[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 12 08:14:14 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bbf0919e by security tracker role at 2026-09-12T07:14:01+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -35,7 +35,7 @@ CVE-2026-90444 (A file-transfer interface that requires valid credentials accept
 CVE-2026-90443 (A web interface reflects a portion of the request URL into a script co ...)
 	TODO: check
 CVE-2026-89332 (Inclusion of functionality from an untrusted control sphere in the Kir ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-89268 (QloApps through 1.7.0 renders back-office list filter POST parameters  ...)
 	TODO: check
 CVE-2026-89267 (starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the sea ...)
@@ -43,109 +43,109 @@ CVE-2026-89267 (starlette-admin versions 0.16.1 through 0.17.1 fail to enforce t
 CVE-2026-89266 (stb_vorbis through 1.22 contains a heap buffer overflow in start_decod ...)
 	TODO: check
 CVE-2026-87919 (The Product XML Feed Manager for WooCommerce  WordPress plugin before  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87918 (The WPBot  WordPress plugin before 8.5.7 does not perform any authoriz ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87916 (The WPBot  WordPress plugin before 8.6.0 does not perform any capabili ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87894 (The Rox Appointment Booking  WordPress plugin before 1.2.3 does not pe ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87892 (The Rox Appointment Booking  WordPress plugin before 1.2.0 does not ve ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87891 (The Rox Appointment Booking  WordPress plugin before 1.2.0 does not pe ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87888 (The YayPricing  WordPress plugin before 3.5.7 does not perform an auth ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87842 (The Zonify  WordPress plugin before 1.0.5 does not perform any capabil ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87797 (The Sprout Invoices  WordPress plugin before 20.8.16 does not perform  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87759 (The Add User Autocomplete WordPress plugin before 1.2 does not perform ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87719 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-86790 (The WP Highlight Box WordPress plugin through 1.0 does not escape some ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-85706 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-85681 (The WP Component WordPress plugin through 2.2.4 does not have any capa ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84171 (The WP images upload on piclect WordPress plugin through 1.0 does not  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84099 (The wpstorecart WordPress plugin through 5.0.7 does not prevent direct ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84047 (The Album Cover Finder WordPress plugin through 0.7.0 does not properl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84025 (The BEAR  WordPress plugin before 1.2.2 does not perform ownership che ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84024 (The BEAR  WordPress plugin before 1.2.2 does not verify a CSRF nonce b ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84023 (The BEAR  WordPress plugin before 1.2.2 does not verify a CSRF nonce o ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-83532 (The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-82851 (The Masteriyo LMS  WordPress plugin before 3.4.1 does not verify owner ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-82847 (The Masteriyo LMS  WordPress plugin before 3.4.1 does not sanitise and ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-82845 (The Masteriyo LMS  WordPress plugin before 3.4.1 does not prevent user ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81918 (Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Form ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81917 (Concrete CMS below 9.5.3 does not apply HTML output escaping to the fi ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81916 (Concrete CMS before 9.5.3 evaluated the authorization check for an Exp ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81915 (Concrete CMS below 9.5.3 does not perform an object-level authorizatio ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81913 (Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redir ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81912 (Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery  ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81911 (Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Bo ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81907 (Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forge ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81742 (The BE REST Endpoints WordPress plugin through 1.0.0 does not perform  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81429 (The Export & Import WPBakery Page Builder WordPress plugin through 1.0 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81402 (The DS Ad Rotator WordPress plugin through 0.8 does not perform any ca ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81090 (The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-80494 (The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a u ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-80491 (The SAMO Forms WordPress plugin through 1.0.0 does not properly saniti ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-79035 (A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.c ...)
 	TODO: check
 CVE-2026-78547 (Out-of-bounds write vulnerability in Citrix Citrix Workspace app for W ...)
-	TODO: check
+	NOT-FOR-US: Citrix
 CVE-2026-78546 (Out-of-bounds read vulnerability in Citirx Workspace app for Windows.  ...)
-	TODO: check
+	NOT-FOR-US: Citrix
 CVE-2026-78152 (The SureRank SEO  WordPress plugin before 1.10.1 does not exclude user ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77753 (The Temporary Login Without Password WordPress plugin before 1.9.9 doe ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77752 (The Temporary Login Without Password WordPress plugin before 1.9.9 doe ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77705 (The Booking for Appointments and Events Calendar  WordPress plugin bef ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77689 (The Booking for Appointments and Events Calendar  WordPress plugin bef ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77490 (Improper neutralization of input during web page generation ('cross-si ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-77006 (The WebTotem Backups WordPress plugin through 1.0.1 does not validate  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77005 (The CODE MONKEYS PROPOSALS  WordPress plugin through 1.0.1 does not va ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-75800 (The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify t ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-68535 (Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5 ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-68526 (Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the C ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-54258 (ZoneMinder is a free, open source closed-circuit television software a ...)
 	TODO: check
 CVE-2026-54248 (Doco-CD is a GitOps continuous delivery tool that automatically deploy ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bbf0919e8adc909649f6ef4cadf0ad89cd5d1f29

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bbf0919e8adc909649f6ef4cadf0ad89cd5d1f29
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260912/f4d02298/attachment.htm>


More information about the debian-security-tracker-commits mailing list