[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 2 08:14:31 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
442e6ecd by security tracker role at 2026-09-02T07:14:23+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
 CVE-2026-9055 (The Booking for Appointments and Events Calendar \u2013 Amelia (Premiu ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84715 (FeatherPanel versions before 1.3.7.10 fail to validate permissions in  ...)
 	TODO: check
 CVE-2026-84702 (facefusion through 3.6.1 fails to normalize job identifiers in get_job ...)
@@ -111,59 +111,59 @@ CVE-2026-84287 (A flaw has been found in NousResearch hermes-agent 0.18.0. Affec
 CVE-2026-84208 (AVideo through version 29.0 contains an unauthenticated SQL injection  ...)
 	TODO: check
 CVE-2026-83549 (Post-authentication Improper Neutralization of Special Elements used i ...)
-	TODO: check
+	NOT-FOR-US: SonicWall
 CVE-2026-83548 (A Pre-authentication SSRF vulnerability exists in the SMA1000 Applianc ...)
-	TODO: check
+	NOT-FOR-US: SonicWall
 CVE-2026-82968 (A flaw was found in the first-broker-login flow of the Keycloak identi ...)
 	TODO: check
 CVE-2026-82883 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-82183 (The OAuth Single Sign On  WordPress plugin before 7.0.1 does not verif ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-82182 (The WPvivid \u2014 Backup, Migration & Staging WordPress plugin before ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81846 (An authorization bypass in the runZero Platform MCP service has been r ...)
 	TODO: check
 CVE-2026-81807 (The Simple Ajax Chat  WordPress plugin before 20260827 does not escape ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81737 (The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81583 (The  My Login WordPress plugin before 7.2.0 does not enforce the netwo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81432 (The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does n ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81428 (The WC Vendors  WordPress plugin before 2.7.2.1 does not verify owners ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81427 (The WC Vendors  WordPress plugin before 2.7.2.1 does not verify that t ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81426 (The WC Vendors  WordPress plugin before 2.7.2.1 does not have CSRF pro ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81199 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.46 d ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81198 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.46 d ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81197 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.46 d ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81196 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.46 d ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81195 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.46 d ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81194 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.46 d ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-80467 (The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 d ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-79621 (The CatalogX  WordPress plugin before 6.1.3 does not sanitise or escap ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-78657 (The SigmaForms Pro \u2013 AI Generated Forms plugin for WordPress is v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-78608 (Missing Authorization (CWE-862) in Kibana can lead to information disc ...)
 	TODO: check
 CVE-2026-78607 (Missing Authorization (CWE-862) in the Elasticsearch custom inference  ...)
-	TODO: check
+	NOT-FOR-US: Elasticsearch
 CVE-2026-78606 (Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized d ...)
 	TODO: check
 CVE-2026-78605 (Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling' ...)
-	TODO: check
+	NOT-FOR-US: Elasticsearch
 CVE-2026-78603 (Missing Authorization (CWE-862) in Kibana can lead to information disc ...)
 	TODO: check
 CVE-2026-78597 (Missing Authorization (CWE-862) in the Kibana Entity Store feature can ...)
@@ -171,23 +171,23 @@ CVE-2026-78597 (Missing Authorization (CWE-862) in the Kibana Entity Store featu
 CVE-2026-78592 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
 	TODO: check
 CVE-2026-78151 (The FormLayer WordPress plugin before 1.0.9 does not perform any autho ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77792 (The RegistrationMagic  WordPress plugin before 6.0.9.9 does not escape ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77788 (The Rank Math SEO  WordPress plugin before 1.0.277 does not verify tha ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77787 (The Rank Math SEO  WordPress plugin before 1.0.277 does not perform a  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77785 (The Rank Math SEO  WordPress plugin before 1.0.277 does not verify tha ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77784 (The Rank Math SEO  WordPress plugin before 1.0.277 does not verify tha ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77783 (The Rank Math SEO  WordPress plugin before 1.0.277 does not verify tha ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77782 (The Rank Math SEO  WordPress plugin before 1.0.277.1 does not check wh ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77764 (The GamiPress  WordPress plugin before 7.9.9.6 does not properly restr ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77223
 	REJECTED
 CVE-2026-77222
@@ -195,181 +195,181 @@ CVE-2026-77222
 CVE-2026-77221
 	REJECTED
 CVE-2026-76851 (A Server-Side Request Forgery (SSRF) vulnerability was identified in G ...)
-	TODO: check
+	NOT-FOR-US: Github Enterprise Server
 CVE-2026-76658 (A vulnerability has been identified in the SSH daemon of HPE Networkin ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-76657 (Vulnerabilities have been identified in the API of HPE Networking Fabr ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-75604 (Next.js is a React framework for building full-stack web applications. ...)
-	TODO: check
+	NOT-FOR-US: Next.js
 CVE-2026-74927 (The MultiVendorX  WordPress plugin before 5.0.15 does not have proper  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-73783 (Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Suc ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73782 (A format string vulnerability exists in the command line interface of  ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73781 (A vulnerability in the web-based management interface of AOS-CX could  ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73780 (A vulnerability in the web-based management interface of AOS-CX switch ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73779 (Vulnerabilities have been identified in the operating system of AOS-CX ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73778 (A vulnerability exists in the Credential Manager component that may al ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73777 (Vulnerabilities have been identified in the API endpoint of AOS-CX swi ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73776 (A signature verification bypass vulnerability exists in the command li ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73775 (Vulnerabilities in the API endpoint of AOS-CX could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73774 (A buffer overflow vulnerability exists in the underlying operating sys ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73773 (An unauthenticated Denial-of-Service (DoS) vulnerability exists in the ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73772 (Buffer overflow vulnerabilities exist in an underlying service of AOS- ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73771 (An authentication vulnerability exists in the AOS-CX management interf ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73770 (An authenticated arbitrary file write vulnerability exists in AOS-CX.  ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73768 (A vulnerability exists in the command line interface of AOS-CX that ma ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73767 (Authenticated command injection vulnerabilities exist in the command l ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73766 (Command injection vulnerabilities in the API endpoint of AOS-CX could  ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73765 (Authenticated path traversal vulnerabilities exist in API endpoints of ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73764 (Vulnerabilities have been identified in the operating system of AOS-CX ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73763 (A vulnerability exists in a management component that could allow an u ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73762 (A vulnerability has been identified in the API endpoint of AOS-CX that ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73761 (An out-of-bounds read vulnerability exists in the underlying operating ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73760 (An authenticated Path Traversal vulnerability exists in AOS-CX. Succes ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73759 (Vulnerabilities in AOS-CX could allow an unauthenticated remote malici ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73758 (A privilege escalation vulnerability exists in the API endpoint of AOS ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73757 (A vulnerability in the web-based management interface of AOS-CX could  ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73756 (A vulnerability in an API endpoint of AOS-CX could allow a remote unau ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73755 (A privilege escalation vulnerability exists in the API endpoint of AOS ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73754 (Denial-of-service vulnerabilities exist in the command line interface  ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73753 (Exploitation through affected command-line operations could allow an a ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73752 (An unauthenticated arbitrary file write vulnerability exists in an API ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73751 (An authenticated user with low-privileged access could submit crafted  ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73750 (Vulnerabilities exist in the authentication module that may improperly ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73749 (Multiple vulnerabilities exist in a daemon of AOS-CX that may allow fo ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73748 (A vulnerability in the affected interface of HPE Networking Fabric Com ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73747 (A local privilege-escalation vulnerability has been discovered in HPE  ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73746 (A denial-of-service vulnerability exists in the API of HPE Networking  ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73745 (A vulnerability in the API endpoint of HPE Networking Fabric Composer  ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73744 (A denial-of-service vulnerability exists in the web-based management i ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73743 (A vulnerability in the web-based management interface of HPE Networkin ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73742 (A vulnerability in an API endpoint of HPE Networking Fabric Composer c ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73741 (A vulnerability in the API of HPE Networking Fabric Composer could all ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73740 (A local privilege escalation vulnerability in HPE Networking Fabric Co ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73739 (A vulnerability exists in the API of HPE Networking Fabric Composer th ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73738 (A vulnerability in the underlying operating system of HPE Networking F ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73737 (An unauthenticated path traversal vulnerability exists in the API endp ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73736 (A vulnerability in the web-based management interface of HPE Networkin ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73735 (Vulnerabilities in the API of HPE Networking Fabric Composer could all ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73734 (A vulnerability in the web-based management interface of HPE Networkin ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73733 (Authentication bypasses in the API of HPE Networking Fabric Composer c ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73732 (A vulnerability in the underlying operating system of HPE Networking F ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73731 (A vulnerability in the web-based management interface of HPE Networkin ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73730 (A privilege escalation vulnerability exists in the API of HPE Networki ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73729 (A vulnerability in the underlying operating system of HPE Networking F ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73728 (Denial-of-service vulnerabilities exist in the API of HPE Networking F ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73727 (Vulnerabilities in the API of HPE Networking Fabric Composer could all ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73726 (A vulnerability has been identified in the underlying operating system ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73725 (A local privilege-escalation vulnerability has been discovered in HPE  ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73724 (Privilege escalation vulnerabilities exist in the API of HPE Networkin ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73723 (A privilege escalation vulnerability exists in the web-based managemen ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73722 (Command injection vulnerabilities in the web-based management interfac ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73721 (Vulnerabilities in the API of HPE Networking Fabric Composer could all ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73720 (Insecure file operations in the API of HPE Networking Fabric Composer  ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73719 (An arbitrary file write vulnerability exists in the API of HPE Network ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73718 (A vulnerability in the web-based management interface of HPE Networkin ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73717 (A command injection vulnerability exists in the web-based management i ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73716 (A remote code execution vulnerability exists in the underlying operati ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73715 (A vulnerability in the API of HPE Networking Fabric Composer could all ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73714 (A sensitive information disclosure vulnerability exists in the API of  ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73713 (Local privilege-escalation vulnerabilities have been discovered in HPE ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73712 (A vulnerability in the API of HPE Networking Fabric Composer could all ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73711 (A privilege escalation vulnerability exists in the API endpoint of HPE ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73710 (Vulnerabilities in an API endpoint of HPE Networking Fabric Composer c ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73709 (A vulnerability in the underlying operating system of HPE Networking F ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73708 (A business logic vulnerability exists in the API of HPE Networking Fab ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73707 (Privilege escalation vulnerabilities exist in the API of HPE Networkin ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73706 (A vulnerability in the API of HPE Networking Fabric Composer could all ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73705 (An arbitrary file write vulnerability in the API of HPE Networking Fab ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73704 (A command sanitization bypass exists in the API of HPE Networking Fabr ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73703 (A vulnerability in the web-based management interface of HPE Networkin ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73702 (A privilege escalation vulnerability exists in the API of HPE Networki ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73701 (An unauthenticated remote code execution vulnerability exists in the u ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73700 (A vulnerability in the web-based management interface of HPE Networkin ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-73524 (Cypht before 2.12.2 contains a cross-site scripting vulnerability in t ...)
 	TODO: check
 CVE-2026-72682 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
@@ -379,7 +379,7 @@ CVE-2026-72654 (Execution with Unnecessary Privileges (CWE-250) in the Kibana ma
 CVE-2026-72652 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
 	TODO: check
 CVE-2026-72649 (Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machi ...)
-	TODO: check
+	NOT-FOR-US: Elasticsearch
 CVE-2026-72644 (Uncaught Exception (CWE-248) in Kibana can lead to a denial of service ...)
 	TODO: check
 CVE-2026-72641 (Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized m ...)
@@ -397,57 +397,57 @@ CVE-2026-63138 (Improper Neutralization of Special Elements in Data Query Logic
 CVE-2026-63137 (Incorrect Authorization (CWE-863) in Kibana can lead to privilege esca ...)
 	TODO: check
 CVE-2026-56143 (Allocation of Resources Without Limits or Throttling (CWE-770) in Elas ...)
-	TODO: check
+	NOT-FOR-US: Elasticsearch
 CVE-2026-45221 (Konga before 2.1.0 contains a privilege escalation vulnerability that  ...)
 	TODO: check
 CVE-2026-3851 (The Divi theme for WordPress is vulnerable to Stored Cross-Site Script ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-3850 (The Divi theme for WordPress is vulnerable to Stored Cross-Site Script ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-33465 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
 	TODO: check
 CVE-2026-19766 (An authentication bypass vulnerability exists in the underlying operat ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-19754 (Baserow 2.3.3 contains a SQL injection vulnerability in the index() fo ...)
 	TODO: check
 CVE-2026-19723 (The Social Media Share Buttons & Social Sharing Icons WordPress plugin ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19719 (The Social Media Share Buttons & Social Sharing Icons WordPress plugin ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19704 (The Comments  WordPress plugin before 7.6.66 does not validate a value ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19453 (The JetBackup  WordPress plugin before 3.1.23.5 does not verify the ro ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19251 (The Ultimate Member  WordPress plugin before 2.13.0 does not check whe ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19118 (A time-of-check time-of-use race condition vulnerability was identifie ...)
-	TODO: check
+	NOT-FOR-US: Github Enterprise Server
 CVE-2026-19116 (The User Frontend  WordPress plugin before 4.3.11 does not prevent use ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18730 (A server-side request forgery (SSRF) vulnerability was identified in G ...)
-	TODO: check
+	NOT-FOR-US: Github Enterprise Server
 CVE-2026-16983 (The Gutentor  WordPress plugin before 4.0.6 does not apply the correct ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16966 (The Solace Extra WordPress plugin before 1.7.0 does not perform any au ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15232 (The MotoPress Appointment Booking WordPress plugin before 2.4.8 does n ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14982 (The WP File Download plugin for WordPress is vulnerable to arbitrary f ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14357 (The DevKit Pro plugin for WordPress is vulnerable to Missing Authoriza ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14215 (The Booking for Appointments and Events Calendar  WordPress plugin bef ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12865 (The Photo Gallery by 10Web  WordPress plugin before 1.8.44 does not es ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12526 (The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 d ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-46418 (Westermo WeOS 5.x starting from 5.24 allows OS command injection via a ...)
 	TODO: check
 CVE-2025-15664 (The Ultimate Before After Image Slider & Gallery  WordPress plugin bef ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-15663 (The Ultimate Before After Image Slider & Gallery  WordPress plugin bef ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2024-35585 (Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP ad ...)
 	TODO: check
 CVE-2023-54391 (Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentic ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/442e6ecdbe62c5df33299d2cdbb7aa72054a113f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/442e6ecdbe62c5df33299d2cdbb7aa72054a113f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260902/ffb2e751/attachment.htm>


More information about the debian-security-tracker-commits mailing list