From 1d5d6cffe3b98e6446e30699ab83c7af912e8d8d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 24 Apr 2025 09:31:52 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-jc5j-vx46-fpgv.json | 4 +- .../GHSA-x43h-8pfv-xx24.json | 6 ++- .../GHSA-243x-8mmp-f9jr.json | 40 ++++++++++++++ .../GHSA-3g36-gf7c-75qw.json | 36 +++++++++++++ .../GHSA-3jmr-84q9-rpjf.json | 44 ++++++++++++++++ .../GHSA-43w4-f729-298m.json | 40 ++++++++++++++ .../GHSA-4662-3xhc-rv2x.json | 40 ++++++++++++++ .../GHSA-4g2r-p7w3-jh5j.json | 52 +++++++++++++++++++ .../GHSA-4xxh-h8pj-qxc6.json | 40 ++++++++++++++ .../GHSA-5c5g-j5fh-2fvr.json | 44 ++++++++++++++++ .../GHSA-689c-xq7x-xjwf.json | 36 +++++++++++++ .../GHSA-69q5-9q88-37jm.json | 40 ++++++++++++++ .../GHSA-8xcw-x64j-h58v.json | 40 ++++++++++++++ .../GHSA-9963-8j6c-xr65.json | 40 ++++++++++++++ .../GHSA-9mx9-xf85-m8v5.json | 40 ++++++++++++++ .../GHSA-c4j4-vf5r-vcpp.json | 44 ++++++++++++++++ .../GHSA-cwjx-755c-h647.json | 44 ++++++++++++++++ .../GHSA-fr22-5377-f3p7.json | 36 +++++++++++++ .../GHSA-ghc6-72j6-q29j.json | 40 ++++++++++++++ .../GHSA-h38g-w8gh-4m6m.json | 38 ++++++++++++++ .../GHSA-hv8q-7rjw-5h3j.json | 40 ++++++++++++++ .../GHSA-jf94-mqcr-qwmx.json | 40 ++++++++++++++ .../GHSA-vhj4-w2vf-v7jq.json | 48 +++++++++++++++++ .../GHSA-vjgj-v6jh-4c36.json | 40 ++++++++++++++ .../GHSA-wj9c-gx74-xrjr.json | 40 ++++++++++++++ 25 files changed, 949 insertions(+), 3 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-243x-8mmp-f9jr/GHSA-243x-8mmp-f9jr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3g36-gf7c-75qw/GHSA-3g36-gf7c-75qw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3jmr-84q9-rpjf/GHSA-3jmr-84q9-rpjf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-43w4-f729-298m/GHSA-43w4-f729-298m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4662-3xhc-rv2x/GHSA-4662-3xhc-rv2x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4g2r-p7w3-jh5j/GHSA-4g2r-p7w3-jh5j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4xxh-h8pj-qxc6/GHSA-4xxh-h8pj-qxc6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5c5g-j5fh-2fvr/GHSA-5c5g-j5fh-2fvr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-689c-xq7x-xjwf/GHSA-689c-xq7x-xjwf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-69q5-9q88-37jm/GHSA-69q5-9q88-37jm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8xcw-x64j-h58v/GHSA-8xcw-x64j-h58v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9963-8j6c-xr65/GHSA-9963-8j6c-xr65.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9mx9-xf85-m8v5/GHSA-9mx9-xf85-m8v5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c4j4-vf5r-vcpp/GHSA-c4j4-vf5r-vcpp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cwjx-755c-h647/GHSA-cwjx-755c-h647.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fr22-5377-f3p7/GHSA-fr22-5377-f3p7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ghc6-72j6-q29j/GHSA-ghc6-72j6-q29j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h38g-w8gh-4m6m/GHSA-h38g-w8gh-4m6m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hv8q-7rjw-5h3j/GHSA-hv8q-7rjw-5h3j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jf94-mqcr-qwmx/GHSA-jf94-mqcr-qwmx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vhj4-w2vf-v7jq/GHSA-vhj4-w2vf-v7jq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vjgj-v6jh-4c36/GHSA-vjgj-v6jh-4c36.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wj9c-gx74-xrjr/GHSA-wj9c-gx74-xrjr.json diff --git a/advisories/unreviewed/2024/05/GHSA-jc5j-vx46-fpgv/GHSA-jc5j-vx46-fpgv.json b/advisories/unreviewed/2024/05/GHSA-jc5j-vx46-fpgv/GHSA-jc5j-vx46-fpgv.json index 94cd24e1395..e5e496722aa 100644 --- a/advisories/unreviewed/2024/05/GHSA-jc5j-vx46-fpgv/GHSA-jc5j-vx46-fpgv.json +++ b/advisories/unreviewed/2024/05/GHSA-jc5j-vx46-fpgv/GHSA-jc5j-vx46-fpgv.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-jc5j-vx46-fpgv", - "modified": "2024-06-03T18:55:49Z", + "modified": "2025-04-24T09:30:33Z", "published": "2024-05-14T21:34:44Z", "aliases": [ "CVE-2024-2637" ], - "details": "\nAn authenticated local attacker who successfully exploited this vulnerability could insert and run arbitrary code using legitimate B&R software's.\n\nAn Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial  Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation mapp View, B&R Industrial Automation mapp Cockpit, B&R Industrial Automation mapp Safety, B&R Industrial Automation VC4 could allow an authenticated local attacker to execute malicious code by placing specially crafted files in the loading search path.\nThis issue affects Scene Viewer: before 4.4.0; Automation Runtime: before J4.93; mapp Vision: before 5.26.1; mapp View: before 5.24.2; mapp Cockpit: before 5.24.2; mapp Safety: before 5.24.2; VC4: before 4.73.2.\n\n", + "details": "An authenticated local attacker who successfully exploited this vulnerability could insert and run arbitrary code using legitimate B&R software's.\n\nAn Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial  Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation mapp View, B&R Industrial Automation mapp Cockpit, B&R Industrial Automation mapp Safety, B&R Industrial Automation VC4 could allow an authenticated local attacker to execute malicious code by placing specially crafted files in the loading search path.\nThis issue affects Scene Viewer: before 4.4.0; Automation Runtime: before J4.93; mapp Vision: before 5.26.1; mapp View: before 5.24.2; mapp Cockpit: before 5.24.2; mapp Safety: before 5.24.2; VC4: before 4.73.2.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2025/03/GHSA-x43h-8pfv-xx24/GHSA-x43h-8pfv-xx24.json b/advisories/unreviewed/2025/03/GHSA-x43h-8pfv-xx24/GHSA-x43h-8pfv-xx24.json index 4128c66069c..77934bdeac4 100644 --- a/advisories/unreviewed/2025/03/GHSA-x43h-8pfv-xx24/GHSA-x43h-8pfv-xx24.json +++ b/advisories/unreviewed/2025/03/GHSA-x43h-8pfv-xx24/GHSA-x43h-8pfv-xx24.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x43h-8pfv-xx24", - "modified": "2025-03-18T09:31:49Z", + "modified": "2025-04-24T09:30:33Z", "published": "2025-03-18T09:31:49Z", "aliases": [ "CVE-2025-0755" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0755" }, + { + "type": "WEB", + "url": "https://jira.mongodb.org/browse/CDRIVER-5601" + }, { "type": "WEB", "url": "https://jira.mongodb.org/browse/SERVER-94461" diff --git a/advisories/unreviewed/2025/04/GHSA-243x-8mmp-f9jr/GHSA-243x-8mmp-f9jr.json b/advisories/unreviewed/2025/04/GHSA-243x-8mmp-f9jr/GHSA-243x-8mmp-f9jr.json new file mode 100644 index 00000000000..dd67d9eaed5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-243x-8mmp-f9jr/GHSA-243x-8mmp-f9jr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-243x-8mmp-f9jr", + "modified": "2025-04-24T09:30:34Z", + "published": "2025-04-24T09:30:34Z", + "aliases": [ + "CVE-2025-3058" + ], + "details": "The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the xwc_save_settings() function in all versions up to, and including, 9.1.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3058" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/xelion-webchat/trunk//includes/class-xelion-webchat-ajax-admin.php#L119" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/250202d5-3a0d-494c-8386-1f4cd015ad7e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T09:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3g36-gf7c-75qw/GHSA-3g36-gf7c-75qw.json b/advisories/unreviewed/2025/04/GHSA-3g36-gf7c-75qw/GHSA-3g36-gf7c-75qw.json new file mode 100644 index 00000000000..5f7e674d16d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3g36-gf7c-75qw/GHSA-3g36-gf7c-75qw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g36-gf7c-75qw", + "modified": "2025-04-24T09:30:33Z", + "published": "2025-04-24T09:30:33Z", + "aliases": [ + "CVE-2025-41395" + ], + "details": "Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom post type in the Playbooks plugin, which allows an attacker to create a specially crafted post with maliciously crafted props and cause a denial of service (DoS) of the web app for all users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41395" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T07:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3jmr-84q9-rpjf/GHSA-3jmr-84q9-rpjf.json b/advisories/unreviewed/2025/04/GHSA-3jmr-84q9-rpjf/GHSA-3jmr-84q9-rpjf.json new file mode 100644 index 00000000000..8b37d2100b2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3jmr-84q9-rpjf/GHSA-3jmr-84q9-rpjf.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jmr-84q9-rpjf", + "modified": "2025-04-24T09:30:34Z", + "published": "2025-04-24T09:30:34Z", + "aliases": [ + "CVE-2025-3065" + ], + "details": "The Database Toolset plugin is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3065" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/database-toolset/trunk/admin/class-database-toolset-admin.php#L109" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/database-toolset" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0e656123-cae4-4e0c-a80a-98526be293a8?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T09:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-43w4-f729-298m/GHSA-43w4-f729-298m.json b/advisories/unreviewed/2025/04/GHSA-43w4-f729-298m/GHSA-43w4-f729-298m.json new file mode 100644 index 00000000000..6d0fe3b18b1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-43w4-f729-298m/GHSA-43w4-f729-298m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43w4-f729-298m", + "modified": "2025-04-24T09:30:33Z", + "published": "2025-04-24T09:30:33Z", + "aliases": [ + "CVE-2024-12244" + ], + "details": "An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12244" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2862754" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/508046" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T08:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4662-3xhc-rv2x/GHSA-4662-3xhc-rv2x.json b/advisories/unreviewed/2025/04/GHSA-4662-3xhc-rv2x/GHSA-4662-3xhc-rv2x.json new file mode 100644 index 00000000000..1d9f3750fa3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4662-3xhc-rv2x/GHSA-4662-3xhc-rv2x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4662-3xhc-rv2x", + "modified": "2025-04-24T09:30:33Z", + "published": "2025-04-24T09:30:33Z", + "aliases": [ + "CVE-2025-3761" + ], + "details": "The My Tickets – Accessible Event Ticketing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.16. This is due to the mt_save_profile() function not appropriately restricting access to unauthorized users to update roles. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update their role to that of an administrator.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3761" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3280248/my-tickets/trunk/my-tickets.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6d875c23-3d8a-4f82-bea3-1c46b5045d94?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T07:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4g2r-p7w3-jh5j/GHSA-4g2r-p7w3-jh5j.json b/advisories/unreviewed/2025/04/GHSA-4g2r-p7w3-jh5j/GHSA-4g2r-p7w3-jh5j.json new file mode 100644 index 00000000000..198801b12d3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4g2r-p7w3-jh5j/GHSA-4g2r-p7w3-jh5j.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g2r-p7w3-jh5j", + "modified": "2025-04-24T09:30:34Z", + "published": "2025-04-24T09:30:34Z", + "aliases": [ + "CVE-2025-2543" + ], + "details": "The Advanced Accordion Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2543" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/advanced-accordion-block/tags/4.8.2/advanced-accordion-block.php#L363" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/advanced-accordion-block/tags/4.8.2/advanced-accordion-block.php#L364" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/advanced-accordion-block/tags/4.8.2/advanced-accordion-block.php#L369" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/advanced-accordion-block/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/79752ac3-cb5f-4d86-be58-c4b892e4edd6?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T09:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4xxh-h8pj-qxc6/GHSA-4xxh-h8pj-qxc6.json b/advisories/unreviewed/2025/04/GHSA-4xxh-h8pj-qxc6/GHSA-4xxh-h8pj-qxc6.json new file mode 100644 index 00000000000..db16eb6c2f7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4xxh-h8pj-qxc6/GHSA-4xxh-h8pj-qxc6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xxh-h8pj-qxc6", + "modified": "2025-04-24T09:30:34Z", + "published": "2025-04-24T09:30:34Z", + "aliases": [ + "CVE-2024-13307" + ], + "details": "The Reales WP - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'reales_delete_file', 'reales_delete_file_plans', 'reales_add_to_favourites', and 'reales_remove_from_favourites' functions in all versions up to, and including, 2.1.2. This makes it possible for unauthenticated attackers to delete arbitrary attachments, and add or remove favorite property listings for any user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13307" + }, + { + "type": "WEB", + "url": "https://themeforest.net/item/reales-wp-real-estate-wordpress-theme/10330568" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cb94caa4-35a4-4aa3-8d25-263bbd58072a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T09:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5c5g-j5fh-2fvr/GHSA-5c5g-j5fh-2fvr.json b/advisories/unreviewed/2025/04/GHSA-5c5g-j5fh-2fvr/GHSA-5c5g-j5fh-2fvr.json new file mode 100644 index 00000000000..d69a11b3ab5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5c5g-j5fh-2fvr/GHSA-5c5g-j5fh-2fvr.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c5g-j5fh-2fvr", + "modified": "2025-04-24T09:30:34Z", + "published": "2025-04-24T09:30:34Z", + "aliases": [ + "CVE-2025-3776" + ], + "details": "The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code Execution in all versions up to, and including, 1.5 via the 'targetvr_ajax_handler' function. This is due to a lack of validation on the type of function that can be called. This makes it possible for unauthenticated attackers to execute any callable function on the site, such as phpinfo().", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3776" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/verification-sms-targetsms/trunk/inc/ajax.php#L7" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/verification-sms-targetsms/trunk/inc/ajax.php#L9" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ed08d248-7467-4a3b-91a2-4286d91b9c50?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T09:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-689c-xq7x-xjwf/GHSA-689c-xq7x-xjwf.json b/advisories/unreviewed/2025/04/GHSA-689c-xq7x-xjwf/GHSA-689c-xq7x-xjwf.json new file mode 100644 index 00000000000..d0291d6b9df --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-689c-xq7x-xjwf/GHSA-689c-xq7x-xjwf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-689c-xq7x-xjwf", + "modified": "2025-04-24T09:30:33Z", + "published": "2025-04-24T09:30:33Z", + "aliases": [ + "CVE-2025-35965" + ], + "details": "Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation, which allows an attacker to create task items containing an excessive number of actions triggered by specific posts, overloading the server and leading to a denial-of-service (DoS) condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-35965" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T07:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-69q5-9q88-37jm/GHSA-69q5-9q88-37jm.json b/advisories/unreviewed/2025/04/GHSA-69q5-9q88-37jm/GHSA-69q5-9q88-37jm.json new file mode 100644 index 00000000000..4d7ec81e41b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-69q5-9q88-37jm/GHSA-69q5-9q88-37jm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69q5-9q88-37jm", + "modified": "2025-04-24T09:30:34Z", + "published": "2025-04-24T09:30:34Z", + "aliases": [ + "CVE-2025-3607" + ], + "details": "The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.7. This is due to the plugin not properly validating a user's identity prior to updating a password. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3607" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/frontend-login-and-registration-blocks/trunk/inc/class-flr-blocks-lost-password.php#L115" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b06ce1e4-5cfb-415d-ad09-db194d6b4354?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-620" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T09:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8xcw-x64j-h58v/GHSA-8xcw-x64j-h58v.json b/advisories/unreviewed/2025/04/GHSA-8xcw-x64j-h58v/GHSA-8xcw-x64j-h58v.json new file mode 100644 index 00000000000..4441249a95c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8xcw-x64j-h58v/GHSA-8xcw-x64j-h58v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xcw-x64j-h58v", + "modified": "2025-04-24T09:30:34Z", + "published": "2025-04-24T09:30:34Z", + "aliases": [ + "CVE-2025-3604" + ], + "details": "The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3604" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/flynax-bridge/trunk/request.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/935caa43-4c75-47ad-a631-63988e21f834?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T09:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9963-8j6c-xr65/GHSA-9963-8j6c-xr65.json b/advisories/unreviewed/2025/04/GHSA-9963-8j6c-xr65/GHSA-9963-8j6c-xr65.json new file mode 100644 index 00000000000..8453f8a81e6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9963-8j6c-xr65/GHSA-9963-8j6c-xr65.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9963-8j6c-xr65", + "modified": "2025-04-24T09:30:33Z", + "published": "2025-04-24T09:30:33Z", + "aliases": [ + "CVE-2025-0639" + ], + "details": "An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions from 16.7 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0639" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2946553" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/514507" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T08:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9mx9-xf85-m8v5/GHSA-9mx9-xf85-m8v5.json b/advisories/unreviewed/2025/04/GHSA-9mx9-xf85-m8v5/GHSA-9mx9-xf85-m8v5.json new file mode 100644 index 00000000000..36258f076b9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9mx9-xf85-m8v5/GHSA-9mx9-xf85-m8v5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mx9-xf85-m8v5", + "modified": "2025-04-24T09:30:34Z", + "published": "2025-04-24T09:30:34Z", + "aliases": [ + "CVE-2025-3300" + ], + "details": "The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with Administrator-level access and above, to read and modify the contents of arbitrary files on the server, which can contain sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3300" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wpmastertoolkit" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c389ba1a-45c5-4fba-9b99-0713fe39da42?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T09:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c4j4-vf5r-vcpp/GHSA-c4j4-vf5r-vcpp.json b/advisories/unreviewed/2025/04/GHSA-c4j4-vf5r-vcpp/GHSA-c4j4-vf5r-vcpp.json new file mode 100644 index 00000000000..21d99cdc77b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c4j4-vf5r-vcpp/GHSA-c4j4-vf5r-vcpp.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4j4-vf5r-vcpp", + "modified": "2025-04-24T09:30:33Z", + "published": "2025-04-24T09:30:33Z", + "aliases": [ + "CVE-2025-32730" + ], + "details": "Use of hard-coded cryptographic key vulnerability in i-PRO Configuration Tool affects the network system for i-PRO Co., Ltd. surveillance cameras and recorders. This vulnerability allows a local authenticated attacker to use the authentication information from the last connected surveillance cameras and recorders.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32730" + }, + { + "type": "WEB", + "url": "https://i-pro.com/products_and_solutions/en/surveillance/solutions/technologies/cyber-security/psirt/security-advisories" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN84627857" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-321" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T07:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cwjx-755c-h647/GHSA-cwjx-755c-h647.json b/advisories/unreviewed/2025/04/GHSA-cwjx-755c-h647/GHSA-cwjx-755c-h647.json new file mode 100644 index 00000000000..61da83df21c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cwjx-755c-h647/GHSA-cwjx-755c-h647.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwjx-755c-h647", + "modified": "2025-04-24T09:30:35Z", + "published": "2025-04-24T09:30:35Z", + "aliases": [ + "CVE-2025-3832" + ], + "details": "The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘successredirect’ parameter in all versions up to, and including, 6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3832" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/fusedesk/trunk/fusedesk.php#L516" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/fusedesk/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/baf12413-eb45-44c3-a6c9-f5a048d6500d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T09:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fr22-5377-f3p7/GHSA-fr22-5377-f3p7.json b/advisories/unreviewed/2025/04/GHSA-fr22-5377-f3p7/GHSA-fr22-5377-f3p7.json new file mode 100644 index 00000000000..787cdb4e50b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fr22-5377-f3p7/GHSA-fr22-5377-f3p7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr22-5377-f3p7", + "modified": "2025-04-24T09:30:33Z", + "published": "2025-04-24T09:30:33Z", + "aliases": [ + "CVE-2025-41423" + ], + "details": "Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread, allowing any user or attacker to delete posts containing actions created by the Playbooks bot, even without channel access or appropriate permissions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41423" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T07:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ghc6-72j6-q29j/GHSA-ghc6-72j6-q29j.json b/advisories/unreviewed/2025/04/GHSA-ghc6-72j6-q29j/GHSA-ghc6-72j6-q29j.json new file mode 100644 index 00000000000..1d8464d6fe5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ghc6-72j6-q29j/GHSA-ghc6-72j6-q29j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghc6-72j6-q29j", + "modified": "2025-04-24T09:30:34Z", + "published": "2025-04-24T09:30:34Z", + "aliases": [ + "CVE-2025-3101" + ], + "details": "The Configurator Theme Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.4.7. This is due to the plugin not properly validating user meta fields prior to updating them in the database. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change escalate their privileges to Administrator.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3101" + }, + { + "type": "WEB", + "url": "https://themeforest.net/item/configurator-woocommerce-wordpress-theme/20474230" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/535aa061-479f-415e-bee6-3151c42b917e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T09:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h38g-w8gh-4m6m/GHSA-h38g-w8gh-4m6m.json b/advisories/unreviewed/2025/04/GHSA-h38g-w8gh-4m6m/GHSA-h38g-w8gh-4m6m.json new file mode 100644 index 00000000000..59e5b3b80d8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h38g-w8gh-4m6m/GHSA-h38g-w8gh-4m6m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h38g-w8gh-4m6m", + "modified": "2025-04-24T09:30:34Z", + "published": "2025-04-24T09:30:34Z", + "aliases": [ + "CVE-2025-1908" + ], + "details": "An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1908" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/3016623" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/523065" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T08:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hv8q-7rjw-5h3j/GHSA-hv8q-7rjw-5h3j.json b/advisories/unreviewed/2025/04/GHSA-hv8q-7rjw-5h3j/GHSA-hv8q-7rjw-5h3j.json new file mode 100644 index 00000000000..a0fef8f1aee --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hv8q-7rjw-5h3j/GHSA-hv8q-7rjw-5h3j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hv8q-7rjw-5h3j", + "modified": "2025-04-24T09:30:35Z", + "published": "2025-04-24T09:30:35Z", + "aliases": [ + "CVE-2025-3793" + ], + "details": "The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plugin not properly validating a user's identity prior to updating their password through the 'bp_force_password_ajax' function in all versions up to, and including, 0.1. This makes it possible for authenticated attackers, with subscriber-level access and above and under certain prerequisites, to change arbitrary user's passwords, including administrators, and leverage that to gain access to their accounts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3793" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/buddy-press-force-password-change/trunk/bp-force-password-change.php#L93" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e3048c4c-77b1-4778-a5d0-b532df777d06?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-620" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T09:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jf94-mqcr-qwmx/GHSA-jf94-mqcr-qwmx.json b/advisories/unreviewed/2025/04/GHSA-jf94-mqcr-qwmx/GHSA-jf94-mqcr-qwmx.json new file mode 100644 index 00000000000..ff225454ac5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jf94-mqcr-qwmx/GHSA-jf94-mqcr-qwmx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jf94-mqcr-qwmx", + "modified": "2025-04-24T09:30:34Z", + "published": "2025-04-24T09:30:34Z", + "aliases": [ + "CVE-2025-3603" + ], + "details": "The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3603" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/flynax-bridge/trunk/request.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fa8124db-ee6a-481d-88c6-4cc84fefcf1c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-620" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T09:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vhj4-w2vf-v7jq/GHSA-vhj4-w2vf-v7jq.json b/advisories/unreviewed/2025/04/GHSA-vhj4-w2vf-v7jq/GHSA-vhj4-w2vf-v7jq.json new file mode 100644 index 00000000000..5188659b4b1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vhj4-w2vf-v7jq/GHSA-vhj4-w2vf-v7jq.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhj4-w2vf-v7jq", + "modified": "2025-04-24T09:30:34Z", + "published": "2025-04-24T09:30:34Z", + "aliases": [ + "CVE-2025-2579" + ], + "details": "The Lottie Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the uploaded file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2579" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/embed-lottie-player/tags/1.1.8/plugin.php#L130" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/embed-lottie-player/tags/1.1.8/plugin.php#L82" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/embed-lottie-player/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b85b314d-a155-4cec-95c9-0db4b9d8e59b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T09:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vjgj-v6jh-4c36/GHSA-vjgj-v6jh-4c36.json b/advisories/unreviewed/2025/04/GHSA-vjgj-v6jh-4c36/GHSA-vjgj-v6jh-4c36.json new file mode 100644 index 00000000000..56eb76f672e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vjgj-v6jh-4c36/GHSA-vjgj-v6jh-4c36.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjgj-v6jh-4c36", + "modified": "2025-04-24T09:30:34Z", + "published": "2025-04-24T09:30:34Z", + "aliases": [ + "CVE-2025-3280" + ], + "details": "The ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value_filter' parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3280" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/elex-bulk-edit-products-prices-attributes-for-woocommerce-basic" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e2e4b83a-34d5-4a8a-b694-a887a46fe6bf?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T09:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wj9c-gx74-xrjr/GHSA-wj9c-gx74-xrjr.json b/advisories/unreviewed/2025/04/GHSA-wj9c-gx74-xrjr/GHSA-wj9c-gx74-xrjr.json new file mode 100644 index 00000000000..c4c4590bd61 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wj9c-gx74-xrjr/GHSA-wj9c-gx74-xrjr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj9c-gx74-xrjr", + "modified": "2025-04-24T09:30:34Z", + "published": "2025-04-24T09:30:34Z", + "aliases": [ + "CVE-2025-1284" + ], + "details": "The Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1 via the xc_woo_printer_preview AJAX action due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view other user's invoices and orders which can contain sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1284" + }, + { + "type": "WEB", + "url": "https://codecanyon.net/item/woocommerce-google-cloud-print/21129093" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6f593dce-4b56-46c0-becd-75fd16f165a8?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T09:15:29Z" + } +} \ No newline at end of file