diff --git a/advisories/unreviewed/2025/03/GHSA-3q2g-cq44-pjqq/GHSA-3q2g-cq44-pjqq.json b/advisories/unreviewed/2025/03/GHSA-3q2g-cq44-pjqq/GHSA-3q2g-cq44-pjqq.json new file mode 100644 index 00000000000..5e1e5e4f821 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3q2g-cq44-pjqq/GHSA-3q2g-cq44-pjqq.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q2g-cq44-pjqq", + "modified": "2025-03-18T09:31:49Z", + "published": "2025-03-18T09:31:49Z", + "aliases": [ + "CVE-2025-2262" + ], + "details": "The The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.7.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2262" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/gs-logo-slider/trunk/includes/shortcode-builder/builder.php#L31" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/gs-logo-slider/trunk/includes/shortcode-builder/builder.php#L51" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/gs-logo-slider/trunk/includes/shortcode-builder/builder.php#L65" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3256441" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3c7cc2d2-8de4-453b-b4dc-48f75b151078?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T07:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4xfg-8977-37fx/GHSA-4xfg-8977-37fx.json b/advisories/unreviewed/2025/03/GHSA-4xfg-8977-37fx/GHSA-4xfg-8977-37fx.json new file mode 100644 index 00000000000..c3c63bc75ce --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4xfg-8977-37fx/GHSA-4xfg-8977-37fx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xfg-8977-37fx", + "modified": "2025-03-18T09:31:49Z", + "published": "2025-03-18T09:31:49Z", + "aliases": [ + "CVE-2025-25220" + ], + "details": "Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.1_1101. If this vulnerability is exploited, an arbitrary OS command may be executed by a remote authenticated attacker.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25220" + }, + { + "type": "WEB", + "url": "https://fsi-plusf.jp/news/25031701.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN11230428" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T09:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f3ff-gxqf-prhc/GHSA-f3ff-gxqf-prhc.json b/advisories/unreviewed/2025/03/GHSA-f3ff-gxqf-prhc/GHSA-f3ff-gxqf-prhc.json new file mode 100644 index 00000000000..bf8a7016a85 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f3ff-gxqf-prhc/GHSA-f3ff-gxqf-prhc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3ff-gxqf-prhc", + "modified": "2025-03-18T09:31:49Z", + "published": "2025-03-18T09:31:49Z", + "aliases": [ + "CVE-2025-24306" + ], + "details": "Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.0_1101. If this vulnerability is exploited, an arbitrary OS command may be executed by a remote authenticated attacker with an administrative privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24306" + }, + { + "type": "WEB", + "url": "https://fsi-plusf.jp/news/25031701.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN11230428" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T09:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x43h-8pfv-xx24/GHSA-x43h-8pfv-xx24.json b/advisories/unreviewed/2025/03/GHSA-x43h-8pfv-xx24/GHSA-x43h-8pfv-xx24.json new file mode 100644 index 00000000000..4128c66069c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x43h-8pfv-xx24/GHSA-x43h-8pfv-xx24.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x43h-8pfv-xx24", + "modified": "2025-03-18T09:31:49Z", + "published": "2025-03-18T09:31:49Z", + "aliases": [ + "CVE-2025-0755" + ], + "details": "The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result in a final BSON document which exceeds the maximum allowable size (INT32_MAX), resulting in a segmentation fault and possible application crash. This issue affected libbson versions prior to 1.27.5, MongoDB Server v8.0 versions prior to 8.0.1 and MongoDB Server v7.0 versions prior to 7.0.16", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0755" + }, + { + "type": "WEB", + "url": "https://jira.mongodb.org/browse/SERVER-94461" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-18T09:15:11Z" + } +} \ No newline at end of file