions trusted spoofable forwarded headers, allowing  ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-63281 (Stored condition values could also execute HTML/JavaScript in administ ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-63280 (Conditions administration did not consistently enforce tokens and comp ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-63265 (Privileged Regular Labs AJAX endpoints did not consistently require va ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-63226 (Printers and Multifunction Printers (MFPs) provided by Ricoh Company,  ...)
 	TODO: check
 CVE-2026-61246 (Vulnerability in the Oracle Platform Security for Java product of Orac ...)
@@ -75,7 +75,7 @@ CVE-2026-38765 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allo
 CVE-2026-38763 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a l ...)
 	TODO: check
 CVE-2026-21723 (The alertmanager templates test endpoint (/api/alertmanager/grafana/co ...)
-	TODO: check
+	NOT-FOR-US: Grafana Labs
 CVE-2026-16653 (A security flaw has been discovered in boazsegev facil.io up to 0.7.58 ...)
 	TODO: check
 CVE-2026-16632 (A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is t ...)
@@ -95,7 +95,7 @@ CVE-2026-14899 (The code to parse MIME headers for display when forwarding a mes
 CVE-2026-14881 (When importing connections in Compass it is possible to override some  ...)
 	TODO: check
 CVE-2026-14291 (The security-ninja-premium WordPress plugin before 5.290 does not veri ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13089 (OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature v ...)
 	TODO: check
 CVE-2026-13078 (A vulnerability was discovered in MongoDB Server where the server-side ...)
@@ -147,7 +147,7 @@ CVE-2026-13056 (Using expressions that generate large arrays it is possible to c
 CVE-2026-13055 (The `$_internalIndexKey` aggregation expression can be used by any aut ...)
 	TODO: check
 CVE-2026-12082 (The Praison AI SEO WordPress plugin before 5.0.7 does not perform auth ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-60835 (An issue in the unrar.dll component of IZArc v4.6 allows attackers to  ...)
 	TODO: check
 CVE-2025-50330 (An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/93d2e085a66515b9098c7a1ebbd9e94ed026c111

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/93d2e085a66515b9098c7a1ebbd9e94ed026c111
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260723/e2658f4b/attachment.htm>


More information about the debian-security-tracker-commits mailing list