[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 19 08:14:30 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3039bff1 by security tracker role at 2026-09-19T07:14:24+00:00
automatic NOT-FOR-US entries update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,9 +1,9 @@
CVE-2026-93923 (SiYuan through 3.8.4 fails to escape heading style attributes when ren ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-93922 (SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily N ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-93921 (SiYuan versions through 3.8.4 fail to enforce publish access control i ...)
- TODO: check
+ NOT-FOR-US: SiYuan
CVE-2026-93894 (In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability w ...)
TODO: check
CVE-2026-93873 (Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contac ...)
@@ -27,45 +27,45 @@ CVE-2026-93839 (LightLLM through 1.2.0 contains an authentication bypass vulnera
CVE-2026-93838 (SGLang versions through 0.5.20 contain an unbounded memory allocation ...)
TODO: check
CVE-2026-93741 (A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1 ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-93740 (A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-93739 (A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-93738 (A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This ...)
- TODO: check
+ NOT-FOR-US: TOTOLINK
CVE-2026-93574 (A flaw was found in Netty's `netty-codec-http` component. A remote att ...)
TODO: check
CVE-2026-93562 (A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of m ...)
TODO: check
CVE-2026-93031 (The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-92967 (The Pochipp plugin for WordPress is vulnerable to Reflected Cross-Site ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-92807 (The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-92708 (Svelte devalue is a JavaScript library that serializes values into str ...)
TODO: check
CVE-2026-92435 (The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not v ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-92430 (The Rede Ita\xfa for WooCommerce \u2014 Payment PIX, Credit Card and D ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-92425 (The Hydra Booking \u2014 Appointment Scheduling & Booking Calendar Wor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-92421 (The Hydra Booking \u2014 Appointment Scheduling & Booking Calendar Wor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-92420 (The Hydra Booking \u2014 Appointment Scheduling & Booking Calendar Wor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-92404 (The MgoSync WordPress plugin before 2.1.7 does not have authorization ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-92403 (The Secure Custom Fields WordPress plugin before 6.9.4 does not proper ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-92229 (The The Forminator Forms \u2013 Contact Form, Payment Form & Custom Fo ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-92099 (The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not requi ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-91847 (The Online Scheduling and Appointment Booking System WordPress plugin ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-91205 (A flaw was found in cockpit-files. A local unprivileged attacker can e ...)
TODO: check
CVE-2026-91203 (A flaw was found in cockpit-files. This vulnerability allows a local a ...)
@@ -73,129 +73,129 @@ CVE-2026-91203 (A flaw was found in cockpit-files. This vulnerability allows a l
CVE-2026-91202 (A flaw was found in cockpit-files. A low-privileged local user can exp ...)
TODO: check
CVE-2026-89334 (The Better Messages \u2013 Chat Rooms, Group Chat, Private Messages & ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-89333 (The Tutor LMS \u2013 eLearning and online course solution plugin for W ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-89274 (The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Sh ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-89093 (The Better Messages \u2013 Chat Rooms, Group Chat, Private Messages & ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-89081 (The Tutor LMS \u2013 eLearning and online course solution plugin for W ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-88944 (The Tutor LMS \u2013 eLearning and online course solution plugin for W ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-88926 (The VikRentItems Flexible Rental Management System WordPress plugin be ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-88824 (The Master Blocks WordPress plugin before 1.5.0 does not have authori ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-88097 (Use after free in Microsoft Edge (Chromium-based) allows an unauthoriz ...)
- TODO: check
+ NOT-FOR-US: Microsoft
CVE-2026-87909 (The WP Photo Album Plus plugin for WordPress is vulnerable to Remote C ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-86814 (The UsersWP WordPress plugin before 1.5.10 does not verify that a soc ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-86591 (The Botiga Pro WordPress plugin before 1.6.5 does not perform any auth ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-85680 (The Ultimate Member WordPress plugin before 2.13.1 does not escape a ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-85574 (The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perf ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-85272 (Open edX Platform enables the authoring and delivery of online learnin ...)
TODO: check
CVE-2026-85271 (Open edX Platform enables the authoring and delivery of online learnin ...)
TODO: check
CVE-2026-84750 (The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 doe ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84434 (The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-84241 (IBM Guardium Data Protection 12.2 could allow a remote attacker to byp ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84239 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84108 (IBM Guardium Data Protection 12.2 could allow a remote attacker to exe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84106 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84105 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84089 (IBM Guardium Data Protection 12.2 could allow a local attacker to gain ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84086 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84085 (IBM Guardium Data Protection 12.2 could allow a remote attacker to exe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84084 (IBM Guardium Data Protection 12.2 could allow a remote attacker to byp ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84083 (IBM Guardium Data Protection 12.2 is vulnerable to local privilege esc ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84082 (IBM Guardium Data Protection 12.2 could allow a remote attacker to exe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84081 (IBM Guardium Data Protection 12.2 could allow a remote attacker to byp ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84078 (IBM Guardium Data Protection 12.2 is vulnerable to a missing authentic ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84077 (IBM Guardium Data Protection 12.2 could allow a remote attacker to byp ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84076 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84075 (IBM Guardium Data Protection 12.2 could allow a remote attacker to byp ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84074 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84073 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84071 (IBM Guardium Data Protection 12.2 is vulnerable to OS command injectio ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84070 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84064 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84036 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84034 (IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credent ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-84031 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-82967 (IBM Guardium Data Protection 12.2 is vulnerable to an authentication b ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-82896 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-82893 (IBM Guardium Data Protection 12.2 could allow a local attacker to gain ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-82892 (IBM Guardium Data Protection 12.2 could allow a remote attacker to exe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-82890 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-82887 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-82885 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-82832 (IBM Guardium Data Protection 12.2 could allow a remote authenticated a ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-82340 (IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated ins ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81937 (IBM Guardium Data Protection 12.2 is vulnerable to a command injection ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81933 (IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vul ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81669 (IBM Guardium Data Protection 12.2 is vulnerable to a command injection ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81657 (IBM Guardium Data Protection 12.2 could allow a remote unauthenticated ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81656 (IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vul ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81626 (IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vul ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-81623 (IBM Guardium Data Protection 12.2 could allow an authenticated user to ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-80442 (IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-80441 (IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-77875 (The application protects access through its calculator-style vault pas ...)
TODO: check
CVE-2026-77820 (The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-77528 (Autobahn Python is a WebSocket and WAMP implementation for Python that ...)
TODO: check
CVE-2026-76902 (CordysCRM is an open source AI-powered customer relationship managemen ...)
@@ -207,15 +207,15 @@ CVE-2026-76900 (CordysCRM is an open source AI-powered customer relationship man
CVE-2026-76899 (CordysCRM is an open source AI-powered customer relationship managemen ...)
TODO: check
CVE-2026-76790 (The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-76554 (The WP Import Export Lite WordPress plugin before 3.9.35 does not veri ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-75895 (In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was foun ...)
TODO: check
CVE-2026-75885 (A flaw was found in the OpenShift console. Unauthenticated access to t ...)
TODO: check
CVE-2026-75878 (IBM Sterling File Gateway could allow a remote attacker to bypass auth ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-71855 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
TODO: check
CVE-2026-71418 (Suricata is a network Intrusion Detection System, Intrusion Prevention ...)
@@ -259,49 +259,49 @@ CVE-2026-61670 (microsandbox is an easy, fast, local-first microVM runtime and l
CVE-2026-52745 (CordysCRM is an open source AI-powered customer relationship managemen ...)
TODO: check
CVE-2026-19860 (The JetFormBuilder \u2014 Dynamic Blocks Form Builder WordPress plugin ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-18869 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17619 (IBM Platform RTM is vulnerable to SQL injection. A remote attacker cou ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-17262 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a d ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-16557 (The Nimble Page Builder WordPress plugin through 3.3.8 does not perfor ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15760 (The Divi Essential plugin for WordPress is vulnerable to sensitive inf ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-15660 (The SEO Booster plugin for WordPress is vulnerable to Missing Authoriz ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-13354 (The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerab ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-12042 (The WP2Social Auto Publish plugin for WordPress is vulnerable to Store ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2026-11727 (IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could al ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11726 (IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authentic ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11725 (IBM MQ could allow an authenticated attacker to cause a denial of serv ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11722 (IBM WebSphere Application Server and WebSphere Application Server Libe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11716 (IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authentic ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11711 (IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserial ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11710 (IBM WebSphere Application Server 8.5 is affected by an HTTP request sm ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11549 (IBM WebSphere Application Server and WebSphere Application Server Libe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11548 (IBM WebSphere Application Server and WebSphere Application Server Libe ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11545 (IBM WebSphere Application Server 8.5 and 9.0 could allow a remote atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11540 (IBM WebSphere Application Server 9.0 and 8.5 could allow a remote atta ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2026-11539 (IBM WebSphere Application Server 9.0 and 8.5 is affected by an authent ...)
- TODO: check
+ NOT-FOR-US: IBM
CVE-2025-15698 (The Business Name Generator WordPress plugin through 1.3 does not sani ...)
- TODO: check
+ NOT-FOR-US: WordPress plugin
CVE-2017-20284 (Caucho Resin contains a path traversal vulnerability in the documentat ...)
TODO: check
CVE-2026-93854 (In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce o ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3039bff1dfd3b125dcbefca83ae0d0505f2e3e32
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3039bff1dfd3b125dcbefca83ae0d0505f2e3e32
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/46b84428/attachment.htm>
More information about the debian-security-tracker-commits
mailing list