From 0748be2319e6f79197232bf179f78c96270b97c3 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 3 Mar 2025 15:33:16 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-4fwr-mh5q-hchh.json | 6 ++- .../GHSA-phg3-gv66-q38x.json | 6 ++- .../GHSA-w22f-vwwp-37pr.json | 6 ++- .../GHSA-fp9w-9x2r-74qr.json | 3 +- .../GHSA-2267-x99j-hcv3.json | 36 +++++++++++++++ .../GHSA-248v-wwj6-r5j3.json | 36 +++++++++++++++ .../GHSA-24wm-5x58-mcgj.json | 36 +++++++++++++++ .../GHSA-26rw-w7w7-gjpm.json | 36 +++++++++++++++ .../GHSA-2739-vvgg-6rwf.json | 36 +++++++++++++++ .../GHSA-29p9-2mj3-cp4j.json | 36 +++++++++++++++ .../GHSA-2ghq-fx5m-357p.json | 40 +++++++++++++++++ .../GHSA-2jwv-3p8q-v273.json | 36 +++++++++++++++ .../GHSA-2pfp-372c-3936.json | 36 +++++++++++++++ .../GHSA-2pmg-cj35-7j9h.json | 36 +++++++++++++++ .../GHSA-2r4h-53cp-fff4.json | 36 +++++++++++++++ .../GHSA-2w7h-g4qr-jpgp.json | 36 +++++++++++++++ .../GHSA-2wmq-9w92-6xx4.json | 36 +++++++++++++++ .../GHSA-349h-vrrw-f3cp.json | 36 +++++++++++++++ .../GHSA-3542-jvch-wmhr.json | 36 +++++++++++++++ .../GHSA-383x-g2c2-mfm5.json | 36 +++++++++++++++ .../GHSA-3gfg-8wp8-c6wx.json | 36 +++++++++++++++ .../GHSA-3hw8-vgvf-843g.json | 36 +++++++++++++++ .../GHSA-3jcv-phqx-p74w.json | 36 +++++++++++++++ .../GHSA-3mf9-w9xg-qcf8.json | 36 +++++++++++++++ .../GHSA-3pj7-9q5p-c6ww.json | 36 +++++++++++++++ .../GHSA-3q4v-7rf3-mxgq.json | 36 +++++++++++++++ .../GHSA-47fm-3mhp-7p4x.json | 36 +++++++++++++++ .../GHSA-487p-v6x9-cqw2.json | 36 +++++++++++++++ .../GHSA-493v-hhpj-94x4.json | 36 +++++++++++++++ .../GHSA-4c75-259h-2625.json | 36 +++++++++++++++ .../GHSA-4fw9-4m74-7p58.json | 36 +++++++++++++++ .../GHSA-4hv4-5v49-7fwm.json | 36 +++++++++++++++ .../GHSA-4pw8-2cvg-fr56.json | 36 +++++++++++++++ .../GHSA-4rg5-q2f4-87rx.json | 36 +++++++++++++++ .../GHSA-5534-8425-cj8p.json | 36 +++++++++++++++ .../GHSA-55xj-pjqm-cpfm.json | 36 +++++++++++++++ .../GHSA-57fr-4f8x-2f8w.json | 36 +++++++++++++++ .../GHSA-57j9-569f-rrxf.json | 36 +++++++++++++++ .../GHSA-589j-7pxj-36jq.json | 36 +++++++++++++++ .../GHSA-5c9h-pc39-3279.json | 36 +++++++++++++++ .../GHSA-5ff8-37w8-2jph.json | 36 +++++++++++++++ .../GHSA-5qv9-7j62-hvqq.json | 36 +++++++++++++++ .../GHSA-5v38-qwvm-8jhv.json | 36 +++++++++++++++ .../GHSA-669h-5888-vp43.json | 36 +++++++++++++++ .../GHSA-699f-fqcg-x2vf.json | 36 +++++++++++++++ .../GHSA-6hmw-2vcp-mxf9.json | 36 +++++++++++++++ .../GHSA-6m3r-6p95-cx92.json | 36 +++++++++++++++ .../GHSA-6p9c-5j69-47jm.json | 36 +++++++++++++++ .../GHSA-6v8q-2724-vv58.json | 36 +++++++++++++++ .../GHSA-6vgf-7pw4-vmph.json | 36 +++++++++++++++ .../GHSA-7wqp-3xf5-h8mf.json | 36 +++++++++++++++ .../GHSA-7ww3-mjf8-v82h.json | 36 +++++++++++++++ .../GHSA-7x99-jm5f-5472.json | 36 +++++++++++++++ .../GHSA-7xxq-9j5v-x7hq.json | 36 +++++++++++++++ .../GHSA-82p8-58px-g6rr.json | 36 +++++++++++++++ .../GHSA-83x4-f67m-mqvw.json | 36 +++++++++++++++ .../GHSA-85qr-39r5-6h8c.json | 36 +++++++++++++++ .../GHSA-8php-j6f4-5qhg.json | 36 +++++++++++++++ .../GHSA-8wxr-c457-gcq8.json | 36 +++++++++++++++ .../GHSA-8x27-9ppr-w79j.json | 36 +++++++++++++++ .../GHSA-8xjv-x6f3-c657.json | 36 +++++++++++++++ .../GHSA-93hc-5gpj-x985.json | 36 +++++++++++++++ .../GHSA-94w6-49r3-prpm.json | 36 +++++++++++++++ .../GHSA-96xg-hj8w-5xr8.json | 36 +++++++++++++++ .../GHSA-9f3f-82x4-gxf9.json | 36 +++++++++++++++ .../GHSA-9hm6-g26q-qh84.json | 36 +++++++++++++++ .../GHSA-9jwh-pfj5-h7hr.json | 36 +++++++++++++++ .../GHSA-9m56-6w89-v45r.json | 36 +++++++++++++++ .../GHSA-9q67-2qv9-58wx.json | 36 +++++++++++++++ .../GHSA-9qc9-qw5g-vjpm.json | 36 +++++++++++++++ .../GHSA-9wx2-g8v2-jrwf.json | 36 +++++++++++++++ .../GHSA-c3q2-mqcc-5vxq.json | 36 +++++++++++++++ .../GHSA-cppc-vw44-3c23.json | 36 +++++++++++++++ .../GHSA-cprp-8vph-m966.json | 36 +++++++++++++++ .../GHSA-cr9g-52ff-5jw4.json | 36 +++++++++++++++ .../GHSA-cr9r-c79q-wqpc.json | 36 +++++++++++++++ .../GHSA-f3m6-3fcq-hc6g.json | 36 +++++++++++++++ .../GHSA-f5cw-29xj-j3h4.json | 36 +++++++++++++++ .../GHSA-f74w-gwxh-h727.json | 36 +++++++++++++++ .../GHSA-fc9w-qrr3-v8w6.json | 36 +++++++++++++++ .../GHSA-fcvf-xxvp-wfjq.json | 36 +++++++++++++++ .../GHSA-ff9r-wcrm-93mr.json | 36 +++++++++++++++ .../GHSA-fj43-p45h-jjgv.json | 44 +++++++++++++++++++ .../GHSA-fjxv-xh69-8464.json | 36 +++++++++++++++ .../GHSA-fv3p-4w3p-jq53.json | 36 +++++++++++++++ .../GHSA-fvv3-vwv4-69v2.json | 36 +++++++++++++++ .../GHSA-g6w8-pv3p-8h85.json | 36 +++++++++++++++ .../GHSA-gfrv-p43m-p2pq.json | 36 +++++++++++++++ .../GHSA-ghjh-3qvr-5wrj.json | 36 +++++++++++++++ .../GHSA-gqxf-qwch-9qfr.json | 36 +++++++++++++++ .../GHSA-grh2-c3rj-hgjx.json | 4 +- .../GHSA-h35h-f387-6vv4.json | 36 +++++++++++++++ .../GHSA-h79p-q4h8-6f5c.json | 36 +++++++++++++++ .../GHSA-hgr2-xwxx-38c3.json | 36 +++++++++++++++ .../GHSA-hh9x-fw93-3j6m.json | 36 +++++++++++++++ .../GHSA-hhmc-jqg9-6g36.json | 36 +++++++++++++++ .../GHSA-hm4x-gf27-qm48.json | 36 +++++++++++++++ .../GHSA-hpr9-p3c2-3m3r.json | 36 +++++++++++++++ .../GHSA-hq27-4gq8-rhhp.json | 36 +++++++++++++++ .../GHSA-hrqf-jvhq-wj2m.json | 36 +++++++++++++++ .../GHSA-hv73-qpqh-gh2w.json | 36 +++++++++++++++ .../GHSA-hv86-vh68-5p67.json | 36 +++++++++++++++ .../GHSA-hvr4-fqgg-4q98.json | 36 +++++++++++++++ .../GHSA-hx56-ccjh-7r85.json | 36 +++++++++++++++ .../GHSA-hx8v-hf96-5hm3.json | 36 +++++++++++++++ .../GHSA-hxcq-fj5p-qg8j.json | 36 +++++++++++++++ .../GHSA-hxp7-4wmp-43rf.json | 36 +++++++++++++++ .../GHSA-j53q-396g-fx48.json | 36 +++++++++++++++ .../GHSA-j5pm-8x2c-24p8.json | 36 +++++++++++++++ .../GHSA-j677-qp5q-rgqf.json | 36 +++++++++++++++ .../GHSA-j6j4-v396-g256.json | 36 +++++++++++++++ .../GHSA-j7jg-rhfm-99f8.json | 36 +++++++++++++++ .../GHSA-j7mr-v9j7-qqm8.json | 36 +++++++++++++++ .../GHSA-j85p-xcpr-h6f2.json | 36 +++++++++++++++ .../GHSA-jf49-xxxc-fhh5.json | 36 +++++++++++++++ .../GHSA-jhx5-m34v-c9rc.json | 36 +++++++++++++++ .../GHSA-jj2v-p635-c948.json | 36 +++++++++++++++ .../GHSA-jjr3-gwjc-24jj.json | 36 +++++++++++++++ .../GHSA-jmjv-7fjg-3vrm.json | 36 +++++++++++++++ .../GHSA-jp2x-7x8q-9jf5.json | 36 +++++++++++++++ .../GHSA-jpvv-qg86-wxw9.json | 36 +++++++++++++++ .../GHSA-jqcw-gv2p-8m5p.json | 36 +++++++++++++++ .../GHSA-jqm6-8ggx-r3ww.json | 40 +++++++++++++++++ .../GHSA-jx5j-v6j9-5q5q.json | 36 +++++++++++++++ .../GHSA-m9hq-fp7j-vgxr.json | 36 +++++++++++++++ .../GHSA-mq6j-52vj-xjq9.json | 36 +++++++++++++++ .../GHSA-p66p-rjjv-9f55.json | 36 +++++++++++++++ .../GHSA-pc4g-h6r6-mq33.json | 36 +++++++++++++++ .../GHSA-pfrf-6qh2-mph6.json | 36 +++++++++++++++ .../GHSA-pmfj-879m-mx7q.json | 36 +++++++++++++++ .../GHSA-pp4h-3vh8-rwrw.json | 36 +++++++++++++++ .../GHSA-pqqp-mv53-62cg.json | 36 +++++++++++++++ .../GHSA-pr82-x8qh-vhp8.json | 36 +++++++++++++++ .../GHSA-pwcq-rwgx-7jcr.json | 36 +++++++++++++++ .../GHSA-q43v-qff8-phm7.json | 36 +++++++++++++++ .../GHSA-q7w8-q2f9-vcmh.json | 40 +++++++++++++++++ .../GHSA-q8c9-hmjx-mh95.json | 36 +++++++++++++++ .../GHSA-qg4m-5hg4-34vq.json | 40 +++++++++++++++++ .../GHSA-qwp8-6r9q-pcjh.json | 36 +++++++++++++++ .../GHSA-r6q3-vp6w-xwf9.json | 36 +++++++++++++++ .../GHSA-r6rh-92mr-9w5v.json | 36 +++++++++++++++ .../GHSA-r8c3-g64c-cw4x.json | 36 +++++++++++++++ .../GHSA-rfpj-c27v-frw8.json | 36 +++++++++++++++ .../GHSA-rfwh-qxvm-5m8j.json | 36 +++++++++++++++ .../GHSA-rjwp-c3f6-mgx5.json | 36 +++++++++++++++ .../GHSA-rq8c-97x5-hqj8.json | 36 +++++++++++++++ .../GHSA-rvj4-hc6m-x437.json | 36 +++++++++++++++ .../GHSA-rvvc-q877-7v49.json | 36 +++++++++++++++ .../GHSA-v4pv-c84v-rvfr.json | 36 +++++++++++++++ .../GHSA-v58q-54f6-f82p.json | 36 +++++++++++++++ .../GHSA-v6vq-mcjw-3qrm.json | 36 +++++++++++++++ .../GHSA-v9w8-xh9q-mp2j.json | 36 +++++++++++++++ .../GHSA-vc7v-xwv2-3v83.json | 36 +++++++++++++++ .../GHSA-vccg-pg4r-fjxh.json | 36 +++++++++++++++ .../GHSA-vcpj-fj22-xw8g.json | 36 +++++++++++++++ .../GHSA-vf46-6rcc-3xxx.json | 36 +++++++++++++++ .../GHSA-vhfr-93vm-g72f.json | 36 +++++++++++++++ .../GHSA-vj7p-3w85-844j.json | 36 +++++++++++++++ .../GHSA-vm7w-2724-5m23.json | 11 +++-- .../GHSA-vm9x-4m38-wvhh.json | 36 +++++++++++++++ .../GHSA-vv57-g9wj-p22r.json | 36 +++++++++++++++ .../GHSA-vw87-rmj6-m6r2.json | 36 +++++++++++++++ .../GHSA-vwf4-2m5x-hmqh.json | 36 +++++++++++++++ .../GHSA-vx54-pfx3-h7c9.json | 36 +++++++++++++++ .../GHSA-w362-6935-wmpr.json | 36 +++++++++++++++ .../GHSA-w43w-pw8h-qxgc.json | 36 +++++++++++++++ .../GHSA-w57q-c2cj-vh4c.json | 36 +++++++++++++++ .../GHSA-w5q2-9cxh-qfcp.json | 36 +++++++++++++++ .../GHSA-w5v4-r62p-wm2c.json | 36 +++++++++++++++ .../GHSA-wgrw-gjpf-rw8c.json | 36 +++++++++++++++ .../GHSA-wgxw-qpwc-vh83.json | 36 +++++++++++++++ .../GHSA-wh75-9866-4mjr.json | 36 +++++++++++++++ .../GHSA-wjwq-xqq9-qhcr.json | 36 +++++++++++++++ .../GHSA-wm36-6qmm-fvr8.json | 36 +++++++++++++++ .../GHSA-wp7c-8g73-37mm.json | 36 +++++++++++++++ .../GHSA-wqcw-wh9g-67rg.json | 11 +++-- .../GHSA-x3hp-xj99-8chx.json | 36 +++++++++++++++ .../GHSA-x3hv-g95w-vv54.json | 36 +++++++++++++++ .../GHSA-x42p-xqqx-2f33.json | 36 +++++++++++++++ .../GHSA-x5w2-q3rj-2cpp.json | 36 +++++++++++++++ .../GHSA-x637-7g3v-9gfj.json | 36 +++++++++++++++ .../GHSA-x87r-h8fj-gvgf.json | 36 +++++++++++++++ .../GHSA-xf59-wfpq-q69c.json | 36 +++++++++++++++ .../GHSA-xfmq-9fj2-xhq6.json | 36 +++++++++++++++ .../GHSA-xgv7-g262-2p9p.json | 36 +++++++++++++++ .../GHSA-xh6j-pwvm-gcgm.json | 36 +++++++++++++++ .../GHSA-xp69-fprf-g2x6.json | 36 +++++++++++++++ .../GHSA-xp77-7ppq-j5jg.json | 36 +++++++++++++++ .../GHSA-xpcx-qq6q-cr7f.json | 36 +++++++++++++++ .../GHSA-xq8m-cj64-vrmm.json | 36 +++++++++++++++ .../GHSA-xr9c-3v5w-98m9.json | 36 +++++++++++++++ .../GHSA-xxc4-h4cm-j5r2.json | 40 +++++++++++++++++ 192 files changed, 6724 insertions(+), 11 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-2267-x99j-hcv3/GHSA-2267-x99j-hcv3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-248v-wwj6-r5j3/GHSA-248v-wwj6-r5j3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-24wm-5x58-mcgj/GHSA-24wm-5x58-mcgj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-26rw-w7w7-gjpm/GHSA-26rw-w7w7-gjpm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2739-vvgg-6rwf/GHSA-2739-vvgg-6rwf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-29p9-2mj3-cp4j/GHSA-29p9-2mj3-cp4j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2ghq-fx5m-357p/GHSA-2ghq-fx5m-357p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2jwv-3p8q-v273/GHSA-2jwv-3p8q-v273.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2pfp-372c-3936/GHSA-2pfp-372c-3936.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2pmg-cj35-7j9h/GHSA-2pmg-cj35-7j9h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2r4h-53cp-fff4/GHSA-2r4h-53cp-fff4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2w7h-g4qr-jpgp/GHSA-2w7h-g4qr-jpgp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2wmq-9w92-6xx4/GHSA-2wmq-9w92-6xx4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-349h-vrrw-f3cp/GHSA-349h-vrrw-f3cp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3542-jvch-wmhr/GHSA-3542-jvch-wmhr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-383x-g2c2-mfm5/GHSA-383x-g2c2-mfm5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3gfg-8wp8-c6wx/GHSA-3gfg-8wp8-c6wx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3hw8-vgvf-843g/GHSA-3hw8-vgvf-843g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3jcv-phqx-p74w/GHSA-3jcv-phqx-p74w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3mf9-w9xg-qcf8/GHSA-3mf9-w9xg-qcf8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3pj7-9q5p-c6ww/GHSA-3pj7-9q5p-c6ww.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3q4v-7rf3-mxgq/GHSA-3q4v-7rf3-mxgq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-47fm-3mhp-7p4x/GHSA-47fm-3mhp-7p4x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-487p-v6x9-cqw2/GHSA-487p-v6x9-cqw2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-493v-hhpj-94x4/GHSA-493v-hhpj-94x4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4c75-259h-2625/GHSA-4c75-259h-2625.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4fw9-4m74-7p58/GHSA-4fw9-4m74-7p58.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4hv4-5v49-7fwm/GHSA-4hv4-5v49-7fwm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4pw8-2cvg-fr56/GHSA-4pw8-2cvg-fr56.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4rg5-q2f4-87rx/GHSA-4rg5-q2f4-87rx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5534-8425-cj8p/GHSA-5534-8425-cj8p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-55xj-pjqm-cpfm/GHSA-55xj-pjqm-cpfm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-57fr-4f8x-2f8w/GHSA-57fr-4f8x-2f8w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-57j9-569f-rrxf/GHSA-57j9-569f-rrxf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-589j-7pxj-36jq/GHSA-589j-7pxj-36jq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5c9h-pc39-3279/GHSA-5c9h-pc39-3279.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5ff8-37w8-2jph/GHSA-5ff8-37w8-2jph.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5qv9-7j62-hvqq/GHSA-5qv9-7j62-hvqq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5v38-qwvm-8jhv/GHSA-5v38-qwvm-8jhv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-669h-5888-vp43/GHSA-669h-5888-vp43.json create mode 100644 advisories/unreviewed/2025/03/GHSA-699f-fqcg-x2vf/GHSA-699f-fqcg-x2vf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6hmw-2vcp-mxf9/GHSA-6hmw-2vcp-mxf9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6m3r-6p95-cx92/GHSA-6m3r-6p95-cx92.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6p9c-5j69-47jm/GHSA-6p9c-5j69-47jm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6v8q-2724-vv58/GHSA-6v8q-2724-vv58.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6vgf-7pw4-vmph/GHSA-6vgf-7pw4-vmph.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7wqp-3xf5-h8mf/GHSA-7wqp-3xf5-h8mf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7ww3-mjf8-v82h/GHSA-7ww3-mjf8-v82h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7x99-jm5f-5472/GHSA-7x99-jm5f-5472.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7xxq-9j5v-x7hq/GHSA-7xxq-9j5v-x7hq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-82p8-58px-g6rr/GHSA-82p8-58px-g6rr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-83x4-f67m-mqvw/GHSA-83x4-f67m-mqvw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-85qr-39r5-6h8c/GHSA-85qr-39r5-6h8c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8php-j6f4-5qhg/GHSA-8php-j6f4-5qhg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8wxr-c457-gcq8/GHSA-8wxr-c457-gcq8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8x27-9ppr-w79j/GHSA-8x27-9ppr-w79j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8xjv-x6f3-c657/GHSA-8xjv-x6f3-c657.json create mode 100644 advisories/unreviewed/2025/03/GHSA-93hc-5gpj-x985/GHSA-93hc-5gpj-x985.json create mode 100644 advisories/unreviewed/2025/03/GHSA-94w6-49r3-prpm/GHSA-94w6-49r3-prpm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-96xg-hj8w-5xr8/GHSA-96xg-hj8w-5xr8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9f3f-82x4-gxf9/GHSA-9f3f-82x4-gxf9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9hm6-g26q-qh84/GHSA-9hm6-g26q-qh84.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9jwh-pfj5-h7hr/GHSA-9jwh-pfj5-h7hr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9m56-6w89-v45r/GHSA-9m56-6w89-v45r.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9q67-2qv9-58wx/GHSA-9q67-2qv9-58wx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9qc9-qw5g-vjpm/GHSA-9qc9-qw5g-vjpm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9wx2-g8v2-jrwf/GHSA-9wx2-g8v2-jrwf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c3q2-mqcc-5vxq/GHSA-c3q2-mqcc-5vxq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cppc-vw44-3c23/GHSA-cppc-vw44-3c23.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cprp-8vph-m966/GHSA-cprp-8vph-m966.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cr9g-52ff-5jw4/GHSA-cr9g-52ff-5jw4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cr9r-c79q-wqpc/GHSA-cr9r-c79q-wqpc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f3m6-3fcq-hc6g/GHSA-f3m6-3fcq-hc6g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f5cw-29xj-j3h4/GHSA-f5cw-29xj-j3h4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f74w-gwxh-h727/GHSA-f74w-gwxh-h727.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fc9w-qrr3-v8w6/GHSA-fc9w-qrr3-v8w6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fcvf-xxvp-wfjq/GHSA-fcvf-xxvp-wfjq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-ff9r-wcrm-93mr/GHSA-ff9r-wcrm-93mr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fj43-p45h-jjgv/GHSA-fj43-p45h-jjgv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fjxv-xh69-8464/GHSA-fjxv-xh69-8464.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fv3p-4w3p-jq53/GHSA-fv3p-4w3p-jq53.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fvv3-vwv4-69v2/GHSA-fvv3-vwv4-69v2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g6w8-pv3p-8h85/GHSA-g6w8-pv3p-8h85.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gfrv-p43m-p2pq/GHSA-gfrv-p43m-p2pq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-ghjh-3qvr-5wrj/GHSA-ghjh-3qvr-5wrj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gqxf-qwch-9qfr/GHSA-gqxf-qwch-9qfr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h35h-f387-6vv4/GHSA-h35h-f387-6vv4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h79p-q4h8-6f5c/GHSA-h79p-q4h8-6f5c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hgr2-xwxx-38c3/GHSA-hgr2-xwxx-38c3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hh9x-fw93-3j6m/GHSA-hh9x-fw93-3j6m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hhmc-jqg9-6g36/GHSA-hhmc-jqg9-6g36.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hm4x-gf27-qm48/GHSA-hm4x-gf27-qm48.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hpr9-p3c2-3m3r/GHSA-hpr9-p3c2-3m3r.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hq27-4gq8-rhhp/GHSA-hq27-4gq8-rhhp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hrqf-jvhq-wj2m/GHSA-hrqf-jvhq-wj2m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hv73-qpqh-gh2w/GHSA-hv73-qpqh-gh2w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hv86-vh68-5p67/GHSA-hv86-vh68-5p67.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hvr4-fqgg-4q98/GHSA-hvr4-fqgg-4q98.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hx56-ccjh-7r85/GHSA-hx56-ccjh-7r85.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hx8v-hf96-5hm3/GHSA-hx8v-hf96-5hm3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hxcq-fj5p-qg8j/GHSA-hxcq-fj5p-qg8j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hxp7-4wmp-43rf/GHSA-hxp7-4wmp-43rf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j53q-396g-fx48/GHSA-j53q-396g-fx48.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j5pm-8x2c-24p8/GHSA-j5pm-8x2c-24p8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j677-qp5q-rgqf/GHSA-j677-qp5q-rgqf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j6j4-v396-g256/GHSA-j6j4-v396-g256.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j7jg-rhfm-99f8/GHSA-j7jg-rhfm-99f8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j7mr-v9j7-qqm8/GHSA-j7mr-v9j7-qqm8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j85p-xcpr-h6f2/GHSA-j85p-xcpr-h6f2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jf49-xxxc-fhh5/GHSA-jf49-xxxc-fhh5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jhx5-m34v-c9rc/GHSA-jhx5-m34v-c9rc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jj2v-p635-c948/GHSA-jj2v-p635-c948.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jjr3-gwjc-24jj/GHSA-jjr3-gwjc-24jj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jmjv-7fjg-3vrm/GHSA-jmjv-7fjg-3vrm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jp2x-7x8q-9jf5/GHSA-jp2x-7x8q-9jf5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jpvv-qg86-wxw9/GHSA-jpvv-qg86-wxw9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jqcw-gv2p-8m5p/GHSA-jqcw-gv2p-8m5p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jqm6-8ggx-r3ww/GHSA-jqm6-8ggx-r3ww.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jx5j-v6j9-5q5q/GHSA-jx5j-v6j9-5q5q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m9hq-fp7j-vgxr/GHSA-m9hq-fp7j-vgxr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mq6j-52vj-xjq9/GHSA-mq6j-52vj-xjq9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p66p-rjjv-9f55/GHSA-p66p-rjjv-9f55.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pc4g-h6r6-mq33/GHSA-pc4g-h6r6-mq33.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pfrf-6qh2-mph6/GHSA-pfrf-6qh2-mph6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pmfj-879m-mx7q/GHSA-pmfj-879m-mx7q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pp4h-3vh8-rwrw/GHSA-pp4h-3vh8-rwrw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pqqp-mv53-62cg/GHSA-pqqp-mv53-62cg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pr82-x8qh-vhp8/GHSA-pr82-x8qh-vhp8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pwcq-rwgx-7jcr/GHSA-pwcq-rwgx-7jcr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q43v-qff8-phm7/GHSA-q43v-qff8-phm7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q7w8-q2f9-vcmh/GHSA-q7w8-q2f9-vcmh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q8c9-hmjx-mh95/GHSA-q8c9-hmjx-mh95.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qg4m-5hg4-34vq/GHSA-qg4m-5hg4-34vq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qwp8-6r9q-pcjh/GHSA-qwp8-6r9q-pcjh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r6q3-vp6w-xwf9/GHSA-r6q3-vp6w-xwf9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r6rh-92mr-9w5v/GHSA-r6rh-92mr-9w5v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r8c3-g64c-cw4x/GHSA-r8c3-g64c-cw4x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rfpj-c27v-frw8/GHSA-rfpj-c27v-frw8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rfwh-qxvm-5m8j/GHSA-rfwh-qxvm-5m8j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rjwp-c3f6-mgx5/GHSA-rjwp-c3f6-mgx5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rq8c-97x5-hqj8/GHSA-rq8c-97x5-hqj8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rvj4-hc6m-x437/GHSA-rvj4-hc6m-x437.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rvvc-q877-7v49/GHSA-rvvc-q877-7v49.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v4pv-c84v-rvfr/GHSA-v4pv-c84v-rvfr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v58q-54f6-f82p/GHSA-v58q-54f6-f82p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v6vq-mcjw-3qrm/GHSA-v6vq-mcjw-3qrm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v9w8-xh9q-mp2j/GHSA-v9w8-xh9q-mp2j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vc7v-xwv2-3v83/GHSA-vc7v-xwv2-3v83.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vccg-pg4r-fjxh/GHSA-vccg-pg4r-fjxh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vcpj-fj22-xw8g/GHSA-vcpj-fj22-xw8g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vf46-6rcc-3xxx/GHSA-vf46-6rcc-3xxx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vhfr-93vm-g72f/GHSA-vhfr-93vm-g72f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vj7p-3w85-844j/GHSA-vj7p-3w85-844j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vm9x-4m38-wvhh/GHSA-vm9x-4m38-wvhh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vv57-g9wj-p22r/GHSA-vv57-g9wj-p22r.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vw87-rmj6-m6r2/GHSA-vw87-rmj6-m6r2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vwf4-2m5x-hmqh/GHSA-vwf4-2m5x-hmqh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vx54-pfx3-h7c9/GHSA-vx54-pfx3-h7c9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w362-6935-wmpr/GHSA-w362-6935-wmpr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w43w-pw8h-qxgc/GHSA-w43w-pw8h-qxgc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w57q-c2cj-vh4c/GHSA-w57q-c2cj-vh4c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w5q2-9cxh-qfcp/GHSA-w5q2-9cxh-qfcp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w5v4-r62p-wm2c/GHSA-w5v4-r62p-wm2c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wgrw-gjpf-rw8c/GHSA-wgrw-gjpf-rw8c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wgxw-qpwc-vh83/GHSA-wgxw-qpwc-vh83.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wh75-9866-4mjr/GHSA-wh75-9866-4mjr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wjwq-xqq9-qhcr/GHSA-wjwq-xqq9-qhcr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wm36-6qmm-fvr8/GHSA-wm36-6qmm-fvr8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wp7c-8g73-37mm/GHSA-wp7c-8g73-37mm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x3hp-xj99-8chx/GHSA-x3hp-xj99-8chx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x3hv-g95w-vv54/GHSA-x3hv-g95w-vv54.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x42p-xqqx-2f33/GHSA-x42p-xqqx-2f33.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x5w2-q3rj-2cpp/GHSA-x5w2-q3rj-2cpp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x637-7g3v-9gfj/GHSA-x637-7g3v-9gfj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x87r-h8fj-gvgf/GHSA-x87r-h8fj-gvgf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xf59-wfpq-q69c/GHSA-xf59-wfpq-q69c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xfmq-9fj2-xhq6/GHSA-xfmq-9fj2-xhq6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xgv7-g262-2p9p/GHSA-xgv7-g262-2p9p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xh6j-pwvm-gcgm/GHSA-xh6j-pwvm-gcgm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xp69-fprf-g2x6/GHSA-xp69-fprf-g2x6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xp77-7ppq-j5jg/GHSA-xp77-7ppq-j5jg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xpcx-qq6q-cr7f/GHSA-xpcx-qq6q-cr7f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xq8m-cj64-vrmm/GHSA-xq8m-cj64-vrmm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xr9c-3v5w-98m9/GHSA-xr9c-3v5w-98m9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xxc4-h4cm-j5r2/GHSA-xxc4-h4cm-j5r2.json diff --git a/advisories/github-reviewed/2025/02/GHSA-4fwr-mh5q-hchh/GHSA-4fwr-mh5q-hchh.json b/advisories/github-reviewed/2025/02/GHSA-4fwr-mh5q-hchh/GHSA-4fwr-mh5q-hchh.json index 2e3194ad61d..75ff68908ad 100644 --- a/advisories/github-reviewed/2025/02/GHSA-4fwr-mh5q-hchh/GHSA-4fwr-mh5q-hchh.json +++ b/advisories/github-reviewed/2025/02/GHSA-4fwr-mh5q-hchh/GHSA-4fwr-mh5q-hchh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4fwr-mh5q-hchh", - "modified": "2025-02-27T18:50:25Z", + "modified": "2025-03-03T15:31:24Z", "published": "2025-02-26T18:30:39Z", "aliases": [ "CVE-2025-1634" @@ -114,6 +114,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:1885" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2067" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-1634" diff --git a/advisories/github-reviewed/2025/02/GHSA-phg3-gv66-q38x/GHSA-phg3-gv66-q38x.json b/advisories/github-reviewed/2025/02/GHSA-phg3-gv66-q38x/GHSA-phg3-gv66-q38x.json index 3b2fdf580cc..f41b708a933 100644 --- a/advisories/github-reviewed/2025/02/GHSA-phg3-gv66-q38x/GHSA-phg3-gv66-q38x.json +++ b/advisories/github-reviewed/2025/02/GHSA-phg3-gv66-q38x/GHSA-phg3-gv66-q38x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-phg3-gv66-q38x", - "modified": "2025-02-28T17:19:59Z", + "modified": "2025-03-03T15:31:24Z", "published": "2025-02-13T15:31:25Z", "aliases": [ "CVE-2025-1247" @@ -159,6 +159,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:1885" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2067" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-1247" diff --git a/advisories/unreviewed/2024/10/GHSA-w22f-vwwp-37pr/GHSA-w22f-vwwp-37pr.json b/advisories/unreviewed/2024/10/GHSA-w22f-vwwp-37pr/GHSA-w22f-vwwp-37pr.json index 8709b89c193..4c8fa347bed 100644 --- a/advisories/unreviewed/2024/10/GHSA-w22f-vwwp-37pr/GHSA-w22f-vwwp-37pr.json +++ b/advisories/unreviewed/2024/10/GHSA-w22f-vwwp-37pr/GHSA-w22f-vwwp-37pr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w22f-vwwp-37pr", - "modified": "2025-03-03T12:30:31Z", + "modified": "2025-03-03T15:31:24Z", "published": "2024-10-22T18:32:11Z", "aliases": [ "CVE-2024-10234" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2026" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2029" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-10234" diff --git a/advisories/unreviewed/2025/02/GHSA-fp9w-9x2r-74qr/GHSA-fp9w-9x2r-74qr.json b/advisories/unreviewed/2025/02/GHSA-fp9w-9x2r-74qr/GHSA-fp9w-9x2r-74qr.json index 4a1de02785c..8aa47c7bf82 100644 --- a/advisories/unreviewed/2025/02/GHSA-fp9w-9x2r-74qr/GHSA-fp9w-9x2r-74qr.json +++ b/advisories/unreviewed/2025/02/GHSA-fp9w-9x2r-74qr/GHSA-fp9w-9x2r-74qr.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-2267-x99j-hcv3/GHSA-2267-x99j-hcv3.json b/advisories/unreviewed/2025/03/GHSA-2267-x99j-hcv3/GHSA-2267-x99j-hcv3.json new file mode 100644 index 00000000000..41777c87984 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2267-x99j-hcv3/GHSA-2267-x99j-hcv3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2267-x99j-hcv3", + "modified": "2025-03-03T15:31:34Z", + "published": "2025-03-03T15:31:34Z", + "aliases": [ + "CVE-2025-27270" + ], + "details": "Missing Authorization vulnerability in NotFound Residential Address Detection allows Privilege Escalation. This issue affects Residential Address Detection: from n/a through 2.5.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27270" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/residential-address-detection/vulnerability/wordpress-residential-address-detection-plugin-2-5-4-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-248v-wwj6-r5j3/GHSA-248v-wwj6-r5j3.json b/advisories/unreviewed/2025/03/GHSA-248v-wwj6-r5j3/GHSA-248v-wwj6-r5j3.json new file mode 100644 index 00000000000..6ca8a7f81b3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-248v-wwj6-r5j3/GHSA-248v-wwj6-r5j3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-248v-wwj6-r5j3", + "modified": "2025-03-03T15:31:31Z", + "published": "2025-03-03T15:31:31Z", + "aliases": [ + "CVE-2025-25114" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ehabstar User Role allows Reflected XSS. This issue affects User Role: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25114" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/user-roles/vulnerability/wordpress-easy-wp-tiles-plugin-1-cross-site-scripting-xss-vulnerability-6?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-24wm-5x58-mcgj/GHSA-24wm-5x58-mcgj.json b/advisories/unreviewed/2025/03/GHSA-24wm-5x58-mcgj/GHSA-24wm-5x58-mcgj.json new file mode 100644 index 00000000000..a508661d395 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-24wm-5x58-mcgj/GHSA-24wm-5x58-mcgj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24wm-5x58-mcgj", + "modified": "2025-03-03T15:31:33Z", + "published": "2025-03-03T15:31:33Z", + "aliases": [ + "CVE-2025-26984" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozy Vision SMS Alert Order Notifications – WooCommerce allows Reflected XSS. This issue affects SMS Alert Order Notifications – WooCommerce: from n/a through 3.7.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26984" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sms-alert/vulnerability/wordpress-sms-alert-order-notifications-woocommerce-plugin-3-7-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-26rw-w7w7-gjpm/GHSA-26rw-w7w7-gjpm.json b/advisories/unreviewed/2025/03/GHSA-26rw-w7w7-gjpm/GHSA-26rw-w7w7-gjpm.json new file mode 100644 index 00000000000..527a7e536ac --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-26rw-w7w7-gjpm/GHSA-26rw-w7w7-gjpm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26rw-w7w7-gjpm", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23579" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound DZS Ajaxer Lite allows Stored XSS. This issue affects DZS Ajaxer Lite: from n/a through 1.04.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23579" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dzs-ajaxer-lite-dynamic-page-load/vulnerability/wordpress-dzs-ajaxer-lite-plugin-1-04-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2739-vvgg-6rwf/GHSA-2739-vvgg-6rwf.json b/advisories/unreviewed/2025/03/GHSA-2739-vvgg-6rwf/GHSA-2739-vvgg-6rwf.json new file mode 100644 index 00000000000..5515a8e3cc7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2739-vvgg-6rwf/GHSA-2739-vvgg-6rwf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2739-vvgg-6rwf", + "modified": "2025-03-03T15:31:26Z", + "published": "2025-03-03T15:31:26Z", + "aliases": [ + "CVE-2025-23439" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in willshouse TinyMCE Extended Config allows Reflected XSS. This issue affects TinyMCE Extended Config: from n/a through 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23439" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tinymce-extended-config/vulnerability/wordpress-tinymce-extended-config-plugin-0-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-29p9-2mj3-cp4j/GHSA-29p9-2mj3-cp4j.json b/advisories/unreviewed/2025/03/GHSA-29p9-2mj3-cp4j/GHSA-29p9-2mj3-cp4j.json new file mode 100644 index 00000000000..91109edc90e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-29p9-2mj3-cp4j/GHSA-29p9-2mj3-cp4j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29p9-2mj3-cp4j", + "modified": "2025-03-03T15:31:31Z", + "published": "2025-03-03T15:31:31Z", + "aliases": [ + "CVE-2025-25112" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Social Links allows Blind SQL Injection. This issue affects Social Links: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25112" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/social-links/vulnerability/wordpress-links-in-captions-plugin-1-2-stored-cross-site-scripting-xss-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2ghq-fx5m-357p/GHSA-2ghq-fx5m-357p.json b/advisories/unreviewed/2025/03/GHSA-2ghq-fx5m-357p/GHSA-2ghq-fx5m-357p.json new file mode 100644 index 00000000000..c2c1d94ad7f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2ghq-fx5m-357p/GHSA-2ghq-fx5m-357p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2ghq-fx5m-357p", + "modified": "2025-03-03T15:31:26Z", + "published": "2025-03-03T15:31:26Z", + "aliases": [ + "CVE-2024-47092" + ], + "details": "Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47092" + }, + { + "type": "WEB", + "url": "https://github.com/HeinleinSupport/check_mk_extensions/commit/b5a2a7529e3367d7a643e66f05da4f2a27013904" + }, + { + "type": "WEB", + "url": "https://exchange.checkmk.com/p/check-mk-api" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2jwv-3p8q-v273/GHSA-2jwv-3p8q-v273.json b/advisories/unreviewed/2025/03/GHSA-2jwv-3p8q-v273/GHSA-2jwv-3p8q-v273.json new file mode 100644 index 00000000000..021a51b7bed --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2jwv-3p8q-v273/GHSA-2jwv-3p8q-v273.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jwv-3p8q-v273", + "modified": "2025-03-03T15:31:29Z", + "published": "2025-03-03T15:31:29Z", + "aliases": [ + "CVE-2025-23615" + ], + "details": "Missing Authorization vulnerability in NotFound Interactive Page Hierarchy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Interactive Page Hierarchy: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23615" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/interactive-page-hierarchy/vulnerability/wordpress-interactive-page-hierarchy-plugin-1-0-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2pfp-372c-3936/GHSA-2pfp-372c-3936.json b/advisories/unreviewed/2025/03/GHSA-2pfp-372c-3936/GHSA-2pfp-372c-3936.json new file mode 100644 index 00000000000..9e6dad6902d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2pfp-372c-3936/GHSA-2pfp-372c-3936.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pfp-372c-3936", + "modified": "2025-03-03T15:31:30Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-23813" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Guten Free Options allows Reflected XSS. This issue affects Guten Free Options: from n/a through 0.9.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23813" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/guten-free-options/vulnerability/wordpress-guten-free-options-plugin-0-9-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2pmg-cj35-7j9h/GHSA-2pmg-cj35-7j9h.json b/advisories/unreviewed/2025/03/GHSA-2pmg-cj35-7j9h/GHSA-2pmg-cj35-7j9h.json new file mode 100644 index 00000000000..e053bd26a18 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2pmg-cj35-7j9h/GHSA-2pmg-cj35-7j9h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pmg-cj35-7j9h", + "modified": "2025-03-03T15:31:34Z", + "published": "2025-03-03T15:31:34Z", + "aliases": [ + "CVE-2025-27263" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Doctor Appointment Booking allows SQL Injection. This issue affects Doctor Appointment Booking: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27263" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/doctor-appointment-booking/vulnerability/wordpress-doctor-appointment-booking-plugin-1-0-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2r4h-53cp-fff4/GHSA-2r4h-53cp-fff4.json b/advisories/unreviewed/2025/03/GHSA-2r4h-53cp-fff4/GHSA-2r4h-53cp-fff4.json new file mode 100644 index 00000000000..e11ace2e290 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2r4h-53cp-fff4/GHSA-2r4h-53cp-fff4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2r4h-53cp-fff4", + "modified": "2025-03-03T15:31:34Z", + "published": "2025-03-03T15:31:34Z", + "aliases": [ + "CVE-2025-27264" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound Doctor Appointment Booking allows PHP Local File Inclusion. This issue affects Doctor Appointment Booking: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27264" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/doctor-appointment-booking/vulnerability/wordpress-doctor-appointment-booking-plugin-1-0-0-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2w7h-g4qr-jpgp/GHSA-2w7h-g4qr-jpgp.json b/advisories/unreviewed/2025/03/GHSA-2w7h-g4qr-jpgp/GHSA-2w7h-g4qr-jpgp.json new file mode 100644 index 00000000000..5de2858a0cd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2w7h-g4qr-jpgp/GHSA-2w7h-g4qr-jpgp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w7h-g4qr-jpgp", + "modified": "2025-03-03T15:31:33Z", + "published": "2025-03-03T15:31:33Z", + "aliases": [ + "CVE-2025-26563" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Mobile allows Reflected XSS. This issue affects Mobile: from n/a through 1.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26563" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rocket-wp-mobile/vulnerability/wordpress-rocket-mobile-plugin-0-4-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2wmq-9w92-6xx4/GHSA-2wmq-9w92-6xx4.json b/advisories/unreviewed/2025/03/GHSA-2wmq-9w92-6xx4/GHSA-2wmq-9w92-6xx4.json new file mode 100644 index 00000000000..a8e3b67db9f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2wmq-9w92-6xx4/GHSA-2wmq-9w92-6xx4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wmq-9w92-6xx4", + "modified": "2025-03-03T15:31:32Z", + "published": "2025-03-03T15:31:32Z", + "aliases": [ + "CVE-2025-25132" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ravi Singh Visitor Details allows Stored XSS. This issue affects Visitor Details: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25132" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/visitors-details/vulnerability/wordpress-visitor-details-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-349h-vrrw-f3cp/GHSA-349h-vrrw-f3cp.json b/advisories/unreviewed/2025/03/GHSA-349h-vrrw-f3cp/GHSA-349h-vrrw-f3cp.json new file mode 100644 index 00000000000..4c346c58e7a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-349h-vrrw-f3cp/GHSA-349h-vrrw-f3cp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-349h-vrrw-f3cp", + "modified": "2025-03-03T15:31:25Z", + "published": "2025-03-03T15:31:25Z", + "aliases": [ + "CVE-2024-54179" + ], + "details": "IBM Business Automation Workflow and IBM Business Automation Workflow Enterprise Service Bus 24.0.0, 24.0.1 and earlier unsupported versions are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54179" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7184647" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3542-jvch-wmhr/GHSA-3542-jvch-wmhr.json b/advisories/unreviewed/2025/03/GHSA-3542-jvch-wmhr/GHSA-3542-jvch-wmhr.json new file mode 100644 index 00000000000..687c3d244d4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3542-jvch-wmhr/GHSA-3542-jvch-wmhr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3542-jvch-wmhr", + "modified": "2025-03-03T15:31:33Z", + "published": "2025-03-03T15:31:33Z", + "aliases": [ + "CVE-2025-26970" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound Ark Theme Core allows Code Injection. This issue affects Ark Theme Core: from n/a through 1.70.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26970" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ark-core/vulnerability/wordpress-ark-theme-core-plugin-1-70-0-unauthenticated-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-383x-g2c2-mfm5/GHSA-383x-g2c2-mfm5.json b/advisories/unreviewed/2025/03/GHSA-383x-g2c2-mfm5/GHSA-383x-g2c2-mfm5.json new file mode 100644 index 00000000000..4294db1bfde --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-383x-g2c2-mfm5/GHSA-383x-g2c2-mfm5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-383x-g2c2-mfm5", + "modified": "2025-03-03T15:31:31Z", + "published": "2025-03-03T15:31:31Z", + "aliases": [ + "CVE-2025-25102" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Yahoo BOSS allows Reflected XSS. This issue affects Yahoo BOSS: from n/a through 0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25102" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/yahoo-boss/vulnerability/wordpress-yahoo-boss-plugin-0-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3gfg-8wp8-c6wx/GHSA-3gfg-8wp8-c6wx.json b/advisories/unreviewed/2025/03/GHSA-3gfg-8wp8-c6wx/GHSA-3gfg-8wp8-c6wx.json new file mode 100644 index 00000000000..5119b804044 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3gfg-8wp8-c6wx/GHSA-3gfg-8wp8-c6wx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gfg-8wp8-c6wx", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23539" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Awesome Hooks allows Reflected XSS. This issue affects Awesome Hooks: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23539" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/awesome-hooks/vulnerability/wordpress-awesome-hooks-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3hw8-vgvf-843g/GHSA-3hw8-vgvf-843g.json b/advisories/unreviewed/2025/03/GHSA-3hw8-vgvf-843g/GHSA-3hw8-vgvf-843g.json new file mode 100644 index 00000000000..16d9d88447a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3hw8-vgvf-843g/GHSA-3hw8-vgvf-843g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hw8-vgvf-843g", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23576" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Intro.JS allows Reflected XSS. This issue affects WP Intro.JS: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23576" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-intro-js-tours/vulnerability/wordpress-wp-intro-js-plugin-plugin-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3jcv-phqx-p74w/GHSA-3jcv-phqx-p74w.json b/advisories/unreviewed/2025/03/GHSA-3jcv-phqx-p74w/GHSA-3jcv-phqx-p74w.json new file mode 100644 index 00000000000..f4ec3a62b2e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3jcv-phqx-p74w/GHSA-3jcv-phqx-p74w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jcv-phqx-p74w", + "modified": "2025-03-03T15:31:34Z", + "published": "2025-03-03T15:31:34Z", + "aliases": [ + "CVE-2025-27275" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andrew_fisher WOO Codice Fiscale allows Reflected XSS. This issue affects WOO Codice Fiscale: from n/a through 1.6.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27275" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-codice-fiscale/vulnerability/wordpress-woo-codice-fiscale-plugin-1-6-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3mf9-w9xg-qcf8/GHSA-3mf9-w9xg-qcf8.json b/advisories/unreviewed/2025/03/GHSA-3mf9-w9xg-qcf8/GHSA-3mf9-w9xg-qcf8.json new file mode 100644 index 00000000000..2952fa3e4ba --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3mf9-w9xg-qcf8/GHSA-3mf9-w9xg-qcf8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mf9-w9xg-qcf8", + "modified": "2025-03-03T15:31:27Z", + "published": "2025-03-03T15:31:27Z", + "aliases": [ + "CVE-2025-23518" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound GoogleMapper allows Reflected XSS. This issue affects GoogleMapper: from n/a through 2.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23518" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/googlemapper-2/vulnerability/wordpress-googlemapper-plugin-2-0-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3pj7-9q5p-c6ww/GHSA-3pj7-9q5p-c6ww.json b/advisories/unreviewed/2025/03/GHSA-3pj7-9q5p-c6ww/GHSA-3pj7-9q5p-c6ww.json new file mode 100644 index 00000000000..6e62852782c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3pj7-9q5p-c6ww/GHSA-3pj7-9q5p-c6ww.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pj7-9q5p-c6ww", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23552" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Texteller allows Reflected XSS. This issue affects Texteller: from n/a through 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23552" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/texteller/vulnerability/wordpress-texteller-plugin-1-3-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3q4v-7rf3-mxgq/GHSA-3q4v-7rf3-mxgq.json b/advisories/unreviewed/2025/03/GHSA-3q4v-7rf3-mxgq/GHSA-3q4v-7rf3-mxgq.json new file mode 100644 index 00000000000..1fc697505ae --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3q4v-7rf3-mxgq/GHSA-3q4v-7rf3-mxgq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q4v-7rf3-mxgq", + "modified": "2025-03-03T15:31:34Z", + "published": "2025-03-03T15:31:34Z", + "aliases": [ + "CVE-2025-27274" + ], + "details": "Path Traversal vulnerability in NotFound GPX Viewer allows Path Traversal. This issue affects GPX Viewer: from n/a through 2.2.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27274" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gpx-viewer/vulnerability/wordpress-gpx-viewer-plugin-2-2-11-path-traversal-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-47fm-3mhp-7p4x/GHSA-47fm-3mhp-7p4x.json b/advisories/unreviewed/2025/03/GHSA-47fm-3mhp-7p4x/GHSA-47fm-3mhp-7p4x.json new file mode 100644 index 00000000000..e67ad213de3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-47fm-3mhp-7p4x/GHSA-47fm-3mhp-7p4x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47fm-3mhp-7p4x", + "modified": "2025-03-03T15:31:30Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-23762" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound DsgnWrks Twitter Importer allows Reflected XSS. This issue affects DsgnWrks Twitter Importer: from n/a through 1.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23762" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dsgnwrks-twitter-importer/vulnerability/wordpress-dsgnwrks-twitter-importer-plugin-1-1-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-487p-v6x9-cqw2/GHSA-487p-v6x9-cqw2.json b/advisories/unreviewed/2025/03/GHSA-487p-v6x9-cqw2/GHSA-487p-v6x9-cqw2.json new file mode 100644 index 00000000000..b550dacbd08 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-487p-v6x9-cqw2/GHSA-487p-v6x9-cqw2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-487p-v6x9-cqw2", + "modified": "2025-03-03T15:31:27Z", + "published": "2025-03-03T15:31:27Z", + "aliases": [ + "CVE-2025-23493" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Google Transliteration allows Reflected XSS. This issue affects Google Transliteration: from n/a through 1.7.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23493" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/google-transliteration/vulnerability/wordpress-google-transliteration-plugin-1-7-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-493v-hhpj-94x4/GHSA-493v-hhpj-94x4.json b/advisories/unreviewed/2025/03/GHSA-493v-hhpj-94x4/GHSA-493v-hhpj-94x4.json new file mode 100644 index 00000000000..8a8a3740ef3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-493v-hhpj-94x4/GHSA-493v-hhpj-94x4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-493v-hhpj-94x4", + "modified": "2025-03-03T15:31:29Z", + "published": "2025-03-03T15:31:29Z", + "aliases": [ + "CVE-2025-23595" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Page Health-O-Meter allows Reflected XSS. This issue affects Page Health-O-Meter: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23595" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/page-health-o-meter/vulnerability/wordpress-page-health-o-meter-plugin-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4c75-259h-2625/GHSA-4c75-259h-2625.json b/advisories/unreviewed/2025/03/GHSA-4c75-259h-2625/GHSA-4c75-259h-2625.json new file mode 100644 index 00000000000..dfb8a16d1de --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4c75-259h-2625/GHSA-4c75-259h-2625.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c75-259h-2625", + "modified": "2025-03-03T15:31:26Z", + "published": "2025-03-03T15:31:26Z", + "aliases": [ + "CVE-2025-23441" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Attach Gallery Posts allows Reflected XSS. This issue affects Attach Gallery Posts: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23441" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/attach-gallery-posts/vulnerability/wordpress-attach-gallery-posts-plugin-1-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4fw9-4m74-7p58/GHSA-4fw9-4m74-7p58.json b/advisories/unreviewed/2025/03/GHSA-4fw9-4m74-7p58/GHSA-4fw9-4m74-7p58.json new file mode 100644 index 00000000000..f0178eeed15 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4fw9-4m74-7p58/GHSA-4fw9-4m74-7p58.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fw9-4m74-7p58", + "modified": "2025-03-03T15:31:30Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-23847" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Site Launcher allows Reflected XSS. This issue affects Site Launcher: from n/a through 0.9.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23847" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/site-launcher/vulnerability/wordpress-site-launcher-plugin-0-9-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4hv4-5v49-7fwm/GHSA-4hv4-5v49-7fwm.json b/advisories/unreviewed/2025/03/GHSA-4hv4-5v49-7fwm/GHSA-4hv4-5v49-7fwm.json new file mode 100644 index 00000000000..404794c4157 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4hv4-5v49-7fwm/GHSA-4hv4-5v49-7fwm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hv4-5v49-7fwm", + "modified": "2025-03-03T15:31:30Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-23753" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound DN Sitemap Control allows Reflected XSS. This issue affects DN Sitemap Control: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23753" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dn-sitemap-control/vulnerability/wordpress-dn-sitemap-control-plugin-1-0-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4pw8-2cvg-fr56/GHSA-4pw8-2cvg-fr56.json b/advisories/unreviewed/2025/03/GHSA-4pw8-2cvg-fr56/GHSA-4pw8-2cvg-fr56.json new file mode 100644 index 00000000000..e514c4bd173 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4pw8-2cvg-fr56/GHSA-4pw8-2cvg-fr56.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pw8-2cvg-fr56", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23585" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CantonBolo Goo.gl Url Shorter allows Reflected XSS. This issue affects Goo.gl Url Shorter: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23585" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/googl-url-shorter/vulnerability/wordpress-goo-gl-url-shorter-plugin-1-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4rg5-q2f4-87rx/GHSA-4rg5-q2f4-87rx.json b/advisories/unreviewed/2025/03/GHSA-4rg5-q2f4-87rx/GHSA-4rg5-q2f4-87rx.json new file mode 100644 index 00000000000..a4ebba8aba2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4rg5-q2f4-87rx/GHSA-4rg5-q2f4-87rx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rg5-q2f4-87rx", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23570" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Social Links allows Reflected XSS. This issue affects WP Social Links: from n/a through 0.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23570" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-social-links/vulnerability/wordpress-wp-social-links-plugin-0-3-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5534-8425-cj8p/GHSA-5534-8425-cj8p.json b/advisories/unreviewed/2025/03/GHSA-5534-8425-cj8p/GHSA-5534-8425-cj8p.json new file mode 100644 index 00000000000..b03eb577ac3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5534-8425-cj8p/GHSA-5534-8425-cj8p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5534-8425-cj8p", + "modified": "2025-03-03T15:31:26Z", + "published": "2025-03-03T15:31:26Z", + "aliases": [ + "CVE-2025-23478" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Photo Video Store allows Reflected XSS. This issue affects Photo Video Store: from n/a through 21.07.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23478" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/photo-video-store/vulnerability/wordpress-photo-video-store-plugin-21-07-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-55xj-pjqm-cpfm/GHSA-55xj-pjqm-cpfm.json b/advisories/unreviewed/2025/03/GHSA-55xj-pjqm-cpfm/GHSA-55xj-pjqm-cpfm.json new file mode 100644 index 00000000000..c73ec6a37c9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-55xj-pjqm-cpfm/GHSA-55xj-pjqm-cpfm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55xj-pjqm-cpfm", + "modified": "2025-03-03T15:31:29Z", + "published": "2025-03-03T15:31:29Z", + "aliases": [ + "CVE-2025-23637" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound 新淘客WordPress插件 allows Reflected XSS. This issue affects 新淘客WordPress插件: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23637" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-xintaoke/vulnerability/wordpress-wordpress-plugin-1-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-57fr-4f8x-2f8w/GHSA-57fr-4f8x-2f8w.json b/advisories/unreviewed/2025/03/GHSA-57fr-4f8x-2f8w/GHSA-57fr-4f8x-2f8w.json new file mode 100644 index 00000000000..bffbc4c968e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-57fr-4f8x-2f8w/GHSA-57fr-4f8x-2f8w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57fr-4f8x-2f8w", + "modified": "2025-03-03T15:31:26Z", + "published": "2025-03-03T15:31:26Z", + "aliases": [ + "CVE-2025-23433" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jnwry vcOS allows Reflected XSS. This issue affects vcOS: from n/a through 1.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23433" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/vcos/vulnerability/wordpress-vcos-plugin-1-4-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-57j9-569f-rrxf/GHSA-57j9-569f-rrxf.json b/advisories/unreviewed/2025/03/GHSA-57j9-569f-rrxf/GHSA-57j9-569f-rrxf.json new file mode 100644 index 00000000000..cd204b82406 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-57j9-569f-rrxf/GHSA-57j9-569f-rrxf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57j9-569f-rrxf", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:27Z", + "aliases": [ + "CVE-2025-23519" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound G Web Pro Store Locator allows Reflected XSS. This issue affects G Web Pro Store Locator: from n/a through 2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23519" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gwebpro-store-locator/vulnerability/wordpress-g-web-pro-store-locator-plugin-2-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-589j-7pxj-36jq/GHSA-589j-7pxj-36jq.json b/advisories/unreviewed/2025/03/GHSA-589j-7pxj-36jq/GHSA-589j-7pxj-36jq.json new file mode 100644 index 00000000000..838dc4f5f57 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-589j-7pxj-36jq/GHSA-589j-7pxj-36jq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-589j-7pxj-36jq", + "modified": "2025-03-03T15:31:32Z", + "published": "2025-03-03T15:31:32Z", + "aliases": [ + "CVE-2025-25142" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Less Compiler allows Stored XSS. This issue affects WP Less Compiler: from n/a through 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25142" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-less-compiler/vulnerability/wordpress-wp-less-compiler-plugin-1-3-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5c9h-pc39-3279/GHSA-5c9h-pc39-3279.json b/advisories/unreviewed/2025/03/GHSA-5c9h-pc39-3279/GHSA-5c9h-pc39-3279.json new file mode 100644 index 00000000000..08148b3a43f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5c9h-pc39-3279/GHSA-5c9h-pc39-3279.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c9h-pc39-3279", + "modified": "2025-03-03T15:31:32Z", + "published": "2025-03-03T15:31:32Z", + "aliases": [ + "CVE-2025-25137" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Social Links allows Stored XSS. This issue affects Social Links: from n/a through 1.0.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25137" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/social-links/vulnerability/wordpress-facilita-form-tracker-plugin-1-0-csrf-to-stored-xss-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5ff8-37w8-2jph/GHSA-5ff8-37w8-2jph.json b/advisories/unreviewed/2025/03/GHSA-5ff8-37w8-2jph/GHSA-5ff8-37w8-2jph.json new file mode 100644 index 00000000000..0eb046fb0c4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5ff8-37w8-2jph/GHSA-5ff8-37w8-2jph.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5ff8-37w8-2jph", + "modified": "2025-03-03T15:31:32Z", + "published": "2025-03-03T15:31:32Z", + "aliases": [ + "CVE-2025-25161" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Find Your Nearest allows Reflected XSS. This issue affects WP Find Your Nearest: from n/a through 0.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25161" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-find-your-nearest/vulnerability/wordpress-globalquran-plugin-1-0-csrf-to-settings-change-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5qv9-7j62-hvqq/GHSA-5qv9-7j62-hvqq.json b/advisories/unreviewed/2025/03/GHSA-5qv9-7j62-hvqq/GHSA-5qv9-7j62-hvqq.json new file mode 100644 index 00000000000..ee80f9d250b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5qv9-7j62-hvqq/GHSA-5qv9-7j62-hvqq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qv9-7j62-hvqq", + "modified": "2025-03-03T15:31:27Z", + "published": "2025-03-03T15:31:27Z", + "aliases": [ + "CVE-2025-23473" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Killer Theme Options allows Reflected XSS. This issue affects Killer Theme Options: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23473" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/killer-theme-options/vulnerability/wordpress-killer-theme-options-plugin-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5v38-qwvm-8jhv/GHSA-5v38-qwvm-8jhv.json b/advisories/unreviewed/2025/03/GHSA-5v38-qwvm-8jhv/GHSA-5v38-qwvm-8jhv.json new file mode 100644 index 00000000000..1b9e149e4d8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5v38-qwvm-8jhv/GHSA-5v38-qwvm-8jhv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v38-qwvm-8jhv", + "modified": "2025-03-03T15:31:31Z", + "published": "2025-03-03T15:31:31Z", + "aliases": [ + "CVE-2025-25109" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound WP Vehicle Manager allows PHP Local File Inclusion. This issue affects WP Vehicle Manager: from n/a through 3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25109" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/js-vehicle-manager/vulnerability/wordpress-embed-rss-plugin-3-1-arbitrary-shortcode-execution-vulnerability-3?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-669h-5888-vp43/GHSA-669h-5888-vp43.json b/advisories/unreviewed/2025/03/GHSA-669h-5888-vp43/GHSA-669h-5888-vp43.json new file mode 100644 index 00000000000..7d6b41e758c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-669h-5888-vp43/GHSA-669h-5888-vp43.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-669h-5888-vp43", + "modified": "2025-03-03T15:31:27Z", + "published": "2025-03-03T15:31:27Z", + "aliases": [ + "CVE-2025-23505" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Pit Login Welcome allows Reflected XSS. This issue affects Pit Login Welcome: from n/a through 1.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23505" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pit-login-welcome/vulnerability/wordpress-pit-login-welcome-plugin-1-1-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-699f-fqcg-x2vf/GHSA-699f-fqcg-x2vf.json b/advisories/unreviewed/2025/03/GHSA-699f-fqcg-x2vf/GHSA-699f-fqcg-x2vf.json new file mode 100644 index 00000000000..6eda63c6106 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-699f-fqcg-x2vf/GHSA-699f-fqcg-x2vf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-699f-fqcg-x2vf", + "modified": "2025-03-03T15:31:27Z", + "published": "2025-03-03T15:31:27Z", + "aliases": [ + "CVE-2025-23517" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Google Map on Post/Page allows Reflected XSS. This issue affects Google Map on Post/Page: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23517" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/google-map-on-postpage/vulnerability/wordpress-google-map-on-post-page-plugin-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6hmw-2vcp-mxf9/GHSA-6hmw-2vcp-mxf9.json b/advisories/unreviewed/2025/03/GHSA-6hmw-2vcp-mxf9/GHSA-6hmw-2vcp-mxf9.json new file mode 100644 index 00000000000..9632271e291 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6hmw-2vcp-mxf9/GHSA-6hmw-2vcp-mxf9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hmw-2vcp-mxf9", + "modified": "2025-03-03T15:31:32Z", + "published": "2025-03-03T15:31:32Z", + "aliases": [ + "CVE-2025-25150" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix uListing allows Blind SQL Injection. This issue affects uListing: from n/a through 2.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25150" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ulisting/vulnerability/wordpress-songkick-concerts-and-festivals-plugin-0-9-7-cross-site-request-forgery-csrf-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6m3r-6p95-cx92/GHSA-6m3r-6p95-cx92.json b/advisories/unreviewed/2025/03/GHSA-6m3r-6p95-cx92/GHSA-6m3r-6p95-cx92.json new file mode 100644 index 00000000000..da43f50dd73 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6m3r-6p95-cx92/GHSA-6m3r-6p95-cx92.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m3r-6p95-cx92", + "modified": "2025-03-03T15:31:26Z", + "published": "2025-03-03T15:31:26Z", + "aliases": [ + "CVE-2025-23446" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in NotFound WP SpaceContent allows Stored XSS. This issue affects WP SpaceContent: from n/a through 0.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23446" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-spacecontent/vulnerability/wordpress-wp-spacecontent-plugin-0-4-5-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6p9c-5j69-47jm/GHSA-6p9c-5j69-47jm.json b/advisories/unreviewed/2025/03/GHSA-6p9c-5j69-47jm/GHSA-6p9c-5j69-47jm.json new file mode 100644 index 00000000000..3c6f0da3034 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6p9c-5j69-47jm/GHSA-6p9c-5j69-47jm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p9c-5j69-47jm", + "modified": "2025-03-03T15:31:27Z", + "published": "2025-03-03T15:31:27Z", + "aliases": [ + "CVE-2025-23479" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound melascrivi allows Reflected XSS. This issue affects melascrivi: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23479" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/melascrivi/vulnerability/wordpress-melascrivi-plugin-1-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6v8q-2724-vv58/GHSA-6v8q-2724-vv58.json b/advisories/unreviewed/2025/03/GHSA-6v8q-2724-vv58/GHSA-6v8q-2724-vv58.json new file mode 100644 index 00000000000..b4c8f7c7048 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6v8q-2724-vv58/GHSA-6v8q-2724-vv58.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v8q-2724-vv58", + "modified": "2025-03-03T15:31:32Z", + "published": "2025-03-03T15:31:32Z", + "aliases": [ + "CVE-2025-25158" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Uncomplicated SEO allows Reflected XSS. This issue affects Uncomplicated SEO: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25158" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/uncomplicated-seo/vulnerability/wordpress-uncomplicated-seo-plugin-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6vgf-7pw4-vmph/GHSA-6vgf-7pw4-vmph.json b/advisories/unreviewed/2025/03/GHSA-6vgf-7pw4-vmph/GHSA-6vgf-7pw4-vmph.json new file mode 100644 index 00000000000..de50b2b2af7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6vgf-7pw4-vmph/GHSA-6vgf-7pw4-vmph.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vgf-7pw4-vmph", + "modified": "2025-03-03T15:31:33Z", + "published": "2025-03-03T15:31:33Z", + "aliases": [ + "CVE-2025-26989" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in softdiscover Zigaform – Form Builder Lite allows Stored XSS. This issue affects Zigaform – Form Builder Lite: from n/a through 7.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26989" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/zigaform-form-builder-lite/vulnerability/wordpress-zigaform-form-builder-lite-plugin-7-4-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7wqp-3xf5-h8mf/GHSA-7wqp-3xf5-h8mf.json b/advisories/unreviewed/2025/03/GHSA-7wqp-3xf5-h8mf/GHSA-7wqp-3xf5-h8mf.json new file mode 100644 index 00000000000..6209746cde2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7wqp-3xf5-h8mf/GHSA-7wqp-3xf5-h8mf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wqp-3xf5-h8mf", + "modified": "2025-03-03T15:31:30Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-23956" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Easy Post Mailer allows Reflected XSS. This issue affects WP Easy Post Mailer: from n/a through 0.64.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23956" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-mailer/vulnerability/wordpress-wp-easy-post-mailer-plugin-0-64-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7ww3-mjf8-v82h/GHSA-7ww3-mjf8-v82h.json b/advisories/unreviewed/2025/03/GHSA-7ww3-mjf8-v82h/GHSA-7ww3-mjf8-v82h.json new file mode 100644 index 00000000000..45d5e606558 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7ww3-mjf8-v82h/GHSA-7ww3-mjf8-v82h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7ww3-mjf8-v82h", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23553" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Cramer Userbase Access Control allows Reflected XSS. This issue affects Userbase Access Control: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23553" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/userbase-access-control/vulnerability/wordpress-userbase-access-control-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7x99-jm5f-5472/GHSA-7x99-jm5f-5472.json b/advisories/unreviewed/2025/03/GHSA-7x99-jm5f-5472/GHSA-7x99-jm5f-5472.json new file mode 100644 index 00000000000..dccb06ad4af --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7x99-jm5f-5472/GHSA-7x99-jm5f-5472.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x99-jm5f-5472", + "modified": "2025-03-03T15:31:32Z", + "published": "2025-03-03T15:31:32Z", + "aliases": [ + "CVE-2025-25122" + ], + "details": "Path Traversal vulnerability in NotFound WizShop allows PHP Local File Inclusion. This issue affects WizShop: from n/a through 3.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25122" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wizshop/vulnerability/wordpress-wp-spell-check-plugin-9-21-cross-site-request-forgery-csrf-vulnerability-4?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7xxq-9j5v-x7hq/GHSA-7xxq-9j5v-x7hq.json b/advisories/unreviewed/2025/03/GHSA-7xxq-9j5v-x7hq/GHSA-7xxq-9j5v-x7hq.json new file mode 100644 index 00000000000..7dd95b4ddaa --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7xxq-9j5v-x7hq/GHSA-7xxq-9j5v-x7hq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xxq-9j5v-x7hq", + "modified": "2025-03-03T15:31:29Z", + "published": "2025-03-03T15:31:29Z", + "aliases": [ + "CVE-2025-23731" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in infosoftplugin Tax Report for WooCommerce allows Reflected XSS. This issue affects Tax Report for WooCommerce: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23731" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tax-report-for-woocommerce/vulnerability/wordpress-tax-report-for-woocommerce-plugin-2-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-82p8-58px-g6rr/GHSA-82p8-58px-g6rr.json b/advisories/unreviewed/2025/03/GHSA-82p8-58px-g6rr/GHSA-82p8-58px-g6rr.json new file mode 100644 index 00000000000..f87f7470e81 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-82p8-58px-g6rr/GHSA-82p8-58px-g6rr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82p8-58px-g6rr", + "modified": "2025-03-03T15:31:29Z", + "published": "2025-03-03T15:31:29Z", + "aliases": [ + "CVE-2025-23670" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound 4 author cheer up donate allows Reflected XSS. This issue affects 4 author cheer up donate: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23670" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/4-author-cheer-up-donate/vulnerability/wordpress-4-author-cheer-up-donate-plugin-1-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-83x4-f67m-mqvw/GHSA-83x4-f67m-mqvw.json b/advisories/unreviewed/2025/03/GHSA-83x4-f67m-mqvw/GHSA-83x4-f67m-mqvw.json new file mode 100644 index 00000000000..ccdc0f709bd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-83x4-f67m-mqvw/GHSA-83x4-f67m-mqvw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83x4-f67m-mqvw", + "modified": "2025-03-03T15:31:30Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-23741" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Notifications Center allows Reflected XSS. This issue affects Notifications Center: from n/a through 1.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23741" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/notifications-center/vulnerability/wordpress-notifications-center-plugin-1-5-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-85qr-39r5-6h8c/GHSA-85qr-39r5-6h8c.json b/advisories/unreviewed/2025/03/GHSA-85qr-39r5-6h8c/GHSA-85qr-39r5-6h8c.json new file mode 100644 index 00000000000..11cca721a89 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-85qr-39r5-6h8c/GHSA-85qr-39r5-6h8c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85qr-39r5-6h8c", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23555" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Ui Slider Filter By Price allows Reflected XSS. This issue affects Ui Slider Filter By Price: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23555" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ui-slider-filter-by-price/vulnerability/wordpress-ui-slider-filter-by-price-plugin-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8php-j6f4-5qhg/GHSA-8php-j6f4-5qhg.json b/advisories/unreviewed/2025/03/GHSA-8php-j6f4-5qhg/GHSA-8php-j6f4-5qhg.json new file mode 100644 index 00000000000..47768e8c226 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8php-j6f4-5qhg/GHSA-8php-j6f4-5qhg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8php-j6f4-5qhg", + "modified": "2025-03-03T15:31:26Z", + "published": "2025-03-03T15:31:26Z", + "aliases": [ + "CVE-2025-23450" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in agenwebsite AW WooCommerce Kode Pembayaran allows Reflected XSS. This issue affects AW WooCommerce Kode Pembayaran: from n/a through 1.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23450" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/aw-woocommerce-kode-pembayaran/vulnerability/wordpress-aw-woocommerce-kode-pembayaran-plugin-1-1-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8wxr-c457-gcq8/GHSA-8wxr-c457-gcq8.json b/advisories/unreviewed/2025/03/GHSA-8wxr-c457-gcq8/GHSA-8wxr-c457-gcq8.json new file mode 100644 index 00000000000..4b71490022c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8wxr-c457-gcq8/GHSA-8wxr-c457-gcq8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wxr-c457-gcq8", + "modified": "2025-03-03T15:31:27Z", + "published": "2025-03-03T15:31:27Z", + "aliases": [ + "CVE-2025-23490" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Browser-Update-Notify allows Reflected XSS. This issue affects Browser-Update-Notify: from n/a through 0.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23490" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/browser-update-notify/vulnerability/wordpress-browser-update-notify-plugin-0-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8x27-9ppr-w79j/GHSA-8x27-9ppr-w79j.json b/advisories/unreviewed/2025/03/GHSA-8x27-9ppr-w79j/GHSA-8x27-9ppr-w79j.json new file mode 100644 index 00000000000..185d8036cfe --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8x27-9ppr-w79j/GHSA-8x27-9ppr-w79j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x27-9ppr-w79j", + "modified": "2025-03-03T15:31:29Z", + "published": "2025-03-03T15:31:29Z", + "aliases": [ + "CVE-2025-23668" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound ChatGPT Open AI Images & Content for WooCommerce allows Reflected XSS. This issue affects ChatGPT Open AI Images & Content for WooCommerce: from n/a through 2.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23668" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/glasses-for-woocommerce/vulnerability/wordpress-chatgpt-open-ai-images-content-for-woocommerce-plugin-2-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8xjv-x6f3-c657/GHSA-8xjv-x6f3-c657.json b/advisories/unreviewed/2025/03/GHSA-8xjv-x6f3-c657/GHSA-8xjv-x6f3-c657.json new file mode 100644 index 00000000000..a428bd9c6d1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8xjv-x6f3-c657/GHSA-8xjv-x6f3-c657.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xjv-x6f3-c657", + "modified": "2025-03-03T15:31:34Z", + "published": "2025-03-03T15:31:34Z", + "aliases": [ + "CVE-2024-8261" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in Proliz Software OBS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects OBS: before 24.0927.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8261" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-25-0049" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-93hc-5gpj-x985/GHSA-93hc-5gpj-x985.json b/advisories/unreviewed/2025/03/GHSA-93hc-5gpj-x985/GHSA-93hc-5gpj-x985.json new file mode 100644 index 00000000000..0a75c156c32 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-93hc-5gpj-x985/GHSA-93hc-5gpj-x985.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93hc-5gpj-x985", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23549" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Maniac SEO allows Reflected XSS. This issue affects Maniac SEO: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23549" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/maniac-seo/vulnerability/wordpress-maniac-seo-plugin-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-94w6-49r3-prpm/GHSA-94w6-49r3-prpm.json b/advisories/unreviewed/2025/03/GHSA-94w6-49r3-prpm/GHSA-94w6-49r3-prpm.json new file mode 100644 index 00000000000..20007af3fda --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-94w6-49r3-prpm/GHSA-94w6-49r3-prpm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94w6-49r3-prpm", + "modified": "2025-03-03T15:31:31Z", + "published": "2025-03-03T15:31:31Z", + "aliases": [ + "CVE-2025-25092" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gtlwpdev All push notification for WP allows Reflected XSS. This issue affects All push notification for WP: from n/a through 1.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25092" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/all-push-notification/vulnerability/wordpress-easy-wp-tiles-plugin-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-96xg-hj8w-5xr8/GHSA-96xg-hj8w-5xr8.json b/advisories/unreviewed/2025/03/GHSA-96xg-hj8w-5xr8/GHSA-96xg-hj8w-5xr8.json new file mode 100644 index 00000000000..91778ed1fdb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-96xg-hj8w-5xr8/GHSA-96xg-hj8w-5xr8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96xg-hj8w-5xr8", + "modified": "2025-03-03T15:31:30Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-23739" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Ultimate Reviews FREE allows Reflected XSS. This issue affects WP Ultimate Reviews FREE: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23739" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-ultimate-reviews-free/vulnerability/wordpress-wp-ultimate-reviews-free-plugin-1-0-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9f3f-82x4-gxf9/GHSA-9f3f-82x4-gxf9.json b/advisories/unreviewed/2025/03/GHSA-9f3f-82x4-gxf9/GHSA-9f3f-82x4-gxf9.json new file mode 100644 index 00000000000..8a78a721316 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9f3f-82x4-gxf9/GHSA-9f3f-82x4-gxf9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f3f-82x4-gxf9", + "modified": "2025-03-03T15:31:27Z", + "published": "2025-03-03T15:31:27Z", + "aliases": [ + "CVE-2025-23484" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Predict When allows Reflected XSS. This issue affects Predict When: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23484" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/predict-when/vulnerability/wordpress-predict-when-plugin-1-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9hm6-g26q-qh84/GHSA-9hm6-g26q-qh84.json b/advisories/unreviewed/2025/03/GHSA-9hm6-g26q-qh84/GHSA-9hm6-g26q-qh84.json new file mode 100644 index 00000000000..56564f99e3c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9hm6-g26q-qh84/GHSA-9hm6-g26q-qh84.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hm6-g26q-qh84", + "modified": "2025-03-03T15:31:30Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-23852" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound First Comment Redirect allows Reflected XSS. This issue affects First Comment Redirect: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23852" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/first-comment-redirect/vulnerability/wordpress-first-comment-redirect-plugin-1-0-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9jwh-pfj5-h7hr/GHSA-9jwh-pfj5-h7hr.json b/advisories/unreviewed/2025/03/GHSA-9jwh-pfj5-h7hr/GHSA-9jwh-pfj5-h7hr.json new file mode 100644 index 00000000000..5880b1c669c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9jwh-pfj5-h7hr/GHSA-9jwh-pfj5-h7hr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jwh-pfj5-h7hr", + "modified": "2025-03-03T15:31:32Z", + "published": "2025-03-03T15:31:32Z", + "aliases": [ + "CVE-2025-25170" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Migrate Posts allows Reflected XSS. This issue affects Migrate Posts: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25170" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/migrate-post/vulnerability/wordpress-migrate-posts-plugin-1-0-post-based-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9m56-6w89-v45r/GHSA-9m56-6w89-v45r.json b/advisories/unreviewed/2025/03/GHSA-9m56-6w89-v45r/GHSA-9m56-6w89-v45r.json new file mode 100644 index 00000000000..0e559f23255 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9m56-6w89-v45r/GHSA-9m56-6w89-v45r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m56-6w89-v45r", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23524" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound ClickBank Storefront allows Reflected XSS. This issue affects ClickBank Storefront: from n/a through 1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23524" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mycbgenie-clickbank-storefront/vulnerability/wordpress-clickbank-storefront-wordpress-plugin-plugin-1-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9q67-2qv9-58wx/GHSA-9q67-2qv9-58wx.json b/advisories/unreviewed/2025/03/GHSA-9q67-2qv9-58wx/GHSA-9q67-2qv9-58wx.json new file mode 100644 index 00000000000..c47a0baec7d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9q67-2qv9-58wx/GHSA-9q67-2qv9-58wx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q67-2qv9-58wx", + "modified": "2025-03-03T15:31:33Z", + "published": "2025-03-03T15:31:33Z", + "aliases": [ + "CVE-2025-26586" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Events Planner allows Reflected XSS. This issue affects Events Planner: from n/a through 1.3.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26586" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/events-planner/vulnerability/wordpress-events-planner-plugin-1-3-10-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9qc9-qw5g-vjpm/GHSA-9qc9-qw5g-vjpm.json b/advisories/unreviewed/2025/03/GHSA-9qc9-qw5g-vjpm/GHSA-9qc9-qw5g-vjpm.json new file mode 100644 index 00000000000..1e164f0fe82 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9qc9-qw5g-vjpm/GHSA-9qc9-qw5g-vjpm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qc9-qw5g-vjpm", + "modified": "2025-03-03T15:31:25Z", + "published": "2025-03-03T15:31:25Z", + "aliases": [ + "CVE-2025-1875" + ], + "details": "SQL injection vulnerability have been found in 101news affecting version 1.0 through the \"searchtitle\" parameter in search.php.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1875" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-101news" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9wx2-g8v2-jrwf/GHSA-9wx2-g8v2-jrwf.json b/advisories/unreviewed/2025/03/GHSA-9wx2-g8v2-jrwf/GHSA-9wx2-g8v2-jrwf.json new file mode 100644 index 00000000000..e7a9aa8a2cd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9wx2-g8v2-jrwf/GHSA-9wx2-g8v2-jrwf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wx2-g8v2-jrwf", + "modified": "2025-03-03T15:31:32Z", + "published": "2025-03-03T15:31:32Z", + "aliases": [ + "CVE-2025-25118" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Top Bar – PopUps – by WPOptin allows Reflected XSS. This issue affects Top Bar – PopUps – by WPOptin: from n/a through 2.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25118" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpoptin/vulnerability/wordpress-easy-wp-tiles-plugin-1-cross-site-scripting-xss-vulnerability-7?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c3q2-mqcc-5vxq/GHSA-c3q2-mqcc-5vxq.json b/advisories/unreviewed/2025/03/GHSA-c3q2-mqcc-5vxq/GHSA-c3q2-mqcc-5vxq.json new file mode 100644 index 00000000000..07e3143033a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c3q2-mqcc-5vxq/GHSA-c3q2-mqcc-5vxq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3q2-mqcc-5vxq", + "modified": "2025-03-03T15:31:29Z", + "published": "2025-03-03T15:31:29Z", + "aliases": [ + "CVE-2025-23716" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Login Watchdog allows Stored XSS. This issue affects Login Watchdog: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23716" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/login-watchdog/vulnerability/wordpress-login-watchdog-plugin-1-0-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cppc-vw44-3c23/GHSA-cppc-vw44-3c23.json b/advisories/unreviewed/2025/03/GHSA-cppc-vw44-3c23/GHSA-cppc-vw44-3c23.json new file mode 100644 index 00000000000..071ec51b788 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cppc-vw44-3c23/GHSA-cppc-vw44-3c23.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cppc-vw44-3c23", + "modified": "2025-03-03T15:31:30Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-23814" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound CRUDLab Like Box allows Reflected XSS. This issue affects CRUDLab Like Box: from n/a through 2.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23814" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/crudlab-facebook-like-box/vulnerability/wordpress-crudlab-like-box-plugin-2-0-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cprp-8vph-m966/GHSA-cprp-8vph-m966.json b/advisories/unreviewed/2025/03/GHSA-cprp-8vph-m966/GHSA-cprp-8vph-m966.json new file mode 100644 index 00000000000..4db3a17c22d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cprp-8vph-m966/GHSA-cprp-8vph-m966.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cprp-8vph-m966", + "modified": "2025-03-03T15:31:34Z", + "published": "2025-03-03T15:31:34Z", + "aliases": [ + "CVE-2025-27279" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Flashfader allows Reflected XSS. This issue affects Flashfader: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27279" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/flashfader/vulnerability/wordpress-flashfader-plugin-1-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cr9g-52ff-5jw4/GHSA-cr9g-52ff-5jw4.json b/advisories/unreviewed/2025/03/GHSA-cr9g-52ff-5jw4/GHSA-cr9g-52ff-5jw4.json new file mode 100644 index 00000000000..1a76950ca8d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cr9g-52ff-5jw4/GHSA-cr9g-52ff-5jw4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr9g-52ff-5jw4", + "modified": "2025-03-03T15:31:33Z", + "published": "2025-03-03T15:31:33Z", + "aliases": [ + "CVE-2025-26587" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound sidebarTabs allows Reflected XSS. This issue affects sidebarTabs: from n/a through 3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26587" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sidebartabs/vulnerability/wordpress-sidebartabs-plugin-3-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cr9r-c79q-wqpc/GHSA-cr9r-c79q-wqpc.json b/advisories/unreviewed/2025/03/GHSA-cr9r-c79q-wqpc/GHSA-cr9r-c79q-wqpc.json new file mode 100644 index 00000000000..9c019e1d0e7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cr9r-c79q-wqpc/GHSA-cr9r-c79q-wqpc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr9r-c79q-wqpc", + "modified": "2025-03-03T15:31:27Z", + "published": "2025-03-03T15:31:27Z", + "aliases": [ + "CVE-2025-23482" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound azurecurve Floating Featured Image allows Reflected XSS. This issue affects azurecurve Floating Featured Image: from n/a through 2.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23482" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/azurecurve-floating-featured-image/vulnerability/wordpress-azurecurve-floating-featured-image-plugin-2-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f3m6-3fcq-hc6g/GHSA-f3m6-3fcq-hc6g.json b/advisories/unreviewed/2025/03/GHSA-f3m6-3fcq-hc6g/GHSA-f3m6-3fcq-hc6g.json new file mode 100644 index 00000000000..ddd45d78cea --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f3m6-3fcq-hc6g/GHSA-f3m6-3fcq-hc6g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3m6-3fcq-hc6g", + "modified": "2025-03-03T15:31:29Z", + "published": "2025-03-03T15:31:29Z", + "aliases": [ + "CVE-2025-23736" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Form To JSON allows Reflected XSS. This issue affects Form To JSON: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23736" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/form-to-json/vulnerability/wordpress-form-to-json-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f5cw-29xj-j3h4/GHSA-f5cw-29xj-j3h4.json b/advisories/unreviewed/2025/03/GHSA-f5cw-29xj-j3h4/GHSA-f5cw-29xj-j3h4.json new file mode 100644 index 00000000000..46af5b00ebc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f5cw-29xj-j3h4/GHSA-f5cw-29xj-j3h4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5cw-29xj-j3h4", + "modified": "2025-03-03T15:31:33Z", + "published": "2025-03-03T15:31:33Z", + "aliases": [ + "CVE-2025-26917" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes WP Templata allows Reflected XSS. This issue affects WP Templata: from n/a through 1.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26917" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wptemplata/vulnerability/wordpress-wp-templata-plugin-1-0-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f74w-gwxh-h727/GHSA-f74w-gwxh-h727.json b/advisories/unreviewed/2025/03/GHSA-f74w-gwxh-h727/GHSA-f74w-gwxh-h727.json new file mode 100644 index 00000000000..ed4945ca347 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f74w-gwxh-h727/GHSA-f74w-gwxh-h727.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f74w-gwxh-h727", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23587" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound all-in-one-box-login allows Reflected XSS. This issue affects all-in-one-box-login: from n/a through 2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23587" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/all-in-one-login/vulnerability/wordpress-all-in-one-box-login-plugin-2-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fc9w-qrr3-v8w6/GHSA-fc9w-qrr3-v8w6.json b/advisories/unreviewed/2025/03/GHSA-fc9w-qrr3-v8w6/GHSA-fc9w-qrr3-v8w6.json new file mode 100644 index 00000000000..c7e953bf805 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fc9w-qrr3-v8w6/GHSA-fc9w-qrr3-v8w6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc9w-qrr3-v8w6", + "modified": "2025-03-03T15:31:30Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-23883" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Stray Random Quotes allows Reflected XSS. This issue affects Stray Random Quotes: from n/a through 1.9.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23883" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/stray-quotes/vulnerability/wordpress-stray-random-quotes-plugin-1-9-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fcvf-xxvp-wfjq/GHSA-fcvf-xxvp-wfjq.json b/advisories/unreviewed/2025/03/GHSA-fcvf-xxvp-wfjq/GHSA-fcvf-xxvp-wfjq.json new file mode 100644 index 00000000000..34d229820d1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fcvf-xxvp-wfjq/GHSA-fcvf-xxvp-wfjq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcvf-xxvp-wfjq", + "modified": "2025-03-03T15:31:33Z", + "published": "2025-03-03T15:31:33Z", + "aliases": [ + "CVE-2025-26994" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in softdiscover Zigaform – Price Calculator & Cost Estimation Form Builder Lite allows Stored XSS. This issue affects Zigaform – Price Calculator & Cost Estimation Form Builder Lite: from n/a through 7.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26994" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/zigaform-calculator-cost-estimation-form-builder-lite/vulnerability/wordpress-zigaform-price-calculator-cost-estimation-form-builder-lite-plugin-7-4-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-ff9r-wcrm-93mr/GHSA-ff9r-wcrm-93mr.json b/advisories/unreviewed/2025/03/GHSA-ff9r-wcrm-93mr/GHSA-ff9r-wcrm-93mr.json new file mode 100644 index 00000000000..746e16ff9ec --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-ff9r-wcrm-93mr/GHSA-ff9r-wcrm-93mr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ff9r-wcrm-93mr", + "modified": "2025-03-03T15:31:33Z", + "published": "2025-03-03T15:31:33Z", + "aliases": [ + "CVE-2025-26585" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound DL Leadback allows Reflected XSS. This issue affects DL Leadback: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26585" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dl-leadback/vulnerability/wordpress-dl-leadback-plugin-1-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fj43-p45h-jjgv/GHSA-fj43-p45h-jjgv.json b/advisories/unreviewed/2025/03/GHSA-fj43-p45h-jjgv/GHSA-fj43-p45h-jjgv.json new file mode 100644 index 00000000000..ac19d5d7274 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fj43-p45h-jjgv/GHSA-fj43-p45h-jjgv.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj43-p45h-jjgv", + "modified": "2025-03-03T15:31:35Z", + "published": "2025-03-03T15:31:34Z", + "aliases": [ + "CVE-2025-1801" + ], + "details": "A flaw was found in the Ansible aap-gateway. Concurrent requests handled by the gateway grpc service can result in concurrency issues due to race condition requests against the proxy. This issue potentially allows a less privileged user to obtain the JWT of a greater privileged user, enabling the server to be jeopardized. A user session or confidential data might be vulnerable.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1801" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:1954" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-1801" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2349081" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fjxv-xh69-8464/GHSA-fjxv-xh69-8464.json b/advisories/unreviewed/2025/03/GHSA-fjxv-xh69-8464/GHSA-fjxv-xh69-8464.json new file mode 100644 index 00000000000..f8372cb398d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fjxv-xh69-8464/GHSA-fjxv-xh69-8464.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjxv-xh69-8464", + "modified": "2025-03-03T15:31:34Z", + "published": "2025-03-03T15:31:34Z", + "aliases": [ + "CVE-2025-27269" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound .htaccess Login block allows Reflected XSS. This issue affects .htaccess Login block: from n/a through 0.9a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27269" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/htaccess-login-block/vulnerability/wordpress-htaccess-login-block-plugin-0-9a-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fv3p-4w3p-jq53/GHSA-fv3p-4w3p-jq53.json b/advisories/unreviewed/2025/03/GHSA-fv3p-4w3p-jq53/GHSA-fv3p-4w3p-jq53.json new file mode 100644 index 00000000000..aa0bbbdb2f7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fv3p-4w3p-jq53/GHSA-fv3p-4w3p-jq53.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv3p-4w3p-jq53", + "modified": "2025-03-03T15:31:30Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-23903" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Local Shipping Labels for WooCommerce allows Reflected XSS. This issue affects Local Shipping Labels for WooCommerce: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23903" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/local-shipping-labels-for-woocommerce/vulnerability/wordpress-local-shipping-labels-for-woocommerce-plugin-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fvv3-vwv4-69v2/GHSA-fvv3-vwv4-69v2.json b/advisories/unreviewed/2025/03/GHSA-fvv3-vwv4-69v2/GHSA-fvv3-vwv4-69v2.json new file mode 100644 index 00000000000..72c8760ee59 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fvv3-vwv4-69v2/GHSA-fvv3-vwv4-69v2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvv3-vwv4-69v2", + "modified": "2025-03-03T15:31:29Z", + "published": "2025-03-03T15:31:29Z", + "aliases": [ + "CVE-2025-23619" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Catch Duplicate Switcher allows Reflected XSS. This issue affects Catch Duplicate Switcher: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23619" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/catch-duplicate-switcher/vulnerability/wordpress-catch-duplicate-switcher-plugin-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g6w8-pv3p-8h85/GHSA-g6w8-pv3p-8h85.json b/advisories/unreviewed/2025/03/GHSA-g6w8-pv3p-8h85/GHSA-g6w8-pv3p-8h85.json new file mode 100644 index 00000000000..da826f9f5ad --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g6w8-pv3p-8h85/GHSA-g6w8-pv3p-8h85.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6w8-pv3p-8h85", + "modified": "2025-03-03T15:31:30Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-23879" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PillarDev Easy Automatic Newsletter Lite allows Reflected XSS. This issue affects Easy Automatic Newsletter Lite: from n/a through 3.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23879" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-automatic-newsletter/vulnerability/wordpress-easy-automatic-newsletter-lite-plugin-3-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gfrv-p43m-p2pq/GHSA-gfrv-p43m-p2pq.json b/advisories/unreviewed/2025/03/GHSA-gfrv-p43m-p2pq/GHSA-gfrv-p43m-p2pq.json new file mode 100644 index 00000000000..8cb91667b03 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gfrv-p43m-p2pq/GHSA-gfrv-p43m-p2pq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfrv-p43m-p2pq", + "modified": "2025-03-03T15:31:29Z", + "published": "2025-03-03T15:31:29Z", + "aliases": [ + "CVE-2025-23718" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Mancx AskMe Widget allows Reflected XSS. This issue affects Mancx AskMe Widget: from n/a through 0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23718" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mancx-askme-widget/vulnerability/wordpress-mancx-askme-widget-plugin-0-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-ghjh-3qvr-5wrj/GHSA-ghjh-3qvr-5wrj.json b/advisories/unreviewed/2025/03/GHSA-ghjh-3qvr-5wrj/GHSA-ghjh-3qvr-5wrj.json new file mode 100644 index 00000000000..04f3fb0d4a5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-ghjh-3qvr-5wrj/GHSA-ghjh-3qvr-5wrj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghjh-3qvr-5wrj", + "modified": "2025-03-03T15:31:27Z", + "published": "2025-03-03T15:31:27Z", + "aliases": [ + "CVE-2025-23496" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP FPO allows Reflected XSS. This issue affects WP FPO: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23496" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-fpo/vulnerability/wordpress-wp-fpo-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gqxf-qwch-9qfr/GHSA-gqxf-qwch-9qfr.json b/advisories/unreviewed/2025/03/GHSA-gqxf-qwch-9qfr/GHSA-gqxf-qwch-9qfr.json new file mode 100644 index 00000000000..5930118e5fe --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gqxf-qwch-9qfr/GHSA-gqxf-qwch-9qfr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqxf-qwch-9qfr", + "modified": "2025-03-03T15:31:33Z", + "published": "2025-03-03T15:31:33Z", + "aliases": [ + "CVE-2025-26967" + ], + "details": "Deserialization of Untrusted Data vulnerability in Stiofan Events Calendar for GeoDirectory allows Object Injection. This issue affects Events Calendar for GeoDirectory: from n/a through 2.3.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26967" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/events-for-geodirectory/vulnerability/wordpress-events-calendar-for-geodirectory-plugin-2-3-14-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-grh2-c3rj-hgjx/GHSA-grh2-c3rj-hgjx.json b/advisories/unreviewed/2025/03/GHSA-grh2-c3rj-hgjx/GHSA-grh2-c3rj-hgjx.json index b9d1a5db750..b776c712c2f 100644 --- a/advisories/unreviewed/2025/03/GHSA-grh2-c3rj-hgjx/GHSA-grh2-c3rj-hgjx.json +++ b/advisories/unreviewed/2025/03/GHSA-grh2-c3rj-hgjx/GHSA-grh2-c3rj-hgjx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-h35h-f387-6vv4/GHSA-h35h-f387-6vv4.json b/advisories/unreviewed/2025/03/GHSA-h35h-f387-6vv4/GHSA-h35h-f387-6vv4.json new file mode 100644 index 00000000000..c523a0591ab --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h35h-f387-6vv4/GHSA-h35h-f387-6vv4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h35h-f387-6vv4", + "modified": "2025-03-03T15:31:33Z", + "published": "2025-03-03T15:31:33Z", + "aliases": [ + "CVE-2025-26918" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enituretechnology Small Package Quotes – Unishippers Edition allows Reflected XSS. This issue affects Small Package Quotes – Unishippers Edition: from n/a through 2.4.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26918" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/small-package-quotes-unishippers-edition/vulnerability/wordpress-small-package-quotes-unishippers-edition-plugin-2-4-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h79p-q4h8-6f5c/GHSA-h79p-q4h8-6f5c.json b/advisories/unreviewed/2025/03/GHSA-h79p-q4h8-6f5c/GHSA-h79p-q4h8-6f5c.json new file mode 100644 index 00000000000..32e8aa3ffe7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h79p-q4h8-6f5c/GHSA-h79p-q4h8-6f5c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h79p-q4h8-6f5c", + "modified": "2025-03-03T15:31:29Z", + "published": "2025-03-03T15:31:29Z", + "aliases": [ + "CVE-2025-23721" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Mobigate allows Reflected XSS. This issue affects Mobigate: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23721" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mobigatevn/vulnerability/wordpress-mobigate-plugin-1-0-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hgr2-xwxx-38c3/GHSA-hgr2-xwxx-38c3.json b/advisories/unreviewed/2025/03/GHSA-hgr2-xwxx-38c3/GHSA-hgr2-xwxx-38c3.json new file mode 100644 index 00000000000..918350edf48 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hgr2-xwxx-38c3/GHSA-hgr2-xwxx-38c3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgr2-xwxx-38c3", + "modified": "2025-03-03T15:31:31Z", + "published": "2025-03-03T15:31:31Z", + "aliases": [ + "CVE-2025-25087" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound seekXL Snapr allows Reflected XSS. This issue affects seekXL Snapr: from n/a through 2.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25087" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/seekxl-snapr/vulnerability/wordpress-seekxl-snapr-plugin-2-0-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hh9x-fw93-3j6m/GHSA-hh9x-fw93-3j6m.json b/advisories/unreviewed/2025/03/GHSA-hh9x-fw93-3j6m/GHSA-hh9x-fw93-3j6m.json new file mode 100644 index 00000000000..ec488e2fd7d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hh9x-fw93-3j6m/GHSA-hh9x-fw93-3j6m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh9x-fw93-3j6m", + "modified": "2025-03-03T15:31:31Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-24758" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Map Locations allows Reflected XSS. This issue affects CM Map Locations: from n/a through 2.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24758" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cm-map-locations/vulnerability/wordpress-cm-map-locations-plugin-2-0-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hhmc-jqg9-6g36/GHSA-hhmc-jqg9-6g36.json b/advisories/unreviewed/2025/03/GHSA-hhmc-jqg9-6g36/GHSA-hhmc-jqg9-6g36.json new file mode 100644 index 00000000000..2fdcf0071e9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hhmc-jqg9-6g36/GHSA-hhmc-jqg9-6g36.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhmc-jqg9-6g36", + "modified": "2025-03-03T15:31:32Z", + "published": "2025-03-03T15:31:32Z", + "aliases": [ + "CVE-2025-26540" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NotFound Helloprint allows Path Traversal. This issue affects Helloprint: from n/a through 2.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26540" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/helloprint/vulnerability/wordpress-helloprint-plugin-2-0-7-arbitrary-file-deletion-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hm4x-gf27-qm48/GHSA-hm4x-gf27-qm48.json b/advisories/unreviewed/2025/03/GHSA-hm4x-gf27-qm48/GHSA-hm4x-gf27-qm48.json new file mode 100644 index 00000000000..389f31d4a78 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hm4x-gf27-qm48/GHSA-hm4x-gf27-qm48.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hm4x-gf27-qm48", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23586" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Post Category Notifications allows Reflected XSS. This issue affects WP Post Category Notifications: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23586" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-post-category-notifications/vulnerability/wordpress-wp-post-category-notifications-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hpr9-p3c2-3m3r/GHSA-hpr9-p3c2-3m3r.json b/advisories/unreviewed/2025/03/GHSA-hpr9-p3c2-3m3r/GHSA-hpr9-p3c2-3m3r.json new file mode 100644 index 00000000000..c2c0d6b8983 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hpr9-p3c2-3m3r/GHSA-hpr9-p3c2-3m3r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpr9-p3c2-3m3r", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23538" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Contest allows Reflected XSS. This issue affects WP Contest: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23538" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-contest/vulnerability/wordpress-wp-contest-plugin-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hq27-4gq8-rhhp/GHSA-hq27-4gq8-rhhp.json b/advisories/unreviewed/2025/03/GHSA-hq27-4gq8-rhhp/GHSA-hq27-4gq8-rhhp.json new file mode 100644 index 00000000000..410f5a2f818 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hq27-4gq8-rhhp/GHSA-hq27-4gq8-rhhp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hq27-4gq8-rhhp", + "modified": "2025-03-03T15:31:32Z", + "published": "2025-03-03T15:31:32Z", + "aliases": [ + "CVE-2025-25131" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound RJ Quickcharts allows Stored XSS. This issue affects RJ Quickcharts: from n/a through 0.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25131" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rj-quickcharts/vulnerability/wordpress-rj-quickcharts-plugin-0-6-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hrqf-jvhq-wj2m/GHSA-hrqf-jvhq-wj2m.json b/advisories/unreviewed/2025/03/GHSA-hrqf-jvhq-wj2m/GHSA-hrqf-jvhq-wj2m.json new file mode 100644 index 00000000000..499c702f647 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hrqf-jvhq-wj2m/GHSA-hrqf-jvhq-wj2m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrqf-jvhq-wj2m", + "modified": "2025-03-03T15:31:26Z", + "published": "2025-03-03T15:31:26Z", + "aliases": [ + "CVE-2025-23437" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound ntp-header-images allows Reflected XSS. This issue affects ntp-header-images: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23437" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/header-images-rotator/vulnerability/wordpress-ntp-header-images-plugin-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hv73-qpqh-gh2w/GHSA-hv73-qpqh-gh2w.json b/advisories/unreviewed/2025/03/GHSA-hv73-qpqh-gh2w/GHSA-hv73-qpqh-gh2w.json new file mode 100644 index 00000000000..17dcb3d861e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hv73-qpqh-gh2w/GHSA-hv73-qpqh-gh2w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hv73-qpqh-gh2w", + "modified": "2025-03-03T15:31:31Z", + "published": "2025-03-03T15:31:31Z", + "aliases": [ + "CVE-2025-25099" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in accreteinfosolution Appointment Buddy Widget allows Reflected XSS. This issue affects Appointment Buddy Widget: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25099" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/appointment-buddy-online-appointment-booking-by-accrete/vulnerability/wordpress-embed-rss-plugin-3-1-arbitrary-shortcode-execution-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hv86-vh68-5p67/GHSA-hv86-vh68-5p67.json b/advisories/unreviewed/2025/03/GHSA-hv86-vh68-5p67/GHSA-hv86-vh68-5p67.json new file mode 100644 index 00000000000..5f613434667 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hv86-vh68-5p67/GHSA-hv86-vh68-5p67.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hv86-vh68-5p67", + "modified": "2025-03-03T15:31:29Z", + "published": "2025-03-03T15:31:29Z", + "aliases": [ + "CVE-2025-23738" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Ps Ads Pro allows Reflected XSS. This issue affects Ps Ads Pro: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23738" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ps-ads-pro/vulnerability/wordpress-ps-ads-pro-plugin-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hvr4-fqgg-4q98/GHSA-hvr4-fqgg-4q98.json b/advisories/unreviewed/2025/03/GHSA-hvr4-fqgg-4q98/GHSA-hvr4-fqgg-4q98.json new file mode 100644 index 00000000000..41abda2fa99 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hvr4-fqgg-4q98/GHSA-hvr4-fqgg-4q98.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvr4-fqgg-4q98", + "modified": "2025-03-03T15:31:33Z", + "published": "2025-03-03T15:31:33Z", + "aliases": [ + "CVE-2025-26557" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound ViperBar allows Reflected XSS. This issue affects ViperBar: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26557" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/viperbar/vulnerability/wordpress-viperbar-plugin-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hx56-ccjh-7r85/GHSA-hx56-ccjh-7r85.json b/advisories/unreviewed/2025/03/GHSA-hx56-ccjh-7r85/GHSA-hx56-ccjh-7r85.json new file mode 100644 index 00000000000..360269a1920 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hx56-ccjh-7r85/GHSA-hx56-ccjh-7r85.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx56-ccjh-7r85", + "modified": "2025-03-03T15:31:31Z", + "published": "2025-03-03T15:31:31Z", + "aliases": [ + "CVE-2025-24694" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Email Registration Blacklist and Whitelist allows Reflected XSS. This issue affects CM Email Registration Blacklist and Whitelist: from n/a through 1.5.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24694" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cm-email-blacklist/vulnerability/wordpress-name-cm-e-mail-registration-blacklist-plugin-1-5-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hx8v-hf96-5hm3/GHSA-hx8v-hf96-5hm3.json b/advisories/unreviewed/2025/03/GHSA-hx8v-hf96-5hm3/GHSA-hx8v-hf96-5hm3.json new file mode 100644 index 00000000000..c623ecb54c8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hx8v-hf96-5hm3/GHSA-hx8v-hf96-5hm3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx8v-hf96-5hm3", + "modified": "2025-03-03T15:31:30Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-23829" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Woo Update Variations In Cart allows Stored XSS. This issue affects Woo Update Variations In Cart: from n/a through 0.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23829" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-update-variations-in-cart/vulnerability/wordpress-woo-update-variations-in-cart-plugin-0-0-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hxcq-fj5p-qg8j/GHSA-hxcq-fj5p-qg8j.json b/advisories/unreviewed/2025/03/GHSA-hxcq-fj5p-qg8j/GHSA-hxcq-fj5p-qg8j.json new file mode 100644 index 00000000000..627e1dff2c0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hxcq-fj5p-qg8j/GHSA-hxcq-fj5p-qg8j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxcq-fj5p-qg8j", + "modified": "2025-03-03T15:31:33Z", + "published": "2025-03-03T15:31:33Z", + "aliases": [ + "CVE-2025-26879" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cristián Lávaque s2Member Pro allows Reflected XSS. This issue affects s2Member Pro: from n/a through 241216.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26879" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/s2member/vulnerability/wordpress-s2member-plugin-241216-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hxp7-4wmp-43rf/GHSA-hxp7-4wmp-43rf.json b/advisories/unreviewed/2025/03/GHSA-hxp7-4wmp-43rf/GHSA-hxp7-4wmp-43rf.json new file mode 100644 index 00000000000..b61557ea778 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hxp7-4wmp-43rf/GHSA-hxp7-4wmp-43rf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxp7-4wmp-43rf", + "modified": "2025-03-03T15:31:26Z", + "published": "2025-03-03T15:31:26Z", + "aliases": [ + "CVE-2025-23465" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Vampire Character Manager allows Reflected XSS. This issue affects Vampire Character Manager: from n/a through 2.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23465" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/vampire-character/vulnerability/wordpress-vampire-character-manager-plugin-2-13-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j53q-396g-fx48/GHSA-j53q-396g-fx48.json b/advisories/unreviewed/2025/03/GHSA-j53q-396g-fx48/GHSA-j53q-396g-fx48.json new file mode 100644 index 00000000000..b9bbefb2478 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j53q-396g-fx48/GHSA-j53q-396g-fx48.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j53q-396g-fx48", + "modified": "2025-03-03T15:31:33Z", + "published": "2025-03-03T15:31:33Z", + "aliases": [ + "CVE-2025-26885" + ], + "details": "Deserialization of Untrusted Data vulnerability in Brent Jett Assistant allows Object Injection. This issue affects Assistant: from n/a through 1.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26885" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/assistant/vulnerability/wordpress-assistant-plugin-1-5-1-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j5pm-8x2c-24p8/GHSA-j5pm-8x2c-24p8.json b/advisories/unreviewed/2025/03/GHSA-j5pm-8x2c-24p8/GHSA-j5pm-8x2c-24p8.json new file mode 100644 index 00000000000..482000e4ff8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j5pm-8x2c-24p8/GHSA-j5pm-8x2c-24p8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5pm-8x2c-24p8", + "modified": "2025-03-03T15:31:31Z", + "published": "2025-03-03T15:31:31Z", + "aliases": [ + "CVE-2025-25115" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Like dislike plus counter allows Stored XSS. This issue affects Like dislike plus counter: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25115" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/like-dislike-plus-counter/vulnerability/wordpress-easy-wp-tiles-plugin-1-cross-site-scripting-xss-vulnerability-5?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j677-qp5q-rgqf/GHSA-j677-qp5q-rgqf.json b/advisories/unreviewed/2025/03/GHSA-j677-qp5q-rgqf/GHSA-j677-qp5q-rgqf.json new file mode 100644 index 00000000000..75952935f82 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j677-qp5q-rgqf/GHSA-j677-qp5q-rgqf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j677-qp5q-rgqf", + "modified": "2025-03-03T15:31:33Z", + "published": "2025-03-03T15:31:33Z", + "aliases": [ + "CVE-2025-26914" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Variable Inspector allows Reflected XSS. This issue affects Variable Inspector: from n/a through 2.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26914" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/variable-inspector/vulnerability/wordpress-variable-inspector-plugin-2-6-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j6j4-v396-g256/GHSA-j6j4-v396-g256.json b/advisories/unreviewed/2025/03/GHSA-j6j4-v396-g256/GHSA-j6j4-v396-g256.json new file mode 100644 index 00000000000..20d162c366c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j6j4-v396-g256/GHSA-j6j4-v396-g256.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6j4-v396-g256", + "modified": "2025-03-03T15:31:34Z", + "published": "2025-03-03T15:31:34Z", + "aliases": [ + "CVE-2025-27278" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound AcuGIS Leaflet Maps allows Reflected XSS. This issue affects AcuGIS Leaflet Maps: from n/a through 5.1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27278" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mapfig-premium-leaflet-map-maker/vulnerability/wordpress-acugis-leaflet-maps-plugin-5-1-1-0-multiple-cross-site-scripting-xss-vulnerabilities?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j7jg-rhfm-99f8/GHSA-j7jg-rhfm-99f8.json b/advisories/unreviewed/2025/03/GHSA-j7jg-rhfm-99f8/GHSA-j7jg-rhfm-99f8.json new file mode 100644 index 00000000000..70ff949e9cd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j7jg-rhfm-99f8/GHSA-j7jg-rhfm-99f8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7jg-rhfm-99f8", + "modified": "2025-03-03T15:31:29Z", + "published": "2025-03-03T15:31:29Z", + "aliases": [ + "CVE-2025-23613" + ], + "details": "Missing Authorization vulnerability in NotFound WP Journal allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Journal: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23613" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpjournal/vulnerability/wordpress-wp-journal-plugin-1-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j7mr-v9j7-qqm8/GHSA-j7mr-v9j7-qqm8.json b/advisories/unreviewed/2025/03/GHSA-j7mr-v9j7-qqm8/GHSA-j7mr-v9j7-qqm8.json new file mode 100644 index 00000000000..991f98f41ae --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j7mr-v9j7-qqm8/GHSA-j7mr-v9j7-qqm8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7mr-v9j7-qqm8", + "modified": "2025-03-03T15:31:29Z", + "published": "2025-03-03T15:31:29Z", + "aliases": [ + "CVE-2025-23726" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound ComparePress allows Reflected XSS. This issue affects ComparePress: from n/a through 2.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23726" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/comparepress/vulnerability/wordpress-comparepress-plugin-2-0-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j85p-xcpr-h6f2/GHSA-j85p-xcpr-h6f2.json b/advisories/unreviewed/2025/03/GHSA-j85p-xcpr-h6f2/GHSA-j85p-xcpr-h6f2.json new file mode 100644 index 00000000000..500a5190a38 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j85p-xcpr-h6f2/GHSA-j85p-xcpr-h6f2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j85p-xcpr-h6f2", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23564" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mohsenshahbazi WP FixTag allows Reflected XSS. This issue affects WP FixTag: from n/a through v2.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23564" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-fixtag/vulnerability/wordpress-wp-fixtag-plugin-v2-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jf49-xxxc-fhh5/GHSA-jf49-xxxc-fhh5.json b/advisories/unreviewed/2025/03/GHSA-jf49-xxxc-fhh5/GHSA-jf49-xxxc-fhh5.json new file mode 100644 index 00000000000..bf1300e679b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jf49-xxxc-fhh5/GHSA-jf49-xxxc-fhh5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jf49-xxxc-fhh5", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23526" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Swift Calendar Online Appointment Scheduling allows Reflected XSS. This issue affects Swift Calendar Online Appointment Scheduling: from n/a through 1.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23526" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/online-appointment-scheduling-software/vulnerability/wordpress-swift-calendar-online-appointment-scheduling-plugin-1-3-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jhx5-m34v-c9rc/GHSA-jhx5-m34v-c9rc.json b/advisories/unreviewed/2025/03/GHSA-jhx5-m34v-c9rc/GHSA-jhx5-m34v-c9rc.json new file mode 100644 index 00000000000..f6eacdd9635 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jhx5-m34v-c9rc/GHSA-jhx5-m34v-c9rc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhx5-m34v-c9rc", + "modified": "2025-03-03T15:31:30Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-23763" + ], + "details": "Missing Authorization vulnerability in Alex Volkov WAH Forms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WAH Forms: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23763" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wah-forms/vulnerability/wordpress-wah-forms-plugin-1-0-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jj2v-p635-c948/GHSA-jj2v-p635-c948.json b/advisories/unreviewed/2025/03/GHSA-jj2v-p635-c948/GHSA-jj2v-p635-c948.json new file mode 100644 index 00000000000..a87a6ce4cde --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jj2v-p635-c948/GHSA-jj2v-p635-c948.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jj2v-p635-c948", + "modified": "2025-03-03T15:31:27Z", + "published": "2025-03-03T15:31:27Z", + "aliases": [ + "CVE-2025-23520" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SecureSubmit Heartland Management Terminal allows Reflected XSS. This issue affects Heartland Management Terminal: from n/a through 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23520" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/heartland-management-terminal/vulnerability/wordpress-heartland-management-terminal-plugin-1-3-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jjr3-gwjc-24jj/GHSA-jjr3-gwjc-24jj.json b/advisories/unreviewed/2025/03/GHSA-jjr3-gwjc-24jj/GHSA-jjr3-gwjc-24jj.json new file mode 100644 index 00000000000..db3a968ecf6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jjr3-gwjc-24jj/GHSA-jjr3-gwjc-24jj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjr3-gwjc-24jj", + "modified": "2025-03-03T15:31:26Z", + "published": "2025-03-03T15:31:26Z", + "aliases": [ + "CVE-2025-23440" + ], + "details": "Missing Authorization vulnerability in radicaldesigns radSLIDE allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects radSLIDE: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23440" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/radslide/vulnerability/wordpress-radslide-plugin-2-1-broken-access-control-to-stored-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jmjv-7fjg-3vrm/GHSA-jmjv-7fjg-3vrm.json b/advisories/unreviewed/2025/03/GHSA-jmjv-7fjg-3vrm/GHSA-jmjv-7fjg-3vrm.json new file mode 100644 index 00000000000..f3d181e86b4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jmjv-7fjg-3vrm/GHSA-jmjv-7fjg-3vrm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmjv-7fjg-3vrm", + "modified": "2025-03-03T15:31:34Z", + "published": "2025-03-03T15:31:34Z", + "aliases": [ + "CVE-2025-26999" + ], + "details": "Deserialization of Untrusted Data vulnerability in Metagauss ProfileGrid allows Object Injection. This issue affects ProfileGrid : from n/a through 5.9.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26999" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/profilegrid-user-profiles-groups-and-communities/vulnerability/wordpress-profilegrid-plugin-5-9-4-3-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jp2x-7x8q-9jf5/GHSA-jp2x-7x8q-9jf5.json b/advisories/unreviewed/2025/03/GHSA-jp2x-7x8q-9jf5/GHSA-jp2x-7x8q-9jf5.json new file mode 100644 index 00000000000..c4a1a41e6ae --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jp2x-7x8q-9jf5/GHSA-jp2x-7x8q-9jf5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jp2x-7x8q-9jf5", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23565" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Wibstats allows Reflected XSS. This issue affects Wibstats: from n/a through 0.5.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23565" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wibstats-statistics-for-wordpress-mu/vulnerability/wordpress-wibstats-plugin-0-5-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jpvv-qg86-wxw9/GHSA-jpvv-qg86-wxw9.json b/advisories/unreviewed/2025/03/GHSA-jpvv-qg86-wxw9/GHSA-jpvv-qg86-wxw9.json new file mode 100644 index 00000000000..fe0b02644a0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jpvv-qg86-wxw9/GHSA-jpvv-qg86-wxw9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpvv-qg86-wxw9", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23521" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Goodlayers Blocks allows Reflected XSS. This issue affects Goodlayers Blocks: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23521" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/goodlayers-blocks/vulnerability/wordpress-goodlayers-blocks-plugin-1-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jqcw-gv2p-8m5p/GHSA-jqcw-gv2p-8m5p.json b/advisories/unreviewed/2025/03/GHSA-jqcw-gv2p-8m5p/GHSA-jqcw-gv2p-8m5p.json new file mode 100644 index 00000000000..5c01887cb93 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jqcw-gv2p-8m5p/GHSA-jqcw-gv2p-8m5p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqcw-gv2p-8m5p", + "modified": "2025-03-03T15:31:30Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-23740" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Easy School Registration allows Reflected XSS. This issue affects Easy School Registration: from n/a through 3.9.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23740" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-school-registration/vulnerability/wordpress-easy-school-registration-plugin-3-9-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jqm6-8ggx-r3ww/GHSA-jqm6-8ggx-r3ww.json b/advisories/unreviewed/2025/03/GHSA-jqm6-8ggx-r3ww/GHSA-jqm6-8ggx-r3ww.json new file mode 100644 index 00000000000..08a3ccf521c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jqm6-8ggx-r3ww/GHSA-jqm6-8ggx-r3ww.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqm6-8ggx-r3ww", + "modified": "2025-03-03T15:31:34Z", + "published": "2025-03-03T15:31:34Z", + "aliases": [ + "CVE-2025-1125" + ], + "details": "When reading data from a hfs filesystem, grub's hfs filesystem module uses user-controlled parameters from the filesystem metadata to calculate the internal buffers size, however it misses to properly check for integer overflows. A maliciouly crafted filesystem may lead some of those buffer size calculation to overflow, causing it to perform a grub_malloc() operation with a smaller size than expected. As a result the hfsplus_open_compressed_real() function will write past of the internal buffer length. This flaw may be leveraged to corrupt grub's internal critical data and may result in arbitrary code execution by-passing secure boot protections.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1125" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-1125" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2346138" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jx5j-v6j9-5q5q/GHSA-jx5j-v6j9-5q5q.json b/advisories/unreviewed/2025/03/GHSA-jx5j-v6j9-5q5q/GHSA-jx5j-v6j9-5q5q.json new file mode 100644 index 00000000000..3684266858e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jx5j-v6j9-5q5q/GHSA-jx5j-v6j9-5q5q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jx5j-v6j9-5q5q", + "modified": "2025-03-03T15:31:29Z", + "published": "2025-03-03T15:31:29Z", + "aliases": [ + "CVE-2025-23663" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adrian Vaquez Contexto allows Reflected XSS. This issue affects Contexto: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23663" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/contexto/vulnerability/wordpress-contexto-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m9hq-fp7j-vgxr/GHSA-m9hq-fp7j-vgxr.json b/advisories/unreviewed/2025/03/GHSA-m9hq-fp7j-vgxr/GHSA-m9hq-fp7j-vgxr.json new file mode 100644 index 00000000000..7b7c9114b84 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m9hq-fp7j-vgxr/GHSA-m9hq-fp7j-vgxr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9hq-fp7j-vgxr", + "modified": "2025-03-03T15:31:27Z", + "published": "2025-03-03T15:31:27Z", + "aliases": [ + "CVE-2025-23480" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound RSVP ME allows Stored XSS. This issue affects RSVP ME: from n/a through 1.9.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23480" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rsvp-me/vulnerability/wordpress-rsvp-me-plugin-1-9-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mq6j-52vj-xjq9/GHSA-mq6j-52vj-xjq9.json b/advisories/unreviewed/2025/03/GHSA-mq6j-52vj-xjq9/GHSA-mq6j-52vj-xjq9.json new file mode 100644 index 00000000000..e3299efe181 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mq6j-52vj-xjq9/GHSA-mq6j-52vj-xjq9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq6j-52vj-xjq9", + "modified": "2025-03-03T15:31:25Z", + "published": "2025-03-03T15:31:25Z", + "aliases": [ + "CVE-2025-1869" + ], + "details": "SQL injection vulnerability have been found in 101news affecting version 1.0 through the \"username\" parameter in admin/check_avalability.php.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1869" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-101news" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p66p-rjjv-9f55/GHSA-p66p-rjjv-9f55.json b/advisories/unreviewed/2025/03/GHSA-p66p-rjjv-9f55/GHSA-p66p-rjjv-9f55.json new file mode 100644 index 00000000000..28c4851bf7d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p66p-rjjv-9f55/GHSA-p66p-rjjv-9f55.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p66p-rjjv-9f55", + "modified": "2025-03-03T15:31:25Z", + "published": "2025-03-03T15:31:25Z", + "aliases": [ + "CVE-2025-1873" + ], + "details": "SQL injection vulnerability have been found in 101news affecting version 1.0 through the \"pagetitle\" and \"pagedescription\" parameters in admin/contactus.php.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1873" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-101news" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pc4g-h6r6-mq33/GHSA-pc4g-h6r6-mq33.json b/advisories/unreviewed/2025/03/GHSA-pc4g-h6r6-mq33/GHSA-pc4g-h6r6-mq33.json new file mode 100644 index 00000000000..78d37e3faec --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pc4g-h6r6-mq33/GHSA-pc4g-h6r6-mq33.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc4g-h6r6-mq33", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23575" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound DX Sales CRM allows Reflected XSS. This issue affects DX Sales CRM: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23575" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dx-sales-crm/vulnerability/wordpress-dx-sales-crm-plugin-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pfrf-6qh2-mph6/GHSA-pfrf-6qh2-mph6.json b/advisories/unreviewed/2025/03/GHSA-pfrf-6qh2-mph6/GHSA-pfrf-6qh2-mph6.json new file mode 100644 index 00000000000..d6636a62941 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pfrf-6qh2-mph6/GHSA-pfrf-6qh2-mph6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfrf-6qh2-mph6", + "modified": "2025-03-03T15:31:32Z", + "published": "2025-03-03T15:31:32Z", + "aliases": [ + "CVE-2025-25165" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Staff Directory Plugin: Company Directory allows Stored XSS. This issue affects Staff Directory Plugin: Company Directory: from n/a through 4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25165" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/staff-directory-pro/vulnerability/wordpress-staff-directory-plugin-company-directory-plugin-4-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pmfj-879m-mx7q/GHSA-pmfj-879m-mx7q.json b/advisories/unreviewed/2025/03/GHSA-pmfj-879m-mx7q/GHSA-pmfj-879m-mx7q.json new file mode 100644 index 00000000000..3d2a5edf329 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pmfj-879m-mx7q/GHSA-pmfj-879m-mx7q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmfj-879m-mx7q", + "modified": "2025-03-03T15:31:29Z", + "published": "2025-03-03T15:31:29Z", + "aliases": [ + "CVE-2025-23688" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Cobwebo URL Plugin allows Reflected XSS. This issue affects Cobwebo URL Plugin: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23688" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cobwebo-url/vulnerability/wordpress-cobwebo-url-plugin-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pp4h-3vh8-rwrw/GHSA-pp4h-3vh8-rwrw.json b/advisories/unreviewed/2025/03/GHSA-pp4h-3vh8-rwrw/GHSA-pp4h-3vh8-rwrw.json new file mode 100644 index 00000000000..a21e8730c09 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pp4h-3vh8-rwrw/GHSA-pp4h-3vh8-rwrw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pp4h-3vh8-rwrw", + "modified": "2025-03-03T15:31:31Z", + "published": "2025-03-03T15:31:31Z", + "aliases": [ + "CVE-2025-25121" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Theme Options Z allows Stored XSS. This issue affects Theme Options Z: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25121" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/theme-options-z/vulnerability/wordpress-wp-spell-check-plugin-9-21-cross-site-request-forgery-csrf-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pqqp-mv53-62cg/GHSA-pqqp-mv53-62cg.json b/advisories/unreviewed/2025/03/GHSA-pqqp-mv53-62cg/GHSA-pqqp-mv53-62cg.json new file mode 100644 index 00000000000..1664cdef4a4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pqqp-mv53-62cg/GHSA-pqqp-mv53-62cg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqqp-mv53-62cg", + "modified": "2025-03-03T15:31:27Z", + "published": "2025-03-03T15:31:27Z", + "aliases": [ + "CVE-2025-23472" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Flexo Slider allows Reflected XSS. This issue affects Flexo Slider: from n/a through 1.0013.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23472" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/flexo-slider/vulnerability/wordpress-flexo-slider-plugin-1-0013-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pr82-x8qh-vhp8/GHSA-pr82-x8qh-vhp8.json b/advisories/unreviewed/2025/03/GHSA-pr82-x8qh-vhp8/GHSA-pr82-x8qh-vhp8.json new file mode 100644 index 00000000000..eebc81d8c6f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pr82-x8qh-vhp8/GHSA-pr82-x8qh-vhp8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pr82-x8qh-vhp8", + "modified": "2025-03-03T15:31:30Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-25083" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound EP4 More Embeds allows Stored XSS. This issue affects EP4 More Embeds: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25083" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ep4-more-embeds/vulnerability/wordpress-ep4-more-embeds-plugin-1-0-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pwcq-rwgx-7jcr/GHSA-pwcq-rwgx-7jcr.json b/advisories/unreviewed/2025/03/GHSA-pwcq-rwgx-7jcr/GHSA-pwcq-rwgx-7jcr.json new file mode 100644 index 00000000000..cfc5fdc5ac8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pwcq-rwgx-7jcr/GHSA-pwcq-rwgx-7jcr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwcq-rwgx-7jcr", + "modified": "2025-03-03T15:31:32Z", + "published": "2025-03-03T15:31:31Z", + "aliases": [ + "CVE-2025-25127" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rohitashv Singhal Contact Us By Lord Linus allows Reflected XSS. This issue affects Contact Us By Lord Linus: from n/a through 2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25127" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/contact-us-by-lord-linus/vulnerability/wordpress-contact-us-by-lord-linus-plugin-2-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q43v-qff8-phm7/GHSA-q43v-qff8-phm7.json b/advisories/unreviewed/2025/03/GHSA-q43v-qff8-phm7/GHSA-q43v-qff8-phm7.json new file mode 100644 index 00000000000..dcc594c08b4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q43v-qff8-phm7/GHSA-q43v-qff8-phm7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q43v-qff8-phm7", + "modified": "2025-03-03T15:31:26Z", + "published": "2025-03-03T15:31:26Z", + "aliases": [ + "CVE-2025-23447" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Smooth Dynamic Slider allows Reflected XSS. This issue affects Smooth Dynamic Slider: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23447" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/smooth-dynamic-slider/vulnerability/wordpress-smooth-dynamic-slider-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q7w8-q2f9-vcmh/GHSA-q7w8-q2f9-vcmh.json b/advisories/unreviewed/2025/03/GHSA-q7w8-q2f9-vcmh/GHSA-q7w8-q2f9-vcmh.json new file mode 100644 index 00000000000..63ce2501f4c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q7w8-q2f9-vcmh/GHSA-q7w8-q2f9-vcmh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7w8-q2f9-vcmh", + "modified": "2025-03-03T15:31:34Z", + "published": "2025-03-03T15:31:34Z", + "aliases": [ + "CVE-2025-0689" + ], + "details": "When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the allocated buffer size which is not guaranteed. A crafted filesystem image may lead to a heap-based buffer overflow resulting in critical data to be corrupted, resulting in the risk of arbitrary code execution by-passing secure boot protections.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0689" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-0689" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2346122" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q8c9-hmjx-mh95/GHSA-q8c9-hmjx-mh95.json b/advisories/unreviewed/2025/03/GHSA-q8c9-hmjx-mh95/GHSA-q8c9-hmjx-mh95.json new file mode 100644 index 00000000000..3ff9dbc0626 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q8c9-hmjx-mh95/GHSA-q8c9-hmjx-mh95.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8c9-hmjx-mh95", + "modified": "2025-03-03T15:31:34Z", + "published": "2025-03-03T15:31:34Z", + "aliases": [ + "CVE-2025-27271" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound DB Tables Import/Export allows Reflected XSS. This issue affects DB Tables Import/Export: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27271" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/db-tables-importexport/vulnerability/wordpress-db-tables-import-export-plugin-1-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qg4m-5hg4-34vq/GHSA-qg4m-5hg4-34vq.json b/advisories/unreviewed/2025/03/GHSA-qg4m-5hg4-34vq/GHSA-qg4m-5hg4-34vq.json new file mode 100644 index 00000000000..a2fb5fd1e66 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qg4m-5hg4-34vq/GHSA-qg4m-5hg4-34vq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg4m-5hg4-34vq", + "modified": "2025-03-03T15:31:34Z", + "published": "2025-03-03T15:31:34Z", + "aliases": [ + "CVE-2024-45779" + ], + "details": "An integer overflow flaw was found in the BFS file system driver in grub2. When reading a file with an indirect extent map, grub2 fails to validate the number of extent entries to be read. A crafted or corrupted BFS filesystem may cause an integer overflow during the file reading, leading to a heap of bounds read. As a consequence, sensitive data may be leaked, or grub2 will crash.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45779" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-45779" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345854" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qwp8-6r9q-pcjh/GHSA-qwp8-6r9q-pcjh.json b/advisories/unreviewed/2025/03/GHSA-qwp8-6r9q-pcjh/GHSA-qwp8-6r9q-pcjh.json new file mode 100644 index 00000000000..cf4b3ab0d15 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qwp8-6r9q-pcjh/GHSA-qwp8-6r9q-pcjh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwp8-6r9q-pcjh", + "modified": "2025-03-03T15:31:33Z", + "published": "2025-03-03T15:31:32Z", + "aliases": [ + "CVE-2025-26534" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NotFound Helloprint allows Path Traversal. This issue affects Helloprint: from n/a through 2.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26534" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/helloprint/vulnerability/wordpress-helloprint-plugin-2-0-7-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r6q3-vp6w-xwf9/GHSA-r6q3-vp6w-xwf9.json b/advisories/unreviewed/2025/03/GHSA-r6q3-vp6w-xwf9/GHSA-r6q3-vp6w-xwf9.json new file mode 100644 index 00000000000..83bb50b7c31 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r6q3-vp6w-xwf9/GHSA-r6q3-vp6w-xwf9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6q3-vp6w-xwf9", + "modified": "2025-03-03T15:31:25Z", + "published": "2025-03-03T15:31:25Z", + "aliases": [ + "CVE-2025-1871" + ], + "details": "SQL injection vulnerability have been found in 101news affecting version 1.0 through the \"category\" and \"subcategory\" parameters in admin/add-subcategory.php.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1871" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-101news" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r6rh-92mr-9w5v/GHSA-r6rh-92mr-9w5v.json b/advisories/unreviewed/2025/03/GHSA-r6rh-92mr-9w5v/GHSA-r6rh-92mr-9w5v.json new file mode 100644 index 00000000000..4281b5b72b8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r6rh-92mr-9w5v/GHSA-r6rh-92mr-9w5v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6rh-92mr-9w5v", + "modified": "2025-03-03T15:31:26Z", + "published": "2025-03-03T15:31:26Z", + "aliases": [ + "CVE-2025-23468" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Essay Wizard (wpCRES) allows Reflected XSS. This issue affects Essay Wizard (wpCRES): from n/a through 1.0.6.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23468" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/essay-wizard-wpcres/vulnerability/wordpress-essay-wizard-wpcres-plugin-1-0-6-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r8c3-g64c-cw4x/GHSA-r8c3-g64c-cw4x.json b/advisories/unreviewed/2025/03/GHSA-r8c3-g64c-cw4x/GHSA-r8c3-g64c-cw4x.json new file mode 100644 index 00000000000..73c0ee6bed8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r8c3-g64c-cw4x/GHSA-r8c3-g64c-cw4x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8c3-g64c-cw4x", + "modified": "2025-03-03T15:31:31Z", + "published": "2025-03-03T15:31:31Z", + "aliases": [ + "CVE-2025-25089" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in appten Image Rotator allows Reflected XSS. This issue affects Image Rotator: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25089" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/appten-image-rotator/vulnerability/wordpress-easy-wp-tiles-plugin-1-cross-site-scripting-xss-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rfpj-c27v-frw8/GHSA-rfpj-c27v-frw8.json b/advisories/unreviewed/2025/03/GHSA-rfpj-c27v-frw8/GHSA-rfpj-c27v-frw8.json new file mode 100644 index 00000000000..66787059030 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rfpj-c27v-frw8/GHSA-rfpj-c27v-frw8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfpj-c27v-frw8", + "modified": "2025-03-03T15:31:31Z", + "published": "2025-03-03T15:31:31Z", + "aliases": [ + "CVE-2025-25113" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Implied Cookie Consent allows Reflected XSS. This issue affects Implied Cookie Consent: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25113" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/implied-cookie-consent/vulnerability/wordpress-external-video-for-everybody-plugin-2-1-1-cross-site-scripting-xss-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rfwh-qxvm-5m8j/GHSA-rfwh-qxvm-5m8j.json b/advisories/unreviewed/2025/03/GHSA-rfwh-qxvm-5m8j/GHSA-rfwh-qxvm-5m8j.json new file mode 100644 index 00000000000..a5c0d2e4ff4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rfwh-qxvm-5m8j/GHSA-rfwh-qxvm-5m8j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfwh-qxvm-5m8j", + "modified": "2025-03-03T15:31:27Z", + "published": "2025-03-03T15:31:27Z", + "aliases": [ + "CVE-2025-23502" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in NotFound Curated Search allows Stored XSS. This issue affects Curated Search: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23502" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/curated-search/vulnerability/wordpress-curated-search-plugin-1-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rjwp-c3f6-mgx5/GHSA-rjwp-c3f6-mgx5.json b/advisories/unreviewed/2025/03/GHSA-rjwp-c3f6-mgx5/GHSA-rjwp-c3f6-mgx5.json new file mode 100644 index 00000000000..a919ea4ef0b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rjwp-c3f6-mgx5/GHSA-rjwp-c3f6-mgx5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjwp-c3f6-mgx5", + "modified": "2025-03-03T15:31:30Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-23843" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphrmanager WP-HR Manager: The Human Resources Plugin for WordPress allows Reflected XSS. This issue affects WP-HR Manager: The Human Resources Plugin for WordPress: from n/a through 3.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23843" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-hr-manager/vulnerability/wordpress-wp-hr-manager-plugin-3-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rq8c-97x5-hqj8/GHSA-rq8c-97x5-hqj8.json b/advisories/unreviewed/2025/03/GHSA-rq8c-97x5-hqj8/GHSA-rq8c-97x5-hqj8.json new file mode 100644 index 00000000000..81a636663a9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rq8c-97x5-hqj8/GHSA-rq8c-97x5-hqj8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq8c-97x5-hqj8", + "modified": "2025-03-03T15:31:26Z", + "published": "2025-03-03T15:31:26Z", + "aliases": [ + "CVE-2025-1872" + ], + "details": "SQL injection vulnerability have been found in 101news affecting version 1.0 through the \"sadminusername\" parameter in admin/add-subadmins.php.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1872" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-101news" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rvj4-hc6m-x437/GHSA-rvj4-hc6m-x437.json b/advisories/unreviewed/2025/03/GHSA-rvj4-hc6m-x437/GHSA-rvj4-hc6m-x437.json new file mode 100644 index 00000000000..b98b934b466 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rvj4-hc6m-x437/GHSA-rvj4-hc6m-x437.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvj4-hc6m-x437", + "modified": "2025-03-03T15:31:31Z", + "published": "2025-03-03T15:31:31Z", + "aliases": [ + "CVE-2025-25119" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Woocommerce osCommerce Sync allows Reflected XSS. This issue affects Woocommerce osCommerce Sync: from n/a through 2.0.20.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25119" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-oscommerce-sync/vulnerability/wordpress-easy-wp-tiles-plugin-1-cross-site-scripting-xss-vulnerability-4?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rvvc-q877-7v49/GHSA-rvvc-q877-7v49.json b/advisories/unreviewed/2025/03/GHSA-rvvc-q877-7v49/GHSA-rvvc-q877-7v49.json new file mode 100644 index 00000000000..334d6b63fc4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rvvc-q877-7v49/GHSA-rvvc-q877-7v49.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvvc-q877-7v49", + "modified": "2025-03-03T15:31:34Z", + "published": "2025-03-03T15:31:34Z", + "aliases": [ + "CVE-2025-27268" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition allows SQL Injection. This issue affects Small Package Quotes – Worldwide Express Edition: from n/a through 5.2.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27268" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/small-package-quotes-wwe-edition/vulnerability/wordpress-small-package-quotes-worldwide-express-edition-plugin-5-2-18-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v4pv-c84v-rvfr/GHSA-v4pv-c84v-rvfr.json b/advisories/unreviewed/2025/03/GHSA-v4pv-c84v-rvfr/GHSA-v4pv-c84v-rvfr.json new file mode 100644 index 00000000000..9e0cf9bcde9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v4pv-c84v-rvfr/GHSA-v4pv-c84v-rvfr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4pv-c84v-rvfr", + "modified": "2025-03-03T15:31:26Z", + "published": "2025-03-03T15:31:26Z", + "aliases": [ + "CVE-2025-23451" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Awesome Twitter Feeds allows Reflected XSS. This issue affects Awesome Twitter Feeds: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23451" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/awesome-twitter-feeds/vulnerability/wordpress-awesome-twitter-feeds-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v58q-54f6-f82p/GHSA-v58q-54f6-f82p.json b/advisories/unreviewed/2025/03/GHSA-v58q-54f6-f82p/GHSA-v58q-54f6-f82p.json new file mode 100644 index 00000000000..d11bf69dee6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v58q-54f6-f82p/GHSA-v58q-54f6-f82p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v58q-54f6-f82p", + "modified": "2025-03-03T15:31:31Z", + "published": "2025-03-03T15:31:31Z", + "aliases": [ + "CVE-2025-25108" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shalomworld SW Plus allows Reflected XSS. This issue affects SW Plus: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25108" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/shalom-world-media-gallery/vulnerability/wordpress-sw-plus-plugin-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v6vq-mcjw-3qrm/GHSA-v6vq-mcjw-3qrm.json b/advisories/unreviewed/2025/03/GHSA-v6vq-mcjw-3qrm/GHSA-v6vq-mcjw-3qrm.json new file mode 100644 index 00000000000..8c885c5c84c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v6vq-mcjw-3qrm/GHSA-v6vq-mcjw-3qrm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6vq-mcjw-3qrm", + "modified": "2025-03-03T15:31:33Z", + "published": "2025-03-03T15:31:33Z", + "aliases": [ + "CVE-2025-26589" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound IE CSS3 Support allows Reflected XSS. This issue affects IE CSS3 Support: from n/a through 2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26589" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ie-css3-support/vulnerability/wordpress-ie-css3-support-plugin-2-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v9w8-xh9q-mp2j/GHSA-v9w8-xh9q-mp2j.json b/advisories/unreviewed/2025/03/GHSA-v9w8-xh9q-mp2j/GHSA-v9w8-xh9q-mp2j.json new file mode 100644 index 00000000000..919ee4a3778 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v9w8-xh9q-mp2j/GHSA-v9w8-xh9q-mp2j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9w8-xh9q-mp2j", + "modified": "2025-03-03T15:31:29Z", + "published": "2025-03-03T15:31:29Z", + "aliases": [ + "CVE-2025-23600" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pinal.shah Send to a Friend Addon allows Reflected XSS. This issue affects Send to a Friend Addon: from n/a through 1.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23600" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/send-booking-invites-to-friends/vulnerability/wordpress-send-to-a-friend-addon-plugin-1-4-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vc7v-xwv2-3v83/GHSA-vc7v-xwv2-3v83.json b/advisories/unreviewed/2025/03/GHSA-vc7v-xwv2-3v83/GHSA-vc7v-xwv2-3v83.json new file mode 100644 index 00000000000..8e85efcb731 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vc7v-xwv2-3v83/GHSA-vc7v-xwv2-3v83.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vc7v-xwv2-3v83", + "modified": "2025-03-03T15:31:32Z", + "published": "2025-03-03T15:31:32Z", + "aliases": [ + "CVE-2025-25133" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Frontend Submit allows Cross-Site Scripting (XSS). This issue affects WP Frontend Submit: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25133" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-frontend-submit/vulnerability/wordpress-indeed-api-plugin-0-5-csrf-to-settings-change-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vccg-pg4r-fjxh/GHSA-vccg-pg4r-fjxh.json b/advisories/unreviewed/2025/03/GHSA-vccg-pg4r-fjxh/GHSA-vccg-pg4r-fjxh.json new file mode 100644 index 00000000000..b1fdd944fc5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vccg-pg4r-fjxh/GHSA-vccg-pg4r-fjxh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vccg-pg4r-fjxh", + "modified": "2025-03-03T15:31:33Z", + "published": "2025-03-03T15:31:33Z", + "aliases": [ + "CVE-2025-26988" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications – WooCommerce allows SQL Injection. This issue affects SMS Alert Order Notifications – WooCommerce: from n/a through 3.7.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26988" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sms-alert/vulnerability/wordpress-sms-alert-order-notifications-woocommerce-plugin-3-7-8-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vcpj-fj22-xw8g/GHSA-vcpj-fj22-xw8g.json b/advisories/unreviewed/2025/03/GHSA-vcpj-fj22-xw8g/GHSA-vcpj-fj22-xw8g.json new file mode 100644 index 00000000000..8d68c271984 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vcpj-fj22-xw8g/GHSA-vcpj-fj22-xw8g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcpj-fj22-xw8g", + "modified": "2025-03-03T15:31:27Z", + "published": "2025-03-03T15:31:27Z", + "aliases": [ + "CVE-2025-23485" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in richestsoft RS Survey allows Reflected XSS. This issue affects RS Survey: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23485" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rs-survey/vulnerability/wordpress-rs-survey-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vf46-6rcc-3xxx/GHSA-vf46-6rcc-3xxx.json b/advisories/unreviewed/2025/03/GHSA-vf46-6rcc-3xxx/GHSA-vf46-6rcc-3xxx.json new file mode 100644 index 00000000000..93496cebe8b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vf46-6rcc-3xxx/GHSA-vf46-6rcc-3xxx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vf46-6rcc-3xxx", + "modified": "2025-03-03T15:31:30Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-23881" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound LJ Custom Menu Links allows Reflected XSS. This issue affects LJ Custom Menu Links: from n/a through 2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23881" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lj-custom-menu-links/vulnerability/wordpress-lj-custom-menu-links-plugin-2-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vhfr-93vm-g72f/GHSA-vhfr-93vm-g72f.json b/advisories/unreviewed/2025/03/GHSA-vhfr-93vm-g72f/GHSA-vhfr-93vm-g72f.json new file mode 100644 index 00000000000..9aae5c3c5e8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vhfr-93vm-g72f/GHSA-vhfr-93vm-g72f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhfr-93vm-g72f", + "modified": "2025-03-03T15:31:31Z", + "published": "2025-03-03T15:31:31Z", + "aliases": [ + "CVE-2025-25090" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Dreamstime Stock Photos allows Reflected XSS. This issue affects Dreamstime Stock Photos: from n/a through 4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25090" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dreamstime-stock-photos/vulnerability/wordpress-dreamstime-stock-photos-plugin-4-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vj7p-3w85-844j/GHSA-vj7p-3w85-844j.json b/advisories/unreviewed/2025/03/GHSA-vj7p-3w85-844j/GHSA-vj7p-3w85-844j.json new file mode 100644 index 00000000000..b32f424aeb4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vj7p-3w85-844j/GHSA-vj7p-3w85-844j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vj7p-3w85-844j", + "modified": "2025-03-03T15:31:27Z", + "published": "2025-03-03T15:31:27Z", + "aliases": [ + "CVE-2025-23487" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Easy Gallery allows Reflected XSS. This issue affects Easy Gallery: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23487" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-gallery-odihost/vulnerability/wordpress-easy-gallery-plugin-1-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vm7w-2724-5m23/GHSA-vm7w-2724-5m23.json b/advisories/unreviewed/2025/03/GHSA-vm7w-2724-5m23/GHSA-vm7w-2724-5m23.json index efe0bc2bf39..6c55178f724 100644 --- a/advisories/unreviewed/2025/03/GHSA-vm7w-2724-5m23/GHSA-vm7w-2724-5m23.json +++ b/advisories/unreviewed/2025/03/GHSA-vm7w-2724-5m23/GHSA-vm7w-2724-5m23.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vm7w-2724-5m23", - "modified": "2025-03-03T12:30:31Z", + "modified": "2025-03-03T15:31:25Z", "published": "2025-03-03T12:30:31Z", "aliases": [ "CVE-2024-24778" ], "details": "Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. \n\n\n\n\n\nThis issue affects Apache StreamPipes: through 0.95.1.\n\nUsers are recommended to upgrade to version 0.97.0 which fixes the issue.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-269" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T11:15:11Z" diff --git a/advisories/unreviewed/2025/03/GHSA-vm9x-4m38-wvhh/GHSA-vm9x-4m38-wvhh.json b/advisories/unreviewed/2025/03/GHSA-vm9x-4m38-wvhh/GHSA-vm9x-4m38-wvhh.json new file mode 100644 index 00000000000..6b4ec21a8f7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vm9x-4m38-wvhh/GHSA-vm9x-4m38-wvhh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vm9x-4m38-wvhh", + "modified": "2025-03-03T15:31:26Z", + "published": "2025-03-03T15:31:26Z", + "aliases": [ + "CVE-2025-23464" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Twitter News Feed allows Reflected XSS. This issue affects Twitter News Feed: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23464" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/twitter-news-feed/vulnerability/wordpress-twitter-news-feed-plugin-1-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vv57-g9wj-p22r/GHSA-vv57-g9wj-p22r.json b/advisories/unreviewed/2025/03/GHSA-vv57-g9wj-p22r/GHSA-vv57-g9wj-p22r.json new file mode 100644 index 00000000000..610cd22fc89 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vv57-g9wj-p22r/GHSA-vv57-g9wj-p22r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv57-g9wj-p22r", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23516" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Sale with Razorpay allows Reflected XSS. This issue affects Sale with Razorpay: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23516" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sell-with-razorpay/vulnerability/wordpress-sale-with-razorpay-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vw87-rmj6-m6r2/GHSA-vw87-rmj6-m6r2.json b/advisories/unreviewed/2025/03/GHSA-vw87-rmj6-m6r2/GHSA-vw87-rmj6-m6r2.json new file mode 100644 index 00000000000..1b5933553b6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vw87-rmj6-m6r2/GHSA-vw87-rmj6-m6r2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw87-rmj6-m6r2", + "modified": "2025-03-03T15:31:25Z", + "published": "2025-03-03T15:31:25Z", + "aliases": [ + "CVE-2025-1870" + ], + "details": "SQL injection vulnerability have been found in 101news affecting version 1.0 through the \"pagedescription\" parameter in admin/aboutus.php.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1870" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-101news" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vwf4-2m5x-hmqh/GHSA-vwf4-2m5x-hmqh.json b/advisories/unreviewed/2025/03/GHSA-vwf4-2m5x-hmqh/GHSA-vwf4-2m5x-hmqh.json new file mode 100644 index 00000000000..b179a52d595 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vwf4-2m5x-hmqh/GHSA-vwf4-2m5x-hmqh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwf4-2m5x-hmqh", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23563" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Explore pages allows Reflected XSS. This issue affects Explore pages: from n/a through 1.01.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23563" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/explore-pages/vulnerability/wordpress-explore-pages-plugin-1-01-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vx54-pfx3-h7c9/GHSA-vx54-pfx3-h7c9.json b/advisories/unreviewed/2025/03/GHSA-vx54-pfx3-h7c9/GHSA-vx54-pfx3-h7c9.json new file mode 100644 index 00000000000..113ad0b1606 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vx54-pfx3-h7c9/GHSA-vx54-pfx3-h7c9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx54-pfx3-h7c9", + "modified": "2025-03-03T15:31:27Z", + "published": "2025-03-03T15:31:27Z", + "aliases": [ + "CVE-2025-23515" + ], + "details": "Missing Authorization vulnerability in tsecher ts-tree allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ts-tree: from n/a through 0.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23515" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ts-tree/vulnerability/wordpress-ts-tree-plugin-0-1-1-arbitrary-content-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w362-6935-wmpr/GHSA-w362-6935-wmpr.json b/advisories/unreviewed/2025/03/GHSA-w362-6935-wmpr/GHSA-w362-6935-wmpr.json new file mode 100644 index 00000000000..7462f514a0c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w362-6935-wmpr/GHSA-w362-6935-wmpr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w362-6935-wmpr", + "modified": "2025-03-03T15:31:26Z", + "published": "2025-03-03T15:31:26Z", + "aliases": [ + "CVE-2025-1874" + ], + "details": "SQL injection vulnerability have been found in 101news affecting version 1.0 through the \"description\" parameter in admin/add-category.php.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1874" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-101news" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w43w-pw8h-qxgc/GHSA-w43w-pw8h-qxgc.json b/advisories/unreviewed/2025/03/GHSA-w43w-pw8h-qxgc/GHSA-w43w-pw8h-qxgc.json new file mode 100644 index 00000000000..3acfeafb8fb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w43w-pw8h-qxgc/GHSA-w43w-pw8h-qxgc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w43w-pw8h-qxgc", + "modified": "2025-03-03T15:31:32Z", + "published": "2025-03-03T15:31:32Z", + "aliases": [ + "CVE-2025-25169" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Authors Autocomplete Meta Box allows Reflected XSS. This issue affects Authors Autocomplete Meta Box: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25169" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/authors-autocomplete-meta-box/vulnerability/wordpress-authors-autocomplete-meta-box-plugin-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w57q-c2cj-vh4c/GHSA-w57q-c2cj-vh4c.json b/advisories/unreviewed/2025/03/GHSA-w57q-c2cj-vh4c/GHSA-w57q-c2cj-vh4c.json new file mode 100644 index 00000000000..8de63d1d905 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w57q-c2cj-vh4c/GHSA-w57q-c2cj-vh4c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w57q-c2cj-vh4c", + "modified": "2025-03-03T15:31:27Z", + "published": "2025-03-03T15:31:27Z", + "aliases": [ + "CVE-2025-23494" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Quizzin allows Reflected XSS. This issue affects Quizzin: from n/a through 1.01.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23494" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quizzin/vulnerability/wordpress-quizzin-plugin-1-01-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w5q2-9cxh-qfcp/GHSA-w5q2-9cxh-qfcp.json b/advisories/unreviewed/2025/03/GHSA-w5q2-9cxh-qfcp/GHSA-w5q2-9cxh-qfcp.json new file mode 100644 index 00000000000..37505135f5d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w5q2-9cxh-qfcp/GHSA-w5q2-9cxh-qfcp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5q2-9cxh-qfcp", + "modified": "2025-03-03T15:31:29Z", + "published": "2025-03-03T15:31:29Z", + "aliases": [ + "CVE-2025-23584" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Pin Locations on Map allows Reflected XSS. This issue affects Pin Locations on Map: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23584" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pin-locations-on-map/vulnerability/wordpress-pin-locations-on-map-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w5v4-r62p-wm2c/GHSA-w5v4-r62p-wm2c.json b/advisories/unreviewed/2025/03/GHSA-w5v4-r62p-wm2c/GHSA-w5v4-r62p-wm2c.json new file mode 100644 index 00000000000..ef1c217d39e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w5v4-r62p-wm2c/GHSA-w5v4-r62p-wm2c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5v4-r62p-wm2c", + "modified": "2025-03-03T15:31:32Z", + "published": "2025-03-03T15:31:32Z", + "aliases": [ + "CVE-2025-25162" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NotFound Sports Rankings and Lists allows Absolute Path Traversal. This issue affects Sports Rankings and Lists: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25162" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sports-rankings-lists/vulnerability/wordpress-read-more-copy-link-plugin-1-0-2-csrf-to-stored-xss-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wgrw-gjpf-rw8c/GHSA-wgrw-gjpf-rw8c.json b/advisories/unreviewed/2025/03/GHSA-wgrw-gjpf-rw8c/GHSA-wgrw-gjpf-rw8c.json new file mode 100644 index 00000000000..aef16a38cbb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wgrw-gjpf-rw8c/GHSA-wgrw-gjpf-rw8c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgrw-gjpf-rw8c", + "modified": "2025-03-03T15:31:32Z", + "published": "2025-03-03T15:31:32Z", + "aliases": [ + "CVE-2025-26535" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Bitcoin / AltCoin Payment Gateway for WooCommerce allows Blind SQL Injection. This issue affects Bitcoin / AltCoin Payment Gateway for WooCommerce: from n/a through 1.7.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26535" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-altcoin-payment-gateway/vulnerability/wordpress-bitcoin-altcoin-payment-gateway-for-woocommerce-multivendor-store-shop-plugin-1-7-6-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wgxw-qpwc-vh83/GHSA-wgxw-qpwc-vh83.json b/advisories/unreviewed/2025/03/GHSA-wgxw-qpwc-vh83/GHSA-wgxw-qpwc-vh83.json new file mode 100644 index 00000000000..c05782dec97 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wgxw-qpwc-vh83/GHSA-wgxw-qpwc-vh83.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgxw-qpwc-vh83", + "modified": "2025-03-03T15:31:31Z", + "published": "2025-03-03T15:31:31Z", + "aliases": [ + "CVE-2025-25070" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Album Reviewer allows Stored XSS. This issue affects Album Reviewer: from n/a through 2.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25070" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/albumreviewer/vulnerability/wordpress-album-reviewer-plugin-2-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wh75-9866-4mjr/GHSA-wh75-9866-4mjr.json b/advisories/unreviewed/2025/03/GHSA-wh75-9866-4mjr/GHSA-wh75-9866-4mjr.json new file mode 100644 index 00000000000..545963656b0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wh75-9866-4mjr/GHSA-wh75-9866-4mjr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh75-9866-4mjr", + "modified": "2025-03-03T15:31:34Z", + "published": "2025-03-03T15:31:34Z", + "aliases": [ + "CVE-2024-8262" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Proliz Software OBS allows Path Traversal.This issue affects OBS: before 24.0927.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8262" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-25-0049" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wjwq-xqq9-qhcr/GHSA-wjwq-xqq9-qhcr.json b/advisories/unreviewed/2025/03/GHSA-wjwq-xqq9-qhcr/GHSA-wjwq-xqq9-qhcr.json new file mode 100644 index 00000000000..ef0f3096245 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wjwq-xqq9-qhcr/GHSA-wjwq-xqq9-qhcr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjwq-xqq9-qhcr", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23536" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Track Page Scroll allows Reflected XSS. This issue affects Track Page Scroll: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23536" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/track-page-scroll/vulnerability/wordpress-track-page-scroll-plugin-1-0-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wm36-6qmm-fvr8/GHSA-wm36-6qmm-fvr8.json b/advisories/unreviewed/2025/03/GHSA-wm36-6qmm-fvr8/GHSA-wm36-6qmm-fvr8.json new file mode 100644 index 00000000000..3c09be0ee37 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wm36-6qmm-fvr8/GHSA-wm36-6qmm-fvr8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm36-6qmm-fvr8", + "modified": "2025-03-03T15:31:31Z", + "published": "2025-03-03T15:31:31Z", + "aliases": [ + "CVE-2025-25124" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devu Status Updater allows Reflected XSS. This issue affects Status Updater: from n/a through 1.9.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25124" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fb-status-updater/vulnerability/wordpress-wp-spell-check-plugin-9-21-cross-site-request-forgery-csrf-vulnerability-3?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wp7c-8g73-37mm/GHSA-wp7c-8g73-37mm.json b/advisories/unreviewed/2025/03/GHSA-wp7c-8g73-37mm/GHSA-wp7c-8g73-37mm.json new file mode 100644 index 00000000000..7bcddbb2ba7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wp7c-8g73-37mm/GHSA-wp7c-8g73-37mm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp7c-8g73-37mm", + "modified": "2025-03-03T15:31:32Z", + "published": "2025-03-03T15:31:32Z", + "aliases": [ + "CVE-2025-25157" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Church Center allows Reflected XSS. This issue affects WP Church Center: from n/a through 1.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25157" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-church-center/vulnerability/wordpress-wp-church-center-plugin-1-3-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wqcw-wh9g-67rg/GHSA-wqcw-wh9g-67rg.json b/advisories/unreviewed/2025/03/GHSA-wqcw-wh9g-67rg/GHSA-wqcw-wh9g-67rg.json index bebb53353c4..c17828b0b93 100644 --- a/advisories/unreviewed/2025/03/GHSA-wqcw-wh9g-67rg/GHSA-wqcw-wh9g-67rg.json +++ b/advisories/unreviewed/2025/03/GHSA-wqcw-wh9g-67rg/GHSA-wqcw-wh9g-67rg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wqcw-wh9g-67rg", - "modified": "2025-03-03T03:31:19Z", + "modified": "2025-03-03T15:31:25Z", "published": "2025-03-03T03:31:19Z", "aliases": [ "CVE-2025-20647" ], "details": "In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00791311 / MOLY01067019; Issue ID: MSV-2721.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-03T03:15:09Z" diff --git a/advisories/unreviewed/2025/03/GHSA-x3hp-xj99-8chx/GHSA-x3hp-xj99-8chx.json b/advisories/unreviewed/2025/03/GHSA-x3hp-xj99-8chx/GHSA-x3hp-xj99-8chx.json new file mode 100644 index 00000000000..8576915374f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x3hp-xj99-8chx/GHSA-x3hp-xj99-8chx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3hp-xj99-8chx", + "modified": "2025-03-03T15:31:33Z", + "published": "2025-03-03T15:31:33Z", + "aliases": [ + "CVE-2025-26588" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound TTT Crop allows Reflected XSS. This issue affects TTT Crop: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26588" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ttt-crop/vulnerability/wordpress-ttt-crop-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x3hv-g95w-vv54/GHSA-x3hv-g95w-vv54.json b/advisories/unreviewed/2025/03/GHSA-x3hv-g95w-vv54/GHSA-x3hv-g95w-vv54.json new file mode 100644 index 00000000000..991f58522b5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x3hv-g95w-vv54/GHSA-x3hv-g95w-vv54.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3hv-g95w-vv54", + "modified": "2025-03-03T15:31:27Z", + "published": "2025-03-03T15:31:27Z", + "aliases": [ + "CVE-2025-23488" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound rng-refresh allows Reflected XSS. This issue affects rng-refresh: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23488" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rng-refresh/vulnerability/wordpress-rng-refresh-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x42p-xqqx-2f33/GHSA-x42p-xqqx-2f33.json b/advisories/unreviewed/2025/03/GHSA-x42p-xqqx-2f33/GHSA-x42p-xqqx-2f33.json new file mode 100644 index 00000000000..33228d6c54b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x42p-xqqx-2f33/GHSA-x42p-xqqx-2f33.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x42p-xqqx-2f33", + "modified": "2025-03-03T15:31:30Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-23850" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Mojo Under Construction allows Reflected XSS. This issue affects Mojo Under Construction: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23850" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mojo-under-construction/vulnerability/wordpress-mojo-under-construction-plugin-1-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x5w2-q3rj-2cpp/GHSA-x5w2-q3rj-2cpp.json b/advisories/unreviewed/2025/03/GHSA-x5w2-q3rj-2cpp/GHSA-x5w2-q3rj-2cpp.json new file mode 100644 index 00000000000..5310115890e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x5w2-q3rj-2cpp/GHSA-x5w2-q3rj-2cpp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5w2-q3rj-2cpp", + "modified": "2025-03-03T15:31:32Z", + "published": "2025-03-03T15:31:32Z", + "aliases": [ + "CVE-2025-25130" + ], + "details": "Relative Path Traversal vulnerability in NotFound Delete Comments By Status allows PHP Local File Inclusion. This issue affects Delete Comments By Status: from n/a through 2.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25130" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/delete-comments-by-status/vulnerability/wordpress-external-video-for-everybody-plugin-2-1-1-cross-site-scripting-xss-vulnerability-3?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x637-7g3v-9gfj/GHSA-x637-7g3v-9gfj.json b/advisories/unreviewed/2025/03/GHSA-x637-7g3v-9gfj/GHSA-x637-7g3v-9gfj.json new file mode 100644 index 00000000000..aabd10a4b36 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x637-7g3v-9gfj/GHSA-x637-7g3v-9gfj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x637-7g3v-9gfj", + "modified": "2025-03-03T15:31:27Z", + "published": "2025-03-03T15:31:27Z", + "aliases": [ + "CVE-2025-23481" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Ni WooCommerce Sales Report Email allows Reflected XSS. This issue affects Ni WooCommerce Sales Report Email: from n/a through 3.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23481" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ni-woocommerce-sales-report-email/vulnerability/wordpress-ni-woocommerce-sales-report-email-plugin-3-1-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x87r-h8fj-gvgf/GHSA-x87r-h8fj-gvgf.json b/advisories/unreviewed/2025/03/GHSA-x87r-h8fj-gvgf/GHSA-x87r-h8fj-gvgf.json new file mode 100644 index 00000000000..d2c743ba1a8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x87r-h8fj-gvgf/GHSA-x87r-h8fj-gvgf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x87r-h8fj-gvgf", + "modified": "2025-03-03T15:31:26Z", + "published": "2025-03-03T15:31:26Z", + "aliases": [ + "CVE-2025-23425" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in marekki Marekkis Watermark allows Reflected XSS. This issue affects Marekkis Watermark: from n/a through 0.9.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23425" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/marekkis-watermark/vulnerability/wordpress-marekkis-watermark-plugin-0-9-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xf59-wfpq-q69c/GHSA-xf59-wfpq-q69c.json b/advisories/unreviewed/2025/03/GHSA-xf59-wfpq-q69c/GHSA-xf59-wfpq-q69c.json new file mode 100644 index 00000000000..5c4186acc9e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xf59-wfpq-q69c/GHSA-xf59-wfpq-q69c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xf59-wfpq-q69c", + "modified": "2025-03-03T15:31:30Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-23904" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Rebrand Fluent Forms allows Reflected XSS. This issue affects Rebrand Fluent Forms: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23904" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rebrand-fluent-forms/vulnerability/wordpress-rebrand-fluent-forms-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xfmq-9fj2-xhq6/GHSA-xfmq-9fj2-xhq6.json b/advisories/unreviewed/2025/03/GHSA-xfmq-9fj2-xhq6/GHSA-xfmq-9fj2-xhq6.json new file mode 100644 index 00000000000..0f21fd982c1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xfmq-9fj2-xhq6/GHSA-xfmq-9fj2-xhq6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xfmq-9fj2-xhq6", + "modified": "2025-03-03T15:31:32Z", + "published": "2025-03-03T15:31:32Z", + "aliases": [ + "CVE-2025-25164" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Meta Accelerator allows Reflected XSS. This issue affects Meta Accelerator: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25164" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/meta-accelerator/vulnerability/wordpress-meta-accelerator-plugin-1-0-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xgv7-g262-2p9p/GHSA-xgv7-g262-2p9p.json b/advisories/unreviewed/2025/03/GHSA-xgv7-g262-2p9p/GHSA-xgv7-g262-2p9p.json new file mode 100644 index 00000000000..7d14ccaec13 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xgv7-g262-2p9p/GHSA-xgv7-g262-2p9p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgv7-g262-2p9p", + "modified": "2025-03-03T15:31:30Z", + "published": "2025-03-03T15:31:30Z", + "aliases": [ + "CVE-2025-23945" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound Popliup allows PHP Local File Inclusion. This issue affects Popliup: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23945" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/popliup/vulnerability/wordpress-popliup-plugin-1-1-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xh6j-pwvm-gcgm/GHSA-xh6j-pwvm-gcgm.json b/advisories/unreviewed/2025/03/GHSA-xh6j-pwvm-gcgm/GHSA-xh6j-pwvm-gcgm.json new file mode 100644 index 00000000000..fca01bd5f6a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xh6j-pwvm-gcgm/GHSA-xh6j-pwvm-gcgm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh6j-pwvm-gcgm", + "modified": "2025-03-03T15:31:34Z", + "published": "2025-03-03T15:31:34Z", + "aliases": [ + "CVE-2025-27273" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in winking Affiliate Links Manager allows Reflected XSS. This issue affects Affiliate Links Manager: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27273" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/affiliate-links-manager/vulnerability/wordpress-affiliate-links-manager-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xp69-fprf-g2x6/GHSA-xp69-fprf-g2x6.json b/advisories/unreviewed/2025/03/GHSA-xp69-fprf-g2x6/GHSA-xp69-fprf-g2x6.json new file mode 100644 index 00000000000..0d916a3b3cf --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xp69-fprf-g2x6/GHSA-xp69-fprf-g2x6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xp69-fprf-g2x6", + "modified": "2025-03-03T15:31:29Z", + "published": "2025-03-03T15:31:29Z", + "aliases": [ + "CVE-2025-23635" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mobde3net ePermissions allows Reflected XSS. This issue affects ePermissions: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23635" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/epermissions/vulnerability/wordpress-epermissions-plugin-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xp77-7ppq-j5jg/GHSA-xp77-7ppq-j5jg.json b/advisories/unreviewed/2025/03/GHSA-xp77-7ppq-j5jg/GHSA-xp77-7ppq-j5jg.json new file mode 100644 index 00000000000..a671b24f991 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xp77-7ppq-j5jg/GHSA-xp77-7ppq-j5jg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xp77-7ppq-j5jg", + "modified": "2025-03-03T15:31:32Z", + "published": "2025-03-03T15:31:31Z", + "aliases": [ + "CVE-2025-25129" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Callback Request allows Reflected XSS. This issue affects Callback Request: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25129" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/callback-request/vulnerability/wordpress-callback-request-plugin-1-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xpcx-qq6q-cr7f/GHSA-xpcx-qq6q-cr7f.json b/advisories/unreviewed/2025/03/GHSA-xpcx-qq6q-cr7f/GHSA-xpcx-qq6q-cr7f.json new file mode 100644 index 00000000000..3a0f9211240 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xpcx-qq6q-cr7f/GHSA-xpcx-qq6q-cr7f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpcx-qq6q-cr7f", + "modified": "2025-03-03T15:31:29Z", + "published": "2025-03-03T15:31:29Z", + "aliases": [ + "CVE-2025-23616" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Canalplan allows Reflected XSS. This issue affects Canalplan: from n/a through 5.31.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23616" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/canalplan-ac/vulnerability/wordpress-canalplan-plugin-5-31-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xq8m-cj64-vrmm/GHSA-xq8m-cj64-vrmm.json b/advisories/unreviewed/2025/03/GHSA-xq8m-cj64-vrmm/GHSA-xq8m-cj64-vrmm.json new file mode 100644 index 00000000000..0b362720336 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xq8m-cj64-vrmm/GHSA-xq8m-cj64-vrmm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xq8m-cj64-vrmm", + "modified": "2025-03-03T15:31:31Z", + "published": "2025-03-03T15:31:31Z", + "aliases": [ + "CVE-2025-25084" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound UniTimetable allows Stored XSS. This issue affects UniTimetable: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25084" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/unitimetable/vulnerability/wordpress-unitimetable-plugin-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xr9c-3v5w-98m9/GHSA-xr9c-3v5w-98m9.json b/advisories/unreviewed/2025/03/GHSA-xr9c-3v5w-98m9/GHSA-xr9c-3v5w-98m9.json new file mode 100644 index 00000000000..128890f25d7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xr9c-3v5w-98m9/GHSA-xr9c-3v5w-98m9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr9c-3v5w-98m9", + "modified": "2025-03-03T15:31:28Z", + "published": "2025-03-03T15:31:28Z", + "aliases": [ + "CVE-2025-23556" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Push Envoy Notifications allows Reflected XSS. This issue affects Push Envoy Notifications: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23556" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/push-envoy/vulnerability/wordpress-push-envoy-notifications-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T14:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xxc4-h4cm-j5r2/GHSA-xxc4-h4cm-j5r2.json b/advisories/unreviewed/2025/03/GHSA-xxc4-h4cm-j5r2/GHSA-xxc4-h4cm-j5r2.json new file mode 100644 index 00000000000..30b7f8b6a42 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xxc4-h4cm-j5r2/GHSA-xxc4-h4cm-j5r2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxc4-h4cm-j5r2", + "modified": "2025-03-03T15:31:34Z", + "published": "2025-03-03T15:31:34Z", + "aliases": [ + "CVE-2024-45780" + ], + "details": "A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45780" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-45780" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345856" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-03T15:15:14Z" + } +} \ No newline at end of file