[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 22 08:15:14 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
83d60f73 by security tracker role at 2026-09-22T07:15:05+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -29,7 +29,7 @@ CVE-2026-94533 (lamp-cloud through 5.10.0 contains an authorization bypass vulne
 CVE-2026-94532 (lamp-cloud through 5.10.0 contains an authorization bypass vulnerabili ...)
 	TODO: check
 CVE-2026-94504 (Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and rend ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-94501 (jshERP through 3.6 contains an authorization bypass vulnerability in t ...)
 	TODO: check
 CVE-2026-94497 (jshERP through 3.6 fails to validate object ownership in by-id info, u ...)
@@ -115,7 +115,7 @@ CVE-2026-94148 (A vulnerability was determined in ScadaBR up to 1.1. Impacted is
 CVE-2026-93884
 	REJECTED
 CVE-2026-93655 (The Booking Calendar plugin for WordPress is vulnerable to Reflected C ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-93340 (Gladys Assistant before 5.1.0 contains a password reset link poisoning ...)
 	TODO: check
 CVE-2026-93339 (Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a  ...)
@@ -123,23 +123,23 @@ CVE-2026-93339 (Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 conta
 CVE-2026-92612 (In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exp ...)
 	TODO: check
 CVE-2026-92438 (The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-92400 (The Payment Gateway for PayPal on WooCommerce WordPress plugin before  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-91921 (Cross-Site Scripting (XSS) vulnerability due to inadequate input sanit ...)
 	TODO: check
 CVE-2026-91867 (When Neethi fetches a remote policy reference, it only limits the time ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-91866 (A specially crafted pair of WS-Policy documents can force Neethi's pol ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-91865 (A small WS-Policy document using repeated policy references can force  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-91864 (A specially crafted WS-Policy document can pack unlimited content insi ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-91863 (A specially crafted WS-Policy document with deeply nested policy eleme ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-91827 (The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitte ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-91167 (Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux ...)
 	TODO: check
 CVE-2026-91166 (Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux ...)
@@ -149,7 +149,7 @@ CVE-2026-91165 (Warpgate is an open source SSH, HTTPS and MySQL bastion host for
 CVE-2026-91164 (Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux ...)
 	TODO: check
 CVE-2026-89412 (The TranslatePress \u2013 Translate Multilingual sites with AI Transla ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-89139 (Temporal Server compiles a Worker Controller Instance module into its  ...)
 	TODO: check
 CVE-2026-88978 (Hatchet is a platform for orchestrating background tasks, AI agents, a ...)
@@ -159,7 +159,7 @@ CVE-2026-88807 (A heap overflow in libXrender before 0.9.13 inRenderQueryPictFor
 CVE-2026-88806 (A malicious X server could exploit a buffer overflow in libX11 before  ...)
 	TODO: check
 CVE-2026-88788 (The Text Styler WordPress plugin through 1.1.1 does not sanitise and e ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-88756 (Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQ ...)
 	TODO: check
 CVE-2026-88746 (idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/mak ...)
@@ -195,27 +195,27 @@ CVE-2026-88402 (A SQL injection vulnerability in the checkSQL function of nocoba
 CVE-2026-87858 (Temporal Server decided whether a Workflow completion callback was int ...)
 	TODO: check
 CVE-2026-86802 (The To Do List Member WordPress plugin through 1.6 does not have autho ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86473 (Apache Airflow: the Core API logout endpoint revokes only a session to ...)
 	TODO: check
 CVE-2026-85751 (Mailu is a mail server distributed as a set of Docker images. From Mai ...)
 	TODO: check
 CVE-2026-85653 (The Contextual Related Posts plugin for WordPress is vulnerable to Sto ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-85220 (A vulnerability in the Thinkst Canary honeypot Redis service allows an ...)
 	TODO: check
 CVE-2026-85219 (Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 ...)
 	TODO: check
 CVE-2026-85113 (The GiveWP WordPress plugin before 4.16.9 does not remove shortcode de ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-85010 (The RestroPress WordPress plugin before 3.4.6 does not validate a clie ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84990 (ntopng is a web-based network traffic monitoring application. Prior to ...)
 	TODO: check
 CVE-2026-84298 (Hatchet is a platform for orchestrating background tasks, AI agents, a ...)
 	TODO: check
 CVE-2026-84285 (An OS Command Injection vulnerability affecting Tuleap Enterprise Edit ...)
-	TODO: check
+	NOT-FOR-US: Dassault Systemes
 CVE-2026-83621 (ntopng is a web-based network traffic monitoring application. Prior to ...)
 	TODO: check
 CVE-2026-82412 (ntopng is a web-based network traffic monitoring application. Prior to ...)
@@ -223,11 +223,11 @@ CVE-2026-82412 (ntopng is a web-based network traffic monitoring application. Pr
 CVE-2026-82355 (When a request to the Airflow core API carries both a session cookie a ...)
 	TODO: check
 CVE-2026-82165 (Dell Command | Integration Suite for System Center, versions prior to  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-82163 (Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contai ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81469 (Dell Inventory Collector Client, versions prior to 15.0.0, contain an  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-79920 (Ajenti is a Linux & BSD modular server admin panel. Prior to version 2 ...)
 	TODO: check
 CVE-2026-79919 (MaxKB is an open-source AI assistant for enterprise. Prior to version  ...)
@@ -283,9 +283,9 @@ CVE-2026-77166 (The emoji field in the page emoji update endpoint does not prope
 CVE-2026-77165 (File owners were unable to unlock TYPE_TOKEN locks placed by other use ...)
 	TODO: check
 CVE-2026-77021 (Improper handling of highly compressed data (data amplification) in Ch ...)
-	TODO: check
+	NOT-FOR-US: Checkmk
 CVE-2026-76974 (SAP Fiori Launchpad does not sufficiently validate certain user-contro ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-76898 (draw.io is a configurable diagramming and whiteboarding application. P ...)
 	TODO: check
 CVE-2026-75158 (Apache Airflow's `/assets/events` API returned asset events for every  ...)
@@ -377,7 +377,7 @@ CVE-2026-61612 (CKAN MCP Server is a tool for querying CKAN open data portals. P
 CVE-2026-61541 (Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to ...)
 	TODO: check
 CVE-2026-59830 (Discourse is an open-source discussion platform. Prior to 2026.7.0, th ...)
-	TODO: check
+	NOT-FOR-US: Discourse
 CVE-2026-59816 (Joplin is an open source note-taking and to-do application that organi ...)
 	TODO: check
 CVE-2026-59815 (Joplin is an open source note-taking and to-do application that organi ...)
@@ -443,9 +443,9 @@ CVE-2026-52740 (GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, t
 CVE-2026-49995 (Tautulli is a Python based monitoring and tracking tool for Plex Media ...)
 	TODO: check
 CVE-2026-49811 (Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an In ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-49810 (Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 cont ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-49453 (Joplin is an open source note-taking and to-do application that organi ...)
 	TODO: check
 CVE-2026-49450 (Joplin is an open source note-taking and to-do application that organi ...)
@@ -479,25 +479,25 @@ CVE-2026-36468 (Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allo
 CVE-2026-36467 (Unrestricted Upload of File with Dangerous Type in core/modules/media. ...)
 	TODO: check
 CVE-2026-19658 (The Give Tributes plugin for WordPress is vulnerable to PHP Object Inj ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-17054 (The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parse ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-17052 (The Time-aware GPIO syscall verification handler z_vrfy_tgpio_pin_read ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-17051 (The Intel SEDI IPM (inter-processor mailbox) driver in drivers/ipm/ipm ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-17050 (The experimental USB host stack allocates a per-device configuration-d ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-16652 (Temporal Server did not bound the work performed while searching for a ...)
 	TODO: check
 CVE-2026-16651 (temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNex ...)
 	TODO: check
 CVE-2026-15890 (The default AEAD nonce provider for the PSA Internal Trusted Storage t ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-13355 (The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escal ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12470 (The CMP \u2013 Coming Soon & Maintenance Plugin by NiteoThemes plugin  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-71421 (UVdesk core-framework before 1.1.7 contains an improper privilege mana ...)
 	TODO: check
 CVE-2025-71420 (UVdesk core-framework before 1.1.7 contains an authorization bypass vu ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/83d60f73b2a408ee55e732a2dc6f3bfa2a96eaa3

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/83d60f73b2a408ee55e732a2dc6f3bfa2a96eaa3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/22d2a8c1/attachment.htm>


More information about the debian-security-tracker-commits mailing list