From 137be9c35ad97126669f732bf13a4ce49cf300de Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 13 Aug 2024 00:33:08 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-hjxq-w2ww-jfj3.json | 11 ++-- .../GHSA-mfh5-9vgh-ffpg.json | 11 ++-- .../GHSA-mjcw-8498-wxpx.json | 11 ++-- .../GHSA-238q-c368-qf6g.json | 38 +++++++++++++ .../GHSA-253q-prr2-4prx.json | 38 +++++++++++++ .../GHSA-35p7-wx7h-98pq.json | 38 +++++++++++++ .../GHSA-3jf5-fxfr-q6hw.json | 38 +++++++++++++ .../GHSA-42r5-3wrh-vr57.json | 38 +++++++++++++ .../GHSA-4hx4-r3cj-464q.json | 38 +++++++++++++ .../GHSA-4p53-mpmm-4v8c.json | 38 +++++++++++++ .../GHSA-4r3v-6hh6-vhf4.json | 38 +++++++++++++ .../GHSA-4x9c-93h9-hxw7.json | 38 +++++++++++++ .../GHSA-5g2j-p4hq-4627.json | 38 +++++++++++++ .../GHSA-5wpf-wxvf-787w.json | 38 +++++++++++++ .../GHSA-62rm-j346-7g82.json | 38 +++++++++++++ .../GHSA-7wcw-mh3f-j3v9.json | 38 +++++++++++++ .../GHSA-86jj-69gr-c7xx.json | 38 +++++++++++++ .../GHSA-8qqw-ccjh-qmvf.json | 11 ++-- .../GHSA-9hpc-rhq4-hv5w.json | 38 +++++++++++++ .../GHSA-c523-x9rf-5jqh.json | 38 +++++++++++++ .../GHSA-f8cm-7v7p-g823.json | 54 +++++++++++++++++++ .../GHSA-fjmc-rvjj-hw23.json | 38 +++++++++++++ .../GHSA-g6hr-hrc3-q5hm.json | 38 +++++++++++++ .../GHSA-j254-m6gh-r4h8.json | 38 +++++++++++++ .../GHSA-j576-h236-74p8.json | 38 +++++++++++++ .../GHSA-j9c3-x4qh-q8j7.json | 38 +++++++++++++ .../GHSA-jxpj-m239-f4pp.json | 38 +++++++++++++ .../GHSA-m5gc-px62-qc98.json | 38 +++++++++++++ .../GHSA-m9j6-7x3m-8fjr.json | 38 +++++++++++++ .../GHSA-mc92-gcwr-fv2g.json | 38 +++++++++++++ .../GHSA-p5cq-hvqv-cwm3.json | 38 +++++++++++++ .../GHSA-pcp7-q64v-6h9p.json | 38 +++++++++++++ .../GHSA-px5h-8vph-x647.json | 38 +++++++++++++ .../GHSA-q647-gxwr-vpp5.json | 38 +++++++++++++ .../GHSA-qg3q-h7pr-4qj6.json | 46 ++++++++++++++++ .../GHSA-qgj5-f662-2hqv.json | 38 +++++++++++++ .../GHSA-rxwh-v4c9-c8v7.json | 38 +++++++++++++ .../GHSA-vhv2-gmg8-h5mc.json | 38 +++++++++++++ .../GHSA-wmmm-gjhq-jq82.json | 38 +++++++++++++ .../GHSA-xmf4-vfcf-qcjg.json | 54 +++++++++++++++++++ 40 files changed, 1436 insertions(+), 16 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-238q-c368-qf6g/GHSA-238q-c368-qf6g.json create mode 100644 advisories/unreviewed/2024/08/GHSA-253q-prr2-4prx/GHSA-253q-prr2-4prx.json create mode 100644 advisories/unreviewed/2024/08/GHSA-35p7-wx7h-98pq/GHSA-35p7-wx7h-98pq.json create mode 100644 advisories/unreviewed/2024/08/GHSA-3jf5-fxfr-q6hw/GHSA-3jf5-fxfr-q6hw.json create mode 100644 advisories/unreviewed/2024/08/GHSA-42r5-3wrh-vr57/GHSA-42r5-3wrh-vr57.json create mode 100644 advisories/unreviewed/2024/08/GHSA-4hx4-r3cj-464q/GHSA-4hx4-r3cj-464q.json create mode 100644 advisories/unreviewed/2024/08/GHSA-4p53-mpmm-4v8c/GHSA-4p53-mpmm-4v8c.json create mode 100644 advisories/unreviewed/2024/08/GHSA-4r3v-6hh6-vhf4/GHSA-4r3v-6hh6-vhf4.json create mode 100644 advisories/unreviewed/2024/08/GHSA-4x9c-93h9-hxw7/GHSA-4x9c-93h9-hxw7.json create mode 100644 advisories/unreviewed/2024/08/GHSA-5g2j-p4hq-4627/GHSA-5g2j-p4hq-4627.json create mode 100644 advisories/unreviewed/2024/08/GHSA-5wpf-wxvf-787w/GHSA-5wpf-wxvf-787w.json create mode 100644 advisories/unreviewed/2024/08/GHSA-62rm-j346-7g82/GHSA-62rm-j346-7g82.json create mode 100644 advisories/unreviewed/2024/08/GHSA-7wcw-mh3f-j3v9/GHSA-7wcw-mh3f-j3v9.json create mode 100644 advisories/unreviewed/2024/08/GHSA-86jj-69gr-c7xx/GHSA-86jj-69gr-c7xx.json create mode 100644 advisories/unreviewed/2024/08/GHSA-9hpc-rhq4-hv5w/GHSA-9hpc-rhq4-hv5w.json create mode 100644 advisories/unreviewed/2024/08/GHSA-c523-x9rf-5jqh/GHSA-c523-x9rf-5jqh.json create mode 100644 advisories/unreviewed/2024/08/GHSA-f8cm-7v7p-g823/GHSA-f8cm-7v7p-g823.json create mode 100644 advisories/unreviewed/2024/08/GHSA-fjmc-rvjj-hw23/GHSA-fjmc-rvjj-hw23.json create mode 100644 advisories/unreviewed/2024/08/GHSA-g6hr-hrc3-q5hm/GHSA-g6hr-hrc3-q5hm.json create mode 100644 advisories/unreviewed/2024/08/GHSA-j254-m6gh-r4h8/GHSA-j254-m6gh-r4h8.json create mode 100644 advisories/unreviewed/2024/08/GHSA-j576-h236-74p8/GHSA-j576-h236-74p8.json create mode 100644 advisories/unreviewed/2024/08/GHSA-j9c3-x4qh-q8j7/GHSA-j9c3-x4qh-q8j7.json create mode 100644 advisories/unreviewed/2024/08/GHSA-jxpj-m239-f4pp/GHSA-jxpj-m239-f4pp.json create mode 100644 advisories/unreviewed/2024/08/GHSA-m5gc-px62-qc98/GHSA-m5gc-px62-qc98.json create mode 100644 advisories/unreviewed/2024/08/GHSA-m9j6-7x3m-8fjr/GHSA-m9j6-7x3m-8fjr.json create mode 100644 advisories/unreviewed/2024/08/GHSA-mc92-gcwr-fv2g/GHSA-mc92-gcwr-fv2g.json create mode 100644 advisories/unreviewed/2024/08/GHSA-p5cq-hvqv-cwm3/GHSA-p5cq-hvqv-cwm3.json create mode 100644 advisories/unreviewed/2024/08/GHSA-pcp7-q64v-6h9p/GHSA-pcp7-q64v-6h9p.json create mode 100644 advisories/unreviewed/2024/08/GHSA-px5h-8vph-x647/GHSA-px5h-8vph-x647.json create mode 100644 advisories/unreviewed/2024/08/GHSA-q647-gxwr-vpp5/GHSA-q647-gxwr-vpp5.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qg3q-h7pr-4qj6/GHSA-qg3q-h7pr-4qj6.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qgj5-f662-2hqv/GHSA-qgj5-f662-2hqv.json create mode 100644 advisories/unreviewed/2024/08/GHSA-rxwh-v4c9-c8v7/GHSA-rxwh-v4c9-c8v7.json create mode 100644 advisories/unreviewed/2024/08/GHSA-vhv2-gmg8-h5mc/GHSA-vhv2-gmg8-h5mc.json create mode 100644 advisories/unreviewed/2024/08/GHSA-wmmm-gjhq-jq82/GHSA-wmmm-gjhq-jq82.json create mode 100644 advisories/unreviewed/2024/08/GHSA-xmf4-vfcf-qcjg/GHSA-xmf4-vfcf-qcjg.json diff --git a/advisories/unreviewed/2024/04/GHSA-hjxq-w2ww-jfj3/GHSA-hjxq-w2ww-jfj3.json b/advisories/unreviewed/2024/04/GHSA-hjxq-w2ww-jfj3/GHSA-hjxq-w2ww-jfj3.json index aba6d60fe8c..2f893db478a 100644 --- a/advisories/unreviewed/2024/04/GHSA-hjxq-w2ww-jfj3/GHSA-hjxq-w2ww-jfj3.json +++ b/advisories/unreviewed/2024/04/GHSA-hjxq-w2ww-jfj3/GHSA-hjxq-w2ww-jfj3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hjxq-w2ww-jfj3", - "modified": "2024-04-16T18:31:34Z", + "modified": "2024-08-13T00:31:42Z", "published": "2024-04-16T18:31:34Z", "aliases": [ "CVE-2024-3856" ], "details": "A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects Firefox < 125.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-16T16:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-mfh5-9vgh-ffpg/GHSA-mfh5-9vgh-ffpg.json b/advisories/unreviewed/2024/04/GHSA-mfh5-9vgh-ffpg/GHSA-mfh5-9vgh-ffpg.json index af500f60dad..d052d421399 100644 --- a/advisories/unreviewed/2024/04/GHSA-mfh5-9vgh-ffpg/GHSA-mfh5-9vgh-ffpg.json +++ b/advisories/unreviewed/2024/04/GHSA-mfh5-9vgh-ffpg/GHSA-mfh5-9vgh-ffpg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mfh5-9vgh-ffpg", - "modified": "2024-04-03T09:30:32Z", + "modified": "2024-08-13T00:31:41Z", "published": "2024-04-03T09:30:32Z", "aliases": [ "CVE-2023-35764" ], "details": "Insufficient verification of data authenticity issue in Survey Maker prior to 3.6.4 allows a remote unauthenticated attacker to spoof an IP address when posting.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-345" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T08:15:49Z" diff --git a/advisories/unreviewed/2024/04/GHSA-mjcw-8498-wxpx/GHSA-mjcw-8498-wxpx.json b/advisories/unreviewed/2024/04/GHSA-mjcw-8498-wxpx/GHSA-mjcw-8498-wxpx.json index 178c9cde6ad..64f221c14bf 100644 --- a/advisories/unreviewed/2024/04/GHSA-mjcw-8498-wxpx/GHSA-mjcw-8498-wxpx.json +++ b/advisories/unreviewed/2024/04/GHSA-mjcw-8498-wxpx/GHSA-mjcw-8498-wxpx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mjcw-8498-wxpx", - "modified": "2024-04-04T00:33:13Z", + "modified": "2024-08-13T00:31:42Z", "published": "2024-04-04T00:33:13Z", "aliases": [ "CVE-2024-29167" ], "details": "SVR-116 firmware version 1.6.0.30028871 allows a remote authenticated attacker with an administrative privilege to execute arbitrary OS commands by sending a specially crafted request to the product.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T00:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-238q-c368-qf6g/GHSA-238q-c368-qf6g.json b/advisories/unreviewed/2024/08/GHSA-238q-c368-qf6g/GHSA-238q-c368-qf6g.json new file mode 100644 index 00000000000..f50ece5e8a5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-238q-c368-qf6g/GHSA-238q-c368-qf6g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-238q-c368-qf6g", + "modified": "2024-08-13T00:31:43Z", + "published": "2024-08-13T00:31:43Z", + "aliases": [ + "CVE-2024-43137" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WappPress Team WappPress allows Stored XSS.This issue affects WappPress: from n/a through 6.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43137" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wapppress-builds-android-app-for-website/wordpress-wapppress-basic-plugin-6-0-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T23:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-253q-prr2-4prx/GHSA-253q-prr2-4prx.json b/advisories/unreviewed/2024/08/GHSA-253q-prr2-4prx/GHSA-253q-prr2-4prx.json new file mode 100644 index 00000000000..761a07ba104 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-253q-prr2-4prx/GHSA-253q-prr2-4prx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-253q-prr2-4prx", + "modified": "2024-08-13T00:31:43Z", + "published": "2024-08-13T00:31:43Z", + "aliases": [ + "CVE-2024-37930" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in ThemeSphere SmartMag allows Excavation, Accessing Functionality Not Properly Constrained by ACLs.This issue affects SmartMag: from n/a through 9.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37930" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/smartmag-responsive-retina-wordpress-magazine/wordpress-smartmag-theme-9-3-0-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T23:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-35p7-wx7h-98pq/GHSA-35p7-wx7h-98pq.json b/advisories/unreviewed/2024/08/GHSA-35p7-wx7h-98pq/GHSA-35p7-wx7h-98pq.json new file mode 100644 index 00000000000..ade68ae7021 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-35p7-wx7h-98pq/GHSA-35p7-wx7h-98pq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35p7-wx7h-98pq", + "modified": "2024-08-13T00:31:43Z", + "published": "2024-08-13T00:31:43Z", + "aliases": [ + "CVE-2024-43125" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Table Builder WP Table Builder – WordPress Table Plugin allows Stored XSS.This issue affects WP Table Builder – WordPress Table Plugin: from n/a through 1.4.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43125" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-table-builder/wordpress-wp-table-builder-plugin-1-4-15-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T23:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3jf5-fxfr-q6hw/GHSA-3jf5-fxfr-q6hw.json b/advisories/unreviewed/2024/08/GHSA-3jf5-fxfr-q6hw/GHSA-3jf5-fxfr-q6hw.json new file mode 100644 index 00000000000..541a0a53bfe --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3jf5-fxfr-q6hw/GHSA-3jf5-fxfr-q6hw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jf5-fxfr-q6hw", + "modified": "2024-08-13T00:31:42Z", + "published": "2024-08-13T00:31:42Z", + "aliases": [ + "CVE-2024-43163" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Parcel Panel ParcelPanel allows Reflected XSS.This issue affects ParcelPanel: from n/a through 4.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43163" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/parcelpanel/wordpress-parcelpanel-plugin-4-3-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-42r5-3wrh-vr57/GHSA-42r5-3wrh-vr57.json b/advisories/unreviewed/2024/08/GHSA-42r5-3wrh-vr57/GHSA-42r5-3wrh-vr57.json new file mode 100644 index 00000000000..923e868fd0a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-42r5-3wrh-vr57/GHSA-42r5-3wrh-vr57.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42r5-3wrh-vr57", + "modified": "2024-08-13T00:31:43Z", + "published": "2024-08-13T00:31:43Z", + "aliases": [ + "CVE-2024-43139" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Antoine Hurkmans Football Pool allows Stored XSS.This issue affects Football Pool: from n/a through 2.11.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43139" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/football-pool/wordpress-football-pool-plugin-2-11-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T23:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4hx4-r3cj-464q/GHSA-4hx4-r3cj-464q.json b/advisories/unreviewed/2024/08/GHSA-4hx4-r3cj-464q/GHSA-4hx4-r3cj-464q.json new file mode 100644 index 00000000000..e35b08d695f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4hx4-r3cj-464q/GHSA-4hx4-r3cj-464q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hx4-r3cj-464q", + "modified": "2024-08-13T00:31:43Z", + "published": "2024-08-13T00:31:43Z", + "aliases": [ + "CVE-2024-37924" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wp2speed WP2Speed Faster allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP2Speed Faster: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37924" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp2speed/wordpress-wp2speed-faster-optimize-pagespeed-insights-score-90-100-plugin-1-0-1-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T23:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4p53-mpmm-4v8c/GHSA-4p53-mpmm-4v8c.json b/advisories/unreviewed/2024/08/GHSA-4p53-mpmm-4v8c/GHSA-4p53-mpmm-4v8c.json new file mode 100644 index 00000000000..d2d289f183e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4p53-mpmm-4v8c/GHSA-4p53-mpmm-4v8c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p53-mpmm-4v8c", + "modified": "2024-08-13T00:31:42Z", + "published": "2024-08-13T00:31:42Z", + "aliases": [ + "CVE-2024-43156" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AddonMaster Post Grid Master allows Reflected XSS.This issue affects Post Grid Master: from n/a through 3.4.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43156" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ajax-filter-posts/wordpress-post-grid-master-plugin-3-4-10-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4r3v-6hh6-vhf4/GHSA-4r3v-6hh6-vhf4.json b/advisories/unreviewed/2024/08/GHSA-4r3v-6hh6-vhf4/GHSA-4r3v-6hh6-vhf4.json new file mode 100644 index 00000000000..2e60e11ae30 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4r3v-6hh6-vhf4/GHSA-4r3v-6hh6-vhf4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r3v-6hh6-vhf4", + "modified": "2024-08-13T00:31:42Z", + "published": "2024-08-13T00:31:42Z", + "aliases": [ + "CVE-2024-43152" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in iberezansky 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery allows Stored XSS.This issue affects 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery: from n/a through 1.15.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43152" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/interactive-3d-flipbook-powered-physics-engine/wordpress-3d-flipbook-plugin-1-15-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4x9c-93h9-hxw7/GHSA-4x9c-93h9-hxw7.json b/advisories/unreviewed/2024/08/GHSA-4x9c-93h9-hxw7/GHSA-4x9c-93h9-hxw7.json new file mode 100644 index 00000000000..cb22ec9893e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4x9c-93h9-hxw7/GHSA-4x9c-93h9-hxw7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x9c-93h9-hxw7", + "modified": "2024-08-13T00:31:42Z", + "published": "2024-08-13T00:31:42Z", + "aliases": [ + "CVE-2024-43216" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Patrick Posner Filr – Secure document library allows Stored XSS.This issue affects Filr – Secure document library: from n/a through 1.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43216" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/filr-protection/wordpress-filr-secure-document-library-plugin-1-2-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T22:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5g2j-p4hq-4627/GHSA-5g2j-p4hq-4627.json b/advisories/unreviewed/2024/08/GHSA-5g2j-p4hq-4627/GHSA-5g2j-p4hq-4627.json new file mode 100644 index 00000000000..caa60f70e78 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5g2j-p4hq-4627/GHSA-5g2j-p4hq-4627.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g2j-p4hq-4627", + "modified": "2024-08-13T00:31:43Z", + "published": "2024-08-13T00:31:43Z", + "aliases": [ + "CVE-2024-43124" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Iqonic Design Graphina allows Stored XSS.This issue affects Graphina: from n/a through 1.8.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43124" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/graphina-elementor-charts-and-graphs/wordpress-graphina-plugin-1-8-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T23:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5wpf-wxvf-787w/GHSA-5wpf-wxvf-787w.json b/advisories/unreviewed/2024/08/GHSA-5wpf-wxvf-787w/GHSA-5wpf-wxvf-787w.json new file mode 100644 index 00000000000..5f13ce2b3e5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5wpf-wxvf-787w/GHSA-5wpf-wxvf-787w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wpf-wxvf-787w", + "modified": "2024-08-13T00:31:42Z", + "published": "2024-08-13T00:31:42Z", + "aliases": [ + "CVE-2024-43217" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pierre Lebedel Kodex Posts likes allows Reflected XSS.This issue affects Kodex Posts likes: from n/a through 2.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43217" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/kodex-posts-likes/wordpress-kodex-posts-likes-plugin-2-5-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T22:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-62rm-j346-7g82/GHSA-62rm-j346-7g82.json b/advisories/unreviewed/2024/08/GHSA-62rm-j346-7g82/GHSA-62rm-j346-7g82.json new file mode 100644 index 00000000000..9de75fa9dfb --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-62rm-j346-7g82/GHSA-62rm-j346-7g82.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62rm-j346-7g82", + "modified": "2024-08-13T00:31:42Z", + "published": "2024-08-13T00:31:42Z", + "aliases": [ + "CVE-2024-43161" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Averta Depicter Slider allows Stored XSS.This issue affects Depicter Slider: from n/a through 3.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43161" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/depicter/wordpress-slider-popup-builder-by-depicter-plugin-3-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7wcw-mh3f-j3v9/GHSA-7wcw-mh3f-j3v9.json b/advisories/unreviewed/2024/08/GHSA-7wcw-mh3f-j3v9/GHSA-7wcw-mh3f-j3v9.json new file mode 100644 index 00000000000..723989ed6aa --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7wcw-mh3f-j3v9/GHSA-7wcw-mh3f-j3v9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wcw-mh3f-j3v9", + "modified": "2024-08-13T00:31:42Z", + "published": "2024-08-13T00:31:42Z", + "aliases": [ + "CVE-2024-43155" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins ComboBlocks allows Stored XSS.This issue affects ComboBlocks: from n/a through 2.2.86.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43155" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/post-grid/wordpress-comboblocks-plugin-2-2-86-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-86jj-69gr-c7xx/GHSA-86jj-69gr-c7xx.json b/advisories/unreviewed/2024/08/GHSA-86jj-69gr-c7xx/GHSA-86jj-69gr-c7xx.json new file mode 100644 index 00000000000..93a3a3a858a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-86jj-69gr-c7xx/GHSA-86jj-69gr-c7xx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86jj-69gr-c7xx", + "modified": "2024-08-13T00:31:43Z", + "published": "2024-08-13T00:31:43Z", + "aliases": [ + "CVE-2024-43149" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Tooltip Glossary allows Stored XSS.This issue affects CM Tooltip Glossary: from n/a through 4.3.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43149" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/enhanced-tooltipglossary/wordpress-cm-tooltip-glossary-plugin-4-3-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T23:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8qqw-ccjh-qmvf/GHSA-8qqw-ccjh-qmvf.json b/advisories/unreviewed/2024/08/GHSA-8qqw-ccjh-qmvf/GHSA-8qqw-ccjh-qmvf.json index 9c7226ab6bf..27648e22b6c 100644 --- a/advisories/unreviewed/2024/08/GHSA-8qqw-ccjh-qmvf/GHSA-8qqw-ccjh-qmvf.json +++ b/advisories/unreviewed/2024/08/GHSA-8qqw-ccjh-qmvf/GHSA-8qqw-ccjh-qmvf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8qqw-ccjh-qmvf", - "modified": "2024-08-12T15:30:49Z", + "modified": "2024-08-13T00:31:42Z", "published": "2024-08-12T15:30:49Z", "aliases": [ "CVE-2024-37826" ], "details": "A NULL pointer dereference in vercot Serva v4.6.0 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-12T13:38:23Z" diff --git a/advisories/unreviewed/2024/08/GHSA-9hpc-rhq4-hv5w/GHSA-9hpc-rhq4-hv5w.json b/advisories/unreviewed/2024/08/GHSA-9hpc-rhq4-hv5w/GHSA-9hpc-rhq4-hv5w.json new file mode 100644 index 00000000000..4a91de800a7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9hpc-rhq4-hv5w/GHSA-9hpc-rhq4-hv5w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hpc-rhq4-hv5w", + "modified": "2024-08-13T00:31:42Z", + "published": "2024-08-13T00:31:42Z", + "aliases": [ + "CVE-2024-43210" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LA-Studio LA-Studio Element Kit for Elementor allows Stored XSS.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.3.9.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43210" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/lastudio-element-kit/wordpress-la-studio-element-kit-for-elementor-plugin-1-3-9-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c523-x9rf-5jqh/GHSA-c523-x9rf-5jqh.json b/advisories/unreviewed/2024/08/GHSA-c523-x9rf-5jqh/GHSA-c523-x9rf-5jqh.json new file mode 100644 index 00000000000..c9e00b017c7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c523-x9rf-5jqh/GHSA-c523-x9rf-5jqh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c523-x9rf-5jqh", + "modified": "2024-08-13T00:31:42Z", + "published": "2024-08-13T00:31:42Z", + "aliases": [ + "CVE-2024-43164" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Blockspare allows Stored XSS.This issue affects Blockspare: from n/a through 3.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43164" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/blockspare/wordpress-blockspare-plugin-3-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f8cm-7v7p-g823/GHSA-f8cm-7v7p-g823.json b/advisories/unreviewed/2024/08/GHSA-f8cm-7v7p-g823/GHSA-f8cm-7v7p-g823.json new file mode 100644 index 00000000000..06a70118042 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f8cm-7v7p-g823/GHSA-f8cm-7v7p-g823.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8cm-7v7p-g823", + "modified": "2024-08-13T00:31:43Z", + "published": "2024-08-13T00:31:43Z", + "aliases": [ + "CVE-2024-7706" + ], + "details": "A vulnerability was found in Fujian mwcms 1.0.0. It has been rated as critical. Affected by this issue is the function uploadimage of the file /uploadfile.html. The manipulation of the argument upfile leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7706" + }, + { + "type": "WEB", + "url": "https://github.com/DeepMountains/Mirage/blob/main/CVE12-2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274184" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274184" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.385651" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T23:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fjmc-rvjj-hw23/GHSA-fjmc-rvjj-hw23.json b/advisories/unreviewed/2024/08/GHSA-fjmc-rvjj-hw23/GHSA-fjmc-rvjj-hw23.json new file mode 100644 index 00000000000..458bc7e352a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fjmc-rvjj-hw23/GHSA-fjmc-rvjj-hw23.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjmc-rvjj-hw23", + "modified": "2024-08-13T00:31:43Z", + "published": "2024-08-13T00:31:43Z", + "aliases": [ + "CVE-2024-43126" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce allows Reflected XSS.This issue affects Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce: from n/a through 2.6.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43126" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sender-net-automated-emails/wordpress-sender-newsletter-sms-and-email-marketing-automation-for-woocommerce-plugin-2-6-14-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T23:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g6hr-hrc3-q5hm/GHSA-g6hr-hrc3-q5hm.json b/advisories/unreviewed/2024/08/GHSA-g6hr-hrc3-q5hm/GHSA-g6hr-hrc3-q5hm.json new file mode 100644 index 00000000000..0132de6d9c1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g6hr-hrc3-q5hm/GHSA-g6hr-hrc3-q5hm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6hr-hrc3-q5hm", + "modified": "2024-08-13T00:31:42Z", + "published": "2024-08-13T00:31:42Z", + "aliases": [ + "CVE-2024-43225" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeLooks Enter Addons allows Stored XSS.This issue affects Enter Addons: from n/a through 2.1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43225" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/enteraddons/wordpress-enter-addons-plugin-2-1-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T22:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j254-m6gh-r4h8/GHSA-j254-m6gh-r4h8.json b/advisories/unreviewed/2024/08/GHSA-j254-m6gh-r4h8/GHSA-j254-m6gh-r4h8.json new file mode 100644 index 00000000000..84733d8fdcb --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j254-m6gh-r4h8/GHSA-j254-m6gh-r4h8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j254-m6gh-r4h8", + "modified": "2024-08-13T00:31:42Z", + "published": "2024-08-13T00:31:42Z", + "aliases": [ + "CVE-2024-43151" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder – Lite allows Stored XSS.This issue affects Ultimate Addons for Beaver Builder – Lite: from n/a through 1.5.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43151" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ultimate-addons-for-beaver-builder-lite/wordpress-ultimate-addons-for-beaver-builder-lite-plugin-1-5-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j576-h236-74p8/GHSA-j576-h236-74p8.json b/advisories/unreviewed/2024/08/GHSA-j576-h236-74p8/GHSA-j576-h236-74p8.json new file mode 100644 index 00000000000..033d7daec56 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j576-h236-74p8/GHSA-j576-h236-74p8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j576-h236-74p8", + "modified": "2024-08-13T00:31:43Z", + "published": "2024-08-13T00:31:43Z", + "aliases": [ + "CVE-2024-43133" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themify Themify Shortcodes allows Stored XSS.This issue affects Themify Shortcodes: from n/a through 2.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43133" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/themify-shortcodes/wordpress-themify-shortcodes-plugin-2-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T23:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j9c3-x4qh-q8j7/GHSA-j9c3-x4qh-q8j7.json b/advisories/unreviewed/2024/08/GHSA-j9c3-x4qh-q8j7/GHSA-j9c3-x4qh-q8j7.json new file mode 100644 index 00000000000..f53c38d3101 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j9c3-x4qh-q8j7/GHSA-j9c3-x4qh-q8j7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9c3-x4qh-q8j7", + "modified": "2024-08-13T00:31:43Z", + "published": "2024-08-13T00:31:43Z", + "aliases": [ + "CVE-2024-43226" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jeroen Sormani WP Dashboard Notes allows Stored XSS.This issue affects WP Dashboard Notes: from n/a through 1.0.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43226" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-dashboard-notes/wordpress-wp-dashboard-notes-plugin-1-0-11-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T22:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jxpj-m239-f4pp/GHSA-jxpj-m239-f4pp.json b/advisories/unreviewed/2024/08/GHSA-jxpj-m239-f4pp/GHSA-jxpj-m239-f4pp.json new file mode 100644 index 00000000000..76b0231ce84 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jxpj-m239-f4pp/GHSA-jxpj-m239-f4pp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxpj-m239-f4pp", + "modified": "2024-08-13T00:31:42Z", + "published": "2024-08-13T00:31:42Z", + "aliases": [ + "CVE-2024-43224" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yuri Baranov YaMaps for WordPress allows Stored XSS.This issue affects YaMaps for WordPress: from n/a through 0.6.27.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43224" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/yamaps/wordpress-yamaps-for-wordpress-plugin-plugin-0-6-27-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T22:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m5gc-px62-qc98/GHSA-m5gc-px62-qc98.json b/advisories/unreviewed/2024/08/GHSA-m5gc-px62-qc98/GHSA-m5gc-px62-qc98.json new file mode 100644 index 00000000000..15d7c0fd45b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m5gc-px62-qc98/GHSA-m5gc-px62-qc98.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5gc-px62-qc98", + "modified": "2024-08-13T00:31:42Z", + "published": "2024-08-13T00:31:42Z", + "aliases": [ + "CVE-2024-43220" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Reflected XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.26.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43220" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/form-maker/wordpress-form-maker-by-10web-plugin-1-15-26-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T22:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m9j6-7x3m-8fjr/GHSA-m9j6-7x3m-8fjr.json b/advisories/unreviewed/2024/08/GHSA-m9j6-7x3m-8fjr/GHSA-m9j6-7x3m-8fjr.json new file mode 100644 index 00000000000..1ab14d0ab70 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m9j6-7x3m-8fjr/GHSA-m9j6-7x3m-8fjr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9j6-7x3m-8fjr", + "modified": "2024-08-13T00:31:43Z", + "published": "2024-08-13T00:31:43Z", + "aliases": [ + "CVE-2024-43148" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in bPlugins StreamCast allows Stored XSS.This issue affects StreamCast: from n/a through 2.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43148" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/streamcast/wordpress-streamcast-2-2-3-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T23:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mc92-gcwr-fv2g/GHSA-mc92-gcwr-fv2g.json b/advisories/unreviewed/2024/08/GHSA-mc92-gcwr-fv2g/GHSA-mc92-gcwr-fv2g.json new file mode 100644 index 00000000000..f7cfdeeb5ac --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mc92-gcwr-fv2g/GHSA-mc92-gcwr-fv2g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc92-gcwr-fv2g", + "modified": "2024-08-13T00:31:43Z", + "published": "2024-08-13T00:31:43Z", + "aliases": [ + "CVE-2024-43123" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Techeshta Card Elements for Elementor allows Stored XSS.This issue affects Card Elements for Elementor: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43123" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/card-elements-for-elementor/wordpress-card-elements-for-elementor-plugin-1-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T23:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p5cq-hvqv-cwm3/GHSA-p5cq-hvqv-cwm3.json b/advisories/unreviewed/2024/08/GHSA-p5cq-hvqv-cwm3/GHSA-p5cq-hvqv-cwm3.json new file mode 100644 index 00000000000..cfa76124511 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p5cq-hvqv-cwm3/GHSA-p5cq-hvqv-cwm3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5cq-hvqv-cwm3", + "modified": "2024-08-13T00:31:43Z", + "published": "2024-08-13T00:31:43Z", + "aliases": [ + "CVE-2024-43147" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Merkulove Selection Lite allows Stored XSS.This issue affects Selection Lite: from n/a through 1.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43147" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/selection-lite/wordpress-selection-lite-plugin-1-11-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T23:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pcp7-q64v-6h9p/GHSA-pcp7-q64v-6h9p.json b/advisories/unreviewed/2024/08/GHSA-pcp7-q64v-6h9p/GHSA-pcp7-q64v-6h9p.json new file mode 100644 index 00000000000..2e328832831 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pcp7-q64v-6h9p/GHSA-pcp7-q64v-6h9p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcp7-q64v-6h9p", + "modified": "2024-08-13T00:31:43Z", + "published": "2024-08-13T00:31:43Z", + "aliases": [ + "CVE-2024-43127" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPFactory Products, Order & Customers Export for WooCommerce allows Reflected XSS.This issue affects Products, Order & Customers Export for WooCommerce: from n/a through 2.0.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43127" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/export-woocommerce/wordpress-products-order-customers-export-for-woocommerce-plugin-2-0-11-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T23:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-px5h-8vph-x647/GHSA-px5h-8vph-x647.json b/advisories/unreviewed/2024/08/GHSA-px5h-8vph-x647/GHSA-px5h-8vph-x647.json new file mode 100644 index 00000000000..cfd6cf9aa4b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-px5h-8vph-x647/GHSA-px5h-8vph-x647.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px5h-8vph-x647", + "modified": "2024-08-13T00:31:43Z", + "published": "2024-08-13T00:31:43Z", + "aliases": [ + "CVE-2024-43150" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xpro Xpro Elementor Addons allows Stored XSS.This issue affects Xpro Elementor Addons: from n/a through 1.4.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43150" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/xpro-elementor-addons/wordpress-xpro-elementor-addons-plugin-1-4-4-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T23:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q647-gxwr-vpp5/GHSA-q647-gxwr-vpp5.json b/advisories/unreviewed/2024/08/GHSA-q647-gxwr-vpp5/GHSA-q647-gxwr-vpp5.json new file mode 100644 index 00000000000..bdbaa5cd56a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q647-gxwr-vpp5/GHSA-q647-gxwr-vpp5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q647-gxwr-vpp5", + "modified": "2024-08-13T00:31:43Z", + "published": "2024-08-13T00:31:43Z", + "aliases": [ + "CVE-2024-7590" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainstorm Force Spectra allows Stored XSS.This issue affects Spectra: from n/a through 2.14.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7590" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ultimate-addons-for-gutenberg/wordpress-spectra-wordpress-gutenberg-blocks-plugin-2-14-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T22:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qg3q-h7pr-4qj6/GHSA-qg3q-h7pr-4qj6.json b/advisories/unreviewed/2024/08/GHSA-qg3q-h7pr-4qj6/GHSA-qg3q-h7pr-4qj6.json new file mode 100644 index 00000000000..7de3477aa99 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qg3q-h7pr-4qj6/GHSA-qg3q-h7pr-4qj6.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg3q-h7pr-4qj6", + "modified": "2024-08-13T00:31:42Z", + "published": "2024-08-13T00:31:42Z", + "aliases": [ + "CVE-2023-7066" + ], + "details": "The affected applications contain an out of bounds read past the end of \nan allocated structure while parsing specially crafted PDF files. This \ncould allow an attacker to execute code in the context of the current \nprocess.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7066" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-722010.html" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-193-03" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qgj5-f662-2hqv/GHSA-qgj5-f662-2hqv.json b/advisories/unreviewed/2024/08/GHSA-qgj5-f662-2hqv/GHSA-qgj5-f662-2hqv.json new file mode 100644 index 00000000000..ae81ab0c2c2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qgj5-f662-2hqv/GHSA-qgj5-f662-2hqv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgj5-f662-2hqv", + "modified": "2024-08-13T00:31:43Z", + "published": "2024-08-13T00:31:43Z", + "aliases": [ + "CVE-2024-43130" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Antoine Hurkmans Football Pool allows Stored XSS.This issue affects Football Pool: from n/a through 2.11.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43130" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/football-pool/wordpress-football-pool-plugin-2-11-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T23:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rxwh-v4c9-c8v7/GHSA-rxwh-v4c9-c8v7.json b/advisories/unreviewed/2024/08/GHSA-rxwh-v4c9-c8v7/GHSA-rxwh-v4c9-c8v7.json new file mode 100644 index 00000000000..4ef7dbd54e8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rxwh-v4c9-c8v7/GHSA-rxwh-v4c9-c8v7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxwh-v4c9-c8v7", + "modified": "2024-08-13T00:31:42Z", + "published": "2024-08-13T00:31:42Z", + "aliases": [ + "CVE-2024-43218" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mediavine Mediavine Control Panel allows Stored XSS.This issue affects Mediavine Control Panel: from n/a through 2.10.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43218" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mediavine-control-panel/wordpress-mediavine-control-panel-plugin-2-10-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T22:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vhv2-gmg8-h5mc/GHSA-vhv2-gmg8-h5mc.json b/advisories/unreviewed/2024/08/GHSA-vhv2-gmg8-h5mc/GHSA-vhv2-gmg8-h5mc.json new file mode 100644 index 00000000000..1715eca89d0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vhv2-gmg8-h5mc/GHSA-vhv2-gmg8-h5mc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhv2-gmg8-h5mc", + "modified": "2024-08-13T00:31:43Z", + "published": "2024-08-13T00:31:43Z", + "aliases": [ + "CVE-2024-35775" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Authentication vulnerability in Soliloquy Team Slider by Soliloquy allows Cross-Site Scripting (XSS).This issue affects Slider by Soliloquy: from n/a through 2.7.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35775" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/soliloquy-lite/wordpress-slider-by-soliloquy-plugin-2-7-6-broken-access-control-to-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T23:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-wmmm-gjhq-jq82/GHSA-wmmm-gjhq-jq82.json b/advisories/unreviewed/2024/08/GHSA-wmmm-gjhq-jq82/GHSA-wmmm-gjhq-jq82.json new file mode 100644 index 00000000000..f95ebb9440e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-wmmm-gjhq-jq82/GHSA-wmmm-gjhq-jq82.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmmm-gjhq-jq82", + "modified": "2024-08-13T00:31:42Z", + "published": "2024-08-13T00:31:42Z", + "aliases": [ + "CVE-2024-43213" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MultiVendorX WC Marketplace allows Reflected XSS.This issue affects WC Marketplace: from n/a through 4.1.17.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43213" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/dc-woocommerce-multi-vendor/wordpress-multivendorx-marketplace-plugin-4-1-17-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xmf4-vfcf-qcjg/GHSA-xmf4-vfcf-qcjg.json b/advisories/unreviewed/2024/08/GHSA-xmf4-vfcf-qcjg/GHSA-xmf4-vfcf-qcjg.json new file mode 100644 index 00000000000..4da2e9e3b36 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xmf4-vfcf-qcjg/GHSA-xmf4-vfcf-qcjg.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmf4-vfcf-qcjg", + "modified": "2024-08-13T00:31:43Z", + "published": "2024-08-13T00:31:43Z", + "aliases": [ + "CVE-2024-7705" + ], + "details": "A vulnerability was found in Fujian mwcms 1.0.0. It has been declared as critical. Affected by this vulnerability is the function uploadeditor of the file /uploadeditor.html?action=uploadimage of the component Image Upload. The manipulation of the argument upfile leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7705" + }, + { + "type": "WEB", + "url": "https://github.com/DeepMountains/Mirage/blob/main/CVE12-1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274183" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274183" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.385617" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-12T23:15:19Z" + } +} \ No newline at end of file