[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 12 20:14:34 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8a332f87 by security tracker role at 2026-09-12T19:14:28+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -49,11 +49,11 @@ CVE-2026-90537 (WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf33
CVE-2026-90536 (WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fa ...)
TODO: check
CVE-2026-90535 (Flowise versions before 3.1.4 contain an unauthenticated denial of ser ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-90534 (Flowise is a low-code platform for building LLM applications. In versi ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-90533 (Flowise before 3.1.4 contains a broken access control vulnerability in ...)
- TODO: check
+ NOT-FOR-US: Flowise
CVE-2026-90474 (MCPHub before 1.0.32 contains an authentication bypass vulnerability i ...)
TODO: check
CVE-2026-90473 (msgpack-java through 0.9.12 contains an integer overflow vulnerability ...)
@@ -61,29 +61,29 @@ CVE-2026-90473 (msgpack-java through 0.9.12 contains an integer overflow vulnera
CVE-2026-90472 (msgpack-java through 0.9.12 contains a stack overflow vulnerability in ...)
TODO: check
CVE-2026-89172 (Improper protection of physical side channels vulnerability in Microch ...)
- TODO: check
+ NOT-FOR-US: Microchip
CVE-2026-85200 (The GEO my WP plugin for WordPress is vulnerable to Local File Inclusi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-85198 (The MPG \u2013 Multiple Page Generator, Bulk Landing Pages & Programma ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-78175 (The Tutor LMS \u2013 eLearning and online course solution plugin for W ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-78159 (The The Events Calendar plugin for WordPress is vulnerable to Remote C ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-78006 (The The Events Calendar plugin for WordPress is vulnerable to Remote C ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77161 (The Smart Marketing SMS and Newsletters Forms plugin for WordPress is ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17585 (The Royal Addons for Elementor \u2013 Addons and Templates Kit for Ele ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16482 (The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15451 (The MemberPress Corporate Accounts plugin for WordPress is vulnerable ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-11355 (The DT LMS \u2013 elearning, WordPress LMS plugin for WordPress is vul ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-10148 (The Booking for Appointments and Events Calendar plugin for WordPress ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-90467 (aiosmtplib before 5.1.3 fails to properly validate email addresses sup ...)
- aiosmtplib <unfixed> (bug #1147474)
NOTE: Fixed by: https://github.com/cole/aiosmtplib/commit/2e1b210714974ccc9efd0d09a8f846cb9aeaaec2 (v5.1.3)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a332f87e94782f1b0074c328a37899a46ce3e7d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a332f87e94782f1b0074c328a37899a46ce3e7d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260912/6af674ee/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list