diff --git a/advisories/unreviewed/2024/05/GHSA-2vq7-8vvf-w66v/GHSA-2vq7-8vvf-w66v.json b/advisories/unreviewed/2024/05/GHSA-2vq7-8vvf-w66v/GHSA-2vq7-8vvf-w66v.json index 508b3a0f4e4..7a5599f388a 100644 --- a/advisories/unreviewed/2024/05/GHSA-2vq7-8vvf-w66v/GHSA-2vq7-8vvf-w66v.json +++ b/advisories/unreviewed/2024/05/GHSA-2vq7-8vvf-w66v/GHSA-2vq7-8vvf-w66v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2vq7-8vvf-w66v", - "modified": "2024-05-03T03:31:04Z", + "modified": "2025-03-28T12:31:34Z", "published": "2024-05-03T03:31:04Z", "aliases": [ "CVE-2023-42118" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://www.zerodayinitiative.com/advisories/ZDI-23-1472" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/03/28/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-28pf-m5g8-4rqm/GHSA-28pf-m5g8-4rqm.json b/advisories/unreviewed/2025/03/GHSA-28pf-m5g8-4rqm/GHSA-28pf-m5g8-4rqm.json new file mode 100644 index 00000000000..fb3618f259e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-28pf-m5g8-4rqm/GHSA-28pf-m5g8-4rqm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28pf-m5g8-4rqm", + "modified": "2025-03-28T12:31:36Z", + "published": "2025-03-28T12:31:36Z", + "aliases": [ + "CVE-2025-31076" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in WP Compress WP Compress for MainWP allows Server Side Request Forgery. This issue affects WP Compress for MainWP: from n/a through 6.30.03.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31076" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-compress-mainwp/vulnerability/wordpress-wp-compress-for-mainwp-plugin-6-30-03-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2975-qhjf-83mc/GHSA-2975-qhjf-83mc.json b/advisories/unreviewed/2025/03/GHSA-2975-qhjf-83mc/GHSA-2975-qhjf-83mc.json new file mode 100644 index 00000000000..db2fc9a307e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2975-qhjf-83mc/GHSA-2975-qhjf-83mc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2975-qhjf-83mc", + "modified": "2025-03-28T12:31:38Z", + "published": "2025-03-28T12:31:38Z", + "aliases": [ + "CVE-2025-31466" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Falcon Solutions Duplicate Page and Post allows Blind SQL Injection. This issue affects Duplicate Page and Post: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31466" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/duplicate-post-and-page/vulnerability/wordpress-duplicate-page-and-post-1-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-369r-wm99-xh2c/GHSA-369r-wm99-xh2c.json b/advisories/unreviewed/2025/03/GHSA-369r-wm99-xh2c/GHSA-369r-wm99-xh2c.json new file mode 100644 index 00000000000..32f5713d67e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-369r-wm99-xh2c/GHSA-369r-wm99-xh2c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-369r-wm99-xh2c", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-2870" + ], + "details": "Reflected Cross-Site Scripting (XSS) vulnerability in version 1.0 of the Clinic Queuing System. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the page parameter in /patient_side.php.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2870" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-clinic-queuing-system" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T11:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3g9m-qpqh-r4r2/GHSA-3g9m-qpqh-r4r2.json b/advisories/unreviewed/2025/03/GHSA-3g9m-qpqh-r4r2/GHSA-3g9m-qpqh-r4r2.json new file mode 100644 index 00000000000..39546c12cc5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3g9m-qpqh-r4r2/GHSA-3g9m-qpqh-r4r2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g9m-qpqh-r4r2", + "modified": "2025-03-28T12:31:38Z", + "published": "2025-03-28T12:31:38Z", + "aliases": [ + "CVE-2025-31459" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in PasqualePuzio Login Alert allows Stored XSS. This issue affects Login Alert: from n/a through 0.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31459" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/login-alert/vulnerability/wordpress-login-alert-plugin-0-2-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4442-448q-43m4/GHSA-4442-448q-43m4.json b/advisories/unreviewed/2025/03/GHSA-4442-448q-43m4/GHSA-4442-448q-43m4.json new file mode 100644 index 00000000000..bda43f48fdd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4442-448q-43m4/GHSA-4442-448q-43m4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4442-448q-43m4", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-31102" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel allows Reflected XSS. This issue affects Hostel: from n/a through 1.1.5.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31102" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hostel/vulnerability/wordpress-hostel-plugin-1-1-5-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T10:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-468r-gf65-prq5/GHSA-468r-gf65-prq5.json b/advisories/unreviewed/2025/03/GHSA-468r-gf65-prq5/GHSA-468r-gf65-prq5.json new file mode 100644 index 00000000000..abb3b635209 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-468r-gf65-prq5/GHSA-468r-gf65-prq5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-468r-gf65-prq5", + "modified": "2025-03-28T12:31:35Z", + "published": "2025-03-28T12:31:35Z", + "aliases": [ + "CVE-2024-12619" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1, allowing internal users to gain unauthorized access to internal projects.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12619" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2888260" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/509324" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1220" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-47pj-m3vr-845x/GHSA-47pj-m3vr-845x.json b/advisories/unreviewed/2025/03/GHSA-47pj-m3vr-845x/GHSA-47pj-m3vr-845x.json new file mode 100644 index 00000000000..38beef7e808 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-47pj-m3vr-845x/GHSA-47pj-m3vr-845x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47pj-m3vr-845x", + "modified": "2025-03-28T12:31:36Z", + "published": "2025-03-28T12:31:36Z", + "aliases": [ + "CVE-2025-31094" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in teastudio.pl WP Posts Carousel allows Stored XSS. This issue affects WP Posts Carousel: from n/a through 1.3.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31094" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-posts-carousel/vulnerability/wordpress-wp-posts-carousel-1-3-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T10:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4h29-vm8p-m838/GHSA-4h29-vm8p-m838.json b/advisories/unreviewed/2025/03/GHSA-4h29-vm8p-m838/GHSA-4h29-vm8p-m838.json new file mode 100644 index 00000000000..f86f6877d74 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4h29-vm8p-m838/GHSA-4h29-vm8p-m838.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4h29-vm8p-m838", + "modified": "2025-03-28T12:31:38Z", + "published": "2025-03-28T12:31:38Z", + "aliases": [ + "CVE-2025-31457" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Aurélien LWS LWS SMS allows Cross Site Request Forgery. This issue affects LWS SMS: from n/a through 2.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31457" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lws-sms/vulnerability/wordpress-lws-sms-2-4-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-526q-mff4-vhw6/GHSA-526q-mff4-vhw6.json b/advisories/unreviewed/2025/03/GHSA-526q-mff4-vhw6/GHSA-526q-mff4-vhw6.json new file mode 100644 index 00000000000..45dac6ab4d4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-526q-mff4-vhw6/GHSA-526q-mff4-vhw6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-526q-mff4-vhw6", + "modified": "2025-03-28T12:31:38Z", + "published": "2025-03-28T12:31:38Z", + "aliases": [ + "CVE-2025-31460" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in danielmuldernl OmniLeads Scripts and Tags Manager allows Stored XSS. This issue affects OmniLeads Scripts and Tags Manager: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31460" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/omnileads-scripts-and-tags-manager/vulnerability/wordpress-omnileads-scripts-and-tags-manager-plugin-1-3-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-53xg-8j7j-pf64/GHSA-53xg-8j7j-pf64.json b/advisories/unreviewed/2025/03/GHSA-53xg-8j7j-pf64/GHSA-53xg-8j7j-pf64.json new file mode 100644 index 00000000000..a119655612b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-53xg-8j7j-pf64/GHSA-53xg-8j7j-pf64.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53xg-8j7j-pf64", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-31435" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Efficient Scripts Microblog Poster allows Stored XSS. This issue affects Microblog Poster: from n/a through 2.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31435" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/microblog-poster/vulnerability/wordpress-microblog-poster-plugin-2-1-6-cross-site-request-forgery-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5c4w-p329-fchf/GHSA-5c4w-p329-fchf.json b/advisories/unreviewed/2025/03/GHSA-5c4w-p329-fchf/GHSA-5c4w-p329-fchf.json new file mode 100644 index 00000000000..545b5a99a49 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5c4w-p329-fchf/GHSA-5c4w-p329-fchf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c4w-p329-fchf", + "modified": "2025-03-28T12:31:38Z", + "published": "2025-03-28T12:31:38Z", + "aliases": [ + "CVE-2025-31474" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in matthewprice1178 WP Database Optimizer allows Cross Site Request Forgery. This issue affects WP Database Optimizer: from n/a through 1.2.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31474" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-database-optimizer/vulnerability/wordpress-wp-database-optimizer-1-2-1-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5cpf-72jj-4ccp/GHSA-5cpf-72jj-4ccp.json b/advisories/unreviewed/2025/03/GHSA-5cpf-72jj-4ccp/GHSA-5cpf-72jj-4ccp.json new file mode 100644 index 00000000000..7b581edd69f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5cpf-72jj-4ccp/GHSA-5cpf-72jj-4ccp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cpf-72jj-4ccp", + "modified": "2025-03-28T12:31:38Z", + "published": "2025-03-28T12:31:38Z", + "aliases": [ + "CVE-2025-31470" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FancyThemes Page Takeover allows Stored XSS. This issue affects Page Takeover: from n/a through 1.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31470" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/page-takeover/vulnerability/wordpress-page-takeover-1-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5g55-34gp-qjxx/GHSA-5g55-34gp-qjxx.json b/advisories/unreviewed/2025/03/GHSA-5g55-34gp-qjxx/GHSA-5g55-34gp-qjxx.json new file mode 100644 index 00000000000..fdeae1d5c14 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5g55-34gp-qjxx/GHSA-5g55-34gp-qjxx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g55-34gp-qjxx", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-31090" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alordiel Dropdown Multisite selector allows Stored XSS. This issue affects Dropdown Multisite selector: from n/a through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31090" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dropdown-multisite-selector/vulnerability/wordpress-dropdown-multisite-selector-0-9-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T10:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5r3q-w36x-6v9v/GHSA-5r3q-w36x-6v9v.json b/advisories/unreviewed/2025/03/GHSA-5r3q-w36x-6v9v/GHSA-5r3q-w36x-6v9v.json new file mode 100644 index 00000000000..0c975af7fdd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5r3q-w36x-6v9v/GHSA-5r3q-w36x-6v9v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r3q-w36x-6v9v", + "modified": "2025-03-28T12:31:38Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-31449" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in EricH The Visitor Counter allows Stored XSS. This issue affects The Visitor Counter: from n/a through 1.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31449" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/the-visitor-counter/vulnerability/wordpress-the-visitor-counter-plugin-1-4-3-cross-site-request-forgery-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-63wv-chh8-pfxx/GHSA-63wv-chh8-pfxx.json b/advisories/unreviewed/2025/03/GHSA-63wv-chh8-pfxx/GHSA-63wv-chh8-pfxx.json new file mode 100644 index 00000000000..4b8f239958c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-63wv-chh8-pfxx/GHSA-63wv-chh8-pfxx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63wv-chh8-pfxx", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-31433" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Miguel Sirvent Magic Embeds allows Stored XSS. This issue affects Magic Embeds: from n/a through 3.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31433" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-embed-facebook/vulnerability/wordpress-magic-embeds-3-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-66cx-46h2-jv42/GHSA-66cx-46h2-jv42.json b/advisories/unreviewed/2025/03/GHSA-66cx-46h2-jv42/GHSA-66cx-46h2-jv42.json new file mode 100644 index 00000000000..c601e4c25cb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-66cx-46h2-jv42/GHSA-66cx-46h2-jv42.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66cx-46h2-jv42", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-31439" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in tobias_.MerZ Browser Caching with .htaccess allows Cross Site Request Forgery. This issue affects Browser Caching with .htaccess: from 1.2.1 through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31439" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/browser-caching-with-htaccess/vulnerability/wordpress-browser-caching-with-htaccess-1-2-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-66f6-7gwp-cw33/GHSA-66f6-7gwp-cw33.json b/advisories/unreviewed/2025/03/GHSA-66f6-7gwp-cw33/GHSA-66f6-7gwp-cw33.json new file mode 100644 index 00000000000..4135bae4b62 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-66f6-7gwp-cw33/GHSA-66f6-7gwp-cw33.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66f6-7gwp-cw33", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-31444" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in youtag ShowTime Slideshow allows Stored XSS. This issue affects ShowTime Slideshow: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31444" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/showtime-slideshow/vulnerability/wordpress-showtime-slideshow-plugin-1-6-cross-site-request-forgery-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6xxf-qx2x-9vh3/GHSA-6xxf-qx2x-9vh3.json b/advisories/unreviewed/2025/03/GHSA-6xxf-qx2x-9vh3/GHSA-6xxf-qx2x-9vh3.json new file mode 100644 index 00000000000..b776fd2b168 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6xxf-qx2x-9vh3/GHSA-6xxf-qx2x-9vh3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xxf-qx2x-9vh3", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-31447" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in nertworks NertWorks All in One Social Share Tools allows Cross Site Request Forgery. This issue affects NertWorks All in One Social Share Tools: from n/a through 1.26.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31447" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nertworks-all-in-one-social-share-tools/vulnerability/wordpress-nertworks-all-in-one-social-share-tools-1-26-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-77v8-cxj6-2cjq/GHSA-77v8-cxj6-2cjq.json b/advisories/unreviewed/2025/03/GHSA-77v8-cxj6-2cjq/GHSA-77v8-cxj6-2cjq.json new file mode 100644 index 00000000000..dabb9ac40e9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-77v8-cxj6-2cjq/GHSA-77v8-cxj6-2cjq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77v8-cxj6-2cjq", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-31440" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Team Terms of Use allows Stored XSS. This issue affects Terms of Use: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31440" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/terms-of-use-2/vulnerability/wordpress-terms-of-use-plugin-2-0-cross-site-request-forgery-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7f6f-m67x-wvm5/GHSA-7f6f-m67x-wvm5.json b/advisories/unreviewed/2025/03/GHSA-7f6f-m67x-wvm5/GHSA-7f6f-m67x-wvm5.json new file mode 100644 index 00000000000..05993b54b95 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7f6f-m67x-wvm5/GHSA-7f6f-m67x-wvm5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f6f-m67x-wvm5", + "modified": "2025-03-28T12:31:38Z", + "published": "2025-03-28T12:31:38Z", + "aliases": [ + "CVE-2025-31458" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in forsgren Video Embedder allows Stored XSS. This issue affects Video Embedder: from n/a through 1.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31458" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/video-embedder/vulnerability/wordpress-video-embedder-plugin-1-7-1-cross-site-request-forgery-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7f6m-mrqm-frhj/GHSA-7f6m-mrqm-frhj.json b/advisories/unreviewed/2025/03/GHSA-7f6m-mrqm-frhj/GHSA-7f6m-mrqm-frhj.json new file mode 100644 index 00000000000..84295a70d59 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7f6m-mrqm-frhj/GHSA-7f6m-mrqm-frhj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f6m-mrqm-frhj", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-2868" + ], + "details": "Reflected Cross-Site Scripting (XSS) vulnerability in version 1.0 of the Clinic Queuing System. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the page parameter in /index.php.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2868" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-clinic-queuing-system" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T11:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7jc6-2qcp-77fq/GHSA-7jc6-2qcp-77fq.json b/advisories/unreviewed/2025/03/GHSA-7jc6-2qcp-77fq/GHSA-7jc6-2qcp-77fq.json new file mode 100644 index 00000000000..3b0f5245967 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7jc6-2qcp-77fq/GHSA-7jc6-2qcp-77fq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jc6-2qcp-77fq", + "modified": "2025-03-28T12:31:38Z", + "published": "2025-03-28T12:31:38Z", + "aliases": [ + "CVE-2025-31473" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in matthewprice1178 WP Database Optimizer allows Stored XSS. This issue affects WP Database Optimizer: from n/a through 1.2.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31473" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-database-optimizer/vulnerability/wordpress-wp-database-optimizer-1-2-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-845q-6693-7whj/GHSA-845q-6693-7whj.json b/advisories/unreviewed/2025/03/GHSA-845q-6693-7whj/GHSA-845q-6693-7whj.json new file mode 100644 index 00000000000..f664d4cc1dc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-845q-6693-7whj/GHSA-845q-6693-7whj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-845q-6693-7whj", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-2815" + ], + "details": "The Administrator Z plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the adminz_import_backup() function in all versions up to, and including, 2025.03.24. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2815" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3262319%40administrator-z&new=3262319%40administrator-z&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/32725074-5c62-49e0-83f9-c6cb77fb77a4?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8qrw-jwc9-44wm/GHSA-8qrw-jwc9-44wm.json b/advisories/unreviewed/2025/03/GHSA-8qrw-jwc9-44wm/GHSA-8qrw-jwc9-44wm.json new file mode 100644 index 00000000000..426cb1767a0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8qrw-jwc9-44wm/GHSA-8qrw-jwc9-44wm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qrw-jwc9-44wm", + "modified": "2025-03-28T12:31:38Z", + "published": "2025-03-28T12:31:38Z", + "aliases": [ + "CVE-2025-31472" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michele Marri Flatty allows Stored XSS. This issue affects Flatty: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31472" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/flatty-flat-admin-theme/vulnerability/wordpress-flatty-2-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8vgx-hg29-89rj/GHSA-8vgx-hg29-89rj.json b/advisories/unreviewed/2025/03/GHSA-8vgx-hg29-89rj/GHSA-8vgx-hg29-89rj.json new file mode 100644 index 00000000000..d89fe6477ba --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8vgx-hg29-89rj/GHSA-8vgx-hg29-89rj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vgx-hg29-89rj", + "modified": "2025-03-28T12:31:38Z", + "published": "2025-03-28T12:31:38Z", + "aliases": [ + "CVE-2025-31453" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stian Andreassen YouTube SimpleGallery allows Stored XSS. This issue affects YouTube SimpleGallery: from n/a through 2.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31453" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/youtube-simplegallery/vulnerability/wordpress-youtube-simplegallery-2-0-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-92fw-qg4x-c3wq/GHSA-92fw-qg4x-c3wq.json b/advisories/unreviewed/2025/03/GHSA-92fw-qg4x-c3wq/GHSA-92fw-qg4x-c3wq.json new file mode 100644 index 00000000000..8b35b64628a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-92fw-qg4x-c3wq/GHSA-92fw-qg4x-c3wq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92fw-qg4x-c3wq", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-31438" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Benoit De Boeck WP Supersized allows Cross Site Request Forgery. This issue affects WP Supersized: from n/a through 3.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31438" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-supersized/vulnerability/wordpress-wp-supersized-3-1-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-95mg-rjvm-5wqp/GHSA-95mg-rjvm-5wqp.json b/advisories/unreviewed/2025/03/GHSA-95mg-rjvm-5wqp/GHSA-95mg-rjvm-5wqp.json new file mode 100644 index 00000000000..09d9d1d4350 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-95mg-rjvm-5wqp/GHSA-95mg-rjvm-5wqp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95mg-rjvm-5wqp", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-31093" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in redpixelstudios RPS Include Content allows DOM-Based XSS. This issue affects RPS Include Content: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31093" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rps-include-content/vulnerability/wordpress-rps-include-content-1-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T10:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c24v-3cc2-569w/GHSA-c24v-3cc2-569w.json b/advisories/unreviewed/2025/03/GHSA-c24v-3cc2-569w/GHSA-c24v-3cc2-569w.json new file mode 100644 index 00000000000..cc0f503f436 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c24v-3cc2-569w/GHSA-c24v-3cc2-569w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c24v-3cc2-569w", + "modified": "2025-03-28T12:31:36Z", + "published": "2025-03-28T12:31:36Z", + "aliases": [ + "CVE-2025-31075" + ], + "details": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in videowhisper MicroPayments allows Stored XSS. This issue affects MicroPayments: from n/a through 2.9.29.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31075" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/paid-membership/vulnerability/wordpress-micropayments-plugin-2-9-29-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c7f5-5939-hq32/GHSA-c7f5-5939-hq32.json b/advisories/unreviewed/2025/03/GHSA-c7f5-5939-hq32/GHSA-c7f5-5939-hq32.json new file mode 100644 index 00000000000..faf9c5ac859 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c7f5-5939-hq32/GHSA-c7f5-5939-hq32.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7f5-5939-hq32", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-31443" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Krzysztof Furtak KK I Like It allows Stored XSS. This issue affects KK I Like It: from n/a through 1.7.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31443" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/kk-i-like-it/vulnerability/wordpress-kk-i-like-it-plugin-1-7-5-3-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cchv-53f9-gpmg/GHSA-cchv-53f9-gpmg.json b/advisories/unreviewed/2025/03/GHSA-cchv-53f9-gpmg/GHSA-cchv-53f9-gpmg.json new file mode 100644 index 00000000000..13ad0ebb299 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cchv-53f9-gpmg/GHSA-cchv-53f9-gpmg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cchv-53f9-gpmg", + "modified": "2025-03-28T12:31:38Z", + "published": "2025-03-28T12:31:38Z", + "aliases": [ + "CVE-2025-31452" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mindshare Labs, Inc. WP Ultimate Search allows Stored XSS. This issue affects WP Ultimate Search: from n/a through 2.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31452" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-ultimate-search/vulnerability/wordpress-wp-ultimate-search-2-0-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f254-h25h-9hpx/GHSA-f254-h25h-9hpx.json b/advisories/unreviewed/2025/03/GHSA-f254-h25h-9hpx/GHSA-f254-h25h-9hpx.json new file mode 100644 index 00000000000..f200cc8f982 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f254-h25h-9hpx/GHSA-f254-h25h-9hpx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f254-h25h-9hpx", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2021-24008" + ], + "details": "An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS version 5.4.0, version 5.3.2 and below, version 5.2.0, version 5.1.0, version 5.0.0, version 4.7.0, version 4.6.0, version 4.5.0, version 4.4.2 and below, FortiDDoS-CM version 5.3.0, version 5.2.0, version 5.1.0, version 5.0.0, version 4.7.0, FortiVoice version 6.0.6 and below, FortiRecorder version 6.0.3 and below and FortiMail version 6.4.1 and below, version 6.2.4 and below, version 6.0.9 and below may allow a remote, unauthenticated attacker to obtain potentially sensitive software-version information by reading a JavaScript file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-24008" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-20-105" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T11:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f69p-2qpf-jwv9/GHSA-f69p-2qpf-jwv9.json b/advisories/unreviewed/2025/03/GHSA-f69p-2qpf-jwv9/GHSA-f69p-2qpf-jwv9.json new file mode 100644 index 00000000000..132466877f0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f69p-2qpf-jwv9/GHSA-f69p-2qpf-jwv9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f69p-2qpf-jwv9", + "modified": "2025-03-28T12:31:36Z", + "published": "2025-03-28T12:31:36Z", + "aliases": [ + "CVE-2025-31079" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in usermaven Usermaven allows Cross Site Request Forgery. This issue affects Usermaven: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31079" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/usermaven/vulnerability/wordpress-usermaven-plugin-1-2-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fg4p-8xwr-5p2r/GHSA-fg4p-8xwr-5p2r.json b/advisories/unreviewed/2025/03/GHSA-fg4p-8xwr-5p2r/GHSA-fg4p-8xwr-5p2r.json new file mode 100644 index 00000000000..deac6585388 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fg4p-8xwr-5p2r/GHSA-fg4p-8xwr-5p2r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg4p-8xwr-5p2r", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-31434" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adrian Tobey FormLift for Infusionsoft Web Forms allows Stored XSS. This issue affects FormLift for Infusionsoft Web Forms: from n/a through 7.5.19.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31434" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/formlift/vulnerability/wordpress-formlift-for-infusionsoft-web-forms-7-5-19-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fpwm-5w47-hfx3/GHSA-fpwm-5w47-hfx3.json b/advisories/unreviewed/2025/03/GHSA-fpwm-5w47-hfx3/GHSA-fpwm-5w47-hfx3.json new file mode 100644 index 00000000000..ee38069cea1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fpwm-5w47-hfx3/GHSA-fpwm-5w47-hfx3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpwm-5w47-hfx3", + "modified": "2025-03-28T12:31:38Z", + "published": "2025-03-28T12:31:38Z", + "aliases": [ + "CVE-2025-31456" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in bsndev Ultimate Security Checker allows Cross Site Request Forgery. This issue affects Ultimate Security Checker: from n/a through 4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31456" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-security-checker/vulnerability/wordpress-ultimate-security-checker-plugin-4-2-cross-site-request-forgery-csrf-to-security-rescan-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g82c-5957-wqpv/GHSA-g82c-5957-wqpv.json b/advisories/unreviewed/2025/03/GHSA-g82c-5957-wqpv/GHSA-g82c-5957-wqpv.json new file mode 100644 index 00000000000..00346755580 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g82c-5957-wqpv/GHSA-g82c-5957-wqpv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g82c-5957-wqpv", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-31448" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in misteraon Simple Trackback Disabler allows Cross Site Request Forgery. This issue affects Simple Trackback Disabler: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31448" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-trackback-disabler/vulnerability/wordpress-simple-trackback-disabler-1-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gj54-ghf2-q4jg/GHSA-gj54-ghf2-q4jg.json b/advisories/unreviewed/2025/03/GHSA-gj54-ghf2-q4jg/GHSA-gj54-ghf2-q4jg.json new file mode 100644 index 00000000000..6d8e225ce16 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gj54-ghf2-q4jg/GHSA-gj54-ghf2-q4jg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj54-ghf2-q4jg", + "modified": "2025-03-28T12:31:35Z", + "published": "2025-03-28T12:31:35Z", + "aliases": [ + "CVE-2024-10307" + ], + "details": "An issue has been discovered in GitLab EE/CE affecting all versions from 12.10 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A maliciously crafted file can cause uncontrolled CPU consumption when viewing the associated merge request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10307" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2775113" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/500497" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gwfx-p3mg-f99w/GHSA-gwfx-p3mg-f99w.json b/advisories/unreviewed/2025/03/GHSA-gwfx-p3mg-f99w/GHSA-gwfx-p3mg-f99w.json new file mode 100644 index 00000000000..18cf7509ea6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gwfx-p3mg-f99w/GHSA-gwfx-p3mg-f99w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwfx-p3mg-f99w", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-31432" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Chop Chop Pop-Up Chop Chop allows PHP Local File Inclusion. This issue affects Pop-Up Chop Chop: from n/a through 2.1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31432" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pop-up/vulnerability/wordpress-pop-up-chop-chop-2-1-7-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gxgw-3343-jpx9/GHSA-gxgw-3343-jpx9.json b/advisories/unreviewed/2025/03/GHSA-gxgw-3343-jpx9/GHSA-gxgw-3343-jpx9.json new file mode 100644 index 00000000000..ae2b7a985ba --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gxgw-3343-jpx9/GHSA-gxgw-3343-jpx9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxgw-3343-jpx9", + "modified": "2025-03-28T12:31:38Z", + "published": "2025-03-28T12:31:38Z", + "aliases": [ + "CVE-2025-31451" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kevinweber wBounce allows Stored XSS. This issue affects wBounce: from n/a through 1.8.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31451" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wbounce/vulnerability/wordpress-wbounce-1-8-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hpqp-8w3c-7h9x/GHSA-hpqp-8w3c-7h9x.json b/advisories/unreviewed/2025/03/GHSA-hpqp-8w3c-7h9x/GHSA-hpqp-8w3c-7h9x.json new file mode 100644 index 00000000000..995810904d9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hpqp-8w3c-7h9x/GHSA-hpqp-8w3c-7h9x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpqp-8w3c-7h9x", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-31437" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Miller WP-OGP allows Stored XSS. This issue affects WP-OGP: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31437" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-ogp/vulnerability/wordpress-wp-ogp-1-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j8c2-6298-q92j/GHSA-j8c2-6298-q92j.json b/advisories/unreviewed/2025/03/GHSA-j8c2-6298-q92j/GHSA-j8c2-6298-q92j.json new file mode 100644 index 00000000000..37e8163776f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j8c2-6298-q92j/GHSA-j8c2-6298-q92j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8c2-6298-q92j", + "modified": "2025-03-28T12:31:35Z", + "published": "2025-03-28T12:31:35Z", + "aliases": [ + "CVE-2019-16149" + ], + "details": "An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attacker to execute unauthorized code by injecting malicious payload in the user profile of a FortiClient instance being managed by the vulnerable system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-16149" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-19-072" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T10:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jcmm-rj83-g6xp/GHSA-jcmm-rj83-g6xp.json b/advisories/unreviewed/2025/03/GHSA-jcmm-rj83-g6xp/GHSA-jcmm-rj83-g6xp.json new file mode 100644 index 00000000000..babb5e06308 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jcmm-rj83-g6xp/GHSA-jcmm-rj83-g6xp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcmm-rj83-g6xp", + "modified": "2025-03-28T12:31:38Z", + "published": "2025-03-28T12:31:38Z", + "aliases": [ + "CVE-2025-31465" + ], + "details": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in cornershop Better Section Navigation Widget allows Stored XSS. This issue affects Better Section Navigation Widget: from n/a through 1.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31465" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/better-section-navigation/vulnerability/wordpress-better-section-navigation-widget-1-6-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jhwv-gfw9-7g73/GHSA-jhwv-gfw9-7g73.json b/advisories/unreviewed/2025/03/GHSA-jhwv-gfw9-7g73/GHSA-jhwv-gfw9-7g73.json new file mode 100644 index 00000000000..fd8640471e4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jhwv-gfw9-7g73/GHSA-jhwv-gfw9-7g73.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhwv-gfw9-7g73", + "modified": "2025-03-28T12:31:38Z", + "published": "2025-03-28T12:31:38Z", + "aliases": [ + "CVE-2025-31463" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Preetinder Singh TGG WP Optimizer allows Stored XSS. This issue affects TGG WP Optimizer: from n/a through 1.22.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31463" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tgg-wp-optimizer/vulnerability/wordpress-tgg-wp-optimizer-1-22-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mp37-h9r8-562g/GHSA-mp37-h9r8-562g.json b/advisories/unreviewed/2025/03/GHSA-mp37-h9r8-562g/GHSA-mp37-h9r8-562g.json new file mode 100644 index 00000000000..77ea9662b91 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mp37-h9r8-562g/GHSA-mp37-h9r8-562g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp37-h9r8-562g", + "modified": "2025-03-28T12:31:36Z", + "published": "2025-03-28T12:31:36Z", + "aliases": [ + "CVE-2025-31088" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs Paid Member Subscriptions allows Stored XSS. This issue affects Paid Member Subscriptions: from n/a through 2.14.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31088" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/paid-member-subscriptions/vulnerability/wordpress-paid-member-subscriptions-2-14-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T10:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mw7x-pfmv-gqjm/GHSA-mw7x-pfmv-gqjm.json b/advisories/unreviewed/2025/03/GHSA-mw7x-pfmv-gqjm/GHSA-mw7x-pfmv-gqjm.json new file mode 100644 index 00000000000..032c455e59c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mw7x-pfmv-gqjm/GHSA-mw7x-pfmv-gqjm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw7x-pfmv-gqjm", + "modified": "2025-03-28T12:31:36Z", + "published": "2025-03-28T12:31:36Z", + "aliases": [ + "CVE-2025-31077" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Blocks Ultimate Blocks allows DOM-Based XSS. This issue affects Ultimate Blocks: from n/a through 3.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31077" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-blocks/vulnerability/wordpress-ultimate-blocks-plugin-3-2-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pj2f-7982-rfq7/GHSA-pj2f-7982-rfq7.json b/advisories/unreviewed/2025/03/GHSA-pj2f-7982-rfq7/GHSA-pj2f-7982-rfq7.json new file mode 100644 index 00000000000..51a228a3b89 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pj2f-7982-rfq7/GHSA-pj2f-7982-rfq7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj2f-7982-rfq7", + "modified": "2025-03-28T12:31:36Z", + "published": "2025-03-28T12:31:36Z", + "aliases": [ + "CVE-2025-31083" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZEEN101 Leaky Paywall allows Stored XSS. This issue affects Leaky Paywall: from n/a through 4.21.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31083" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/leaky-paywall/vulnerability/wordpress-leaky-paywall-4-21-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T10:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qmh6-m8qq-5h2c/GHSA-qmh6-m8qq-5h2c.json b/advisories/unreviewed/2025/03/GHSA-qmh6-m8qq-5h2c/GHSA-qmh6-m8qq-5h2c.json new file mode 100644 index 00000000000..46845acb786 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qmh6-m8qq-5h2c/GHSA-qmh6-m8qq-5h2c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmh6-m8qq-5h2c", + "modified": "2025-03-28T12:31:38Z", + "published": "2025-03-28T12:31:38Z", + "aliases": [ + "CVE-2025-31469" + ], + "details": "Missing Authorization vulnerability in webrangers Clear Sucuri Cache allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Clear Sucuri Cache: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31469" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/clear-sucuri-cache/vulnerability/wordpress-clear-sucuri-cache-1-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qqpj-cc4g-r5fm/GHSA-qqpj-cc4g-r5fm.json b/advisories/unreviewed/2025/03/GHSA-qqpj-cc4g-r5fm/GHSA-qqpj-cc4g-r5fm.json new file mode 100644 index 00000000000..3cf6e659bc6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qqpj-cc4g-r5fm/GHSA-qqpj-cc4g-r5fm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqpj-cc4g-r5fm", + "modified": "2025-03-28T12:31:38Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-31450" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phantom.omaga Toggle Box allows Stored XSS. This issue affects Toggle Box: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31450" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/toggle-box/vulnerability/wordpress-toggle-box-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rcp5-qv59-99x9/GHSA-rcp5-qv59-99x9.json b/advisories/unreviewed/2025/03/GHSA-rcp5-qv59-99x9/GHSA-rcp5-qv59-99x9.json new file mode 100644 index 00000000000..307a0a58f19 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rcp5-qv59-99x9/GHSA-rcp5-qv59-99x9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcp5-qv59-99x9", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-2869" + ], + "details": "Reflected Cross-Site Scripting (XSS) vulnerability in version 1.0 of the Clinic Queuing System. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the id parameter in /manage_user.php.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2869" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-clinic-queuing-system" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T11:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rh54-h682-292g/GHSA-rh54-h682-292g.json b/advisories/unreviewed/2025/03/GHSA-rh54-h682-292g/GHSA-rh54-h682-292g.json new file mode 100644 index 00000000000..54eecccbc1a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rh54-h682-292g/GHSA-rh54-h682-292g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh54-h682-292g", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-31096" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPXPO PostX allows DOM-Based XSS. This issue affects PostX: from n/a through 4.1.25.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31096" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-post/vulnerability/wordpress-postx-4-1-25-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T10:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vj37-r98f-rrj5/GHSA-vj37-r98f-rrj5.json b/advisories/unreviewed/2025/03/GHSA-vj37-r98f-rrj5/GHSA-vj37-r98f-rrj5.json new file mode 100644 index 00000000000..b536d7fa500 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vj37-r98f-rrj5/GHSA-vj37-r98f-rrj5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vj37-r98f-rrj5", + "modified": "2025-03-28T12:31:36Z", + "published": "2025-03-28T12:31:36Z", + "aliases": [ + "CVE-2025-27001" + ], + "details": "Insertion of Sensitive Information Into Sent Data vulnerability in Shipmondo Shipmondo – A complete shipping solution for WooCommerce allows Retrieve Embedded Sensitive Data.This issue affects Shipmondo – A complete shipping solution for WooCommerce: from n/a through 5.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27001" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pakkelabels-for-woocommerce/vulnerability/wordpress-shipmondo-a-complete-shipping-solution-for-woocommerce-plugin-5-0-3-authenticated-arbitrary-wordpress-option-disclosure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w2mg-683w-6gr8/GHSA-w2mg-683w-6gr8.json b/advisories/unreviewed/2025/03/GHSA-w2mg-683w-6gr8/GHSA-w2mg-683w-6gr8.json new file mode 100644 index 00000000000..f30928515e0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w2mg-683w-6gr8/GHSA-w2mg-683w-6gr8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2mg-683w-6gr8", + "modified": "2025-03-28T12:31:38Z", + "published": "2025-03-28T12:31:38Z", + "aliases": [ + "CVE-2025-31464" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nazmur Rahman Text Selection Color allows Stored XSS. This issue affects Text Selection Color: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31464" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/text-selection-color/vulnerability/wordpress-text-selection-color-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wx7h-789f-rpr3/GHSA-wx7h-789f-rpr3.json b/advisories/unreviewed/2025/03/GHSA-wx7h-789f-rpr3/GHSA-wx7h-789f-rpr3.json new file mode 100644 index 00000000000..4da597a577e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wx7h-789f-rpr3/GHSA-wx7h-789f-rpr3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx7h-789f-rpr3", + "modified": "2025-03-28T12:31:38Z", + "published": "2025-03-28T12:31:38Z", + "aliases": [ + "CVE-2025-31471" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Falcon Solutions Duplicate Page and Post allows Stored XSS. This issue affects Duplicate Page and Post: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31471" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/duplicate-post-and-page/vulnerability/wordpress-duplicate-page-and-post-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x46r-qvwm-8m8h/GHSA-x46r-qvwm-8m8h.json b/advisories/unreviewed/2025/03/GHSA-x46r-qvwm-8m8h/GHSA-x46r-qvwm-8m8h.json new file mode 100644 index 00000000000..f212ae6593d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x46r-qvwm-8m8h/GHSA-x46r-qvwm-8m8h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x46r-qvwm-8m8h", + "modified": "2025-03-28T12:31:37Z", + "published": "2025-03-28T12:31:37Z", + "aliases": [ + "CVE-2025-31099" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bestwebsoft Slider by BestWebSoft allows SQL Injection. This issue affects Slider by BestWebSoft: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31099" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/slider-bws/vulnerability/wordpress-slider-by-bestwebsoft-1-1-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T10:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xrw8-7vj3-m4f7/GHSA-xrw8-7vj3-m4f7.json b/advisories/unreviewed/2025/03/GHSA-xrw8-7vj3-m4f7/GHSA-xrw8-7vj3-m4f7.json new file mode 100644 index 00000000000..1a9669ae944 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xrw8-7vj3-m4f7/GHSA-xrw8-7vj3-m4f7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrw8-7vj3-m4f7", + "modified": "2025-03-28T12:31:36Z", + "published": "2025-03-28T12:31:36Z", + "aliases": [ + "CVE-2025-31073" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Compete Themes Unlimited allows Stored XSS. This issue affects Unlimited: from n/a through 1.45.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31073" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/unlimited/vulnerability/wordpress-unlimited-1-45-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-28T10:15:16Z" + } +} \ No newline at end of file