diff --git a/advisories/unreviewed/2024/03/GHSA-25m9-3j97-v6cg/GHSA-25m9-3j97-v6cg.json b/advisories/unreviewed/2024/03/GHSA-25m9-3j97-v6cg/GHSA-25m9-3j97-v6cg.json index 5d478cd226d..0a2ff42d5bc 100644 --- a/advisories/unreviewed/2024/03/GHSA-25m9-3j97-v6cg/GHSA-25m9-3j97-v6cg.json +++ b/advisories/unreviewed/2024/03/GHSA-25m9-3j97-v6cg/GHSA-25m9-3j97-v6cg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-25m9-3j97-v6cg", - "modified": "2024-03-26T18:32:06Z", + "modified": "2024-03-27T12:30:38Z", "published": "2024-03-26T18:32:06Z", "aliases": [ "CVE-2023-52622" diff --git a/advisories/unreviewed/2024/03/GHSA-4mmc-mh89-xjx6/GHSA-4mmc-mh89-xjx6.json b/advisories/unreviewed/2024/03/GHSA-4mmc-mh89-xjx6/GHSA-4mmc-mh89-xjx6.json new file mode 100644 index 00000000000..db5053a639b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-4mmc-mh89-xjx6/GHSA-4mmc-mh89-xjx6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mmc-mh89-xjx6", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-29932" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Stored XSS.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29932" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-meta-data-filter-and-taxonomy-filter/wordpress-wordpress-meta-data-and-taxonomies-filter-mdtf-plugin-1-3-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-4wjc-cc7w-rv94/GHSA-4wjc-cc7w-rv94.json b/advisories/unreviewed/2024/03/GHSA-4wjc-cc7w-rv94/GHSA-4wjc-cc7w-rv94.json new file mode 100644 index 00000000000..2b97d768fbf --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-4wjc-cc7w-rv94/GHSA-4wjc-cc7w-rv94.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wjc-cc7w-rv94", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-29815" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aminur Islam WP Change Email Sender allows Stored XSS.This issue affects WP Change Email Sender: from n/a before 1.3.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29815" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-change-email-sender/wordpress-wp-change-email-sender-plugin-1-3-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T12:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-55f2-cvqm-cw4q/GHSA-55f2-cvqm-cw4q.json b/advisories/unreviewed/2024/03/GHSA-55f2-cvqm-cw4q/GHSA-55f2-cvqm-cw4q.json new file mode 100644 index 00000000000..5ea4b7e2871 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-55f2-cvqm-cw4q/GHSA-55f2-cvqm-cw4q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55f2-cvqm-cw4q", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-30180" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Social Feed allows Stored XSS.This issue affects Easy Social Feed: from n/a through 6.5.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30180" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/easy-facebook-likebox/wordpress-easy-social-feed-plugin-6-5-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T12:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5mpf-9786-89gh/GHSA-5mpf-9786-89gh.json b/advisories/unreviewed/2024/03/GHSA-5mpf-9786-89gh/GHSA-5mpf-9786-89gh.json new file mode 100644 index 00000000000..e82d3db1ef3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5mpf-9786-89gh/GHSA-5mpf-9786-89gh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mpf-9786-89gh", + "modified": "2024-03-27T12:30:42Z", + "published": "2024-03-27T12:30:42Z", + "aliases": [ + "CVE-2024-30185" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons allows Stored XSS.This issue affects Element Pack Elementor Addons: from n/a through 5.5.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30185" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bdthemes-element-pack-lite/wordpress-element-pack-elementor-addons-plugin-5-5-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-69q2-pwf5-cf5q/GHSA-69q2-pwf5-cf5q.json b/advisories/unreviewed/2024/03/GHSA-69q2-pwf5-cf5q/GHSA-69q2-pwf5-cf5q.json new file mode 100644 index 00000000000..6ac90be11c4 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-69q2-pwf5-cf5q/GHSA-69q2-pwf5-cf5q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69q2-pwf5-cf5q", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-30177" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30177" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/exclusive-addons-for-elementor/wordpress-exclusive-addons-for-elementor-plugin-2-6-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T11:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-6cxc-vjp6-ff53/GHSA-6cxc-vjp6-ff53.json b/advisories/unreviewed/2024/03/GHSA-6cxc-vjp6-ff53/GHSA-6cxc-vjp6-ff53.json new file mode 100644 index 00000000000..dfa1cec23d7 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6cxc-vjp6-ff53/GHSA-6cxc-vjp6-ff53.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cxc-vjp6-ff53", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-29931" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Go Maps (formerly WP Google Maps) WP Google Maps allows Reflected XSS.This issue affects WP Google Maps: from n/a through 9.0.29.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29931" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-google-maps/wordpress-wp-go-maps-plugin-9-0-29-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7mr5-vq55-2cv2/GHSA-7mr5-vq55-2cv2.json b/advisories/unreviewed/2024/03/GHSA-7mr5-vq55-2cv2/GHSA-7mr5-vq55-2cv2.json new file mode 100644 index 00000000000..1a03b8d8966 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7mr5-vq55-2cv2/GHSA-7mr5-vq55-2cv2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mr5-vq55-2cv2", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-29934" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor allows Stored XSS.This issue affects Piotnet Addons For Elementor: from n/a through 2.4.25.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29934" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/piotnet-addons-for-elementor/wordpress-piotnet-addons-for-elementor-plugin-2-4-25-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T11:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-94hp-8q4r-rqfx/GHSA-94hp-8q4r-rqfx.json b/advisories/unreviewed/2024/03/GHSA-94hp-8q4r-rqfx/GHSA-94hp-8q4r-rqfx.json new file mode 100644 index 00000000000..46d9cec4ed1 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-94hp-8q4r-rqfx/GHSA-94hp-8q4r-rqfx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94hp-8q4r-rqfx", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-29817" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SERVIT Software Solutions affiliate-toolkit allows Stored XSS.This issue affects affiliate-toolkit: from n/a through 3.4.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29817" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/affiliate-toolkit-starter/wordpress-affiliate-toolkit-wordpress-affiliate-plugin-plugin-3-4-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T12:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9wgw-hmc7-9m96/GHSA-9wgw-hmc7-9m96.json b/advisories/unreviewed/2024/03/GHSA-9wgw-hmc7-9m96/GHSA-9wgw-hmc7-9m96.json new file mode 100644 index 00000000000..9abbd8fada1 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9wgw-hmc7-9m96/GHSA-9wgw-hmc7-9m96.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wgw-hmc7-9m96", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-30183" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Livemesh Livemesh Addons for WPBakery Page Builder allows Stored XSS.This issue affects Livemesh Addons for WPBakery Page Builder: from n/a through 3.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30183" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/addons-for-visual-composer/wordpress-wpbakery-page-builder-addons-by-livemesh-plugin-3-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T12:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fqj8-mhv5-gm5f/GHSA-fqj8-mhv5-gm5f.json b/advisories/unreviewed/2024/03/GHSA-fqj8-mhv5-gm5f/GHSA-fqj8-mhv5-gm5f.json new file mode 100644 index 00000000000..fc033248748 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fqj8-mhv5-gm5f/GHSA-fqj8-mhv5-gm5f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqj8-mhv5-gm5f", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-25962" + ], + "details": "Dell InsightIQ, version 5.0, contains an improper access control vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to monitoring data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25962" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000223551/dsa-2024-134-security-update-for-dell-insightiq-for-proprietary-code-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T11:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fwxm-rcr3-5pw6/GHSA-fwxm-rcr3-5pw6.json b/advisories/unreviewed/2024/03/GHSA-fwxm-rcr3-5pw6/GHSA-fwxm-rcr3-5pw6.json new file mode 100644 index 00000000000..ece13a11a1a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fwxm-rcr3-5pw6/GHSA-fwxm-rcr3-5pw6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwxm-rcr3-5pw6", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-30179" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through 4.7.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30179" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bold-page-builder/wordpress-bold-page-builder-plugin-4-7-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-gxjw-hv3q-88gf/GHSA-gxjw-hv3q-88gf.json b/advisories/unreviewed/2024/03/GHSA-gxjw-hv3q-88gf/GHSA-gxjw-hv3q-88gf.json new file mode 100644 index 00000000000..5a0aa5c3d8f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-gxjw-hv3q-88gf/GHSA-gxjw-hv3q-88gf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxjw-hv3q-88gf", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-29930" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CurrencyRate.Today Crypto Converter Widget allows Stored XSS.This issue affects Crypto Converter Widget: from n/a through 1.8.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29930" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/crypto-converter-widget/wordpress-crypto-converter-widget-plugin-1-8-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-hfm4-r5j9-2q25/GHSA-hfm4-r5j9-2q25.json b/advisories/unreviewed/2024/03/GHSA-hfm4-r5j9-2q25/GHSA-hfm4-r5j9-2q25.json new file mode 100644 index 00000000000..81c4853580d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-hfm4-r5j9-2q25/GHSA-hfm4-r5j9-2q25.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfm4-r5j9-2q25", + "modified": "2024-03-27T12:30:42Z", + "published": "2024-03-27T12:30:42Z", + "aliases": [ + "CVE-2024-30186" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Prime Slider – Addons For Elementor allows Stored XSS.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.13.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30186" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bdthemes-prime-slider-lite/wordpress-prime-slider-plugin-3-13-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-jvf9-fjx5-9rv3/GHSA-jvf9-fjx5-9rv3.json b/advisories/unreviewed/2024/03/GHSA-jvf9-fjx5-9rv3/GHSA-jvf9-fjx5-9rv3.json new file mode 100644 index 00000000000..9b5e4ebd5ad --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-jvf9-fjx5-9rv3/GHSA-jvf9-fjx5-9rv3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvf9-fjx5-9rv3", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-30178" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Patrick Posner Simply Static allows Stored XSS.This issue affects Simply Static: from n/a through 3.1.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30178" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/simply-static/wordpress-simply-static-plugin-3-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T11:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-mf26-xjpm-h3gp/GHSA-mf26-xjpm-h3gp.json b/advisories/unreviewed/2024/03/GHSA-mf26-xjpm-h3gp/GHSA-mf26-xjpm-h3gp.json new file mode 100644 index 00000000000..6d5cfa7a73a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-mf26-xjpm-h3gp/GHSA-mf26-xjpm-h3gp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf26-xjpm-h3gp", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-29813" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CartFlows Inc. Funnel Builder by CartFlows allows Stored XSS.This issue affects Funnel Builder by CartFlows: from n/a through 2.0.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29813" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cartflows/wordpress-cartflows-plugin-2-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p2xq-64qm-cf6f/GHSA-p2xq-64qm-cf6f.json b/advisories/unreviewed/2024/03/GHSA-p2xq-64qm-cf6f/GHSA-p2xq-64qm-cf6f.json new file mode 100644 index 00000000000..60f902d5fae --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p2xq-64qm-cf6f/GHSA-p2xq-64qm-cf6f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2xq-64qm-cf6f", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-30182" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega allows Stored XSS.This issue affects HT Mega: from n/a through 2.4.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30182" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ht-mega-for-elementor/wordpress-ht-mega-absolute-addons-for-elementor-plugin-2-4-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T12:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p4h8-v7q2-j29f/GHSA-p4h8-v7q2-j29f.json b/advisories/unreviewed/2024/03/GHSA-p4h8-v7q2-j29f/GHSA-p4h8-v7q2-j29f.json new file mode 100644 index 00000000000..50bc7e04f03 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p4h8-v7q2-j29f/GHSA-p4h8-v7q2-j29f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4h8-v7q2-j29f", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-29933" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab, Inc. Web Icons allows Stored XSS.This issue affects Web Icons: from n/a through 1.0.0.10.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29933" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/icon/wordpress-web-icons-plugin-1-0-0-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T11:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-pw7v-256v-7c4f/GHSA-pw7v-256v-7c4f.json b/advisories/unreviewed/2024/03/GHSA-pw7v-256v-7c4f/GHSA-pw7v-256v-7c4f.json new file mode 100644 index 00000000000..a74f5f73a16 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-pw7v-256v-7c4f/GHSA-pw7v-256v-7c4f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw7v-256v-7c4f", + "modified": "2024-03-27T12:30:40Z", + "published": "2024-03-27T12:30:40Z", + "aliases": [ + "CVE-2024-29929" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WC Lovers WCFM – Frontend Manager for WooCommerce allows Stored XSS.This issue affects WCFM – Frontend Manager for WooCommerce: from n/a through 6.7.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29929" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wc-frontend-manager/wordpress-wcfm-plugin-6-7-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-q24c-736q-gxgj/GHSA-q24c-736q-gxgj.json b/advisories/unreviewed/2024/03/GHSA-q24c-736q-gxgj/GHSA-q24c-736q-gxgj.json new file mode 100644 index 00000000000..2a7ff63a93a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-q24c-736q-gxgj/GHSA-q24c-736q-gxgj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q24c-736q-gxgj", + "modified": "2024-03-27T12:30:42Z", + "published": "2024-03-27T12:30:42Z", + "aliases": [ + "CVE-2024-30184" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Looking Forward Software Incorporated. Popup Builder allows Stored XSS.This issue affects Popup Builder: from n/a through 4.2.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30184" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/popup-builder/wordpress-popup-builder-plugin-4-2-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qf8g-47rf-49pj/GHSA-qf8g-47rf-49pj.json b/advisories/unreviewed/2024/03/GHSA-qf8g-47rf-49pj/GHSA-qf8g-47rf-49pj.json new file mode 100644 index 00000000000..79e28273307 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qf8g-47rf-49pj/GHSA-qf8g-47rf-49pj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qf8g-47rf-49pj", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-30181" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plainware Locatoraid Store Locator allows Stored XSS.This issue affects Locatoraid Store Locator: from n/a through 3.9.30.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30181" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/locatoraid/wordpress-locatoraid-store-locator-plugin-3-9-30-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T12:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qr75-gfvc-2mvw/GHSA-qr75-gfvc-2mvw.json b/advisories/unreviewed/2024/03/GHSA-qr75-gfvc-2mvw/GHSA-qr75-gfvc-2mvw.json new file mode 100644 index 00000000000..aabd2d00c91 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qr75-gfvc-2mvw/GHSA-qr75-gfvc-2mvw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr75-gfvc-2mvw", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-29814" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CurrencyRate.Today Exchange Rates Widget allows Stored XSS.This issue affects Exchange Rates Widget: from n/a through 1.4.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29814" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/exchange-rates-widget/wordpress-exchange-rates-widget-plugin-1-4-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-r88r-x2j2-hw6q/GHSA-r88r-x2j2-hw6q.json b/advisories/unreviewed/2024/03/GHSA-r88r-x2j2-hw6q/GHSA-r88r-x2j2-hw6q.json new file mode 100644 index 00000000000..fa070177e7c --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-r88r-x2j2-hw6q/GHSA-r88r-x2j2-hw6q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r88r-x2j2-hw6q", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-29818" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Maker allows Stored XSS.This issue affects WP Poll Maker: from n/a through 3.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29818" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/epoll-wp-voting/wordpress-wp-poll-maker-plugin-3-1-authenticated-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T12:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vjjj-7w4f-j46m/GHSA-vjjj-7w4f-j46m.json b/advisories/unreviewed/2024/03/GHSA-vjjj-7w4f-j46m/GHSA-vjjj-7w4f-j46m.json new file mode 100644 index 00000000000..dfcfa8caf38 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vjjj-7w4f-j46m/GHSA-vjjj-7w4f-j46m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjjj-7w4f-j46m", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-29935" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SinaExtra Sina Extension for Elementor allows Stored XSS.This issue affects Sina Extension for Elementor: from n/a through 3.5.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29935" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sina-extension-for-elementor/wordpress-sina-extension-for-elementor-plugin-3-5-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T11:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-w4h4-hxwp-c4rm/GHSA-w4h4-hxwp-c4rm.json b/advisories/unreviewed/2024/03/GHSA-w4h4-hxwp-c4rm/GHSA-w4h4-hxwp-c4rm.json new file mode 100644 index 00000000000..03eaed97a0c --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-w4h4-hxwp-c4rm/GHSA-w4h4-hxwp-c4rm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4h4-hxwp-c4rm", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-29819" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syam Mohan WPFront Notification Bar allows Stored XSS.This issue affects WPFront Notification Bar: from n/a through 3.3.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29819" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpfront-notification-bar/wordpress-wpfront-notification-bar-plugin-3-3-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T11:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-w98h-wrpq-r4p5/GHSA-w98h-wrpq-r4p5.json b/advisories/unreviewed/2024/03/GHSA-w98h-wrpq-r4p5/GHSA-w98h-wrpq-r4p5.json new file mode 100644 index 00000000000..9e6b5bcf3c5 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-w98h-wrpq-r4p5/GHSA-w98h-wrpq-r4p5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w98h-wrpq-r4p5", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-29936" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blocksera Image Hover Effects – Elementor Addon allows Stored XSS.This issue affects Image Hover Effects – Elementor Addon: from n/a through 1.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29936" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/image-hover-effects-addon-for-elementor/wordpress-image-hover-effects-elementor-addon-plugin-1-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T11:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-xp3f-f794-84fg/GHSA-xp3f-f794-84fg.json b/advisories/unreviewed/2024/03/GHSA-xp3f-f794-84fg/GHSA-xp3f-f794-84fg.json new file mode 100644 index 00000000000..706a1f946de --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-xp3f-f794-84fg/GHSA-xp3f-f794-84fg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xp3f-f794-84fg", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2023-6173" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeoSOFT Software TeoBASE allows SQL Injection.This issue affects TeoBASE: through 27032024. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6173" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-0238" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-xpgf-pqw3-pcp4/GHSA-xpgf-pqw3-pcp4.json b/advisories/unreviewed/2024/03/GHSA-xpgf-pqw3-pcp4/GHSA-xpgf-pqw3-pcp4.json new file mode 100644 index 00000000000..f063146c511 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-xpgf-pqw3-pcp4/GHSA-xpgf-pqw3-pcp4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpgf-pqw3-pcp4", + "modified": "2024-03-27T12:30:41Z", + "published": "2024-03-27T12:30:41Z", + "aliases": [ + "CVE-2024-29816" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in htdat Woo Viet allows Stored XSS.This issue affects Woo Viet: from n/a through 1.5.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29816" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woo-viet/wordpress-woo-viet-plugin-1-5-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-27T12:15:09Z" + } +} \ No newline at end of file