[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Mar 6 20:15:02 GMT 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
21a8fa5c by security tracker role at 2026-03-06T20:14:49+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
CVE-2026-3653
REJECTED
CVE-2026-3589 (The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does no ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-3419 (Fastify incorrectly accepts malformed `Content-Type` headers containin ...)
TODO: check
CVE-2026-30847 (Wekan is an open source kanban tool built with Meteor. In versions 8.3 ...)
@@ -47,9 +47,9 @@ CVE-2026-29063 (Immutable.js provides many Persistent Immutable data structures.
CVE-2026-28514 (Rocket.Chat is an open-source, secure, fully customizable communicatio ...)
TODO: check
CVE-2026-28106 (URL Redirection to Untrusted Site ('Open Redirect') vulnerability in K ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-28080 (Missing Authorization vulnerability in Rank Math Rank Math SEO PRO all ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-27777 (Charging station authentication identifiers are publicly accessible vi ...)
TODO: check
CVE-2026-27764 (The WebSocket backend uses charging station identifiers to uniquely as ...)
@@ -101,7 +101,7 @@ CVE-2025-69644 (An issue was discovered in Binutils before 2.46. The objdump con
CVE-2025-15602 (Snipe-IT versions prior to 8.3.7 contain sensitive user attributes rel ...)
TODO: check
CVE-2024-35644 (Improper Neutralization of Input During Web Page Generation (XSS or 'C ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2022-4947
REJECTED
CVE-2018-25200 (OOP CMS BLOG 1.0 contains a cross-site request forgery vulnerability t ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/21a8fa5cf33a1fe046fdaf75853c7f528bde09be
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/21a8fa5cf33a1fe046fdaf75853c7f528bde09be
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260306/9af73785/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list