[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 18 08:14:11 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
6fe1ef2a by security tracker role at 2026-09-18T07:13:37+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -83,107 +83,107 @@ CVE-2026-93308 (A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affect
CVE-2026-93307 (A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affecte ...)
TODO: check
CVE-2026-92991 (The Biggop Library is vulnerable to Cross-Site Scripting via the \u201 ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-92757 (Applications built on MongoDB Entity Framework Core Provider which pla ...)
TODO: check
CVE-2026-92714 (The Download Manager plugin for WordPress is vulnerable to Insecure Di ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-92619 (The Booking Calendar plugin for WordPress is vulnerable to Privilege E ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-92561 (The Booking Calendar plugin for WordPress is vulnerable to Reflected C ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-91707 (The The Divi theme for WordPress is vulnerable to arbitrary shortcode ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-90984 (The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 do ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-90978 (The Filter Gallery WordPress plugin before 1.1.5 does not verify the n ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-90977 (The Clean Login WordPress plugin before 1.19 does not verify its regis ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-90976 (The Clean Login WordPress plugin before 1.19 does not check whether us ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-89413 (The Filter Gallery plugin for WordPress is vulnerable to authorization ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-89330 (The EmbedPress \u2013 PDF Embedder, 3D PDF FlipBook, Google Reviews, Y ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-89278 (The GPTranslate \u2013 Multilingual AI Translation Agent for WordPress ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-89138 (The Filter Gallery plugin for WordPress is vulnerable to authorization ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-89008 (The Bookit \u2014 Booking & Appointment Calendar WordPress plugin befo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-89007 (The Bookit \u2014 Booking & Appointment Calendar WordPress plugin befo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-88994 (The All Bootstrap Blocks WordPress plugin through 1.3.31 does not vali ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-88993 (The All Bootstrap Blocks WordPress plugin through 1.3.31 does not prop ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-88844 (The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 d ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-88825 (The iGMS Direct Booking WordPress plugin before 2.0 does not authorise ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-88798 (The Really Simple Security WordPress plugin before 9.8.3 does not val ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87966 (The Easy Appointments WordPress plugin before 4.0.2.2 does not perform ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87965 (The Easy Appointments WordPress plugin before 4.0.2.2 does not use an ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87886 (Local privilege escalation due to insecure file permissions. The follo ...)
- TODO: check
+ NOT-FOR-US: Acronis
CVE-2026-87775 (The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not s ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87774 (The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not s ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87771 (The Product Question and Answer WordPress plugin through 1.1.0 does no ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87770 (The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 doe ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87767 (The wp shortcut link and advertisement baner WordPress plugin through ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-87701 (Improper neutralization of special elements in output used by a downst ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-86800 (The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-86796 (The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify th ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-86688 (Session Fixation vulnerability in team-alembic ash_authentication allo ...)
TODO: check
CVE-2026-86049 (Jupyter Server is the backend for Jupyter web applications. Prior to v ...)
TODO: check
CVE-2026-85917 (Server-side request forgery (ssrf) in Azure AI Foundry allows an unaut ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-85889 (Missing authentication for critical function in Azure AI Foundry allow ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-85887 (Incorrect permission assignment for critical resource in M365 Copilot ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-85885 (Improper neutralization of special elements used in a command ('comman ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-85878 (Improper authorization in Azure Database for PostgreSQL allows an auth ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-85350 (The UpsellWP WordPress plugin before 2.2.10 does not check that produ ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-85127 (The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8. ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-85123 (The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 do ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-85122 (The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 do ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-85009 (The RestroPress WordPress plugin through 3.4.6 does not verify owners ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84909 (The Custom Twitter Feeds \u2013 A Tweets Widget or X Feed Widget plugi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84904 (The King Addons for Elementor WordPress plugin before 51.1.81 does no ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84903 (The King Addons for Elementor WordPress plugin before 51.1.81 does no ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84902 (The King Addons for Elementor WordPress plugin before 51.1.81 does no ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84738 (The AF Companion WordPress plugin before 2.2.0 does not validate the ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-83946 (Improper neutralization of input during web page generation ('cross-si ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-83944 (Improper access control in Azure Logic Apps allows an unauthorized att ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-82985 (The Photos app's filter-based "smart albums" build their file listing ...)
TODO: check
CVE-2026-82982 (The Approval app's approve/reject endpoint is meant to require the fil ...)
@@ -191,19 +191,19 @@ CVE-2026-82982 (The Approval app's approve/reject endpoint is meant to require t
CVE-2026-82980 (Any authenticated user can lock or unlock files they do not own by tar ...)
TODO: check
CVE-2026-81810 (The All-in-One WP Migration and Backup WordPress plugin before 7.111 d ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-81340 (The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 d ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-79954 (NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerabilit ...)
TODO: check
CVE-2026-79713 (The Breeze Cache WordPress plugin before 2.5.15 does not include a set ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-78668
REJECTED
CVE-2026-78501 (Improper neutralization of special elements used in a command ('comman ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-77903 (Authentication bypass by spoofing in Microsoft Dataverse allows an una ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-77615 (Paella Player is a set of libraries to create a multi stream video pla ...)
TODO: check
CVE-2026-77281 (Caddy is an extensible server platform that uses TLS by default. In ve ...)
@@ -217,23 +217,23 @@ CVE-2026-77164 (Circles' remote-instance signature verification fetches the atta
CVE-2026-76949 (Authentication Bypass by Spoofing vulnerability in team-alembic ash_au ...)
TODO: check
CVE-2026-76154 (A stored cross-site scripting vulnerability in the Geomap panel's MapL ...)
- TODO: check
+ NOT-FOR-US: Grafana
CVE-2026-75017 (The Magazine Blocks \u2013 Blog Designer, Magazine & Newspaper Website ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75016 (The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-70200 (Improper limitation of a pathname to a restricted directory ('path tra ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-70009 (Improper limitation of a pathname to a restricted directory ('path tra ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-69865 (Authorization bypass through user-controlled key in Microsoft Containe ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-69843 (Authentication bypass by spoofing in Microsoft Fabric allows an unauth ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-69399 (Azure Arc Elevation of Privilege Vulnerability)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-68791 (Incorrect authorization in Azure Machine Learning allows an unauthoriz ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-68537 (`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server th ...)
TODO: check
CVE-2026-68523 (`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server th ...)
@@ -241,17 +241,17 @@ CVE-2026-68523 (`fulgur` converts untrusted HTML/CSS into PDF, commonly on a ser
CVE-2026-68493 (After guessing a 62^15 complex unique identifier, a malicious logged i ...)
TODO: check
CVE-2026-67071 (HCL DevOps Deploy / HCL Launch is susceptible to an information disclo ...)
- TODO: check
+ NOT-FOR-US: HCL
CVE-2026-65323
REJECTED
CVE-2026-62874 (Insufficient verification of data authenticity in Azure Billing allows ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-57847
REJECTED
CVE-2026-57846
REJECTED
CVE-2026-55946 (Improper neutralization of special elements used in a command ('comman ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-54918 (NetBox Device Type Library is a collection of community-sourced device ...)
TODO: check
CVE-2026-54916 (NetBox Device Type Library is a collection of community-sourced device ...)
@@ -259,7 +259,7 @@ CVE-2026-54916 (NetBox Device Type Library is a collection of community-sourced
CVE-2026-54907 (Caddy Proxy Manager is a web interface for managing Caddy Server rever ...)
TODO: check
CVE-2026-54767 (WeGIA is a web manager for charitable institutions. Prior to 3.8.5, we ...)
- TODO: check
+ NOT-FOR-US: WeGIA
CVE-2026-54752 (NetBox Device Type Library is a collection of community-sourced device ...)
TODO: check
CVE-2026-54734 (Prebid Server Java is the Java version of Prebid Server. Prior to 3.43 ...)
@@ -269,9 +269,9 @@ CVE-2026-54716 (Valhalla is an open source routing engine and accompanying libra
CVE-2026-54692 (SAIL is a cross-platform library for loading and saving images with su ...)
TODO: check
CVE-2026-54671 (WeGIA is a web manager for charitable institutions. Prior to 3.8.5, We ...)
- TODO: check
+ NOT-FOR-US: WeGIA
CVE-2026-54670 (WeGIA is a web manager for charitable institutions. Prior to 3.8.5, th ...)
- TODO: check
+ NOT-FOR-US: WeGIA
CVE-2026-54648 (CubeCart is an ecommerce software solution. Prior to 6.7.5, the GDPR t ...)
TODO: check
CVE-2026-54647 (CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sour ...)
@@ -373,37 +373,37 @@ CVE-2026-45723 (Omni manages Kubernetes on bare metal, virtual machines, or in a
CVE-2026-45720 (Omni manages Kubernetes on bare metal, virtual machines, or in a cloud ...)
TODO: check
CVE-2026-45143 (Chamilo LMS is an open-source learning management system. From 2.0.0 t ...)
- TODO: check
+ NOT-FOR-US: Chamilo LMS
CVE-2026-45140 (Chamilo LMS is an open-source learning management system. Prior to 2.0 ...)
- TODO: check
+ NOT-FOR-US: Chamilo LMS
CVE-2026-2585 (The Brizy \u2013 Page Builder plugin for WordPress is vulnerable to St ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18912 (ManageEngine DataSecurity Plus versions before 6310 are vulnerable to ...)
- TODO: check
+ NOT-FOR-US: Zoho
CVE-2026-18911 (ManageEngine DataSecurity Plus versions before 6310 are vulnerable to ...)
- TODO: check
+ NOT-FOR-US: Zoho
CVE-2026-18441 (The Appointment Booking Plugin \u2013 LatePoint | Calendar & Schedulin ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18317 (The Foxtool All-in-One: Contact chat button, Custom login, Media optim ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17576 (The InfiniteWP Client plugin for WordPress is vulnerable to SQL Inject ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-17086 (The ShortPixel Image Optimizer \u2013 Optimize Images, Convert WebP & ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16750 (The Motors \u2013 Car Dealership & Classified Listings Plugin plugin f ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-16582 (The Booking for Appointments and Events Calendar \u2013 Amelia plugin ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15815 (Grafana OSS and Grafana Enterprise did not safely resolve symbolic lin ...)
- TODO: check
+ NOT-FOR-US: Grafana
CVE-2026-15650 (The RT Mega Menu \u2013 Mega Menu Builder for Elementor & Gutenberg pl ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14855 (The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Si ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-14311 (The Booking for Appointments and Events Calendar \u2013 Amelia plugin ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12106 (The Auto Upload Images plugin for WordPress is vulnerable to Limited S ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-11432
REJECTED
CVE-2026-11314
@@ -415,9 +415,9 @@ CVE-2025-62167
CVE-2025-55787 (In MailData Email Archiving System v4.2 and earlier, a SQL injection v ...)
TODO: check
CVE-2024-38639 (An improper authentication vulnerability has been reported to affect p ...)
- TODO: check
+ NOT-FOR-US: QNAP
CVE-2024-27123 (A cross-site scripting (XSS) vulnerability has been reported to affect ...)
- TODO: check
+ NOT-FOR-US: QNAP
CVE-2026-XXXX [OSSA-2026-039]
- octavia 18.0.0-4 (bug #1148175)
NOTE: https://bugs.launchpad.net/octavia/+bug/2162101
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6fe1ef2a6433f3b48b8ebf1c8780025f20468c45
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6fe1ef2a6433f3b48b8ebf1c8780025f20468c45
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/4e75fcbd/attachment.htm>
More information about the debian-security-tracker-commits
mailing list