[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 23 08:14:45 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e2565d36 by security tracker role at 2026-09-23T07:14:37+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -17,7 +17,7 @@ CVE-2026-96257 (A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Af
 CVE-2026-95958 (A security flaw has been discovered in JusticeRage Manalyze 1.0.0. Imp ...)
 	TODO: check
 CVE-2026-95957 (A vulnerability was found in SourceCodester Smart Attendance System wi ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-95930 (A security vulnerability has been detected in iFlytek astron-agent up  ...)
 	TODO: check
 CVE-2026-95929 (A weakness has been identified in iFlytek astron-agent up to 1.0.7. Af ...)
@@ -25,19 +25,19 @@ CVE-2026-95929 (A weakness has been identified in iFlytek astron-agent up to 1.0
 CVE-2026-95928 (A security flaw has been discovered in recommenders-team recommenders  ...)
 	TODO: check
 CVE-2026-95927 (A vulnerability was identified in SourceCodester Online Reviewer Manag ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-95926 (A vulnerability was determined in SourceCodester Online Reviewer Manag ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-95925 (A vulnerability was found in SourceCodester Online Reviewer Management ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-95924 (A vulnerability has been found in SourceCodester Online Reviewer Manag ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-95897 (A security vulnerability has been detected in Dask up to 2026.8.0. Thi ...)
 	TODO: check
 CVE-2026-95868 (A weakness has been identified in AdithyaYelloju Restaurant-Management ...)
 	TODO: check
 CVE-2026-95833 (A weakness has been identified in itsourcecode Leave Management System ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-95830 (A security flaw has been discovered in theRealSain Pixtream up to 866a ...)
 	TODO: check
 CVE-2026-95829 (A vulnerability was identified in TDuckCloud tduck-platform up to 5.3. ...)
@@ -49,7 +49,7 @@ CVE-2026-95820 (A vulnerability was found in anirbandutta9 College-Notes-Gallery
 CVE-2026-95819 (A vulnerability has been found in anirbandutta9 College-Notes-Gallery  ...)
 	TODO: check
 CVE-2026-95815 (OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs inclu ...)
-	TODO: check
+	NOT-FOR-US: OpenClaw
 CVE-2026-95814 (Vaultwarden through 1.37.3 omits organization membership status valida ...)
 	TODO: check
 CVE-2026-95813 (e621ng versions before 26.09.16 pass untrusted request parameters dire ...)
@@ -59,19 +59,19 @@ CVE-2026-95812 (ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site
 CVE-2026-94574 (A local cross-user code execution vulnerability exists in GNU wget (Wi ...)
 	TODO: check
 CVE-2026-94450 (Improper validation of the Destination Connection ID length in s2n-qui ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-94367 (OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains  ...)
 	TODO: check
 CVE-2026-93528 (The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 do ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-93511 (The Premium Packages  WordPress plugin before 7.2.1 does not verify Pa ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-93510 (The Points and Rewards for WooCommerce WordPress plugin before 2.10.4  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-93508 (The WC Fields Factory WordPress plugin before 4.1.11 does not properly ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-93507 (The WC Fields Factory WordPress plugin before 4.1.11 does not properly ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-92930 (OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an a ...)
 	TODO: check
 CVE-2026-92929 (OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an ...)
@@ -83,23 +83,23 @@ CVE-2026-91777 (Forward-reference completion for @JsonIdentityInfo object IDs in
 CVE-2026-91776 (TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind ...)
 	TODO: check
 CVE-2026-91077 (The Event Booking Manager for WooCommerce  WordPress plugin before 5.7 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-91073 (The Subscribe Forms  WordPress plugin before 1.6.3 does not sanitise a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-91025 (The Booking Manager  WordPress plugin before 2.1.21 does not verify th ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-91024 (The Booking Manager  WordPress plugin before 2.1.21 does not sanitize  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-91018 (lwIP (Lightweight IP)has a double free vulnerability, which could cras ...)
 	TODO: check
 CVE-2026-90985 (The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 do ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-90951 (The Paid Membership Subscriptions  WordPress plugin before 3.1.0 does  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-89425 (UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-cor ...)
 	TODO: check
 CVE-2026-89331 (The FluentBoards  WordPress plugin before 2.1.0 does not properly rest ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-89282 (The Apache Lounge Windows distribution of Apache HTTP Server build con ...)
 	TODO: check
 CVE-2026-89281 (The Apache Lounge Windows distribution of Apache HTTP Server build con ...)
@@ -107,9 +107,9 @@ CVE-2026-89281 (The Apache Lounge Windows distribution of Apache HTTP Server bui
 CVE-2026-89019
 	REJECTED
 CVE-2026-88997 (The JSM Show Post Metadata WordPress plugin before 4.9.1 does not prop ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-88929 (The Product Badge, Label, Countdown Timer for WooCommerce  WordPress p ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-88624 (Missing path validation in the Worktree.remove component of openCode v ...)
 	TODO: check
 CVE-2026-88419 (An unrestricted upload of files with a dangerous type in the thumbnail ...)
@@ -133,73 +133,73 @@ CVE-2026-88339 (A NULL pointer dereference vulnerability exists in the gf_sg_vrm
 CVE-2026-88020 (Autonomy Logic OpenPLC 3is susceptible to an improper neutralization o ...)
 	TODO: check
 CVE-2026-87981 (The Paymob for WooCommerce WordPress plugin before 4.1.14 does not per ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87979 (The Paymob for WooCommerce WordPress plugin before 4.1.14 does not ver ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87121 (lwIPTCP/IP Stack MQTTis vulnerable to an out-of-bounds write, which ma ...)
 	TODO: check
 CVE-2026-87074 (The Forminator Forms  WordPress plugin before 1.57.2.1 does not bind i ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87069 (The Forminator Forms  WordPress plugin before 1.57.2.1 does not perfor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86842 (The Real3D Flipbook  WordPress plugin before 5.4 does not perform capa ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86785 (The Social Commerce for WooCommerce WordPress plugin through 2.5.4 doe ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86783 (The Post Grid Gutenberg Blocks  WordPress plugin before 5.0.41 does no ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86608 (The WP Recipe Maker WordPress plugin before 10.8.2 does not have any a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86603 (The WP Recipe Maker WordPress plugin before 10.8.2 does not have any a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86602 (The WP Recipe Maker WordPress plugin before 10.8.2 does not perform an ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-85006 (The HappyAddons for Elementor  WordPress plugin before 3.50.0 does not ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84743 (The Events Calendar WordPress plugin before 6.17.5 does not perform a  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84742 (The Events Calendar WordPress plugin before 6.17.5 does not check the  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84741 (The Events Calendar WordPress plugin before 6.17.5 does not check the  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84168 (The Easy Hide Login WordPress plugin before 1.7 does not fully enforce ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84150 (The Directorist: AI-Powered Business Directory, Listings & Classified  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84098 (The Directorist: AI-Powered Business Directory, Listings & Classified  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84046 (The Directorist: AI-Powered Business Directory, Listings & Classified  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84027 (The Directorist: AI-Powered Business Directory, Listings & Classified  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84026 (The Directorist: AI-Powered Business Directory, Listings & Classified  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-83805 (Nautobot is a Network Source of Truth and Network Automation Platform. ...)
 	TODO: check
 CVE-2026-83801 (Nautobot is a Network Source of Truth and Network Automation Platform. ...)
 	TODO: check
 CVE-2026-83555 (The Email Subscribers & Newsletters  WordPress plugin before 5.9.35 do ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-82843 (The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-82331 (Improper link resolution before file access ('link following') vulnera ...)
 	TODO: check
 CVE-2026-81339 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 d ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81338 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 d ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-80342 (The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-79767 (Gardener implements the automated management and operation of Kubernet ...)
 	TODO: check
 CVE-2026-77987 (A server-side request forgery (SSRF) vulnerability was identified in t ...)
-	TODO: check
+	NOT-FOR-US: Github Enterprise Server
 CVE-2026-77912 (A stored cross-site scripting (XSS) vulnerability was identified in Gi ...)
-	TODO: check
+	NOT-FOR-US: Github Enterprise Server
 CVE-2026-77766 (The Directorist: AI-Powered Business Directory, Listings & Classified  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77765 (The Better Payment  WordPress plugin before 2.3.4 does not validate th ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77426 (Unleash is an open-source feature management platform. Prior to 8.0.3, ...)
 	TODO: check
 CVE-2026-77425 (Unleash is an open-source feature management platform. Prior to 8.0.3, ...)
@@ -211,33 +211,33 @@ CVE-2026-76910 (Unleash is an open-source feature management platform. Prior to
 CVE-2026-76909 (Unleash is an open-source feature management platform. Prior to 8.0.3, ...)
 	TODO: check
 CVE-2026-76717 (A vulnerability exists in the Analytics and Location Engine (ALE) API  ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-76716 (Multiple vulnerabilities exist in the Analytics and Location Engine (A ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-76715 (A vulnerability in an administrative component of Analytics and Locati ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-76714 (Vulnerabilities in the Analytics and Location Engine web interface all ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-76713 (A vulnerability exists in the maintenance restore functionality of Ana ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-76712 (A vulnerability exists in the Analytics and Location Engine (ALE) that ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-76711 (A vulnerability exists in an Analytics and Location Engine (ALE) compo ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-76710 (A vulnerability exists in the Analytics and Location Engine (ALE) mana ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-76709 (A vulnerability exists in the internal administrative component of Ana ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-76708 (A vulnerability exists in the Analytics and Location Engine (ALE) wher ...)
-	TODO: check
+	NOT-FOR-US: HPE
 CVE-2026-75799 (The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate th ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-75432 (An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitiv ...)
 	TODO: check
 CVE-2026-75101 (An authorization bypass vulnerability was identified in GitHub Enterpr ...)
-	TODO: check
+	NOT-FOR-US: Github Enterprise Server
 CVE-2026-6831 (The Advanced Contact form 7 DB plugin for WordPress is vulnerable to m ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-67615 (openEQUELLA before 2026.1.0 contains an authenticated remote code exec ...)
 	TODO: check
 CVE-2026-65829 (MPXJ is an open source library to read and write project plans from a  ...)
@@ -257,7 +257,7 @@ CVE-2026-61685 (ReactPress is a publishing system for React developers. Prior to
 CVE-2026-61570 (MPXJ is an open source library to read and write project plans from a  ...)
 	TODO: check
 CVE-2026-5924 (The Getwid \u2013 Gutenberg Blocks plugin for WordPress is vulnerable  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-59991 (psd-tools is a Python package for working with Adobe Photoshop PSD fil ...)
 	TODO: check
 CVE-2026-58268 (SIPGO is a library for writing SIP services in the GO language. Prior  ...)
@@ -267,113 +267,113 @@ CVE-2026-57576 (plone.app.dexterity is a content-type system for the Plone conte
 CVE-2026-47116 (LTSecurity LTK3500SF contains a hard-coded credentials vulnerability w ...)
 	TODO: check
 CVE-2026-28325 (SolarWinds Observability Self-Hosted was found to be affected by an un ...)
-	TODO: check
+	NOT-FOR-US: SolarWinds
 CVE-2026-28324 (SolarWinds Observability Self-Hosted was found to be affected by an un ...)
-	TODO: check
+	NOT-FOR-US: SolarWinds
 CVE-2026-19438 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
-	TODO: check
+	NOT-FOR-US: ABB group
 CVE-2026-19202 (A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-pyth ...)
 	TODO: check
 CVE-2026-18365 (The zportals WordPress plugin before 6.4.2 does not perform any capabi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18364 (The zportals WordPress plugin before 6.4.2 does not perform any capabi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18176 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18173 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18172 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18170 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18169 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18163 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18162 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18161 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18156 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18154 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18153 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18152 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18137 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18134 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18133 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18132 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18131 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18124 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18123 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18114 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18095 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18074 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18066 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17647 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17646 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17645 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17644 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17643 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17637 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17636 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17635 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17620 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 t ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17618 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17472 (IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17465 (IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17102 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16672 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16469 (IBM DataStage on Cloud Pak for Data 5.4.0.0 px-runtime could allow a r ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16468 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16426 (IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request f ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16346 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16264 (The Newsletters WordPress plugin before 4.18.1 does not perform an own ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15915 (IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-14321 (The divi-dash WordPress plugin before 1.0.7 does not validate the sour ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-36084 (IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographi ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-15696 (The Real3D Flipbook  WordPress plugin before 5.4 does not sanitize or  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-12767 (IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2022-4997 (The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-95350
 	- chromium <unfixed>
 CVE-2026-95357



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2565d367ec505a4112c7e3cf14201be5b987476

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2565d367ec505a4112c7e3cf14201be5b987476
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260923/6035bb3d/attachment.htm>


More information about the debian-security-tracker-commits mailing list