diff --git a/advisories/unreviewed/2023/09/GHSA-6m5p-5ccp-c8p3/GHSA-6m5p-5ccp-c8p3.json b/advisories/unreviewed/2023/09/GHSA-6m5p-5ccp-c8p3/GHSA-6m5p-5ccp-c8p3.json index 68139262048..1f14df1c23c 100644 --- a/advisories/unreviewed/2023/09/GHSA-6m5p-5ccp-c8p3/GHSA-6m5p-5ccp-c8p3.json +++ b/advisories/unreviewed/2023/09/GHSA-6m5p-5ccp-c8p3/GHSA-6m5p-5ccp-c8p3.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-5mfr-vx4f-m7q7/GHSA-5mfr-vx4f-m7q7.json b/advisories/unreviewed/2024/01/GHSA-5mfr-vx4f-m7q7/GHSA-5mfr-vx4f-m7q7.json index e56efee345f..31df32567a5 100644 --- a/advisories/unreviewed/2024/01/GHSA-5mfr-vx4f-m7q7/GHSA-5mfr-vx4f-m7q7.json +++ b/advisories/unreviewed/2024/01/GHSA-5mfr-vx4f-m7q7/GHSA-5mfr-vx4f-m7q7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-37jf-744c-x2h5/GHSA-37jf-744c-x2h5.json b/advisories/unreviewed/2024/05/GHSA-37jf-744c-x2h5/GHSA-37jf-744c-x2h5.json index 5b451cd1828..60c7ad4dfc2 100644 --- a/advisories/unreviewed/2024/05/GHSA-37jf-744c-x2h5/GHSA-37jf-744c-x2h5.json +++ b/advisories/unreviewed/2024/05/GHSA-37jf-744c-x2h5/GHSA-37jf-744c-x2h5.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-3g9x-fmvg-62j2/GHSA-3g9x-fmvg-62j2.json b/advisories/unreviewed/2024/05/GHSA-3g9x-fmvg-62j2/GHSA-3g9x-fmvg-62j2.json index d226ece8d5c..a7178da9c94 100644 --- a/advisories/unreviewed/2024/05/GHSA-3g9x-fmvg-62j2/GHSA-3g9x-fmvg-62j2.json +++ b/advisories/unreviewed/2024/05/GHSA-3g9x-fmvg-62j2/GHSA-3g9x-fmvg-62j2.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-52hw-j6hq-6qp4/GHSA-52hw-j6hq-6qp4.json b/advisories/unreviewed/2024/05/GHSA-52hw-j6hq-6qp4/GHSA-52hw-j6hq-6qp4.json index 75dfbd0441d..2953a96ae6b 100644 --- a/advisories/unreviewed/2024/05/GHSA-52hw-j6hq-6qp4/GHSA-52hw-j6hq-6qp4.json +++ b/advisories/unreviewed/2024/05/GHSA-52hw-j6hq-6qp4/GHSA-52hw-j6hq-6qp4.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-9f2x-6r69-376x/GHSA-9f2x-6r69-376x.json b/advisories/unreviewed/2024/05/GHSA-9f2x-6r69-376x/GHSA-9f2x-6r69-376x.json index fcb8dce18ea..3498d6bdb98 100644 --- a/advisories/unreviewed/2024/05/GHSA-9f2x-6r69-376x/GHSA-9f2x-6r69-376x.json +++ b/advisories/unreviewed/2024/05/GHSA-9f2x-6r69-376x/GHSA-9f2x-6r69-376x.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-c2p5-5fm9-fh69/GHSA-c2p5-5fm9-fh69.json b/advisories/unreviewed/2024/05/GHSA-c2p5-5fm9-fh69/GHSA-c2p5-5fm9-fh69.json index d9cba1add13..b9f9e766964 100644 --- a/advisories/unreviewed/2024/05/GHSA-c2p5-5fm9-fh69/GHSA-c2p5-5fm9-fh69.json +++ b/advisories/unreviewed/2024/05/GHSA-c2p5-5fm9-fh69/GHSA-c2p5-5fm9-fh69.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-h8wr-g7f7-2xmr/GHSA-h8wr-g7f7-2xmr.json b/advisories/unreviewed/2024/05/GHSA-h8wr-g7f7-2xmr/GHSA-h8wr-g7f7-2xmr.json index e4f54b5e6b1..c0cc3302ee7 100644 --- a/advisories/unreviewed/2024/05/GHSA-h8wr-g7f7-2xmr/GHSA-h8wr-g7f7-2xmr.json +++ b/advisories/unreviewed/2024/05/GHSA-h8wr-g7f7-2xmr/GHSA-h8wr-g7f7-2xmr.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-q386-c4r6-fhpq/GHSA-q386-c4r6-fhpq.json b/advisories/unreviewed/2024/05/GHSA-q386-c4r6-fhpq/GHSA-q386-c4r6-fhpq.json index 524aec1bd43..68a64a26f8f 100644 --- a/advisories/unreviewed/2024/05/GHSA-q386-c4r6-fhpq/GHSA-q386-c4r6-fhpq.json +++ b/advisories/unreviewed/2024/05/GHSA-q386-c4r6-fhpq/GHSA-q386-c4r6-fhpq.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-q6j3-4jqj-3hgc/GHSA-q6j3-4jqj-3hgc.json b/advisories/unreviewed/2024/05/GHSA-q6j3-4jqj-3hgc/GHSA-q6j3-4jqj-3hgc.json index 2989a9a47f0..d33c85ce5a4 100644 --- a/advisories/unreviewed/2024/05/GHSA-q6j3-4jqj-3hgc/GHSA-q6j3-4jqj-3hgc.json +++ b/advisories/unreviewed/2024/05/GHSA-q6j3-4jqj-3hgc/GHSA-q6j3-4jqj-3hgc.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-qcxh-gjw8-cccm/GHSA-qcxh-gjw8-cccm.json b/advisories/unreviewed/2024/05/GHSA-qcxh-gjw8-cccm/GHSA-qcxh-gjw8-cccm.json index 8e91ef91e68..479d37ce159 100644 --- a/advisories/unreviewed/2024/05/GHSA-qcxh-gjw8-cccm/GHSA-qcxh-gjw8-cccm.json +++ b/advisories/unreviewed/2024/05/GHSA-qcxh-gjw8-cccm/GHSA-qcxh-gjw8-cccm.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-v589-46c9-8j65/GHSA-v589-46c9-8j65.json b/advisories/unreviewed/2024/05/GHSA-v589-46c9-8j65/GHSA-v589-46c9-8j65.json index 42e91059bb2..5e23592b772 100644 --- a/advisories/unreviewed/2024/05/GHSA-v589-46c9-8j65/GHSA-v589-46c9-8j65.json +++ b/advisories/unreviewed/2024/05/GHSA-v589-46c9-8j65/GHSA-v589-46c9-8j65.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-457" + "CWE-457", + "CWE-908" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-vgm9-qjfw-qx5v/GHSA-vgm9-qjfw-qx5v.json b/advisories/unreviewed/2024/05/GHSA-vgm9-qjfw-qx5v/GHSA-vgm9-qjfw-qx5v.json index 8f859402ff3..9516c9ab84a 100644 --- a/advisories/unreviewed/2024/05/GHSA-vgm9-qjfw-qx5v/GHSA-vgm9-qjfw-qx5v.json +++ b/advisories/unreviewed/2024/05/GHSA-vgm9-qjfw-qx5v/GHSA-vgm9-qjfw-qx5v.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-w78w-3hhc-mfhw/GHSA-w78w-3hhc-mfhw.json b/advisories/unreviewed/2024/05/GHSA-w78w-3hhc-mfhw/GHSA-w78w-3hhc-mfhw.json index 85ba34d31ba..c24d3edce62 100644 --- a/advisories/unreviewed/2024/05/GHSA-w78w-3hhc-mfhw/GHSA-w78w-3hhc-mfhw.json +++ b/advisories/unreviewed/2024/05/GHSA-w78w-3hhc-mfhw/GHSA-w78w-3hhc-mfhw.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-x9cx-4jwp-33c3/GHSA-x9cx-4jwp-33c3.json b/advisories/unreviewed/2024/05/GHSA-x9cx-4jwp-33c3/GHSA-x9cx-4jwp-33c3.json index 541092144bf..60854e09f24 100644 --- a/advisories/unreviewed/2024/05/GHSA-x9cx-4jwp-33c3/GHSA-x9cx-4jwp-33c3.json +++ b/advisories/unreviewed/2024/05/GHSA-x9cx-4jwp-33c3/GHSA-x9cx-4jwp-33c3.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-2fj9-fc6x-hgw7/GHSA-2fj9-fc6x-hgw7.json b/advisories/unreviewed/2025/04/GHSA-2fj9-fc6x-hgw7/GHSA-2fj9-fc6x-hgw7.json index 559a37d9145..dffac621d78 100644 --- a/advisories/unreviewed/2025/04/GHSA-2fj9-fc6x-hgw7/GHSA-2fj9-fc6x-hgw7.json +++ b/advisories/unreviewed/2025/04/GHSA-2fj9-fc6x-hgw7/GHSA-2fj9-fc6x-hgw7.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-266" + "CWE-266", + "CWE-639" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-5qq7-mwf3-hg8r/GHSA-5qq7-mwf3-hg8r.json b/advisories/unreviewed/2025/04/GHSA-5qq7-mwf3-hg8r/GHSA-5qq7-mwf3-hg8r.json index 0da2d71b351..198843976fa 100644 --- a/advisories/unreviewed/2025/04/GHSA-5qq7-mwf3-hg8r/GHSA-5qq7-mwf3-hg8r.json +++ b/advisories/unreviewed/2025/04/GHSA-5qq7-mwf3-hg8r/GHSA-5qq7-mwf3-hg8r.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-6jjf-6382-x2fp/GHSA-6jjf-6382-x2fp.json b/advisories/unreviewed/2025/04/GHSA-6jjf-6382-x2fp/GHSA-6jjf-6382-x2fp.json index 76a8119a3c4..484ce161024 100644 --- a/advisories/unreviewed/2025/04/GHSA-6jjf-6382-x2fp/GHSA-6jjf-6382-x2fp.json +++ b/advisories/unreviewed/2025/04/GHSA-6jjf-6382-x2fp/GHSA-6jjf-6382-x2fp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6jjf-6382-x2fp", - "modified": "2025-04-30T09:30:25Z", + "modified": "2025-05-16T18:30:48Z", "published": "2025-04-30T09:30:25Z", "aliases": [ "CVE-2025-4125" diff --git a/advisories/unreviewed/2025/04/GHSA-cjv5-cj2c-3fgv/GHSA-cjv5-cj2c-3fgv.json b/advisories/unreviewed/2025/04/GHSA-cjv5-cj2c-3fgv/GHSA-cjv5-cj2c-3fgv.json index 5631746d3b1..fba9a5c6d14 100644 --- a/advisories/unreviewed/2025/04/GHSA-cjv5-cj2c-3fgv/GHSA-cjv5-cj2c-3fgv.json +++ b/advisories/unreviewed/2025/04/GHSA-cjv5-cj2c-3fgv/GHSA-cjv5-cj2c-3fgv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cjv5-cj2c-3fgv", - "modified": "2025-04-30T09:30:25Z", + "modified": "2025-05-16T18:30:48Z", "published": "2025-04-30T09:30:25Z", "aliases": [ "CVE-2025-4124" diff --git a/advisories/unreviewed/2025/04/GHSA-fgcv-8655-jx3q/GHSA-fgcv-8655-jx3q.json b/advisories/unreviewed/2025/04/GHSA-fgcv-8655-jx3q/GHSA-fgcv-8655-jx3q.json index ce515a248fc..d1363cd53c5 100644 --- a/advisories/unreviewed/2025/04/GHSA-fgcv-8655-jx3q/GHSA-fgcv-8655-jx3q.json +++ b/advisories/unreviewed/2025/04/GHSA-fgcv-8655-jx3q/GHSA-fgcv-8655-jx3q.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-gjrg-9xwg-gxw7/GHSA-gjrg-9xwg-gxw7.json b/advisories/unreviewed/2025/04/GHSA-gjrg-9xwg-gxw7/GHSA-gjrg-9xwg-gxw7.json index b9f8d687cc9..7f7c0d56155 100644 --- a/advisories/unreviewed/2025/04/GHSA-gjrg-9xwg-gxw7/GHSA-gjrg-9xwg-gxw7.json +++ b/advisories/unreviewed/2025/04/GHSA-gjrg-9xwg-gxw7/GHSA-gjrg-9xwg-gxw7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-h6hq-c28c-48r4/GHSA-h6hq-c28c-48r4.json b/advisories/unreviewed/2025/04/GHSA-h6hq-c28c-48r4/GHSA-h6hq-c28c-48r4.json index efb9e6a46b7..9f200be624c 100644 --- a/advisories/unreviewed/2025/04/GHSA-h6hq-c28c-48r4/GHSA-h6hq-c28c-48r4.json +++ b/advisories/unreviewed/2025/04/GHSA-h6hq-c28c-48r4/GHSA-h6hq-c28c-48r4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h6hq-c28c-48r4", - "modified": "2025-04-30T09:30:24Z", + "modified": "2025-05-16T18:30:48Z", "published": "2025-04-30T09:30:24Z", "aliases": [ "CVE-2025-22883" diff --git a/advisories/unreviewed/2025/04/GHSA-j2cm-6452-83gj/GHSA-j2cm-6452-83gj.json b/advisories/unreviewed/2025/04/GHSA-j2cm-6452-83gj/GHSA-j2cm-6452-83gj.json index fd7f676fb80..7a0ba0dcc43 100644 --- a/advisories/unreviewed/2025/04/GHSA-j2cm-6452-83gj/GHSA-j2cm-6452-83gj.json +++ b/advisories/unreviewed/2025/04/GHSA-j2cm-6452-83gj/GHSA-j2cm-6452-83gj.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-mpc5-8rvq-8qfx/GHSA-mpc5-8rvq-8qfx.json b/advisories/unreviewed/2025/04/GHSA-mpc5-8rvq-8qfx/GHSA-mpc5-8rvq-8qfx.json index 84c31078d30..f66a8ae54d9 100644 --- a/advisories/unreviewed/2025/04/GHSA-mpc5-8rvq-8qfx/GHSA-mpc5-8rvq-8qfx.json +++ b/advisories/unreviewed/2025/04/GHSA-mpc5-8rvq-8qfx/GHSA-mpc5-8rvq-8qfx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mpc5-8rvq-8qfx", - "modified": "2025-04-30T18:31:55Z", + "modified": "2025-05-16T18:30:54Z", "published": "2025-04-30T18:31:55Z", "aliases": [ "CVE-2025-39413" diff --git a/advisories/unreviewed/2025/04/GHSA-p64x-rw6v-fqhc/GHSA-p64x-rw6v-fqhc.json b/advisories/unreviewed/2025/04/GHSA-p64x-rw6v-fqhc/GHSA-p64x-rw6v-fqhc.json index 523df504bb2..b61cae5b025 100644 --- a/advisories/unreviewed/2025/04/GHSA-p64x-rw6v-fqhc/GHSA-p64x-rw6v-fqhc.json +++ b/advisories/unreviewed/2025/04/GHSA-p64x-rw6v-fqhc/GHSA-p64x-rw6v-fqhc.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-q3vr-42pm-pvrf/GHSA-q3vr-42pm-pvrf.json b/advisories/unreviewed/2025/04/GHSA-q3vr-42pm-pvrf/GHSA-q3vr-42pm-pvrf.json index a0a13bb43fa..1fad954b2f8 100644 --- a/advisories/unreviewed/2025/04/GHSA-q3vr-42pm-pvrf/GHSA-q3vr-42pm-pvrf.json +++ b/advisories/unreviewed/2025/04/GHSA-q3vr-42pm-pvrf/GHSA-q3vr-42pm-pvrf.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-v74x-4c9w-5ccp/GHSA-v74x-4c9w-5ccp.json b/advisories/unreviewed/2025/04/GHSA-v74x-4c9w-5ccp/GHSA-v74x-4c9w-5ccp.json index 1a1329a344e..a36cbed1966 100644 --- a/advisories/unreviewed/2025/04/GHSA-v74x-4c9w-5ccp/GHSA-v74x-4c9w-5ccp.json +++ b/advisories/unreviewed/2025/04/GHSA-v74x-4c9w-5ccp/GHSA-v74x-4c9w-5ccp.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-v8cr-jv23-8vf6/GHSA-v8cr-jv23-8vf6.json b/advisories/unreviewed/2025/04/GHSA-v8cr-jv23-8vf6/GHSA-v8cr-jv23-8vf6.json index 5e7d82a725e..77da960a11e 100644 --- a/advisories/unreviewed/2025/04/GHSA-v8cr-jv23-8vf6/GHSA-v8cr-jv23-8vf6.json +++ b/advisories/unreviewed/2025/04/GHSA-v8cr-jv23-8vf6/GHSA-v8cr-jv23-8vf6.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-vv87-89p2-ffxm/GHSA-vv87-89p2-ffxm.json b/advisories/unreviewed/2025/04/GHSA-vv87-89p2-ffxm/GHSA-vv87-89p2-ffxm.json index 25ddf1a61d7..cd3ade4771f 100644 --- a/advisories/unreviewed/2025/04/GHSA-vv87-89p2-ffxm/GHSA-vv87-89p2-ffxm.json +++ b/advisories/unreviewed/2025/04/GHSA-vv87-89p2-ffxm/GHSA-vv87-89p2-ffxm.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-wh9p-qc46-94pw/GHSA-wh9p-qc46-94pw.json b/advisories/unreviewed/2025/04/GHSA-wh9p-qc46-94pw/GHSA-wh9p-qc46-94pw.json index 4109d5c6e89..c2c4005ce16 100644 --- a/advisories/unreviewed/2025/04/GHSA-wh9p-qc46-94pw/GHSA-wh9p-qc46-94pw.json +++ b/advisories/unreviewed/2025/04/GHSA-wh9p-qc46-94pw/GHSA-wh9p-qc46-94pw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-26rj-c885-v2wv/GHSA-26rj-c885-v2wv.json b/advisories/unreviewed/2025/05/GHSA-26rj-c885-v2wv/GHSA-26rj-c885-v2wv.json new file mode 100644 index 00000000000..fb381698a2b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-26rj-c885-v2wv/GHSA-26rj-c885-v2wv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26rj-c885-v2wv", + "modified": "2025-05-16T18:31:08Z", + "published": "2025-05-16T18:31:08Z", + "aliases": [ + "CVE-2025-39509" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNcode TNC FlipBook allows Stored XSS. This issue affects TNC FlipBook: from n/a through 12.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39509" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pdf-viewer-for-wordpress/vulnerability/wordpress-tnc-flipbook-plugin-12-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-29r9-5qqf-325f/GHSA-29r9-5qqf-325f.json b/advisories/unreviewed/2025/05/GHSA-29r9-5qqf-325f/GHSA-29r9-5qqf-325f.json new file mode 100644 index 00000000000..c7eacb1e9c8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-29r9-5qqf-325f/GHSA-29r9-5qqf-325f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29r9-5qqf-325f", + "modified": "2025-05-16T18:31:10Z", + "published": "2025-05-16T18:31:10Z", + "aliases": [ + "CVE-2025-48138" + ], + "details": "Missing Authorization vulnerability in berthaai BERTHA AI allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects BERTHA AI: from n/a through 1.12.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48138" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bertha-ai-free/vulnerability/wordpress-bertha-ai-1-12-11-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-342x-54j8-cm6q/GHSA-342x-54j8-cm6q.json b/advisories/unreviewed/2025/05/GHSA-342x-54j8-cm6q/GHSA-342x-54j8-cm6q.json new file mode 100644 index 00000000000..caed9bc29b9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-342x-54j8-cm6q/GHSA-342x-54j8-cm6q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-342x-54j8-cm6q", + "modified": "2025-05-16T18:31:07Z", + "published": "2025-05-16T18:31:07Z", + "aliases": [ + "CVE-2025-39493" + ], + "details": "Missing Authorization vulnerability in ValvePress Rankie allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Rankie: from n/a through 1.8.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39493" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/valvepress-rankie/vulnerability/wordpress-rankie-1-8-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-345f-895w-jg76/GHSA-345f-895w-jg76.json b/advisories/unreviewed/2025/05/GHSA-345f-895w-jg76/GHSA-345f-895w-jg76.json index 9998a65b9ad..6b161798bce 100644 --- a/advisories/unreviewed/2025/05/GHSA-345f-895w-jg76/GHSA-345f-895w-jg76.json +++ b/advisories/unreviewed/2025/05/GHSA-345f-895w-jg76/GHSA-345f-895w-jg76.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-345f-895w-jg76", - "modified": "2025-05-15T21:31:27Z", + "modified": "2025-05-16T18:31:05Z", "published": "2025-05-15T21:31:27Z", "aliases": [ "CVE-2023-7228" ], "details": "The illi Link Party! WordPress plugin through 1.0 does not sanitise and escape some parameters, which could allow unauthenticated vistors to perform Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:30Z" diff --git a/advisories/unreviewed/2025/05/GHSA-347j-34g4-w8rf/GHSA-347j-34g4-w8rf.json b/advisories/unreviewed/2025/05/GHSA-347j-34g4-w8rf/GHSA-347j-34g4-w8rf.json new file mode 100644 index 00000000000..fff672d8d7c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-347j-34g4-w8rf/GHSA-347j-34g4-w8rf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-347j-34g4-w8rf", + "modified": "2025-05-16T18:31:06Z", + "published": "2025-05-16T18:31:06Z", + "aliases": [ + "CVE-2025-31071" + ], + "details": "Missing Authorization vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects HotStar – Multi-Purpose Business Theme: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31071" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/hotstar/vulnerability/wordpress-hotstar-multi-purpose-business-theme-1-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-36r2-q47h-w228/GHSA-36r2-q47h-w228.json b/advisories/unreviewed/2025/05/GHSA-36r2-q47h-w228/GHSA-36r2-q47h-w228.json index 87c283edb39..793bd85f75d 100644 --- a/advisories/unreviewed/2025/05/GHSA-36r2-q47h-w228/GHSA-36r2-q47h-w228.json +++ b/advisories/unreviewed/2025/05/GHSA-36r2-q47h-w228/GHSA-36r2-q47h-w228.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-3phq-v5rj-pfgp/GHSA-3phq-v5rj-pfgp.json b/advisories/unreviewed/2025/05/GHSA-3phq-v5rj-pfgp/GHSA-3phq-v5rj-pfgp.json new file mode 100644 index 00000000000..d9fea393084 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3phq-v5rj-pfgp/GHSA-3phq-v5rj-pfgp.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3phq-v5rj-pfgp", + "modified": "2025-05-16T18:31:06Z", + "published": "2025-05-16T18:31:06Z", + "aliases": [ + "CVE-2025-4785" + ], + "details": "A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user-profile.php. The manipulation of the argument fullname/contactnumber leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4785" + }, + { + "type": "WEB", + "url": "https://github.com/f1rstb100d/myCVE/issues/10" + }, + { + "type": "WEB", + "url": "https://github.com/f1rstb100d/myCVE/issues/9" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309086" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309086" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.572264" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T15:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3w84-6c49-fr7m/GHSA-3w84-6c49-fr7m.json b/advisories/unreviewed/2025/05/GHSA-3w84-6c49-fr7m/GHSA-3w84-6c49-fr7m.json new file mode 100644 index 00000000000..6887be1a8f1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3w84-6c49-fr7m/GHSA-3w84-6c49-fr7m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w84-6c49-fr7m", + "modified": "2025-05-16T18:31:07Z", + "published": "2025-05-16T18:31:07Z", + "aliases": [ + "CVE-2025-32301" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup CountDown Pro WP Plugin allows SQL Injection. This issue affects CountDown Pro WP Plugin: from n/a through 2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32301" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/circular_countdown/vulnerability/wordpress-countdown-pro-wp-plugin-2-7-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4853-m5x6-p4rx/GHSA-4853-m5x6-p4rx.json b/advisories/unreviewed/2025/05/GHSA-4853-m5x6-p4rx/GHSA-4853-m5x6-p4rx.json new file mode 100644 index 00000000000..06bbe225220 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4853-m5x6-p4rx/GHSA-4853-m5x6-p4rx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4853-m5x6-p4rx", + "modified": "2025-05-16T18:31:09Z", + "published": "2025-05-16T18:31:09Z", + "aliases": [ + "CVE-2025-48137" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in proxymis Interview allows SQL Injection. This issue affects Interview: from n/a through 1.01.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48137" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/interview/vulnerability/wordpress-interview-1-01-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-488m-4fx8-f36v/GHSA-488m-4fx8-f36v.json b/advisories/unreviewed/2025/05/GHSA-488m-4fx8-f36v/GHSA-488m-4fx8-f36v.json index 8def70b0840..3370078398f 100644 --- a/advisories/unreviewed/2025/05/GHSA-488m-4fx8-f36v/GHSA-488m-4fx8-f36v.json +++ b/advisories/unreviewed/2025/05/GHSA-488m-4fx8-f36v/GHSA-488m-4fx8-f36v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-488m-4fx8-f36v", - "modified": "2025-05-16T15:31:02Z", + "modified": "2025-05-16T18:31:06Z", "published": "2025-05-16T15:31:02Z", "aliases": [ "CVE-2025-40907" ], "details": "FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library.\n\nThe included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -41,7 +46,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-16T13:15:52Z" diff --git a/advisories/unreviewed/2025/05/GHSA-4c59-wg4x-f787/GHSA-4c59-wg4x-f787.json b/advisories/unreviewed/2025/05/GHSA-4c59-wg4x-f787/GHSA-4c59-wg4x-f787.json new file mode 100644 index 00000000000..ed006e09676 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4c59-wg4x-f787/GHSA-4c59-wg4x-f787.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c59-wg4x-f787", + "modified": "2025-05-16T18:31:10Z", + "published": "2025-05-16T18:31:10Z", + "aliases": [ + "CVE-2025-4787" + ], + "details": "A vulnerability classified as critical has been found in SourceCodester/oretnom23 Stock Management System 1.0. Affected is an unknown function of the file /admin/?page=sales/view_sale. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4787" + }, + { + "type": "WEB", + "url": "https://github.com/th3w0lf-1337/Vulnerabilities/blob/main/SMS-PHP/SQLi/Sale-List/info.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309096" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309096" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.572333" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4cwh-m6gc-c4p6/GHSA-4cwh-m6gc-c4p6.json b/advisories/unreviewed/2025/05/GHSA-4cwh-m6gc-c4p6/GHSA-4cwh-m6gc-c4p6.json index faa29e52a98..b3485a55571 100644 --- a/advisories/unreviewed/2025/05/GHSA-4cwh-m6gc-c4p6/GHSA-4cwh-m6gc-c4p6.json +++ b/advisories/unreviewed/2025/05/GHSA-4cwh-m6gc-c4p6/GHSA-4cwh-m6gc-c4p6.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-4jhj-88x4-5xw5/GHSA-4jhj-88x4-5xw5.json b/advisories/unreviewed/2025/05/GHSA-4jhj-88x4-5xw5/GHSA-4jhj-88x4-5xw5.json index e7b64c577d3..fd37476e399 100644 --- a/advisories/unreviewed/2025/05/GHSA-4jhj-88x4-5xw5/GHSA-4jhj-88x4-5xw5.json +++ b/advisories/unreviewed/2025/05/GHSA-4jhj-88x4-5xw5/GHSA-4jhj-88x4-5xw5.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-4qr9-wqj5-m42w/GHSA-4qr9-wqj5-m42w.json b/advisories/unreviewed/2025/05/GHSA-4qr9-wqj5-m42w/GHSA-4qr9-wqj5-m42w.json new file mode 100644 index 00000000000..57400f1f0c5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4qr9-wqj5-m42w/GHSA-4qr9-wqj5-m42w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qr9-wqj5-m42w", + "modified": "2025-05-16T18:31:07Z", + "published": "2025-05-16T18:31:07Z", + "aliases": [ + "CVE-2025-32299" + ], + "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Themovation QuickCal allows Retrieve Embedded Sensitive Data. This issue affects QuickCal: from n/a through 1.0.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32299" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quickcal/vulnerability/wordpress-quickcal-1-0-15-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4rxj-726p-wq74/GHSA-4rxj-726p-wq74.json b/advisories/unreviewed/2025/05/GHSA-4rxj-726p-wq74/GHSA-4rxj-726p-wq74.json index e386a2222e9..6183cb7f384 100644 --- a/advisories/unreviewed/2025/05/GHSA-4rxj-726p-wq74/GHSA-4rxj-726p-wq74.json +++ b/advisories/unreviewed/2025/05/GHSA-4rxj-726p-wq74/GHSA-4rxj-726p-wq74.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-4vxm-8pm4-5h85/GHSA-4vxm-8pm4-5h85.json b/advisories/unreviewed/2025/05/GHSA-4vxm-8pm4-5h85/GHSA-4vxm-8pm4-5h85.json index aa8c2c05a35..8594d449227 100644 --- a/advisories/unreviewed/2025/05/GHSA-4vxm-8pm4-5h85/GHSA-4vxm-8pm4-5h85.json +++ b/advisories/unreviewed/2025/05/GHSA-4vxm-8pm4-5h85/GHSA-4vxm-8pm4-5h85.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4vxm-8pm4-5h85", - "modified": "2025-05-15T21:31:27Z", + "modified": "2025-05-16T18:31:05Z", "published": "2025-05-15T21:31:27Z", "aliases": [ "CVE-2023-7229" ], "details": "The illi Link Party! WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:30Z" diff --git a/advisories/unreviewed/2025/05/GHSA-4w7m-m9xf-94pc/GHSA-4w7m-m9xf-94pc.json b/advisories/unreviewed/2025/05/GHSA-4w7m-m9xf-94pc/GHSA-4w7m-m9xf-94pc.json new file mode 100644 index 00000000000..894d930c72f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4w7m-m9xf-94pc/GHSA-4w7m-m9xf-94pc.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4w7m-m9xf-94pc", + "modified": "2025-05-16T18:31:10Z", + "published": "2025-05-16T18:31:10Z", + "aliases": [ + "CVE-2025-4786" + ], + "details": "A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/?page=return/view_return. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4786" + }, + { + "type": "WEB", + "url": "https://github.com/th3w0lf-1337/Vulnerabilities/blob/main/SMS-PHP/SQLi/Return-List/info.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309095" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309095" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.572297" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4wqv-9wp5-h8x2/GHSA-4wqv-9wp5-h8x2.json b/advisories/unreviewed/2025/05/GHSA-4wqv-9wp5-h8x2/GHSA-4wqv-9wp5-h8x2.json index c19b1fbb97c..aa9107e6a83 100644 --- a/advisories/unreviewed/2025/05/GHSA-4wqv-9wp5-h8x2/GHSA-4wqv-9wp5-h8x2.json +++ b/advisories/unreviewed/2025/05/GHSA-4wqv-9wp5-h8x2/GHSA-4wqv-9wp5-h8x2.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-5g6j-mffc-487c/GHSA-5g6j-mffc-487c.json b/advisories/unreviewed/2025/05/GHSA-5g6j-mffc-487c/GHSA-5g6j-mffc-487c.json new file mode 100644 index 00000000000..2cb13f1be47 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5g6j-mffc-487c/GHSA-5g6j-mffc-487c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g6j-mffc-487c", + "modified": "2025-05-16T18:31:07Z", + "published": "2025-05-16T18:31:07Z", + "aliases": [ + "CVE-2025-32287" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Responsive HTML5 Audio Player PRO With Playlist allows SQL Injection. This issue affects Responsive HTML5 Audio Player PRO With Playlist: from n/a through 3.5.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32287" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lbg-audio2-html5/vulnerability/wordpress-responsive-html5-audio-player-pro-with-playlist-3-5-7-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5h66-pmcp-rg7r/GHSA-5h66-pmcp-rg7r.json b/advisories/unreviewed/2025/05/GHSA-5h66-pmcp-rg7r/GHSA-5h66-pmcp-rg7r.json new file mode 100644 index 00000000000..277ff6de4b4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5h66-pmcp-rg7r/GHSA-5h66-pmcp-rg7r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h66-pmcp-rg7r", + "modified": "2025-05-16T18:31:06Z", + "published": "2025-05-16T18:31:06Z", + "aliases": [ + "CVE-2025-31922" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in QuanticaLabs CSS3 Accordions for WordPress allows Stored XSS. This issue affects CSS3 Accordions for WordPress: from n/a through 3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31922" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/css3_accordions/vulnerability/wordpress-css3-accordions-for-wordpress-plugin-3-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5pww-x83q-7gjh/GHSA-5pww-x83q-7gjh.json b/advisories/unreviewed/2025/05/GHSA-5pww-x83q-7gjh/GHSA-5pww-x83q-7gjh.json new file mode 100644 index 00000000000..30139ae8063 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5pww-x83q-7gjh/GHSA-5pww-x83q-7gjh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pww-x83q-7gjh", + "modified": "2025-05-16T18:31:08Z", + "published": "2025-05-16T18:31:08Z", + "aliases": [ + "CVE-2025-40906" + ], + "details": "BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities.\n\nThose include CVE-2017-14227, CVE-2018-16790, CVE-2023-0437, CVE-2024-6381, CVE-2024-6383, and CVE-2025-0755. \n\nBSON-XS was the official Perl XS implementation of MongoDB's BSON serialization, but this distribution has reached its end of life as of August 13, 2020 and is no longer supported.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40906" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00012.html" + }, + { + "type": "WEB", + "url": "https://www.mongodb.com/community/forums/t/mongodb-perl-driver-end-of-life/7890" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1104" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-64wr-jqr8-4q27/GHSA-64wr-jqr8-4q27.json b/advisories/unreviewed/2025/05/GHSA-64wr-jqr8-4q27/GHSA-64wr-jqr8-4q27.json new file mode 100644 index 00000000000..cbeadd9bc26 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-64wr-jqr8-4q27/GHSA-64wr-jqr8-4q27.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64wr-jqr8-4q27", + "modified": "2025-05-16T18:31:06Z", + "published": "2025-05-16T18:31:06Z", + "aliases": [ + "CVE-2025-31630" + ], + "details": "Missing Authorization vulnerability in themeton The Business allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Business: from n/a through 1.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31630" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/nrgbusiness/vulnerability/wordpress-the-business-1-6-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-65xm-c867-m6j9/GHSA-65xm-c867-m6j9.json b/advisories/unreviewed/2025/05/GHSA-65xm-c867-m6j9/GHSA-65xm-c867-m6j9.json new file mode 100644 index 00000000000..223daf00c9d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-65xm-c867-m6j9/GHSA-65xm-c867-m6j9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65xm-c867-m6j9", + "modified": "2025-05-16T18:31:08Z", + "published": "2025-05-16T18:31:08Z", + "aliases": [ + "CVE-2025-39511" + ], + "details": "Missing Authorization vulnerability in ValvePress Pinterest Automatic Pin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pinterest Automatic Pin: from n/a through 4.18.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39511" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-pinterest-automatic/vulnerability/wordpress-pinterest-automatic-pin-4-18-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6f38-fhvp-wmgg/GHSA-6f38-fhvp-wmgg.json b/advisories/unreviewed/2025/05/GHSA-6f38-fhvp-wmgg/GHSA-6f38-fhvp-wmgg.json new file mode 100644 index 00000000000..d8f12072d84 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6f38-fhvp-wmgg/GHSA-6f38-fhvp-wmgg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f38-fhvp-wmgg", + "modified": "2025-05-16T18:31:10Z", + "published": "2025-05-16T18:31:10Z", + "aliases": [ + "CVE-2025-48146" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Michael Lups SEO Flow by LupsOnline allows Stored XSS. This issue affects SEO Flow by LupsOnline: from n/a through 2.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48146" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lupsonline-link-netwerk/vulnerability/wordpress-seo-flow-by-lupsonline-plugin-2-2-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6jfm-gw74-r7cx/GHSA-6jfm-gw74-r7cx.json b/advisories/unreviewed/2025/05/GHSA-6jfm-gw74-r7cx/GHSA-6jfm-gw74-r7cx.json index ce71f69a81d..164e45eb96b 100644 --- a/advisories/unreviewed/2025/05/GHSA-6jfm-gw74-r7cx/GHSA-6jfm-gw74-r7cx.json +++ b/advisories/unreviewed/2025/05/GHSA-6jfm-gw74-r7cx/GHSA-6jfm-gw74-r7cx.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-6p5x-4w46-32gx/GHSA-6p5x-4w46-32gx.json b/advisories/unreviewed/2025/05/GHSA-6p5x-4w46-32gx/GHSA-6p5x-4w46-32gx.json index 3a052386e65..d8c04da64bf 100644 --- a/advisories/unreviewed/2025/05/GHSA-6p5x-4w46-32gx/GHSA-6p5x-4w46-32gx.json +++ b/advisories/unreviewed/2025/05/GHSA-6p5x-4w46-32gx/GHSA-6p5x-4w46-32gx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6p5x-4w46-32gx", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-16T18:31:06Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-4665" ], "details": "The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:54Z" diff --git a/advisories/unreviewed/2025/05/GHSA-6rc8-h6xq-v545/GHSA-6rc8-h6xq-v545.json b/advisories/unreviewed/2025/05/GHSA-6rc8-h6xq-v545/GHSA-6rc8-h6xq-v545.json index 55577eb960d..0b6ed1caf1d 100644 --- a/advisories/unreviewed/2025/05/GHSA-6rc8-h6xq-v545/GHSA-6rc8-h6xq-v545.json +++ b/advisories/unreviewed/2025/05/GHSA-6rc8-h6xq-v545/GHSA-6rc8-h6xq-v545.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-6wgm-4pp5-5r56/GHSA-6wgm-4pp5-5r56.json b/advisories/unreviewed/2025/05/GHSA-6wgm-4pp5-5r56/GHSA-6wgm-4pp5-5r56.json index 69fed705d49..6a20207c804 100644 --- a/advisories/unreviewed/2025/05/GHSA-6wgm-4pp5-5r56/GHSA-6wgm-4pp5-5r56.json +++ b/advisories/unreviewed/2025/05/GHSA-6wgm-4pp5-5r56/GHSA-6wgm-4pp5-5r56.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-72pr-qv32-rvf8/GHSA-72pr-qv32-rvf8.json b/advisories/unreviewed/2025/05/GHSA-72pr-qv32-rvf8/GHSA-72pr-qv32-rvf8.json new file mode 100644 index 00000000000..ed4ad4cdba7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-72pr-qv32-rvf8/GHSA-72pr-qv32-rvf8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72pr-qv32-rvf8", + "modified": "2025-05-16T18:31:07Z", + "published": "2025-05-16T18:31:07Z", + "aliases": [ + "CVE-2025-39491" + ], + "details": "Path Traversal vulnerability in WHMPress WHMpress allows Path Traversal. This issue affects WHMpress: from 6.2 through revision.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39491" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/whmpress/vulnerability/wordpress-whmpress-plugin-6-2-revision-9-local-file-inclusion-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-76h7-whc6-vxcf/GHSA-76h7-whc6-vxcf.json b/advisories/unreviewed/2025/05/GHSA-76h7-whc6-vxcf/GHSA-76h7-whc6-vxcf.json index ef054c22b97..47bc6ea5719 100644 --- a/advisories/unreviewed/2025/05/GHSA-76h7-whc6-vxcf/GHSA-76h7-whc6-vxcf.json +++ b/advisories/unreviewed/2025/05/GHSA-76h7-whc6-vxcf/GHSA-76h7-whc6-vxcf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-76h7-whc6-vxcf", - "modified": "2025-05-15T21:31:27Z", + "modified": "2025-05-16T18:31:05Z", "published": "2025-05-15T21:31:27Z", "aliases": [ "CVE-2024-0249" ], "details": "The Advanced Schedule Posts WordPress plugin through 2.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admins.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:31Z" diff --git a/advisories/unreviewed/2025/05/GHSA-7f63-jgvw-vgjq/GHSA-7f63-jgvw-vgjq.json b/advisories/unreviewed/2025/05/GHSA-7f63-jgvw-vgjq/GHSA-7f63-jgvw-vgjq.json index 2914d9d6b1e..2f8e4fb42ff 100644 --- a/advisories/unreviewed/2025/05/GHSA-7f63-jgvw-vgjq/GHSA-7f63-jgvw-vgjq.json +++ b/advisories/unreviewed/2025/05/GHSA-7f63-jgvw-vgjq/GHSA-7f63-jgvw-vgjq.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-7fp8-7q2p-mmxm/GHSA-7fp8-7q2p-mmxm.json b/advisories/unreviewed/2025/05/GHSA-7fp8-7q2p-mmxm/GHSA-7fp8-7q2p-mmxm.json index 21077c4f681..23cafdad460 100644 --- a/advisories/unreviewed/2025/05/GHSA-7fp8-7q2p-mmxm/GHSA-7fp8-7q2p-mmxm.json +++ b/advisories/unreviewed/2025/05/GHSA-7fp8-7q2p-mmxm/GHSA-7fp8-7q2p-mmxm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7fp8-7q2p-mmxm", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-16T18:31:05Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-3996" ], "details": "The Smart Post Show WordPress plugin before 2.4.28 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:53Z" diff --git a/advisories/unreviewed/2025/05/GHSA-7frv-rj2q-gfpw/GHSA-7frv-rj2q-gfpw.json b/advisories/unreviewed/2025/05/GHSA-7frv-rj2q-gfpw/GHSA-7frv-rj2q-gfpw.json new file mode 100644 index 00000000000..28bcbf40033 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7frv-rj2q-gfpw/GHSA-7frv-rj2q-gfpw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7frv-rj2q-gfpw", + "modified": "2025-05-16T18:31:08Z", + "published": "2025-05-16T18:31:08Z", + "aliases": [ + "CVE-2025-47556" + ], + "details": "Missing Authorization vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CSS3 Compare Pricing Tables for WordPress: from n/a through 11.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47556" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/css3_web_pricing_tables_grids/vulnerability/wordpress-css3-compare-pricing-tables-for-wordpress-11-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7hw5-qp4r-xc6c/GHSA-7hw5-qp4r-xc6c.json b/advisories/unreviewed/2025/05/GHSA-7hw5-qp4r-xc6c/GHSA-7hw5-qp4r-xc6c.json index a8adaf91a49..b75071327ae 100644 --- a/advisories/unreviewed/2025/05/GHSA-7hw5-qp4r-xc6c/GHSA-7hw5-qp4r-xc6c.json +++ b/advisories/unreviewed/2025/05/GHSA-7hw5-qp4r-xc6c/GHSA-7hw5-qp4r-xc6c.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-7rv8-qgm5-32cr/GHSA-7rv8-qgm5-32cr.json b/advisories/unreviewed/2025/05/GHSA-7rv8-qgm5-32cr/GHSA-7rv8-qgm5-32cr.json index 5cab2883746..727fbdbef13 100644 --- a/advisories/unreviewed/2025/05/GHSA-7rv8-qgm5-32cr/GHSA-7rv8-qgm5-32cr.json +++ b/advisories/unreviewed/2025/05/GHSA-7rv8-qgm5-32cr/GHSA-7rv8-qgm5-32cr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7rv8-qgm5-32cr", - "modified": "2025-05-15T21:31:27Z", + "modified": "2025-05-16T18:31:05Z", "published": "2025-05-15T21:31:27Z", "aliases": [ "CVE-2023-7297" ], "details": "The TwitterPosts WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:31Z" diff --git a/advisories/unreviewed/2025/05/GHSA-7vx7-qjwv-wcrm/GHSA-7vx7-qjwv-wcrm.json b/advisories/unreviewed/2025/05/GHSA-7vx7-qjwv-wcrm/GHSA-7vx7-qjwv-wcrm.json index 380b8c5e6fc..457a3b2d122 100644 --- a/advisories/unreviewed/2025/05/GHSA-7vx7-qjwv-wcrm/GHSA-7vx7-qjwv-wcrm.json +++ b/advisories/unreviewed/2025/05/GHSA-7vx7-qjwv-wcrm/GHSA-7vx7-qjwv-wcrm.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-7whp-5ffj-6crj/GHSA-7whp-5ffj-6crj.json b/advisories/unreviewed/2025/05/GHSA-7whp-5ffj-6crj/GHSA-7whp-5ffj-6crj.json new file mode 100644 index 00000000000..0359fa7fe50 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7whp-5ffj-6crj/GHSA-7whp-5ffj-6crj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7whp-5ffj-6crj", + "modified": "2025-05-16T18:31:06Z", + "published": "2025-05-16T18:31:06Z", + "aliases": [ + "CVE-2025-31639" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in themeton Spare allows Cross Site Request Forgery. This issue affects Spare: from n/a through 1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31639" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/spare/vulnerability/wordpress-spare-1-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8547-q6h5-6x7x/GHSA-8547-q6h5-6x7x.json b/advisories/unreviewed/2025/05/GHSA-8547-q6h5-6x7x/GHSA-8547-q6h5-6x7x.json new file mode 100644 index 00000000000..b4913fa768b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8547-q6h5-6x7x/GHSA-8547-q6h5-6x7x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8547-q6h5-6x7x", + "modified": "2025-05-16T18:31:07Z", + "published": "2025-05-16T18:31:07Z", + "aliases": [ + "CVE-2025-39482" + ], + "details": "Missing Authorization vulnerability in imithemes Eventer allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Eventer: from n/a through 3.9.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39482" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/eventer/vulnerability/wordpress-eventer-wordpress-event-booking-manager-plugin-plugin-3-9-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-87jp-vccx-5qj5/GHSA-87jp-vccx-5qj5.json b/advisories/unreviewed/2025/05/GHSA-87jp-vccx-5qj5/GHSA-87jp-vccx-5qj5.json index bd3ab425e04..a9b71ed3709 100644 --- a/advisories/unreviewed/2025/05/GHSA-87jp-vccx-5qj5/GHSA-87jp-vccx-5qj5.json +++ b/advisories/unreviewed/2025/05/GHSA-87jp-vccx-5qj5/GHSA-87jp-vccx-5qj5.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-88m5-wrqh-4w9g/GHSA-88m5-wrqh-4w9g.json b/advisories/unreviewed/2025/05/GHSA-88m5-wrqh-4w9g/GHSA-88m5-wrqh-4w9g.json index d0487b793e9..377ec8a4845 100644 --- a/advisories/unreviewed/2025/05/GHSA-88m5-wrqh-4w9g/GHSA-88m5-wrqh-4w9g.json +++ b/advisories/unreviewed/2025/05/GHSA-88m5-wrqh-4w9g/GHSA-88m5-wrqh-4w9g.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-8hx2-3q2m-9xxf/GHSA-8hx2-3q2m-9xxf.json b/advisories/unreviewed/2025/05/GHSA-8hx2-3q2m-9xxf/GHSA-8hx2-3q2m-9xxf.json index e3c8d6efb9f..b86f59c3f69 100644 --- a/advisories/unreviewed/2025/05/GHSA-8hx2-3q2m-9xxf/GHSA-8hx2-3q2m-9xxf.json +++ b/advisories/unreviewed/2025/05/GHSA-8hx2-3q2m-9xxf/GHSA-8hx2-3q2m-9xxf.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-94", "CWE-95" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2025/05/GHSA-8jv9-mqgc-pr2j/GHSA-8jv9-mqgc-pr2j.json b/advisories/unreviewed/2025/05/GHSA-8jv9-mqgc-pr2j/GHSA-8jv9-mqgc-pr2j.json index a4d2d9ecdc2..14d68a2f041 100644 --- a/advisories/unreviewed/2025/05/GHSA-8jv9-mqgc-pr2j/GHSA-8jv9-mqgc-pr2j.json +++ b/advisories/unreviewed/2025/05/GHSA-8jv9-mqgc-pr2j/GHSA-8jv9-mqgc-pr2j.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-8q8m-pcp7-hvmj/GHSA-8q8m-pcp7-hvmj.json b/advisories/unreviewed/2025/05/GHSA-8q8m-pcp7-hvmj/GHSA-8q8m-pcp7-hvmj.json new file mode 100644 index 00000000000..cf24298de94 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8q8m-pcp7-hvmj/GHSA-8q8m-pcp7-hvmj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q8m-pcp7-hvmj", + "modified": "2025-05-16T18:31:08Z", + "published": "2025-05-16T18:31:08Z", + "aliases": [ + "CVE-2025-47563" + ], + "details": "Missing Authorization vulnerability in villatheme CURCY allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects CURCY: from n/a through 2.3.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47563" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-multi-currency/vulnerability/wordpress-curcy-plugin-2-3-7-arbitrary-shortcode-execution-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8rhp-wjw3-rg6r/GHSA-8rhp-wjw3-rg6r.json b/advisories/unreviewed/2025/05/GHSA-8rhp-wjw3-rg6r/GHSA-8rhp-wjw3-rg6r.json new file mode 100644 index 00000000000..e07dff200b1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8rhp-wjw3-rg6r/GHSA-8rhp-wjw3-rg6r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rhp-wjw3-rg6r", + "modified": "2025-05-16T18:31:09Z", + "published": "2025-05-16T18:31:09Z", + "aliases": [ + "CVE-2025-48127" + ], + "details": "Missing Authorization vulnerability in App Cheap Push notification for Mobile and Web app allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Push notification for Mobile and Web app: from n/a through 2.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48127" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/push-notification-mobile-and-web-app/vulnerability/wordpress-push-notification-for-mobile-and-web-app-2-0-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8rwp-w2r2-g8vm/GHSA-8rwp-w2r2-g8vm.json b/advisories/unreviewed/2025/05/GHSA-8rwp-w2r2-g8vm/GHSA-8rwp-w2r2-g8vm.json new file mode 100644 index 00000000000..73705d2e89c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8rwp-w2r2-g8vm/GHSA-8rwp-w2r2-g8vm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rwp-w2r2-g8vm", + "modified": "2025-05-16T18:31:06Z", + "published": "2025-05-16T18:31:06Z", + "aliases": [ + "CVE-2025-31915" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder allows Cross Site Request Forgery. This issue affects Pixel WordPress Form BuilderPlugin & Autoresponder: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31915" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pixel-formbuilder/vulnerability/wordpress-pixel-wordpress-form-builderplugin-autoresponder-1-0-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8xm8-cg3h-pvgm/GHSA-8xm8-cg3h-pvgm.json b/advisories/unreviewed/2025/05/GHSA-8xm8-cg3h-pvgm/GHSA-8xm8-cg3h-pvgm.json new file mode 100644 index 00000000000..298ca2f8a02 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8xm8-cg3h-pvgm/GHSA-8xm8-cg3h-pvgm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xm8-cg3h-pvgm", + "modified": "2025-05-16T18:31:09Z", + "published": "2025-05-16T18:31:09Z", + "aliases": [ + "CVE-2025-48131" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saiful Islam UltraAddons Elementor Lite allows Stored XSS. This issue affects UltraAddons Elementor Lite: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48131" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultraaddons-elementor-lite/vulnerability/wordpress-ultraaddons-elementor-lite-2-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-928r-3p4g-rrxw/GHSA-928r-3p4g-rrxw.json b/advisories/unreviewed/2025/05/GHSA-928r-3p4g-rrxw/GHSA-928r-3p4g-rrxw.json index bc4e1e4a9b0..bcc9cbf2353 100644 --- a/advisories/unreviewed/2025/05/GHSA-928r-3p4g-rrxw/GHSA-928r-3p4g-rrxw.json +++ b/advisories/unreviewed/2025/05/GHSA-928r-3p4g-rrxw/GHSA-928r-3p4g-rrxw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-928r-3p4g-rrxw", - "modified": "2025-05-15T21:31:27Z", + "modified": "2025-05-16T18:31:05Z", "published": "2025-05-15T21:31:27Z", "aliases": [ "CVE-2023-7239" ], "details": "The WP Dashboard Notes WordPress plugin before 1.0.11 does not validate that the user has access to the post_id parameter in its wpdn_update_note AJAX action. This allows users with a role of contributor and above to update notes created by other users.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:30Z" diff --git a/advisories/unreviewed/2025/05/GHSA-95xf-mvwq-p849/GHSA-95xf-mvwq-p849.json b/advisories/unreviewed/2025/05/GHSA-95xf-mvwq-p849/GHSA-95xf-mvwq-p849.json new file mode 100644 index 00000000000..1940d98a318 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-95xf-mvwq-p849/GHSA-95xf-mvwq-p849.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95xf-mvwq-p849", + "modified": "2025-05-16T18:31:07Z", + "published": "2025-05-16T18:31:07Z", + "aliases": [ + "CVE-2025-32306" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Radio Player Shoutcast & Icecast WordPress Plugin allows Blind SQL Injection. This issue affects Radio Player Shoutcast & Icecast WordPress Plugin: from n/a through 4.4.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32306" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/audio4-html5/vulnerability/wordpress-radio-player-shoutcast-icecast-wordpress-plugin-4-4-6-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-96q3-fjrx-h9hh/GHSA-96q3-fjrx-h9hh.json b/advisories/unreviewed/2025/05/GHSA-96q3-fjrx-h9hh/GHSA-96q3-fjrx-h9hh.json new file mode 100644 index 00000000000..b9fdf4ed686 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-96q3-fjrx-h9hh/GHSA-96q3-fjrx-h9hh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96q3-fjrx-h9hh", + "modified": "2025-05-16T18:31:06Z", + "published": "2025-05-16T18:31:06Z", + "aliases": [ + "CVE-2025-47916" + ], + "details": "Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (file: /applications/core/modules/front/system/themeeditor.php), where a protected method named customCss can be invoked by unauthenticated users. This method passes the value of the content parameter to the Theme::makeProcessFunction() method; hence it is evaluated by the template engine. Accordingly, this can be exploited by unauthenticated attackers to inject and execute arbitrary PHP code by providing crafted template strings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47916" + }, + { + "type": "WEB", + "url": "https://invisioncommunity.com/release-notes-v5/507-r41" + }, + { + "type": "WEB", + "url": "https://karmainsecurity.com/KIS-2025-02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1336" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-97qr-gc42-m9f7/GHSA-97qr-gc42-m9f7.json b/advisories/unreviewed/2025/05/GHSA-97qr-gc42-m9f7/GHSA-97qr-gc42-m9f7.json new file mode 100644 index 00000000000..538e594ef2f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-97qr-gc42-m9f7/GHSA-97qr-gc42-m9f7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97qr-gc42-m9f7", + "modified": "2025-05-16T18:31:06Z", + "published": "2025-05-16T18:31:06Z", + "aliases": [ + "CVE-2025-31065" + ], + "details": "Missing Authorization vulnerability in themeton Rozario allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Rozario: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31065" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/rozario/vulnerability/wordpress-rozario-1-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9mm8-854r-8wvw/GHSA-9mm8-854r-8wvw.json b/advisories/unreviewed/2025/05/GHSA-9mm8-854r-8wvw/GHSA-9mm8-854r-8wvw.json new file mode 100644 index 00000000000..1997a5428ee --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9mm8-854r-8wvw/GHSA-9mm8-854r-8wvw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mm8-854r-8wvw", + "modified": "2025-05-16T18:31:07Z", + "published": "2025-05-16T18:31:07Z", + "aliases": [ + "CVE-2025-39481" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in imithemes Eventer allows Blind SQL Injection. This issue affects Eventer: from n/a through 3.9.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39481" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/eventer/vulnerability/wordpress-eventer-wordpress-event-booking-manager-plugin-plugin-3-9-6-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9rvg-2xr8-g4f4/GHSA-9rvg-2xr8-g4f4.json b/advisories/unreviewed/2025/05/GHSA-9rvg-2xr8-g4f4/GHSA-9rvg-2xr8-g4f4.json new file mode 100644 index 00000000000..84819849330 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9rvg-2xr8-g4f4/GHSA-9rvg-2xr8-g4f4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rvg-2xr8-g4f4", + "modified": "2025-05-16T18:31:10Z", + "published": "2025-05-16T18:31:10Z", + "aliases": [ + "CVE-2025-48144" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in sidngr Import Export For WooCommerce allows Stored XSS. This issue affects Import Export For WooCommerce: from n/a through 1.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48144" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/import-export-for-woocommerce/vulnerability/wordpress-import-export-for-woocommerce-plugin-1-6-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c29g-jjrw-x2ff/GHSA-c29g-jjrw-x2ff.json b/advisories/unreviewed/2025/05/GHSA-c29g-jjrw-x2ff/GHSA-c29g-jjrw-x2ff.json new file mode 100644 index 00000000000..cd6961d94d8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c29g-jjrw-x2ff/GHSA-c29g-jjrw-x2ff.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c29g-jjrw-x2ff", + "modified": "2025-05-16T18:31:06Z", + "published": "2025-05-16T18:31:06Z", + "aliases": [ + "CVE-2025-31640" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Magic Responsive Slider and Carousel WordPress allows SQL Injection. This issue affects Magic Responsive Slider and Carousel WordPress: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31640" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/magic-carousel/vulnerability/wordpress-magic-responsive-slider-and-carousel-wordpress-1-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c397-p6xh-cjxg/GHSA-c397-p6xh-cjxg.json b/advisories/unreviewed/2025/05/GHSA-c397-p6xh-cjxg/GHSA-c397-p6xh-cjxg.json new file mode 100644 index 00000000000..4210a03674d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c397-p6xh-cjxg/GHSA-c397-p6xh-cjxg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c397-p6xh-cjxg", + "modified": "2025-05-16T18:31:07Z", + "published": "2025-05-16T18:31:07Z", + "aliases": [ + "CVE-2025-32310" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ThemeMove QuickCal allows Privilege Escalation. This issue affects QuickCal: from n/a through 1.0.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32310" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quickcal/vulnerability/wordpress-quickcal-plugin-1-0-13-csrf-to-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c44h-wf4g-24fr/GHSA-c44h-wf4g-24fr.json b/advisories/unreviewed/2025/05/GHSA-c44h-wf4g-24fr/GHSA-c44h-wf4g-24fr.json index 0a6e84cdaf0..af89dcb5eb6 100644 --- a/advisories/unreviewed/2025/05/GHSA-c44h-wf4g-24fr/GHSA-c44h-wf4g-24fr.json +++ b/advisories/unreviewed/2025/05/GHSA-c44h-wf4g-24fr/GHSA-c44h-wf4g-24fr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c44h-wf4g-24fr", - "modified": "2025-05-15T21:31:27Z", + "modified": "2025-05-16T18:31:05Z", "published": "2025-05-15T21:31:27Z", "aliases": [ "CVE-2023-7231" ], "details": "The illi Link Party! WordPress plugin through 1.0 lacks proper access controls, allowing unauthenticated visitors to delete links.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:30Z" diff --git a/advisories/unreviewed/2025/05/GHSA-c6wh-53mq-4gr9/GHSA-c6wh-53mq-4gr9.json b/advisories/unreviewed/2025/05/GHSA-c6wh-53mq-4gr9/GHSA-c6wh-53mq-4gr9.json index 023698d6642..47c47846bbd 100644 --- a/advisories/unreviewed/2025/05/GHSA-c6wh-53mq-4gr9/GHSA-c6wh-53mq-4gr9.json +++ b/advisories/unreviewed/2025/05/GHSA-c6wh-53mq-4gr9/GHSA-c6wh-53mq-4gr9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c6wh-53mq-4gr9", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-16T18:31:05Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-12767" ], "details": "The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view comments on private posts", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:37Z" diff --git a/advisories/unreviewed/2025/05/GHSA-c8fv-rjf6-9q8v/GHSA-c8fv-rjf6-9q8v.json b/advisories/unreviewed/2025/05/GHSA-c8fv-rjf6-9q8v/GHSA-c8fv-rjf6-9q8v.json new file mode 100644 index 00000000000..31886507cad --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c8fv-rjf6-9q8v/GHSA-c8fv-rjf6-9q8v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8fv-rjf6-9q8v", + "modified": "2025-05-16T18:31:08Z", + "published": "2025-05-16T18:31:08Z", + "aliases": [ + "CVE-2025-47567" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Video Player & FullScreen Video Background allows Blind SQL Injection. This issue affects Video Player & FullScreen Video Background: from n/a through 2.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47567" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/universal-video-player-and-bg/vulnerability/wordpress-video-player-fullscreen-video-background-plugin-2-4-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-chgf-rv7c-3x2f/GHSA-chgf-rv7c-3x2f.json b/advisories/unreviewed/2025/05/GHSA-chgf-rv7c-3x2f/GHSA-chgf-rv7c-3x2f.json index b4abd8a6f2f..91a6a112bf5 100644 --- a/advisories/unreviewed/2025/05/GHSA-chgf-rv7c-3x2f/GHSA-chgf-rv7c-3x2f.json +++ b/advisories/unreviewed/2025/05/GHSA-chgf-rv7c-3x2f/GHSA-chgf-rv7c-3x2f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-chgf-rv7c-3x2f", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-16T18:31:06Z", "published": "2025-05-15T21:31:31Z", "aliases": [ "CVE-2024-6711" ], "details": "The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:55Z" diff --git a/advisories/unreviewed/2025/05/GHSA-cjvp-vp4r-jppc/GHSA-cjvp-vp4r-jppc.json b/advisories/unreviewed/2025/05/GHSA-cjvp-vp4r-jppc/GHSA-cjvp-vp4r-jppc.json new file mode 100644 index 00000000000..d9189f44f4d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cjvp-vp4r-jppc/GHSA-cjvp-vp4r-jppc.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjvp-vp4r-jppc", + "modified": "2025-05-16T18:31:10Z", + "published": "2025-05-16T18:31:10Z", + "aliases": [ + "CVE-2025-4788" + ], + "details": "A vulnerability classified as critical was found in FreeFloat FTP Server 1.0. Affected by this vulnerability is an unknown functionality of the component DELETE Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4788" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-cd619c9271a231511f4fa2de1cf569b7040376a5cfe23dc6060884c32638254e.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309097" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309097" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.572476" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cjvw-2hqr-v93r/GHSA-cjvw-2hqr-v93r.json b/advisories/unreviewed/2025/05/GHSA-cjvw-2hqr-v93r/GHSA-cjvw-2hqr-v93r.json index d19f4045d7c..91da4b2fdbc 100644 --- a/advisories/unreviewed/2025/05/GHSA-cjvw-2hqr-v93r/GHSA-cjvw-2hqr-v93r.json +++ b/advisories/unreviewed/2025/05/GHSA-cjvw-2hqr-v93r/GHSA-cjvw-2hqr-v93r.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-crw6-rj3g-7hfh/GHSA-crw6-rj3g-7hfh.json b/advisories/unreviewed/2025/05/GHSA-crw6-rj3g-7hfh/GHSA-crw6-rj3g-7hfh.json new file mode 100644 index 00000000000..b8b2de84e22 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-crw6-rj3g-7hfh/GHSA-crw6-rj3g-7hfh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crw6-rj3g-7hfh", + "modified": "2025-05-16T18:31:08Z", + "published": "2025-05-16T18:31:08Z", + "aliases": [ + "CVE-2025-47562" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG allows Code Injection. This issue affects MapSVG: from n/a through 8.5.34.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47562" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mapsvg/vulnerability/wordpress-mapsvg-8-5-34-content-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ffvf-jcq5-f366/GHSA-ffvf-jcq5-f366.json b/advisories/unreviewed/2025/05/GHSA-ffvf-jcq5-f366/GHSA-ffvf-jcq5-f366.json index 3a92fc6fc0a..91a1411aeac 100644 --- a/advisories/unreviewed/2025/05/GHSA-ffvf-jcq5-f366/GHSA-ffvf-jcq5-f366.json +++ b/advisories/unreviewed/2025/05/GHSA-ffvf-jcq5-f366/GHSA-ffvf-jcq5-f366.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ffvf-jcq5-f366", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-16T18:31:06Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-4004" ], "details": "The Advanced Cron Manager WordPress plugin before 2.5.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:54Z" diff --git a/advisories/unreviewed/2025/05/GHSA-fhmg-vgv9-r776/GHSA-fhmg-vgv9-r776.json b/advisories/unreviewed/2025/05/GHSA-fhmg-vgv9-r776/GHSA-fhmg-vgv9-r776.json new file mode 100644 index 00000000000..f38e62c8d76 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fhmg-vgv9-r776/GHSA-fhmg-vgv9-r776.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhmg-vgv9-r776", + "modified": "2025-05-16T18:31:09Z", + "published": "2025-05-16T18:31:09Z", + "aliases": [ + "CVE-2025-48132" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pencilwp X Addons for Elementor allows Stored XSS. This issue affects X Addons for Elementor: from n/a through 1.0.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48132" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/x-addons-elementor/vulnerability/wordpress-x-addons-for-elementor-1-0-14-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fjwm-36m9-wg5m/GHSA-fjwm-36m9-wg5m.json b/advisories/unreviewed/2025/05/GHSA-fjwm-36m9-wg5m/GHSA-fjwm-36m9-wg5m.json new file mode 100644 index 00000000000..3ccaf91d9c3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fjwm-36m9-wg5m/GHSA-fjwm-36m9-wg5m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjwm-36m9-wg5m", + "modified": "2025-05-16T18:31:07Z", + "published": "2025-05-16T18:31:07Z", + "aliases": [ + "CVE-2025-32180" + ], + "details": "Missing Authorization vulnerability in QuanticaLabs CSS3 Tooltips for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CSS3 Tooltips for WordPress: from n/a through 1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32180" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/css3_tooltips/vulnerability/wordpress-css3-tooltips-for-wordpress-1-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fm37-cg6p-8x57/GHSA-fm37-cg6p-8x57.json b/advisories/unreviewed/2025/05/GHSA-fm37-cg6p-8x57/GHSA-fm37-cg6p-8x57.json new file mode 100644 index 00000000000..57a1324817f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fm37-cg6p-8x57/GHSA-fm37-cg6p-8x57.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm37-cg6p-8x57", + "modified": "2025-05-16T18:31:08Z", + "published": "2025-05-16T18:31:08Z", + "aliases": [ + "CVE-2025-47564" + ], + "details": "Missing Authorization vulnerability in ashanjay EventON allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects EventON: from n/a through 4.9.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47564" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/eventon/vulnerability/wordpress-eventon-plugin-4-9-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fmgr-wh24-38gx/GHSA-fmgr-wh24-38gx.json b/advisories/unreviewed/2025/05/GHSA-fmgr-wh24-38gx/GHSA-fmgr-wh24-38gx.json new file mode 100644 index 00000000000..feadfd5f5e7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fmgr-wh24-38gx/GHSA-fmgr-wh24-38gx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmgr-wh24-38gx", + "modified": "2025-05-16T18:31:06Z", + "published": "2025-05-16T18:31:06Z", + "aliases": [ + "CVE-2025-31641" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup UberSlider allows SQL Injection. This issue affects UberSlider: from n/a through 2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31641" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/uber-classic/vulnerability/wordpress-uberslider-2-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fpx7-q8wv-4mj3/GHSA-fpx7-q8wv-4mj3.json b/advisories/unreviewed/2025/05/GHSA-fpx7-q8wv-4mj3/GHSA-fpx7-q8wv-4mj3.json new file mode 100644 index 00000000000..079365ade59 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fpx7-q8wv-4mj3/GHSA-fpx7-q8wv-4mj3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpx7-q8wv-4mj3", + "modified": "2025-05-16T18:31:07Z", + "published": "2025-05-16T18:31:07Z", + "aliases": [ + "CVE-2025-39492" + ], + "details": "Path Traversal vulnerability in WHMPress WHMpress allows Relative Path Traversal. This issue affects WHMpress: from 6.2 through revision.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39492" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/whmpress/vulnerability/wordpress-whmpress-plugin-6-2-revision-9-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fv2r-4fvf-x6vp/GHSA-fv2r-4fvf-x6vp.json b/advisories/unreviewed/2025/05/GHSA-fv2r-4fvf-x6vp/GHSA-fv2r-4fvf-x6vp.json new file mode 100644 index 00000000000..9483229a397 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fv2r-4fvf-x6vp/GHSA-fv2r-4fvf-x6vp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv2r-4fvf-x6vp", + "modified": "2025-05-16T18:31:07Z", + "published": "2025-05-16T18:31:07Z", + "aliases": [ + "CVE-2025-32296" + ], + "details": "Missing Authorization vulnerability in quantumcloud Simple Link Directory Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple Link Directory Pro: from n/a through 14.7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32296" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/qc-simple-link-directory/vulnerability/wordpress-simple-link-directory-pro-plugin-14-7-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g2f9-237v-8mgp/GHSA-g2f9-237v-8mgp.json b/advisories/unreviewed/2025/05/GHSA-g2f9-237v-8mgp/GHSA-g2f9-237v-8mgp.json new file mode 100644 index 00000000000..63a0dc32604 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g2f9-237v-8mgp/GHSA-g2f9-237v-8mgp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2f9-237v-8mgp", + "modified": "2025-05-16T18:31:07Z", + "published": "2025-05-16T18:31:07Z", + "aliases": [ + "CVE-2025-31926" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Sticky Radio Player allows SQL Injection. This issue affects Sticky Radio Player: from n/a through 3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31926" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lbg-audio5-html5-shoutcast_sticky/vulnerability/wordpress-sticky-radio-player-3-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g4cf-3pjw-w4xj/GHSA-g4cf-3pjw-w4xj.json b/advisories/unreviewed/2025/05/GHSA-g4cf-3pjw-w4xj/GHSA-g4cf-3pjw-w4xj.json index 9954296d4d3..1683f623d44 100644 --- a/advisories/unreviewed/2025/05/GHSA-g4cf-3pjw-w4xj/GHSA-g4cf-3pjw-w4xj.json +++ b/advisories/unreviewed/2025/05/GHSA-g4cf-3pjw-w4xj/GHSA-g4cf-3pjw-w4xj.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-g6x2-86jw-7c7w/GHSA-g6x2-86jw-7c7w.json b/advisories/unreviewed/2025/05/GHSA-g6x2-86jw-7c7w/GHSA-g6x2-86jw-7c7w.json index 2760c86c16f..263594f56d0 100644 --- a/advisories/unreviewed/2025/05/GHSA-g6x2-86jw-7c7w/GHSA-g6x2-86jw-7c7w.json +++ b/advisories/unreviewed/2025/05/GHSA-g6x2-86jw-7c7w/GHSA-g6x2-86jw-7c7w.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-gpv2-32pf-74f2/GHSA-gpv2-32pf-74f2.json b/advisories/unreviewed/2025/05/GHSA-gpv2-32pf-74f2/GHSA-gpv2-32pf-74f2.json index b42250f6929..017ce7a4246 100644 --- a/advisories/unreviewed/2025/05/GHSA-gpv2-32pf-74f2/GHSA-gpv2-32pf-74f2.json +++ b/advisories/unreviewed/2025/05/GHSA-gpv2-32pf-74f2/GHSA-gpv2-32pf-74f2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gpv2-32pf-74f2", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-16T18:31:05Z", "published": "2025-05-15T21:31:31Z", "aliases": [ "CVE-2024-4002" ], "details": "The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.6.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:54Z" diff --git a/advisories/unreviewed/2025/05/GHSA-gqrv-63m2-x4mj/GHSA-gqrv-63m2-x4mj.json b/advisories/unreviewed/2025/05/GHSA-gqrv-63m2-x4mj/GHSA-gqrv-63m2-x4mj.json index 696fa308254..06d237497fe 100644 --- a/advisories/unreviewed/2025/05/GHSA-gqrv-63m2-x4mj/GHSA-gqrv-63m2-x4mj.json +++ b/advisories/unreviewed/2025/05/GHSA-gqrv-63m2-x4mj/GHSA-gqrv-63m2-x4mj.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-grjw-vx74-33j3/GHSA-grjw-vx74-33j3.json b/advisories/unreviewed/2025/05/GHSA-grjw-vx74-33j3/GHSA-grjw-vx74-33j3.json new file mode 100644 index 00000000000..e8795ece99d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-grjw-vx74-33j3/GHSA-grjw-vx74-33j3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grjw-vx74-33j3", + "modified": "2025-05-16T18:31:08Z", + "published": "2025-05-16T18:31:08Z", + "aliases": [ + "CVE-2025-46464" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scripteo Ads Pro Plugin allows Stored XSS. This issue affects Ads Pro Plugin: from n/a through 4.88.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46464" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ap-plugin-scripteo/vulnerability/wordpress-ads-pro-plugin-4-88-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gx24-fg4m-2f7m/GHSA-gx24-fg4m-2f7m.json b/advisories/unreviewed/2025/05/GHSA-gx24-fg4m-2f7m/GHSA-gx24-fg4m-2f7m.json index 3e7b78e49d5..2949cb8767a 100644 --- a/advisories/unreviewed/2025/05/GHSA-gx24-fg4m-2f7m/GHSA-gx24-fg4m-2f7m.json +++ b/advisories/unreviewed/2025/05/GHSA-gx24-fg4m-2f7m/GHSA-gx24-fg4m-2f7m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gx24-fg4m-2f7m", - "modified": "2025-05-15T21:31:27Z", + "modified": "2025-05-16T18:31:05Z", "published": "2025-05-15T21:31:27Z", "aliases": [ "CVE-2024-0852" ], "details": "The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting it back in the admin dashboard, allowing unauthenticated users to perform Stored XSS attack against high privilege users such as admin", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:32Z" diff --git a/advisories/unreviewed/2025/05/GHSA-h3fw-28mg-f834/GHSA-h3fw-28mg-f834.json b/advisories/unreviewed/2025/05/GHSA-h3fw-28mg-f834/GHSA-h3fw-28mg-f834.json new file mode 100644 index 00000000000..f09f2d57254 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h3fw-28mg-f834/GHSA-h3fw-28mg-f834.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3fw-28mg-f834", + "modified": "2025-05-16T18:31:06Z", + "published": "2025-05-16T18:31:06Z", + "aliases": [ + "CVE-2025-31062" + ], + "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in redqteam Wishlist allows Retrieve Embedded Sensitive Data. This issue affects Wishlist: from n/a through 2.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31062" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wishlist/vulnerability/wordpress-wishlist-2-1-0-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h3xv-8c7h-5fjq/GHSA-h3xv-8c7h-5fjq.json b/advisories/unreviewed/2025/05/GHSA-h3xv-8c7h-5fjq/GHSA-h3xv-8c7h-5fjq.json index 47f43d99001..d33d0edd8d5 100644 --- a/advisories/unreviewed/2025/05/GHSA-h3xv-8c7h-5fjq/GHSA-h3xv-8c7h-5fjq.json +++ b/advisories/unreviewed/2025/05/GHSA-h3xv-8c7h-5fjq/GHSA-h3xv-8c7h-5fjq.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-h44c-m38r-j8w7/GHSA-h44c-m38r-j8w7.json b/advisories/unreviewed/2025/05/GHSA-h44c-m38r-j8w7/GHSA-h44c-m38r-j8w7.json new file mode 100644 index 00000000000..213217c57d0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h44c-m38r-j8w7/GHSA-h44c-m38r-j8w7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h44c-m38r-j8w7", + "modified": "2025-05-16T18:31:09Z", + "published": "2025-05-16T18:31:09Z", + "aliases": [ + "CVE-2025-48114" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Shayan Farhang Pazhooh ShayanWeb Admin FontChanger allows Stored XSS. This issue affects ShayanWeb Admin FontChanger: from n/a through 1.8.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48114" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/shayanweb-admin-fontchanger/vulnerability/wordpress-shayanweb-admin-fontchanger-plugin-1-8-1-cross-site-request-forgery-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h4wc-pvj9-rqm4/GHSA-h4wc-pvj9-rqm4.json b/advisories/unreviewed/2025/05/GHSA-h4wc-pvj9-rqm4/GHSA-h4wc-pvj9-rqm4.json new file mode 100644 index 00000000000..5cd5c03373a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h4wc-pvj9-rqm4/GHSA-h4wc-pvj9-rqm4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4wc-pvj9-rqm4", + "modified": "2025-05-16T18:31:07Z", + "published": "2025-05-16T18:31:07Z", + "aliases": [ + "CVE-2025-32245" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Apollo allows SQL Injection. This issue affects Apollo: from n/a through 3.6.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32245" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lbg-audio7_html5_full_width_sticky_pro/vulnerability/wordpress-apollo-3-6-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h63w-98j8-p38r/GHSA-h63w-98j8-p38r.json b/advisories/unreviewed/2025/05/GHSA-h63w-98j8-p38r/GHSA-h63w-98j8-p38r.json new file mode 100644 index 00000000000..bd635315a09 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h63w-98j8-p38r/GHSA-h63w-98j8-p38r.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h63w-98j8-p38r", + "modified": "2025-05-16T18:31:11Z", + "published": "2025-05-16T18:31:11Z", + "aliases": [ + "CVE-2025-4794" + ], + "details": "A vulnerability was found in PHPGurukul Online Course Registration 3.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /news.php. The manipulation of the argument newstitle leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4794" + }, + { + "type": "WEB", + "url": "https://github.com/FLYFISH567/CVE/issues/8" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309103" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309103" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.572508" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T18:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h8fr-pjww-7cvj/GHSA-h8fr-pjww-7cvj.json b/advisories/unreviewed/2025/05/GHSA-h8fr-pjww-7cvj/GHSA-h8fr-pjww-7cvj.json new file mode 100644 index 00000000000..c21ff353f66 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h8fr-pjww-7cvj/GHSA-h8fr-pjww-7cvj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8fr-pjww-7cvj", + "modified": "2025-05-16T18:31:08Z", + "published": "2025-05-16T18:31:08Z", + "aliases": [ + "CVE-2025-47560" + ], + "details": "Missing Authorization vulnerability in RomanCode MapSVG allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MapSVG: from n/a through 8.5.32.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47560" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mapsvg/vulnerability/wordpress-mapsvg-plugin-8-5-32-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hfqg-w7pg-59vf/GHSA-hfqg-w7pg-59vf.json b/advisories/unreviewed/2025/05/GHSA-hfqg-w7pg-59vf/GHSA-hfqg-w7pg-59vf.json index d11c959be94..254db1ea39f 100644 --- a/advisories/unreviewed/2025/05/GHSA-hfqg-w7pg-59vf/GHSA-hfqg-w7pg-59vf.json +++ b/advisories/unreviewed/2025/05/GHSA-hfqg-w7pg-59vf/GHSA-hfqg-w7pg-59vf.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-hjjf-c94m-282j/GHSA-hjjf-c94m-282j.json b/advisories/unreviewed/2025/05/GHSA-hjjf-c94m-282j/GHSA-hjjf-c94m-282j.json new file mode 100644 index 00000000000..7be9b48fbad --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hjjf-c94m-282j/GHSA-hjjf-c94m-282j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjjf-c94m-282j", + "modified": "2025-05-16T18:31:09Z", + "published": "2025-05-16T18:31:09Z", + "aliases": [ + "CVE-2025-48135" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aptivadadev Aptivada for WP allows DOM-Based XSS. This issue affects Aptivada for WP: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48135" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/aptivada-for-wp/vulnerability/wordpress-aptivada-for-wp-2-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hp82-hh22-6jg2/GHSA-hp82-hh22-6jg2.json b/advisories/unreviewed/2025/05/GHSA-hp82-hh22-6jg2/GHSA-hp82-hh22-6jg2.json new file mode 100644 index 00000000000..72c14dafcc1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hp82-hh22-6jg2/GHSA-hp82-hh22-6jg2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp82-hh22-6jg2", + "modified": "2025-05-16T18:31:08Z", + "published": "2025-05-16T18:31:08Z", + "aliases": [ + "CVE-2025-47534" + ], + "details": "Missing Authorization vulnerability in ValvePress Wordpress Auto Spinner allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Wordpress Auto Spinner: from n/a through 3.25.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47534" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-auto-spinner/vulnerability/wordpress-wordpress-auto-spinner-3-25-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hvcm-8rx2-h2mj/GHSA-hvcm-8rx2-h2mj.json b/advisories/unreviewed/2025/05/GHSA-hvcm-8rx2-h2mj/GHSA-hvcm-8rx2-h2mj.json new file mode 100644 index 00000000000..e68fe2ada1a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hvcm-8rx2-h2mj/GHSA-hvcm-8rx2-h2mj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvcm-8rx2-h2mj", + "modified": "2025-05-16T18:31:07Z", + "published": "2025-05-16T18:31:07Z", + "aliases": [ + "CVE-2025-32643" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPGYM allows Blind SQL Injection. This issue affects WPGYM: from n/a through 65.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32643" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gym-management/vulnerability/wordpress-wpgym-plugin-65-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hwh8-w9p9-ff96/GHSA-hwh8-w9p9-ff96.json b/advisories/unreviewed/2025/05/GHSA-hwh8-w9p9-ff96/GHSA-hwh8-w9p9-ff96.json new file mode 100644 index 00000000000..1c50ba478fb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hwh8-w9p9-ff96/GHSA-hwh8-w9p9-ff96.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwh8-w9p9-ff96", + "modified": "2025-05-16T18:31:06Z", + "published": "2025-05-16T18:31:06Z", + "aliases": [ + "CVE-2025-31923" + ], + "details": "Missing Authorization vulnerability in QuanticaLabs CSS3 Accordions for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CSS3 Accordions for WordPress: from n/a through 3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31923" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/css3_accordions/vulnerability/wordpress-css3-accordions-for-wordpress-3-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hwwj-8rjh-78m2/GHSA-hwwj-8rjh-78m2.json b/advisories/unreviewed/2025/05/GHSA-hwwj-8rjh-78m2/GHSA-hwwj-8rjh-78m2.json new file mode 100644 index 00000000000..202a23b6de9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hwwj-8rjh-78m2/GHSA-hwwj-8rjh-78m2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwwj-8rjh-78m2", + "modified": "2025-05-16T18:31:06Z", + "published": "2025-05-16T18:31:06Z", + "aliases": [ + "CVE-2025-31637" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup SHOUT allows SQL Injection. This issue affects SHOUT: from n/a through 3.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31637" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lbg-audio8-html5-radio_ads/vulnerability/wordpress-shout-3-5-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j3m2-jq2c-m776/GHSA-j3m2-jq2c-m776.json b/advisories/unreviewed/2025/05/GHSA-j3m2-jq2c-m776/GHSA-j3m2-jq2c-m776.json index 1c942e791f7..cfddde4ed1d 100644 --- a/advisories/unreviewed/2025/05/GHSA-j3m2-jq2c-m776/GHSA-j3m2-jq2c-m776.json +++ b/advisories/unreviewed/2025/05/GHSA-j3m2-jq2c-m776/GHSA-j3m2-jq2c-m776.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j3m2-jq2c-m776", - "modified": "2025-05-15T21:31:27Z", + "modified": "2025-05-16T18:31:05Z", "published": "2025-05-15T21:31:27Z", "aliases": [ "CVE-2023-7230" ], "details": "The illi Link Party! WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:30Z" diff --git a/advisories/unreviewed/2025/05/GHSA-j54f-33q2-h2fj/GHSA-j54f-33q2-h2fj.json b/advisories/unreviewed/2025/05/GHSA-j54f-33q2-h2fj/GHSA-j54f-33q2-h2fj.json index 877e0c52aa2..325ed89049c 100644 --- a/advisories/unreviewed/2025/05/GHSA-j54f-33q2-h2fj/GHSA-j54f-33q2-h2fj.json +++ b/advisories/unreviewed/2025/05/GHSA-j54f-33q2-h2fj/GHSA-j54f-33q2-h2fj.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-j869-cw6m-fwm6/GHSA-j869-cw6m-fwm6.json b/advisories/unreviewed/2025/05/GHSA-j869-cw6m-fwm6/GHSA-j869-cw6m-fwm6.json new file mode 100644 index 00000000000..9f176f9122a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j869-cw6m-fwm6/GHSA-j869-cw6m-fwm6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j869-cw6m-fwm6", + "modified": "2025-05-16T18:31:06Z", + "published": "2025-05-16T18:31:06Z", + "aliases": [ + "CVE-2025-31066" + ], + "details": "Missing Authorization vulnerability in themeton Acerola allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Acerola: from n/a through 1.6.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31066" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/acerola/vulnerability/wordpress-acerola-1-6-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j8r3-cghj-9jhg/GHSA-j8r3-cghj-9jhg.json b/advisories/unreviewed/2025/05/GHSA-j8r3-cghj-9jhg/GHSA-j8r3-cghj-9jhg.json index c6c679a5ced..041e7586aec 100644 --- a/advisories/unreviewed/2025/05/GHSA-j8r3-cghj-9jhg/GHSA-j8r3-cghj-9jhg.json +++ b/advisories/unreviewed/2025/05/GHSA-j8r3-cghj-9jhg/GHSA-j8r3-cghj-9jhg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j8r3-cghj-9jhg", - "modified": "2025-05-15T15:31:27Z", + "modified": "2025-05-16T18:31:05Z", "published": "2025-05-15T15:31:27Z", "aliases": [ "CVE-2025-4516" @@ -38,6 +38,10 @@ { "type": "WEB", "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/L75IPBBTSCYEF56I2M4KIW353BB3AY74" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/16/4" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-jc84-wwc9-v77w/GHSA-jc84-wwc9-v77w.json b/advisories/unreviewed/2025/05/GHSA-jc84-wwc9-v77w/GHSA-jc84-wwc9-v77w.json new file mode 100644 index 00000000000..59ea12c93a4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jc84-wwc9-v77w/GHSA-jc84-wwc9-v77w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc84-wwc9-v77w", + "modified": "2025-05-16T18:31:08Z", + "published": "2025-05-16T18:31:08Z", + "aliases": [ + "CVE-2025-47557" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RomanCode MapSVG allows Stored XSS. This issue affects MapSVG: from n/a through 8.5.31.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47557" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mapsvg/vulnerability/wordpress-mapsvg-plugin-8-5-31-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jc87-r4xp-8252/GHSA-jc87-r4xp-8252.json b/advisories/unreviewed/2025/05/GHSA-jc87-r4xp-8252/GHSA-jc87-r4xp-8252.json index dc181644f80..537441dccca 100644 --- a/advisories/unreviewed/2025/05/GHSA-jc87-r4xp-8252/GHSA-jc87-r4xp-8252.json +++ b/advisories/unreviewed/2025/05/GHSA-jc87-r4xp-8252/GHSA-jc87-r4xp-8252.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-jj3q-f75g-58c4/GHSA-jj3q-f75g-58c4.json b/advisories/unreviewed/2025/05/GHSA-jj3q-f75g-58c4/GHSA-jj3q-f75g-58c4.json new file mode 100644 index 00000000000..9a4247f2480 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jj3q-f75g-58c4/GHSA-jj3q-f75g-58c4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jj3q-f75g-58c4", + "modified": "2025-05-16T18:31:09Z", + "published": "2025-05-16T18:31:09Z", + "aliases": [ + "CVE-2025-48112" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in karimmughal Dot html,php,xml etc pages allows Reflected XSS. This issue affects Dot html,php,xml etc pages: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48112" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dot-htmlphpxml-etc-pages/vulnerability/wordpress-dot-html-php-xml-etc-pages-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jqxw-7j2j-95x7/GHSA-jqxw-7j2j-95x7.json b/advisories/unreviewed/2025/05/GHSA-jqxw-7j2j-95x7/GHSA-jqxw-7j2j-95x7.json index 87d61288b84..403f33501e0 100644 --- a/advisories/unreviewed/2025/05/GHSA-jqxw-7j2j-95x7/GHSA-jqxw-7j2j-95x7.json +++ b/advisories/unreviewed/2025/05/GHSA-jqxw-7j2j-95x7/GHSA-jqxw-7j2j-95x7.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-m389-w49c-wmf6/GHSA-m389-w49c-wmf6.json b/advisories/unreviewed/2025/05/GHSA-m389-w49c-wmf6/GHSA-m389-w49c-wmf6.json new file mode 100644 index 00000000000..97606a2c87f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m389-w49c-wmf6/GHSA-m389-w49c-wmf6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m389-w49c-wmf6", + "modified": "2025-05-16T18:31:09Z", + "published": "2025-05-16T18:31:09Z", + "aliases": [ + "CVE-2025-48080" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash allows Stored XSS. This issue affects Uncanny Toolkit for LearnDash: from n/a through 3.7.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48080" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/uncanny-learndash-toolkit/vulnerability/wordpress-uncanny-toolkit-for-learndash-3-7-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m88h-r836-p5fc/GHSA-m88h-r836-p5fc.json b/advisories/unreviewed/2025/05/GHSA-m88h-r836-p5fc/GHSA-m88h-r836-p5fc.json new file mode 100644 index 00000000000..d122aade677 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m88h-r836-p5fc/GHSA-m88h-r836-p5fc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m88h-r836-p5fc", + "modified": "2025-05-16T18:31:07Z", + "published": "2025-05-16T18:31:07Z", + "aliases": [ + "CVE-2025-32290" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Sticky HTML5 Music Player allows SQL Injection. This issue affects Sticky HTML5 Music Player: from n/a through 3.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32290" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lbg-audio3-html5/vulnerability/wordpress-sticky-html5-music-player-3-1-6-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mjmj-jr4w-6rm4/GHSA-mjmj-jr4w-6rm4.json b/advisories/unreviewed/2025/05/GHSA-mjmj-jr4w-6rm4/GHSA-mjmj-jr4w-6rm4.json new file mode 100644 index 00000000000..182ac30bebc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mjmj-jr4w-6rm4/GHSA-mjmj-jr4w-6rm4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjmj-jr4w-6rm4", + "modified": "2025-05-16T18:31:07Z", + "published": "2025-05-16T18:31:07Z", + "aliases": [ + "CVE-2025-32307" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Chameleon HTML5 Audio Player With/Without Playlist allows SQL Injection. This issue affects Chameleon HTML5 Audio Player With/Without Playlist: from n/a through 3.5.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32307" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lbg-audio1-html5/vulnerability/wordpress-chameleon-html5-audio-player-with-without-playlist-3-5-6-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mp7h-693f-hwvj/GHSA-mp7h-693f-hwvj.json b/advisories/unreviewed/2025/05/GHSA-mp7h-693f-hwvj/GHSA-mp7h-693f-hwvj.json index bae26815f5b..bf3310f2a68 100644 --- a/advisories/unreviewed/2025/05/GHSA-mp7h-693f-hwvj/GHSA-mp7h-693f-hwvj.json +++ b/advisories/unreviewed/2025/05/GHSA-mp7h-693f-hwvj/GHSA-mp7h-693f-hwvj.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-mpq9-qw6g-7f69/GHSA-mpq9-qw6g-7f69.json b/advisories/unreviewed/2025/05/GHSA-mpq9-qw6g-7f69/GHSA-mpq9-qw6g-7f69.json new file mode 100644 index 00000000000..8d275f408c4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mpq9-qw6g-7f69/GHSA-mpq9-qw6g-7f69.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpq9-qw6g-7f69", + "modified": "2025-05-16T18:31:08Z", + "published": "2025-05-16T18:31:08Z", + "aliases": [ + "CVE-2025-47693" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in roninwp FAT Services Booking allows PHP Local File Inclusion. This issue affects FAT Services Booking: from n/a through 5.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47693" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fat-services-booking/vulnerability/wordpress-fat-services-booking-plugin-5-5-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mvfc-pmj6-8j77/GHSA-mvfc-pmj6-8j77.json b/advisories/unreviewed/2025/05/GHSA-mvfc-pmj6-8j77/GHSA-mvfc-pmj6-8j77.json new file mode 100644 index 00000000000..afcfc48ceb4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mvfc-pmj6-8j77/GHSA-mvfc-pmj6-8j77.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvfc-pmj6-8j77", + "modified": "2025-05-16T18:31:10Z", + "published": "2025-05-16T18:31:10Z", + "aliases": [ + "CVE-2025-4791" + ], + "details": "A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. This vulnerability affects unknown code of the component HASH Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4791" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-bc230ff2f41a996bdab8ab4072a38e2e99aa486f2d7f50f8f9e983adb7dc4536.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309100" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309100" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.572480" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T17:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mwh9-fj7v-cfgq/GHSA-mwh9-fj7v-cfgq.json b/advisories/unreviewed/2025/05/GHSA-mwh9-fj7v-cfgq/GHSA-mwh9-fj7v-cfgq.json new file mode 100644 index 00000000000..387f9b205b6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mwh9-fj7v-cfgq/GHSA-mwh9-fj7v-cfgq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwh9-fj7v-cfgq", + "modified": "2025-05-16T18:31:09Z", + "published": "2025-05-16T18:31:09Z", + "aliases": [ + "CVE-2025-48134" + ], + "details": "Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC WP Tabs allows Object Injection. This issue affects WP Tabs: from n/a through 2.2.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48134" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-expand-tabs-free/vulnerability/wordpress-wp-tabs-2-2-11-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p2gx-629f-525f/GHSA-p2gx-629f-525f.json b/advisories/unreviewed/2025/05/GHSA-p2gx-629f-525f/GHSA-p2gx-629f-525f.json index b68e0617006..acd67d58e6b 100644 --- a/advisories/unreviewed/2025/05/GHSA-p2gx-629f-525f/GHSA-p2gx-629f-525f.json +++ b/advisories/unreviewed/2025/05/GHSA-p2gx-629f-525f/GHSA-p2gx-629f-525f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p2gx-629f-525f", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-16T18:31:05Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-3901" ], "details": "The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed to write posts (like those with the contributor role) to conduct Stored XSS attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:53Z" diff --git a/advisories/unreviewed/2025/05/GHSA-p474-6pr8-pwcj/GHSA-p474-6pr8-pwcj.json b/advisories/unreviewed/2025/05/GHSA-p474-6pr8-pwcj/GHSA-p474-6pr8-pwcj.json index 1acb51f5a10..628a57162d5 100644 --- a/advisories/unreviewed/2025/05/GHSA-p474-6pr8-pwcj/GHSA-p474-6pr8-pwcj.json +++ b/advisories/unreviewed/2025/05/GHSA-p474-6pr8-pwcj/GHSA-p474-6pr8-pwcj.json @@ -50,7 +50,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-p83p-mwrh-7pp6/GHSA-p83p-mwrh-7pp6.json b/advisories/unreviewed/2025/05/GHSA-p83p-mwrh-7pp6/GHSA-p83p-mwrh-7pp6.json index 80401ca8f2c..d8cf0df2db9 100644 --- a/advisories/unreviewed/2025/05/GHSA-p83p-mwrh-7pp6/GHSA-p83p-mwrh-7pp6.json +++ b/advisories/unreviewed/2025/05/GHSA-p83p-mwrh-7pp6/GHSA-p83p-mwrh-7pp6.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-pf9g-5cwx-37fm/GHSA-pf9g-5cwx-37fm.json b/advisories/unreviewed/2025/05/GHSA-pf9g-5cwx-37fm/GHSA-pf9g-5cwx-37fm.json index 3275ad67bcc..888cf08dd3e 100644 --- a/advisories/unreviewed/2025/05/GHSA-pf9g-5cwx-37fm/GHSA-pf9g-5cwx-37fm.json +++ b/advisories/unreviewed/2025/05/GHSA-pf9g-5cwx-37fm/GHSA-pf9g-5cwx-37fm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pf9g-5cwx-37fm", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-16T18:31:06Z", "published": "2025-05-15T21:31:31Z", "aliases": [ "CVE-2024-4091" ], "details": "The Responsive Gallery Grid WordPress plugin before 2.3.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:54Z" diff --git a/advisories/unreviewed/2025/05/GHSA-pgf2-cx64-92mc/GHSA-pgf2-cx64-92mc.json b/advisories/unreviewed/2025/05/GHSA-pgf2-cx64-92mc/GHSA-pgf2-cx64-92mc.json new file mode 100644 index 00000000000..55a7c442fec --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pgf2-cx64-92mc/GHSA-pgf2-cx64-92mc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgf2-cx64-92mc", + "modified": "2025-05-16T18:31:09Z", + "published": "2025-05-16T18:31:09Z", + "aliases": [ + "CVE-2025-48121" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Steve Puddick WP Notes Widget allows DOM-Based XSS. This issue affects WP Notes Widget: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48121" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-notes-widget/vulnerability/wordpress-wp-notes-widget-1-0-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-phr9-hmp9-rhqp/GHSA-phr9-hmp9-rhqp.json b/advisories/unreviewed/2025/05/GHSA-phr9-hmp9-rhqp/GHSA-phr9-hmp9-rhqp.json new file mode 100644 index 00000000000..b3d6a62e1ef --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-phr9-hmp9-rhqp/GHSA-phr9-hmp9-rhqp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phr9-hmp9-rhqp", + "modified": "2025-05-16T18:31:06Z", + "published": "2025-05-16T18:31:06Z", + "aliases": [ + "CVE-2025-31068" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in themeton Seven Stars allows Cross Site Request Forgery. This issue affects Seven Stars: from n/a through 1.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31068" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/sevenstars/vulnerability/wordpress-seven-stars-1-4-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pq8q-9hj8-gjmr/GHSA-pq8q-9hj8-gjmr.json b/advisories/unreviewed/2025/05/GHSA-pq8q-9hj8-gjmr/GHSA-pq8q-9hj8-gjmr.json index 52f607a1427..79011d13230 100644 --- a/advisories/unreviewed/2025/05/GHSA-pq8q-9hj8-gjmr/GHSA-pq8q-9hj8-gjmr.json +++ b/advisories/unreviewed/2025/05/GHSA-pq8q-9hj8-gjmr/GHSA-pq8q-9hj8-gjmr.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-q8gw-4vx7-3593/GHSA-q8gw-4vx7-3593.json b/advisories/unreviewed/2025/05/GHSA-q8gw-4vx7-3593/GHSA-q8gw-4vx7-3593.json new file mode 100644 index 00000000000..79e5cd1946c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q8gw-4vx7-3593/GHSA-q8gw-4vx7-3593.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8gw-4vx7-3593", + "modified": "2025-05-16T18:31:10Z", + "published": "2025-05-16T18:31:10Z", + "aliases": [ + "CVE-2025-4792" + ], + "details": "A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. This issue affects some unknown processing of the component MDELETE Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4792" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-fb7e880a8c21bdec1f4d3953a2c57bcc582b95ffc83513c7d709f45c15d60504.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309101" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309101" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.572481" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T18:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q97m-8853-pq76/GHSA-q97m-8853-pq76.json b/advisories/unreviewed/2025/05/GHSA-q97m-8853-pq76/GHSA-q97m-8853-pq76.json index a0b0faf14a5..75dbeca0ec1 100644 --- a/advisories/unreviewed/2025/05/GHSA-q97m-8853-pq76/GHSA-q97m-8853-pq76.json +++ b/advisories/unreviewed/2025/05/GHSA-q97m-8853-pq76/GHSA-q97m-8853-pq76.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q97m-8853-pq76", - "modified": "2025-05-16T15:31:02Z", + "modified": "2025-05-16T18:31:06Z", "published": "2025-05-16T15:31:02Z", "aliases": [ "CVE-2024-40120" ], "details": "seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_store.go.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-16T13:15:51Z" diff --git a/advisories/unreviewed/2025/05/GHSA-q9j8-hx2p-36g7/GHSA-q9j8-hx2p-36g7.json b/advisories/unreviewed/2025/05/GHSA-q9j8-hx2p-36g7/GHSA-q9j8-hx2p-36g7.json new file mode 100644 index 00000000000..ed8aa692e85 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q9j8-hx2p-36g7/GHSA-q9j8-hx2p-36g7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9j8-hx2p-36g7", + "modified": "2025-05-16T18:31:09Z", + "published": "2025-05-16T18:31:09Z", + "aliases": [ + "CVE-2025-48117" + ], + "details": "Missing Authorization vulnerability in kilbot WooCommerce POS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WooCommerce POS: from n/a through 1.7.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48117" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-pos/vulnerability/wordpress-woocommerce-pos-1-7-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q9q6-5878-p2qv/GHSA-q9q6-5878-p2qv.json b/advisories/unreviewed/2025/05/GHSA-q9q6-5878-p2qv/GHSA-q9q6-5878-p2qv.json new file mode 100644 index 00000000000..393a5d29641 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q9q6-5878-p2qv/GHSA-q9q6-5878-p2qv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9q6-5878-p2qv", + "modified": "2025-05-16T18:31:08Z", + "published": "2025-05-16T18:31:08Z", + "aliases": [ + "CVE-2025-48079" + ], + "details": "Missing Authorization vulnerability in Metagauss ProfileGrid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ProfileGrid : from n/a through 5.9.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48079" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/profilegrid-user-profiles-groups-and-communities/vulnerability/wordpress-profilegrid-5-9-5-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qgq4-89p9-qfrh/GHSA-qgq4-89p9-qfrh.json b/advisories/unreviewed/2025/05/GHSA-qgq4-89p9-qfrh/GHSA-qgq4-89p9-qfrh.json new file mode 100644 index 00000000000..a274b289add --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qgq4-89p9-qfrh/GHSA-qgq4-89p9-qfrh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgq4-89p9-qfrh", + "modified": "2025-05-16T18:31:10Z", + "published": "2025-05-16T18:31:10Z", + "aliases": [ + "CVE-2025-4476" + ], + "details": "A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted domain parameter within the WWW-Authenticate header. Processing this malformed header can lead to a crash of the client application using libsoup. An attacker could exploit this by setting up a malicious HTTP server. If a user's application using the vulnerable libsoup library connects to this malicious server, it could result in a denial-of-service. Successful exploitation requires tricking a user's client application into connecting to the attacker's malicious server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4476" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-4476" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2366513" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T18:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qgq6-gvqh-g8w9/GHSA-qgq6-gvqh-g8w9.json b/advisories/unreviewed/2025/05/GHSA-qgq6-gvqh-g8w9/GHSA-qgq6-gvqh-g8w9.json new file mode 100644 index 00000000000..5bbd0bc2cd2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qgq6-gvqh-g8w9/GHSA-qgq6-gvqh-g8w9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgq6-gvqh-g8w9", + "modified": "2025-05-16T18:31:07Z", + "published": "2025-05-16T18:31:07Z", + "aliases": [ + "CVE-2025-31928" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Multimedia Responsive Carousel with Image Video Audio Support allows SQL Injection. This issue affects Multimedia Responsive Carousel with Image Video Audio Support: from n/a through 2.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31928" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/multimedia-carousel/vulnerability/wordpress-multimedia-responsive-carousel-with-image-video-audio-support-2-6-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qpvp-c873-3p8q/GHSA-qpvp-c873-3p8q.json b/advisories/unreviewed/2025/05/GHSA-qpvp-c873-3p8q/GHSA-qpvp-c873-3p8q.json new file mode 100644 index 00000000000..20ecf3e571e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qpvp-c873-3p8q/GHSA-qpvp-c873-3p8q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpvp-c873-3p8q", + "modified": "2025-05-16T18:31:09Z", + "published": "2025-05-16T18:31:09Z", + "aliases": [ + "CVE-2025-48128" + ], + "details": "Missing Authorization vulnerability in Sharespine Sharespine Woocommerce Connector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sharespine Woocommerce Connector: from n/a through 4.7.55.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48128" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sharespine-woocommerce-connector/vulnerability/wordpress-sharespine-woocommerce-connector-4-7-55-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qqv4-m5cq-pp99/GHSA-qqv4-m5cq-pp99.json b/advisories/unreviewed/2025/05/GHSA-qqv4-m5cq-pp99/GHSA-qqv4-m5cq-pp99.json index 2b81ef54e1e..97ac1ce14a0 100644 --- a/advisories/unreviewed/2025/05/GHSA-qqv4-m5cq-pp99/GHSA-qqv4-m5cq-pp99.json +++ b/advisories/unreviewed/2025/05/GHSA-qqv4-m5cq-pp99/GHSA-qqv4-m5cq-pp99.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qqv4-m5cq-pp99", - "modified": "2025-05-16T06:30:24Z", + "modified": "2025-05-16T18:31:06Z", "published": "2025-05-16T06:30:24Z", "aliases": [ "CVE-2025-3201" ], "details": "The Contact Form builder with drag & drop for WordPress WordPress plugin before 2.4.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-16T06:15:46Z" diff --git a/advisories/unreviewed/2025/05/GHSA-qx2c-cjfg-57c3/GHSA-qx2c-cjfg-57c3.json b/advisories/unreviewed/2025/05/GHSA-qx2c-cjfg-57c3/GHSA-qx2c-cjfg-57c3.json index 07b017338f1..0f7293fb26a 100644 --- a/advisories/unreviewed/2025/05/GHSA-qx2c-cjfg-57c3/GHSA-qx2c-cjfg-57c3.json +++ b/advisories/unreviewed/2025/05/GHSA-qx2c-cjfg-57c3/GHSA-qx2c-cjfg-57c3.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-r66x-pvwm-7pf5/GHSA-r66x-pvwm-7pf5.json b/advisories/unreviewed/2025/05/GHSA-r66x-pvwm-7pf5/GHSA-r66x-pvwm-7pf5.json new file mode 100644 index 00000000000..b999aa4a510 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r66x-pvwm-7pf5/GHSA-r66x-pvwm-7pf5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r66x-pvwm-7pf5", + "modified": "2025-05-16T18:31:08Z", + "published": "2025-05-16T18:31:08Z", + "aliases": [ + "CVE-2025-39537" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in Chimpstudio WP JobHunt allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP JobHunt: from n/a through 7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39537" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-jobhunt/vulnerability/wordpress-wp-jobhunt-7-1-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r9hp-mj25-9rxr/GHSA-r9hp-mj25-9rxr.json b/advisories/unreviewed/2025/05/GHSA-r9hp-mj25-9rxr/GHSA-r9hp-mj25-9rxr.json index 4d62c136fbe..818a19113fb 100644 --- a/advisories/unreviewed/2025/05/GHSA-r9hp-mj25-9rxr/GHSA-r9hp-mj25-9rxr.json +++ b/advisories/unreviewed/2025/05/GHSA-r9hp-mj25-9rxr/GHSA-r9hp-mj25-9rxr.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-rcqp-hx94-8h2w/GHSA-rcqp-hx94-8h2w.json b/advisories/unreviewed/2025/05/GHSA-rcqp-hx94-8h2w/GHSA-rcqp-hx94-8h2w.json new file mode 100644 index 00000000000..b4097d5c688 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rcqp-hx94-8h2w/GHSA-rcqp-hx94-8h2w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcqp-hx94-8h2w", + "modified": "2025-05-16T18:31:09Z", + "published": "2025-05-16T18:31:09Z", + "aliases": [ + "CVE-2025-48116" + ], + "details": "Missing Authorization vulnerability in Ashan Perera EventON allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects EventON: from n/a through 2.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48116" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/eventon-lite/vulnerability/wordpress-eventon-2-4-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rfh7-48pv-qj88/GHSA-rfh7-48pv-qj88.json b/advisories/unreviewed/2025/05/GHSA-rfh7-48pv-qj88/GHSA-rfh7-48pv-qj88.json new file mode 100644 index 00000000000..d51a2d8441c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rfh7-48pv-qj88/GHSA-rfh7-48pv-qj88.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfh7-48pv-qj88", + "modified": "2025-05-16T18:31:07Z", + "published": "2025-05-16T18:31:07Z", + "aliases": [ + "CVE-2025-32295" + ], + "details": "Missing Authorization vulnerability in wordpresschef Salon Booking Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Salon Booking Pro: from n/a through 10.10.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32295" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/salon-booking-plugin-pro-cc/vulnerability/wordpress-salon-booking-wordpress-plugin-10-10-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rhc7-gggc-mcgq/GHSA-rhc7-gggc-mcgq.json b/advisories/unreviewed/2025/05/GHSA-rhc7-gggc-mcgq/GHSA-rhc7-gggc-mcgq.json new file mode 100644 index 00000000000..4e0711ee84f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rhc7-gggc-mcgq/GHSA-rhc7-gggc-mcgq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhc7-gggc-mcgq", + "modified": "2025-05-16T18:31:09Z", + "published": "2025-05-16T18:31:09Z", + "aliases": [ + "CVE-2025-48113" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Broadstreet Broadstreet allows Stored XSS. This issue affects Broadstreet: from n/a through 1.51.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48113" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/broadstreet/vulnerability/wordpress-broadstreet-1-51-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rhpf-gwq4-5q7j/GHSA-rhpf-gwq4-5q7j.json b/advisories/unreviewed/2025/05/GHSA-rhpf-gwq4-5q7j/GHSA-rhpf-gwq4-5q7j.json new file mode 100644 index 00000000000..4456953749c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rhpf-gwq4-5q7j/GHSA-rhpf-gwq4-5q7j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhpf-gwq4-5q7j", + "modified": "2025-05-16T18:31:06Z", + "published": "2025-05-16T18:31:06Z", + "aliases": [ + "CVE-2025-31063" + ], + "details": "Missing Authorization vulnerability in redqteam Wishlist allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Wishlist: from n/a through 2.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31063" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wishlist/vulnerability/wordpress-wishlist-2-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rjhr-6wxv-pvg4/GHSA-rjhr-6wxv-pvg4.json b/advisories/unreviewed/2025/05/GHSA-rjhr-6wxv-pvg4/GHSA-rjhr-6wxv-pvg4.json new file mode 100644 index 00000000000..6a7198dfcea --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rjhr-6wxv-pvg4/GHSA-rjhr-6wxv-pvg4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjhr-6wxv-pvg4", + "modified": "2025-05-16T18:31:09Z", + "published": "2025-05-16T18:31:09Z", + "aliases": [ + "CVE-2025-48115" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Javier Revilla ValidateCertify allows Cross Site Request Forgery. This issue affects ValidateCertify: from n/a through 1.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48115" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/validar-certificados-de-cursos/vulnerability/wordpress-validatecertify-1-6-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rvmj-3rpq-mg5g/GHSA-rvmj-3rpq-mg5g.json b/advisories/unreviewed/2025/05/GHSA-rvmj-3rpq-mg5g/GHSA-rvmj-3rpq-mg5g.json index 6be714b4cdd..896492b094f 100644 --- a/advisories/unreviewed/2025/05/GHSA-rvmj-3rpq-mg5g/GHSA-rvmj-3rpq-mg5g.json +++ b/advisories/unreviewed/2025/05/GHSA-rvmj-3rpq-mg5g/GHSA-rvmj-3rpq-mg5g.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-v45r-44c3-w45r/GHSA-v45r-44c3-w45r.json b/advisories/unreviewed/2025/05/GHSA-v45r-44c3-w45r/GHSA-v45r-44c3-w45r.json index 9c0641bfdec..5387720b8c0 100644 --- a/advisories/unreviewed/2025/05/GHSA-v45r-44c3-w45r/GHSA-v45r-44c3-w45r.json +++ b/advisories/unreviewed/2025/05/GHSA-v45r-44c3-w45r/GHSA-v45r-44c3-w45r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v45r-44c3-w45r", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-16T18:31:06Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-8009" ], "details": "The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:57Z" diff --git a/advisories/unreviewed/2025/05/GHSA-v8c3-r2xf-ghv6/GHSA-v8c3-r2xf-ghv6.json b/advisories/unreviewed/2025/05/GHSA-v8c3-r2xf-ghv6/GHSA-v8c3-r2xf-ghv6.json index 5437ecfc899..0934b747fa9 100644 --- a/advisories/unreviewed/2025/05/GHSA-v8c3-r2xf-ghv6/GHSA-v8c3-r2xf-ghv6.json +++ b/advisories/unreviewed/2025/05/GHSA-v8c3-r2xf-ghv6/GHSA-v8c3-r2xf-ghv6.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-427" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-v8j5-hjg7-w5w5/GHSA-v8j5-hjg7-w5w5.json b/advisories/unreviewed/2025/05/GHSA-v8j5-hjg7-w5w5/GHSA-v8j5-hjg7-w5w5.json index 6ae035a45b0..6027d4ee4d3 100644 --- a/advisories/unreviewed/2025/05/GHSA-v8j5-hjg7-w5w5/GHSA-v8j5-hjg7-w5w5.json +++ b/advisories/unreviewed/2025/05/GHSA-v8j5-hjg7-w5w5/GHSA-v8j5-hjg7-w5w5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v8j5-hjg7-w5w5", - "modified": "2025-05-15T21:31:27Z", + "modified": "2025-05-16T18:31:05Z", "published": "2025-05-15T21:31:27Z", "aliases": [ "CVE-2024-0970" ], "details": "This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:32Z" diff --git a/advisories/unreviewed/2025/05/GHSA-vg3c-chr5-76wm/GHSA-vg3c-chr5-76wm.json b/advisories/unreviewed/2025/05/GHSA-vg3c-chr5-76wm/GHSA-vg3c-chr5-76wm.json new file mode 100644 index 00000000000..be69f9e32fe --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vg3c-chr5-76wm/GHSA-vg3c-chr5-76wm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg3c-chr5-76wm", + "modified": "2025-05-16T18:31:06Z", + "published": "2025-05-16T18:31:06Z", + "aliases": [ + "CVE-2025-31921" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Ultimate Tours Builder allows Cross Site Request Forgery. This issue affects WP Ultimate Tours Builder: from n/a through 1.055.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31921" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp_ultimatetoursbuilder/vulnerability/wordpress-wp-ultimate-tours-builder-1-055-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vp89-77x6-5qqm/GHSA-vp89-77x6-5qqm.json b/advisories/unreviewed/2025/05/GHSA-vp89-77x6-5qqm/GHSA-vp89-77x6-5qqm.json index 42d20097c11..129d341ae48 100644 --- a/advisories/unreviewed/2025/05/GHSA-vp89-77x6-5qqm/GHSA-vp89-77x6-5qqm.json +++ b/advisories/unreviewed/2025/05/GHSA-vp89-77x6-5qqm/GHSA-vp89-77x6-5qqm.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-vw88-v4w8-cwv4/GHSA-vw88-v4w8-cwv4.json b/advisories/unreviewed/2025/05/GHSA-vw88-v4w8-cwv4/GHSA-vw88-v4w8-cwv4.json new file mode 100644 index 00000000000..9e52ad8a525 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vw88-v4w8-cwv4/GHSA-vw88-v4w8-cwv4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw88-v4w8-cwv4", + "modified": "2025-05-16T18:31:09Z", + "published": "2025-05-16T18:31:09Z", + "aliases": [ + "CVE-2025-48136" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Estatik Mortgage Calculator Estatik allows PHP Local File Inclusion. This issue affects Mortgage Calculator Estatik: from n/a through 2.0.12.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48136" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/estatik-mortgage-calculator/vulnerability/wordpress-mortgage-calculator-estatik-2-0-12-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w7v2-r8f5-7h23/GHSA-w7v2-r8f5-7h23.json b/advisories/unreviewed/2025/05/GHSA-w7v2-r8f5-7h23/GHSA-w7v2-r8f5-7h23.json index 20fa3f16bbd..033311259e8 100644 --- a/advisories/unreviewed/2025/05/GHSA-w7v2-r8f5-7h23/GHSA-w7v2-r8f5-7h23.json +++ b/advisories/unreviewed/2025/05/GHSA-w7v2-r8f5-7h23/GHSA-w7v2-r8f5-7h23.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-wfj8-m9jg-h945/GHSA-wfj8-m9jg-h945.json b/advisories/unreviewed/2025/05/GHSA-wfj8-m9jg-h945/GHSA-wfj8-m9jg-h945.json new file mode 100644 index 00000000000..b4bb15d9125 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wfj8-m9jg-h945/GHSA-wfj8-m9jg-h945.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfj8-m9jg-h945", + "modified": "2025-05-16T18:31:08Z", + "published": "2025-05-16T18:31:07Z", + "aliases": [ + "CVE-2025-39507" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Nasa Core allows PHP Local File Inclusion. This issue affects Nasa Core: from n/a through 6.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39507" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nasa-core/vulnerability/wordpress-nasa-core-plugin-6-3-2-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wg2m-xw57-fqc9/GHSA-wg2m-xw57-fqc9.json b/advisories/unreviewed/2025/05/GHSA-wg2m-xw57-fqc9/GHSA-wg2m-xw57-fqc9.json new file mode 100644 index 00000000000..618be0c0a44 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wg2m-xw57-fqc9/GHSA-wg2m-xw57-fqc9.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg2m-xw57-fqc9", + "modified": "2025-05-16T18:31:10Z", + "published": "2025-05-16T18:31:10Z", + "aliases": [ + "CVE-2025-4790" + ], + "details": "A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part of the component GLOB Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4790" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-3b4e822c5e445f2fe48f704745994fc63a9300dacddaaeb5290b1149dd2d7704.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309099" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309099" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.572479" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wmr9-84fj-r9j8/GHSA-wmr9-84fj-r9j8.json b/advisories/unreviewed/2025/05/GHSA-wmr9-84fj-r9j8/GHSA-wmr9-84fj-r9j8.json index 10f6398abb1..0e9fe163701 100644 --- a/advisories/unreviewed/2025/05/GHSA-wmr9-84fj-r9j8/GHSA-wmr9-84fj-r9j8.json +++ b/advisories/unreviewed/2025/05/GHSA-wmr9-84fj-r9j8/GHSA-wmr9-84fj-r9j8.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-wqrq-vwwp-qpvv/GHSA-wqrq-vwwp-qpvv.json b/advisories/unreviewed/2025/05/GHSA-wqrq-vwwp-qpvv/GHSA-wqrq-vwwp-qpvv.json new file mode 100644 index 00000000000..7c5f1a97b50 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wqrq-vwwp-qpvv/GHSA-wqrq-vwwp-qpvv.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqrq-vwwp-qpvv", + "modified": "2025-05-16T18:31:10Z", + "published": "2025-05-16T18:31:10Z", + "aliases": [ + "CVE-2025-4789" + ], + "details": "A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. Affected by this issue is some unknown functionality of the component LCD Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4789" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-23d12ba21a827aadd1af628488c8d5308103beb3a2038981aa59a1a6ee3fc7dd.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309098" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309098" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.572478" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T17:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wvh4-qfmr-fv6q/GHSA-wvh4-qfmr-fv6q.json b/advisories/unreviewed/2025/05/GHSA-wvh4-qfmr-fv6q/GHSA-wvh4-qfmr-fv6q.json new file mode 100644 index 00000000000..e72c919e5ed --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wvh4-qfmr-fv6q/GHSA-wvh4-qfmr-fv6q.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvh4-qfmr-fv6q", + "modified": "2025-05-16T18:31:11Z", + "published": "2025-05-16T18:31:11Z", + "aliases": [ + "CVE-2025-4793" + ], + "details": "A vulnerability was found in PHPGurukul Online Course Registration 3.1. It has been classified as critical. Affected is an unknown function of the file /edit-student-profile.php. The manipulation of the argument cgpa leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4793" + }, + { + "type": "WEB", + "url": "https://github.com/FLYFISH567/CVE/issues/7" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309102" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309102" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.572507" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T18:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wwhv-9m6v-jg97/GHSA-wwhv-9m6v-jg97.json b/advisories/unreviewed/2025/05/GHSA-wwhv-9m6v-jg97/GHSA-wwhv-9m6v-jg97.json index d1fa0e51074..bd22a7e7c8c 100644 --- a/advisories/unreviewed/2025/05/GHSA-wwhv-9m6v-jg97/GHSA-wwhv-9m6v-jg97.json +++ b/advisories/unreviewed/2025/05/GHSA-wwhv-9m6v-jg97/GHSA-wwhv-9m6v-jg97.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-x4jw-p584-84v2/GHSA-x4jw-p584-84v2.json b/advisories/unreviewed/2025/05/GHSA-x4jw-p584-84v2/GHSA-x4jw-p584-84v2.json index 129975492ec..bd18ee170a8 100644 --- a/advisories/unreviewed/2025/05/GHSA-x4jw-p584-84v2/GHSA-x4jw-p584-84v2.json +++ b/advisories/unreviewed/2025/05/GHSA-x4jw-p584-84v2/GHSA-x4jw-p584-84v2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x4jw-p584-84v2", - "modified": "2025-05-16T06:30:25Z", + "modified": "2025-05-16T18:31:06Z", "published": "2025-05-16T06:30:25Z", "aliases": [ "CVE-2025-3516" ], "details": "The Simple Lightbox WordPress plugin before 2.9.4 does not validate and escape some of its attributes before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-16T06:15:46Z" diff --git a/advisories/unreviewed/2025/05/GHSA-xfhf-5q2m-cx8p/GHSA-xfhf-5q2m-cx8p.json b/advisories/unreviewed/2025/05/GHSA-xfhf-5q2m-cx8p/GHSA-xfhf-5q2m-cx8p.json index c36922853ac..6fbb353c10f 100644 --- a/advisories/unreviewed/2025/05/GHSA-xfhf-5q2m-cx8p/GHSA-xfhf-5q2m-cx8p.json +++ b/advisories/unreviewed/2025/05/GHSA-xfhf-5q2m-cx8p/GHSA-xfhf-5q2m-cx8p.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-xgfh-h2p4-f7v7/GHSA-xgfh-h2p4-f7v7.json b/advisories/unreviewed/2025/05/GHSA-xgfh-h2p4-f7v7/GHSA-xgfh-h2p4-f7v7.json index 913e0f4b284..25125805da0 100644 --- a/advisories/unreviewed/2025/05/GHSA-xgfh-h2p4-f7v7/GHSA-xgfh-h2p4-f7v7.json +++ b/advisories/unreviewed/2025/05/GHSA-xgfh-h2p4-f7v7/GHSA-xgfh-h2p4-f7v7.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-xhqg-qw3g-gfc2/GHSA-xhqg-qw3g-gfc2.json b/advisories/unreviewed/2025/05/GHSA-xhqg-qw3g-gfc2/GHSA-xhqg-qw3g-gfc2.json new file mode 100644 index 00000000000..e378032af24 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xhqg-qw3g-gfc2/GHSA-xhqg-qw3g-gfc2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhqg-qw3g-gfc2", + "modified": "2025-05-16T18:31:09Z", + "published": "2025-05-16T18:31:09Z", + "aliases": [ + "CVE-2025-48119" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in RS WP THEMES RS WP Book Showcase allows Code Injection. This issue affects RS WP Book Showcase: from n/a through 6.7.41.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48119" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rs-wp-books-showcase/vulnerability/wordpress-rs-wp-book-showcase-plugin-6-7-40-arbitrary-shortcode-execution-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xjh5-jf5m-43hx/GHSA-xjh5-jf5m-43hx.json b/advisories/unreviewed/2025/05/GHSA-xjh5-jf5m-43hx/GHSA-xjh5-jf5m-43hx.json new file mode 100644 index 00000000000..9b6c59e42cf --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xjh5-jf5m-43hx/GHSA-xjh5-jf5m-43hx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjh5-jf5m-43hx", + "modified": "2025-05-16T18:31:09Z", + "published": "2025-05-16T18:31:09Z", + "aliases": [ + "CVE-2025-48120" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG Lite allows Code Injection. This issue affects MapSVG Lite: from n/a through 8.6.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48120" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mapsvg-lite-interactive-vector-maps/vulnerability/wordpress-mapsvg-lite-plugin-8-5-41-arbitrary-shortcode-execution-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T16:15:44Z" + } +} \ No newline at end of file