[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 22 20:16:13 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c32abbc9 by security tracker role at 2026-09-22T19:15:51+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,11 +1,11 @@
 CVE-2026-9231 (The WP Travel Engine \u2013 Tour Booking Plugin \u2013 Tour Operator S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-9004 (The WP-CRM System \u2013 Manage Clients and Projects plugin for WordPr ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-95862 (A malicious actor with access to the network could exploit an Out-of-b ...)
-	TODO: check
+	NOT-FOR-US: Ubiquity
 CVE-2026-95861 (A malicious actor with access to the network could exploit an Uncontro ...)
-	TODO: check
+	NOT-FOR-US: Ubiquity
 CVE-2026-95806 (MISP ships with PHP's phar stream wrapper registered in both its web e ...)
 	TODO: check
 CVE-2026-95805 (A typo in the MISP ACLComponent access control configuration caused th ...)
@@ -31,7 +31,7 @@ CVE-2026-95682 (MISP contains a stored cross-site scripting (XSS) vulnerability
 CVE-2026-95679 (MISP's RequestHandlerComponent automatically decodes XML request bodie ...)
 	TODO: check
 CVE-2026-95675 (D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthen ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-95674 (In MISP, the queryEnrichment method in EventsController.php accepted a ...)
 	TODO: check
 CVE-2026-95671 (In MISP, the CollectionsController add() method enforced the sharing-g ...)
@@ -97,25 +97,25 @@ CVE-2026-94456 (Postiz generates security-sensitive credentials using `Math.rand
 CVE-2026-94455 (An HTTP endpoint intended for provisioning enterprise and reseller org ...)
 	TODO: check
 CVE-2026-94384 (Missing authorization in Amazon amazon-connect-salesforce-lambda befor ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-94127 (When a BIG-IP APM access policy and an OAuth profile is configured on  ...)
-	TODO: check
+	NOT-FOR-US: F5
 CVE-2026-94117 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-93952 (VeloCloud Orchestrator (VCO) on-prem has a security issue where this i ...)
-	TODO: check
+	NOT-FOR-US: Arista Networks
 CVE-2026-93928 (Authentication Bypass Using an Alternate Path or Channel vulnerability ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-93836 (The WPC Product Bundles for WooCommerce plugin for WordPress is vulner ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-93778 (The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-93616 (A directory traversal and file upload vulnerability allows an unauthen ...)
-	TODO: check
+	NOT-FOR-US: Check Point
 CVE-2026-93556 (The \u2018/password/guardarClau/recover\u2019 endpoint accepts the \u2 ...)
 	TODO: check
 CVE-2026-93345 (MikroTik RouterOS before 7.25beta4 contains an improper input validati ...)
-	TODO: check
+	NOT-FOR-US: MikroTik
 CVE-2026-93344 (MarketKing plugin for WordPress before 2.1.72 contains a missing autho ...)
 	TODO: check
 CVE-2026-93343 (MarketKing plugin for WordPress before 2.1.72 contains a missing autho ...)
@@ -127,27 +127,27 @@ CVE-2026-93341 (MarketKing plugin for WordPress before 2.1.72 contains a missing
 CVE-2026-93088 (SGLang's multimodal generation runtime is vulnerable to unauthenticate ...)
 	TODO: check
 CVE-2026-92969 (The HUSKY \u2013 Products Filter for WooCommerce Professional plugin f ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-92882 (Insufficiently protected credentials in the host and folder configurat ...)
-	TODO: check
+	NOT-FOR-US: Checkmk
 CVE-2026-92706 (Dark Reader is an accessibility browser extension that makes web pages ...)
 	TODO: check
 CVE-2026-92235 (The The WP Ultimate Review plugin for WordPress is vulnerable to arbit ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-91130 (Home Assistant is open source home automation software focused on loca ...)
 	TODO: check
 CVE-2026-91129 (Home Assistant is open source home automation software focused on loca ...)
 	TODO: check
 CVE-2026-91092 (The wpForo Forum plugin for WordPress is vulnerable to authorization b ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-90990 (Improper neutralization of newlines in filter values in the monitoring ...)
-	TODO: check
+	NOT-FOR-US: Checkmk
 CVE-2026-90882 (The open-vsx.org deployment returned Access-Control-Allow-Origin refle ...)
 	TODO: check
 CVE-2026-90462 (A flaw was found in SSSD. When configured with the LDAP access provide ...)
 	TODO: check
 CVE-2026-8849 (Use After Free vulnerability in RTI Connext Professional (Security Plu ...)
-	TODO: check
+	NOT-FOR-US: RTI Connext
 CVE-2026-89422 (Key Exchange without Entity Authentication vulnerability in Erlang/OTP ...)
 	TODO: check
 CVE-2026-89420 (Improper Validation of Specified Quantity in Input in ZenHive mpp allo ...)
@@ -155,11 +155,11 @@ CVE-2026-89420 (Improper Validation of Specified Quantity in Input in ZenHive mp
 CVE-2026-89407 (NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-valid ...)
 	TODO: check
 CVE-2026-89277 (CAI Content Credentials is affected by an Integer Overflow or Wraparou ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-89276 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-89275 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-88415 (MCMS 6.1.1 through 6.2.1 is vulnerable to stored Cross-Site Scripting  ...)
 	TODO: check
 CVE-2026-88414 (MCMS 6.1.1 through 6.2.1 contains a SQL injection vulnerability in the ...)
@@ -197,25 +197,25 @@ CVE-2026-85279 (Notepad++ is a free and open-source source code editor. Prior to
 CVE-2026-85055 (Twenty is an open-source CRM (customer relationship management) platfo ...)
 	TODO: check
 CVE-2026-84412 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-84396 (InDesign Desktop is affected by a NULL Pointer Dereference vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-84395 (Premiere Pro [NEEDS REVIEW: environment mismatch \u2014 product 'Premi ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-84388 (A improper restriction of rendered ui layers or frames vulnerability i ...)
-	TODO: check
+	NOT-FOR-US: Fortinet
 CVE-2026-84301 (FastGPT is an open-source LLM platform for building AI applications on ...)
 	TODO: check
 CVE-2026-83964 (Adobe Connect is affected by an Improper Certificate Validation vulner ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-83963 (Substance3D - Modeler is affected by an out-of-bounds write vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-83962 (Substance3D - Modeler is affected by a Stack-based Buffer Overflow vul ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-83803 (Sentry is an error tracking and performance monitoring tool. From 23.1 ...)
 	TODO: check
 CVE-2026-83660 (Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forg ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-83603 (Netdata is an open source observability tool. Prior to 2.10.4, the set ...)
 	TODO: check
 CVE-2026-83602 (Netdata is an open source observability tool. From 2.0.0 until 2.11.0, ...)
@@ -231,27 +231,27 @@ CVE-2026-83598 (Netdata is an open source observability tool. From rom 2.0.0 unt
 CVE-2026-83597 (Netdata is an open source observability tool. From version 2.0.0 until ...)
 	TODO: check
 CVE-2026-82443 (Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forg ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-82013 (Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forg ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-82011 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-82010 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-82009 (Adobe Campaign Classic (ACC) is affected by an Improper Neutralization ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-82008 (Adobe Campaign Classic (ACC) is affected by an Improper Input Validati ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-82003 (Adobe Campaign Classic (ACC) is affected by an Improper Input Validati ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-82000 (Adobe Experience Manager Forms JEE is affected by a Server-Side Reques ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-81999 (Adobe Experience Manager Forms JEE is affected by a Server-Side Reques ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-81998 (Substance3D - Modeler is affected by an out-of-bounds write vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-81995 (Adobe Experience Manager Forms JEE is affected by an Improper Input Va ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-81886 (radare2 is a UNIX-like reverse engineering framework and command-line  ...)
 	TODO: check
 CVE-2026-81885 (radare2 is a UNIX-like reverse engineering framework and command-line  ...)
@@ -297,13 +297,13 @@ CVE-2026-80144 (Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 befo
 CVE-2026-80143 (Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before fir ...)
 	TODO: check
 CVE-2026-7866 (Stack-based Buffer Overflow vulnerability in RTI Connext Professional  ...)
-	TODO: check
+	NOT-FOR-US: RTI Connext
 CVE-2026-7622 (The ThumbPress plugin for WordPress is vulnerable to unauthorized acce ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-79913 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
 	TODO: check
 CVE-2026-79906 (Substance3D - Modeler is affected by an out-of-bounds write vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-79315 (A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. T ...)
 	TODO: check
 CVE-2026-79314 (A horizontal privilege escalation vulnerability exists in x-ui 0.3.2.  ...)
@@ -327,13 +327,13 @@ CVE-2026-77619 (Vector is a high-performance observability data pipeline. From 0
 CVE-2026-77605 (Notepad++ is a free and open-source source code editor. Prior to 8.9.8 ...)
 	TODO: check
 CVE-2026-77558 (A malicious actor with access to the network could exploit an Out-of-b ...)
-	TODO: check
+	NOT-FOR-US: Ubiquity
 CVE-2026-77556 (A malicious actor with access to the network could exploit an Out-of-b ...)
-	TODO: check
+	NOT-FOR-US: Ubiquity
 CVE-2026-77555 (A malicious actor with access to the network could exploit an Out-of-b ...)
-	TODO: check
+	NOT-FOR-US: Ubiquity
 CVE-2026-77544 (A malicious actor with access to the network could exploit an Out-of-b ...)
-	TODO: check
+	NOT-FOR-US: Ubiquity
 CVE-2026-77399 (icalendar is an RFC 5545 compatible parser and generator of iCalendar  ...)
 	TODO: check
 CVE-2026-77274 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
@@ -405,61 +405,61 @@ CVE-2026-76803 (Nuclei is a vulnerability scanner built on a simple YAML-based D
 CVE-2026-76802 (Nuclei is a vulnerability scanner built on a simple YAML-based DSL. Fr ...)
 	TODO: check
 CVE-2026-76194 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-76192 (InDesign Desktop is affected by a NULL Pointer Dereference vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75791 (Zohocorp ManageEngine ADSelfService Plus versions before build 7001 ar ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2026-75745 (Adobe Experience Manager Forms JEE is affected by an Incorrect Authori ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75744 (Adobe Experience Manager Forms JEE is affected by a stored Cross-Site  ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75743 (Adobe Experience Manager Forms JEE is affected by a Cross-Site Request ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75728 (Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75723 (Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75721 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75703 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75699 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75698 (Adobe Connect is affected by a reflected Cross-Site Scripting (XSS) vu ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75697 (Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulne ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75689 (Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulne ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75686 (Adobe Connect is affected by an Improper Input Validation vulnerabilit ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75684 (Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulne ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75682 (Adobe Connect is affected by an Improper Neutralization of Special Ele ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75676 (Bridge is affected by a Stack-based Buffer Overflow vulnerability that ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75665 (Bridge is affected by a Heap-based Buffer Overflow vulnerability that  ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75663 (Bridge is affected by an out-of-bounds write vulnerability that could  ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75658 (Bridge is affected by an out-of-bounds write vulnerability that could  ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75656 (Bridge is affected by an out-of-bounds read vulnerability that could l ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75655 (Bridge is affected by an Uncontrolled Recursion vulnerability that cou ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75649 (Bridge is affected by a Heap-based Buffer Overflow vulnerability that  ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75638 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75634 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75633 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75632 (CAI Content Credentials is affected by an Uncontrolled Resource Consum ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-75608 (Frigate is an open source network video recorder. Prior to 0.18.0, the ...)
 	TODO: check
 CVE-2026-75607 (Frigate is an open source network video recorder. Prior to 0.17.2, the ...)
@@ -471,13 +471,13 @@ CVE-2026-75511 (Novu provides an API for sending notifications through multiple
 CVE-2026-75510 (Novu provides an API for sending notifications through multiple channe ...)
 	TODO: check
 CVE-2026-74849 (Zohocorp ManageEngine ADSelfService Plus versions before build 7001 ar ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2026-73369 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-70410 (Use of Externally-Controlled Input to Select Classes or Code ('Unsafe  ...)
 	TODO: check
 CVE-2026-6922 (The WP Table Builder \u2013 Drag & Drop Table Builder plugin for WordP ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-68956 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
 	TODO: check
 CVE-2026-65634 (Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENT ...)
@@ -535,13 +535,13 @@ CVE-2026-63272 (LibreOffice can import WMF graphics, which may be embedded in do
 CVE-2026-57149 (plone.app.portlets.portlets provides a Plone-specific user interface f ...)
 	TODO: check
 CVE-2026-56682 (9Router is an AI router & token saver. Prior to 0.5.6, 9Router deploym ...)
-	TODO: check
+	NOT-FOR-US: Next.js
 CVE-2026-56681 (9Router is an AI router & token saver. Prior to 0.5.6, 9Router deploym ...)
-	TODO: check
+	NOT-FOR-US: Next.js
 CVE-2026-4123 (The RW Elephant Rental Inventory plugin for WordPress is vulnerable to ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-48361 (Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulne ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-43643 (Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an a ...)
 	TODO: check
 CVE-2026-43642 (Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PH ...)
@@ -553,69 +553,69 @@ CVE-2026-37604 (pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 re
 CVE-2026-37603 (Improper Restriction of Excessive Authentication Attempts in the admin ...)
 	TODO: check
 CVE-2026-34689 (Adobe Connect is affected by an Improper Limitation of a Pathname to a ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-25265 (Privilege escalation due to weak configuration while temporary file ha ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2026-25264 (Privilege escalation due to weak configuration during package extracti ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2026-25262 (Memory corruption while processing a crafted ELF file in the Primary B ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2026-25255 (Exposed dangerous function lead to privilege escalation via gRPC serve ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2026-25254 (Improper authorization leads to Remote Code Execution via SocketIO int ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2026-24267 (NVIDIA NeMo Speech for all platforms contains a vulnerability in the s ...)
 	TODO: check
 CVE-2026-24239 (NVIDIA NeMo Speech for all platforms contains a vulnerability where ma ...)
 	TODO: check
 CVE-2026-1645 (The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scr ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19915 (A potential security vulnerability has been identified in the HP Suppo ...)
 	TODO: check
 CVE-2026-19480 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-18626 (Out-of-bounds Read vulnerability in RTI Connext Professional (Core Lib ...)
-	TODO: check
+	NOT-FOR-US: RTI Connext
 CVE-2026-18462 (Integer Overflow or Wraparound, Improper Access Control vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: RTI Connext
 CVE-2026-18461 (Use of Externally-Controlled Format String vulnerability in RTI Connex ...)
-	TODO: check
+	NOT-FOR-US: RTI Connext
 CVE-2026-18460 (Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Pro ...)
-	TODO: check
+	NOT-FOR-US: RTI Connext
 CVE-2026-18459 (Incorrect Calculation vulnerability in RTI Connext Professional (Core  ...)
-	TODO: check
+	NOT-FOR-US: RTI Connext
 CVE-2026-18458 (Out-of-bounds Read, Function Call With Incorrect Number of Arguments,  ...)
-	TODO: check
+	NOT-FOR-US: RTI Connext
 CVE-2026-18457 (Heap-based Buffer Overflow vulnerability in RTI Connext Professional ( ...)
-	TODO: check
+	NOT-FOR-US: RTI Connext
 CVE-2026-18439 (The Tutor LMS \u2013 eLearning and online course solution plugin for W ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18345 (The WP User Manager plugin for WordPress is vulnerable to unauthorized ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16778 (The Live Composer \u2013 Free WordPress Website Builder plugin for Wor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15095 (The Product Feed Manager for WooCommerce \u2013 CTX Feed \u2013 Suppor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13087 (A heap out-of-bounds write vulnerability was found in the Linux kernel ...)
 	TODO: check
 CVE-2026-12995 (The Custom Field Template plugin for WordPress is vulnerable to Insecu ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12718 (Improper neutralization of special elements used in an SQL command ('S ...)
 	TODO: check
 CVE-2026-11389 (Out-of-bounds Read, Function Call With Incorrect Number of Arguments,  ...)
-	TODO: check
+	NOT-FOR-US: RTI Connext
 CVE-2026-11388 (Double Free vulnerability in RTI Connext Professional (Core Libraries) ...)
-	TODO: check
+	NOT-FOR-US: RTI Connext
 CVE-2025-1281 (The BM Content Builder plugin for WordPress is vulnerable to arbitrary ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-1280 (The BM Content Builder plugin for WordPress is vulnerable to Directory ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-14487 (The Handily plugin for WordPress is vulnerable to unauthorized payment ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-14486 (The PixelPlay plugin for WordPress is vulnerable to unauthorized API k ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-14484 (The Image Buzz plugin for WordPress is vulnerable to unauthorized API  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-95831 (Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contai ...)
 	NOT-FOR-US: Crypt::SelfCertificate Perl module
 CVE-2026-95818 (A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c32abbc9e7cfea867d0234fd253f7ced36fc456e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c32abbc9e7cfea867d0234fd253f7ced36fc456e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/d6a98d01/attachment.htm>


More information about the debian-security-tracker-commits mailing list