[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 30 08:13:18 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ef6bcbdc by security tracker role at 2026-07-30T07:13:12+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2026-6336 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-6267 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-6102 (MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalat ...)
 	TODO: check
 CVE-2026-67595 (VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated Ja ...)
@@ -25,15 +25,15 @@ CVE-2026-67431 (MCP Ruby SDK is the official Ruby SDK for Model Context Protocol
 CVE-2026-67430 (MCP Ruby SDK is the official Ruby SDK for Model Context Protocol serve ...)
 	TODO: check
 CVE-2026-67248 (A stack-based buffer overflow vulnerability was found in the File Expl ...)
-	TODO: check
+	NOT-FOR-US: Asustor
 CVE-2026-67247 (A path traversal vulnerability was found in the IHM Log handling of AD ...)
-	TODO: check
+	NOT-FOR-US: Asustor
 CVE-2026-67246 (A path traversal vulnerability was found in the Wallpaper component of ...)
-	TODO: check
+	NOT-FOR-US: Asustor
 CVE-2026-67245 (A path traversal vulnerability was found in the VPN Clients on the ADM ...)
-	TODO: check
+	NOT-FOR-US: Asustor
 CVE-2026-67244 (A format string vulnerability was found in the Notification OAuth sett ...)
-	TODO: check
+	NOT-FOR-US: Asustor
 CVE-2026-65975 (Pydantic AI is a Python agent framework for building applications and  ...)
 	TODO: check
 CVE-2026-64685 (ImageMagick is free and open-source software used for editing and mani ...)
@@ -87,11 +87,11 @@ CVE-2026-54249 (Pydantic AI is a Python agent framework for building Generative
 CVE-2026-50782 (Jinher OA C6 contains an XML External Entity (XXE) injection vulnerabi ...)
 	TODO: check
 CVE-2026-4672 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-48449 (Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-48448 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-47882 (When enabling Spring Boot DevTools support for a remote application ta ...)
 	TODO: check
 CVE-2026-47873 (The Boot Dashboard Docker integration in Spring Tools publishes contai ...)
@@ -101,19 +101,19 @@ CVE-2026-47858 (Starting Spring Boot applications in the Spring Tools with the l
 CVE-2026-46678 (Pydantic AI is a Python agent framework for building Generative AI app ...)
 	TODO: check
 CVE-2026-3093 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-1982 (The Persian Elementor (\u0627\u0644\u0645\u0646\u062a\u0648\u0631 \u06 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-1360 (The BuddyPress plugin for WordPress is vulnerable to Deserialization o ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18266 (Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This  ...)
 	TODO: check
 CVE-2026-18188 (A format string vulnerability was found in the Rsync Backup on the ADM ...)
-	TODO: check
+	NOT-FOR-US: Asustor
 CVE-2026-18187 (A format string vulnerability was found in the Internal Backup on the  ...)
-	TODO: check
+	NOT-FOR-US: Asustor
 CVE-2026-18186 (A stored format string vulnerability was found in the FTP Backup on th ...)
-	TODO: check
+	NOT-FOR-US: Asustor
 CVE-2026-18060
 	REJECTED
 CVE-2026-18022 (Integer wraparound in IVFFlat index build in pgvector before 0.8.6 all ...)
@@ -861,11 +861,11 @@ CVE-2026-17650 (Use after free in Compositing in Google Chrome prior to 151.0.79
 CVE-2026-16728 (undici's retry interceptor can deliver a response whose body length do ...)
 	TODO: check
 CVE-2026-16727 (Concurrent Execution using Shared Resource with Improper Synchronizati ...)
-	TODO: check
+	NOT-FOR-US: ASUS
 CVE-2026-16610 (The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vuln ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16553 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-16531 (An unauthenticated remote attacker can exploit a path traversal vulner ...)
 	TODO: check
 CVE-2026-16530 (A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service.  ...)
@@ -881,79 +881,79 @@ CVE-2026-16524 (A command injection flaw in PCP's linux_sockets PMDA allows mali
 CVE-2026-16339
 	REJECTED
 CVE-2026-16092 (The Improved Save Button plugin for WordPress is vulnerable to second- ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15975 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-15929 (Improper neutralization of special elements used in an SQL command ('S ...)
 	TODO: check
 CVE-2026-15831 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-15382 (The Ultimate Addons for WPBakery Page Builder WordPress plugin before  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15257 (The RegistrationMagic  WordPress plugin before 6.0.9.4 does not perfor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15255 (The RegistrationMagic  WordPress plugin before 6.0.9.4 does not proper ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15252 (The Search Atlas SEO  WordPress plugin before 2.6.12 does not perform  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15250 (The Appointment Booking Plugin  WordPress plugin before 5.6.8 does not ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15240 (The Customer Switching WordPress plugin before 2.1.3 does not securely ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15235 (The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not per ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15157 (undici does not validate the type property of a duck-typed blob-like r ...)
 	TODO: check
 CVE-2026-15153 (The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15077 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-15054 (The Bit Form  WordPress plugin before 3.1.2 does not enforce a form's  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14923 (The Sync Post With Other Site WordPress plugin before 1.9.3 does not c ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14643 (undici's cache interceptor mishandles optional whitespace placed aroun ...)
 	TODO: check
 CVE-2026-14602 (The Remote API WordPress plugin through 0.2 does not authenticate a re ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14592 (The WP Real IP-based Access Control WordPress plugin through 1.3.1 doe ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14356 (The FleekDash V2 plugin for WordPress is vulnerable to authorization b ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14351 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-14341 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-14318 (The GiveWP  WordPress plugin before 4.16.3 does not escape a donation- ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14310 (The Tutor LMS  WordPress plugin before 4.0.0 does not properly verify  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14305 (The WP Delicious  WordPress plugin before 1.10.2 does not perform an a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14239 (The tourmaster WordPress plugin before 5.4.8 does not perform a nonce  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14231 (The LifterLMS  WordPress plugin before 10.0.10 does not perform a capa ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14226 (The Easy Appointments WordPress plugin through 3.12.26 does not requir ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14223 (The Easy Appointments WordPress plugin through 3.12.26 does not verify ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14222 (The Easy Appointments WordPress plugin through 3.12.26 does not perfor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14221 (The Easy Appointments WordPress plugin through 3.12.26 does not perfor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14207 (The LifterLMS  WordPress plugin before 10.0.10 does not strip event-ha ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14188 (The Easy Appointments WordPress plugin through 3.12.26 does not perfor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13395 (The Online Scheduling and Appointment Booking System  WordPress plugin ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13345 (The Essential Addons for Elementor  WordPress plugin before 6.6.10 doe ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13344 (The Essential Addons for Elementor  WordPress plugin before 6.6.10 doe ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13330 (The Animation Addons for Elementor  WordPress plugin before 2.7.0 does ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13309 (Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitr ...)
 	TODO: check
 CVE-2026-13308 (Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Co ...)
@@ -967,29 +967,29 @@ CVE-2026-13305 (Autel MaxiCharger AC Elite Home Software Update Improper Verific
 CVE-2026-13268 (G DATA Total Security Backup Service Link Following Local Privilege Es ...)
 	TODO: check
 CVE-2026-13178 (The Eventin  WordPress plugin before 4.1.16 does not properly authoriz ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13145 (The WP Travel  WordPress plugin before 11.8.1 does not verify that the ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13143 (The WP Travel  WordPress plugin before 11.8.1 does not verify PayPal I ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13113 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-12687 (The ProfileGrid  WordPress plugin before 5.9.9.8 does not restrict whi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12500 (The WP Travel Engine  WordPress plugin before 6.8.2 does not perform a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12436 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-12357 (Heimdall Data Database Proxy generateFileContent CRLF Injection Remote ...)
 	TODO: check
 CVE-2026-11881 (The Fluent Forms  WordPress plugin before 6.2.6 does not sanitise and  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11870 (The WP Ghost (Hide My WP Ghost)  WordPress plugin before 7.0.05 does n ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11867 (The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does n ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11782 (The Points and Rewards for WooCommerce WordPress plugin before 2.10.1  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-69949 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injecti ...)
 	TODO: check
 CVE-2025-69945 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injecti ...)
@@ -1001,23 +1001,23 @@ CVE-2025-69943 (kishan0725 Hospital Management System 4.0 is vulnerale to SQL In
 CVE-2025-69942 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injecti ...)
 	TODO: check
 CVE-2025-67408 (Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to  ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2025-67407 (Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to  ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2025-67406 (https://www.sourcecodester.com Advocate office management system 1.0 i ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2025-67405 (Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to  ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2025-67404 (Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to  ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2025-67403 (Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to  ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2025-65340 (kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injecti ...)
 	TODO: check
 CVE-2025-65337 (Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scri ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2025-14562 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-9720 (The Facturaci\xf3n Electr\xf3nica Costa Rica plugin for WordPress is v ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-9177 (A Server-Side Template Injection (SSTI) vulnerability was identified   ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ef6bcbdce4804beea687ab8eb2c88b5e34898424

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ef6bcbdce4804beea687ab8eb2c88b5e34898424
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260730/69618837/attachment.htm>


More information about the debian-security-tracker-commits mailing list