[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Sep 6 13:25:18 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
cb1c9666 by Salvatore Bonaccorso at 2026-09-06T14:24:02+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -200,7 +200,7 @@ CVE-2026-0799 (In BPF instructions that load/store a value from/to a scratch mem
 CVE-2025-9049 (The Nokri \u2013 Job Board WordPress Theme theme for WordPress is vuln ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-15647 (CDT before 1.4.5 contains an out-of-bounds read vulnerability in the o ...)
-	TODO: check
+	NOT-FOR-US: CDT
 CVE-2025-15614 (ugrep before 7.6.0 contains a heap buffer over-read vulnerability in t ...)
 	- ugrep 7.6.0+dfsg-1
 	NOTE: https://github.com/Genivia/ugrep/issues/511
@@ -899,15 +899,15 @@ CVE-2026-4644 (A Missing Authorization vulnerability in HTTP Connector in Google
 CVE-2026-4361 (The Divi theme for WordPress is vulnerable to Server-Side Request Forg ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-44402 (Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote co ...)
-	TODO: check
+	NOT-FOR-US: Voltronic Power SNMP Web Pro
 CVE-2026-3853 (The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-S ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-38961 (Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate  ...)
-	TODO: check
+	NOT-FOR-US: Netgate pfSense Plus
 CVE-2026-32480 (Missing Authorization vulnerability in WC Lovers WCFM Membership allow ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-31020 (In DocsGPT 0.15.0 and below, the application provides a custom prompt  ...)
-	TODO: check
+	NOT-FOR-US: DocsGPT
 CVE-2026-27432 (Authorization Bypass Through User-Controlled Key vulnerability in sc I ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27347 (Missing Authorization vulnerability in Crocoblock JetPopup allows Expl ...)
@@ -923,7 +923,7 @@ CVE-2026-19858 (The JetFormBuilder \u2014 Dynamic Blocks Form Builder WordPress
 CVE-2026-19769 (The Ninja Forms \u2013 The Contact Form Builder That Grows With You pl ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-19727 (Improper neutralization of input during web page generation ('cross-si ...)
-	TODO: check
+	NOT-FOR-US: Library Information and Document Automation Program
 CVE-2026-19649 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thr ...)
 	NOT-FOR-US: IBM
 CVE-2026-19645 (IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user  ...)
@@ -1074,7 +1074,7 @@ CVE-2026-14975 (The WP File Download plugin for WordPress is vulnerable to Direc
 CVE-2026-14470 (IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated att ...)
 	NOT-FOR-US: IBM
 CVE-2026-14466 (It\u2019s possible to run a stored XSS in Stormshield\u2019s web admin ...)
-	TODO: check
+	NOT-FOR-US: Stormshield
 CVE-2026-14350 (IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could a ...)
 	NOT-FOR-US: IBM
 CVE-2026-13447 (The Mstore Api plugin for WordPress is vulnerable to Authentication By ...)
@@ -1086,7 +1086,7 @@ CVE-2026-13148 (Missing release of memory after effective lifetime vulnerability
 CVE-2026-12483 (The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted F ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-67066 (SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote ...)
-	TODO: check
+	NOT-FOR-US: oasys sysoa
 CVE-2025-15694 (The Joli Table Of Contents WordPress plugin before 2.8.1 does not sani ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-15693 (The JCH Optimize WordPress plugin before 5.0.1 does not properly restr ...)
@@ -502131,11 +502131,11 @@ CVE-2022-35501 (Stored Cross-site Scripting (XSS) exists in the Amasty Blog Pro
 CVE-2022-35500 (Amasty Blog 2.10.3 is vulnerable to Cross Site Scripting (XSS) via lea ...)
 	NOT-FOR-US: Amasty Blog
 CVE-2022-35499 (In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulne ...)
-	TODO: check
+	NOT-FOR-US: Trimble TM4WEB
 CVE-2022-35498
 	RESERVED
 CVE-2022-35497 (In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with sessi ...)
-	TODO: check
+	NOT-FOR-US: Trimble TM4WEB
 CVE-2022-35496
 	RESERVED
 CVE-2022-35495
@@ -527222,7 +527222,7 @@ CVE-2022-26963
 CVE-2022-26962
 	RESERVED
 CVE-2022-26961 (Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_ ...)
-	TODO: check
+	NOT-FOR-US: Italtel NetMatch-S
 CVE-2022-26960 (connector.minimal.php in std42 elFinder through 2.1.60 is affected by  ...)
 	NOT-FOR-US: std42 elFinder
 CVE-2022-26959 (There are two full (read/write) Blind/Time-based SQL injection vulnera ...)
@@ -549277,9 +549277,9 @@ CVE-2021-44322
 CVE-2021-44321 (Mini-Inventory-and-Sales-Management-System is affected by Cross Site R ...)
 	NOT-FOR-US: Mini-Inventory-and-Sales-Management-System
 CVE-2021-44320 (Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism t ...)
-	TODO: check
+	NOT-FOR-US: Parrot AR.Drone
 CVE-2021-44319 (Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service.  ...)
-	TODO: check
+	NOT-FOR-US: Parrot AR.Drone
 CVE-2021-44318
 	RESERVED
 CVE-2021-44317 (In Bus Pass Management System v1.0, parameters 'pagedes' and `About Us ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb1c96665fd4cdd6749ad4f8b5887b6340bcc08e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb1c96665fd4cdd6749ad4f8b5887b6340bcc08e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260906/dc62d9cd/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list