[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 27 08:15:59 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e1408aef by security tracker role at 2026-07-27T07:15:52+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
 CVE-2026-9830 (The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-66412 (Leantime 3.6.2 and prior contains a broken access control vulnerabilit ...)
 	TODO: check
 CVE-2026-17501 (A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerabilit ...)
@@ -9,49 +9,49 @@ CVE-2026-17500 (A vulnerability was detected in ggml-org llama.cpp d006858/e15ef
 CVE-2026-15928 (XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a ref ...)
 	TODO: check
 CVE-2026-14827 (The Calendar WordPress plugin before 1.3.18 does not properly escape a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14820 (The Quiz and Survey Master (QSM)  WordPress plugin before 11.1.3 does  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14568 (The User Frontend: AI Powered Frontend Post Submission, User Directory ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14289 (The FacturaONE para WooCommerce con VeriFactu WordPress plugin before  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14236 (The Contact Form 7  WordPress plugin before 2.5 does not validate the  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14235 (The Download Manager WordPress plugin before 3.3.62 does not bind its  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14203 (The Smart Manager  WordPress plugin before 8.92.0 does not properly en ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14190 (The Sina Extension for Elementor WordPress plugin before 3.10.2 does n ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14189 (The WPBot  WordPress plugin before 8.5.2 does not validate administrat ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13726 (The MPG  WordPress plugin before 4.1.8 does not sanitise and escape a  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13714 (The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin bef ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13597 (The \u5fae\u4fe1\u4e8c\u7ef4\u7801\u767b\u9646 WordPress plugin throug ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13400 (Simply Schedule Appointments is vulnerable to unauthenticated Stored C ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13390 (The Events Calendar WordPress plugin before 6.16.5.1 does not perform  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13332 (The Masteriyo LMS  WordPress plugin before 2.3.1 does not correctly ve ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13152 (The Custom Fields Account Registration For Woocommerce WordPress plugi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12982 (The Document Gallery WordPress plugin before 5.1.1 does not properly s ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12493 (The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12394 (The MemberGlut  WordPress plugin before 1.1.5 does not validate the ro ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12255 (The MainWP Child  WordPress plugin before 6.1.2 does not verify the re ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-10082 (The Advanced Ads  WordPress plugin before 2.0.23 does not sanitize and ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-15662 (The Printcart Web to Print Product Designer for WooCommerce WordPress  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-64536 [staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop]
 	- linux 7.1.4-1
 	[trixie] - linux 6.12.96-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e1408aef131522eb68b7fa65727b51d827f5dd05

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e1408aef131522eb68b7fa65727b51d827f5dd05
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260727/8300b8ab/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list