diff --git a/advisories/unreviewed/2025/01/GHSA-2cwp-9vcw-fc97/GHSA-2cwp-9vcw-fc97.json b/advisories/unreviewed/2025/01/GHSA-2cwp-9vcw-fc97/GHSA-2cwp-9vcw-fc97.json new file mode 100644 index 00000000000..6b7af05c6b6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2cwp-9vcw-fc97/GHSA-2cwp-9vcw-fc97.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cwp-9vcw-fc97", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2025-22293" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gutentor Gutentor allows DOM-Based XSS.This issue affects Gutentor: from n/a through 3.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22293" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gutentor/vulnerability/wordpress-gutentor-plugin-3-4-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2v5m-7mpw-7w7j/GHSA-2v5m-7mpw-7w7j.json b/advisories/unreviewed/2025/01/GHSA-2v5m-7mpw-7w7j/GHSA-2v5m-7mpw-7w7j.json new file mode 100644 index 00000000000..8bc356f2909 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2v5m-7mpw-7w7j/GHSA-2v5m-7mpw-7w7j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v5m-7mpw-7w7j", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22333" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor allows Stored XSS.This issue affects Piotnet Addons For Elementor: from n/a through 2.4.31.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22333" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/piotnet-addons-for-elementor/vulnerability/wordpress-piotnet-addons-for-elementor-plugin-2-4-31-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2wvv-4p4q-7mq5/GHSA-2wvv-4p4q-7mq5.json b/advisories/unreviewed/2025/01/GHSA-2wvv-4p4q-7mq5/GHSA-2wvv-4p4q-7mq5.json new file mode 100644 index 00000000000..db15ecc5d63 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2wvv-4p4q-7mq5/GHSA-2wvv-4p4q-7mq5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wvv-4p4q-7mq5", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22302" + ], + "details": "Missing Authorization vulnerability in WP Wand WP Wand allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Wand: from n/a through 1.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22302" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ai-content-generation/vulnerability/wordpress-wp-wand-plugin-1-2-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2xjp-g4vr-mgh3/GHSA-2xjp-g4vr-mgh3.json b/advisories/unreviewed/2025/01/GHSA-2xjp-g4vr-mgh3/GHSA-2xjp-g4vr-mgh3.json new file mode 100644 index 00000000000..95c02389797 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2xjp-g4vr-mgh3/GHSA-2xjp-g4vr-mgh3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xjp-g4vr-mgh3", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56290" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerce allows SQL Injection.This issue affects Multiple Shipping And Billing Address For Woocommerce: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56290" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/different-shipping-and-billing-address-for-woocommerce/vulnerability/wordpress-multiple-shipping-and-billing-address-for-woocommerce-plugin-1-2-unauthenticated-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-32x8-mv4r-c7xp/GHSA-32x8-mv4r-c7xp.json b/advisories/unreviewed/2025/01/GHSA-32x8-mv4r-c7xp/GHSA-32x8-mv4r-c7xp.json new file mode 100644 index 00000000000..7b05ac6fbda --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-32x8-mv4r-c7xp/GHSA-32x8-mv4r-c7xp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32x8-mv4r-c7xp", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22357" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simple Plugins Target Notifications allows Reflected XSS.This issue affects Target Notifications: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22357" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/target-notifications/vulnerability/wordpress-target-notifications-plugin-1-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-33q2-cxrh-v3f9/GHSA-33q2-cxrh-v3f9.json b/advisories/unreviewed/2025/01/GHSA-33q2-cxrh-v3f9/GHSA-33q2-cxrh-v3f9.json new file mode 100644 index 00000000000..1213a8ad1eb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-33q2-cxrh-v3f9/GHSA-33q2-cxrh-v3f9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33q2-cxrh-v3f9", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56281" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodeMShop 워드프레스 결제 심플페이 allows PHP Local File Inclusion.This issue affects 워드프레스 결제 심플페이: from n/a through 5.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56281" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pgall-for-woocommerce/vulnerability/wordpress-plugin-5-2-0-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3g64-6hgp-5m64/GHSA-3g64-6hgp-5m64.json b/advisories/unreviewed/2025/01/GHSA-3g64-6hgp-5m64/GHSA-3g64-6hgp-5m64.json new file mode 100644 index 00000000000..d9259bb5848 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3g64-6hgp-5m64/GHSA-3g64-6hgp-5m64.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g64-6hgp-5m64", + "modified": "2025-01-07T12:30:58Z", + "published": "2025-01-07T12:30:58Z", + "aliases": [ + "CVE-2024-43243" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGlow JobBoard Job listing allows Upload a Web Shell to a Web Server.This issue affects JobBoard Job listing: from n/a through 1.2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43243" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/job-board-light/vulnerability/wordpress-jobboard-job-listing-plugin-1-2-6-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3j37-r883-3mwm/GHSA-3j37-r883-3mwm.json b/advisories/unreviewed/2025/01/GHSA-3j37-r883-3mwm/GHSA-3j37-r883-3mwm.json new file mode 100644 index 00000000000..1c9f0abeb46 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3j37-r883-3mwm/GHSA-3j37-r883-3mwm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j37-r883-3mwm", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56286" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Classic Addons Classic Addons – WPBakery Page Builder allows PHP Local File Inclusion.This issue affects Classic Addons – WPBakery Page Builder: from n/a through 3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56286" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/classic-addons-wpbakery-page-builder-addons/vulnerability/wordpress-classic-addons-wpbakery-page-builder-plugin-3-0-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3rg4-57j5-xx9q/GHSA-3rg4-57j5-xx9q.json b/advisories/unreviewed/2025/01/GHSA-3rg4-57j5-xx9q/GHSA-3rg4-57j5-xx9q.json new file mode 100644 index 00000000000..16f69c30361 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3rg4-57j5-xx9q/GHSA-3rg4-57j5-xx9q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rg4-57j5-xx9q", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56273" + ], + "details": "Missing Authorization vulnerability in WPvivid Backup & Migration WPvivid Backup and Migration allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPvivid Backup and Migration: from n/a through 0.9.106.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56273" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpvivid-backuprestore/vulnerability/wordpress-wpvivid-backup-plugin-0-9-106-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3vg4-xxp4-82w8/GHSA-3vg4-xxp4-82w8.json b/advisories/unreviewed/2025/01/GHSA-3vg4-xxp4-82w8/GHSA-3vg4-xxp4-82w8.json new file mode 100644 index 00000000000..8f877a329af --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3vg4-xxp4-82w8/GHSA-3vg4-xxp4-82w8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vg4-xxp4-82w8", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2024-12532" + ], + "details": "The BWD Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.18 in widgets/bwdeb-content-switcher.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12532" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3211460/bwd-elementor-addons" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8bdf6a52-7316-440b-9d36-d405a672dce1?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3xq2-pr52-j49m/GHSA-3xq2-pr52-j49m.json b/advisories/unreviewed/2025/01/GHSA-3xq2-pr52-j49m/GHSA-3xq2-pr52-j49m.json new file mode 100644 index 00000000000..8efc13ea97d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3xq2-pr52-j49m/GHSA-3xq2-pr52-j49m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xq2-pr52-j49m", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22320" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ProductDyno ProductDyno allows Reflected XSS.This issue affects ProductDyno: from n/a through 1.0.24.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22320" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/productdyno/vulnerability/wordpress-productdyno-plugin-1-0-24-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4cw5-64wg-w2cj/GHSA-4cw5-64wg-w2cj.json b/advisories/unreviewed/2025/01/GHSA-4cw5-64wg-w2cj/GHSA-4cw5-64wg-w2cj.json new file mode 100644 index 00000000000..4c28cd8286f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4cw5-64wg-w2cj/GHSA-4cw5-64wg-w2cj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cw5-64wg-w2cj", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22342" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Jens Törnell WP Simple Sitemap allows Stored XSS.This issue affects WP Simple Sitemap: from n/a through 0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22342" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-simple-sitemap/vulnerability/wordpress-wp-simple-sitemap-plugin-0-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4pgh-j6jq-5w7w/GHSA-4pgh-j6jq-5w7w.json b/advisories/unreviewed/2025/01/GHSA-4pgh-j6jq-5w7w/GHSA-4pgh-j6jq-5w7w.json new file mode 100644 index 00000000000..d95b3301c77 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4pgh-j6jq-5w7w/GHSA-4pgh-j6jq-5w7w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pgh-j6jq-5w7w", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56287" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in biztechc WP jQuery DataTable allows Stored XSS.This issue affects WP jQuery DataTable: from n/a through 4.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56287" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-jquery-datatable/vulnerability/wordpress-wp-jquery-datatable-plugin-4-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-54pq-v77f-xwc4/GHSA-54pq-v77f-xwc4.json b/advisories/unreviewed/2025/01/GHSA-54pq-v77f-xwc4/GHSA-54pq-v77f-xwc4.json new file mode 100644 index 00000000000..044aa56b84e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-54pq-v77f-xwc4/GHSA-54pq-v77f-xwc4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54pq-v77f-xwc4", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2024-11826" + ], + "details": "The Quill Forms | The Best Typeform Alternative | Create Conversational Multi Step Form, Survey, Quiz, Cost Estimation or Donation Form on WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quillforms-popup' shortcode in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11826" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3214019/quillforms/trunk/includes/class-shortcode.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d59a4d69-cf51-44c1-90bf-19be04774c27?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T12:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-59hj-pg8f-pgxq/GHSA-59hj-pg8f-pgxq.json b/advisories/unreviewed/2025/01/GHSA-59hj-pg8f-pgxq/GHSA-59hj-pg8f-pgxq.json new file mode 100644 index 00000000000..a5e130533e7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-59hj-pg8f-pgxq/GHSA-59hj-pg8f-pgxq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59hj-pg8f-pgxq", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22343" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Dennis Koot wpSOL allows Stored XSS.This issue affects wpSOL: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22343" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpsol/vulnerability/wordpress-wpsol-plugin-1-2-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5gq4-27hv-48vf/GHSA-5gq4-27hv-48vf.json b/advisories/unreviewed/2025/01/GHSA-5gq4-27hv-48vf/GHSA-5gq4-27hv-48vf.json new file mode 100644 index 00000000000..d23b0bf70ba --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5gq4-27hv-48vf/GHSA-5gq4-27hv-48vf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gq4-27hv-48vf", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2025-22261" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite WP FullCalendar allows Stored XSS.This issue affects WP FullCalendar: from n/a through 1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22261" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-fullcalendar/vulnerability/wordpress-wp-fullcalendar-plugin-1-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-624w-cg87-4jvw/GHSA-624w-cg87-4jvw.json b/advisories/unreviewed/2025/01/GHSA-624w-cg87-4jvw/GHSA-624w-cg87-4jvw.json new file mode 100644 index 00000000000..03c9be0280b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-624w-cg87-4jvw/GHSA-624w-cg87-4jvw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-624w-cg87-4jvw", + "modified": "2025-01-07T12:30:59Z", + "published": "2025-01-07T12:30:59Z", + "aliases": [ + "CVE-2024-49249" + ], + "details": "Path Traversal vulnerability in SMSA Express SMSA Shipping allows Path Traversal.This issue affects SMSA Shipping: from n/a through 2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49249" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/smsa-shipping-official/vulnerability/wordpress-smsa-shipping-plugin-2-3-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-644r-qf97-j5r3/GHSA-644r-qf97-j5r3.json b/advisories/unreviewed/2025/01/GHSA-644r-qf97-j5r3/GHSA-644r-qf97-j5r3.json new file mode 100644 index 00000000000..b1c28a4e762 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-644r-qf97-j5r3/GHSA-644r-qf97-j5r3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-644r-qf97-j5r3", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56288" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood WP Docs allows Stored XSS.This issue affects WP Docs: from n/a through 2.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56288" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-docs/vulnerability/wordpress-wp-docs-plugin-2-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-64r8-pvg5-v5f6/GHSA-64r8-pvg5-v5f6.json b/advisories/unreviewed/2025/01/GHSA-64r8-pvg5-v5f6/GHSA-64r8-pvg5-v5f6.json new file mode 100644 index 00000000000..c3dba41800c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-64r8-pvg5-v5f6/GHSA-64r8-pvg5-v5f6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64r8-pvg5-v5f6", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56280" + ], + "details": "Incorrect Privilege Assignment vulnerability in Amento Tech Pvt ltd WPGuppy allows Privilege Escalation.This issue affects WPGuppy: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56280" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpguppy-lite/vulnerability/wordpress-wpguppy-plugin-1-1-0-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-669q-763p-5x4x/GHSA-669q-763p-5x4x.json b/advisories/unreviewed/2025/01/GHSA-669q-763p-5x4x/GHSA-669q-763p-5x4x.json new file mode 100644 index 00000000000..9cf4f703e77 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-669q-763p-5x4x/GHSA-669q-763p-5x4x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-669q-763p-5x4x", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56279" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Tips and Tricks HQ Compact WP Audio Player allows Server Side Request Forgery.This issue affects Compact WP Audio Player: from n/a through 1.9.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56279" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/compact-wp-audio-player/vulnerability/wordpress-compact-wp-audio-player-plugin-1-9-14-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6w2w-q6gj-hjxw/GHSA-6w2w-q6gj-hjxw.json b/advisories/unreviewed/2025/01/GHSA-6w2w-q6gj-hjxw/GHSA-6w2w-q6gj-hjxw.json new file mode 100644 index 00000000000..fe378cadc5d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6w2w-q6gj-hjxw/GHSA-6w2w-q6gj-hjxw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w2w-q6gj-hjxw", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22328" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Elevio Elevio allows Stored XSS.This issue affects Elevio: from n/a through 4.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22328" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/elevio/vulnerability/wordpress-elevio-plugin-4-4-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6x53-588x-53g2/GHSA-6x53-588x-53g2.json b/advisories/unreviewed/2025/01/GHSA-6x53-588x-53g2/GHSA-6x53-588x-53g2.json new file mode 100644 index 00000000000..883af48a977 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6x53-588x-53g2/GHSA-6x53-588x-53g2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6x53-588x-53g2", + "modified": "2025-01-07T12:31:02Z", + "published": "2025-01-07T12:31:02Z", + "aliases": [ + "CVE-2024-12425" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal.\n\n\n\n\nAn attacker can write to arbitrary locations, albeit suffixed with \".ttf\", by supplying a file in a format that supports embedded font files.\n\n\nThis issue affects LibreOffice: from 24.8 before < 24.8.4.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12425" + }, + { + "type": "WEB", + "url": "https://www.libreoffice.org/about-us/security/advisories/cve-2024-12425" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-72pw-c6fg-fp6g/GHSA-72pw-c6fg-fp6g.json b/advisories/unreviewed/2025/01/GHSA-72pw-c6fg-fp6g/GHSA-72pw-c6fg-fp6g.json new file mode 100644 index 00000000000..47f91a8a8b2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-72pw-c6fg-fp6g/GHSA-72pw-c6fg-fp6g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72pw-c6fg-fp6g", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56274" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets allows Stored XSS.This issue affects Astra Widgets: from n/a through 1.2.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56274" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/astra-widgets/vulnerability/wordpress-astra-widgets-plugin-1-2-15-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7442-pm7x-25q8/GHSA-7442-pm7x-25q8.json b/advisories/unreviewed/2025/01/GHSA-7442-pm7x-25q8/GHSA-7442-pm7x-25q8.json new file mode 100644 index 00000000000..8fb05d9b2ac --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7442-pm7x-25q8/GHSA-7442-pm7x-25q8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7442-pm7x-25q8", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22339" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aThemeArt Store Commerce allows DOM-Based XSS.This issue affects Store Commerce: from n/a through 1.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22339" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/store-commerce/vulnerability/wordpress-store-commerce-theme-1-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-76v8-965q-f4x7/GHSA-76v8-965q-f4x7.json b/advisories/unreviewed/2025/01/GHSA-76v8-965q-f4x7/GHSA-76v8-965q-f4x7.json new file mode 100644 index 00000000000..c19ebd819a2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-76v8-965q-f4x7/GHSA-76v8-965q-f4x7.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76v8-965q-f4x7", + "modified": "2025-01-07T12:30:58Z", + "published": "2025-01-07T12:30:58Z", + "aliases": [ + "CVE-2024-12719" + ], + "details": "The WordPress File Upload plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wfu_ajax_action_read_subfolders' function in all versions up to, and including, 4.24.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform limited path traversal to view directories and subdirectories in WordPress. Files cannot be viewed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12719" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-file-upload/trunk/lib/wfu_ajaxactions.php#L849" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3217005" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/314ae0f5-8a4e-4bf3-9fc9-49f5b036b99e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-78m5-q63q-x3p3/GHSA-78m5-q63q-x3p3.json b/advisories/unreviewed/2025/01/GHSA-78m5-q63q-x3p3/GHSA-78m5-q63q-x3p3.json new file mode 100644 index 00000000000..bb48c2ed3d1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-78m5-q63q-x3p3/GHSA-78m5-q63q-x3p3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78m5-q63q-x3p3", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56297" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dn88 Highlight allows Stored XSS.This issue affects Highlight: from n/a through 2.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56297" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/highlight/vulnerability/wordpress-highlight-plugin-2-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7cfc-x63p-hphw/GHSA-7cfc-x63p-hphw.json b/advisories/unreviewed/2025/01/GHSA-7cfc-x63p-hphw/GHSA-7cfc-x63p-hphw.json new file mode 100644 index 00000000000..85dd3d17262 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7cfc-x63p-hphw/GHSA-7cfc-x63p-hphw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cfc-x63p-hphw", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22315" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Typing Text allows Stored XSS.This issue affects Typing Text: from n/a through 1.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22315" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/typing-text/vulnerability/wordpress-typing-text-plugin-1-2-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7p5r-7226-8pqg/GHSA-7p5r-7226-8pqg.json b/advisories/unreviewed/2025/01/GHSA-7p5r-7226-8pqg/GHSA-7p5r-7226-8pqg.json new file mode 100644 index 00000000000..4c49ef334ab --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7p5r-7226-8pqg/GHSA-7p5r-7226-8pqg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p5r-7226-8pqg", + "modified": "2025-01-07T12:30:59Z", + "published": "2025-01-07T12:30:59Z", + "aliases": [ + "CVE-2024-51715" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickWhale ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages allows Blind SQL Injection.This issue affects ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages: from n/a through 2.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51715" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/clickwhale/vulnerability/wordpress-clickwhale-plugin-2-4-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-84jx-2vcx-hfmh/GHSA-84jx-2vcx-hfmh.json b/advisories/unreviewed/2025/01/GHSA-84jx-2vcx-hfmh/GHSA-84jx-2vcx-hfmh.json new file mode 100644 index 00000000000..ff92784e6c2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-84jx-2vcx-hfmh/GHSA-84jx-2vcx-hfmh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84jx-2vcx-hfmh", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22312" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress Thim Elementor Kit allows DOM-Based XSS.This issue affects Thim Elementor Kit: from n/a through 1.2.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22312" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/thim-elementor-kit/vulnerability/wordpress-thim-elementor-kit-plugin-1-2-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8646-v3mf-m963/GHSA-8646-v3mf-m963.json b/advisories/unreviewed/2025/01/GHSA-8646-v3mf-m963/GHSA-8646-v3mf-m963.json new file mode 100644 index 00000000000..2882ee1d1d9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8646-v3mf-m963/GHSA-8646-v3mf-m963.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8646-v3mf-m963", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22303" + ], + "details": "Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster allows Retrieve Embedded Sensitive Data.This issue affects WP Mailster: from n/a through 1.8.17.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22303" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-mailster/vulnerability/wordpress-wp-mailster-plugin-1-8-17-0-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-86f3-wr96-fm48/GHSA-86f3-wr96-fm48.json b/advisories/unreviewed/2025/01/GHSA-86f3-wr96-fm48/GHSA-86f3-wr96-fm48.json new file mode 100644 index 00000000000..e8f0a05933a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-86f3-wr96-fm48/GHSA-86f3-wr96-fm48.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86f3-wr96-fm48", + "modified": "2025-01-07T12:31:02Z", + "published": "2025-01-07T12:31:02Z", + "aliases": [ + "CVE-2024-12316" + ], + "details": "The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_popup_action() function in all versions up to, and including, 4.8.5. This makes it possible for unauthenticated attackers to export popup templates.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12316" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/jupiterx-core/trunk/includes/popups/class.php#L475" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3214798/jupiterx-core/trunk/includes/popups/class.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5db195c1-8917-4465-a5ca-21089afb0bc7?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-89g3-3wcc-6vq4/GHSA-89g3-3wcc-6vq4.json b/advisories/unreviewed/2025/01/GHSA-89g3-3wcc-6vq4/GHSA-89g3-3wcc-6vq4.json new file mode 100644 index 00000000000..c4265ab2d16 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-89g3-3wcc-6vq4/GHSA-89g3-3wcc-6vq4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89g3-3wcc-6vq4", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2024-12711" + ], + "details": "The RSVP and Event Management plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX functions like bulk_delete_attendees() and bulk_delete_questions() in all versions up to, and including, 2.7.13. This makes it possible for unauthenticated attackers to delete questions and attendees and for authenticated users to update question menu orders.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12711" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3216473%40rsvp&new=3216473%40rsvp&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d234212a-2019-477d-81d1-b2acc2321055?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8h38-qx4m-2f5r/GHSA-8h38-qx4m-2f5r.json b/advisories/unreviewed/2025/01/GHSA-8h38-qx4m-2f5r/GHSA-8h38-qx4m-2f5r.json new file mode 100644 index 00000000000..283ec8f3b4f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8h38-qx4m-2f5r/GHSA-8h38-qx4m-2f5r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h38-qx4m-2f5r", + "modified": "2025-01-07T12:31:02Z", + "published": "2025-01-07T12:31:02Z", + "aliases": [ + "CVE-2024-52891" + ], + "details": "IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 \n\ncould allow an authenticated user to inject malicious information or obtain information from log files due to improper log neutralization.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52891" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7180303" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-117" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T12:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8pm7-c6qf-gwqg/GHSA-8pm7-c6qf-gwqg.json b/advisories/unreviewed/2025/01/GHSA-8pm7-c6qf-gwqg/GHSA-8pm7-c6qf-gwqg.json new file mode 100644 index 00000000000..2c1fb0f20b9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8pm7-c6qf-gwqg/GHSA-8pm7-c6qf-gwqg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pm7-c6qf-gwqg", + "modified": "2025-01-07T12:30:59Z", + "published": "2025-01-07T12:30:59Z", + "aliases": [ + "CVE-2024-51700" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 김 민준 (Minjun Kim) NAVER Analytics allows Stored XSS.This issue affects NAVER Analytics: from n/a through 0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51700" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/naver-analytics/vulnerability/wordpress-naver-analytics-plugin-0-9-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8qfm-m93q-xc6c/GHSA-8qfm-m93q-xc6c.json b/advisories/unreviewed/2025/01/GHSA-8qfm-m93q-xc6c/GHSA-8qfm-m93q-xc6c.json new file mode 100644 index 00000000000..59a2ee9187d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8qfm-m93q-xc6c/GHSA-8qfm-m93q-xc6c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qfm-m93q-xc6c", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2025-22297" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in AIpost AI WP Writer allows Cross Site Request Forgery.This issue affects AI WP Writer: from n/a through 3.8.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22297" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ai-wp-writer/vulnerability/wordpress-ai-wp-writer-plugin-3-8-4-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8rqw-pf8c-9xhv/GHSA-8rqw-pf8c-9xhv.json b/advisories/unreviewed/2025/01/GHSA-8rqw-pf8c-9xhv/GHSA-8rqw-pf8c-9xhv.json new file mode 100644 index 00000000000..024be5b536e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8rqw-pf8c-9xhv/GHSA-8rqw-pf8c-9xhv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rqw-pf8c-9xhv", + "modified": "2025-01-07T12:30:59Z", + "published": "2025-01-07T12:30:59Z", + "aliases": [ + "CVE-2024-51651" + ], + "details": "Missing Authorization vulnerability in CubeWP CubeWP Forms – All-in-One Form Builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CubeWP Forms – All-in-One Form Builder: from n/a through 1.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51651" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cubewp-forms/vulnerability/wordpress-cubewp-forms-plugin-1-1-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-96gm-h9qj-xwj3/GHSA-96gm-h9qj-xwj3.json b/advisories/unreviewed/2025/01/GHSA-96gm-h9qj-xwj3/GHSA-96gm-h9qj-xwj3.json new file mode 100644 index 00000000000..f51d5de5a3b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-96gm-h9qj-xwj3/GHSA-96gm-h9qj-xwj3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96gm-h9qj-xwj3", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56292" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop, oplugins Email Reminders allows Stored XSS.This issue affects Email Reminders: from n/a through 2.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56292" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/email-reminders/vulnerability/wordpress-email-reminders-plugin-2-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-979r-43h2-87mp/GHSA-979r-43h2-87mp.json b/advisories/unreviewed/2025/01/GHSA-979r-43h2-87mp/GHSA-979r-43h2-87mp.json new file mode 100644 index 00000000000..224d70704fa --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-979r-43h2-87mp/GHSA-979r-43h2-87mp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-979r-43h2-87mp", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22301" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Stormhill Media MyBookTable Bookstore allows Cross Site Request Forgery.This issue affects MyBookTable Bookstore: from n/a through 3.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22301" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mybooktable/vulnerability/wordpress-mybooktable-bookstore-by-stormhill-media-plugin-3-5-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9mv3-q2x2-pjqc/GHSA-9mv3-q2x2-pjqc.json b/advisories/unreviewed/2025/01/GHSA-9mv3-q2x2-pjqc/GHSA-9mv3-q2x2-pjqc.json new file mode 100644 index 00000000000..608b59e3f6a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9mv3-q2x2-pjqc/GHSA-9mv3-q2x2-pjqc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mv3-q2x2-pjqc", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22304" + ], + "details": "Missing Authorization vulnerability in osamaesh WP Visitor Statistics (Real Time Traffic) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22304" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-stats-manager/vulnerability/wordpress-wp-visitor-statistics-plugin-7-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9x5c-5jg6-mcv6/GHSA-9x5c-5jg6-mcv6.json b/advisories/unreviewed/2025/01/GHSA-9x5c-5jg6-mcv6/GHSA-9x5c-5jg6-mcv6.json new file mode 100644 index 00000000000..879b03a38db --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9x5c-5jg6-mcv6/GHSA-9x5c-5jg6-mcv6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x5c-5jg6-mcv6", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56291" + ], + "details": "Deserialization of Untrusted Data vulnerability in plainware.com PlainInventory allows Object Injection.This issue affects PlainInventory: from n/a through 3.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56291" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/z-inventory-manager/vulnerability/wordpress-plaininventory-inventory-management-plugin-plugin-3-1-6-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c3v4-qwrh-x627/GHSA-c3v4-qwrh-x627.json b/advisories/unreviewed/2025/01/GHSA-c3v4-qwrh-x627/GHSA-c3v4-qwrh-x627.json new file mode 100644 index 00000000000..670edef8c67 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c3v4-qwrh-x627/GHSA-c3v4-qwrh-x627.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3v4-qwrh-x627", + "modified": "2025-01-07T12:30:59Z", + "published": "2025-01-07T12:30:59Z", + "aliases": [ + "CVE-2024-49644" + ], + "details": "Incorrect Privilege Assignment vulnerability in AllAccessible Team Accessibility by AllAccessible allows Privilege Escalation.This issue affects Accessibility by AllAccessible: from n/a through 1.3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49644" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/allaccessible/vulnerability/wordpress-accessibility-by-allaccessible-plugin-1-3-4-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c7r9-86xh-x342/GHSA-c7r9-86xh-x342.json b/advisories/unreviewed/2025/01/GHSA-c7r9-86xh-x342/GHSA-c7r9-86xh-x342.json new file mode 100644 index 00000000000..8f08c3d24f8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c7r9-86xh-x342/GHSA-c7r9-86xh-x342.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7r9-86xh-x342", + "modified": "2025-01-07T12:30:59Z", + "published": "2025-01-07T12:30:59Z", + "aliases": [ + "CVE-2024-49633" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designinvento DirectoryPress allows Reflected XSS.This issue affects DirectoryPress: from n/a through 3.6.19.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49633" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/directorypress/vulnerability/wordpress-directorypress-plugin-3-6-19-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cf4g-4qgv-7m28/GHSA-cf4g-4qgv-7m28.json b/advisories/unreviewed/2025/01/GHSA-cf4g-4qgv-7m28/GHSA-cf4g-4qgv-7m28.json new file mode 100644 index 00000000000..078ae90e169 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cf4g-4qgv-7m28/GHSA-cf4g-4qgv-7m28.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cf4g-4qgv-7m28", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22309" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Steve D SpeakOut! Email Petitions allows DOM-Based XSS.This issue affects SpeakOut! Email Petitions: from n/a through 4.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22309" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/speakout/vulnerability/wordpress-speakout-email-petitions-plugin-4-4-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f433-x362-f3jr/GHSA-f433-x362-f3jr.json b/advisories/unreviewed/2025/01/GHSA-f433-x362-f3jr/GHSA-f433-x362-f3jr.json new file mode 100644 index 00000000000..b4e586d517f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f433-x362-f3jr/GHSA-f433-x362-f3jr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f433-x362-f3jr", + "modified": "2025-01-07T12:31:02Z", + "published": "2025-01-07T12:31:02Z", + "aliases": [ + "CVE-2024-52366" + ], + "details": "IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52366" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7180303" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f9ph-wj2c-x49w/GHSA-f9ph-wj2c-x49w.json b/advisories/unreviewed/2025/01/GHSA-f9ph-wj2c-x49w/GHSA-f9ph-wj2c-x49w.json new file mode 100644 index 00000000000..a44bcd362de --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f9ph-wj2c-x49w/GHSA-f9ph-wj2c-x49w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9ph-wj2c-x49w", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56294" + ], + "details": "Missing Authorization vulnerability in POSIMYTH Nexter Blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nexter Blocks: from n/a through 4.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56294" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/the-plus-addons-for-block-editor/vulnerability/wordpress-nexter-blocks-plugin-4-0-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gffx-5j8v-v6xp/GHSA-gffx-5j8v-v6xp.json b/advisories/unreviewed/2025/01/GHSA-gffx-5j8v-v6xp/GHSA-gffx-5j8v-v6xp.json new file mode 100644 index 00000000000..d5b9a2acf49 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gffx-5j8v-v6xp/GHSA-gffx-5j8v-v6xp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gffx-5j8v-v6xp", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22316" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPBits WPBITS Addons For Elementor Page Builder allows Stored XSS.This issue affects WPBITS Addons For Elementor Page Builder: from n/a through 1.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22316" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpbits-addons-for-elementor/vulnerability/wordpress-wpbits-addons-for-elementor-page-builder-plugin-1-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-ghcw-8wwc-6phr/GHSA-ghcw-8wwc-6phr.json b/advisories/unreviewed/2025/01/GHSA-ghcw-8wwc-6phr/GHSA-ghcw-8wwc-6phr.json new file mode 100644 index 00000000000..661dd4a42a7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-ghcw-8wwc-6phr/GHSA-ghcw-8wwc-6phr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghcw-8wwc-6phr", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56289" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Groundhogg Inc. Groundhogg allows Reflected XSS.This issue affects Groundhogg: from n/a through 3.7.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56289" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/groundhogg/vulnerability/wordpress-groundhogg-plugin-3-7-3-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gxv5-32mg-3j6c/GHSA-gxv5-32mg-3j6c.json b/advisories/unreviewed/2025/01/GHSA-gxv5-32mg-3j6c/GHSA-gxv5-32mg-3j6c.json new file mode 100644 index 00000000000..8e5c5083a56 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gxv5-32mg-3j6c/GHSA-gxv5-32mg-3j6c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxv5-32mg-3j6c", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22325" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Nik Chankov Autocompleter allows Stored XSS.This issue affects Autocompleter: from n/a through 1.3.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22325" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/autocompleter/vulnerability/wordpress-autocompleter-plugin-1-3-5-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h2jh-5338-vh22/GHSA-h2jh-5338-vh22.json b/advisories/unreviewed/2025/01/GHSA-h2jh-5338-vh22/GHSA-h2jh-5338-vh22.json new file mode 100644 index 00000000000..0fcc67b78f7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h2jh-5338-vh22/GHSA-h2jh-5338-vh22.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2jh-5338-vh22", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22305" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP OnlineSupport, Essential Plugin Hero Banner Ultimate allows PHP Local File Inclusion.This issue affects Hero Banner Ultimate: from n/a through 1.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22305" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hero-banner-ultimate/vulnerability/wordpress-hero-banner-ultimate-plugin-1-4-2-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h5pw-6wvq-g597/GHSA-h5pw-6wvq-g597.json b/advisories/unreviewed/2025/01/GHSA-h5pw-6wvq-g597/GHSA-h5pw-6wvq-g597.json new file mode 100644 index 00000000000..758e83fad69 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h5pw-6wvq-g597/GHSA-h5pw-6wvq-g597.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5pw-6wvq-g597", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56271" + ], + "details": "Missing Authorization vulnerability in SecureSubmit WP SecureSubmit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP SecureSubmit: from n/a through 1.5.16.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56271" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/securesubmit/vulnerability/wordpress-wp-securesubmit-plugin-1-5-16-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hcfm-4g95-m8qp/GHSA-hcfm-4g95-m8qp.json b/advisories/unreviewed/2025/01/GHSA-hcfm-4g95-m8qp/GHSA-hcfm-4g95-m8qp.json new file mode 100644 index 00000000000..62f18b0f351 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hcfm-4g95-m8qp/GHSA-hcfm-4g95-m8qp.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcfm-4g95-m8qp", + "modified": "2025-01-07T12:30:58Z", + "published": "2025-01-07T12:30:58Z", + "aliases": [ + "CVE-2024-12152" + ], + "details": "The MIPL WC Multisite Sync plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.5 via the 'mipl_wc_sync_download_log' action. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12152" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3215735%40mipl-wc-multisite-sync&new=3215735%40mipl-wc-multisite-sync&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3216574%40mipl-wc-multisite-sync&new=3216574%40mipl-wc-multisite-sync&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/575d1e24-d23d-4589-bb71-f52efec1ac58?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T10:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hj6w-6w27-6783/GHSA-hj6w-6w27-6783.json b/advisories/unreviewed/2025/01/GHSA-hj6w-6w27-6783/GHSA-hj6w-6w27-6783.json new file mode 100644 index 00000000000..a9c66ea342a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hj6w-6w27-6783/GHSA-hj6w-6w27-6783.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj6w-6w27-6783", + "modified": "2025-01-07T12:31:02Z", + "published": "2025-01-07T12:31:02Z", + "aliases": [ + "CVE-2024-52367" + ], + "details": "IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could disclose sensitive system information to an unauthorized actor that could be used in further attacks against the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52367" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7180303" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hp3m-8c64-p7fp/GHSA-hp3m-8c64-p7fp.json b/advisories/unreviewed/2025/01/GHSA-hp3m-8c64-p7fp/GHSA-hp3m-8c64-p7fp.json new file mode 100644 index 00000000000..ee8c47ca899 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hp3m-8c64-p7fp/GHSA-hp3m-8c64-p7fp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp3m-8c64-p7fp", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56284" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SSL Wireless SSL Wireless SMS Notification allows SQL Injection.This issue affects SSL Wireless SMS Notification: from n/a through 3.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56284" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ssl-wireless-sms-notification/vulnerability/wordpress-ssl-wireless-sms-notification-plugin-3-5-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j2mg-9wpw-gcm4/GHSA-j2mg-9wpw-gcm4.json b/advisories/unreviewed/2025/01/GHSA-j2mg-9wpw-gcm4/GHSA-j2mg-9wpw-gcm4.json new file mode 100644 index 00000000000..3fcc0cf8575 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j2mg-9wpw-gcm4/GHSA-j2mg-9wpw-gcm4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2mg-9wpw-gcm4", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2025-22298" + ], + "details": "Missing Authorization vulnerability in Hive Support Hive Support – WordPress Help Desk allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hive Support – WordPress Help Desk: from n/a through 1.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22298" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hive-support/vulnerability/wordpress-hive-support-plugin-1-1-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j6w8-j3gw-86hg/GHSA-j6w8-j3gw-86hg.json b/advisories/unreviewed/2025/01/GHSA-j6w8-j3gw-86hg/GHSA-j6w8-j3gw-86hg.json new file mode 100644 index 00000000000..abb3dc34963 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j6w8-j3gw-86hg/GHSA-j6w8-j3gw-86hg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6w8-j3gw-86hg", + "modified": "2025-01-07T12:30:59Z", + "published": "2025-01-07T12:30:59Z", + "aliases": [ + "CVE-2024-49649" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Abdul Hakeem Build App Online allows PHP Local File Inclusion.This issue affects Build App Online: from n/a through 1.0.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49649" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/build-app-online/vulnerability/wordpress-build-app-online-plugin-1-0-23-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jghv-8ggj-pc3g/GHSA-jghv-8ggj-pc3g.json b/advisories/unreviewed/2025/01/GHSA-jghv-8ggj-pc3g/GHSA-jghv-8ggj-pc3g.json new file mode 100644 index 00000000000..b96026dcd48 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jghv-8ggj-pc3g/GHSA-jghv-8ggj-pc3g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jghv-8ggj-pc3g", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22352" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes allows Blind SQL Injection.This issue affects ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes: from n/a through 1.4.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22352" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/elex-bulk-edit-products-prices-attributes-for-woocommerce-basic/vulnerability/wordpress-elex-woocommerce-advanced-bulk-edit-products-prices-attributes-plugin-1-4-8-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jv78-2xvm-hw3j/GHSA-jv78-2xvm-hw3j.json b/advisories/unreviewed/2025/01/GHSA-jv78-2xvm-hw3j/GHSA-jv78-2xvm-hw3j.json new file mode 100644 index 00000000000..ab4b0ea72eb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jv78-2xvm-hw3j/GHSA-jv78-2xvm-hw3j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv78-2xvm-hw3j", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22326" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 5centsCDN 5centsCDN allows Reflected XSS.This issue affects 5centsCDN: from n/a through 24.8.16.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22326" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/5centscdn/vulnerability/wordpress-5centscdn-wordpress-cdn-plugin-plugin-24-8-16-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m27v-7wcw-gcj8/GHSA-m27v-7wcw-gcj8.json b/advisories/unreviewed/2025/01/GHSA-m27v-7wcw-gcj8/GHSA-m27v-7wcw-gcj8.json new file mode 100644 index 00000000000..3eb07d01502 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m27v-7wcw-gcj8/GHSA-m27v-7wcw-gcj8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m27v-7wcw-gcj8", + "modified": "2025-01-07T12:31:02Z", + "published": "2025-01-07T12:31:02Z", + "aliases": [ + "CVE-2024-52893" + ], + "details": "IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 \n\ncould allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52893" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7180303" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T12:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m3cg-3cm2-pwvv/GHSA-m3cg-3cm2-pwvv.json b/advisories/unreviewed/2025/01/GHSA-m3cg-3cm2-pwvv/GHSA-m3cg-3cm2-pwvv.json new file mode 100644 index 00000000000..1802e31cae6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m3cg-3cm2-pwvv/GHSA-m3cg-3cm2-pwvv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3cg-3cm2-pwvv", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22336" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WordPress 智库 Wizhi Multi Filters by Wenprise allows Stored XSS.This issue affects Wizhi Multi Filters by Wenprise: from n/a through 1.8.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22336" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wizhi-multi-filters/vulnerability/wordpress-wizhi-multi-filters-by-wenprise-plugin-1-8-6-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m486-qpph-3q32/GHSA-m486-qpph-3q32.json b/advisories/unreviewed/2025/01/GHSA-m486-qpph-3q32/GHSA-m486-qpph-3q32.json new file mode 100644 index 00000000000..e1b85ae279a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m486-qpph-3q32/GHSA-m486-qpph-3q32.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m486-qpph-3q32", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56296" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hometory Mang Board WP allows Reflected XSS.This issue affects Mang Board WP: from n/a through 1.8.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56296" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mangboard/vulnerability/wordpress-mang-board-wp-plugin-1-8-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m4mw-x2q4-jx9x/GHSA-m4mw-x2q4-jx9x.json b/advisories/unreviewed/2025/01/GHSA-m4mw-x2q4-jx9x/GHSA-m4mw-x2q4-jx9x.json new file mode 100644 index 00000000000..085b159e20c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m4mw-x2q4-jx9x/GHSA-m4mw-x2q4-jx9x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4mw-x2q4-jx9x", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56293" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nasirahmed Advanced Form Integration allows Stored XSS.This issue affects Advanced Form Integration: from n/a through 1.95.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56293" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-form-integration/vulnerability/wordpress-afi-the-easiest-integration-plugin-1-95-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mf6r-39pm-fg5j/GHSA-mf6r-39pm-fg5j.json b/advisories/unreviewed/2025/01/GHSA-mf6r-39pm-fg5j/GHSA-mf6r-39pm-fg5j.json new file mode 100644 index 00000000000..759480fa9e2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mf6r-39pm-fg5j/GHSA-mf6r-39pm-fg5j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf6r-39pm-fg5j", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22323" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jewel Theme Image Hover Effects for Elementor allows Stored XSS.This issue affects Image Hover Effects for Elementor: from n/a through 1.0.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22323" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/image-hover-effects-elementor-addon/vulnerability/wordpress-image-hover-effects-for-elementor-plugin-1-0-2-3-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mhx9-6h3w-c2mg/GHSA-mhx9-6h3w-c2mg.json b/advisories/unreviewed/2025/01/GHSA-mhx9-6h3w-c2mg/GHSA-mhx9-6h3w-c2mg.json new file mode 100644 index 00000000000..8ff74211802 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mhx9-6h3w-c2mg/GHSA-mhx9-6h3w-c2mg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhx9-6h3w-c2mg", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22358" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcon Simone Wp advertising management allows Reflected XSS.This issue affects Wp advertising management: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22358" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advertising-management/vulnerability/wordpress-wp-advertising-management-plugin-1-0-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mp95-f3p8-2jrx/GHSA-mp95-f3p8-2jrx.json b/advisories/unreviewed/2025/01/GHSA-mp95-f3p8-2jrx/GHSA-mp95-f3p8-2jrx.json new file mode 100644 index 00000000000..35da3e12e50 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mp95-f3p8-2jrx/GHSA-mp95-f3p8-2jrx.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp95-f3p8-2jrx", + "modified": "2025-01-07T12:30:58Z", + "published": "2025-01-07T12:30:58Z", + "aliases": [ + "CVE-2024-12699" + ], + "details": "The Service Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12699" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3216752%40service-boxs&new=3216752%40service-boxs&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/service-boxs/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e6a65630-0852-4ffc-8c23-295be95bd7f0?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mq22-44hf-43p9/GHSA-mq22-44hf-43p9.json b/advisories/unreviewed/2025/01/GHSA-mq22-44hf-43p9/GHSA-mq22-44hf-43p9.json new file mode 100644 index 00000000000..eb47f4e82e0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mq22-44hf-43p9/GHSA-mq22-44hf-43p9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq22-44hf-43p9", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2025-22299" + ], + "details": "Missing Authorization vulnerability in spacecodes AI for SEO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI for SEO: from n/a through 1.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22299" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ai-for-seo/vulnerability/wordpress-ai-for-seo-plugin-1-2-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mqc6-fvr2-5xfx/GHSA-mqc6-fvr2-5xfx.json b/advisories/unreviewed/2025/01/GHSA-mqc6-fvr2-5xfx/GHSA-mqc6-fvr2-5xfx.json new file mode 100644 index 00000000000..9eb1f36a161 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mqc6-fvr2-5xfx/GHSA-mqc6-fvr2-5xfx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqc6-fvr2-5xfx", + "modified": "2025-01-07T12:30:59Z", + "published": "2025-01-07T12:30:59Z", + "aliases": [ + "CVE-2024-49294" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team Bus Ticket Booking with Seat Reservation allows Cross Site Request Forgery.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through 5.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49294" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bus-ticket-booking-with-seat-reservation/vulnerability/wordpress-wpbusticketly-plugin-5-4-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mvr8-66hg-75w5/GHSA-mvr8-66hg-75w5.json b/advisories/unreviewed/2025/01/GHSA-mvr8-66hg-75w5/GHSA-mvr8-66hg-75w5.json new file mode 100644 index 00000000000..b9fc5d87a9b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mvr8-66hg-75w5/GHSA-mvr8-66hg-75w5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvr8-66hg-75w5", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22310" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TemplatesNext TemplatesNext ToolKit allows Stored XSS.This issue affects TemplatesNext ToolKit: from n/a through 3.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22310" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/templatesnext-toolkit/vulnerability/wordpress-templatesnext-toolkit-plugin-3-2-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mwv9-m4p2-2cc4/GHSA-mwv9-m4p2-2cc4.json b/advisories/unreviewed/2025/01/GHSA-mwv9-m4p2-2cc4/GHSA-mwv9-m4p2-2cc4.json new file mode 100644 index 00000000000..7c7c3442291 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mwv9-m4p2-2cc4/GHSA-mwv9-m4p2-2cc4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwv9-m4p2-2cc4", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22348" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RTO GmbH DynamicTags allows Blind SQL Injection.This issue affects DynamicTags: from n/a through 1.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22348" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dynamictags/vulnerability/wordpress-dynamictags-plugin-1-4-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p3pp-r8w3-m3f7/GHSA-p3pp-r8w3-m3f7.json b/advisories/unreviewed/2025/01/GHSA-p3pp-r8w3-m3f7/GHSA-p3pp-r8w3-m3f7.json new file mode 100644 index 00000000000..d097264a369 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p3pp-r8w3-m3f7/GHSA-p3pp-r8w3-m3f7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3pp-r8w3-m3f7", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56278" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders WP Ultimate Exporter allows PHP Remote File Inclusion.This issue affects WP Ultimate Exporter: from n/a through 2.9.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56278" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-ultimate-exporter/vulnerability/wordpress-wp-ultimate-exporter-plugin-2-9-1-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p44r-wx48-2j96/GHSA-p44r-wx48-2j96.json b/advisories/unreviewed/2025/01/GHSA-p44r-wx48-2j96/GHSA-p44r-wx48-2j96.json new file mode 100644 index 00000000000..1899fcb0889 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p44r-wx48-2j96/GHSA-p44r-wx48-2j96.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p44r-wx48-2j96", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22353" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Balcom-Vetillo Design, Inc. BVD Easy Gallery Manager allows Reflected XSS.This issue affects BVD Easy Gallery Manager: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22353" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bvd-easy-gallery-manager/vulnerability/wordpress-bvd-easy-gallery-manager-plugin-1-0-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p88h-2rv9-3575/GHSA-p88h-2rv9-3575.json b/advisories/unreviewed/2025/01/GHSA-p88h-2rv9-3575/GHSA-p88h-2rv9-3575.json new file mode 100644 index 00000000000..3f657de27dd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p88h-2rv9-3575/GHSA-p88h-2rv9-3575.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p88h-2rv9-3575", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22362" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Powerfusion WPAchievements Free allows Stored XSS.This issue affects WPAchievements Free: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22362" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpachievements-free/vulnerability/wordpress-wpachievements-free-plugin-1-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pjwp-p686-rpwj/GHSA-pjwp-p686-rpwj.json b/advisories/unreviewed/2025/01/GHSA-pjwp-p686-rpwj/GHSA-pjwp-p686-rpwj.json new file mode 100644 index 00000000000..4981c3776be --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pjwp-p686-rpwj/GHSA-pjwp-p686-rpwj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjwp-p686-rpwj", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56300" + ], + "details": "Insertion of Sensitive Information Into Sent Data vulnerability in WPSpins Post/Page Copying Tool allows Retrieve Embedded Sensitive Data.This issue affects Post/Page Copying Tool: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56300" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/postpage-import-export-with-custom-fields-taxonomies/vulnerability/wordpress-post-page-copying-tool-plugin-2-0-0-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pwmw-79j9-vj9r/GHSA-pwmw-79j9-vj9r.json b/advisories/unreviewed/2025/01/GHSA-pwmw-79j9-vj9r/GHSA-pwmw-79j9-vj9r.json new file mode 100644 index 00000000000..80e822ea507 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pwmw-79j9-vj9r/GHSA-pwmw-79j9-vj9r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwmw-79j9-vj9r", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22359" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PJFC SyncFields allows Reflected XSS.This issue affects SyncFields: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22359" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/syncfields/vulnerability/wordpress-syncfields-plugin-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pwwx-c4hj-3v9g/GHSA-pwwx-c4hj-3v9g.json b/advisories/unreviewed/2025/01/GHSA-pwwx-c4hj-3v9g/GHSA-pwwx-c4hj-3v9g.json new file mode 100644 index 00000000000..e88ae6c9d53 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pwwx-c4hj-3v9g/GHSA-pwwx-c4hj-3v9g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwwx-c4hj-3v9g", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56275" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Envato Envato Elements allows Server Side Request Forgery.This issue affects Envato Elements: from n/a through 2.0.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56275" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/envato-elements/vulnerability/wordpress-envato-elements-plugin-2-0-14-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-px2w-wv2v-r557/GHSA-px2w-wv2v-r557.json b/advisories/unreviewed/2025/01/GHSA-px2w-wv2v-r557/GHSA-px2w-wv2v-r557.json new file mode 100644 index 00000000000..bb30462a8e0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-px2w-wv2v-r557/GHSA-px2w-wv2v-r557.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px2w-wv2v-r557", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22327" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Olaf Lederer EO4WP allows Stored XSS.This issue affects EO4WP: from n/a through 1.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22327" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fw-integration-for-emailoctopus/vulnerability/wordpress-eo4wp-plugin-1-0-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q34h-cpvf-cv68/GHSA-q34h-cpvf-cv68.json b/advisories/unreviewed/2025/01/GHSA-q34h-cpvf-cv68/GHSA-q34h-cpvf-cv68.json new file mode 100644 index 00000000000..556e3e5a2c3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q34h-cpvf-cv68/GHSA-q34h-cpvf-cv68.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q34h-cpvf-cv68", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56283" + ], + "details": "Deserialization of Untrusted Data vulnerability in plainware.com Locatoraid Store Locator allows Object Injection.This issue affects Locatoraid Store Locator: from n/a through 3.9.50.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56283" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/locatoraid/vulnerability/wordpress-locatoraid-store-locator-plugin-3-9-50-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q55v-rg55-hfpm/GHSA-q55v-rg55-hfpm.json b/advisories/unreviewed/2025/01/GHSA-q55v-rg55-hfpm/GHSA-q55v-rg55-hfpm.json new file mode 100644 index 00000000000..e19d5504371 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q55v-rg55-hfpm/GHSA-q55v-rg55-hfpm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q55v-rg55-hfpm", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22324" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andon Ivanov OZ Canonical allows Reflected XSS.This issue affects OZ Canonical: from n/a through 0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22324" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/oz-canonical/vulnerability/wordpress-oz-canonical-plugin-0-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q8v2-3wfw-6mhf/GHSA-q8v2-3wfw-6mhf.json b/advisories/unreviewed/2025/01/GHSA-q8v2-3wfw-6mhf/GHSA-q8v2-3wfw-6mhf.json new file mode 100644 index 00000000000..1799e55630d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q8v2-3wfw-6mhf/GHSA-q8v2-3wfw-6mhf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8v2-3wfw-6mhf", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56285" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPBits WPBITS Addons For Elementor Page Builder allows Stored XSS.This issue affects WPBITS Addons For Elementor Page Builder: from n/a through 1.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56285" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpbits-addons-for-elementor/vulnerability/wordpress-wpbits-addons-for-elementor-page-builder-plugin-1-5-1-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qvc8-367v-rwrv/GHSA-qvc8-367v-rwrv.json b/advisories/unreviewed/2025/01/GHSA-qvc8-367v-rwrv/GHSA-qvc8-367v-rwrv.json new file mode 100644 index 00000000000..736e261b4cc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qvc8-367v-rwrv/GHSA-qvc8-367v-rwrv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvc8-367v-rwrv", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22351" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PenguinArts Contact Form 7 Database – CFDB7 allows SQL Injection.This issue affects Contact Form 7 Database – CFDB7: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22351" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-cf7-database/vulnerability/wordpress-contact-form-7-database-cfdb7-plugin-1-0-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r8xj-278c-2qv8/GHSA-r8xj-278c-2qv8.json b/advisories/unreviewed/2025/01/GHSA-r8xj-278c-2qv8/GHSA-r8xj-278c-2qv8.json new file mode 100644 index 00000000000..e6cb70ee63b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r8xj-278c-2qv8/GHSA-r8xj-278c-2qv8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8xj-278c-2qv8", + "modified": "2025-01-07T12:30:59Z", + "published": "2025-01-07T12:30:59Z", + "aliases": [ + "CVE-2024-49222" + ], + "details": "Deserialization of Untrusted Data vulnerability in Amento Tech Pvt ltd WPGuppy allows Object Injection.This issue affects WPGuppy: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49222" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpguppy-lite/vulnerability/wordpress-wpguppy-plugin-1-1-0-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rpqq-f9fv-4hwq/GHSA-rpqq-f9fv-4hwq.json b/advisories/unreviewed/2025/01/GHSA-rpqq-f9fv-4hwq/GHSA-rpqq-f9fv-4hwq.json new file mode 100644 index 00000000000..4e9357ad22d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rpqq-f9fv-4hwq/GHSA-rpqq-f9fv-4hwq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpqq-f9fv-4hwq", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56276" + ], + "details": "Missing Authorization vulnerability in WPForms Contact Form by WPForms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by WPForms: from n/a through 1.9.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56276" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpforms-lite/vulnerability/wordpress-wpforms-lite-plugin-1-9-2-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v47g-xr27-3c46/GHSA-v47g-xr27-3c46.json b/advisories/unreviewed/2025/01/GHSA-v47g-xr27-3c46/GHSA-v47g-xr27-3c46.json new file mode 100644 index 00000000000..8b0cd0dcf7c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v47g-xr27-3c46/GHSA-v47g-xr27-3c46.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v47g-xr27-3c46", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22364" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Service Shogun Ach Invoice App allows PHP Local File Inclusion.This issue affects Ach Invoice App: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22364" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ach-invoice-app/vulnerability/wordpress-ach-invoice-app-plugin-1-0-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v4jh-c8p9-66g4/GHSA-v4jh-c8p9-66g4.json b/advisories/unreviewed/2025/01/GHSA-v4jh-c8p9-66g4/GHSA-v4jh-c8p9-66g4.json new file mode 100644 index 00000000000..14a5350d1ce --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v4jh-c8p9-66g4/GHSA-v4jh-c8p9-66g4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4jh-c8p9-66g4", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22300" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in PixelYourSite PixelYourSite – Your smart PIXEL (TAG) Manager allows Cross Site Request Forgery.This issue affects PixelYourSite – Your smart PIXEL (TAG) Manager: from n/a through 10.0.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22300" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pixelyoursite/vulnerability/wordpress-pixelyoursite-plugin-10-0-1-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v6v8-rm6c-8j83/GHSA-v6v8-rm6c-8j83.json b/advisories/unreviewed/2025/01/GHSA-v6v8-rm6c-8j83/GHSA-v6v8-rm6c-8j83.json new file mode 100644 index 00000000000..26fe01572b5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v6v8-rm6c-8j83/GHSA-v6v8-rm6c-8j83.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6v8-rm6c-8j83", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22349" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Owen Cutajar & Hyder Jaffari WordPress Auction Plugin allows SQL Injection.This issue affects WordPress Auction Plugin: from n/a through 3.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22349" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-auctions/vulnerability/wordpress-wordpress-auction-plugin-plugin-3-7-sql-injection-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v9p2-r57p-mjxc/GHSA-v9p2-r57p-mjxc.json b/advisories/unreviewed/2025/01/GHSA-v9p2-r57p-mjxc/GHSA-v9p2-r57p-mjxc.json new file mode 100644 index 00000000000..0dc8cb539aa --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v9p2-r57p-mjxc/GHSA-v9p2-r57p-mjxc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9p2-r57p-mjxc", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2024-12033" + ], + "details": "The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sync_libraries() function in all versions up to, and including, 4.8.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to sync libraries", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12033" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3214798/jupiterx-core/trunk/includes/extensions/raven/includes/plugin.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7e452aa0-bfb9-4805-b2ed-53464a4b5308?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T12:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w7pp-w9q5-q8q9/GHSA-w7pp-w9q5-q8q9.json b/advisories/unreviewed/2025/01/GHSA-w7pp-w9q5-q8q9/GHSA-w7pp-w9q5-q8q9.json new file mode 100644 index 00000000000..e2705346c29 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w7pp-w9q5-q8q9/GHSA-w7pp-w9q5-q8q9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7pp-w9q5-q8q9", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22355" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kiKx Kikx Simple Post Author Filter allows Reflected XSS.This issue affects Kikx Simple Post Author Filter: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22355" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sa-post-author-filter/vulnerability/wordpress-kikx-simple-post-author-filter-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wfgj-q84v-qhr5/GHSA-wfgj-q84v-qhr5.json b/advisories/unreviewed/2025/01/GHSA-wfgj-q84v-qhr5/GHSA-wfgj-q84v-qhr5.json new file mode 100644 index 00000000000..045a410a032 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wfgj-q84v-qhr5/GHSA-wfgj-q84v-qhr5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfgj-q84v-qhr5", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22308" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in inc2734 Smart Custom Fields allows Stored XSS.This issue affects Smart Custom Fields: from n/a through 5.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22308" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/smart-custom-fields/vulnerability/wordpress-smart-custom-fields-plugin-5-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wv37-xgjf-vmrr/GHSA-wv37-xgjf-vmrr.json b/advisories/unreviewed/2025/01/GHSA-wv37-xgjf-vmrr/GHSA-wv37-xgjf-vmrr.json new file mode 100644 index 00000000000..0899756d7be --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wv37-xgjf-vmrr/GHSA-wv37-xgjf-vmrr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wv37-xgjf-vmrr", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22347" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in BannerSky.com BSK Forms Blacklist allows Blind SQL Injection.This issue affects BSK Forms Blacklist: from n/a through 3.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22347" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bsk-gravityforms-blacklist/vulnerability/wordpress-bsk-forms-blacklist-plugin-3-9-csrf-to-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wvj5-x5x8-fxg9/GHSA-wvj5-x5x8-fxg9.json b/advisories/unreviewed/2025/01/GHSA-wvj5-x5x8-fxg9/GHSA-wvj5-x5x8-fxg9.json new file mode 100644 index 00000000000..ab3c6eae383 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wvj5-x5x8-fxg9/GHSA-wvj5-x5x8-fxg9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvj5-x5x8-fxg9", + "modified": "2025-01-07T12:31:01Z", + "published": "2025-01-07T12:31:01Z", + "aliases": [ + "CVE-2025-22321" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TheInnovs ElementsCSS Addons for Elementor allows Stored XSS.This issue affects ElementsCSS Addons for Elementor: from n/a through 1.0.8.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22321" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/css-for-elementor/vulnerability/wordpress-elementscss-addons-for-elementor-plugin-1-0-8-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x23w-pv3p-jj5p/GHSA-x23w-pv3p-jj5p.json b/advisories/unreviewed/2025/01/GHSA-x23w-pv3p-jj5p/GHSA-x23w-pv3p-jj5p.json new file mode 100644 index 00000000000..42dbdad1a80 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x23w-pv3p-jj5p/GHSA-x23w-pv3p-jj5p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x23w-pv3p-jj5p", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56299" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pektsekye Notify Odoo allows Stored XSS.This issue affects Notify Odoo: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56299" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/notify-odoo/vulnerability/wordpress-notify-odoo-plugin-1-0-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xf57-jqcw-ch9j/GHSA-xf57-jqcw-ch9j.json b/advisories/unreviewed/2025/01/GHSA-xf57-jqcw-ch9j/GHSA-xf57-jqcw-ch9j.json new file mode 100644 index 00000000000..2e2f398cc7f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xf57-jqcw-ch9j/GHSA-xf57-jqcw-ch9j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xf57-jqcw-ch9j", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56298" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 5 Star Plugins Pretty Simple Popup Builder allows Stored XSS.This issue affects Pretty Simple Popup Builder: from n/a through 1.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56298" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pretty-simple-popup-builder/vulnerability/wordpress-pretty-simple-popup-builder-plugin-1-0-9-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xvgx-mppj-c76r/GHSA-xvgx-mppj-c76r.json b/advisories/unreviewed/2025/01/GHSA-xvgx-mppj-c76r/GHSA-xvgx-mppj-c76r.json new file mode 100644 index 00000000000..f5ca94b2740 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xvgx-mppj-c76r/GHSA-xvgx-mppj-c76r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvgx-mppj-c76r", + "modified": "2025-01-07T12:31:00Z", + "published": "2025-01-07T12:31:00Z", + "aliases": [ + "CVE-2024-56282" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elicus WPMozo Addons Lite for Elementor allows PHP Local File Inclusion.This issue affects WPMozo Addons Lite for Elementor: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56282" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpmozo-addons-lite-for-elementor/vulnerability/wordpress-wpmozo-addons-lite-for-elementor-plugin-1-1-0-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T11:15:10Z" + } +} \ No newline at end of file