Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-04-08 18:36:04 +00:00
parent 52cb2e421d
commit 3788dc6a4a
208 changed files with 6165 additions and 58 deletions
@@ -33,7 +33,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-400"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-58wq-p76f-6qjh",
"modified": "2023-01-20T21:30:28Z",
"modified": "2025-04-08T18:34:05Z",
"published": "2023-01-12T15:30:24Z",
"aliases": [
"CVE-2022-3515"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6fr8-22pf-g32x",
"modified": "2023-01-23T15:30:33Z",
"modified": "2025-04-08T18:34:05Z",
"published": "2023-01-12T21:30:30Z",
"aliases": [
"CVE-2022-3977"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mp4c-w7j9-95f4",
"modified": "2023-01-20T21:30:29Z",
"modified": "2025-04-08T18:34:04Z",
"published": "2023-01-12T06:30:24Z",
"aliases": [
"CVE-2022-4345"
@@ -27,6 +27,14 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/02/msg00007.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDZMWIKH3L5JQZC6GSVOJ3N5UXNQPJGQ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGWIW6K64PKC375YAONYXKIVT2FDEDV3"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RDZMWIKH3L5JQZC6GSVOJ3N5UXNQPJGQ"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wv3p-jvhj-v4jc",
"modified": "2023-01-20T15:30:27Z",
"modified": "2025-04-08T18:34:04Z",
"published": "2023-01-12T06:30:23Z",
"aliases": [
"CVE-2022-47927"
@@ -23,10 +23,18 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/07/msg00011.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AP65YEN762IBNQPOYGUVLTQIDLM5XD2A"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AP65YEN762IBNQPOYGUVLTQIDLM5XD2A"
},
{
"type": "WEB",
"url": "https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce%40lists.wikimedia.org/thread/UEMW64LVEH3BEXCJV43CVS6XPYURKWU3"
},
{
"type": "WEB",
"url": "https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/thread/UEMW64LVEH3BEXCJV43CVS6XPYURKWU3"
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-327x-6c4p-8g25",
"modified": "2024-03-29T15:30:28Z",
"modified": "2025-04-08T18:34:07Z",
"published": "2024-03-29T15:30:28Z",
"aliases": [
"CVE-2024-30503"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress Mailster allows Reflected XSS.This issue affects Mailster: from n/a through 4.0.6.\n\n",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EverPress Mailster allows Reflected XSS.This issue affects Mailster: from n/a through 4.0.6.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3vqf-26wq-v77m",
"modified": "2024-03-28T06:30:46Z",
"modified": "2025-04-08T18:34:06Z",
"published": "2024-03-28T06:30:46Z",
"aliases": [
"CVE-2024-30230"
],
"details": "Deserialization of Untrusted Data vulnerability in Acowebs PDF Invoices and Packing Slips For WooCommerce.This issue affects PDF Invoices and Packing Slips For WooCommerce: from n/a through 1.3.7.\n\n",
"details": "Deserialization of Untrusted Data vulnerability in Acowebs PDF Invoices and Packing Slips For WooCommerce.This issue affects PDF Invoices and Packing Slips For WooCommerce: from n/a through 1.3.7.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4gwg-56fg-39pf",
"modified": "2024-03-27T09:30:40Z",
"modified": "2025-04-08T18:34:06Z",
"published": "2024-03-27T09:30:40Z",
"aliases": [
"CVE-2024-30194"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Sunshine Sunshine Photo Cart allows Reflected XSS.This issue affects Sunshine Photo Cart: from n/a through 3.1.1.\n\n",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Sunshine Sunshine Photo Cart allows Reflected XSS.This issue affects Sunshine Photo Cart: from n/a through 3.1.1.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-539g-ppw2-7c4r",
"modified": "2024-03-28T06:30:47Z",
"modified": "2025-04-08T18:34:07Z",
"published": "2024-03-28T06:30:47Z",
"aliases": [
"CVE-2024-29100"
],
"details": "Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.\n\n",
"details": "Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c7mc-vqjx-hc9c",
"modified": "2024-03-28T06:30:46Z",
"modified": "2025-04-08T18:34:06Z",
"published": "2024-03-28T06:30:46Z",
"aliases": [
"CVE-2024-30224"
],
"details": "Deserialization of Untrusted Data vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.2.\n\n",
"details": "Deserialization of Untrusted Data vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.2.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jr8p-29pq-j5wf",
"modified": "2024-03-29T15:30:28Z",
"modified": "2025-04-08T18:34:08Z",
"published": "2024-03-29T15:30:28Z",
"aliases": [
"CVE-2024-30520"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Labib Ahmed Carousel Anything For WPBakery Page Builder allows Stored XSS.This issue affects Carousel Anything For WPBakery Page Builder: from n/a through 2.1.\n\n",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Labib Ahmed Carousel Anything For WPBakery Page Builder allows Stored XSS.This issue affects Carousel Anything For WPBakery Page Builder: from n/a through 2.1.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p2c5-vphq-jrxg",
"modified": "2024-03-29T15:30:31Z",
"modified": "2025-04-08T18:34:08Z",
"published": "2024-03-29T15:30:31Z",
"aliases": [
"CVE-2024-30488"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Katie Seaborn Zotpress.This issue affects Zotpress: from n/a through 7.3.7.\n\n",
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Katie Seaborn Zotpress.This issue affects Zotpress: from n/a through 7.3.7.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pr9j-p6wx-p73x",
"modified": "2024-03-28T06:30:47Z",
"modified": "2025-04-08T18:34:07Z",
"published": "2024-03-28T06:30:47Z",
"aliases": [
"CVE-2024-30221"
],
"details": "Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart.This issue affects Sunshine Photo Cart: from n/a through 3.1.1.\n\n",
"details": "Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart.This issue affects Sunshine Photo Cart: from n/a through 3.1.1.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qw72-jmvh-wj6r",
"modified": "2024-03-28T06:30:46Z",
"modified": "2025-04-08T18:34:06Z",
"published": "2024-03-28T06:30:46Z",
"aliases": [
"CVE-2024-30236"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contest Gallery.This issue affects Contest Gallery: from n/a through 21.3.4.\n\n",
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contest Gallery.This issue affects Contest Gallery: from n/a through 21.3.4.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qxgj-php7-wrw3",
"modified": "2024-03-29T15:30:28Z",
"modified": "2025-04-08T18:34:07Z",
"published": "2024-03-29T15:30:28Z",
"aliases": [
"CVE-2024-30483"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simple Sponsorships Sponsors allows Stored XSS.This issue affects Sponsors: from n/a through 3.5.1.\n\n",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simple Sponsorships Sponsors allows Stored XSS.This issue affects Sponsors: from n/a through 3.5.1.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vxq6-3hh5-mcjj",
"modified": "2024-03-29T15:30:28Z",
"modified": "2025-04-08T18:34:07Z",
"published": "2024-03-29T15:30:28Z",
"aliases": [
"CVE-2024-30519"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lordicon Lordicon Animated Icons allows Stored XSS.This issue affects Lordicon Animated Icons: from n/a through 2.0.1.\n\n",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lordicon Lordicon Animated Icons allows Stored XSS.This issue affects Lordicon Animated Icons: from n/a through 2.0.1.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-27w6-8m77-x3qf",
"modified": "2024-04-10T18:30:47Z",
"modified": "2025-04-08T18:34:11Z",
"published": "2024-04-10T18:30:47Z",
"aliases": [
"CVE-2024-31254"
],
"details": "Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.7.\n\n",
"details": "Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.7.",
"severity": [
{
"type": "CVSS_V3",
@@ -38,6 +38,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22",
"CWE-24"
],
"severity": "MODERATE",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c4qr-mpj2-hxhr",
"modified": "2024-04-12T15:37:21Z",
"modified": "2025-04-08T18:34:11Z",
"published": "2024-04-12T15:37:21Z",
"aliases": [
"CVE-2023-51409"
],
"details": "Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 1.9.98.\n\n",
"details": "Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 1.9.98.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-chwx-r397-6ww4",
"modified": "2024-04-10T18:30:47Z",
"modified": "2025-04-08T18:34:11Z",
"published": "2024-04-10T18:30:47Z",
"aliases": [
"CVE-2024-31245"
],
"details": "Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5.\n\n",
"details": "Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5.",
"severity": [
{
"type": "CVSS_V3",

Some files were not shown because too many files have changed in this diff Show More