[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Jul 23 20:14:53 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
0d1457d7 by security tracker role at 2026-07-23T19:14:44+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,13 +1,13 @@
CVE-2026-9729 (The Webpushr Push Notifications plugin for WordPress is vulnerable to ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-9713 (The Lumise Product Designer for WooCommerce plugin for WordPress is vu ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-9635 (The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-8287 (Allocation of resources without limits or throttling vulnerability in ...)
TODO: check
CVE-2026-6516 (Zohocorp ManageEngine ADAudit Plus versionsbefore 8606 are affected by ...)
- TODO: check
+ NOT-FOR-US: Zoho
CVE-2026-65920 (Diffusers through 0.39.0, fixed in commit cee298c, contains a path tra ...)
TODO: check
CVE-2026-65919 (Meshery before 1.0.57 contains an unauthenticated arbitrary file read ...)
@@ -27,11 +27,11 @@ CVE-2026-65912 (DOMPurify before 3.3.2 contains a URI validation bypass vulnerab
CVE-2026-65911 (In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR ...)
TODO: check
CVE-2026-65908 (In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-65907 (In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-65906 (In JetBrains TeamCity before 2026.1.2, 2025.11.6 \u0441ode execution v ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-65904 (DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_P ...)
TODO: check
CVE-2026-65903 (DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function ...)
@@ -53,29 +53,29 @@ CVE-2026-65896 (Grav API Plugin (Composer package getgrav/grav-plugin-api) befor
CVE-2026-65895 (Grav API Plugin versions before 1.0.10 fail to restrict write access t ...)
TODO: check
CVE-2026-65763 (Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Map ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65762 (Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Gue ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65761 (Joomla Extension - joomshaper.com - Unauthenticated SQL injection in E ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65760 (Joomla Extension - joomshaper.com - cross-customer order and personal ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65759 (Joomla Extension - joomshaper.com - unauthenticated payment/order forg ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65758 (Joomla Extension - tassos.gr - Sensitive data exposure in Convert Form ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65757 (Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65756 (Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65755 (Joomla Extension - regularlabs.com - Date-sensitive query-cache leakag ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65754 (Joomla Extension - regularlabs.com - Insecure path handling in ReRepla ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65713 (Joomla Extension - regularlabs.com - Insecure path handling in Modals ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65712 (Joomla Extension - regularlabs.com - Insecure path handling in CDN for ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65702 (Vanna through 2.0.2 contains a path traversal vulnerability in the Fil ...)
TODO: check
CVE-2026-65701 (SoftVC VITS Singing Voice Conversion through commit 730930d contains a ...)
@@ -109,187 +109,187 @@ CVE-2026-65606 (SiYuan before v3.7.2 contains a cross-site scripting vulnerabili
CVE-2026-65605 (SiYuan before v3.7.2 contains a stored cross-site scripting vulnerabil ...)
TODO: check
CVE-2026-65550 (Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65540 (Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 wit ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65539 (Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitema ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65538 (Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65537 (Subscriber Broken Access Control in Cyr to Lat reloaded \u2013 transli ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65536 (Unauthenticated Cross Site Request Forgery (CSRF) in \u0627\u0641\u063 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65535 (Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65534 (Author Cross Site Scripting (XSS) in Custom links in Elementor Image C ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65533 (Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65532 (Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65531 (Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65530 (Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65529 (Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65528 (Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65527 (Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65526 (Contributor SQL Injection in Visualizer <= 4.0.6 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65525 (Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65524 (Contributor Broken Access Control in Avada Custom Branding <= 1.2 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65522 (Contributor Cross Site Scripting (XSS) in Manual - Documentation, Know ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65521 (Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65519 (Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65518 (Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65516 (Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimat ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65514 (Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65512 (Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log < ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65511 (Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65510 (Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoic ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65506 (Unauthenticated Broken Access Control in MP3 Audio Player for Music, R ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65505 (Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elemento ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65503 (Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65501 (Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65500 (Unauthenticated Broken Access Control in Manual - Documentation, Knowl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65499 (Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65498 (Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65497 (Administrator PHP Object Injection in Complianz <= 7.5.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65496 (Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65495 (Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65494 (Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65493 (Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65492 (Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65491 (Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65490 (Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65489 (Unauthenticated Broken Access Control in LA-Studio Element Kit for Ele ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65488 (Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65487 (Unauthenticated Broken Access Control in Photography <= 7.7.6 versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65486 (Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65485 (Unauthenticated Broken Access Control in Content Control <= 2.6.5 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65484 (Contributor Broken Access Control in Style Kits <= 2.6.5 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65483 (Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65482 (Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit for El ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65481 (Contributor Local File Inclusion in Vino <= 1.9 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65480 (Contributor Cross Site Scripting (XSS) in TheGem <= 5.11.1 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65479 (Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65478 (Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65477 (Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65476 (Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65475 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65474 (Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65473 (Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolk ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65472 (Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65471 (Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65470 (Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65469 (Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65468 (Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65467 (Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65466 (Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65465 (Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65464 (Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65463 (Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65462 (Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65461 (Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65460 (Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65458 (Contributor Sensitive Data Exposure in Polylang <= 3.8.5 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65457 (Subscriber Broken Access Control in \u042eKassa \u0434\u043b\u044f Woo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65456 (Contributor Insecure Direct Object References (IDOR) in Product Slider ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65455 (Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65454 (Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65453 (Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65452 (Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65451 (Contributor SQL Injection in MapSVG <= 8.14.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65450 (Contributor SQL Injection in MapSVG <= 8.14.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65449 (Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-65431 (Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65430 (Joomla Extension - regularlabs.com - MaxMind Credential leakage in Geo ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-65010 (Datasets through 5.00, fixed in commit ad2d853, contains a symlink-fol ...)
TODO: check
CVE-2026-64876 (Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-64875 (Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoI ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-64874 (Joomla Extension - regularlabs.com - CDN Credential leakage Cache Clea ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-64873 (Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extensi ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-64872 (Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner P ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-64871 (Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-64815 (In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was ...)
TODO: check
CVE-2026-64814 (In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was ...)
@@ -303,141 +303,141 @@ CVE-2026-64811 (In JetBrains IntelliJ IDEA before 2026.2 arbitrary code executio
CVE-2026-64810 (In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible i ...)
TODO: check
CVE-2026-64809 (In JetBrains PhpStorm before 2026.2 arbitrary code execution was possi ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-64808 (In JetBrains PhpStorm before 2026.2 arbitrary code execution was possi ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-64807 (In JetBrains WebStorm before 2026.2 arbitrary code execution was possi ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-64806 (In JetBrains WebStorm before 2026.2 arbitrary code execution was possi ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-64805 (In JetBrains WebStorm before 2026.2 arbitrary code execution was possi ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-64804 (In JetBrains WebStorm before 2026.2 arbitrary code execution was possi ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-64803 (In JetBrains GoLand before 2026.2 arbitrary code execution was possibl ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-64802 (In JetBrains GoLand before 2026.2 arbitrary code execution was possibl ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-64800 (In JetBrains GoLand before 2026.2 sensitive configuration values writt ...)
- TODO: check
+ NOT-FOR-US: JetBrains
CVE-2026-64799 (Joomla Extension - regularlabs.com - SSRF via remote image downloads i ...)
- TODO: check
+ NOT-FOR-US: Joomla
CVE-2026-64611 (A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() ...)
TODO: check
CVE-2026-63765 (Chatwoot before 4.16.0 contains an authentication bypass vulnerability ...)
TODO: check
CVE-2026-61981 (Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Direc ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61973 (Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61972 (Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61954 (Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61951 (Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61950 (Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61949 (Unauthenticated SQL Injection in Bookly <= 27.7 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61948 (Unauthenticated SQL Injection in WPDM \u2013 Premium Packages <= 6.2.0 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61947 (Unauthenticated Cross Site Scripting (XSS) in Form Vibes \u2013 Databa ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61946 (Unauthenticated Insecure Direct Object References (IDOR) in Easy Appoi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61945 (Exposure of Sensitive System Information to an Unauthorized Control Sp ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61944 (Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-61943 (Unauthenticated Broken Access Control in WPDM \u2013 Premium Packages ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59678 (An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt ...)
TODO: check
CVE-2026-59677 (A Missing Authorization vulnerability in selinux policycoreutils seuns ...)
TODO: check
CVE-2026-59555 (Unauthenticated Arbitrary File Deletion in Participants Database <= 2. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59554 (Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59547 (Unauthenticated Broken Access Control in Payment Gateway for PayPal on ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59545 (Unauthenticated Broken Authentication in miniOrange Discord Integratio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59544 (Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59543 (Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 ver ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59542 (Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59541 (Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59540 (Unauthenticated Privilege Escalation in SMS Alert Order Notifications ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59526 (Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59525 (Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59524 (Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59522 (Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59517 (Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59514 (Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59513 (Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-59512 (Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooC ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57809 (Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57808 (Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57785 (Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57784 (Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57769 (Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57767 (Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57735 (Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57717 (Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57716 (Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57704 (Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57703 (Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 ve ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57701 (Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57699 (Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57696 (Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57626 (Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cro ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57428 (Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57427 (Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPFor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57425 (Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57397 (Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57384 (Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57374 (Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builde ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57373 (Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO < ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57370 (Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Tim ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-57367 (Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-52684 (If the auth responds very slowly and the records expire in between, th ...)
TODO: check
CVE-2026-48539 (GFI Archiver before 15.13 contains a stored cross-site scripting vulne ...)
@@ -471,55 +471,55 @@ CVE-2026-47743 (Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, th
CVE-2026-47668 (DbGate is cross-platform database manager. In versions 7.1.8 and prior ...)
TODO: check
CVE-2026-44909 (Proxygen lacked a generalized slow-consumer detection mechanism in its ...)
- TODO: check
+ NOT-FOR-US: Meta software not packaged in Debian
CVE-2026-44210 (Kata Containers is an open source project focusing on a standard imple ...)
TODO: check
CVE-2026-43823 (When initializing an RSA public key from DER or PEM bytes throws an er ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-43820 (NIOSSLCertificate._subjectAlternativeNames provides access to the raw ...)
- TODO: check
+ NOT-FOR-US: Apple
CVE-2026-27423 (Subscriber Broken Access Control in Participants Database <= 2.7.8.4 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27422 (Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27418 (Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27403 (Contributor Cross Site Scripting (XSS) in Hubbub Lite <= 1.36.3 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27399 (Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27392 (Contributor Broken Access Control in uListing <= 2.2.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27391 (Subscriber Broken Access Control in uListing <= 2.2.0 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27377 (Booking Agent Broken Access Control in QuickCal - Appointment Booking ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27372 (Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice < ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27355 (Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27064 (Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-25466 (Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-25427 (Subscriber Broken Access Control in eRoom <= 1.7.1 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-25424 (Contributor Broken Access Control in Mediavine Control Panel <= 2.10.1 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-25405 (Contributor SQL Injection in eRoom <= 1.7.1 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-24639 (Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 vers ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-24628 (Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-24552 (Contributor SQL Injection in Create by Mediavine <= 2.5.3 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-24537 (Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-16768 (A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO f ...)
TODO: check
CVE-2026-16756 (Missing connection and header-read timeouts and the absence of a concu ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-16745 (A flaw was found in odh-dashboard, the web console component of Red Ha ...)
TODO: check
CVE-2026-16735 (A security vulnerability has been detected in release-it conventional- ...)
@@ -529,27 +529,27 @@ CVE-2026-16733 (A weakness has been identified in bahmutov find-cypress-specs up
CVE-2026-16723 (A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 ...)
TODO: check
CVE-2026-16584 (Improper handling of an initialization failure in AWS API MCP Server f ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-16287 (Improper neutralization of special elements used in an OS command ('OS ...)
TODO: check
CVE-2026-16078 (The WCPOS \u2013 Point of Sale (POS) plugin for WooCommerce plugin for ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15906 (The Premium Packages \u2013 Sell Digital Products Securely plugin for ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15827 (The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15794 (The Grid/List View for WooCommerce plugin for WordPress is vulnerable ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15786 (The WP Encryption \u2013 One Click Free SSL Certificate & SSL / HTTPS ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15761 (The Tickera \u2013 Sell Tickets & Manage Events plugin for WordPress i ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15687 (A security issue was discovered in the Kubernetes Java client library ...)
TODO: check
CVE-2026-15647 (The Brands for WooCommerce plugin for WordPress is vulnerable to Store ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15646 (The Brands for WooCommerce plugin for WordPress is vulnerable to Store ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15617 (Logto performs principal lookup without normalizing email and identifi ...)
TODO: check
CVE-2026-15616 (Logto does not enforce locally configured MFA during SSO authenticatio ...)
@@ -563,41 +563,41 @@ CVE-2026-15612 (Logto bypasses OIDC nonce validation when the nonce claim is abs
CVE-2026-15611 (Logto allows unverified email-based SSO account linking, enabling an a ...)
TODO: check
CVE-2026-15448 (The Tickera \u2013 Sell Tickets & Manage Events plugin for WordPress i ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15404 (The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Sc ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15394 (The Header Footer Script Adder \u2013 Insert Code in Header, Body & Fo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15348 (The Premium Packages \u2013 Sell Digital Products Securely plugin for ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15037 (Improper output neutralization (XML injection) in QDom comment, CDATA, ...)
TODO: check
CVE-2026-15017 (The MDJM Event Management plugin for WordPress is vulnerable to Privil ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15015 (The MountDev AI MCP Connector for WordPress plugin for WordPress is vu ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15011 (The Customer Support Ticket System & Helpdesk plugin for WordPress is ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14481 (The Equalize Digital Accessibility Checker \u2013 WCAG, ADA, EAA and S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14282 (The GoDAM \u2013 Organize WordPress Media Library & File Manager with ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14257 (brace-expansion through 5.0.7 is vulnerable to denial of service via m ...)
TODO: check
CVE-2026-13119 (The Registrations For The Events Calendar plugin for WordPress is vuln ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13009 (The AI Copilot \u2013 Content Generator plugin for WordPress is vulner ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12421 (The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Sc ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-11804 (Improper handling of insufficient permissions or privileges vulnerabil ...)
- TODO: check
+ NOT-FOR-US: Honeywell
CVE-2025-68081 (Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2024-58330 (A missing authentication check in Bosch IP cameras of families CPP13 a ...)
- TODO: check
+ NOT-FOR-US: Bosch
CVE-2024-58023 (Information disclosure in Bosch Configuration Manager in Version 7.72. ...)
- TODO: check
+ NOT-FOR-US: Bosch
CVE-2026-9737 (During query planning when reading the sort pattern in raw BSONObj for ...)
- mongodb <removed>
NOTE: https://jira.mongodb.org/browse/SERVER-128341
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0d1457d7507ab6178925f6bffff96f9f491433c6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0d1457d7507ab6178925f6bffff96f9f491433c6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260723/46cbe325/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list