[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jul 28 20:15:14 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6b4376bc by security tracker role at 2026-07-28T19:15:08+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5,17 +5,17 @@ CVE-2026-8167 (Improper neutralization of input during web page generation ('cro
 CVE-2026-8164 (Uncontrolled Search Path Element vulnerability in ArkSigner Software a ...)
 	TODO: check
 CVE-2026-8058 (IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060. ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-7868 (IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060. ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-7775 (IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-7769 (IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-7521 (Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6 ...)
 	TODO: check
 CVE-2026-7362 (IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 thr ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-7187 (Missing authentication for critical function vulnerability in Universa ...)
 	TODO: check
 CVE-2026-6879 (`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O ...)
@@ -71,11 +71,11 @@ CVE-2026-66713 (Deserialization of Untrusted Data (CWE-502) in the Tribes-based
 CVE-2026-66299 (Uncontrolled Resource Consumption vulnerability in Apache Tomcat's Web ...)
 	TODO: check
 CVE-2026-65882 (Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdl ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-65881 (Joomla Extension - joomdle.com - Insecure default configuration allows ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-65880 (Joomla Extension - balbooa.com - Unauthenticated remote code execution ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-65624 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
 	TODO: check
 CVE-2026-63727 (Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an ...)
@@ -87,7 +87,7 @@ CVE-2026-63302 (Quick.CMS is vulnerable to Local File Inclusion (LFI) in the adm
 CVE-2026-63301 (In Quick.CMS, the administrative user interface restricts deletion of  ...)
 	TODO: check
 CVE-2026-62828 (Improper input validation in Microsoft Edge for Android allows an unau ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-61609 (Pterodactyl is a free, open-source game server management panel. From  ...)
 	TODO: check
 CVE-2026-61487 (Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ...)
@@ -95,7 +95,7 @@ CVE-2026-61487 (Improper Authorization vulnerability in Apache ActiveMQ Broker,
 CVE-2026-61376 (ELECOM wireless LAN routers and access points devices contain an OS Co ...)
 	TODO: check
 CVE-2026-5114 (The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File R ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-59933 (PhpSpreadsheet is a pure PHP library for reading and writing spreadshe ...)
 	TODO: check
 CVE-2026-59932 (PhpSpreadsheet is a pure PHP library for reading and writing spreadshe ...)
@@ -109,7 +109,7 @@ CVE-2026-59764 (ELECOM wireless LAN routers and access points devices contain an
 CVE-2026-59248 (Allocation of resources without limits vulnerability in ninenines cowl ...)
 	TODO: check
 CVE-2026-58246 (SAP NetWeaver Application Server for ABAP and ABAP Platform writes sen ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-55977 (Successful exploitation of this vulnerability could allow an attacker  ...)
 	TODO: check
 CVE-2026-54635 (pytonapi is a Python SDK for TONAPI that provides REST API, streaming, ...)
@@ -173,9 +173,9 @@ CVE-2026-50736 (The pglogical queue mechanism, used to convey out-of-band comman
 CVE-2026-50735 (pglogical's apply worker does not sufficiently validate the length of  ...)
 	TODO: check
 CVE-2026-4932 (IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 thro ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-4912 (The Media Cleaner: Clean your WordPress! plugin for WordPress is vulne ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-4648 (Use of an insecure cryptographic algorithm in the cashless payment sys ...)
 	TODO: check
 CVE-2026-49332 (A flaw was found in openshift/oauth-proxy. The proxy sets authenticate ...)
@@ -183,25 +183,25 @@ CVE-2026-49332 (A flaw was found in openshift/oauth-proxy. The proxy sets authen
 CVE-2026-49258 (Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh V ...)
 	TODO: check
 CVE-2026-48396 (Bridge is affected by an Incorrect Authorization vulnerability that co ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48395 (Bridge is affected by an Untrusted Search Path vulnerability that coul ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48394 (Bridge is affected by an out-of-bounds write vulnerability that could  ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48393 (Bridge is affected by an out-of-bounds write vulnerability that could  ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48392 (Bridge is affected by an out-of-bounds write vulnerability that could  ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48391 (Bridge is affected by an Untrusted Search Path vulnerability that coul ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48390 (Bridge is affected by an Incorrect Authorization vulnerability that co ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48388 (Adobe Photoshop Installer was affected by an Uncontrolled Search Path  ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48374 (Bridge is affected by an Improper Limitation of a Pathname to a Restri ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48372 (Format Plugins is affected by a Heap-based Buffer Overflow vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48058 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtu ...)
 	TODO: check
 CVE-2026-48025 (nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtu ...)
@@ -225,27 +225,27 @@ CVE-2026-43910 (Appium Java Client is the Java language binding for writing Appi
 CVE-2026-41874 (Quick.Cart stores hard-coded, plaintext admin credentials in a configu ...)
 	TODO: check
 CVE-2026-21047 (Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allo ...)
-	TODO: check
+	NOT-FOR-US: Samsung Mobile
 CVE-2026-18107 (A flaw was found in CRIU's handling of restartable sequences (rseq) du ...)
 	TODO: check
 CVE-2026-18085 (An Improper Input Validation in the BlackBerry UEMManagementConsoleofB ...)
-	TODO: check
+	NOT-FOR-US: Blackberry
 CVE-2026-18084 (Improper Neutralization of Input During Web Page Generation vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Blackberry
 CVE-2026-18047 (A flaw was found in Dogtag PKI's ACME responder where the web.xml secu ...)
 	TODO: check
 CVE-2026-18038 (A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affecte ...)
 	TODO: check
 CVE-2026-18029 (Our payment integration with GiroCheckout did not properly validate  p ...)
-	TODO: check
+	NOT-FOR-US: rami.io products
 CVE-2026-18028 (The "quick setup" view presented to users after they first create an   ...)
-	TODO: check
+	NOT-FOR-US: rami.io products
 CVE-2026-17072 (A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of- ...)
 	TODO: check
 CVE-2026-16774 (The Chatbot plugin for WordPress is vulnerable to Missing Authorizatio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16773 (The WPBot \u2013 AI ChatBot for Live Support, Lead Generation, AI Serv ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16771 (In firmware versions 2.7.7 and earlier, the Arris BGW210\u2011700 gate ...)
 	TODO: check
 CVE-2026-16498 (The terraform-mcp-server before version 1.1.0 is vulnerable to a cross ...)
@@ -257,39 +257,39 @@ CVE-2026-16462 (In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly s
 CVE-2026-16313 (A flaw was found in sg3_utils. The sg_inq command, when invoked with t ...)
 	TODO: check
 CVE-2026-15992 (The WP Password Policy plugin for WordPress is vulnerable to Privilege ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15730 (The GamiPress \u2013 Gamification plugin to reward points, achievement ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15673 (The SMS Alert \u2013 SMS & OTP for WooCommerce, Order Notifications &  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15671 (The SMS Alert \u2013 SMS & OTP for WooCommerce, Order Notifications &  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15670 (The SMS Alert \u2013 SMS & OTP for WooCommerce, Order Notifications &  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15444 (The Tutor LMS \u2013 eLearning and online course solution plugin for W ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15411 (The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells,  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15393 (The Cozy Blocks \u2013 Page Builder for Gutenberg Editor & FSE with 60 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15304 (The Plugin Organizer plugin for WordPress is vulnerable to SQL Injecti ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15267 (The Taskbuilder \u2013 Project Management & Task Management Tool With  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15025 (The Uncanny Automator \u2013 Easy Automation, Integration, Webhooks &  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15016 (The Paid Memberships Pro \u2013 Content Restriction, User Registration ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15014 (The SMS Alert \u2013 SMS & OTP for WooCommerce, Order Notifications &  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14869 (The terraform-mcp-server before version 1.1.0 is vulnerable to a serve ...)
 	TODO: check
 CVE-2026-14785 (The Web Directory Free plugin for WordPress is vulnerable to generic S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14516 (The Online Scheduling and Appointment Booking System \u2013 Bookly plu ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14328 (The Eazy Plugin Manager \u2013 Powerful Plugin Management Solution for ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14171 (An unauthenticated remote attacker can abuse the improper validation o ...)
 	TODO: check
 CVE-2026-14170
@@ -301,23 +301,23 @@ CVE-2026-14168 (A low privileged remote attacker can gain administrator privileg
 CVE-2026-14167 (A low privileged remote attacker can perform privileged configuration  ...)
 	TODO: check
 CVE-2026-13440 (The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells,  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13161 (The TrueBooker \u2013 Appointment Booking and Scheduler System plugin  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13110 (The Storegrowth Sales Booster plugin for WordPress is vulnerable to Mi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12800 (The Premium Packages \u2013 Sell Digital Products Securely plugin for  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12741 (The WP Fast Total Search \u2013 The Power of Indexed Search plugin for ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11841 (An attacker may perform unauthenticated read and write operations on s ...)
-	TODO: check
+	NOT-FOR-US: SICK AG
 CVE-2026-11756 (A Deserialization of Untrusted Data vulnerability affecting Station La ...)
-	TODO: check
+	NOT-FOR-US: Dassault Systemes
 CVE-2026-11598 (The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Sit ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-10207 (The PickPlugins Question Answer plugin for WordPress is vulnerable to  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-14041 (In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYS ...)
 	TODO: check
 CVE-2026-59986



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6b4376bc4e499ad3e3119f532c1d7bcd2c528e82

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6b4376bc4e499ad3e3119f532c1d7bcd2c528e82
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260728/a551c777/attachment.htm>


More information about the debian-security-tracker-commits mailing list