Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
0d1457d7 by security tracker role at 2026-07-23T19:14:44+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,13 +1,13 @@
 CVE-2026-9729 (The Webpushr Push Notifications plugin for WordPress is 
vulnerable to  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-9713 (The Lumise Product Designer for WooCommerce plugin for 
WordPress is vu ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-9635 (The WP Shortcode by MyThemeShop plugin for WordPress is 
vulnerable to  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-8287 (Allocation of resources without limits or throttling 
vulnerability in  ...)
        TODO: check
 CVE-2026-6516 (Zohocorp ManageEngine ADAudit Plus versionsbefore 8606 are 
affected by ...)
-       TODO: check
+       NOT-FOR-US: Zoho
 CVE-2026-65920 (Diffusers through 0.39.0, fixed in commit cee298c, contains a 
path tra ...)
        TODO: check
 CVE-2026-65919 (Meshery before 1.0.57 contains an unauthenticated arbitrary 
file read  ...)
@@ -27,11 +27,11 @@ CVE-2026-65912 (DOMPurify before 3.3.2 contains a URI 
validation bypass vulnerab
 CVE-2026-65911 (In DOMPurify through 3.3.3, function predicates supplied via 
ADD_ATTR  ...)
        TODO: check
 CVE-2026-65908 (In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code 
execution  ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-65907 (In JetBrains TeamCity before 2026.1.2, 2025.11.6 code 
execution in Git ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-65906 (In JetBrains TeamCity before 2026.1.2, 2025.11.6 \u0441ode 
execution v ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-65904 (DOMPurify through 3.3.3 fails to sanitize DOM elements passed 
via IN_P ...)
        TODO: check
 CVE-2026-65903 (DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS 
function ...)
@@ -53,29 +53,29 @@ CVE-2026-65896 (Grav API Plugin (Composer package 
getgrav/grav-plugin-api) befor
 CVE-2026-65895 (Grav API Plugin versions before 1.0.10 fail to restrict write 
access t ...)
        TODO: check
 CVE-2026-65763 (Joomla Extension - phoca.cz - Reflected XSS vulnerability in 
Phoca Map ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-65762 (Joomla Extension - phoca.cz - Reflected XSS vulnerability in 
Phoca Gue ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-65761 (Joomla Extension - joomshaper.com - Unauthenticated SQL 
injection in E ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-65760 (Joomla Extension - joomshaper.com - cross-customer order and 
personal  ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-65759 (Joomla Extension - joomshaper.com - unauthenticated 
payment/order forg ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-65758 (Joomla Extension - tassos.gr - Sensitive data exposure in 
Convert Form ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-65757 (Joomla Extension - regularlabs.com - Inconsistent CSRF token 
checks /  ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-65756 (Joomla Extension - regularlabs.com - XSS vector in Keyboard 
Shortcuts  ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-65755 (Joomla Extension - regularlabs.com - Date-sensitive 
query-cache leakag ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-65754 (Joomla Extension - regularlabs.com - Insecure path handling in 
ReRepla ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-65713 (Joomla Extension - regularlabs.com - Insecure path handling in 
Modals  ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-65712 (Joomla Extension - regularlabs.com - Insecure path handling in 
CDN for ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-65702 (Vanna through 2.0.2 contains a path traversal vulnerability in 
the Fil ...)
        TODO: check
 CVE-2026-65701 (SoftVC VITS Singing Voice Conversion through commit 730930d 
contains a ...)
@@ -109,187 +109,187 @@ CVE-2026-65606 (SiYuan before v3.7.2 contains a 
cross-site scripting vulnerabili
 CVE-2026-65605 (SiYuan before v3.7.2 contains a stored cross-site scripting 
vulnerabil ...)
        TODO: check
 CVE-2026-65550 (Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65540 (Unauthenticated Cross Site Request Forgery (CSRF) in Popup for 
CF7 wit ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65539 (Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy 
HTML Sitema ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65538 (Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65537 (Subscriber Broken Access Control in Cyr to Lat reloaded \u2013 
transli ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65536 (Unauthenticated Cross Site Request Forgery (CSRF) in 
\u0627\u0641\u063 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65535 (Contributor Sensitive Data Exposure in TinyMCE Templates <= 
4.8.1 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65534 (Author Cross Site Scripting (XSS) in Custom links in Elementor 
Image C ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65533 (Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 
4.1.2 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65532 (Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65531 (Unauthenticated Broken Access Control in Qubely <= 1.8.14 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65530 (Subscriber Broken Access Control in TemplateSpare <= 4.2.2 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65529 (Unauthenticated Broken Access Control in Graphina <= 3.1.12 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65528 (Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 
3.8 versi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65527 (Contributor Cross Site Scripting (XSS) in LIQUID SPEECH 
BALLOON <= 1.2 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65526 (Contributor SQL Injection in Visualizer <= 4.0.6 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65525 (Unauthenticated Broken Access Control in Civi Framework <= 
2.2.0 versi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65524 (Contributor Broken Access Control in Avada Custom Branding <= 
1.2 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65522 (Contributor Cross Site Scripting (XSS) in Manual - 
Documentation, Know ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65521 (Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 
4.3.0 ve ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65519 (Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65518 (Contributor Cross Site Scripting (XSS) in Accept Donations 
with PayPal ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65516 (Unauthenticated Server Side Request Forgery (SSRF) in PeproDev 
Ultimat ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65514 (Contributor Cross Site Scripting (XSS) in Appointment Hour 
Booking <=  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65512 (Unauthenticated Cross Site Request Forgery (CSRF) in WP 
Activity Log < ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65511 (Unauthenticated Cross Site Scripting (XSS) in Manual - 
Documentation,  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65510 (Unauthenticated Cross Site Scripting (XSS) in PeproDev 
Ultimate Invoic ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65506 (Unauthenticated Broken Access Control in MP3 Audio Player for 
Music, R ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65505 (Unauthenticated Sensitive Data Exposure in Ultimate Store Kit 
Elemento ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65503 (Contributor Cross Site Scripting (XSS) in Ultimate Store Kit 
Elementor ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65501 (Unauthenticated Insecure Direct Object References (IDOR) in 
Shiptastic ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65500 (Unauthenticated Broken Access Control in Manual - 
Documentation, Knowl ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65499 (Unauthenticated Broken Access Control in PeproDev Ultimate 
Invoice <=  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65498 (Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 
versions ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65497 (Administrator PHP Object Injection in Complianz <= 7.5.0 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65496 (Author Server Side Request Forgery (SSRF) in Complianz <= 
7.5.0 versio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65495 (Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65494 (Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65493 (Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65492 (Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 
5.0.0 versi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65491 (Subscriber Broken Access Control in Query Wrangler <= 1.5.57 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65490 (Unauthenticated Sensitive Data Exposure in Create by Mediavine 
<= 2.5. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65489 (Unauthenticated Broken Access Control in LA-Studio Element Kit 
for Ele ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65488 (Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio 
Element ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65487 (Unauthenticated Broken Access Control in Photography <= 7.7.6 
versions ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65486 (Unauthenticated Broken Access Control in Event post <= 6.0.1 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65485 (Unauthenticated Broken Access Control in Content Control <= 
2.6.5 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65484 (Contributor Broken Access Control in Style Kits <= 2.6.5 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65483 (Author Cross Site Scripting (XSS) in HashThemes Demo Importer 
<= 1.4.2 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65482 (Contributor Cross Site Scripting (XSS) in LA-Studio Element 
Kit for El ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65481 (Contributor Local File Inclusion in Vino <= 1.9 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65480 (Contributor Cross Site Scripting (XSS) in TheGem <= 5.11.1 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65479 (Subscriber Broken Access Control in Reviewer <= 3.14.2 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65478 (Subscriber Broken Access Control in ListingPro <= 2.9.10 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65477 (Contributor Local File Inclusion in Tonda Core <= 2.1.2 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65476 (Unauthenticated Broken Access Control in Civi <= 2.2.4 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65475 (Improper Neutralization of Input During Web Page Generation 
('Cross-si ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65474 (Unauthenticated Sensitive Data Exposure in Ninja Tables <= 
5.2.10 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65473 (Contributor Cross Site Scripting (XSS) in 
Virtue/Ascend/Pinnacle Toolk ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65472 (Unauthenticated Broken Access Control in Kit (formerly 
ConvertKit) <=  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65471 (Unauthenticated Cross Site Request Forgery (CSRF) in Avada 
Core <= 5.1 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65470 (Contributor Cross Site Scripting (XSS) in Fluent Support <= 
2.3.0 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65469 (Unauthenticated Broken Access Control in AWP Classifieds <= 
4.4.7 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65468 (Unauthenticated Broken Access Control in JetBooking <= 4.1.2 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65467 (Contributor Server Side Request Forgery (SSRF) in JetEngine <= 
3.8.11  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65466 (Custom role Server Side Request Forgery (SSRF) in JetBooking 
<= 4.1.2  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65465 (Contributor Cross Site Scripting (XSS) in JetElements For 
Elementor <= ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65464 (Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 
4.16.3  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65463 (Subscriber Insecure Direct Object References (IDOR) in 
Masteriyo - LMS ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65462 (Administrator SQL Injection in Uncanny Automator <= 7.3.2 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65461 (Administrator Arbitrary File Upload in Really Simple CSV 
Importer <= 1 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65460 (Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal 
Gateway  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65458 (Contributor Sensitive Data Exposure in Polylang <= 3.8.5 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65457 (Subscriber Broken Access Control in \u042eKassa 
\u0434\u043b\u044f Woo ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65456 (Contributor Insecure Direct Object References (IDOR) in 
Product Slider ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65455 (Administrator Arbitrary File Upload in MapSVG <= 8.14.0 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65454 (Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 
versions ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65453 (Unauthenticated Broken Access Control in Ebook Store <= 6.19 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65452 (Unauthenticated Broken Access Control in Ebook Store <= 6.19 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65451 (Contributor SQL Injection in MapSVG <= 8.14.0 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65450 (Contributor SQL Injection in MapSVG <= 8.14.0 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65449 (Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65431 (Joomla Extension - regularlabs.com - Zipslip in GeoIP 
extension - Geo  ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-65430 (Joomla Extension - regularlabs.com - MaxMind Credential 
leakage in Geo ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-65010 (Datasets through 5.00, fixed in commit ad2d853, contains a 
symlink-fol ...)
        TODO: check
 CVE-2026-64876 (Joomla Extension - regularlabs.com - Inconsistent CSRF token 
checks /  ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-64875 (Joomla Extension - regularlabs.com - IP spoofing vulnerability 
in GeoI ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-64874 (Joomla Extension - regularlabs.com - CDN Credential leakage 
Cache Clea ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-64873 (Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro 
extensi ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-64872 (Joomla Extension - regularlabs.com - Path traversal in Cache 
Cleaner P ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-64871 (Joomla Extension - regularlabs.com - Inconsistent CSRF token 
checks /  ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-64815 (In JetBrains IntelliJ IDEA before 2026.2 arbitrary code 
injection was  ...)
        TODO: check
 CVE-2026-64814 (In JetBrains IntelliJ IDEA before 2026.2 unauthorized file 
access was  ...)
@@ -303,141 +303,141 @@ CVE-2026-64811 (In JetBrains IntelliJ IDEA before 
2026.2 arbitrary code executio
 CVE-2026-64810 (In JetBrains IntelliJ IDEA before 2026.2 hTML injection was 
possible i ...)
        TODO: check
 CVE-2026-64809 (In JetBrains PhpStorm before 2026.2 arbitrary code execution 
was possi ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-64808 (In JetBrains PhpStorm before 2026.2 arbitrary code execution 
was possi ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-64807 (In JetBrains WebStorm before 2026.2 arbitrary code execution 
was possi ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-64806 (In JetBrains WebStorm before 2026.2 arbitrary code execution 
was possi ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-64805 (In JetBrains WebStorm before 2026.2 arbitrary code execution 
was possi ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-64804 (In JetBrains WebStorm before 2026.2 arbitrary code execution 
was possi ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-64803 (In JetBrains GoLand before 2026.2 arbitrary code execution was 
possibl ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-64802 (In JetBrains GoLand before 2026.2 arbitrary code execution was 
possibl ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-64800 (In JetBrains GoLand before 2026.2 sensitive configuration 
values writt ...)
-       TODO: check
+       NOT-FOR-US: JetBrains
 CVE-2026-64799 (Joomla Extension - regularlabs.com - SSRF via remote image 
downloads i ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-64611 (A flaw was found in libcupsfilters. The 
cfIEEE1284NormalizeMakeModel() ...)
        TODO: check
 CVE-2026-63765 (Chatwoot before 4.16.0 contains an authentication bypass 
vulnerability ...)
        TODO: check
 CVE-2026-61981 (Unauthenticated Cross Site Request Forgery (CSRF) in Simple 
Link Direc ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61973 (Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61972 (Unauthenticated Broken Access Control in ShopLentor Pro <= 
2.8.5 versi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61954 (Unauthenticated Broken Access Control in PayU India <= 3.8.9 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61951 (Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61950 (Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61949 (Unauthenticated SQL Injection in Bookly <= 27.7 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61948 (Unauthenticated SQL Injection in WPDM \u2013 Premium Packages 
<= 6.2.0 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61947 (Unauthenticated Cross Site Scripting (XSS) in Form Vibes 
\u2013 Databa ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61946 (Unauthenticated Insecure Direct Object References (IDOR) in 
Easy Appoi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61945 (Exposure of Sensitive System Information to an Unauthorized 
Control Sp ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61944 (Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-61943 (Unauthenticated Broken Access Control in WPDM \u2013 Premium 
Packages  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59678 (An Incorrect Authorization vulnerability in Linux-Gaming 
PortProtonQt  ...)
        TODO: check
 CVE-2026-59677 (A Missing Authorization vulnerability in selinux 
policycoreutils seuns ...)
        TODO: check
 CVE-2026-59555 (Unauthenticated Arbitrary File Deletion in Participants 
Database <= 2. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59554 (Unauthenticated Broken Authentication in Ziina <= 1.2.21 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59547 (Unauthenticated Broken Access Control in Payment Gateway for 
PayPal on ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59545 (Unauthenticated Broken Authentication in miniOrange Discord 
Integratio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59544 (Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 
10.9.3. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59543 (Subscriber Remote Code Execution (RCE) in Advanced Views <= 
3.8.11 ver ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59542 (Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59541 (Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59540 (Unauthenticated Privilege Escalation in SMS Alert Order 
Notifications  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59526 (Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59525 (Unauthenticated SQL Injection in Participants Database <= 
2.7.8.3 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59524 (Unauthenticated Broken Authentication in Easy Digital 
Downloads <= 3.6 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59522 (Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59517 (Unauthenticated Cross Site Scripting (XSS) in Easy Form 
Builder <= 4.0 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59514 (Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59513 (Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 
2.3.0 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59512 (Unauthenticated Cross Site Scripting (XSS) in Product Enquiry 
for WooC ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57809 (Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 
2.34.0 ve ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57808 (Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57785 (Unauthenticated Cross Site Request Forgery (CSRF) in 
ApusListing <= 1. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57784 (Unauthenticated Cross Site Request Forgery (CSRF) in  Ninja 
Forms File ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57769 (Unauthenticated Cross Site Scripting (XSS) in Grand 
Photography <= 5.7 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57767 (Unauthenticated Cross Site Scripting (XSS) in WP Google Maps 
Pro <= 10 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57735 (Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 
2.7.1 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57717 (Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57716 (Unauthenticated Arbitrary File Deletion in Broadcast Live 
Video <= 7.2 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57704 (Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 
8.90.0  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57703 (Subscriber Broken Access Control in Sunshine Photo Cart <= 
3.6.10.1 ve ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57701 (Unauthenticated Cross Site Scripting (XSS) in Real Estate 
Manager Pro  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57699 (Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 
versions ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57696 (Contributor Arbitrary File Deletion in Picture Gallery <= 
1.6.5 versio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57626 (Cross-Site Request Forgery (CSRF) vulnerability in MailPoet 
allows Cro ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57428 (Unauthenticated Cross Site Scripting (XSS) in Sprout Clients 
<= 3.2.3  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57427 (Unauthenticated Cross Site Scripting (XSS) in Download Monitor 
- WPFor ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57425 (Unauthenticated Broken Access Control in Autopay dla 
WooCommerce <= 2. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57397 (Unauthenticated Cross Site Scripting (XSS) in Coaching <= 
3.9.2 versio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57384 (Subscriber Cross Site Scripting (XSS) in WishList Member X <= 
3.32.0 v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57374 (Unauthenticated Cross Site Scripting (XSS) in Funnel Kit 
Funnel Builde ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57373 (Customer Cross Site Scripting (XSS) in Funnel Kit Funnel 
Builder PRO < ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57370 (Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic 
Real Tim ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57367 (Subscriber Broken Access Control in WP Booking System < 
5.12.8.1 versi ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-52684 (If the auth responds very slowly and the records expire in 
between, th ...)
        TODO: check
 CVE-2026-48539 (GFI Archiver before 15.13 contains a stored cross-site 
scripting vulne ...)
@@ -471,55 +471,55 @@ CVE-2026-47743 (Shopper is a Headless e-commerce Admin 
Panel. Prior to 2.8.0, th
 CVE-2026-47668 (DbGate is cross-platform database manager. In versions 7.1.8 
and prior ...)
        TODO: check
 CVE-2026-44909 (Proxygen lacked a generalized slow-consumer detection 
mechanism in its ...)
-       TODO: check
+       NOT-FOR-US: Meta software not packaged in Debian
 CVE-2026-44210 (Kata Containers is an open source project focusing on a 
standard imple ...)
        TODO: check
 CVE-2026-43823 (When initializing an RSA public key from DER or PEM bytes 
throws an er ...)
-       TODO: check
+       NOT-FOR-US: Apple
 CVE-2026-43820 (NIOSSLCertificate._subjectAlternativeNames provides access to 
the raw  ...)
-       TODO: check
+       NOT-FOR-US: Apple
 CVE-2026-27423 (Subscriber Broken Access Control in Participants Database <= 
2.7.8.4 v ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27422 (Unauthenticated Broken Access Control in YT Player <= 2.0.9 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27418 (Unauthenticated Broken Access Control in WP Fast Total Search 
<= 1.81. ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27403 (Contributor Cross Site Scripting (XSS) in Hubbub Lite <= 
1.36.3 versio ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27399 (Unauthenticated Broken Access Control in MarketKing <= 2.1.40 
versions ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27392 (Contributor Broken Access Control in uListing <= 2.2.0 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27391 (Subscriber Broken Access Control in uListing <= 2.2.0 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27377 (Booking Agent Broken Access Control in QuickCal - Appointment 
Booking  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27372 (Unauthenticated Sensitive Data Exposure in PeproDev Ultimate 
Invoice < ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27355 (Unauthenticated Broken Access Control in Ditty <= 3.1.66 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-27064 (Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-25466 (Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-25427 (Subscriber Broken Access Control in eRoom <= 1.7.1 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-25424 (Contributor Broken Access Control in Mediavine Control Panel 
<= 2.10.1 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-25405 (Contributor SQL Injection in eRoom <= 1.7.1 versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-24639 (Author Server Side Request Forgery (SSRF) in Photo Block <= 
1.7.1 vers ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-24628 (Administrator Cross Site Scripting (XSS) in Photo Gallery by 
Supsystic ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-24552 (Contributor SQL Injection in Create by Mediavine <= 2.5.3 
versions.)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-24537 (Unauthenticated Cross Site Request Forgery (CSRF) in WP 
Accessibility  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-16768 (A flaw was found in gdk-pixbuf. When parsing a specially 
crafted ICO f ...)
        TODO: check
 CVE-2026-16756 (Missing connection and header-read timeouts and the absence of 
a concu ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-16745 (A flaw was found in odh-dashboard, the web console component 
of Red Ha ...)
        TODO: check
 CVE-2026-16735 (A security vulnerability has been detected in release-it 
conventional- ...)
@@ -529,27 +529,27 @@ CVE-2026-16733 (A weakness has been identified in 
bahmutov find-cypress-specs up
 CVE-2026-16723 (A remote code execution (RCE) vulnerability exists in fastjson 
1.2.68  ...)
        TODO: check
 CVE-2026-16584 (Improper handling of an initialization failure in AWS API MCP 
Server f ...)
-       TODO: check
+       NOT-FOR-US: Amazon
 CVE-2026-16287 (Improper neutralization of special elements used in an OS 
command ('OS ...)
        TODO: check
 CVE-2026-16078 (The WCPOS \u2013 Point of Sale (POS) plugin for WooCommerce 
plugin for ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15906 (The Premium Packages \u2013 Sell Digital Products Securely 
plugin for  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15827 (The GutenKit Blocks plugin for WordPress is vulnerable to 
unauthorized ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15794 (The Grid/List View for WooCommerce plugin for WordPress is 
vulnerable  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15786 (The WP Encryption \u2013 One Click Free SSL Certificate & SSL 
/ HTTPS  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15761 (The Tickera \u2013 Sell Tickets & Manage Events plugin for 
WordPress i ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15687 (A security issue was discovered in the Kubernetes Java client 
library  ...)
        TODO: check
 CVE-2026-15647 (The Brands for WooCommerce plugin for WordPress is vulnerable 
to Store ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15646 (The Brands for WooCommerce plugin for WordPress is vulnerable 
to Store ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15617 (Logto performs principal lookup without normalizing email and 
identifi ...)
        TODO: check
 CVE-2026-15616 (Logto does not enforce locally configured MFA during SSO 
authenticatio ...)
@@ -563,41 +563,41 @@ CVE-2026-15612 (Logto bypasses OIDC nonce validation when 
the nonce claim is abs
 CVE-2026-15611 (Logto allows unverified email-based SSO account linking, 
enabling an a ...)
        TODO: check
 CVE-2026-15448 (The Tickera \u2013 Sell Tickets & Manage Events plugin for 
WordPress i ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15404 (The Lpagery plugin for WordPress is vulnerable to Stored 
Cross-Site Sc ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15394 (The Header Footer Script Adder \u2013 Insert Code in Header, 
Body & Fo ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15348 (The Premium Packages \u2013 Sell Digital Products Securely 
plugin for  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15037 (Improper output neutralization (XML injection) in QDom 
comment, CDATA, ...)
        TODO: check
 CVE-2026-15017 (The MDJM Event Management plugin for WordPress is vulnerable 
to Privil ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15015 (The MountDev AI MCP Connector for WordPress plugin for 
WordPress is vu ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15011 (The Customer Support Ticket System & Helpdesk plugin for 
WordPress is  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14481 (The Equalize Digital Accessibility Checker \u2013 WCAG, ADA, 
EAA and S ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14282 (The GoDAM \u2013 Organize WordPress Media Library & File 
Manager with  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-14257 (brace-expansion through 5.0.7 is vulnerable to denial of 
service via m ...)
        TODO: check
 CVE-2026-13119 (The Registrations For The Events Calendar plugin for WordPress 
is vuln ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13009 (The AI Copilot \u2013 Content Generator plugin for WordPress 
is vulner ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-12421 (The ARforms plugin for WordPress is vulnerable to Stored 
Cross-Site Sc ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-11804 (Improper handling of insufficient permissions or privileges 
vulnerabil ...)
-       TODO: check
+       NOT-FOR-US: Honeywell
 CVE-2025-68081 (Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 
version ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2024-58330 (A missing authentication check in Bosch IP cameras of families 
CPP13 a ...)
-       TODO: check
+       NOT-FOR-US: Bosch
 CVE-2024-58023 (Information disclosure in Bosch Configuration Manager in 
Version 7.72. ...)
-       TODO: check
+       NOT-FOR-US: Bosch
 CVE-2026-9737 (During query planning when reading the sort pattern in raw 
BSONObj for ...)
        - mongodb <removed>
        NOTE: https://jira.mongodb.org/browse/SERVER-128341



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0d1457d7507ab6178925f6bffff96f9f491433c6

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0d1457d7507ab6178925f6bffff96f9f491433c6
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to