[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Sep 10 08:14:11 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
bdbd0c26 by security tracker role at 2026-09-10T07:14:00+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -35,9 +35,9 @@ CVE-2026-87922 (A security flaw has been discovered in Rizwan17 inventory-manage
CVE-2026-87921 (A vulnerability was identified in Rizwan17 inventory-management-system ...)
TODO: check
CVE-2026-87911 (An OS command injection weakness in the read-only enforcement of the S ...)
- TODO: check
+ NOT-FOR-US: Amazon
CVE-2026-87870 (The Ninja Forms - Scheduled Exports plugin for WordPress is vulnerable ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87804
REJECTED
CVE-2026-87017 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
@@ -55,7 +55,7 @@ CVE-2026-87012 (Open WebUI is an extensible, feature-rich, and user-friendly sel
CVE-2026-87011 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
TODO: check
CVE-2026-85645 (The Form Maker by 10Web \u2013 Mobile-Friendly Drag & Drop Contact For ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84939 (Path traversal vulnerability in Apache FreeMarker template loading mec ...)
TODO: check
CVE-2026-84063 (BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted u ...)
@@ -63,7 +63,7 @@ CVE-2026-84063 (BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestri
CVE-2026-84062 (BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization ...)
TODO: check
CVE-2026-82925 (The Site Reviews WordPress plugin before 8.3.0 does not prevent reques ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-82582 (An authorization bypass vulnerability exists in SHIRASAGI through a us ...)
TODO: check
CVE-2026-82079 (A stack-based buffer overflow vulnerability in the Nintendo Switch loc ...)
@@ -71,7 +71,7 @@ CVE-2026-82079 (A stack-based buffer overflow vulnerability in the Nintendo Swit
CVE-2026-81635 (A cross-site scripting vulnerability exists in SHIRASAGI, which may al ...)
TODO: check
CVE-2026-81431 (The Registration Form for WooCommerce WordPress plugin before 1.1.3 do ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-79522 (An out-of-bounds read in the gf_dm_get_chunk_data function (src/utils/ ...)
TODO: check
CVE-2026-79516 (An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h) ...)
@@ -87,13 +87,13 @@ CVE-2026-79387 (SQL injection vulnerability in PbootCMS versions 3.2.0 through 3
CVE-2026-79324 (Missing authorization in the Address Delete controller in Mageplaza GD ...)
TODO: check
CVE-2026-78361 (The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77771 (The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA Wor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77770 (The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA Wor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-76562 (The Sidebar Manager Light plugin for WordPress is vulnerable to Stored ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75880 (An authenticated client could attach a consumer with a selector contai ...)
TODO: check
CVE-2026-75308 (yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file ...)
@@ -101,15 +101,15 @@ CVE-2026-75308 (yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The
CVE-2026-75307 (zhitan-ems 1.0.0 is vulnerable to Cross Site Scripting (XSS) via SVG f ...)
TODO: check
CVE-2026-73789 (A vulnerability in the web-based management interface of CPPM guest ac ...)
- TODO: check
+ NOT-FOR-US: HPE
CVE-2026-73788 (A vulnerability in the ClearPass OnGuard agent could allow an authenti ...)
- TODO: check
+ NOT-FOR-US: HPE
CVE-2026-73787 (A vulnerability in the CPPM web interface could allow an authenticated ...)
- TODO: check
+ NOT-FOR-US: HPE
CVE-2026-73786 (A vulnerability in the web-based management interface of CPPM could al ...)
- TODO: check
+ NOT-FOR-US: HPE
CVE-2026-73769 (A vulnerability in the web-based management interface of vulnerable CP ...)
- TODO: check
+ NOT-FOR-US: HPE
CVE-2026-71809 (Authentication Bypass via Hardcoded Master Verification Code vulnerabi ...)
TODO: check
CVE-2026-71808 (A SQL Injection vulnerability in Siam Ordering (siam-server) 1.0.0 all ...)
@@ -153,7 +153,7 @@ CVE-2026-53956 (Rattler is a library that provides common functionality used wit
CVE-2026-50165 (alf.io is an open source ticket reservation system for conferences, tr ...)
TODO: check
CVE-2026-4657 (The Easy Google Fonts plugin for WordPress is vulnerable to Stored Cro ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-49364 (An unauthenticated network-adjacent attacker can leverage discovery to ...)
TODO: check
CVE-2026-49363 (An unauthenticated remote attacker connecting with the CORE protocol c ...)
@@ -165,53 +165,53 @@ CVE-2026-38998 (A use-after-free in the SocketDescriptor::tcpReadHandler1 functi
CVE-2026-36433 (An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities ...)
TODO: check
CVE-2026-19840 (The Notiqoo WordPress plugin before 1.4.14 does not have capability c ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19584 (Velociraptor allows for the creation of notebook backups in its defaul ...)
- TODO: check
+ NOT-FOR-US: Rapid7
CVE-2026-19583 (Velociraptor allows some sensitive artifacts to be gated by additional ...)
- TODO: check
+ NOT-FOR-US: Rapid7
CVE-2026-19439 (The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-19436 (The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18594 (The Advanced Contact form 7 DB plugin for WordPress is vulnerable to a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18386 (The WP BackItUp Community Edition plugin for WordPress is vulnerable t ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18351 (The Drag and Drop File Upload for Elementor Forms plugin for WordPress ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15913 (In versions prior to 7.10.2 a path traversal vulnerability in the/atta ...)
- TODO: check
+ NOT-FOR-US: Fortra
CVE-2026-15823 (The Builderall Cheetah For Wp plugin for WordPress is vulnerable to un ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15820 (The Builderall for WordPress plugin for WordPress is vulnerable to Sto ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15796 (The Builderall for WordPress plugin for WordPress is vulnerable to Sto ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15460 (The Bluetooth Classic (BR/EDR) L2CAP receive handler bt_l2cap_br_recv( ...)
- TODO: check
+ NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-15019 (The Direct Download for WooCommerce plugin for WordPress is vulnerable ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14873 (The Bulk Password Reset plugin for WordPress is vulnerable to privileg ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-0310 (A buffer overflow vulnerability in the XML processing functionality of ...)
- TODO: check
+ NOT-FOR-US: Palo Alto Networks
CVE-2026-0309 (A command injection vulnerability in Palo Alto Networks PAN-OS\xae sof ...)
- TODO: check
+ NOT-FOR-US: Palo Alto Networks
CVE-2026-0308 (A stored cross-site scripting (XSS) vulnerability in Palo Alto Network ...)
- TODO: check
+ NOT-FOR-US: Palo Alto Networks
CVE-2026-0307 (Multiple local privilege escalation vulnerabilities in the Palo Alto N ...)
- TODO: check
+ NOT-FOR-US: Palo Alto Networks
CVE-2026-0306 (A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement ...)
- TODO: check
+ NOT-FOR-US: Palo Alto Networks
CVE-2026-0305 (An information disclosure vulnerability in the Palo Alto Networks Pris ...)
- TODO: check
+ NOT-FOR-US: Palo Alto Networks
CVE-2026-0304 (A privilege escalation vulnerability in Palo Alto Networks Cortex XDR ...)
- TODO: check
+ NOT-FOR-US: Palo Alto Networks
CVE-2026-0303 (A code execution vulnerability in Palo Alto Networks Checkov by Prisma ...)
- TODO: check
+ NOT-FOR-US: Palo Alto Networks
CVE-2026-0302 (An OS command injection vulnerability in Palo Alto Networks Checkov by ...)
- TODO: check
+ NOT-FOR-US: Palo Alto Networks
CVE-2026-19816
- packagekit 1.4.0-1
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2515940
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bdbd0c2603f25345e839a3f9e686d6d6fbd8548a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bdbd0c2603f25345e839a3f9e686d6d6fbd8548a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260910/d7742e50/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list