From 1bc114ba059b9bed340cb178cf568799ffed897d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 24 Feb 2025 15:32:36 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-9442-gm4v-r222.json | 17 +++--- .../GHSA-44qf-gpjx-pm9g.json | 9 +++- .../GHSA-73jm-6x85-hwg5.json | 3 +- .../GHSA-74vv-6p4c-8fhj.json | 9 +++- .../GHSA-r3c8-67q5-2xw8.json | 9 +++- .../GHSA-hgvv-9m7h-78q7.json | 6 ++- .../GHSA-jrrq-62hw-r9fw.json | 2 +- .../GHSA-frh3-73v3-rg46.json | 4 +- .../GHSA-25gx-qr96-f826.json | 36 +++++++++++++ .../GHSA-26mm-6qr4-6xj3.json | 36 +++++++++++++ .../GHSA-2824-52jc-w55m.json | 36 +++++++++++++ .../GHSA-297w-r8j3-c69q.json | 36 +++++++++++++ .../GHSA-3775-gcxp-8pxm.json | 36 +++++++++++++ .../GHSA-3m4p-3m6j-4rq2.json | 36 +++++++++++++ .../GHSA-3qqr-67hg-8c4v.json | 36 +++++++++++++ .../GHSA-3x3j-pmx9-j3r7.json | 36 +++++++++++++ .../GHSA-486p-pvq9-8w7q.json | 36 +++++++++++++ .../GHSA-4mw2-mw6m-p7x4.json | 36 +++++++++++++ .../GHSA-5553-rf4f-g9qc.json | 36 +++++++++++++ .../GHSA-56c7-jcxw-47mf.json | 36 +++++++++++++ .../GHSA-5rg9-ph4r-3frg.json | 2 +- .../GHSA-5x22-hprq-4vqq.json | 36 +++++++++++++ .../GHSA-736r-93pp-2mvh.json | 36 +++++++++++++ .../GHSA-73vj-rj78-cc72.json | 36 +++++++++++++ .../GHSA-7927-94hw-7qx3.json | 36 +++++++++++++ .../GHSA-79mg-hfrx-5889.json | 3 +- .../GHSA-7fh8-cm5f-gg3q.json | 36 +++++++++++++ .../GHSA-7vcf-jcc6-ppj2.json | 4 +- .../GHSA-8p9v-vmfp-j798.json | 36 +++++++++++++ .../GHSA-8qrw-8hx5-vg32.json | 36 +++++++++++++ .../GHSA-8rqp-g9hp-4x68.json | 3 +- .../GHSA-8w8c-r2pm-xh9r.json | 36 +++++++++++++ .../GHSA-8xgg-j54h-3gpg.json | 3 +- .../GHSA-93cq-gv6v-xr7v.json | 2 +- .../GHSA-9q3v-f9ch-76v7.json | 36 +++++++++++++ .../GHSA-c2p9-qv8x-42cj.json | 11 ++-- .../GHSA-c3ff-v8pw-m28w.json | 36 +++++++++++++ .../GHSA-c7wx-6527-3jvg.json | 36 +++++++++++++ .../GHSA-cr92-jq55-gj75.json | 36 +++++++++++++ .../GHSA-crrc-pmgr-mphw.json | 36 +++++++++++++ .../GHSA-cv45-3m55-xp7r.json | 36 +++++++++++++ .../GHSA-cv6c-2jmj-cr4h.json | 36 +++++++++++++ .../GHSA-cw9m-pj72-3cj5.json | 52 +++++++++++++++++++ .../GHSA-f872-rr6m-x9r7.json | 36 +++++++++++++ .../GHSA-fchw-7cp9-hjpp.json | 36 +++++++++++++ .../GHSA-ghh6-jcf7-xpx9.json | 36 +++++++++++++ .../GHSA-gv2g-83jv-h4v9.json | 2 +- .../GHSA-h764-fh5p-vfc9.json | 36 +++++++++++++ .../GHSA-h7xh-jqw8-mhx8.json | 36 +++++++++++++ .../GHSA-hcp8-2v69-c2fm.json | 36 +++++++++++++ .../GHSA-hv9g-xmv8-5frh.json | 36 +++++++++++++ .../GHSA-hvxc-4j7p-9r6f.json | 36 +++++++++++++ .../GHSA-hwff-5jf9-m789.json | 36 +++++++++++++ .../GHSA-j69j-6h4m-c446.json | 36 +++++++++++++ .../GHSA-jpq8-pr23-m9c6.json | 36 +++++++++++++ .../GHSA-m2px-76cx-93fc.json | 36 +++++++++++++ .../GHSA-m6ff-f9xg-9wxx.json | 36 +++++++++++++ .../GHSA-mqcj-7rfq-46jf.json | 36 +++++++++++++ .../GHSA-mwr3-8q5m-r388.json | 36 +++++++++++++ .../GHSA-p4vv-vjj8-538h.json | 36 +++++++++++++ .../GHSA-p555-fgxh-v7q6.json | 36 +++++++++++++ .../GHSA-pw98-79r8-4mjg.json | 36 +++++++++++++ .../GHSA-pxh9-q2hp-6252.json | 36 +++++++++++++ .../GHSA-q34f-q4r4-rg8f.json | 36 +++++++++++++ .../GHSA-q598-5464-x6q8.json | 1 + .../GHSA-qg2c-hj47-j83g.json | 36 +++++++++++++ .../GHSA-qm52-xrp7-84q5.json | 36 +++++++++++++ .../GHSA-r3jw-928j-3957.json | 36 +++++++++++++ .../GHSA-rph7-pv2v-px9j.json | 36 +++++++++++++ .../GHSA-vmjx-294p-54xm.json | 36 +++++++++++++ .../GHSA-w8hr-h827-x7c3.json | 36 +++++++++++++ .../GHSA-wh8c-9r6f-25hp.json | 36 +++++++++++++ .../GHSA-ww6h-9f7x-62fr.json | 36 +++++++++++++ .../GHSA-x664-7q93-cmgg.json | 36 +++++++++++++ .../GHSA-xvpj-rpwv-6v3h.json | 36 +++++++++++++ 75 files changed, 2166 insertions(+), 28 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-25gx-qr96-f826/GHSA-25gx-qr96-f826.json create mode 100644 advisories/unreviewed/2025/02/GHSA-26mm-6qr4-6xj3/GHSA-26mm-6qr4-6xj3.json create mode 100644 advisories/unreviewed/2025/02/GHSA-2824-52jc-w55m/GHSA-2824-52jc-w55m.json create mode 100644 advisories/unreviewed/2025/02/GHSA-297w-r8j3-c69q/GHSA-297w-r8j3-c69q.json create mode 100644 advisories/unreviewed/2025/02/GHSA-3775-gcxp-8pxm/GHSA-3775-gcxp-8pxm.json create mode 100644 advisories/unreviewed/2025/02/GHSA-3m4p-3m6j-4rq2/GHSA-3m4p-3m6j-4rq2.json create mode 100644 advisories/unreviewed/2025/02/GHSA-3qqr-67hg-8c4v/GHSA-3qqr-67hg-8c4v.json create mode 100644 advisories/unreviewed/2025/02/GHSA-3x3j-pmx9-j3r7/GHSA-3x3j-pmx9-j3r7.json create mode 100644 advisories/unreviewed/2025/02/GHSA-486p-pvq9-8w7q/GHSA-486p-pvq9-8w7q.json create mode 100644 advisories/unreviewed/2025/02/GHSA-4mw2-mw6m-p7x4/GHSA-4mw2-mw6m-p7x4.json create mode 100644 advisories/unreviewed/2025/02/GHSA-5553-rf4f-g9qc/GHSA-5553-rf4f-g9qc.json create mode 100644 advisories/unreviewed/2025/02/GHSA-56c7-jcxw-47mf/GHSA-56c7-jcxw-47mf.json create mode 100644 advisories/unreviewed/2025/02/GHSA-5x22-hprq-4vqq/GHSA-5x22-hprq-4vqq.json create mode 100644 advisories/unreviewed/2025/02/GHSA-736r-93pp-2mvh/GHSA-736r-93pp-2mvh.json create mode 100644 advisories/unreviewed/2025/02/GHSA-73vj-rj78-cc72/GHSA-73vj-rj78-cc72.json create mode 100644 advisories/unreviewed/2025/02/GHSA-7927-94hw-7qx3/GHSA-7927-94hw-7qx3.json create mode 100644 advisories/unreviewed/2025/02/GHSA-7fh8-cm5f-gg3q/GHSA-7fh8-cm5f-gg3q.json create mode 100644 advisories/unreviewed/2025/02/GHSA-8p9v-vmfp-j798/GHSA-8p9v-vmfp-j798.json create mode 100644 advisories/unreviewed/2025/02/GHSA-8qrw-8hx5-vg32/GHSA-8qrw-8hx5-vg32.json create mode 100644 advisories/unreviewed/2025/02/GHSA-8w8c-r2pm-xh9r/GHSA-8w8c-r2pm-xh9r.json create mode 100644 advisories/unreviewed/2025/02/GHSA-9q3v-f9ch-76v7/GHSA-9q3v-f9ch-76v7.json create mode 100644 advisories/unreviewed/2025/02/GHSA-c3ff-v8pw-m28w/GHSA-c3ff-v8pw-m28w.json create mode 100644 advisories/unreviewed/2025/02/GHSA-c7wx-6527-3jvg/GHSA-c7wx-6527-3jvg.json create mode 100644 advisories/unreviewed/2025/02/GHSA-cr92-jq55-gj75/GHSA-cr92-jq55-gj75.json create mode 100644 advisories/unreviewed/2025/02/GHSA-crrc-pmgr-mphw/GHSA-crrc-pmgr-mphw.json create mode 100644 advisories/unreviewed/2025/02/GHSA-cv45-3m55-xp7r/GHSA-cv45-3m55-xp7r.json create mode 100644 advisories/unreviewed/2025/02/GHSA-cv6c-2jmj-cr4h/GHSA-cv6c-2jmj-cr4h.json create mode 100644 advisories/unreviewed/2025/02/GHSA-cw9m-pj72-3cj5/GHSA-cw9m-pj72-3cj5.json create mode 100644 advisories/unreviewed/2025/02/GHSA-f872-rr6m-x9r7/GHSA-f872-rr6m-x9r7.json create mode 100644 advisories/unreviewed/2025/02/GHSA-fchw-7cp9-hjpp/GHSA-fchw-7cp9-hjpp.json create mode 100644 advisories/unreviewed/2025/02/GHSA-ghh6-jcf7-xpx9/GHSA-ghh6-jcf7-xpx9.json create mode 100644 advisories/unreviewed/2025/02/GHSA-h764-fh5p-vfc9/GHSA-h764-fh5p-vfc9.json create mode 100644 advisories/unreviewed/2025/02/GHSA-h7xh-jqw8-mhx8/GHSA-h7xh-jqw8-mhx8.json create mode 100644 advisories/unreviewed/2025/02/GHSA-hcp8-2v69-c2fm/GHSA-hcp8-2v69-c2fm.json create mode 100644 advisories/unreviewed/2025/02/GHSA-hv9g-xmv8-5frh/GHSA-hv9g-xmv8-5frh.json create mode 100644 advisories/unreviewed/2025/02/GHSA-hvxc-4j7p-9r6f/GHSA-hvxc-4j7p-9r6f.json create mode 100644 advisories/unreviewed/2025/02/GHSA-hwff-5jf9-m789/GHSA-hwff-5jf9-m789.json create mode 100644 advisories/unreviewed/2025/02/GHSA-j69j-6h4m-c446/GHSA-j69j-6h4m-c446.json create mode 100644 advisories/unreviewed/2025/02/GHSA-jpq8-pr23-m9c6/GHSA-jpq8-pr23-m9c6.json create mode 100644 advisories/unreviewed/2025/02/GHSA-m2px-76cx-93fc/GHSA-m2px-76cx-93fc.json create mode 100644 advisories/unreviewed/2025/02/GHSA-m6ff-f9xg-9wxx/GHSA-m6ff-f9xg-9wxx.json create mode 100644 advisories/unreviewed/2025/02/GHSA-mqcj-7rfq-46jf/GHSA-mqcj-7rfq-46jf.json create mode 100644 advisories/unreviewed/2025/02/GHSA-mwr3-8q5m-r388/GHSA-mwr3-8q5m-r388.json create mode 100644 advisories/unreviewed/2025/02/GHSA-p4vv-vjj8-538h/GHSA-p4vv-vjj8-538h.json create mode 100644 advisories/unreviewed/2025/02/GHSA-p555-fgxh-v7q6/GHSA-p555-fgxh-v7q6.json create mode 100644 advisories/unreviewed/2025/02/GHSA-pw98-79r8-4mjg/GHSA-pw98-79r8-4mjg.json create mode 100644 advisories/unreviewed/2025/02/GHSA-pxh9-q2hp-6252/GHSA-pxh9-q2hp-6252.json create mode 100644 advisories/unreviewed/2025/02/GHSA-q34f-q4r4-rg8f/GHSA-q34f-q4r4-rg8f.json create mode 100644 advisories/unreviewed/2025/02/GHSA-qg2c-hj47-j83g/GHSA-qg2c-hj47-j83g.json create mode 100644 advisories/unreviewed/2025/02/GHSA-qm52-xrp7-84q5/GHSA-qm52-xrp7-84q5.json create mode 100644 advisories/unreviewed/2025/02/GHSA-r3jw-928j-3957/GHSA-r3jw-928j-3957.json create mode 100644 advisories/unreviewed/2025/02/GHSA-rph7-pv2v-px9j/GHSA-rph7-pv2v-px9j.json create mode 100644 advisories/unreviewed/2025/02/GHSA-vmjx-294p-54xm/GHSA-vmjx-294p-54xm.json create mode 100644 advisories/unreviewed/2025/02/GHSA-w8hr-h827-x7c3/GHSA-w8hr-h827-x7c3.json create mode 100644 advisories/unreviewed/2025/02/GHSA-wh8c-9r6f-25hp/GHSA-wh8c-9r6f-25hp.json create mode 100644 advisories/unreviewed/2025/02/GHSA-ww6h-9f7x-62fr/GHSA-ww6h-9f7x-62fr.json create mode 100644 advisories/unreviewed/2025/02/GHSA-x664-7q93-cmgg/GHSA-x664-7q93-cmgg.json create mode 100644 advisories/unreviewed/2025/02/GHSA-xvpj-rpwv-6v3h/GHSA-xvpj-rpwv-6v3h.json diff --git a/advisories/github-reviewed/2024/06/GHSA-9442-gm4v-r222/GHSA-9442-gm4v-r222.json b/advisories/github-reviewed/2024/06/GHSA-9442-gm4v-r222/GHSA-9442-gm4v-r222.json index 334dcc907c8..ff733d95cc9 100644 --- a/advisories/github-reviewed/2024/06/GHSA-9442-gm4v-r222/GHSA-9442-gm4v-r222.json +++ b/advisories/github-reviewed/2024/06/GHSA-9442-gm4v-r222/GHSA-9442-gm4v-r222.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9442-gm4v-r222", - "modified": "2024-11-29T12:31:48Z", + "modified": "2025-02-24T15:30:22Z", "published": "2024-06-20T15:31:19Z", "aliases": [ "CVE-2024-6162" @@ -51,14 +51,11 @@ "introduced": "0" }, { - "fixed": "2.3.14.Final" + "fixed": "2.2.33.Final" } ] } - ], - "database_specific": { - "last_known_affected_version_range": "< 2.2.33.Final" - } + ] } ], "references": [ @@ -102,6 +99,14 @@ "type": "PACKAGE", "url": "https://github.com/undertow-io/undertow" }, + { + "type": "WEB", + "url": "https://github.com/undertow-io/undertow/releases/tag/2.2.33.Final" + }, + { + "type": "WEB", + "url": "https://github.com/undertow-io/undertow/releases/tag/2.3.14.Final" + }, { "type": "WEB", "url": "https://issues.redhat.com/browse/JBEAP-26268" diff --git a/advisories/unreviewed/2022/05/GHSA-44qf-gpjx-pm9g/GHSA-44qf-gpjx-pm9g.json b/advisories/unreviewed/2022/05/GHSA-44qf-gpjx-pm9g/GHSA-44qf-gpjx-pm9g.json index 4008fc38887..b5c54712164 100644 --- a/advisories/unreviewed/2022/05/GHSA-44qf-gpjx-pm9g/GHSA-44qf-gpjx-pm9g.json +++ b/advisories/unreviewed/2022/05/GHSA-44qf-gpjx-pm9g/GHSA-44qf-gpjx-pm9g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-44qf-gpjx-pm9g", - "modified": "2022-05-24T19:19:32Z", + "modified": "2025-02-24T15:30:42Z", "published": "2022-05-24T19:19:32Z", "aliases": [ "CVE-2021-43141" ], "details": "Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Simple Subscription Website 1.0 via the id parameter in plan_application.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-73jm-6x85-hwg5/GHSA-73jm-6x85-hwg5.json b/advisories/unreviewed/2022/05/GHSA-73jm-6x85-hwg5/GHSA-73jm-6x85-hwg5.json index f2caa807fb1..e06b220bee9 100644 --- a/advisories/unreviewed/2022/05/GHSA-73jm-6x85-hwg5/GHSA-73jm-6x85-hwg5.json +++ b/advisories/unreviewed/2022/05/GHSA-73jm-6x85-hwg5/GHSA-73jm-6x85-hwg5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-73jm-6x85-hwg5", - "modified": "2022-05-13T01:14:58Z", + "modified": "2025-02-24T15:30:41Z", "published": "2022-05-13T01:14:58Z", "aliases": [ "CVE-2019-1652" @@ -54,6 +54,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-20", "CWE-78" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-74vv-6p4c-8fhj/GHSA-74vv-6p4c-8fhj.json b/advisories/unreviewed/2022/05/GHSA-74vv-6p4c-8fhj/GHSA-74vv-6p4c-8fhj.json index 1b94bf7ea17..7dd6baf5900 100644 --- a/advisories/unreviewed/2022/05/GHSA-74vv-6p4c-8fhj/GHSA-74vv-6p4c-8fhj.json +++ b/advisories/unreviewed/2022/05/GHSA-74vv-6p4c-8fhj/GHSA-74vv-6p4c-8fhj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-74vv-6p4c-8fhj", - "modified": "2022-05-24T17:15:13Z", + "modified": "2025-02-24T15:30:41Z", "published": "2022-05-24T17:15:13Z", "aliases": [ "CVE-2020-3161" ], "details": "A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-r3c8-67q5-2xw8/GHSA-r3c8-67q5-2xw8.json b/advisories/unreviewed/2022/05/GHSA-r3c8-67q5-2xw8/GHSA-r3c8-67q5-2xw8.json index 2e44b806f41..e4e5ae46909 100644 --- a/advisories/unreviewed/2022/05/GHSA-r3c8-67q5-2xw8/GHSA-r3c8-67q5-2xw8.json +++ b/advisories/unreviewed/2022/05/GHSA-r3c8-67q5-2xw8/GHSA-r3c8-67q5-2xw8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r3c8-67q5-2xw8", - "modified": "2022-05-24T19:19:32Z", + "modified": "2025-02-24T15:30:41Z", "published": "2022-05-24T19:19:32Z", "aliases": [ "CVE-2021-43140" ], "details": "SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2023/03/GHSA-hgvv-9m7h-78q7/GHSA-hgvv-9m7h-78q7.json b/advisories/unreviewed/2023/03/GHSA-hgvv-9m7h-78q7/GHSA-hgvv-9m7h-78q7.json index 7bb6b06c198..9c34fdb0d91 100644 --- a/advisories/unreviewed/2023/03/GHSA-hgvv-9m7h-78q7/GHSA-hgvv-9m7h-78q7.json +++ b/advisories/unreviewed/2023/03/GHSA-hgvv-9m7h-78q7/GHSA-hgvv-9m7h-78q7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hgvv-9m7h-78q7", - "modified": "2023-04-03T18:32:08Z", + "modified": "2025-02-24T15:30:45Z", "published": "2023-03-28T00:34:28Z", "aliases": [ "CVE-2022-48353" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-jrrq-62hw-r9fw/GHSA-jrrq-62hw-r9fw.json b/advisories/unreviewed/2023/03/GHSA-jrrq-62hw-r9fw/GHSA-jrrq-62hw-r9fw.json index 69b65ccf60d..664091adb99 100644 --- a/advisories/unreviewed/2023/03/GHSA-jrrq-62hw-r9fw/GHSA-jrrq-62hw-r9fw.json +++ b/advisories/unreviewed/2023/03/GHSA-jrrq-62hw-r9fw/GHSA-jrrq-62hw-r9fw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jrrq-62hw-r9fw", - "modified": "2023-04-03T18:32:07Z", + "modified": "2025-02-24T15:30:44Z", "published": "2023-03-28T00:34:28Z", "aliases": [ "CVE-2022-48352" diff --git a/advisories/unreviewed/2024/03/GHSA-frh3-73v3-rg46/GHSA-frh3-73v3-rg46.json b/advisories/unreviewed/2024/03/GHSA-frh3-73v3-rg46/GHSA-frh3-73v3-rg46.json index 5c8e70ab4f2..81c84ca12ac 100644 --- a/advisories/unreviewed/2024/03/GHSA-frh3-73v3-rg46/GHSA-frh3-73v3-rg46.json +++ b/advisories/unreviewed/2024/03/GHSA-frh3-73v3-rg46/GHSA-frh3-73v3-rg46.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-frh3-73v3-rg46", - "modified": "2024-03-29T15:30:31Z", + "modified": "2025-02-24T15:30:46Z", "published": "2024-03-29T15:30:31Z", "aliases": [ "CVE-2024-30426" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Hash Elements allows Stored XSS.This issue affects Hash Elements: from n/a through 1.3.3.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Hash Elements allows Stored XSS.This issue affects Hash Elements: from n/a through 1.3.3.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2025/02/GHSA-25gx-qr96-f826/GHSA-25gx-qr96-f826.json b/advisories/unreviewed/2025/02/GHSA-25gx-qr96-f826/GHSA-25gx-qr96-f826.json new file mode 100644 index 00000000000..c661593a3e6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-25gx-qr96-f826/GHSA-25gx-qr96-f826.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25gx-qr96-f826", + "modified": "2025-02-24T15:30:53Z", + "published": "2025-02-24T15:30:53Z", + "aliases": [ + "CVE-2025-27349" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nurelm Get Posts allows Stored XSS. This issue affects Get Posts: from n/a through 0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27349" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nurelm-get-posts/vulnerability/wordpress-get-posts-plugin-0-6-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-26mm-6qr4-6xj3/GHSA-26mm-6qr4-6xj3.json b/advisories/unreviewed/2025/02/GHSA-26mm-6qr4-6xj3/GHSA-26mm-6qr4-6xj3.json new file mode 100644 index 00000000000..ca81318b687 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-26mm-6qr4-6xj3/GHSA-26mm-6qr4-6xj3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26mm-6qr4-6xj3", + "modified": "2025-02-24T15:30:49Z", + "published": "2025-02-24T15:30:49Z", + "aliases": [ + "CVE-2024-12916" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Life4All allows SQL Injection.This issue affects Life4All: before 10.01.2025.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12916" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-25-0042" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2824-52jc-w55m/GHSA-2824-52jc-w55m.json b/advisories/unreviewed/2025/02/GHSA-2824-52jc-w55m/GHSA-2824-52jc-w55m.json new file mode 100644 index 00000000000..d5f05fad9f2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2824-52jc-w55m/GHSA-2824-52jc-w55m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2824-52jc-w55m", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27325" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruce Video.js HLS Player allows DOM-Based XSS. This issue affects Video.js HLS Player: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27325" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/videojs-hls-player/vulnerability/wordpress-video-js-hls-player-plugin-1-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-297w-r8j3-c69q/GHSA-297w-r8j3-c69q.json b/advisories/unreviewed/2025/02/GHSA-297w-r8j3-c69q/GHSA-297w-r8j3-c69q.json new file mode 100644 index 00000000000..a8bdaa76e0e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-297w-r8j3-c69q/GHSA-297w-r8j3-c69q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-297w-r8j3-c69q", + "modified": "2025-02-24T15:30:53Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27329" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in inlinkz EZ InLinkz linkup allows DOM-Based XSS. This issue affects EZ InLinkz linkup: from n/a through 0.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27329" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/inlinkz-scripter/vulnerability/wordpress-ez-inlinkz-linkup-plugin-0-18-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3775-gcxp-8pxm/GHSA-3775-gcxp-8pxm.json b/advisories/unreviewed/2025/02/GHSA-3775-gcxp-8pxm/GHSA-3775-gcxp-8pxm.json new file mode 100644 index 00000000000..c714c9b53c6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3775-gcxp-8pxm/GHSA-3775-gcxp-8pxm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3775-gcxp-8pxm", + "modified": "2025-02-24T15:30:53Z", + "published": "2025-02-24T15:30:53Z", + "aliases": [ + "CVE-2025-27335" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Free plug in by SEO Roma Auto Tag Links allows Cross Site Request Forgery. This issue affects Auto Tag Links: from n/a through 1.0.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27335" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/auto-tag-links/vulnerability/wordpress-auto-tag-links-plugin-1-0-13-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3m4p-3m6j-4rq2/GHSA-3m4p-3m6j-4rq2.json b/advisories/unreviewed/2025/02/GHSA-3m4p-3m6j-4rq2/GHSA-3m4p-3m6j-4rq2.json new file mode 100644 index 00000000000..5e2081c5743 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3m4p-3m6j-4rq2/GHSA-3m4p-3m6j-4rq2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3m4p-3m6j-4rq2", + "modified": "2025-02-24T15:30:51Z", + "published": "2025-02-24T15:30:51Z", + "aliases": [ + "CVE-2025-27277" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in tiefpunkt Add Linked Images To Gallery allows Cross Site Request Forgery. This issue affects Add Linked Images To Gallery: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27277" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/add-linked-images-to-gallery-v01/vulnerability/wordpress-add-linked-images-to-gallery-plugin-1-4-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3qqr-67hg-8c4v/GHSA-3qqr-67hg-8c4v.json b/advisories/unreviewed/2025/02/GHSA-3qqr-67hg-8c4v/GHSA-3qqr-67hg-8c4v.json new file mode 100644 index 00000000000..af50374c114 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3qqr-67hg-8c4v/GHSA-3qqr-67hg-8c4v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qqr-67hg-8c4v", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27323" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jon Bishop WP About Author allows DOM-Based XSS. This issue affects WP About Author: from n/a through 1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27323" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-about-author/vulnerability/wordpress-wp-about-author-plugin-1-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3x3j-pmx9-j3r7/GHSA-3x3j-pmx9-j3r7.json b/advisories/unreviewed/2025/02/GHSA-3x3j-pmx9-j3r7/GHSA-3x3j-pmx9-j3r7.json new file mode 100644 index 00000000000..b8909cc88e5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3x3j-pmx9-j3r7/GHSA-3x3j-pmx9-j3r7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x3j-pmx9-j3r7", + "modified": "2025-02-24T15:30:50Z", + "published": "2025-02-24T15:30:50Z", + "aliases": [ + "CVE-2025-23017" + ], + "details": "WorkOS Hosted AuthKit before 2025-01-07 allows a password authentication MFA bypass (by enrolling a new authentication factor) when the attacker knows the user's password. No exploitation occurred.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23017" + }, + { + "type": "WEB", + "url": "https://workos.com/security/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-305" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-486p-pvq9-8w7q/GHSA-486p-pvq9-8w7q.json b/advisories/unreviewed/2025/02/GHSA-486p-pvq9-8w7q/GHSA-486p-pvq9-8w7q.json new file mode 100644 index 00000000000..73b00af509f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-486p-pvq9-8w7q/GHSA-486p-pvq9-8w7q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-486p-pvq9-8w7q", + "modified": "2025-02-24T15:30:53Z", + "published": "2025-02-24T15:30:53Z", + "aliases": [ + "CVE-2025-27344" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in filipstepanov Phee's LinkPreview allows Cross Site Request Forgery. This issue affects Phee's LinkPreview: from n/a through 1.6.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27344" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/linkpreview/vulnerability/wordpress-phee-s-linkpreview-plugin-1-6-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4mw2-mw6m-p7x4/GHSA-4mw2-mw6m-p7x4.json b/advisories/unreviewed/2025/02/GHSA-4mw2-mw6m-p7x4/GHSA-4mw2-mw6m-p7x4.json new file mode 100644 index 00000000000..5e3c94be2af --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4mw2-mw6m-p7x4/GHSA-4mw2-mw6m-p7x4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mw2-mw6m-p7x4", + "modified": "2025-02-24T15:30:53Z", + "published": "2025-02-24T15:30:53Z", + "aliases": [ + "CVE-2025-27351" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpertBusinessSearch Local Search SEO Contact Page allows Stored XSS. This issue affects Local Search SEO Contact Page: from n/a through 4.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27351" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/local-search-seo-contact-page/vulnerability/wordpress-local-search-seo-contact-page-plugin-4-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5553-rf4f-g9qc/GHSA-5553-rf4f-g9qc.json b/advisories/unreviewed/2025/02/GHSA-5553-rf4f-g9qc/GHSA-5553-rf4f-g9qc.json new file mode 100644 index 00000000000..beb6aa19c3e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5553-rf4f-g9qc/GHSA-5553-rf4f-g9qc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5553-rf4f-g9qc", + "modified": "2025-02-24T15:30:50Z", + "published": "2025-02-24T15:30:50Z", + "aliases": [ + "CVE-2024-12917" + ], + "details": "Files or Directories Accessible to External Parties vulnerability in Agito Computer Health4All allows Exploiting Incorrectly Configured Access Control Security Levels, Authentication Abuse.This issue affects Health4All: before 10.01.2025.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12917" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-25-0042" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-56c7-jcxw-47mf/GHSA-56c7-jcxw-47mf.json b/advisories/unreviewed/2025/02/GHSA-56c7-jcxw-47mf/GHSA-56c7-jcxw-47mf.json new file mode 100644 index 00000000000..68f61600bd4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-56c7-jcxw-47mf/GHSA-56c7-jcxw-47mf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56c7-jcxw-47mf", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27318" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ixiter Simple Google Sitemap allows Cross Site Request Forgery. This issue affects Simple Google Sitemap: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27318" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-google-sitemap/vulnerability/wordpress-simple-google-sitemap-plugin-1-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5rg9-ph4r-3frg/GHSA-5rg9-ph4r-3frg.json b/advisories/unreviewed/2025/02/GHSA-5rg9-ph4r-3frg/GHSA-5rg9-ph4r-3frg.json index 6df771a6f4f..741e0246cc5 100644 --- a/advisories/unreviewed/2025/02/GHSA-5rg9-ph4r-3frg/GHSA-5rg9-ph4r-3frg.json +++ b/advisories/unreviewed/2025/02/GHSA-5rg9-ph4r-3frg/GHSA-5rg9-ph4r-3frg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5rg9-ph4r-3frg", - "modified": "2025-02-18T06:35:38Z", + "modified": "2025-02-24T15:30:47Z", "published": "2025-02-18T06:35:38Z", "aliases": [ "CVE-2024-12813" diff --git a/advisories/unreviewed/2025/02/GHSA-5x22-hprq-4vqq/GHSA-5x22-hprq-4vqq.json b/advisories/unreviewed/2025/02/GHSA-5x22-hprq-4vqq/GHSA-5x22-hprq-4vqq.json new file mode 100644 index 00000000000..fe4522422a8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5x22-hprq-4vqq/GHSA-5x22-hprq-4vqq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5x22-hprq-4vqq", + "modified": "2025-02-24T15:30:53Z", + "published": "2025-02-24T15:30:53Z", + "aliases": [ + "CVE-2025-27353" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Bob Namaste! LMS allows Cross Site Request Forgery. This issue affects Namaste! LMS: from n/a through 2.6.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27353" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/namaste-lms/vulnerability/wordpress-namaste-lms-plugin-2-6-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-736r-93pp-2mvh/GHSA-736r-93pp-2mvh.json b/advisories/unreviewed/2025/02/GHSA-736r-93pp-2mvh/GHSA-736r-93pp-2mvh.json new file mode 100644 index 00000000000..b41882b2374 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-736r-93pp-2mvh/GHSA-736r-93pp-2mvh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-736r-93pp-2mvh", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27301" + ], + "details": "Deserialization of Untrusted Data vulnerability in Nazmul Hasan Robin NHR Options Table Manager allows Object Injection. This issue affects NHR Options Table Manager: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27301" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nhrrob-options-table-manager/vulnerability/wordpress-nhr-options-table-manager-plugin-1-1-2-deserialization-of-untrusted-data-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-73vj-rj78-cc72/GHSA-73vj-rj78-cc72.json b/advisories/unreviewed/2025/02/GHSA-73vj-rj78-cc72/GHSA-73vj-rj78-cc72.json new file mode 100644 index 00000000000..19df111ff08 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-73vj-rj78-cc72/GHSA-73vj-rj78-cc72.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73vj-rj78-cc72", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27303" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themelogger Contact Form 7 Star Rating allows Stored XSS. This issue affects Contact Form 7 Star Rating: from n/a through 1.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27303" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/contact-form-7-star-rating/vulnerability/wordpress-contact-form-7-star-rating-plugin-1-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7927-94hw-7qx3/GHSA-7927-94hw-7qx3.json b/advisories/unreviewed/2025/02/GHSA-7927-94hw-7qx3/GHSA-7927-94hw-7qx3.json new file mode 100644 index 00000000000..f7a8f762581 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7927-94hw-7qx3/GHSA-7927-94hw-7qx3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7927-94hw-7qx3", + "modified": "2025-02-24T15:30:53Z", + "published": "2025-02-24T15:30:53Z", + "aliases": [ + "CVE-2025-27331" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sébastien Dumont WooCommerce Display Products by Tags allows DOM-Based XSS. This issue affects WooCommerce Display Products by Tags: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27331" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-display-products-by-tags/vulnerability/wordpress-woocommerce-display-products-by-tags-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-79mg-hfrx-5889/GHSA-79mg-hfrx-5889.json b/advisories/unreviewed/2025/02/GHSA-79mg-hfrx-5889/GHSA-79mg-hfrx-5889.json index 4d0b0f5543c..9766d750a82 100644 --- a/advisories/unreviewed/2025/02/GHSA-79mg-hfrx-5889/GHSA-79mg-hfrx-5889.json +++ b/advisories/unreviewed/2025/02/GHSA-79mg-hfrx-5889/GHSA-79mg-hfrx-5889.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-209" + "CWE-209", + "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-7fh8-cm5f-gg3q/GHSA-7fh8-cm5f-gg3q.json b/advisories/unreviewed/2025/02/GHSA-7fh8-cm5f-gg3q/GHSA-7fh8-cm5f-gg3q.json new file mode 100644 index 00000000000..7bc3b328f00 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7fh8-cm5f-gg3q/GHSA-7fh8-cm5f-gg3q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fh8-cm5f-gg3q", + "modified": "2025-02-24T15:30:53Z", + "published": "2025-02-24T15:30:53Z", + "aliases": [ + "CVE-2025-27357" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Musa AVCI Önceki Yazı Link allows Cross Site Request Forgery. This issue affects Önceki Yazı Link: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27357" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/onceki-yazi-linki/vulnerability/wordpress-oenceki-yazi-link-plugin-1-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7vcf-jcc6-ppj2/GHSA-7vcf-jcc6-ppj2.json b/advisories/unreviewed/2025/02/GHSA-7vcf-jcc6-ppj2/GHSA-7vcf-jcc6-ppj2.json index 0830e54aa03..280ae46ec89 100644 --- a/advisories/unreviewed/2025/02/GHSA-7vcf-jcc6-ppj2/GHSA-7vcf-jcc6-ppj2.json +++ b/advisories/unreviewed/2025/02/GHSA-7vcf-jcc6-ppj2/GHSA-7vcf-jcc6-ppj2.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-427" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-8p9v-vmfp-j798/GHSA-8p9v-vmfp-j798.json b/advisories/unreviewed/2025/02/GHSA-8p9v-vmfp-j798/GHSA-8p9v-vmfp-j798.json new file mode 100644 index 00000000000..f36c771ab92 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8p9v-vmfp-j798/GHSA-8p9v-vmfp-j798.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p9v-vmfp-j798", + "modified": "2025-02-24T15:30:51Z", + "published": "2025-02-24T15:30:51Z", + "aliases": [ + "CVE-2025-27265" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aaron D. Campbell Google Maps for WordPress allows DOM-Based XSS. This issue affects Google Maps for WordPress: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27265" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/google-maps-for-wordpress/vulnerability/wordpress-google-maps-for-wordpress-plugin-1-0-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8qrw-8hx5-vg32/GHSA-8qrw-8hx5-vg32.json b/advisories/unreviewed/2025/02/GHSA-8qrw-8hx5-vg32/GHSA-8qrw-8hx5-vg32.json new file mode 100644 index 00000000000..4588dd8178c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8qrw-8hx5-vg32/GHSA-8qrw-8hx5-vg32.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qrw-8hx5-vg32", + "modified": "2025-02-24T15:30:53Z", + "published": "2025-02-24T15:30:53Z", + "aliases": [ + "CVE-2025-27342" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in josesan WooCommerce Recargo de Equivalencia allows Cross Site Request Forgery. This issue affects WooCommerce Recargo de Equivalencia: from n/a through 1.6.24.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27342" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-recargo-de-equivalencia/vulnerability/wordpress-woocommerce-recargo-de-equivalencia-plugin-1-6-24-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8rqp-g9hp-4x68/GHSA-8rqp-g9hp-4x68.json b/advisories/unreviewed/2025/02/GHSA-8rqp-g9hp-4x68/GHSA-8rqp-g9hp-4x68.json index 61c5dac3e05..6c61d8ce51f 100644 --- a/advisories/unreviewed/2025/02/GHSA-8rqp-g9hp-4x68/GHSA-8rqp-g9hp-4x68.json +++ b/advisories/unreviewed/2025/02/GHSA-8rqp-g9hp-4x68/GHSA-8rqp-g9hp-4x68.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-209" + "CWE-209", + "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-8w8c-r2pm-xh9r/GHSA-8w8c-r2pm-xh9r.json b/advisories/unreviewed/2025/02/GHSA-8w8c-r2pm-xh9r/GHSA-8w8c-r2pm-xh9r.json new file mode 100644 index 00000000000..f965890fbfe --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8w8c-r2pm-xh9r/GHSA-8w8c-r2pm-xh9r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w8c-r2pm-xh9r", + "modified": "2025-02-24T15:30:51Z", + "published": "2025-02-24T15:30:51Z", + "aliases": [ + "CVE-2025-27276" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in lizeipe Photo Gallery ( Responsive ) allows Privilege Escalation. This issue affects Photo Gallery ( Responsive ): from n/a through 4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27276" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/photo-gallery-pearlbells/vulnerability/wordpress-photo-gallery-responsive-plugin-4-0-csrf-to-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8xgg-j54h-3gpg/GHSA-8xgg-j54h-3gpg.json b/advisories/unreviewed/2025/02/GHSA-8xgg-j54h-3gpg/GHSA-8xgg-j54h-3gpg.json index 0959422ae14..d78f2ba98fe 100644 --- a/advisories/unreviewed/2025/02/GHSA-8xgg-j54h-3gpg/GHSA-8xgg-j54h-3gpg.json +++ b/advisories/unreviewed/2025/02/GHSA-8xgg-j54h-3gpg/GHSA-8xgg-j54h-3gpg.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-93cq-gv6v-xr7v/GHSA-93cq-gv6v-xr7v.json b/advisories/unreviewed/2025/02/GHSA-93cq-gv6v-xr7v/GHSA-93cq-gv6v-xr7v.json index 30f524971f8..637337ceef2 100644 --- a/advisories/unreviewed/2025/02/GHSA-93cq-gv6v-xr7v/GHSA-93cq-gv6v-xr7v.json +++ b/advisories/unreviewed/2025/02/GHSA-93cq-gv6v-xr7v/GHSA-93cq-gv6v-xr7v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-93cq-gv6v-xr7v", - "modified": "2025-02-18T06:35:38Z", + "modified": "2025-02-24T15:30:48Z", "published": "2025-02-18T06:35:38Z", "aliases": [ "CVE-2024-13565" diff --git a/advisories/unreviewed/2025/02/GHSA-9q3v-f9ch-76v7/GHSA-9q3v-f9ch-76v7.json b/advisories/unreviewed/2025/02/GHSA-9q3v-f9ch-76v7/GHSA-9q3v-f9ch-76v7.json new file mode 100644 index 00000000000..4b9fb2dd7df --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9q3v-f9ch-76v7/GHSA-9q3v-f9ch-76v7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q3v-f9ch-76v7", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27297" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in guelben Bravo Search & Replace allows Blind SQL Injection. This issue affects Bravo Search & Replace: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27297" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bravo-search-and-replace/vulnerability/wordpress-bravo-search-replace-plugin-1-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-c2p9-qv8x-42cj/GHSA-c2p9-qv8x-42cj.json b/advisories/unreviewed/2025/02/GHSA-c2p9-qv8x-42cj/GHSA-c2p9-qv8x-42cj.json index 1bed7eb6a6f..7f56d84c524 100644 --- a/advisories/unreviewed/2025/02/GHSA-c2p9-qv8x-42cj/GHSA-c2p9-qv8x-42cj.json +++ b/advisories/unreviewed/2025/02/GHSA-c2p9-qv8x-42cj/GHSA-c2p9-qv8x-42cj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c2p9-qv8x-42cj", - "modified": "2025-02-22T15:30:51Z", + "modified": "2025-02-24T15:30:48Z", "published": "2025-02-22T15:30:51Z", "aliases": [ "CVE-2024-52939" ], "details": "Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write data outside the Guest's virtualised GPU memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-823" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-22T15:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-c3ff-v8pw-m28w/GHSA-c3ff-v8pw-m28w.json b/advisories/unreviewed/2025/02/GHSA-c3ff-v8pw-m28w/GHSA-c3ff-v8pw-m28w.json new file mode 100644 index 00000000000..7184318cd54 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-c3ff-v8pw-m28w/GHSA-c3ff-v8pw-m28w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3ff-v8pw-m28w", + "modified": "2025-02-24T15:30:51Z", + "published": "2025-02-24T15:30:51Z", + "aliases": [ + "CVE-2025-27280" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alobaidi Archive Page allows DOM-Based XSS. This issue affects Archive Page: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27280" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/archive-page/vulnerability/wordpress-archive-page-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-c7wx-6527-3jvg/GHSA-c7wx-6527-3jvg.json b/advisories/unreviewed/2025/02/GHSA-c7wx-6527-3jvg/GHSA-c7wx-6527-3jvg.json new file mode 100644 index 00000000000..3042ded5b4c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-c7wx-6527-3jvg/GHSA-c7wx-6527-3jvg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7wx-6527-3jvg", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27317" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in IT-RAYS RAYS Grid allows Cross Site Request Forgery. This issue affects RAYS Grid: from n/a through 1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27317" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rays-grid/vulnerability/wordpress-rays-grid-plugin-1-3-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cr92-jq55-gj75/GHSA-cr92-jq55-gj75.json b/advisories/unreviewed/2025/02/GHSA-cr92-jq55-gj75/GHSA-cr92-jq55-gj75.json new file mode 100644 index 00000000000..da8aa9e07d1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cr92-jq55-gj75/GHSA-cr92-jq55-gj75.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr92-jq55-gj75", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27311" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in luk3thomas Bulk Content Creator allows Cross Site Request Forgery. This issue affects Bulk Content Creator: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27311" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bulk-content-creator/vulnerability/wordpress-bulk-content-creator-plugin-1-2-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-crrc-pmgr-mphw/GHSA-crrc-pmgr-mphw.json b/advisories/unreviewed/2025/02/GHSA-crrc-pmgr-mphw/GHSA-crrc-pmgr-mphw.json new file mode 100644 index 00000000000..a52292b8c75 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-crrc-pmgr-mphw/GHSA-crrc-pmgr-mphw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crrc-pmgr-mphw", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27290" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in seyyed-amir Erima Zarinpal Donate allows Cross Site Request Forgery. This issue affects Erima Zarinpal Donate: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27290" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/erima-zarinpal-donate/vulnerability/wordpress-select-erima-zarinpal-donate-plugin-1-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cv45-3m55-xp7r/GHSA-cv45-3m55-xp7r.json b/advisories/unreviewed/2025/02/GHSA-cv45-3m55-xp7r/GHSA-cv45-3m55-xp7r.json new file mode 100644 index 00000000000..a777cc684bb --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cv45-3m55-xp7r/GHSA-cv45-3m55-xp7r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv45-3m55-xp7r", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27304" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themelogger Contact Form 7 Star Rating with font Awesome allows Stored XSS. This issue affects Contact Form 7 Star Rating with font Awesome: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27304" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/contact-form-7-star-rating-with-font-awersome/vulnerability/wordpress-contact-form-7-star-rating-with-font-awesome-plugin-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cv6c-2jmj-cr4h/GHSA-cv6c-2jmj-cr4h.json b/advisories/unreviewed/2025/02/GHSA-cv6c-2jmj-cr4h/GHSA-cv6c-2jmj-cr4h.json new file mode 100644 index 00000000000..5677e739fff --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cv6c-2jmj-cr4h/GHSA-cv6c-2jmj-cr4h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv6c-2jmj-cr4h", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27315" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in wptom All-In-One Cufon allows Cross Site Request Forgery. This issue affects All-In-One Cufon: from n/a through 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27315" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/all-in-one-cufon/vulnerability/wordpress-all-in-one-cufon-plugin-1-3-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cw9m-pj72-3cj5/GHSA-cw9m-pj72-3cj5.json b/advisories/unreviewed/2025/02/GHSA-cw9m-pj72-3cj5/GHSA-cw9m-pj72-3cj5.json new file mode 100644 index 00000000000..d552b1c9d08 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cw9m-pj72-3cj5/GHSA-cw9m-pj72-3cj5.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cw9m-pj72-3cj5", + "modified": "2025-02-24T15:30:49Z", + "published": "2025-02-24T15:30:49Z", + "aliases": [ + "CVE-2025-1632" + ], + "details": "A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1632" + }, + { + "type": "WEB", + "url": "https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.296619" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.296619" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.496460" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f872-rr6m-x9r7/GHSA-f872-rr6m-x9r7.json b/advisories/unreviewed/2025/02/GHSA-f872-rr6m-x9r7/GHSA-f872-rr6m-x9r7.json new file mode 100644 index 00000000000..02595321f96 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f872-rr6m-x9r7/GHSA-f872-rr6m-x9r7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f872-rr6m-x9r7", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27307" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oooorgle Quotes llama allows Reflected XSS. This issue affects Quotes llama: from n/a through 3.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27307" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quotes-llama/vulnerability/wordpress-quotes-llama-plugin-3-0-1-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fchw-7cp9-hjpp/GHSA-fchw-7cp9-hjpp.json b/advisories/unreviewed/2025/02/GHSA-fchw-7cp9-hjpp/GHSA-fchw-7cp9-hjpp.json new file mode 100644 index 00000000000..5413f690ae3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fchw-7cp9-hjpp/GHSA-fchw-7cp9-hjpp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fchw-7cp9-hjpp", + "modified": "2025-02-24T15:30:53Z", + "published": "2025-02-24T15:30:53Z", + "aliases": [ + "CVE-2025-27341" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in afzal_du Reactive Mortgage Calculator allows Stored XSS. This issue affects Reactive Mortgage Calculator: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27341" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/reactive-mortgage-calculator/vulnerability/wordpress-reactive-mortgage-calculator-plugin-1-1-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-ghh6-jcf7-xpx9/GHSA-ghh6-jcf7-xpx9.json b/advisories/unreviewed/2025/02/GHSA-ghh6-jcf7-xpx9/GHSA-ghh6-jcf7-xpx9.json new file mode 100644 index 00000000000..c8d953fa4e0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-ghh6-jcf7-xpx9/GHSA-ghh6-jcf7-xpx9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghh6-jcf7-xpx9", + "modified": "2025-02-24T15:30:53Z", + "published": "2025-02-24T15:30:53Z", + "aliases": [ + "CVE-2025-27347" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in techmix Direct Checkout Button for WooCommerce allows Stored XSS. This issue affects Direct Checkout Button for WooCommerce: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27347" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-direct-checkout-button/vulnerability/wordpress-direct-checkout-button-for-woocommerce-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gv2g-83jv-h4v9/GHSA-gv2g-83jv-h4v9.json b/advisories/unreviewed/2025/02/GHSA-gv2g-83jv-h4v9/GHSA-gv2g-83jv-h4v9.json index ab24cbfb494..d752d092b1d 100644 --- a/advisories/unreviewed/2025/02/GHSA-gv2g-83jv-h4v9/GHSA-gv2g-83jv-h4v9.json +++ b/advisories/unreviewed/2025/02/GHSA-gv2g-83jv-h4v9/GHSA-gv2g-83jv-h4v9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gv2g-83jv-h4v9", - "modified": "2025-02-18T06:35:38Z", + "modified": "2025-02-24T15:30:48Z", "published": "2025-02-18T06:35:38Z", "aliases": [ "CVE-2024-13555" diff --git a/advisories/unreviewed/2025/02/GHSA-h764-fh5p-vfc9/GHSA-h764-fh5p-vfc9.json b/advisories/unreviewed/2025/02/GHSA-h764-fh5p-vfc9/GHSA-h764-fh5p-vfc9.json new file mode 100644 index 00000000000..aff4ad8ba37 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h764-fh5p-vfc9/GHSA-h764-fh5p-vfc9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h764-fh5p-vfc9", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27316" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in hosting.io JPG, PNG Compression and Optimization allows Cross Site Request Forgery. This issue affects JPG, PNG Compression and Optimization: from n/a through 1.7.35.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27316" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-image-compression/vulnerability/wordpress-jpg-png-compression-and-optimization-plugin-1-7-35-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h7xh-jqw8-mhx8/GHSA-h7xh-jqw8-mhx8.json b/advisories/unreviewed/2025/02/GHSA-h7xh-jqw8-mhx8/GHSA-h7xh-jqw8-mhx8.json new file mode 100644 index 00000000000..70a2fc17e51 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h7xh-jqw8-mhx8/GHSA-h7xh-jqw8-mhx8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7xh-jqw8-mhx8", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27294" + ], + "details": "Missing Authorization vulnerability in platcom WP-Asambleas allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP-Asambleas: from n/a through 2.85.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27294" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-asambleas/vulnerability/wordpress-wp-asambleas-plugin-2-85-0-arbitrary-shortcode-execution-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hcp8-2v69-c2fm/GHSA-hcp8-2v69-c2fm.json b/advisories/unreviewed/2025/02/GHSA-hcp8-2v69-c2fm/GHSA-hcp8-2v69-c2fm.json new file mode 100644 index 00000000000..f99ef9fb0cd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hcp8-2v69-c2fm/GHSA-hcp8-2v69-c2fm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcp8-2v69-c2fm", + "modified": "2025-02-24T15:30:50Z", + "published": "2025-02-24T15:30:50Z", + "aliases": [ + "CVE-2025-26883" + ], + "details": "Missing Authorization vulnerability in bPlugins Animated Text Block allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Animated Text Block: from n/a through 1.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26883" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/animated-text-block/vulnerability/wordpress-animated-text-block-plugin-1-0-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hv9g-xmv8-5frh/GHSA-hv9g-xmv8-5frh.json b/advisories/unreviewed/2025/02/GHSA-hv9g-xmv8-5frh/GHSA-hv9g-xmv8-5frh.json new file mode 100644 index 00000000000..7373494cf55 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hv9g-xmv8-5frh/GHSA-hv9g-xmv8-5frh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hv9g-xmv8-5frh", + "modified": "2025-02-24T15:30:48Z", + "published": "2025-02-24T15:30:48Z", + "aliases": [ + "CVE-2024-5174" + ], + "details": "A flaw in Gliffy results in broken authentication through the reset functionality of the application.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5174" + }, + { + "type": "WEB", + "url": "https://portal.perforce.com/s/detail/a91PA000001ScD3YAK" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hvxc-4j7p-9r6f/GHSA-hvxc-4j7p-9r6f.json b/advisories/unreviewed/2025/02/GHSA-hvxc-4j7p-9r6f/GHSA-hvxc-4j7p-9r6f.json new file mode 100644 index 00000000000..9cba71c88b8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hvxc-4j7p-9r6f/GHSA-hvxc-4j7p-9r6f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvxc-4j7p-9r6f", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27305" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Achal Jain Table of Contents Block allows Stored XSS. This issue affects Table of Contents Block: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27305" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/table-of-contents/vulnerability/wordpress-table-of-contents-block-plugin-1-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hwff-5jf9-m789/GHSA-hwff-5jf9-m789.json b/advisories/unreviewed/2025/02/GHSA-hwff-5jf9-m789/GHSA-hwff-5jf9-m789.json new file mode 100644 index 00000000000..c66e44a3d89 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hwff-5jf9-m789/GHSA-hwff-5jf9-m789.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwff-5jf9-m789", + "modified": "2025-02-24T15:30:53Z", + "published": "2025-02-24T15:30:53Z", + "aliases": [ + "CVE-2025-27348" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel WP Social SEO Booster – Knowledge Graph Social Signals SEO allows Stored XSS. This issue affects WP Social SEO Booster – Knowledge Graph Social Signals SEO: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27348" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-social-seo-booster/vulnerability/wordpress-wp-social-seo-booster-plugin-1-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j69j-6h4m-c446/GHSA-j69j-6h4m-c446.json b/advisories/unreviewed/2025/02/GHSA-j69j-6h4m-c446/GHSA-j69j-6h4m-c446.json new file mode 100644 index 00000000000..acb84baf64c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-j69j-6h4m-c446/GHSA-j69j-6h4m-c446.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j69j-6h4m-c446", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27328" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in queeez WP-PostRatings Cheater allows Cross Site Request Forgery. This issue affects WP-PostRatings Cheater: from n/a through 1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27328" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-postratings-cheater/vulnerability/wordpress-wp-postratings-cheater-plugin-1-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jpq8-pr23-m9c6/GHSA-jpq8-pr23-m9c6.json b/advisories/unreviewed/2025/02/GHSA-jpq8-pr23-m9c6/GHSA-jpq8-pr23-m9c6.json new file mode 100644 index 00000000000..5a2647a5dc4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jpq8-pr23-m9c6/GHSA-jpq8-pr23-m9c6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpq8-pr23-m9c6", + "modified": "2025-02-24T15:30:50Z", + "published": "2025-02-24T15:30:50Z", + "aliases": [ + "CVE-2024-12918" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Health4All allows SQL Injection.This issue affects Health4All: before 10.01.2025.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12918" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-25-0042" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m2px-76cx-93fc/GHSA-m2px-76cx-93fc.json b/advisories/unreviewed/2025/02/GHSA-m2px-76cx-93fc/GHSA-m2px-76cx-93fc.json new file mode 100644 index 00000000000..3374d8029c5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m2px-76cx-93fc/GHSA-m2px-76cx-93fc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2px-76cx-93fc", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27298" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in cmstactics WP Video Posts allows OS Command Injection. This issue affects WP Video Posts: from n/a through 3.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27298" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-video-posts/vulnerability/wordpress-wp-video-posts-plugin-3-5-1-csrf-to-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m6ff-f9xg-9wxx/GHSA-m6ff-f9xg-9wxx.json b/advisories/unreviewed/2025/02/GHSA-m6ff-f9xg-9wxx/GHSA-m6ff-f9xg-9wxx.json new file mode 100644 index 00000000000..70f0b5541c8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m6ff-f9xg-9wxx/GHSA-m6ff-f9xg-9wxx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6ff-f9xg-9wxx", + "modified": "2025-02-24T15:30:53Z", + "published": "2025-02-24T15:30:53Z", + "aliases": [ + "CVE-2025-27356" + ], + "details": "Missing Authorization vulnerability in Hardik Sticky Header On Scroll allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sticky Header On Scroll: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27356" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sticky-header-on-scroll/vulnerability/wordpress-sticky-header-on-scroll-plugin-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mqcj-7rfq-46jf/GHSA-mqcj-7rfq-46jf.json b/advisories/unreviewed/2025/02/GHSA-mqcj-7rfq-46jf/GHSA-mqcj-7rfq-46jf.json new file mode 100644 index 00000000000..46e7d67bc32 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mqcj-7rfq-46jf/GHSA-mqcj-7rfq-46jf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqcj-7rfq-46jf", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27321" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Blighty Blightly Explorer allows Stored XSS. This issue affects Blightly Explorer: from n/a through 2.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27321" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/blighty-explorer/vulnerability/wordpress-blightly-explorer-plugin-2-3-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mwr3-8q5m-r388/GHSA-mwr3-8q5m-r388.json b/advisories/unreviewed/2025/02/GHSA-mwr3-8q5m-r388/GHSA-mwr3-8q5m-r388.json new file mode 100644 index 00000000000..039f736eb79 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mwr3-8q5m-r388/GHSA-mwr3-8q5m-r388.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwr3-8q5m-r388", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27320" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pankaj Mondal Profile Widget Ninja allows DOM-Based XSS. This issue affects Profile Widget Ninja: from n/a through 4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27320" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/profile-widget-ninja/vulnerability/wordpress-profile-widget-ninja-plugin-4-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p4vv-vjj8-538h/GHSA-p4vv-vjj8-538h.json b/advisories/unreviewed/2025/02/GHSA-p4vv-vjj8-538h/GHSA-p4vv-vjj8-538h.json new file mode 100644 index 00000000000..02164328390 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p4vv-vjj8-538h/GHSA-p4vv-vjj8-538h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4vv-vjj8-538h", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27312" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jenst WP Sitemap allows SQL Injection. This issue affects WP Sitemap: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27312" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-sitemap/vulnerability/wordpress-wp-sitemap-plugin-1-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p555-fgxh-v7q6/GHSA-p555-fgxh-v7q6.json b/advisories/unreviewed/2025/02/GHSA-p555-fgxh-v7q6/GHSA-p555-fgxh-v7q6.json new file mode 100644 index 00000000000..6949f7a01db --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p555-fgxh-v7q6/GHSA-p555-fgxh-v7q6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p555-fgxh-v7q6", + "modified": "2025-02-24T15:30:49Z", + "published": "2025-02-24T15:30:49Z", + "aliases": [ + "CVE-2025-0545" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tekrom Technology T-Soft E-Commerce allows Cross-Site Scripting (XSS).This issue affects T-Soft E-Commerce: before v5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0545" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-25-0041" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pw98-79r8-4mjg/GHSA-pw98-79r8-4mjg.json b/advisories/unreviewed/2025/02/GHSA-pw98-79r8-4mjg/GHSA-pw98-79r8-4mjg.json new file mode 100644 index 00000000000..5394eb8580b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pw98-79r8-4mjg/GHSA-pw98-79r8-4mjg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw98-79r8-4mjg", + "modified": "2025-02-24T15:30:53Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27330" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PlayerJS PlayerJS allows DOM-Based XSS. This issue affects PlayerJS: from n/a through 2.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27330" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/playerjs/vulnerability/wordpress-playerjs-plugin-2-23-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pxh9-q2hp-6252/GHSA-pxh9-q2hp-6252.json b/advisories/unreviewed/2025/02/GHSA-pxh9-q2hp-6252/GHSA-pxh9-q2hp-6252.json new file mode 100644 index 00000000000..8537b6ccfea --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pxh9-q2hp-6252/GHSA-pxh9-q2hp-6252.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxh9-q2hp-6252", + "modified": "2025-02-24T15:30:53Z", + "published": "2025-02-24T15:30:53Z", + "aliases": [ + "CVE-2025-27352" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wumii team 无觅相关文章插件 allows Stored XSS. This issue affects 无觅相关文章插件: from n/a through 1.0.5.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27352" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wumii-related-posts/vulnerability/wordpress-plugin-1-0-5-7-csrf-to-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-q34f-q4r4-rg8f/GHSA-q34f-q4r4-rg8f.json b/advisories/unreviewed/2025/02/GHSA-q34f-q4r4-rg8f/GHSA-q34f-q4r4-rg8f.json new file mode 100644 index 00000000000..bc0c16a0c93 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-q34f-q4r4-rg8f/GHSA-q34f-q4r4-rg8f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q34f-q4r4-rg8f", + "modified": "2025-02-24T15:30:53Z", + "published": "2025-02-24T15:30:53Z", + "aliases": [ + "CVE-2025-27332" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in gmnazmul Smart Maintenance & Countdown allows Stored XSS. This issue affects Smart Maintenance & Countdown: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27332" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/smart-maintenance-countdown/vulnerability/wordpress-smart-maintenance-countdown-plugin-1-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-q598-5464-x6q8/GHSA-q598-5464-x6q8.json b/advisories/unreviewed/2025/02/GHSA-q598-5464-x6q8/GHSA-q598-5464-x6q8.json index ae56ddcb054..fdf9d4d2ea7 100644 --- a/advisories/unreviewed/2025/02/GHSA-q598-5464-x6q8/GHSA-q598-5464-x6q8.json +++ b/advisories/unreviewed/2025/02/GHSA-q598-5464-x6q8/GHSA-q598-5464-x6q8.json @@ -38,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/02/GHSA-qg2c-hj47-j83g/GHSA-qg2c-hj47-j83g.json b/advisories/unreviewed/2025/02/GHSA-qg2c-hj47-j83g/GHSA-qg2c-hj47-j83g.json new file mode 100644 index 00000000000..d7d4dfdf48c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qg2c-hj47-j83g/GHSA-qg2c-hj47-j83g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg2c-hj47-j83g", + "modified": "2025-02-24T15:30:51Z", + "published": "2025-02-24T15:30:51Z", + "aliases": [ + "CVE-2025-27272" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in vinagecko VG PostCarousel allows PHP Local File Inclusion. This issue affects VG PostCarousel: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27272" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/vg-postcarousel/vulnerability/wordpress-vg-postcarousel-plugin-1-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qm52-xrp7-84q5/GHSA-qm52-xrp7-84q5.json b/advisories/unreviewed/2025/02/GHSA-qm52-xrp7-84q5/GHSA-qm52-xrp7-84q5.json new file mode 100644 index 00000000000..d7939fe1370 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qm52-xrp7-84q5/GHSA-qm52-xrp7-84q5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm52-xrp7-84q5", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27306" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pathomation Pathomation allows Stored XSS. This issue affects Pathomation: from n/a through 2.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27306" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pathomation/vulnerability/wordpress-pathomation-plugin-2-5-1-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r3jw-928j-3957/GHSA-r3jw-928j-3957.json b/advisories/unreviewed/2025/02/GHSA-r3jw-928j-3957/GHSA-r3jw-928j-3957.json new file mode 100644 index 00000000000..58d61ffa05a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r3jw-928j-3957/GHSA-r3jw-928j-3957.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3jw-928j-3957", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27296" + ], + "details": "Missing Authorization vulnerability in revenueflex Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue: from n/a through 1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27296" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/revenueflex-easy-ads/vulnerability/wordpress-auto-ad-inserter-increase-google-adsense-and-ad-manager-revenue-plugin-1-5-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rph7-pv2v-px9j/GHSA-rph7-pv2v-px9j.json b/advisories/unreviewed/2025/02/GHSA-rph7-pv2v-px9j/GHSA-rph7-pv2v-px9j.json new file mode 100644 index 00000000000..b44c8fe00c3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rph7-pv2v-px9j/GHSA-rph7-pv2v-px9j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rph7-pv2v-px9j", + "modified": "2025-02-24T15:30:53Z", + "published": "2025-02-24T15:30:53Z", + "aliases": [ + "CVE-2025-27340" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Marc F12-Profiler allows Cross Site Request Forgery. This issue affects F12-Profiler: from n/a through 1.3.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27340" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/f12-profiler/vulnerability/wordpress-f12-profiler-plugin-1-3-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vmjx-294p-54xm/GHSA-vmjx-294p-54xm.json b/advisories/unreviewed/2025/02/GHSA-vmjx-294p-54xm/GHSA-vmjx-294p-54xm.json new file mode 100644 index 00000000000..31cb013180c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vmjx-294p-54xm/GHSA-vmjx-294p-54xm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmjx-294p-54xm", + "modified": "2025-02-24T15:30:53Z", + "published": "2025-02-24T15:30:53Z", + "aliases": [ + "CVE-2025-27336" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Alex Prokopenko / JustCoded Just Variables allows Cross Site Request Forgery. This issue affects Just Variables: from n/a through 1.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27336" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/just-wp-variables/vulnerability/wordpress-just-variables-plugin-1-2-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-w8hr-h827-x7c3/GHSA-w8hr-h827-x7c3.json b/advisories/unreviewed/2025/02/GHSA-w8hr-h827-x7c3/GHSA-w8hr-h827-x7c3.json new file mode 100644 index 00000000000..9aebfb6990c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-w8hr-h827-x7c3/GHSA-w8hr-h827-x7c3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8hr-h827-x7c3", + "modified": "2025-02-24T15:30:51Z", + "published": "2025-02-24T15:30:51Z", + "aliases": [ + "CVE-2025-27266" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ignacio Perez Hover Image Button allows DOM-Based XSS. This issue affects Hover Image Button: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27266" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hover-image-button/vulnerability/wordpress-hover-image-button-plugin-1-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wh8c-9r6f-25hp/GHSA-wh8c-9r6f-25hp.json b/advisories/unreviewed/2025/02/GHSA-wh8c-9r6f-25hp/GHSA-wh8c-9r6f-25hp.json new file mode 100644 index 00000000000..295d42f095e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wh8c-9r6f-25hp/GHSA-wh8c-9r6f-25hp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh8c-9r6f-25hp", + "modified": "2025-02-24T15:30:53Z", + "published": "2025-02-24T15:30:53Z", + "aliases": [ + "CVE-2025-27355" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Nicolas GRILLET Woocommerce – Loi Hamon allows Stored XSS. This issue affects Woocommerce – Loi Hamon: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27355" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/loi-hamon/vulnerability/wordpress-woocommerce-loi-hamon-plugin-1-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-ww6h-9f7x-62fr/GHSA-ww6h-9f7x-62fr.json b/advisories/unreviewed/2025/02/GHSA-ww6h-9f7x-62fr/GHSA-ww6h-9f7x-62fr.json new file mode 100644 index 00000000000..16b853b7ef1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-ww6h-9f7x-62fr/GHSA-ww6h-9f7x-62fr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww6h-9f7x-62fr", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27327" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Winlin Live Streaming Video Player – by SRS Player allows DOM-Based XSS. This issue affects Live Streaming Video Player – by SRS Player: from n/a through 1.0.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27327" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/srs-player/vulnerability/wordpress-live-streaming-video-player-by-srs-player-plugin-1-0-18-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x664-7q93-cmgg/GHSA-x664-7q93-cmgg.json b/advisories/unreviewed/2025/02/GHSA-x664-7q93-cmgg/GHSA-x664-7q93-cmgg.json new file mode 100644 index 00000000000..895f85e9a52 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x664-7q93-cmgg/GHSA-x664-7q93-cmgg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x664-7q93-cmgg", + "modified": "2025-02-24T15:30:53Z", + "published": "2025-02-24T15:30:53Z", + "aliases": [ + "CVE-2025-27339" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Will Anderson Minimum Password Strength allows Cross Site Request Forgery. This issue affects Minimum Password Strength: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27339" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/minimum-password-strength/vulnerability/wordpress-minimum-password-strength-plugin-1-2-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xvpj-rpwv-6v3h/GHSA-xvpj-rpwv-6v3h.json b/advisories/unreviewed/2025/02/GHSA-xvpj-rpwv-6v3h/GHSA-xvpj-rpwv-6v3h.json new file mode 100644 index 00000000000..20a06cdb710 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xvpj-rpwv-6v3h/GHSA-xvpj-rpwv-6v3h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvpj-rpwv-6v3h", + "modified": "2025-02-24T15:30:52Z", + "published": "2025-02-24T15:30:52Z", + "aliases": [ + "CVE-2025-27300" + ], + "details": "Deserialization of Untrusted Data vulnerability in giuliopanda ADFO allows Object Injection. This issue affects ADFO: from n/a through 1.9.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27300" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/admin-form/vulnerability/wordpress-adfo-plugin-1-9-1-deserialization-of-untrusted-data-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T15:15:15Z" + } +} \ No newline at end of file