diff --git a/advisories/unreviewed/2024/06/GHSA-mgcv-6r68-pw73/GHSA-mgcv-6r68-pw73.json b/advisories/unreviewed/2024/06/GHSA-mgcv-6r68-pw73/GHSA-mgcv-6r68-pw73.json index 3d4e6639fac..643fb261af8 100644 --- a/advisories/unreviewed/2024/06/GHSA-mgcv-6r68-pw73/GHSA-mgcv-6r68-pw73.json +++ b/advisories/unreviewed/2024/06/GHSA-mgcv-6r68-pw73/GHSA-mgcv-6r68-pw73.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mgcv-6r68-pw73", - "modified": "2024-06-25T21:31:16Z", + "modified": "2025-04-05T00:30:25Z", "published": "2024-06-25T21:31:16Z", "aliases": [ "CVE-2024-5276" @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-r2j9-gh64-cp47/GHSA-r2j9-gh64-cp47.json b/advisories/unreviewed/2024/07/GHSA-r2j9-gh64-cp47/GHSA-r2j9-gh64-cp47.json index 010c1b5805f..2efa746008f 100644 --- a/advisories/unreviewed/2024/07/GHSA-r2j9-gh64-cp47/GHSA-r2j9-gh64-cp47.json +++ b/advisories/unreviewed/2024/07/GHSA-r2j9-gh64-cp47/GHSA-r2j9-gh64-cp47.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r2j9-gh64-cp47", - "modified": "2024-07-20T09:30:36Z", + "modified": "2025-04-05T00:30:26Z", "published": "2024-07-20T09:30:36Z", "aliases": [ "CVE-2024-6497" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6497" }, + { + "type": "WEB", + "url": "https://nowotarski.info/wordpress-nonce-authorization" + }, { "type": "WEB", "url": "https://plugins.trac.wordpress.org/browser/squirrly-seo/trunk/controllers/Api.php#L267" @@ -38,6 +42,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-89" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/10/GHSA-79wf-qgrg-2p6c/GHSA-79wf-qgrg-2p6c.json b/advisories/unreviewed/2024/10/GHSA-79wf-qgrg-2p6c/GHSA-79wf-qgrg-2p6c.json index 6d506011aca..85f4bab2eb1 100644 --- a/advisories/unreviewed/2024/10/GHSA-79wf-qgrg-2p6c/GHSA-79wf-qgrg-2p6c.json +++ b/advisories/unreviewed/2024/10/GHSA-79wf-qgrg-2p6c/GHSA-79wf-qgrg-2p6c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-79wf-qgrg-2p6c", - "modified": "2024-10-30T21:30:38Z", + "modified": "2025-04-05T00:30:26Z", "published": "2024-10-27T06:30:47Z", "aliases": [ "CVE-2024-50602" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/libexpat/libexpat/pull/915" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250404-0008" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-ph84-rcj2-fxxm/GHSA-ph84-rcj2-fxxm.json b/advisories/unreviewed/2024/12/GHSA-ph84-rcj2-fxxm/GHSA-ph84-rcj2-fxxm.json index 890fca5d609..04c591b675e 100644 --- a/advisories/unreviewed/2024/12/GHSA-ph84-rcj2-fxxm/GHSA-ph84-rcj2-fxxm.json +++ b/advisories/unreviewed/2024/12/GHSA-ph84-rcj2-fxxm/GHSA-ph84-rcj2-fxxm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ph84-rcj2-fxxm", - "modified": "2025-01-31T21:32:44Z", + "modified": "2025-04-05T00:30:26Z", "published": "2024-12-06T18:30:45Z", "aliases": [ "CVE-2024-12254" @@ -47,6 +47,10 @@ "type": "WEB", "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/H4O3UBAOAQQXGT4RE3E4XQYR5XLROORB" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250404-0010" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/12/06/1" diff --git a/advisories/unreviewed/2025/02/GHSA-3frg-24qp-xxv2/GHSA-3frg-24qp-xxv2.json b/advisories/unreviewed/2025/02/GHSA-3frg-24qp-xxv2/GHSA-3frg-24qp-xxv2.json index 476e3c33a54..361c2c8e663 100644 --- a/advisories/unreviewed/2025/02/GHSA-3frg-24qp-xxv2/GHSA-3frg-24qp-xxv2.json +++ b/advisories/unreviewed/2025/02/GHSA-3frg-24qp-xxv2/GHSA-3frg-24qp-xxv2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3frg-24qp-xxv2", - "modified": "2025-02-10T21:31:39Z", + "modified": "2025-04-05T00:30:27Z", "published": "2025-02-10T21:31:39Z", "aliases": [ "CVE-2025-1153" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1153" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250404-0005" + }, { "type": "WEB", "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32603" diff --git a/advisories/unreviewed/2025/02/GHSA-73x9-xqqp-w963/GHSA-73x9-xqqp-w963.json b/advisories/unreviewed/2025/02/GHSA-73x9-xqqp-w963/GHSA-73x9-xqqp-w963.json index d6262df84e6..7325a960e08 100644 --- a/advisories/unreviewed/2025/02/GHSA-73x9-xqqp-w963/GHSA-73x9-xqqp-w963.json +++ b/advisories/unreviewed/2025/02/GHSA-73x9-xqqp-w963/GHSA-73x9-xqqp-w963.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-73x9-xqqp-w963", - "modified": "2025-02-10T15:32:22Z", + "modified": "2025-04-05T00:30:26Z", "published": "2025-02-10T15:32:22Z", "aliases": [ "CVE-2025-1147" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1147" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250404-0003" + }, { "type": "WEB", "url": "https://sourceware.org/bugzilla/attachment.cgi?id=15881" @@ -50,7 +54,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-gqj6-fppc-vr34/GHSA-gqj6-fppc-vr34.json b/advisories/unreviewed/2025/02/GHSA-gqj6-fppc-vr34/GHSA-gqj6-fppc-vr34.json index 99425c874b6..5940236394a 100644 --- a/advisories/unreviewed/2025/02/GHSA-gqj6-fppc-vr34/GHSA-gqj6-fppc-vr34.json +++ b/advisories/unreviewed/2025/02/GHSA-gqj6-fppc-vr34/GHSA-gqj6-fppc-vr34.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gqj6-fppc-vr34", - "modified": "2025-02-10T15:32:22Z", + "modified": "2025-04-05T00:30:27Z", "published": "2025-02-10T15:32:22Z", "aliases": [ "CVE-2025-1148" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1148" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250404-0004" + }, { "type": "WEB", "url": "https://sourceware.org/bugzilla/attachment.cgi?id=15887" diff --git a/advisories/unreviewed/2025/04/GHSA-rp6w-32qw-r275/GHSA-rp6w-32qw-r275.json b/advisories/unreviewed/2025/04/GHSA-rp6w-32qw-r275/GHSA-rp6w-32qw-r275.json new file mode 100644 index 00000000000..1af0e35ac9c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rp6w-32qw-r275/GHSA-rp6w-32qw-r275.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rp6w-32qw-r275", + "modified": "2025-04-05T00:30:27Z", + "published": "2025-04-05T00:30:27Z", + "aliases": [ + "CVE-2025-2889" + ], + "details": "The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Additional Parameters in all versions up to, and including, 7.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2889" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/link-library/tags/7.7.3/link-library-admin.php#L7610" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0881efbe-9b47-4b56-be2d-12258460b429?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-05T00:15:15Z" + } +} \ No newline at end of file