[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Jul 29 20:13:50 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ebaaf9f4 by security tracker role at 2026-07-29T19:13:44+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,19 +1,19 @@
 CVE-2026-9720 (The Facturaci\xf3n Electr\xf3nica Costa Rica plugin for WordPress is v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-9177 (A Server-Side Template Injection (SSTI) vulnerability was identified   ...)
 	TODO: check
 CVE-2026-8791 (The Booking System Trafft plugin for WordPress is vulnerable to Stored ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-8497 (Improper certificate validation in the Devolutions Server connection h ...)
-	TODO: check
+	NOT-FOR-US: Devolutions
 CVE-2026-8339 (A SQL injection vulnerability exists in the Coverity Connect SOAP API  ...)
-	TODO: check
+	NOT-FOR-US: Black Duck
 CVE-2026-8338 (A Spring Security authentication and authorization bypass exists in Co ...)
-	TODO: check
+	NOT-FOR-US: Black Duck
 CVE-2026-7436 (The WPC Badge Management for WooCommerce plugin for WordPress is vulne ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-6089 (The WP CTA plugin for WordPress is vulnerable to Server-Side Request F ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-67429 (Flyto2 Core is an execution kernel for automation and AI-agent workflo ...)
 	TODO: check
 CVE-2026-67428 (Flyto2 Core is an execution kernel for automation and AI-agent workflo ...)
@@ -55,41 +55,41 @@ CVE-2026-66724 (MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authori
 CVE-2026-66723 (MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization ...)
 	TODO: check
 CVE-2026-66490 (Joomla Extension - balbooa.com - Stored cross-site scripting via a com ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-66489 (Joomla Extension - balbooa.com - Various unauthenticated file system d ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-66488 (Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-66400 (Grav Login Plugin versions before 3.8.13 contain an insufficient sessi ...)
 	TODO: check
 CVE-2026-66051
 	REJECTED
 CVE-2026-65947 (Joomla Extension - balbooa.com - Various CSRF vectors in the admin int ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-65946 (Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-65944 (Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handler ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-65943 (Joomla Extension - rolandd.com - Unauthenticated directory creation RO ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-65891 (Joomla Extension - joomlacontenteditor.net - Creation of hidden files  ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-65890 (Joomla Extension - balbooa.com - Unauthenticated SQL injection in Grid ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-65889 (Joomla Extension - balbooa.com - Unauthenticated recursive directory d ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-65888 (Joomla Extension - balbooa.com - Account takeover vulnerability in Gri ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-65887 (Joomla Extension - balbooa.com - Unauthenticated arbitrary password re ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-65886 (Joomla Extension - balbooa.com - Unauthenticated arbitrary file read i ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-65885 (Joomla Extension - balbooa.com - Authenticated arbitrary file upload i ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-65884 (Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.2 ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-65883 (Joomla Extension - aimy-extensions.com - RCE via PHP object injection  ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-65325 (Apache Traffic Server reuses multiplexed HTTP/2 origin connections wit ...)
 	TODO: check
 CVE-2026-65324 (Apache Traffic Server drops the per-stream buffer cap when dechunking  ...)
@@ -107,7 +107,7 @@ CVE-2026-60113 (AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interfac
 CVE-2026-60112 (AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing aut ...)
 	TODO: check
 CVE-2026-5060 (The MasterStudy LMS WordPress Plugin \u2013 for Online Courses and Edu ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-59920 (Netty is an asynchronous, event-driven network application framework.  ...)
 	TODO: check
 CVE-2026-59919 (Netty is an asynchronous, event-driven network application framework.  ...)
@@ -233,11 +233,11 @@ CVE-2026-50642 (diff\u2011so\u2011fancy does not properly sanitize non\u2011SGR
 CVE-2026-50641 (Streamsoft Business Intelligence (BI) stores users' passwords in plain ...)
 	TODO: check
 CVE-2026-50622 (Description: Missing Authorizationin Apache Atlas. A missing authoriza ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-50558 (Penelope Shell Handler is a post-exploitation shell handler for author ...)
 	TODO: check
 CVE-2026-4604 (The Klubraum Membership Request plugin for WordPress is vulnerable to  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-44944 (An Incorrect Authorization vulnerability in open-iscsi allowsunprivili ...)
 	TODO: check
 CVE-2026-44943 (An Improper Limitation of a Pathname to a Restricted Directory ('Path  ...)
@@ -247,9 +247,9 @@ CVE-2026-41939 (Care Everywhere Gateway 14.3.10 contains a hard-coded credential
 CVE-2026-41920 (Improper Access Control vulnerability in Apache Traffic Server.  This  ...)
 	TODO: check
 CVE-2026-40272 (Improper Input Validation in the decode() function of the traceparser  ...)
-	TODO: check
+	NOT-FOR-US: Blackberry
 CVE-2026-35226 (An out\u2011of\u2011bounds write vulnerability in the CODESYS PROFINET ...)
-	TODO: check
+	NOT-FOR-US: CODESYS
 CVE-2026-33930 (Apache Traffic Server copies the client Host header into a fixed-size  ...)
 	TODO: check
 CVE-2026-33385 (A Blind SQL injection vulnerability has been identified in Quick.CMS.  ...)
@@ -257,11 +257,11 @@ CVE-2026-33385 (A Blind SQL injection vulnerability has been identified in Quick
 CVE-2026-33267 (Improper Input Validation vulnerability in Apache Traffic Server.  Thi ...)
 	TODO: check
 CVE-2026-2482 (IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 i ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-24033 (Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response S ...)
 	TODO: check
 CVE-2026-23904 (Kyuubi Engine UI proxy accepts a host and port from the request path a ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-22068 (Regular Expression without Anchors vulnerability in Apache Traffic Ser ...)
 	TODO: check
 CVE-2026-20316 (A vulnerability in the web interface of Cisco Secure Firewall Manageme ...)
@@ -287,21 +287,21 @@ CVE-2026-18191 (VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vul
 CVE-2026-18174 (@fastify/forwarded resolves client addresses from the X-Forwarded-For  ...)
 	TODO: check
 CVE-2026-17550 (A maliciously crafted DWG or DXF file, when parsed through Autodesk Au ...)
-	TODO: check
+	NOT-FOR-US: Autodesk
 CVE-2026-16751 (Authorization Bypass in the emergency recovery approval component in E ...)
 	TODO: check
 CVE-2026-16729 (undici's setCookie function does not fully sanitize cookie attributes. ...)
 	TODO: check
 CVE-2026-16655 (The Fluent Forms \u2013 Customizable Contact Forms, Survey, Quiz, & Co ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16597 (The GTM4WP \u2013 A Google Tag Manager (GTM) plugin for WordPress plug ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16543 (Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allo ...)
 	TODO: check
 CVE-2026-16465 (A maliciously crafted DWG or DXF file, when parsed through Autodesk Au ...)
-	TODO: check
+	NOT-FOR-US: Autodesk
 CVE-2026-16463 (A maliciously crafted DXF file, when parsed through Autodesk AutoCAD,  ...)
-	TODO: check
+	NOT-FOR-US: Autodesk
 CVE-2026-16328 (In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how  ...)
 	TODO: check
 CVE-2026-16326 (In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isol ...)
@@ -311,41 +311,41 @@ CVE-2026-15228 (Kong Kubernetes Ingress Controller (KIC) allows a user with name
 CVE-2026-15144 (@fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verba ...)
 	TODO: check
 CVE-2026-14900 (The Cost Calculator Builder PRO plugin for WordPress is vulnerable to  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14529 (IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Applic ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-14488 (The Meta Box AIO plugin for WordPress is vulnerable to Missing Authori ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14354 (CWE-522 Insufficiently Protected Credentials vulnerability exists that ...)
-	TODO: check
+	NOT-FOR-US: Schneider Electric
 CVE-2026-14270 (The Extra Checkout Options (addon for Extra Product Options & Add-Ons  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13723 (A vulnerability in the `zipx.Unzip` extraction routine of Develar's ap ...)
 	TODO: check
 CVE-2026-13697 (undici's cache interceptor mishandles malformed Cache-Control private  ...)
 	TODO: check
 CVE-2026-13425 (The Database for CF7 plugin for WordPress is vulnerable to Stored Cros ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13346 (pip would incorrectly handle doubly-encoded package URLs from indexes  ...)
 	TODO: check
 CVE-2026-12935 (The TL-WR940N v6 router contains a vulnerability in its RTSP connectio ...)
-	TODO: check
+	NOT-FOR-US: TPLink
 CVE-2026-12927 (CWE-787 Out-of-bounds write vulnerability exists that could cause loss ...)
-	TODO: check
+	NOT-FOR-US: Schneider Electric
 CVE-2026-12895 (SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frapp ...)
 	TODO: check
 CVE-2026-12703 (TeamViewer Full Client and Hostfor macOS before version 15.80containa  ...)
-	TODO: check
+	NOT-FOR-US: TeamViewer
 CVE-2026-11973 (The WP-Lister Lite for eBay plugin for WordPress is vulnerable to gene ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-10684 (In subsys/debug/coredump/coredump_shell.c, print_coredump_hdr() used t ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-0667 (CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerab ...)
-	TODO: check
+	NOT-FOR-US: Schneider Electric
 CVE-2025-60931 (An Insecure Direct Object Reference (IDOR) in the Employee Compensatio ...)
 	TODO: check
 CVE-2025-10656 (The Spreadsheet Price Changer for WooCommerce and WP E-commerce \u2013 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-64560 (In the Linux kernel, the following vulnerability has been resolved:  p ...)
 	- linux 7.1.5-1
 	NOTE: https://git.kernel.org/linus/920f893f735e92ba3a1cd9256899a186b161928d (7.2-rc3)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ebaaf9f472c8303463a5ff2609830456d1f2ef0b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ebaaf9f472c8303463a5ff2609830456d1f2ef0b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260729/467ef781/attachment.htm>


More information about the debian-security-tracker-commits mailing list