From 2cdc4338be136dcd1e483358bef0d6f914a433c2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 20 Oct 2023 18:32:13 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-r2h7-crvv-2qgp.json | 8 ++++ .../GHSA-5mrq-972x-qwr6.json | 4 ++ .../GHSA-9fwm-2jcf-cq55.json | 4 ++ .../GHSA-9r4g-gmfh-6gxg.json | 12 ++++++ .../GHSA-6h3g-g32r-8ff5.json | 4 ++ .../GHSA-f2g6-m663-wjp3.json | 4 ++ .../GHSA-mxm7-jfgp-4j4v.json | 4 ++ .../GHSA-r8cv-3fj5-m22g.json | 4 ++ .../GHSA-3f78-pw9p-j3pc.json | 4 ++ .../GHSA-3jmc-pgpg-8r5g.json | 8 ++++ .../GHSA-7hvf-4934-vphx.json | 6 ++- .../GHSA-8937-55wj-p8rf.json | 4 ++ .../GHSA-8m25-j5jf-5mj2.json | 4 ++ .../GHSA-fprx-q72j-hq6c.json | 4 ++ .../GHSA-wqf2-g6cp-rrpx.json | 10 ++++- .../GHSA-268j-8q64-9cqx.json | 4 ++ .../GHSA-4rjr-p7j3-f64g.json | 4 ++ .../GHSA-6537-j3xq-39r6.json | 4 ++ .../GHSA-crr5-mf4p-x3rf.json | 12 ++++++ .../GHSA-ggqc-76h3-jpv2.json | 4 ++ .../GHSA-j8g4-6p94-j4fp.json | 10 ++++- .../GHSA-rcgv-p6g8-m244.json | 6 ++- .../GHSA-wxr3-9j23-3f82.json | 6 ++- .../GHSA-2895-g6rw-7xgr.json | 4 ++ .../GHSA-3pxc-92w9-cmx7.json | 4 ++ .../GHSA-3xc8-4p8r-q7hj.json | 5 +++ .../GHSA-58w6-59mj-vv9c.json | 6 ++- .../GHSA-7r9g-mrcm-864m.json | 6 ++- .../GHSA-83m6-f4m3-wc9r.json | 4 ++ .../GHSA-9fcg-cr5h-v9g7.json | 4 ++ .../GHSA-jv46-73g5-gg89.json | 8 ++++ .../GHSA-m3m9-j74g-58fw.json | 18 +++++++- .../GHSA-pwp2-44q5-vv6j.json | 8 ++++ .../GHSA-q8hw-79g9-xx95.json | 4 ++ .../GHSA-rg5x-v7gc-4p6v.json | 4 ++ .../GHSA-299r-q2gj-44gj.json | 7 +++- .../GHSA-2qr8-62wg-7r5w.json | 2 +- .../GHSA-2vvx-5g27-9gvj.json | 7 +++- .../GHSA-32qf-g28m-p524.json | 42 +++++++++++++++++++ .../GHSA-39v7-36rj-8jh4.json | 42 +++++++++++++++++++ .../GHSA-3qf9-64j6-3672.json | 42 +++++++++++++++++++ .../GHSA-57cr-rq3f-ppmx.json | 42 +++++++++++++++++++ .../GHSA-5jv2-8f4c-rp62.json | 42 +++++++++++++++++++ .../GHSA-8hhq-vrcj-6mpj.json | 2 +- .../GHSA-9wj3-cfq8-wpvj.json | 42 +++++++++++++++++++ .../GHSA-f464-84q7-49hm.json | 4 ++ .../GHSA-fc5f-gc6j-gfhf.json | 7 +++- .../GHSA-gx5h-6g66-6r78.json | 7 +++- .../GHSA-h9gw-q7wq-vrfv.json | 7 +++- .../GHSA-hg5g-m3rr-7xx2.json | 7 +++- .../GHSA-j6r3-vq2c-4ghw.json | 7 +++- .../GHSA-pqgm-9g82-wcm7.json | 42 +++++++++++++++++++ .../GHSA-pqgv-m3cr-37hw.json | 7 +++- .../GHSA-q5xh-mxrq-59gx.json | 7 +++- .../GHSA-qr56-4922-vccv.json | 38 +++++++++++++++++ .../GHSA-r738-3h9r-fpvv.json | 42 +++++++++++++++++++ .../GHSA-rcgg-pr6j-3pmh.json | 7 +++- .../GHSA-rv9v-x78f-m73w.json | 7 +++- .../GHSA-w72r-ch4p-xqg3.json | 7 +++- 59 files changed, 641 insertions(+), 34 deletions(-) create mode 100644 advisories/unreviewed/2023/10/GHSA-32qf-g28m-p524/GHSA-32qf-g28m-p524.json create mode 100644 advisories/unreviewed/2023/10/GHSA-39v7-36rj-8jh4/GHSA-39v7-36rj-8jh4.json create mode 100644 advisories/unreviewed/2023/10/GHSA-3qf9-64j6-3672/GHSA-3qf9-64j6-3672.json create mode 100644 advisories/unreviewed/2023/10/GHSA-57cr-rq3f-ppmx/GHSA-57cr-rq3f-ppmx.json create mode 100644 advisories/unreviewed/2023/10/GHSA-5jv2-8f4c-rp62/GHSA-5jv2-8f4c-rp62.json create mode 100644 advisories/unreviewed/2023/10/GHSA-9wj3-cfq8-wpvj/GHSA-9wj3-cfq8-wpvj.json create mode 100644 advisories/unreviewed/2023/10/GHSA-pqgm-9g82-wcm7/GHSA-pqgm-9g82-wcm7.json create mode 100644 advisories/unreviewed/2023/10/GHSA-qr56-4922-vccv/GHSA-qr56-4922-vccv.json create mode 100644 advisories/unreviewed/2023/10/GHSA-r738-3h9r-fpvv/GHSA-r738-3h9r-fpvv.json diff --git a/advisories/unreviewed/2022/03/GHSA-r2h7-crvv-2qgp/GHSA-r2h7-crvv-2qgp.json b/advisories/unreviewed/2022/03/GHSA-r2h7-crvv-2qgp/GHSA-r2h7-crvv-2qgp.json index 58f7e0454f5..65aa6e06c10 100644 --- a/advisories/unreviewed/2022/03/GHSA-r2h7-crvv-2qgp/GHSA-r2h7-crvv-2qgp.json +++ b/advisories/unreviewed/2022/03/GHSA-r2h7-crvv-2qgp/GHSA-r2h7-crvv-2qgp.json @@ -21,9 +21,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-0750" }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/photoswipe-masonry/" + }, { "type": "WEB", "url": "https://www.wordfence.com/blog/2022/02/stored-cross-site-scripting-vulnerability-patched-in-a-wordpress-photo-gallery-plugin/" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/64624d4c-3ffb-4516-a938-0accde24c79f?source=cve" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/04/GHSA-5mrq-972x-qwr6/GHSA-5mrq-972x-qwr6.json b/advisories/unreviewed/2022/04/GHSA-5mrq-972x-qwr6/GHSA-5mrq-972x-qwr6.json index a0c0298d7c7..6b980a3cf3e 100644 --- a/advisories/unreviewed/2022/04/GHSA-5mrq-972x-qwr6/GHSA-5mrq-972x-qwr6.json +++ b/advisories/unreviewed/2022/04/GHSA-5mrq-972x-qwr6/GHSA-5mrq-972x-qwr6.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://www.wordfence.com/blog/2022/04/critical-authentication-bypass-vulnerability-patched-in-siteground-security-plugin/" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6e5c6bf7-a653-4571-9566-574d2bb35c4f?source=cve" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/04/GHSA-9fwm-2jcf-cq55/GHSA-9fwm-2jcf-cq55.json b/advisories/unreviewed/2022/04/GHSA-9fwm-2jcf-cq55/GHSA-9fwm-2jcf-cq55.json index 070bf9298b0..55089ebd8c6 100644 --- a/advisories/unreviewed/2022/04/GHSA-9fwm-2jcf-cq55/GHSA-9fwm-2jcf-cq55.json +++ b/advisories/unreviewed/2022/04/GHSA-9fwm-2jcf-cq55/GHSA-9fwm-2jcf-cq55.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2701343%40be-popia-compliant&new=2701343%40be-popia-compliant&sfp_email=&sfph_mail=" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0fcdd6b5-a273-4916-a894-a753be0a7921?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1186" diff --git a/advisories/unreviewed/2022/04/GHSA-9r4g-gmfh-6gxg/GHSA-9r4g-gmfh-6gxg.json b/advisories/unreviewed/2022/04/GHSA-9r4g-gmfh-6gxg/GHSA-9r4g-gmfh-6gxg.json index 082897cbe96..44ddda3cecb 100644 --- a/advisories/unreviewed/2022/04/GHSA-9r4g-gmfh-6gxg/GHSA-9r4g-gmfh-6gxg.json +++ b/advisories/unreviewed/2022/04/GHSA-9r4g-gmfh-6gxg/GHSA-9r4g-gmfh-6gxg.json @@ -21,10 +21,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1187" }, + { + "type": "WEB", + "url": "https://github.com/macbookandrew/wp-youtube-live/commit/2d8ccb7b12742bf16b5a6068f9fdeeac69bc11b1" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-youtube-live/trunk/inc/admin.php#L355" + }, { "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2702715%40wp-youtube-live&new=2702715%40wp-youtube-live&sfp_email=&sfph_mail=" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2d540b53-5c39-43d5-a055-cc5eccfa65b8?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1187" diff --git a/advisories/unreviewed/2022/05/GHSA-6h3g-g32r-8ff5/GHSA-6h3g-g32r-8ff5.json b/advisories/unreviewed/2022/05/GHSA-6h3g-g32r-8ff5/GHSA-6h3g-g32r-8ff5.json index b5d8d5e306a..b01d6f2de33 100644 --- a/advisories/unreviewed/2022/05/GHSA-6h3g-g32r-8ff5/GHSA-6h3g-g32r-8ff5.json +++ b/advisories/unreviewed/2022/05/GHSA-6h3g-g32r-8ff5/GHSA-6h3g-g32r-8ff5.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2715095%40rsvpmaker&new=2715095%40rsvpmaker&sfp_email=&sfph_mail=" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6837b91d-b3ba-435a-965b-fa18d9b9b9c8?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1505" diff --git a/advisories/unreviewed/2022/05/GHSA-f2g6-m663-wjp3/GHSA-f2g6-m663-wjp3.json b/advisories/unreviewed/2022/05/GHSA-f2g6-m663-wjp3/GHSA-f2g6-m663-wjp3.json index 64f16bd3c60..109fa6eda79 100644 --- a/advisories/unreviewed/2022/05/GHSA-f2g6-m663-wjp3/GHSA-f2g6-m663-wjp3.json +++ b/advisories/unreviewed/2022/05/GHSA-f2g6-m663-wjp3/GHSA-f2g6-m663-wjp3.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/browser/wp-js/trunk/wp-js.php?rev=100281#L140" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0ab82117-73dd-4257-8dfc-01dadcc3a83f?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1567" diff --git a/advisories/unreviewed/2022/05/GHSA-mxm7-jfgp-4j4v/GHSA-mxm7-jfgp-4j4v.json b/advisories/unreviewed/2022/05/GHSA-mxm7-jfgp-4j4v/GHSA-mxm7-jfgp-4j4v.json index 860909568fc..95117ebe33c 100644 --- a/advisories/unreviewed/2022/05/GHSA-mxm7-jfgp-4j4v/GHSA-mxm7-jfgp-4j4v.json +++ b/advisories/unreviewed/2022/05/GHSA-mxm7-jfgp-4j4v/GHSA-mxm7-jfgp-4j4v.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset/2711944/metform/trunk/core/forms/action.php" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/04a46249-b5b2-4082-b520-cdc4a1370bb1?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1442" diff --git a/advisories/unreviewed/2022/05/GHSA-r8cv-3fj5-m22g/GHSA-r8cv-3fj5-m22g.json b/advisories/unreviewed/2022/05/GHSA-r8cv-3fj5-m22g/GHSA-r8cv-3fj5-m22g.json index 281654469d3..b91e44b4b12 100644 --- a/advisories/unreviewed/2022/05/GHSA-r8cv-3fj5-m22g/GHSA-r8cv-3fj5-m22g.json +++ b/advisories/unreviewed/2022/05/GHSA-r8cv-3fj5-m22g/GHSA-r8cv-3fj5-m22g.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2714389%40rsvpmaker&new=2714389%40rsvpmaker&sfp_email=&sfph_mail=" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6031edec-4274-4e42-9e3a-ce0c94958b17?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1453" diff --git a/advisories/unreviewed/2022/06/GHSA-3f78-pw9p-j3pc/GHSA-3f78-pw9p-j3pc.json b/advisories/unreviewed/2022/06/GHSA-3f78-pw9p-j3pc/GHSA-3f78-pw9p-j3pc.json index 54a3b5e7e45..1f6a2436bb8 100644 --- a/advisories/unreviewed/2022/06/GHSA-3f78-pw9p-j3pc/GHSA-3f78-pw9p-j3pc.json +++ b/advisories/unreviewed/2022/06/GHSA-3f78-pw9p-j3pc/GHSA-3f78-pw9p-j3pc.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://github.com/duracelltomi/gtm4wp/blob/1.15/public/frontend.php#L782" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0435ae14-c1fd-4611-acbe-5f3bafd4bb6a?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1707" diff --git a/advisories/unreviewed/2022/06/GHSA-3jmc-pgpg-8r5g/GHSA-3jmc-pgpg-8r5g.json b/advisories/unreviewed/2022/06/GHSA-3jmc-pgpg-8r5g/GHSA-3jmc-pgpg-8r5g.json index b389e4b395c..813676d1068 100644 --- a/advisories/unreviewed/2022/06/GHSA-3jmc-pgpg-8r5g/GHSA-3jmc-pgpg-8r5g.json +++ b/advisories/unreviewed/2022/06/GHSA-3jmc-pgpg-8r5g/GHSA-3jmc-pgpg-8r5g.json @@ -29,6 +29,14 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2732977%40duracelltomi-google-tag-manager&new=2732977%40duracelltomi-google-tag-manager&sfp_email=&sfph_mail=" }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/duracelltomi-google-tag-manager/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/202c14d0-9207-47cb-9410-ca4c70d7b6d2?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1961" diff --git a/advisories/unreviewed/2022/06/GHSA-7hvf-4934-vphx/GHSA-7hvf-4934-vphx.json b/advisories/unreviewed/2022/06/GHSA-7hvf-4934-vphx/GHSA-7hvf-4934-vphx.json index f83e242a555..74f52acf055 100644 --- a/advisories/unreviewed/2022/06/GHSA-7hvf-4934-vphx/GHSA-7hvf-4934-vphx.json +++ b/advisories/unreviewed/2022/06/GHSA-7hvf-4934-vphx/GHSA-7hvf-4934-vphx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7hvf-4934-vphx", - "modified": "2022-06-22T00:00:49Z", + "modified": "2023-10-20T18:30:54Z", "published": "2022-06-14T00:00:34Z", "aliases": [ "CVE-2022-1750" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1750" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4a5262d8-d9cd-4bd9-a95e-f60782095173?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1750" diff --git a/advisories/unreviewed/2022/06/GHSA-8937-55wj-p8rf/GHSA-8937-55wj-p8rf.json b/advisories/unreviewed/2022/06/GHSA-8937-55wj-p8rf/GHSA-8937-55wj-p8rf.json index cb831566a67..04ce2f80d88 100644 --- a/advisories/unreviewed/2022/06/GHSA-8937-55wj-p8rf/GHSA-8937-55wj-p8rf.json +++ b/advisories/unreviewed/2022/06/GHSA-8937-55wj-p8rf/GHSA-8937-55wj-p8rf.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/browser/mobile-browser-color-select/trunk/mobile-browser-color-select.php#L62" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/687cd0ac-5f78-4429-b6b5-dd1113143a4d?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1969" diff --git a/advisories/unreviewed/2022/06/GHSA-8m25-j5jf-5mj2/GHSA-8m25-j5jf-5mj2.json b/advisories/unreviewed/2022/06/GHSA-8m25-j5jf-5mj2/GHSA-8m25-j5jf-5mj2.json index 55162640e3b..27a25e07924 100644 --- a/advisories/unreviewed/2022/06/GHSA-8m25-j5jf-5mj2/GHSA-8m25-j5jf-5mj2.json +++ b/advisories/unreviewed/2022/06/GHSA-8m25-j5jf-5mj2/GHSA-8m25-j5jf-5mj2.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/browser/find-any-think/trunk/inc/config/create-plugin-admin.php" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1d063d01-5f67-4c7f-ab71-01708456e82b?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1749" diff --git a/advisories/unreviewed/2022/06/GHSA-fprx-q72j-hq6c/GHSA-fprx-q72j-hq6c.json b/advisories/unreviewed/2022/06/GHSA-fprx-q72j-hq6c/GHSA-fprx-q72j-hq6c.json index 5afdea453b3..5d00401bcf1 100644 --- a/advisories/unreviewed/2022/06/GHSA-fprx-q72j-hq6c/GHSA-fprx-q72j-hq6c.json +++ b/advisories/unreviewed/2022/06/GHSA-fprx-q72j-hq6c/GHSA-fprx-q72j-hq6c.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1900" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e92c6374-d11d-458c-b089-0ee79c33e4a6?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1900" diff --git a/advisories/unreviewed/2022/06/GHSA-wqf2-g6cp-rrpx/GHSA-wqf2-g6cp-rrpx.json b/advisories/unreviewed/2022/06/GHSA-wqf2-g6cp-rrpx/GHSA-wqf2-g6cp-rrpx.json index 0c856bc8a3d..8d4a5912157 100644 --- a/advisories/unreviewed/2022/06/GHSA-wqf2-g6cp-rrpx/GHSA-wqf2-g6cp-rrpx.json +++ b/advisories/unreviewed/2022/06/GHSA-wqf2-g6cp-rrpx/GHSA-wqf2-g6cp-rrpx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wqf2-g6cp-rrpx", - "modified": "2022-06-22T00:00:54Z", + "modified": "2023-10-20T18:30:54Z", "published": "2022-06-14T00:00:36Z", "aliases": [ "CVE-2022-1822" @@ -25,6 +25,14 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2727947%40zephyr-project-manager&new=2727947%40zephyr-project-manager&sfp_email=&sfph_mail=" }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/zephyr-project-manager/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/22d50526-e21f-412d-9eed-b9b1f48c3358?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1822" diff --git a/advisories/unreviewed/2022/07/GHSA-268j-8q64-9cqx/GHSA-268j-8q64-9cqx.json b/advisories/unreviewed/2022/07/GHSA-268j-8q64-9cqx/GHSA-268j-8q64-9cqx.json index 1d44815c78c..a399928c620 100644 --- a/advisories/unreviewed/2022/07/GHSA-268j-8q64-9cqx/GHSA-268j-8q64-9cqx.json +++ b/advisories/unreviewed/2022/07/GHSA-268j-8q64-9cqx/GHSA-268j-8q64-9cqx.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/browser/smartsoftbutton-widget-de-botones-de-chat/trunk/admin/pages/settings.php#L60" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/53757567-5024-46cc-b2ae-04b5fc55a35c?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1912" diff --git a/advisories/unreviewed/2022/07/GHSA-4rjr-p7j3-f64g/GHSA-4rjr-p7j3-f64g.json b/advisories/unreviewed/2022/07/GHSA-4rjr-p7j3-f64g/GHSA-4rjr-p7j3-f64g.json index 9e430eeedcb..6766e4468f2 100644 --- a/advisories/unreviewed/2022/07/GHSA-4rjr-p7j3-f64g/GHSA-4rjr-p7j3-f64g.json +++ b/advisories/unreviewed/2022/07/GHSA-4rjr-p7j3-f64g/GHSA-4rjr-p7j3-f64g.json @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2752058%40visualizer&new=2752058%40visualizer&sfp_email=&sfph_mail=" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d9606d92-8061-4dfc-a6e2-509b54613277?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2444" diff --git a/advisories/unreviewed/2022/07/GHSA-6537-j3xq-39r6/GHSA-6537-j3xq-39r6.json b/advisories/unreviewed/2022/07/GHSA-6537-j3xq-39r6/GHSA-6537-j3xq-39r6.json index 9da10644efe..a50def36b4f 100644 --- a/advisories/unreviewed/2022/07/GHSA-6537-j3xq-39r6/GHSA-6537-j3xq-39r6.json +++ b/advisories/unreviewed/2022/07/GHSA-6537-j3xq-39r6/GHSA-6537-j3xq-39r6.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2749352%40image-slider-widget&new=2749352%40image-slider-widget&sfp_email=&sfph_mail=" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6356e226-a449-4cd0-be60-2a1c9c70aa59?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2223" diff --git a/advisories/unreviewed/2022/07/GHSA-crr5-mf4p-x3rf/GHSA-crr5-mf4p-x3rf.json b/advisories/unreviewed/2022/07/GHSA-crr5-mf4p-x3rf/GHSA-crr5-mf4p-x3rf.json index 45c6d1f9784..8c25563882e 100644 --- a/advisories/unreviewed/2022/07/GHSA-crr5-mf4p-x3rf/GHSA-crr5-mf4p-x3rf.json +++ b/advisories/unreviewed/2022/07/GHSA-crr5-mf4p-x3rf/GHSA-crr5-mf4p-x3rf.json @@ -21,10 +21,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2001" }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/dx-share-selection/trunk/dx-share-selection.php#L284" + }, { "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset/2747572/dx-share-selection/trunk?contextall=1&old=2384535&old_path=%2Fdx-share-selection%2Ftrunk" }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/dx-share-selection/" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6a85fe7f-2d28-4509-99f2-875cb63c6500?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2001" diff --git a/advisories/unreviewed/2022/07/GHSA-ggqc-76h3-jpv2/GHSA-ggqc-76h3-jpv2.json b/advisories/unreviewed/2022/07/GHSA-ggqc-76h3-jpv2/GHSA-ggqc-76h3-jpv2.json index 19802f56bd2..2d82305af38 100644 --- a/advisories/unreviewed/2022/07/GHSA-ggqc-76h3-jpv2/GHSA-ggqc-76h3-jpv2.json +++ b/advisories/unreviewed/2022/07/GHSA-ggqc-76h3-jpv2/GHSA-ggqc-76h3-jpv2.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset/2749264/wp-all-import/trunk?contextall=1&old=2737093&old_path=%2Fwp-all-import%2Ftrunk" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5d281333-d9af-4eb7-bc5c-ea7ceeddac03?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1565" diff --git a/advisories/unreviewed/2022/07/GHSA-j8g4-6p94-j4fp/GHSA-j8g4-6p94-j4fp.json b/advisories/unreviewed/2022/07/GHSA-j8g4-6p94-j4fp/GHSA-j8g4-6p94-j4fp.json index 1925e30716b..68372631d3d 100644 --- a/advisories/unreviewed/2022/07/GHSA-j8g4-6p94-j4fp/GHSA-j8g4-6p94-j4fp.json +++ b/advisories/unreviewed/2022/07/GHSA-j8g4-6p94-j4fp/GHSA-j8g4-6p94-j4fp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j8g4-6p94-j4fp", - "modified": "2023-07-24T15:30:25Z", + "modified": "2023-10-20T18:30:54Z", "published": "2022-07-19T00:00:25Z", "aliases": [ "CVE-2022-2108" @@ -21,10 +21,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2108" }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/review-buddypress-groups/trunk/includes/bgr-ajax.php#L359" + }, { "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset/2742109" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/397dabc3-5dcf-4d1f-9e24-28af889cb76f?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2108" diff --git a/advisories/unreviewed/2022/07/GHSA-rcgv-p6g8-m244/GHSA-rcgv-p6g8-m244.json b/advisories/unreviewed/2022/07/GHSA-rcgv-p6g8-m244/GHSA-rcgv-p6g8-m244.json index 64c80a43d49..4ca45b856b5 100644 --- a/advisories/unreviewed/2022/07/GHSA-rcgv-p6g8-m244/GHSA-rcgv-p6g8-m244.json +++ b/advisories/unreviewed/2022/07/GHSA-rcgv-p6g8-m244/GHSA-rcgv-p6g8-m244.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rcgv-p6g8-m244", - "modified": "2022-07-26T00:01:05Z", + "modified": "2023-10-20T18:30:54Z", "published": "2022-07-19T00:00:26Z", "aliases": [ "CVE-2022-2435" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/browser/anymind-widget/trunk/anymind-widget-id.php" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/174eae70-15d7-4772-8fcd-dc4c0fca5b7d?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2435" diff --git a/advisories/unreviewed/2022/07/GHSA-wxr3-9j23-3f82/GHSA-wxr3-9j23-3f82.json b/advisories/unreviewed/2022/07/GHSA-wxr3-9j23-3f82/GHSA-wxr3-9j23-3f82.json index 8c6d9532be8..49be693eda3 100644 --- a/advisories/unreviewed/2022/07/GHSA-wxr3-9j23-3f82/GHSA-wxr3-9j23-3f82.json +++ b/advisories/unreviewed/2022/07/GHSA-wxr3-9j23-3f82/GHSA-wxr3-9j23-3f82.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wxr3-9j23-3f82", - "modified": "2022-07-26T00:01:05Z", + "modified": "2023-10-20T18:30:54Z", "published": "2022-07-19T00:00:26Z", "aliases": [ "CVE-2022-2437" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2754749%40feed-them-social&new=2754749%40feed-them-social&sfp_email=&sfph_mail=" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/50bcea94-b12a-4b31-b0c1-bba834ea9bd0?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2437" diff --git a/advisories/unreviewed/2022/09/GHSA-2895-g6rw-7xgr/GHSA-2895-g6rw-7xgr.json b/advisories/unreviewed/2022/09/GHSA-2895-g6rw-7xgr/GHSA-2895-g6rw-7xgr.json index 0416146d8d5..420512987dd 100644 --- a/advisories/unreviewed/2022/09/GHSA-2895-g6rw-7xgr/GHSA-2895-g6rw-7xgr.json +++ b/advisories/unreviewed/2022/09/GHSA-2895-g6rw-7xgr/GHSA-2895-g6rw-7xgr.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2761422%40download-manager%2Ftrunk%2Fsrc%2FAdmin%2FMenu%2FPackages.php&new=2761422%40download-manager%2Ftrunk%2Fsrc%2FAdmin%2FMenu%2FPackages.php" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/471957f6-54c1-4268-b2e1-8efa391dcaec?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2436" diff --git a/advisories/unreviewed/2022/09/GHSA-3pxc-92w9-cmx7/GHSA-3pxc-92w9-cmx7.json b/advisories/unreviewed/2022/09/GHSA-3pxc-92w9-cmx7/GHSA-3pxc-92w9-cmx7.json index c70cc6d9178..3ef8893b003 100644 --- a/advisories/unreviewed/2022/09/GHSA-3pxc-92w9-cmx7/GHSA-3pxc-92w9-cmx7.json +++ b/advisories/unreviewed/2022/09/GHSA-3pxc-92w9-cmx7/GHSA-3pxc-92w9-cmx7.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset/2757773/broken-link-checker/trunk/core/core.php?old=2605914&old_path=broken-link-checker%2Ftrunk%2Fcore%2Fcore.php" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/62fd472e-208b-48db-8f98-3d935c7a678c?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2438" diff --git a/advisories/unreviewed/2022/09/GHSA-3xc8-4p8r-q7hj/GHSA-3xc8-4p8r-q7hj.json b/advisories/unreviewed/2022/09/GHSA-3xc8-4p8r-q7hj/GHSA-3xc8-4p8r-q7hj.json index 6cd4ba14b5f..19e53e939a0 100644 --- a/advisories/unreviewed/2022/09/GHSA-3xc8-4p8r-q7hj/GHSA-3xc8-4p8r-q7hj.json +++ b/advisories/unreviewed/2022/09/GHSA-3xc8-4p8r-q7hj/GHSA-3xc8-4p8r-q7hj.json @@ -37,6 +37,10 @@ "type": "WEB", "url": "https://www.rcesecurity.com/2022/07/WordPress-Transposh-Exploiting-a-Blind-SQL-Injection-via-XSS/" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/223373fc-9d78-47f0-b283-109f8e00b802?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2461" @@ -44,6 +48,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-285", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/09/GHSA-58w6-59mj-vv9c/GHSA-58w6-59mj-vv9c.json b/advisories/unreviewed/2022/09/GHSA-58w6-59mj-vv9c/GHSA-58w6-59mj-vv9c.json index 7c84bb0a8d0..45c878685be 100644 --- a/advisories/unreviewed/2022/09/GHSA-58w6-59mj-vv9c/GHSA-58w6-59mj-vv9c.json +++ b/advisories/unreviewed/2022/09/GHSA-58w6-59mj-vv9c/GHSA-58w6-59mj-vv9c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-58w6-59mj-vv9c", - "modified": "2022-09-10T00:00:24Z", + "modified": "2023-10-20T18:30:54Z", "published": "2022-09-07T00:01:52Z", "aliases": [ "CVE-2022-2433" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset/2772627/ajax-load-more/trunk/admin/admin.php" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/040ae20d-93e3-4c65-ba74-4ff0b5c1afc7?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2433" diff --git a/advisories/unreviewed/2022/09/GHSA-7r9g-mrcm-864m/GHSA-7r9g-mrcm-864m.json b/advisories/unreviewed/2022/09/GHSA-7r9g-mrcm-864m/GHSA-7r9g-mrcm-864m.json index 378a11a75c4..6050c968473 100644 --- a/advisories/unreviewed/2022/09/GHSA-7r9g-mrcm-864m/GHSA-7r9g-mrcm-864m.json +++ b/advisories/unreviewed/2022/09/GHSA-7r9g-mrcm-864m/GHSA-7r9g-mrcm-864m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7r9g-mrcm-864m", - "modified": "2022-09-10T00:00:35Z", + "modified": "2023-10-20T18:30:54Z", "published": "2022-09-07T00:01:51Z", "aliases": [ "CVE-2022-2233" @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/browser/banner-cycler/trunk/admin/admin.php#L131" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6cc1d7f2-053d-42d4-afb7-6fb69fd71b91?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2233" diff --git a/advisories/unreviewed/2022/09/GHSA-83m6-f4m3-wc9r/GHSA-83m6-f4m3-wc9r.json b/advisories/unreviewed/2022/09/GHSA-83m6-f4m3-wc9r/GHSA-83m6-f4m3-wc9r.json index 729a4198fe1..4ccfa86c4c0 100644 --- a/advisories/unreviewed/2022/09/GHSA-83m6-f4m3-wc9r/GHSA-83m6-f4m3-wc9r.json +++ b/advisories/unreviewed/2022/09/GHSA-83m6-f4m3-wc9r/GHSA-83m6-f4m3-wc9r.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/browser/ucontext/trunk/app/sites/ajax/actions/keyword_save.php" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4af83d4b-2eae-481f-b3fd-d5bcacc1d709?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2542" diff --git a/advisories/unreviewed/2022/09/GHSA-9fcg-cr5h-v9g7/GHSA-9fcg-cr5h-v9g7.json b/advisories/unreviewed/2022/09/GHSA-9fcg-cr5h-v9g7/GHSA-9fcg-cr5h-v9g7.json index 5b9c5274102..928da0f8897 100644 --- a/advisories/unreviewed/2022/09/GHSA-9fcg-cr5h-v9g7/GHSA-9fcg-cr5h-v9g7.json +++ b/advisories/unreviewed/2022/09/GHSA-9fcg-cr5h-v9g7/GHSA-9fcg-cr5h-v9g7.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2758766%40simple-banner&new=2758766%40simple-banner&sfp_email=&sfph_mail=" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3bb9520d-e679-4e8a-ae3c-8207f17d45a2?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2515" diff --git a/advisories/unreviewed/2022/09/GHSA-jv46-73g5-gg89/GHSA-jv46-73g5-gg89.json b/advisories/unreviewed/2022/09/GHSA-jv46-73g5-gg89/GHSA-jv46-73g5-gg89.json index 648806f635b..1de09ef9e82 100644 --- a/advisories/unreviewed/2022/09/GHSA-jv46-73g5-gg89/GHSA-jv46-73g5-gg89.json +++ b/advisories/unreviewed/2022/09/GHSA-jv46-73g5-gg89/GHSA-jv46-73g5-gg89.json @@ -25,6 +25,14 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/browser/stockists-manager/trunk/stockist_settings.php" }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/stockists-manager/" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5b5e0204-4a05-45c1-833a-c2e4016d9830?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2518" diff --git a/advisories/unreviewed/2022/09/GHSA-m3m9-j74g-58fw/GHSA-m3m9-j74g-58fw.json b/advisories/unreviewed/2022/09/GHSA-m3m9-j74g-58fw/GHSA-m3m9-j74g-58fw.json index 908cbe33607..d1484aa9701 100644 --- a/advisories/unreviewed/2022/09/GHSA-m3m9-j74g-58fw/GHSA-m3m9-j74g-58fw.json +++ b/advisories/unreviewed/2022/09/GHSA-m3m9-j74g-58fw/GHSA-m3m9-j74g-58fw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m3m9-j74g-58fw", - "modified": "2022-09-11T00:00:30Z", + "modified": "2023-10-20T18:30:54Z", "published": "2022-09-07T00:01:52Z", "aliases": [ "CVE-2022-2473" @@ -29,13 +29,29 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2758412%40wp-useronline&new=2758412%40wp-useronline&sfp_email=&sfph_mail=" }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/50988" + }, { "type": "WEB", "url": "https://www.exploitalert.com/view-details.html?id=38893" }, + { + "type": "WEB", + "url": "https://www.exploitalert.com/view-details.html?id=38912" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6a44a55e-a96a-4698-9948-6ef33138a834?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2473" + }, + { + "type": "WEB", + "url": "https://youtu.be/Q3zInrUnAV0" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/09/GHSA-pwp2-44q5-vv6j/GHSA-pwp2-44q5-vv6j.json b/advisories/unreviewed/2022/09/GHSA-pwp2-44q5-vv6j/GHSA-pwp2-44q5-vv6j.json index b7eca18444a..daea2ef061d 100644 --- a/advisories/unreviewed/2022/09/GHSA-pwp2-44q5-vv6j/GHSA-pwp2-44q5-vv6j.json +++ b/advisories/unreviewed/2022/09/GHSA-pwp2-44q5-vv6j/GHSA-pwp2-44q5-vv6j.json @@ -25,10 +25,18 @@ "type": "WEB", "url": "https://github.com/lesterchan/wp-useronline/commit/59c76b20e4e27489f93dee4ef1254d6204e08b3c" }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/168479/wpuseronline2880-xss.txt" + }, { "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2770235%40wp-useronline&new=2770235%40wp-useronline&sfp_email=&sfph_mail=" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5c4fb14c-de6d-4247-8f83-050f1350f6a2?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2941" diff --git a/advisories/unreviewed/2022/09/GHSA-q8hw-79g9-xx95/GHSA-q8hw-79g9-xx95.json b/advisories/unreviewed/2022/09/GHSA-q8hw-79g9-xx95/GHSA-q8hw-79g9-xx95.json index 37ff3b513d2..22aeeb88ba0 100644 --- a/advisories/unreviewed/2022/09/GHSA-q8hw-79g9-xx95/GHSA-q8hw-79g9-xx95.json +++ b/advisories/unreviewed/2022/09/GHSA-q8hw-79g9-xx95/GHSA-q8hw-79g9-xx95.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2759486%40string-locator&new=2759486%40string-locator&sfp_email=&sfph_mail=" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/10a36e37-4188-403f-9b17-d7e79b8b8a6d?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2434" diff --git a/advisories/unreviewed/2022/09/GHSA-rg5x-v7gc-4p6v/GHSA-rg5x-v7gc-4p6v.json b/advisories/unreviewed/2022/09/GHSA-rg5x-v7gc-4p6v/GHSA-rg5x-v7gc-4p6v.json index d8d8182eaa9..7d73d385232 100644 --- a/advisories/unreviewed/2022/09/GHSA-rg5x-v7gc-4p6v/GHSA-rg5x-v7gc-4p6v.json +++ b/advisories/unreviewed/2022/09/GHSA-rg5x-v7gc-4p6v/GHSA-rg5x-v7gc-4p6v.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://plugins.trac.wordpress.org/browser/ucontext-for-amazon/trunk/app/sites/ajax/actions/keyword_save.php" }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0f7c43d4-cf21-4324-bc77-50bdc2c24661?source=cve" + }, { "type": "WEB", "url": "https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2541" diff --git a/advisories/unreviewed/2023/10/GHSA-299r-q2gj-44gj/GHSA-299r-q2gj-44gj.json b/advisories/unreviewed/2023/10/GHSA-299r-q2gj-44gj/GHSA-299r-q2gj-44gj.json index d3caaa49704..da4dec6b085 100644 --- a/advisories/unreviewed/2023/10/GHSA-299r-q2gj-44gj/GHSA-299r-q2gj-44gj.json +++ b/advisories/unreviewed/2023/10/GHSA-299r-q2gj-44gj/GHSA-299r-q2gj-44gj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-299r-q2gj-44gj", - "modified": "2023-10-16T21:30:26Z", + "modified": "2023-10-20T18:30:55Z", "published": "2023-10-16T21:30:26Z", "aliases": [ "CVE-2023-4646" ], "details": "The Simple Posts Ticker WordPress plugin before 1.1.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-2qr8-62wg-7r5w/GHSA-2qr8-62wg-7r5w.json b/advisories/unreviewed/2023/10/GHSA-2qr8-62wg-7r5w/GHSA-2qr8-62wg-7r5w.json index 96924b96dae..714b9a6e5f7 100644 --- a/advisories/unreviewed/2023/10/GHSA-2qr8-62wg-7r5w/GHSA-2qr8-62wg-7r5w.json +++ b/advisories/unreviewed/2023/10/GHSA-2qr8-62wg-7r5w/GHSA-2qr8-62wg-7r5w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2qr8-62wg-7r5w", - "modified": "2023-10-14T12:30:23Z", + "modified": "2023-10-20T18:30:55Z", "published": "2023-10-14T12:30:23Z", "aliases": [ "CVE-2023-5578" diff --git a/advisories/unreviewed/2023/10/GHSA-2vvx-5g27-9gvj/GHSA-2vvx-5g27-9gvj.json b/advisories/unreviewed/2023/10/GHSA-2vvx-5g27-9gvj/GHSA-2vvx-5g27-9gvj.json index 6a4d7620766..1d7c416ea6e 100644 --- a/advisories/unreviewed/2023/10/GHSA-2vvx-5g27-9gvj/GHSA-2vvx-5g27-9gvj.json +++ b/advisories/unreviewed/2023/10/GHSA-2vvx-5g27-9gvj/GHSA-2vvx-5g27-9gvj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2vvx-5g27-9gvj", - "modified": "2023-10-16T21:30:27Z", + "modified": "2023-10-20T18:30:55Z", "published": "2023-10-16T21:30:27Z", "aliases": [ "CVE-2023-5003" ], "details": "The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-32qf-g28m-p524/GHSA-32qf-g28m-p524.json b/advisories/unreviewed/2023/10/GHSA-32qf-g28m-p524/GHSA-32qf-g28m-p524.json new file mode 100644 index 00000000000..d02dd3c1df5 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-32qf-g28m-p524/GHSA-32qf-g28m-p524.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32qf-g28m-p524", + "modified": "2023-10-20T18:30:57Z", + "published": "2023-10-20T18:30:57Z", + "aliases": [ + "CVE-2023-3965" + ], + "details": "The nsc theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3965" + }, + { + "type": "WEB", + "url": "https://github.com/BlackFan/client-side-prototype-pollution" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5909513d-8877-40ff-bee9-d565141b7ed2?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-39v7-36rj-8jh4/GHSA-39v7-36rj-8jh4.json b/advisories/unreviewed/2023/10/GHSA-39v7-36rj-8jh4/GHSA-39v7-36rj-8jh4.json new file mode 100644 index 00000000000..3bbb568276d --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-39v7-36rj-8jh4/GHSA-39v7-36rj-8jh4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39v7-36rj-8jh4", + "modified": "2023-10-20T18:30:57Z", + "published": "2023-10-20T18:30:57Z", + "aliases": [ + "CVE-2023-5686" + ], + "details": "Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5686" + }, + { + "type": "WEB", + "url": "https://github.com/radareorg/radare2/commit/1bdda93e348c160c84e30da3637acef26d0348de" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/bbfe1f76-8fa1-4a8c-909d-65b16e970be0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-3qf9-64j6-3672/GHSA-3qf9-64j6-3672.json b/advisories/unreviewed/2023/10/GHSA-3qf9-64j6-3672/GHSA-3qf9-64j6-3672.json new file mode 100644 index 00000000000..52f80abc599 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-3qf9-64j6-3672/GHSA-3qf9-64j6-3672.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qf9-64j6-3672", + "modified": "2023-10-20T18:30:56Z", + "published": "2023-10-20T18:30:56Z", + "aliases": [ + "CVE-2023-3933" + ], + "details": "The Your Journey theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up to, and including, 1.9.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3933" + }, + { + "type": "WEB", + "url": "https://github.com/BlackFan/client-side-prototype-pollution" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c738e051-ad1c-4115-94d3-127dd5dff935?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-57cr-rq3f-ppmx/GHSA-57cr-rq3f-ppmx.json b/advisories/unreviewed/2023/10/GHSA-57cr-rq3f-ppmx/GHSA-57cr-rq3f-ppmx.json new file mode 100644 index 00000000000..bb38aaf393a --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-57cr-rq3f-ppmx/GHSA-57cr-rq3f-ppmx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57cr-rq3f-ppmx", + "modified": "2023-10-20T18:30:58Z", + "published": "2023-10-20T18:30:58Z", + "aliases": [ + "CVE-2023-5690" + ], + "details": "Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5690" + }, + { + "type": "WEB", + "url": "https://github.com/modoboa/modoboa/commit/23e4c25511c66c0548da001236f47e19e3f9e4d9" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/980c75a5-d978-4b0e-9bcc-2b2682c97e01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-5jv2-8f4c-rp62/GHSA-5jv2-8f4c-rp62.json b/advisories/unreviewed/2023/10/GHSA-5jv2-8f4c-rp62/GHSA-5jv2-8f4c-rp62.json new file mode 100644 index 00000000000..6d1f21bcb5d --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-5jv2-8f4c-rp62/GHSA-5jv2-8f4c-rp62.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jv2-8f4c-rp62", + "modified": "2023-10-20T18:30:57Z", + "published": "2023-10-20T18:30:57Z", + "aliases": [ + "CVE-2023-5687" + ], + "details": "Cross-Site Request Forgery (CSRF) in GitHub repository mosparo/mosparo prior to 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5687" + }, + { + "type": "WEB", + "url": "https://github.com/mosparo/mosparo/commit/fb3ac528b7548beb802182310967968a21c1354a" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/33f95510-cdee-460e-8e61-107874962f2d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-8hhq-vrcj-6mpj/GHSA-8hhq-vrcj-6mpj.json b/advisories/unreviewed/2023/10/GHSA-8hhq-vrcj-6mpj/GHSA-8hhq-vrcj-6mpj.json index 242ce7f9b53..bd2ed0556ae 100644 --- a/advisories/unreviewed/2023/10/GHSA-8hhq-vrcj-6mpj/GHSA-8hhq-vrcj-6mpj.json +++ b/advisories/unreviewed/2023/10/GHSA-8hhq-vrcj-6mpj/GHSA-8hhq-vrcj-6mpj.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-9wj3-cfq8-wpvj/GHSA-9wj3-cfq8-wpvj.json b/advisories/unreviewed/2023/10/GHSA-9wj3-cfq8-wpvj/GHSA-9wj3-cfq8-wpvj.json new file mode 100644 index 00000000000..8cf6b987b47 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-9wj3-cfq8-wpvj/GHSA-9wj3-cfq8-wpvj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wj3-cfq8-wpvj", + "modified": "2023-10-20T18:30:57Z", + "published": "2023-10-20T18:30:57Z", + "aliases": [ + "CVE-2023-5689" + ], + "details": "Cross-site Scripting (XSS) - DOM in GitHub repository modoboa/modoboa prior to 2.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5689" + }, + { + "type": "WEB", + "url": "https://github.com/modoboa/modoboa/commit/d33d3cd2d11dbfebd8162c46e2c2a9873919a967" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/24835833-3421-412b-bafb-1b7ea3cf60e6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-f464-84q7-49hm/GHSA-f464-84q7-49hm.json b/advisories/unreviewed/2023/10/GHSA-f464-84q7-49hm/GHSA-f464-84q7-49hm.json index 21212f56957..8b506b166e7 100644 --- a/advisories/unreviewed/2023/10/GHSA-f464-84q7-49hm/GHSA-f464-84q7-49hm.json +++ b/advisories/unreviewed/2023/10/GHSA-f464-84q7-49hm/GHSA-f464-84q7-49hm.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1809" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1809" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-fc5f-gc6j-gfhf/GHSA-fc5f-gc6j-gfhf.json b/advisories/unreviewed/2023/10/GHSA-fc5f-gc6j-gfhf/GHSA-fc5f-gc6j-gfhf.json index 944d7cb908b..5b77412a484 100644 --- a/advisories/unreviewed/2023/10/GHSA-fc5f-gc6j-gfhf/GHSA-fc5f-gc6j-gfhf.json +++ b/advisories/unreviewed/2023/10/GHSA-fc5f-gc6j-gfhf/GHSA-fc5f-gc6j-gfhf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fc5f-gc6j-gfhf", - "modified": "2023-10-16T21:30:27Z", + "modified": "2023-10-20T18:30:55Z", "published": "2023-10-16T21:30:27Z", "aliases": [ "CVE-2023-5177" ], "details": "The Vrm 360 3D Model Viewer WordPress plugin through 1.2.1 exposes the full path of a file when putting in a non-existent file in a parameter of the shortcode.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-gx5h-6g66-6r78/GHSA-gx5h-6g66-6r78.json b/advisories/unreviewed/2023/10/GHSA-gx5h-6g66-6r78/GHSA-gx5h-6g66-6r78.json index 7526b5f3745..97127ee1f96 100644 --- a/advisories/unreviewed/2023/10/GHSA-gx5h-6g66-6r78/GHSA-gx5h-6g66-6r78.json +++ b/advisories/unreviewed/2023/10/GHSA-gx5h-6g66-6r78/GHSA-gx5h-6g66-6r78.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gx5h-6g66-6r78", - "modified": "2023-10-16T21:30:26Z", + "modified": "2023-10-20T18:30:55Z", "published": "2023-10-16T21:30:26Z", "aliases": [ "CVE-2023-4290" ], "details": "The WP Matterport Shortcode WordPress plugin before 2.1.7 does not escape the PHP_SELF server variable when outputting it in attributes, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as admin", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-h9gw-q7wq-vrfv/GHSA-h9gw-q7wq-vrfv.json b/advisories/unreviewed/2023/10/GHSA-h9gw-q7wq-vrfv/GHSA-h9gw-q7wq-vrfv.json index 8744fdb545e..793c7212782 100644 --- a/advisories/unreviewed/2023/10/GHSA-h9gw-q7wq-vrfv/GHSA-h9gw-q7wq-vrfv.json +++ b/advisories/unreviewed/2023/10/GHSA-h9gw-q7wq-vrfv/GHSA-h9gw-q7wq-vrfv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h9gw-q7wq-vrfv", - "modified": "2023-10-16T21:30:26Z", + "modified": "2023-10-20T18:30:55Z", "published": "2023-10-16T21:30:26Z", "aliases": [ "CVE-2023-4643" ], "details": "The Enable Media Replace WordPress plugin before 4.1.3 unserializes user input via the Remove Background feature, which could allow Author+ users to perform PHP Object Injection when a suitable gadget is present on the blog", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-hg5g-m3rr-7xx2/GHSA-hg5g-m3rr-7xx2.json b/advisories/unreviewed/2023/10/GHSA-hg5g-m3rr-7xx2/GHSA-hg5g-m3rr-7xx2.json index be40c840e39..bf812ca8ae2 100644 --- a/advisories/unreviewed/2023/10/GHSA-hg5g-m3rr-7xx2/GHSA-hg5g-m3rr-7xx2.json +++ b/advisories/unreviewed/2023/10/GHSA-hg5g-m3rr-7xx2/GHSA-hg5g-m3rr-7xx2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hg5g-m3rr-7xx2", - "modified": "2023-10-16T21:30:26Z", + "modified": "2023-10-20T18:30:55Z", "published": "2023-10-16T21:30:26Z", "aliases": [ "CVE-2023-4289" ], "details": "The WP Matterport Shortcode WordPress plugin before 2.1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-j6r3-vq2c-4ghw/GHSA-j6r3-vq2c-4ghw.json b/advisories/unreviewed/2023/10/GHSA-j6r3-vq2c-4ghw/GHSA-j6r3-vq2c-4ghw.json index 95ebf10aac1..169e005873d 100644 --- a/advisories/unreviewed/2023/10/GHSA-j6r3-vq2c-4ghw/GHSA-j6r3-vq2c-4ghw.json +++ b/advisories/unreviewed/2023/10/GHSA-j6r3-vq2c-4ghw/GHSA-j6r3-vq2c-4ghw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j6r3-vq2c-4ghw", - "modified": "2023-10-16T21:30:27Z", + "modified": "2023-10-20T18:30:55Z", "published": "2023-10-16T21:30:27Z", "aliases": [ "CVE-2023-5089" ], "details": "The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-pqgm-9g82-wcm7/GHSA-pqgm-9g82-wcm7.json b/advisories/unreviewed/2023/10/GHSA-pqgm-9g82-wcm7/GHSA-pqgm-9g82-wcm7.json new file mode 100644 index 00000000000..b4604c9a4f2 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-pqgm-9g82-wcm7/GHSA-pqgm-9g82-wcm7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqgm-9g82-wcm7", + "modified": "2023-10-20T18:30:57Z", + "published": "2023-10-20T18:30:57Z", + "aliases": [ + "CVE-2023-5688" + ], + "details": "Cross-site Scripting (XSS) - DOM in GitHub repository modoboa/modoboa prior to 2.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5688" + }, + { + "type": "WEB", + "url": "https://github.com/modoboa/modoboa/commit/d33d3cd2d11dbfebd8162c46e2c2a9873919a967" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/0ceb10e4-952b-4ca4-baf8-5b6f12e3a8a7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-pqgv-m3cr-37hw/GHSA-pqgv-m3cr-37hw.json b/advisories/unreviewed/2023/10/GHSA-pqgv-m3cr-37hw/GHSA-pqgv-m3cr-37hw.json index 4e7ab37fec0..e5e18c44f62 100644 --- a/advisories/unreviewed/2023/10/GHSA-pqgv-m3cr-37hw/GHSA-pqgv-m3cr-37hw.json +++ b/advisories/unreviewed/2023/10/GHSA-pqgv-m3cr-37hw/GHSA-pqgv-m3cr-37hw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pqgv-m3cr-37hw", - "modified": "2023-10-16T21:30:27Z", + "modified": "2023-10-20T18:30:55Z", "published": "2023-10-16T21:30:27Z", "aliases": [ "CVE-2023-5087" ], "details": "The Page Builder: Pagelayer WordPress plugin before 1.7.8 doesn't prevent attackers with author privileges and higher from inserting malicious JavaScript inside a post's header or footer code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-q5xh-mxrq-59gx/GHSA-q5xh-mxrq-59gx.json b/advisories/unreviewed/2023/10/GHSA-q5xh-mxrq-59gx/GHSA-q5xh-mxrq-59gx.json index 09cc158defe..161e5bb2965 100644 --- a/advisories/unreviewed/2023/10/GHSA-q5xh-mxrq-59gx/GHSA-q5xh-mxrq-59gx.json +++ b/advisories/unreviewed/2023/10/GHSA-q5xh-mxrq-59gx/GHSA-q5xh-mxrq-59gx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q5xh-mxrq-59gx", - "modified": "2023-10-16T21:30:26Z", + "modified": "2023-10-20T18:30:55Z", "published": "2023-10-16T21:30:26Z", "aliases": [ "CVE-2023-4388" ], "details": "The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-qr56-4922-vccv/GHSA-qr56-4922-vccv.json b/advisories/unreviewed/2023/10/GHSA-qr56-4922-vccv/GHSA-qr56-4922-vccv.json new file mode 100644 index 00000000000..38082296add --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-qr56-4922-vccv/GHSA-qr56-4922-vccv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr56-4922-vccv", + "modified": "2023-10-20T18:30:57Z", + "published": "2023-10-20T18:30:57Z", + "aliases": [ + "CVE-2023-23373" + ], + "details": "An OS command injection vulnerability has been reported to affect QUSBCam2. If exploited, the vulnerability could allow users to execute commands via a network.\n\nWe have already fixed the vulnerability in the following version:\nQUSBCam2 2.0.3 ( 2023/06/15 ) and later\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23373" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-43" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-r738-3h9r-fpvv/GHSA-r738-3h9r-fpvv.json b/advisories/unreviewed/2023/10/GHSA-r738-3h9r-fpvv/GHSA-r738-3h9r-fpvv.json new file mode 100644 index 00000000000..6e50cb32353 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-r738-3h9r-fpvv/GHSA-r738-3h9r-fpvv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r738-3h9r-fpvv", + "modified": "2023-10-20T18:30:56Z", + "published": "2023-10-20T18:30:56Z", + "aliases": [ + "CVE-2023-3962" + ], + "details": "The Winters theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3962" + }, + { + "type": "WEB", + "url": "https://github.com/BlackFan/client-side-prototype-pollution" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6f8b75a1-f0f2-445b-a1c7-1628916470d3?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-rcgg-pr6j-3pmh/GHSA-rcgg-pr6j-3pmh.json b/advisories/unreviewed/2023/10/GHSA-rcgg-pr6j-3pmh/GHSA-rcgg-pr6j-3pmh.json index 5dd9dba9a11..80d87267be0 100644 --- a/advisories/unreviewed/2023/10/GHSA-rcgg-pr6j-3pmh/GHSA-rcgg-pr6j-3pmh.json +++ b/advisories/unreviewed/2023/10/GHSA-rcgg-pr6j-3pmh/GHSA-rcgg-pr6j-3pmh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rcgg-pr6j-3pmh", - "modified": "2023-10-16T21:30:27Z", + "modified": "2023-10-20T18:30:55Z", "published": "2023-10-16T21:30:27Z", "aliases": [ "CVE-2023-5057" ], "details": "The ActivityPub WordPress plugin before 1.0.0 does not escape user metadata before outputting them in mentions, which could allow users with a role of Contributor and above to perform Stored XSS attacks", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-rv9v-x78f-m73w/GHSA-rv9v-x78f-m73w.json b/advisories/unreviewed/2023/10/GHSA-rv9v-x78f-m73w/GHSA-rv9v-x78f-m73w.json index 37b6d33bf55..ccfa06736e4 100644 --- a/advisories/unreviewed/2023/10/GHSA-rv9v-x78f-m73w/GHSA-rv9v-x78f-m73w.json +++ b/advisories/unreviewed/2023/10/GHSA-rv9v-x78f-m73w/GHSA-rv9v-x78f-m73w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rv9v-x78f-m73w", - "modified": "2023-10-16T15:30:20Z", + "modified": "2023-10-20T18:30:55Z", "published": "2023-10-16T15:30:20Z", "aliases": [ "CVE-2023-5575" ], "details": "\n\nImproper access control in the permission inheritance in Devolutions Server 2022.3.13.0 and earlier allows an attacker that compromised a low privileged user to access entries via a specific combination of permissions in the entry and in its parent.\n\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-w72r-ch4p-xqg3/GHSA-w72r-ch4p-xqg3.json b/advisories/unreviewed/2023/10/GHSA-w72r-ch4p-xqg3/GHSA-w72r-ch4p-xqg3.json index 6008f1b2dcd..c815ca11e16 100644 --- a/advisories/unreviewed/2023/10/GHSA-w72r-ch4p-xqg3/GHSA-w72r-ch4p-xqg3.json +++ b/advisories/unreviewed/2023/10/GHSA-w72r-ch4p-xqg3/GHSA-w72r-ch4p-xqg3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w72r-ch4p-xqg3", - "modified": "2023-10-16T21:30:26Z", + "modified": "2023-10-20T18:30:55Z", "published": "2023-10-16T21:30:26Z", "aliases": [ "CVE-2023-4666" ], "details": "The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [