[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Sep 20 08:14:42 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
85eb06a5 by security tracker role at 2026-09-20T07:14:35+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,19 +1,19 @@
 CVE-2026-9858 (The Partial Shipment for Woocommerce plugin for WordPress is vulnerabl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-9855 (The Custom Field Template plugin for WordPress is vulnerable to generi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-9832 (The Payment Gateway of Stripe for WooCommerce plugin for WordPress is  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-9766 (The Empik for Woocommerce plugin for WordPress is vulnerable to author ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-9615 (The Flex Import plugin for WordPress is vulnerable to Missing Authoriz ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-9613 (The Datalogics Ecommerce Delivery \u2013 Datalogics plugin for WordPre ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-9289 (The WordLift \u2013 AI powered SEO \u2013 Schema plugin for WordPress  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-9232 (The Easy Appointments plugin for WordPress is vulnerable to Sensitive  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-94084 (Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a ...)
 	TODO: check
 CVE-2026-94083 (Suricata before 8.0.7 has a DoH2 type confusion that can cause an inva ...)
@@ -71,7 +71,7 @@ CVE-2026-93965 (A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is
 CVE-2026-93964 (A vulnerability was detected in NginxProxyManager nginx-proxy-manager  ...)
 	TODO: check
 CVE-2026-93963 (A security vulnerability has been detected in itsourcecode Leave Manag ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-93962 (A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2 ...)
 	TODO: check
 CVE-2026-93961 (A security flaw has been discovered in Dromara UJCMS up to 12.3.1. The ...)
@@ -79,9 +79,9 @@ CVE-2026-93961 (A security flaw has been discovered in Dromara UJCMS up to 12.3.
 CVE-2026-93960 (A vulnerability was identified in Pixelfed up to 0.12.11. Impacted is  ...)
 	TODO: check
 CVE-2026-93959 (A vulnerability was determined in SourceCodester Online Reviewer Manag ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-93958 (A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerabi ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-93957 (A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3. This ...)
 	TODO: check
 CVE-2026-93956 (A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by t ...)
@@ -91,117 +91,117 @@ CVE-2026-93955 (A vulnerability was detected in grimmory-tools grimmory up to 3.
 CVE-2026-93954 (A security vulnerability has been detected in grimmory-tools grimmory  ...)
 	TODO: check
 CVE-2026-93742 (A weakness has been identified in Totolink A3002MU Hh-B20211125.1046.  ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-92965 (The TikTok WordPress plugin before 1.4.2 does not check that a request ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-92541 (The Import and export users and customers WordPress plugin before 2.5. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-92540 (The Import and export users and customers WordPress plugin before 2.5. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-92423 (The Meow Gallery WordPress plugin before 5.5.5 does not perform a prop ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-92422 (The Meow Gallery WordPress plugin before 5.5.5 does not properly sanit ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-92410 (The Sign-up Sheets WordPress plugin before 2.4.0 does not properly val ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-8354 (The Gum Addon for Elementor plugin for WordPress is vulnerable to Stor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-89155
 	REJECTED
 CVE-2026-87917 (The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87840 (The Tripzzy  WordPress plugin before 1.5.1 does not perform any capabi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87839 (The Tripzzy  WordPress plugin before 1.5.1 does not have authorisation ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87068 (The Forminator Forms  WordPress plugin before 1.57.2.1 does not apply  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87067 (The Forminator Forms  WordPress plugin before 1.57.2.1 does not restri ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86553 (SmartLife app dynamically generates fresh SmartLife application authen ...)
-	TODO: check
+	NOT-FOR-US: ZTE
 CVE-2026-86552 (SmartLife app dynamically generates brand\u2011new SmartLife applicati ...)
-	TODO: check
+	NOT-FOR-US: ZTE
 CVE-2026-86551 (The Z80Ultra (NX741J) product contains a vulnerability where non-privi ...)
-	TODO: check
+	NOT-FOR-US: ZTE
 CVE-2026-85658 (The Paid Membership Plugin, Ecommerce, User Registration Form, Login F ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-85017 (The Unlimited Elements For Elementor WordPress plugin before 2.0.20 do ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84223 (The Kirki  WordPress plugin before 6.3.1 does not sanitize uploaded SV ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-82842 (The SAML Single Sign On  WordPress plugin before 6.0.0 does not honour ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-82672 (Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response S ...)
 	TODO: check
 CVE-2026-81654 (The Photo Gallery, Sliders, Proofing and   WordPress plugin before 4.5 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81653 (The Photo Gallery, Sliders, Proofing and   WordPress plugin before 4.5 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81652 (The Photo Gallery, Sliders, Proofing and   WordPress plugin before 4.5 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81651 (The Photo Gallery, Sliders, Proofing and   WordPress plugin before 4.5 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81650 (The Photo Gallery, Sliders, Proofing and   WordPress plugin before 4.5 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-7527 (The WP Ghost (Hide My WP Ghost) \u2013 Security & Firewall plugin for  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-76579 (The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cr ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-75959 (The GoPay for WooCommerce plugin for WordPress is vulnerable to generi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-6295 (The WP Optimizer plugin for WordPress is vulnerable to SQL Injection v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-5410 (The Redux Framework plugin for WordPress is vulnerable to Stored Cross ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-5400 (The Redux Framework plugin for WordPress is vulnerable to Stored Cross ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-4792 (The Bread plugin for WordPress is vulnerable to information exposure i ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-4327 (The The Welcomizer plugin for WordPress is vulnerable to Remote Code E ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-2422 (The WP Composer \u2013 The Easiest Page Builder plugin for WordPress i ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-2278 (The VW Writer Blog theme for WordPress is vulnerable to unauthorized m ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-1984 (The Ibtana \u2013 Ecommerce Product Addons plugin for WordPress is vul ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-1641 (The Wow Elements Addons for Elementor plugin for WordPress is vulnerab ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-1256 (The YS LeadGen plugin for WordPress is vulnerable to authorization byp ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-1255 (The YS LeadGen plugin for WordPress is vulnerable to Sensitive Informa ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-1242 (The BlockSpare plugin for WordPress is vulnerable to authorization byp ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18346 (The TikTok plugin for WordPress is vulnerable to authorization bypass  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16542 (The Import and export users and customers WordPress plugin before 2.4. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15947 (The Metasync plugin for WordPress is vulnerable to unauthorized modifi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15946 (The Search Atlas SEO \u2013 Premier SEO Plugin for One-Click WP Publis ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15664 (The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes p ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15463 (The SSL Zen \u2014 SSL Certificate Installer & HTTPS Redirects plugin  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15098 (The Real3D Flipbook Lite plugin for WordPress is vulnerable to Stored  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14844 (The Master Slider  WordPress plugin through 3.11.2 does not sanitise a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13770 (The AppMySite \u2013 WordPress & WooCommerce Mobile App Builder (No-Co ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13200 (The Create plugin for WordPress is vulnerable to generic SQL Injection ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13191 (The Create plugin for WordPress is vulnerable to generic SQL Injection ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12402 (The OTP Login & Register Woocommerce plugin for WordPress is vulnerabl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11899 (The PDF Builder for WooCommerce. Create invoices,packing slips and mor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11608 (The WP Customer Reviews plugin for WordPress is vulnerable to Reflecte ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-82560 (Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhausti ...)
 	- perl <unfixed> (bug #1148455)
 	- podlators-perl <removed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/85eb06a584a7ca2aa073b48cdd7369687c23a553

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/85eb06a584a7ca2aa073b48cdd7369687c23a553
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260920/0275d028/attachment.htm>


More information about the debian-security-tracker-commits mailing list