[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Sep 1 08:13:48 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b84eb790 by security tracker role at 2026-09-01T07:13:40+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -33,7 +33,7 @@ CVE-2026-82905 (A vulnerability was detected in sdcb chats up to 1.12.0. This af
CVE-2026-82882 (Devtron through 2.2.0 fails to enforce authorization checks on the GET ...)
TODO: check
CVE-2026-82852 (Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-82835 (A weakness has been identified in caoqianming django-vue-admin 1.0. Th ...)
TODO: check
CVE-2026-82834 (A security flaw has been discovered in Doccano Open Source Annotation ...)
@@ -95,19 +95,19 @@ CVE-2026-82393 (pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm ac
CVE-2026-82392 (pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.1 ...)
TODO: check
CVE-2026-82346 (A potential security vulnerability has been identified in the HP Image ...)
- TODO: check
+ NOT-FOR-US: HP
CVE-2026-82229 (Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-82228 (Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-82226 (Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-82225 (Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-82224 (Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-82221 (Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81892 (EasyAdmin is a fast and modern admin generator for Symfony application ...)
TODO: check
CVE-2026-81891 (elFinder is an open-source file manager for web, written in JavaScript ...)
@@ -121,43 +121,43 @@ CVE-2026-81888 (@hono/oauth-providers is Authentication middleware for Hono. Pri
CVE-2026-81887 (Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 unti ...)
TODO: check
CVE-2026-81780 (Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81779 (Improper Validation of Specified Quantity in Input vulnerability in Si ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81778 (Subscriber Cross Site Scripting (XSS) in Kalles Addons <= 1.0.6 versio ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81768 (Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81765 (Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81764 (Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81763 (Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81762 (Subscriber Broken Access Control in Booking and Rental Manager <= 2.7. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81758 (Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81756 (Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters F ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81298 (Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81297 (Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81296 (Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81293 (Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81291 (Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 version ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81290 (Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & News ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81287 (Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81280 (Subscriber Sensitive Data Exposure in Print Barcode Labels for your Wo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81278 (Missing Authorization vulnerability in WPExperts Post SMTP allows Expl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin or theme
CVE-2026-81267 (A malicious webpage could stall a popup's cross-origin navigation afte ...)
TODO: check
CVE-2026-79483 (FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a No ...)
@@ -173,7 +173,7 @@ CVE-2026-77950 (Generation of Error Message Containing Sensitive Information vul
CVE-2026-77856 (Allocation of Resources Without Limits or Throttling vulnerability in ...)
TODO: check
CVE-2026-77823 (The LearnPress plugin for WordPress is vulnerable to SQL Injection via ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77353 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
TODO: check
CVE-2026-77352 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
@@ -183,19 +183,19 @@ CVE-2026-77351 (Wallos is an open-source, self-hostable personal subscription tr
CVE-2026-77348 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
TODO: check
CVE-2026-77189 (The Charitable \u2013 Donation & Fundraising Platform (Donation Forms, ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-76006 (The Photo Gallery by Ays \u2013 Responsive Image Gallery plugin for Wo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75980 (The BetterDocs \u2013 AI Documentation, Knowledge Base, Docs, Wikis, F ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75965 (The User Profile Builder \u2013 Beautiful User Registration Forms, Use ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75964 (The User Profile Builder \u2013 Beautiful User Registration Forms, Use ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75921 (The Master Addons for Elementor \u2013 Elementor Addons, Widgets, Mega ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75865 (The WPLP Cookie Consent \u2013 Cookie Banner & Consent Management for ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75594 (Kirby is an open-source content management system. Prior to 4.9.5 and ...)
TODO: check
CVE-2026-75592 (Kirby is an open-source content management system. Prior to 4.9.5 and ...)
@@ -235,25 +235,25 @@ CVE-2026-54179 (backpack/crud provides Create, Read, Update & Delete (CRUD) func
CVE-2026-52730 (Xibo is an open source digital signage platform with a web content man ...)
TODO: check
CVE-2026-51740 (Incorrect access control in the killProcess function of TOTOLINK T6 4. ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51739 (Incorrect access control in the CloudSrvVersionCheck function of TOTOL ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51738 (Incorrect access control in the LoadDefSettings function of TOTOLINK T ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51737 (Incorrect access control in the clearTracerouteLog function of TOTOLIN ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51736 (Incorrect access control in the clearSyslog function of TOTOLINK T6 4. ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51735 (Incorrect access control in the showSyslog function of TOTOLINK T6 4.1 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51734 (Incorrect access control in the informSlaveUpdate function of TOTOLINK ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51733 (Incorrect access control in the FirmwareUpgrade function of TOTOLINK T ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51732 (Incorrect access control in the delWiFiScheduleCfg function of TOTOLIN ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-51731 (Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-50199 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
TODO: check
CVE-2026-50198 (Wallos is an open-source, self-hostable personal subscription tracker. ...)
@@ -263,39 +263,39 @@ CVE-2026-4560
CVE-2026-48932 (A flaw in Node.js HTTP client can cause a request desynchronization fo ...)
TODO: check
CVE-2026-38577 (Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0 ...)
- TODO: check
+ NOT-FOR-US: Tenda
CVE-2026-19952 (The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19948 (The Cozy Blocks \u2013 Page Builder for Gutenberg Editor & FSE with 70 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19820 (A vulnerability in the Backblaze Client allows a local user to make th ...)
TODO: check
CVE-2026-19806 (The Support Genix \u2013 Helpdesk, AI Chatbot, Knowledge Base & Custom ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19796 (The Listdom: AI-powered Business Directory with Classifieds Ads Listin ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19573 (The Affiliate Super Assistent plugin for WordPress is vulnerable to St ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19032 (jackson-databind's deserializer for java.nio.file.Path resolves an att ...)
TODO: check
CVE-2026-18752 (The Persistent Login plugin for WordPress is vulnerable to generic SQL ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18743 (A flaw was found in popt. This vulnerability allows an attacker to pro ...)
TODO: check
CVE-2026-18488 (The Blocksy Companion plugin for WordPress is vulnerable to Stored Cro ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17589 (The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16787 (The Live Composer \u2013 Free WordPress Website Builder plugin for Wor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14697 (net_ipv6_send_ns() in subsys/net/ip/ipv6_nbr.c allocates a transmit ne ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-13732 (A flaw was found in GDB's STABS debug format parser. The read_member_f ...)
TODO: check
CVE-2026-13203 (The Live Composer \u2013 Free WordPress Website Builder plugin for Wor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12747 (The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2025-63607 (TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_ ...)
TODO: check
CVE-2026-XXXX [GHSA-g89c-p67h-r497: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items]
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b84eb790f49ec71c36aaf0db0dbd2173a76aba4d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b84eb790f49ec71c36aaf0db0dbd2173a76aba4d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260901/424109b1/attachment.htm>
More information about the debian-security-tracker-commits
mailing list