[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 25 20:15:10 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5649433d by security tracker role at 2026-09-25T19:15:03+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -103,25 +103,25 @@ CVE-2026-97063 (X-SpringBoot through 6.0 returns login verification codes in HTT
 CVE-2026-97060 (X-SpringBoot through 6.0 lacks object-level authorization in user mana ...)
 	TODO: check
 CVE-2026-96883 (pgcollection is an open source extension to PostgreSQL. A type confusi ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-96874 (Improper neutralization of input during web page generation ('cross-si ...)
 	TODO: check
 CVE-2026-96812 (Improper Exposure of Resource to Wrong Sphere in the host file helper  ...)
 	TODO: check
 CVE-2026-96766 (The GeoDirectory \u2013 WP Business Directory Plugin and Classified Li ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-96752 (The Zero Spam for WordPress plugin for WordPress is vulnerable to Stor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-96568 (The Restaurant Menu and Food Ordering plugin for WordPress is vulnerab ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-96448 (A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) featu ...)
 	TODO: check
 CVE-2026-96039 (The BA Book Everything plugin for WordPress is vulnerable to Stored Cr ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-95866 (The User Profile Builder \u2013 Beautiful User Registration Forms, Use ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-95864 (The Themify Builder plugin for WordPress is vulnerable to Stored Cross ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-95835 (Missing Authorization in the askpass escape code handler in kitty from ...)
 	TODO: check
 CVE-2026-95834 (Use After Free in the drag source path of the drag and drop protocol i ...)
@@ -131,37 +131,37 @@ CVE-2026-95832 (Improper Neutralization of Special Elements in Output Used by a
 CVE-2026-95699 (Prior to 9/18/2026, the iSteamX mobile application's AWS policy could  ...)
 	TODO: check
 CVE-2026-94573 (The Repeater Fields for Elementor Forms plugin for WordPress is vulner ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-94445 (A malicious txtar could escape the intended execution context and forc ...)
 	TODO: check
 CVE-2026-94376 (The Better Messages \u2013 Chat Rooms, Group Chat, Private Messages &  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-93901 (The Optima Express IDX plugin for WordPress is vulnerable to Privilege ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-93899 (The Better Messages \u2013 Chat Rooms, Group Chat, Private Messages &  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-93897 (The GeoDirectory \u2013 WP Business Directory Plugin and Classified Li ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-93834 (A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A r ...)
 	TODO: check
 CVE-2026-93747 (The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-93656 (The User Profile Builder \u2013 Beautiful User Registration Forms, Use ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-93654 (The Premium Packages \u2013 Sell Digital Products Securely plugin for  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-93647 (An unauthenticated calendar sender can place active markup in a COUNTE ...)
-	TODO: check
+	NOT-FOR-US: Zimbra
 CVE-2026-93643 (When OnlyOffice/Document Editing is available, an unauthenticated remo ...)
 	TODO: check
 CVE-2026-93642 (An unauthenticated sender can forge a share notification that triggers ...)
-	TODO: check
+	NOT-FOR-US: Zimbra
 CVE-2026-93641 (An unauthenticated sender can forge a share notification that triggers ...)
-	TODO: check
+	NOT-FOR-US: Zimbra
 CVE-2026-93477 (Improperly Controlled Modification of Dynamically-Determined Object At ...)
 	TODO: check
 CVE-2026-93399 (The Bookly plugin for WordPress is vulnerable to Insecure Direct Objec ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-93366 (Bludit CMS through 3.22.0 contains an authorization bypass vulnerabili ...)
 	TODO: check
 CVE-2026-93365 (Bludit CMS through 3.22.0 contains a missing authorization vulnerabili ...)
@@ -175,9 +175,9 @@ CVE-2026-93354 (Taskview Community before 1.56.0 contains a missing authenticati
 CVE-2026-93353 (copyparty contains a volume restriction bypass vulnerability in its SF ...)
 	TODO: check
 CVE-2026-93306 (IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-93303 (The HT Contact Form \u2013 Drag & Drop Form Builder for WordPress plug ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-93291 (Omni C20 lacks proper certificate validation which could allow an atta ...)
 	TODO: check
 CVE-2026-93290 (Omni C20 uses hard-coded credentials that could allow an attacker to m ...)
@@ -185,35 +185,35 @@ CVE-2026-93290 (Omni C20 uses hard-coded credentials that could allow an attacke
 CVE-2026-93289 (The affected products are vulnerable to command injection attack that  ...)
 	TODO: check
 CVE-2026-93030 (FTM 4.x ALL could allow a remote authenticated attacker to obtain sens ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-92829 (The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPre ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-92799 (The Online Scheduling and Appointment Booking System \u2013 Bookly plu ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-92746 (The Gutenverse \u2013 WordPress Blocks, Page Builder & Site Editor plu ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-92713 (The Modula Image Gallery \u2013 Photo Grid & Video Gallery plugin for  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-92212 (The JetFormBuilder \u2014 Dynamic Blocks Form Builder plugin for WordP ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-92161 (FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Tw ...)
 	TODO: check
 CVE-2026-92106 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
 	TODO: check
 CVE-2026-89426 (The Knit Pay \u2013 Cashfree, Instamojo, Razorpay, PayPal and more plu ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-89406 (The Modula Image Gallery \u2013 Photo Grid & Video Gallery plugin for  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-89055 (The Customer Reviews for WooCommerce plugin for WordPress is vulnerabl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-89032 (BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass ...)
 	TODO: check
 CVE-2026-88996 (The WPForms \u2013 AI Form Builder for WordPress \u2013 Contact Forms, ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-88956 (The Botslab G980H dash camera firmware contains an authentication vuln ...)
 	TODO: check
 CVE-2026-88848 (The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-88761 (The Botslab G980H dash camera firmware generates the default WiFi pass ...)
 	TODO: check
 CVE-2026-88421 (Incorrect access control in the BlogPage.get_entries() component of AP ...)
@@ -237,15 +237,15 @@ CVE-2026-87720 (Incorrect Authorization (CWE-863) in project name normalization
 CVE-2026-87118 (The Botslab G980H dash camera firmware contains an out of bounds write ...)
 	TODO: check
 CVE-2026-86837 (The Bookly WordPress plugin before 28.3 does not properly verify a cus ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-85750 (Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote  ...)
 	TODO: check
 CVE-2026-85542 (IBM Guardium Data Protection 12.2 is affected by a command injection v ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-85496 (The Botslab G980H dash camera firmware generates session identifiers u ...)
 	TODO: check
 CVE-2026-85417 (Incomplete property masking in the SANnav logging subsystem permits SN ...)
-	TODO: check
+	NOT-FOR-US: Brocade
 CVE-2026-85293 (InvoicePlane is a self-hosted open source application for managing inv ...)
 	TODO: check
 CVE-2026-85292 (InvoicePlane is a self-hosted open source application for managing inv ...)
@@ -261,15 +261,15 @@ CVE-2026-85274 (InvoicePlane is a self-hosted open source application for managi
 CVE-2026-85082 (Root Browser Classic 3.3.0 passes the path of a selected SQLite databa ...)
 	TODO: check
 CVE-2026-85029 (IBM Guardium Data Protection 12.2 could allow a remote attacker to obt ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-84893 (IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in th ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-84884 (IBM Guardium Data Protection 12.2 stores internal REST service-account ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-84882 (IBM Guardium Data Protection 12.2 is vulnerable to path traversal in t ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-84862 (IBM Guardium Data Protection 12.2 is vulnerable to insecure deserializ ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-84465 (Zammad is a web based open source helpdesk/customer support system. Pr ...)
 	TODO: check
 CVE-2026-84464 (Zammad is a web based open source helpdesk/customer support system. Pr ...)
@@ -291,13 +291,13 @@ CVE-2026-84399 (The Botslab G980H dash camera firmware contains an authorization
 CVE-2026-84283 (Secure Folder 1.2 stores files selected for its password-protected vau ...)
 	TODO: check
 CVE-2026-84281 (The Fancy Product Designer plugin for WordPress is vulnerable to Store ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84280 (The Fancy Product Designer plugin for WordPress is vulnerable to Store ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84279 (The Fancy Product Designer plugin for WordPress is vulnerable to Store ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-83591 (The AMP for WP \u2013 Accelerated Mobile Pages plugin for WordPress is ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-82716 (The Botslab G980H dash camera firmware includes sensitive configuratio ...)
 	TODO: check
 CVE-2026-82708 (The Botslab G980H dash camera firmware contains a path traversal vulne ...)
@@ -307,13 +307,13 @@ CVE-2026-82585 (The Botslab G980H dash camera firmware transmits sensitive infor
 CVE-2026-82566 (The Botslab G980H dash camera firmware contains a session management v ...)
 	TODO: check
 CVE-2026-82372 (Improper handling of sensitive data during IPsec policy creation and m ...)
-	TODO: check
+	NOT-FOR-US: Brocade
 CVE-2026-82164 (Dell Trusted Device Client, versions prior to 8.1.359.0, contain an In ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-81630 (The Botslab G980H dash camera firmware does not adequately verify the  ...)
 	TODO: check
 CVE-2026-80514 (The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not ver ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-80432 (Missing Authorization in the drop handling path of the drag and drop p ...)
 	TODO: check
 CVE-2026-80431 (Out-of-bounds Write in the natural width branch of the text sizing pro ...)
@@ -327,11 +327,11 @@ CVE-2026-79153 (Seclore FileSecure Desktop Client before 3.25.1.0 contains impro
 CVE-2026-78902 (Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE  ...)
 	TODO: check
 CVE-2026-78397 (The Link Library WordPress plugin before 7.9.6 does not validate the d ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-78394 (The Link Library WordPress plugin before 7.9.6 does not sanitize a use ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-78393 (The Link Library WordPress plugin before 7.9.6 does not properly escap ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-77967 (The Botslab G980H dash camera firmware accepts a reusable authenticati ...)
 	TODO: check
 CVE-2026-75558 (The Botslab G980H dash camera firmware uses a hard-coded cryptographic ...)
@@ -425,7 +425,7 @@ CVE-2026-63006 (Zammad is a web based open source helpdesk/customer support syst
 CVE-2026-62262 (Piwigo is a full featured open source photo gallery application for th ...)
 	TODO: check
 CVE-2026-62062 (Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website B ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61855 (Zammad is a web based open source helpdesk/customer support system. In ...)
 	TODO: check
 CVE-2026-61837 (RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3,  ...)
@@ -535,9 +535,9 @@ CVE-2026-33639 (InvoicePlane is a self-hosted open source application for managi
 CVE-2026-27867 (An attacker with access via network to the Regesta Smart HD-PLC of the ...)
 	TODO: check
 CVE-2026-19804 (The s2Member \u2013 Excellent for All Kinds of Memberships, Content Re ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19775 (The OpenStation \u2014 Desktop Windows, Dock & Virtual Desktops for WP ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18320 (Readwise Reader for Android uses a sanitize-html configuration that pe ...)
 	TODO: check
 CVE-2026-18312 (Readwise Reader for Android constructs URLs in its WebView using attac ...)
@@ -545,23 +545,23 @@ CVE-2026-18312 (Readwise Reader for Android constructs URLs in its WebView using
 CVE-2026-18311 (Readwise Reader for Android contains a cross-site scripting vulnerabil ...)
 	TODO: check
 CVE-2026-17602 (The SSL Zen \u2014 SSL Certificate Installer & HTTPS Redirects plugin  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-17577 (The SSL Zen plugin for WordPress is vulnerable to Reflected Cross-Site ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14443 (Incomplete log sanitization during bulk IPsec policy collection in Bro ...)
-	TODO: check
+	NOT-FOR-US: Brocade
 CVE-2026-14442 (An information exposure vulnerability in the job scheduling component  ...)
-	TODO: check
+	NOT-FOR-US: Brocade
 CVE-2026-14441 (A logic flaw in Java cache key handling object comparison handling cou ...)
-	TODO: check
+	NOT-FOR-US: Brocade
 CVE-2026-14281 (The Automation Web Platform \u2013 Notifications and OTP for WooCommer ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13456 (The WP Maps \u2013 Google Maps,OpenStreetMap,Mapbox,Store Locator,List ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13179 (The WP Maps \u2013 Google Maps,OpenStreetMap,Mapbox,Store Locator,List ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12037 (The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerab ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-100306 (TDuck survey form through 6.0 fails to validate write passwords on sub ...)
 	TODO: check
 CVE-2026-100305 (TDuck survey form through 6.0 fails to enforce form fill-in restrictio ...)
@@ -591,9 +591,9 @@ CVE-2026-100174 (The AIL Framework tag selector component (var/www/static/js/tag
 CVE-2026-100172 (The AIL Framework (ail-project/ail-framework) contains a stored cross- ...)
 	TODO: check
 CVE-2025-51457 (D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command in ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2025-14814 (The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Sto ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-98162 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
 	- linux 7.2.6-1
 	NOTE: https://git.kernel.org/linus/39f2032096715daae5f6fd0f587ca7a474b019df (7.3-rc1)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5649433db6038a7ffa3dfe6f3e029856fdaf75f7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5649433db6038a7ffa3dfe6f3e029856fdaf75f7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/fccd8131/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list