[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 27 08:45:08 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8bd1d123 by Salvatore Bonaccorso at 2026-07-27T09:44:42+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2026-9830 (The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-66412 (Leantime 3.6.2 and prior contains a broken access control vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: Leantime
 CVE-2026-17501 (A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerabilit ...)
 	TODO: check
 CVE-2026-17500 (A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. Th ...)
@@ -110,15 +110,15 @@ CVE-2026-57989 (Origin validation error in Microsoft Edge (Chromium-based) allow
 CVE-2026-57978 (Origin validation error in Microsoft Edge (Chromium-based) allows an u ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-17497 (NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execut ...)
-	TODO: check
+	NOT-FOR-US: NoteGen
 CVE-2026-17496 (NoteGen before 0.32.0 renders AI chat responses with markdown-it confi ...)
-	TODO: check
+	NOT-FOR-US: NoteGen
 CVE-2026-17459 (A vulnerability was determined in perwendel spark up to 2.9.4. This vu ...)
-	TODO: check
+	NOT-FOR-US: perwendel spark
 CVE-2026-17458 (A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This aff ...)
-	TODO: check
+	NOT-FOR-US: mf-yang openclaw-cn
 CVE-2026-17457 (A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Aff ...)
-	TODO: check
+	NOT-FOR-US: mf-yang openclaw-cn
 CVE-2026-63319
 	- qemu 1:11.0.3+ds-1
 	NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3995
@@ -2071,7 +2071,7 @@ CVE-2026-12502 (Improper Privilege Management (CWE-269)in `/usr/bin/ltsudo` in L
 CVE-2026-12496 (Stored Cross-Site Scripting (CWE-79)in the OPC XML-DA server statistic ...)
 	NOT-FOR-US: Loytec
 CVE-2026-10610 (Local privilege escalationpotentially allowed an attacker to execute a ...)
-	TODO: check
+	NOT-FOR-US: ESET
 CVE-2026-10033 (The EventON Action User plugin for WordPress is vulnerable to authoriz ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-16634 (TOML::XS versions before 0.06 for Perl bundle an unsupported and vulne ...)
@@ -7649,7 +7649,7 @@ CVE-2026-16150 (A vulnerability was found in RobinHerbots Inputmask up to 5.0.9.
 CVE-2026-12228 (A stored cross-site scripting (XSS) vulnerability exists in the `POST  ...)
 	NOT-FOR-US: parisneo/lollms
 CVE-2026-10130 (QueryWeaver contains an authentication bypass vulnerability that allow ...)
-	TODO: check
+	NOT-FOR-US: FalkorDB QueryWeaver
 CVE-2026-64186 (In the Linux kernel, the following vulnerability has been resolved:  i ...)
 	- linux 7.0.12-1
 	[trixie] - linux <not-affected> (Vulnerable code not present)
@@ -11354,7 +11354,7 @@ CVE-2026-11740
 CVE-2026-11575 (The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not p ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-11386 (An input validation and injection vulnerability exists in Canonical ub ...)
-	TODO: check
+	NOT-FOR-US: Canonical ubuntu-pro-client
 CVE-2026-11324 (The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plug ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-10590 (A potential missing authentication vulnerability could allow a local p ...)
@@ -15674,7 +15674,7 @@ CVE-2026-11591 (The Widgets for Google Reviews plugin for WordPress is vulnerabl
 CVE-2026-11426 (The UnderConstructionPage PRO plugin for WordPress is vulnerable to Ar ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-11321 (The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates ...)
-	TODO: check
+	NOT-FOR-US: DataInjection plugin for GLPI
 CVE-2026-10865 (The Cost Calculator Builder plugin for WordPress is vulnerable to Sens ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-10770 (Improper Neutralization of Input During Web Page Generation ("Cross-si ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8bd1d1234ca2b29bad2581f550e0e431e9d55aff

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8bd1d1234ca2b29bad2581f550e0e431e9d55aff
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260727/904b9458/attachment.htm>


More information about the debian-security-tracker-commits mailing list