Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
93d2e085 by security tracker role at 2026-07-23T07:14:47+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,13 +1,13 @@
 CVE-2026-9737 (During query planning when reading the sort pattern in raw 
BSONObj for ...)
        TODO: check
 CVE-2026-9577 (The Post Status Notifier Lite WordPress plugin before 1.13.0 
does not  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-9066 (The WP Compress  WordPress plugin before 7.10.04 does not 
validate the ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-7534 (The SUMO Reward Points plugin for WordPress is vulnerable to 
Unauthent ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-7232 (The FormCraft plugin for WordPress is vulnerable to Stored 
Cross-Site  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-7120 (@fastify/static evaluates the allowedPath callback before 
normalizing  ...)
        TODO: check
 CVE-2026-6390 (A flaw was found in GNU nano's multi-buffer error message 
handling. Wh ...)
@@ -15,33 +15,33 @@ CVE-2026-6390 (A flaw was found in GNU nano's multi-buffer 
error message handlin
 CVE-2026-64829 (Question2Answer through 1.8.8 contains a session invalidation 
vulnerab ...)
        TODO: check
 CVE-2026-64798 (Persistent URL login keys were also generated using a 
non-cryptographi ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-64797 (IP Login trusted forwarded client-IP headers without requiring 
a confi ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-64796 (Free did not require both the article creator and last 
modifier to be  ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-64795 (Tag-provided custom HTML, module content/title overrides and 
decoded m ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-64794 (User tags, filters and conditions allowed access to 
insufficiently res ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-64793 (Content tags could use ignore flags or property overrides to 
render re ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-64792 (Smart Search indexing could render generated content using the 
indexin ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-64791 (Administrator routes and install/update/uninstall processing 
did not c ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-63685 (Administrator routes and replacement requests did not 
consistently req ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-63684 (Administrator actions, editor popups and import/export 
requests lacked ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-63683 (IP and GeoIP conditions trusted spoofable forwarded headers, 
allowing  ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-63281 (Stored condition values could also execute HTML/JavaScript in 
administ ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-63280 (Conditions administration did not consistently enforce tokens 
and comp ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-63265 (Privileged Regular Labs AJAX endpoints did not consistently 
require va ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-63226 (Printers and Multifunction Printers (MFPs) provided by Ricoh 
Company,  ...)
        TODO: check
 CVE-2026-61246 (Vulnerability in the Oracle Platform Security for Java product 
of Orac ...)
@@ -75,7 +75,7 @@ CVE-2026-38765 (An issue in Unistal Systems Pvt. 
Ltd.Protegent 360 v2.0.0.4 allo
 CVE-2026-38763 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 
allows a l ...)
        TODO: check
 CVE-2026-21723 (The alertmanager templates test endpoint 
(/api/alertmanager/grafana/co ...)
-       TODO: check
+       NOT-FOR-US: Grafana Labs
 CVE-2026-16653 (A security flaw has been discovered in boazsegev facil.io up 
to 0.7.58 ...)
        TODO: check
 CVE-2026-16632 (A flaw has been found in boazsegev facil.io up to 0.7.4. 
Affected is t ...)
@@ -95,7 +95,7 @@ CVE-2026-14899 (The code to parse MIME headers for display 
when forwarding a mes
 CVE-2026-14881 (When importing connections in Compass it is possible to 
override some  ...)
        TODO: check
 CVE-2026-14291 (The security-ninja-premium WordPress plugin before 5.290 does 
not veri ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13089 (OIDC::Lite versions through 0.12.1 for Perl allow ID Token 
signature v ...)
        TODO: check
 CVE-2026-13078 (A vulnerability was discovered in MongoDB Server where the 
server-side ...)
@@ -147,7 +147,7 @@ CVE-2026-13056 (Using expressions that generate large 
arrays it is possible to c
 CVE-2026-13055 (The `$_internalIndexKey` aggregation expression can be used by 
any aut ...)
        TODO: check
 CVE-2026-12082 (The Praison AI SEO WordPress plugin before 5.0.7 does not 
perform auth ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2025-60835 (An issue in the unrar.dll component of IZArc v4.6 allows 
attackers to  ...)
        TODO: check
 CVE-2025-50330 (An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before 
allows a  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/93d2e085a66515b9098c7a1ebbd9e94ed026c111

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/93d2e085a66515b9098c7a1ebbd9e94ed026c111
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to