diff --git a/advisories/unreviewed/2025/04/GHSA-23pg-v644-m29h/GHSA-23pg-v644-m29h.json b/advisories/unreviewed/2025/04/GHSA-23pg-v644-m29h/GHSA-23pg-v644-m29h.json new file mode 100644 index 00000000000..426d410c97a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-23pg-v644-m29h/GHSA-23pg-v644-m29h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23pg-v644-m29h", + "modified": "2025-04-01T06:30:44Z", + "published": "2025-04-01T06:30:44Z", + "aliases": [ + "CVE-2025-0416" + ], + "details": "Local privilege escalation through insecure DCOM configuration in Valmet DNA versions prior to C2023. The DCOM object Valmet DNA Engineering has permissions that allow it to run commands as a user with the SeImpersonatePrivilege privilege. The SeImpersonatePrivilege privilege is a Windows permission that allows a process to impersonate another user. An attacker can use this vulnerability to escalate their privileges and take complete control of the system.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:H/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0416" + }, + { + "type": "WEB", + "url": "https://www.valmet.com/about-us/about/research-and-development/vulnerabilityadvisories/cve-2025-0416" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T04:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-28ch-w3c2-xg68/GHSA-28ch-w3c2-xg68.json b/advisories/unreviewed/2025/04/GHSA-28ch-w3c2-xg68/GHSA-28ch-w3c2-xg68.json index d3765b59063..5d4def13edf 100644 --- a/advisories/unreviewed/2025/04/GHSA-28ch-w3c2-xg68/GHSA-28ch-w3c2-xg68.json +++ b/advisories/unreviewed/2025/04/GHSA-28ch-w3c2-xg68/GHSA-28ch-w3c2-xg68.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-28ch-w3c2-xg68", - "modified": "2025-04-01T00:30:35Z", + "modified": "2025-04-01T06:30:40Z", "published": "2025-04-01T00:30:35Z", "aliases": [ "CVE-2025-24097" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, tvOS 18.4, macOS Sequoia 15.4. An app may be able to read arbitrary file metadata.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:16Z" diff --git a/advisories/unreviewed/2025/04/GHSA-2cp9-r2rg-qvgg/GHSA-2cp9-r2rg-qvgg.json b/advisories/unreviewed/2025/04/GHSA-2cp9-r2rg-qvgg/GHSA-2cp9-r2rg-qvgg.json new file mode 100644 index 00000000000..dc71660cd76 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2cp9-r2rg-qvgg/GHSA-2cp9-r2rg-qvgg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cp9-r2rg-qvgg", + "modified": "2025-04-01T06:30:44Z", + "published": "2025-04-01T06:30:44Z", + "aliases": [ + "CVE-2025-1534" + ], + "details": "CVE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Payara Platform Payara Server allows : Remote Code Inclusion.This issue affects Payara Server: from 4.1.2.1919.1 before 4.1.2.191.51, from 5.20.0 before 5.68.0, from 6.0.0 before 6.23.0, from 6.2022.1 before 6.2025.2.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1534" + }, + { + "type": "WEB", + "url": "https://docs.payara.fish/community/docs/6.2025.3/Release%20Notes/Release%20Notes%206.2025.3.html" + }, + { + "type": "WEB", + "url": "https://docs.payara.fish/enterprise/docs/Release%20Notes/Release%20Notes%206.24.0.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T04:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2f88-2r9h-hx4p/GHSA-2f88-2r9h-hx4p.json b/advisories/unreviewed/2025/04/GHSA-2f88-2r9h-hx4p/GHSA-2f88-2r9h-hx4p.json index e3f79e78b8c..e00204950a7 100644 --- a/advisories/unreviewed/2025/04/GHSA-2f88-2r9h-hx4p/GHSA-2f88-2r9h-hx4p.json +++ b/advisories/unreviewed/2025/04/GHSA-2f88-2r9h-hx4p/GHSA-2f88-2r9h-hx4p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2f88-2r9h-hx4p", - "modified": "2025-04-01T00:30:38Z", + "modified": "2025-04-01T06:30:40Z", "published": "2025-04-01T00:30:38Z", "aliases": [ "CVE-2025-24235" ], "details": "A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A remote attacker may be able to cause unexpected app termination or heap corruption.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-2mc3-h3h3-g4xq/GHSA-2mc3-h3h3-g4xq.json b/advisories/unreviewed/2025/04/GHSA-2mc3-h3h3-g4xq/GHSA-2mc3-h3h3-g4xq.json new file mode 100644 index 00000000000..207177f4e42 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2mc3-h3h3-g4xq/GHSA-2mc3-h3h3-g4xq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mc3-h3h3-g4xq", + "modified": "2025-04-01T06:30:47Z", + "published": "2025-04-01T06:30:47Z", + "aliases": [ + "CVE-2025-30882" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk allows Path Traversal. This issue affects JS Help Desk: from n/a through 2.9.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30882" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/js-support-ticket/vulnerability/wordpress-js-help-desk-plugin-2-9-1-arbitrary-file-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2w35-685f-3mpc/GHSA-2w35-685f-3mpc.json b/advisories/unreviewed/2025/04/GHSA-2w35-685f-3mpc/GHSA-2w35-685f-3mpc.json index b37066b141a..29d930dcdc9 100644 --- a/advisories/unreviewed/2025/04/GHSA-2w35-685f-3mpc/GHSA-2w35-685f-3mpc.json +++ b/advisories/unreviewed/2025/04/GHSA-2w35-685f-3mpc/GHSA-2w35-685f-3mpc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2w35-685f-3mpc", - "modified": "2025-04-01T00:30:41Z", + "modified": "2025-04-01T06:30:43Z", "published": "2025-04-01T00:30:41Z", "aliases": [ "CVE-2025-24279" ], "details": "This issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access contacts.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-3286-4p8w-f9gp/GHSA-3286-4p8w-f9gp.json b/advisories/unreviewed/2025/04/GHSA-3286-4p8w-f9gp/GHSA-3286-4p8w-f9gp.json index 89cd8308ea7..d548aa4dcc3 100644 --- a/advisories/unreviewed/2025/04/GHSA-3286-4p8w-f9gp/GHSA-3286-4p8w-f9gp.json +++ b/advisories/unreviewed/2025/04/GHSA-3286-4p8w-f9gp/GHSA-3286-4p8w-f9gp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3286-4p8w-f9gp", - "modified": "2025-04-01T00:30:35Z", + "modified": "2025-04-01T06:30:39Z", "published": "2025-04-01T00:30:35Z", "aliases": [ "CVE-2024-40864" ], "details": "The issue was addressed with improved handling of protocols. This issue is fixed in macOS Ventura 13.7.5, macOS Sonoma 14.7.5. An attacker in a privileged network position can track a user's activity.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:15Z" diff --git a/advisories/unreviewed/2025/04/GHSA-3f9w-j677-96fc/GHSA-3f9w-j677-96fc.json b/advisories/unreviewed/2025/04/GHSA-3f9w-j677-96fc/GHSA-3f9w-j677-96fc.json new file mode 100644 index 00000000000..9871ae399a0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3f9w-j677-96fc/GHSA-3f9w-j677-96fc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3f9w-j677-96fc", + "modified": "2025-04-01T06:30:45Z", + "published": "2025-04-01T06:30:45Z", + "aliases": [ + "CVE-2025-30607" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Name.ly Quick Localization allows Reflected XSS. This issue affects Quick Localization: from n/a through 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30607" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quick-localization/vulnerability/wordpress-quick-localization-plugin-0-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3fv4-r47x-rg42/GHSA-3fv4-r47x-rg42.json b/advisories/unreviewed/2025/04/GHSA-3fv4-r47x-rg42/GHSA-3fv4-r47x-rg42.json new file mode 100644 index 00000000000..c739e80dff9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3fv4-r47x-rg42/GHSA-3fv4-r47x-rg42.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fv4-r47x-rg42", + "modified": "2025-04-01T06:30:45Z", + "published": "2025-04-01T06:30:45Z", + "aliases": [ + "CVE-2025-30622" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in torsteino PostMash allows SQL Injection. This issue affects PostMash: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30622" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/postmash-custom/vulnerability/wordpress-postmash-1-0-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3h6v-4pff-pgf4/GHSA-3h6v-4pff-pgf4.json b/advisories/unreviewed/2025/04/GHSA-3h6v-4pff-pgf4/GHSA-3h6v-4pff-pgf4.json index 6ae554c2ed3..c352dd0ceef 100644 --- a/advisories/unreviewed/2025/04/GHSA-3h6v-4pff-pgf4/GHSA-3h6v-4pff-pgf4.json +++ b/advisories/unreviewed/2025/04/GHSA-3h6v-4pff-pgf4/GHSA-3h6v-4pff-pgf4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3h6v-4pff-pgf4", - "modified": "2025-04-01T00:30:36Z", + "modified": "2025-04-01T06:30:40Z", "published": "2025-04-01T00:30:36Z", "aliases": [ "CVE-2025-24167" ], "details": "This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A download's origin may be incorrectly associated.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:16Z" diff --git a/advisories/unreviewed/2025/04/GHSA-3jwh-25gj-xrgf/GHSA-3jwh-25gj-xrgf.json b/advisories/unreviewed/2025/04/GHSA-3jwh-25gj-xrgf/GHSA-3jwh-25gj-xrgf.json new file mode 100644 index 00000000000..df494b3c900 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3jwh-25gj-xrgf/GHSA-3jwh-25gj-xrgf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jwh-25gj-xrgf", + "modified": "2025-04-01T06:30:46Z", + "published": "2025-04-01T06:30:45Z", + "aliases": [ + "CVE-2025-30794" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Events Calendar Event Tickets allows Reflected XSS. This issue affects Event Tickets: from n/a through 5.20.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30794" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/event-tickets/vulnerability/wordpress-event-tickets-plugin-5-20-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3vmq-cr85-65gq/GHSA-3vmq-cr85-65gq.json b/advisories/unreviewed/2025/04/GHSA-3vmq-cr85-65gq/GHSA-3vmq-cr85-65gq.json new file mode 100644 index 00000000000..1a1db59565c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3vmq-cr85-65gq/GHSA-3vmq-cr85-65gq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vmq-cr85-65gq", + "modified": "2025-04-01T06:30:48Z", + "published": "2025-04-01T06:30:48Z", + "aliases": [ + "CVE-2025-31084" + ], + "details": "Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart allows Object Injection. This issue affects Sunshine Photo Cart: from n/a through 3.4.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31084" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sunshine-photo-cart/vulnerability/wordpress-sunshine-photo-cart-3-4-10-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4p87-w32h-vjhw/GHSA-4p87-w32h-vjhw.json b/advisories/unreviewed/2025/04/GHSA-4p87-w32h-vjhw/GHSA-4p87-w32h-vjhw.json new file mode 100644 index 00000000000..5d4254691b7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4p87-w32h-vjhw/GHSA-4p87-w32h-vjhw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p87-w32h-vjhw", + "modified": "2025-04-01T06:30:47Z", + "published": "2025-04-01T06:30:47Z", + "aliases": [ + "CVE-2025-30902" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ATL Software SRL AEC Kiosque allows Reflected XSS. This issue affects AEC Kiosque: from n/a through 1.9.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30902" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/aec-kiosque/vulnerability/wordpress-aec-kiosque-plugin-1-9-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4r7q-g5mr-63x8/GHSA-4r7q-g5mr-63x8.json b/advisories/unreviewed/2025/04/GHSA-4r7q-g5mr-63x8/GHSA-4r7q-g5mr-63x8.json index 935a9c86c22..6ac8c8fa24a 100644 --- a/advisories/unreviewed/2025/04/GHSA-4r7q-g5mr-63x8/GHSA-4r7q-g5mr-63x8.json +++ b/advisories/unreviewed/2025/04/GHSA-4r7q-g5mr-63x8/GHSA-4r7q-g5mr-63x8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4r7q-g5mr-63x8", - "modified": "2025-04-01T00:30:42Z", + "modified": "2025-04-01T06:30:43Z", "published": "2025-04-01T00:30:42Z", "aliases": [ "CVE-2025-30451" ], "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:26Z" diff --git a/advisories/unreviewed/2025/04/GHSA-4rxj-2g88-h4fp/GHSA-4rxj-2g88-h4fp.json b/advisories/unreviewed/2025/04/GHSA-4rxj-2g88-h4fp/GHSA-4rxj-2g88-h4fp.json index 254eeb2de07..d8efd924259 100644 --- a/advisories/unreviewed/2025/04/GHSA-4rxj-2g88-h4fp/GHSA-4rxj-2g88-h4fp.json +++ b/advisories/unreviewed/2025/04/GHSA-4rxj-2g88-h4fp/GHSA-4rxj-2g88-h4fp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4rxj-2g88-h4fp", - "modified": "2025-04-01T00:30:41Z", + "modified": "2025-04-01T06:30:43Z", "published": "2025-04-01T00:30:41Z", "aliases": [ "CVE-2025-24280" ], "details": "An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access user-sensitive data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-523x-xm4x-3xxw/GHSA-523x-xm4x-3xxw.json b/advisories/unreviewed/2025/04/GHSA-523x-xm4x-3xxw/GHSA-523x-xm4x-3xxw.json new file mode 100644 index 00000000000..6a5a8a41b25 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-523x-xm4x-3xxw/GHSA-523x-xm4x-3xxw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-523x-xm4x-3xxw", + "modified": "2025-04-01T06:30:46Z", + "published": "2025-04-01T06:30:46Z", + "aliases": [ + "CVE-2025-30798" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rickonline_nl Better WishList API allows Reflected XSS. This issue affects Better WishList API: from n/a through 1.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30798" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/better-wlm-api/vulnerability/wordpress-better-wishlist-api-plugin-1-1-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5278-2h8h-4p7c/GHSA-5278-2h8h-4p7c.json b/advisories/unreviewed/2025/04/GHSA-5278-2h8h-4p7c/GHSA-5278-2h8h-4p7c.json new file mode 100644 index 00000000000..88e88c14f79 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5278-2h8h-4p7c/GHSA-5278-2h8h-4p7c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5278-2h8h-4p7c", + "modified": "2025-04-01T06:30:46Z", + "published": "2025-04-01T06:30:46Z", + "aliases": [ + "CVE-2025-30849" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Essential Real Estate allows PHP Local File Inclusion. This issue affects Essential Real Estate: from n/a through 5.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30849" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/essential-real-estate/vulnerability/wordpress-essential-real-estate-plugin-5-2-0-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-567g-2w6m-m2jv/GHSA-567g-2w6m-m2jv.json b/advisories/unreviewed/2025/04/GHSA-567g-2w6m-m2jv/GHSA-567g-2w6m-m2jv.json new file mode 100644 index 00000000000..ad20f4576ea --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-567g-2w6m-m2jv/GHSA-567g-2w6m-m2jv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-567g-2w6m-m2jv", + "modified": "2025-04-01T06:30:46Z", + "published": "2025-04-01T06:30:46Z", + "aliases": [ + "CVE-2025-30848" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel allows Reflected XSS. This issue affects Hostel: from n/a through 1.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30848" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hostel/vulnerability/wordpress-hostel-plugin-1-1-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-56x3-c3f3-5345/GHSA-56x3-c3f3-5345.json b/advisories/unreviewed/2025/04/GHSA-56x3-c3f3-5345/GHSA-56x3-c3f3-5345.json index 4a9c8bfac1c..963a2e3c1ca 100644 --- a/advisories/unreviewed/2025/04/GHSA-56x3-c3f3-5345/GHSA-56x3-c3f3-5345.json +++ b/advisories/unreviewed/2025/04/GHSA-56x3-c3f3-5345/GHSA-56x3-c3f3-5345.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-56x3-c3f3-5345", - "modified": "2025-04-01T00:30:38Z", + "modified": "2025-04-01T06:30:40Z", "published": "2025-04-01T00:30:38Z", "aliases": [ "CVE-2025-24234" ], "details": "This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to gain root privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-5cgr-6hjx-88v5/GHSA-5cgr-6hjx-88v5.json b/advisories/unreviewed/2025/04/GHSA-5cgr-6hjx-88v5/GHSA-5cgr-6hjx-88v5.json index d3f788269e4..a03042750cf 100644 --- a/advisories/unreviewed/2025/04/GHSA-5cgr-6hjx-88v5/GHSA-5cgr-6hjx-88v5.json +++ b/advisories/unreviewed/2025/04/GHSA-5cgr-6hjx-88v5/GHSA-5cgr-6hjx-88v5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5cgr-6hjx-88v5", - "modified": "2025-04-01T00:30:40Z", + "modified": "2025-04-01T06:30:41Z", "published": "2025-04-01T00:30:40Z", "aliases": [ "CVE-2025-24259" ], "details": "This issue was addressed with additional entitlement checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:22Z" diff --git a/advisories/unreviewed/2025/04/GHSA-5h6v-gcfg-p36f/GHSA-5h6v-gcfg-p36f.json b/advisories/unreviewed/2025/04/GHSA-5h6v-gcfg-p36f/GHSA-5h6v-gcfg-p36f.json new file mode 100644 index 00000000000..c27d8fdef94 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5h6v-gcfg-p36f/GHSA-5h6v-gcfg-p36f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h6v-gcfg-p36f", + "modified": "2025-04-01T06:30:46Z", + "published": "2025-04-01T06:30:46Z", + "aliases": [ + "CVE-2025-30840" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup dev xili-dictionary allows Reflected XSS. This issue affects xili-dictionary: from n/a through 2.12.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30840" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/xili-dictionary/vulnerability/wordpress-xili-dictionary-plugin-2-12-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5hc2-q9h7-36hr/GHSA-5hc2-q9h7-36hr.json b/advisories/unreviewed/2025/04/GHSA-5hc2-q9h7-36hr/GHSA-5hc2-q9h7-36hr.json new file mode 100644 index 00000000000..a6339ee34c9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5hc2-q9h7-36hr/GHSA-5hc2-q9h7-36hr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hc2-q9h7-36hr", + "modified": "2025-04-01T06:30:44Z", + "published": "2025-04-01T06:30:44Z", + "aliases": [ + "CVE-2025-30520" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in crosstec Breezing Forms allows Reflected XSS. This issue affects Breezing Forms: from n/a through 1.2.8.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30520" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/breezing-forms/vulnerability/wordpress-breezing-forms-plugin-1-2-8-11-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5qvg-xp2f-fp45/GHSA-5qvg-xp2f-fp45.json b/advisories/unreviewed/2025/04/GHSA-5qvg-xp2f-fp45/GHSA-5qvg-xp2f-fp45.json index 06e65c2f510..280eb4d75b2 100644 --- a/advisories/unreviewed/2025/04/GHSA-5qvg-xp2f-fp45/GHSA-5qvg-xp2f-fp45.json +++ b/advisories/unreviewed/2025/04/GHSA-5qvg-xp2f-fp45/GHSA-5qvg-xp2f-fp45.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5qvg-xp2f-fp45", - "modified": "2025-04-01T00:30:44Z", + "modified": "2025-04-01T06:30:44Z", "published": "2025-04-01T00:30:44Z", "aliases": [ "CVE-2025-30470" ], "details": "A path handling issue was addressed with improved logic. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to read sensitive location information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:28Z" diff --git a/advisories/unreviewed/2025/04/GHSA-62f2-58pp-q2wg/GHSA-62f2-58pp-q2wg.json b/advisories/unreviewed/2025/04/GHSA-62f2-58pp-q2wg/GHSA-62f2-58pp-q2wg.json index 1c8e9b06daf..8fc848ca199 100644 --- a/advisories/unreviewed/2025/04/GHSA-62f2-58pp-q2wg/GHSA-62f2-58pp-q2wg.json +++ b/advisories/unreviewed/2025/04/GHSA-62f2-58pp-q2wg/GHSA-62f2-58pp-q2wg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-62f2-58pp-q2wg", - "modified": "2025-04-01T00:30:41Z", + "modified": "2025-04-01T06:30:43Z", "published": "2025-04-01T00:30:41Z", "aliases": [ "CVE-2025-30427" ], "details": "A use-after-free issue was addressed with improved memory management. This issue is fixed in visionOS 2.4, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, Safari 18.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:25Z" diff --git a/advisories/unreviewed/2025/04/GHSA-6cfv-73h4-f63c/GHSA-6cfv-73h4-f63c.json b/advisories/unreviewed/2025/04/GHSA-6cfv-73h4-f63c/GHSA-6cfv-73h4-f63c.json new file mode 100644 index 00000000000..02e3ff0b304 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6cfv-73h4-f63c/GHSA-6cfv-73h4-f63c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cfv-73h4-f63c", + "modified": "2025-04-01T06:30:44Z", + "published": "2025-04-01T06:30:44Z", + "aliases": [ + "CVE-2025-30548" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VarDump s.r.l. Advanced Post Search allows Reflected XSS. This issue affects Advanced Post Search: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30548" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-post-search/vulnerability/wordpress-advanced-post-search-plugin-1-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6frf-vfxm-qwfx/GHSA-6frf-vfxm-qwfx.json b/advisories/unreviewed/2025/04/GHSA-6frf-vfxm-qwfx/GHSA-6frf-vfxm-qwfx.json new file mode 100644 index 00000000000..e08a3a4799c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6frf-vfxm-qwfx/GHSA-6frf-vfxm-qwfx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6frf-vfxm-qwfx", + "modified": "2025-04-01T06:30:47Z", + "published": "2025-04-01T06:30:47Z", + "aliases": [ + "CVE-2025-30924" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in primersoftware Primer MyData for Woocommerce allows Reflected XSS. This issue affects Primer MyData for Woocommerce: from n/a through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30924" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/primer-mydata/vulnerability/wordpress-primer-mydata-for-woocommerce-plugin-4-2-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6j5v-mrj8-gc92/GHSA-6j5v-mrj8-gc92.json b/advisories/unreviewed/2025/04/GHSA-6j5v-mrj8-gc92/GHSA-6j5v-mrj8-gc92.json new file mode 100644 index 00000000000..9f7a200a566 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6j5v-mrj8-gc92/GHSA-6j5v-mrj8-gc92.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j5v-mrj8-gc92", + "modified": "2025-04-01T06:30:46Z", + "published": "2025-04-01T06:30:46Z", + "aliases": [ + "CVE-2025-30802" + ], + "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPBean Our Team Members. This issue affects Our Team Members: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30802" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/our-team-members/vulnerability/wordpress-our-team-members-plugin-2-2-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6vwx-w44x-jp9q/GHSA-6vwx-w44x-jp9q.json b/advisories/unreviewed/2025/04/GHSA-6vwx-w44x-jp9q/GHSA-6vwx-w44x-jp9q.json new file mode 100644 index 00000000000..765b759d5d3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6vwx-w44x-jp9q/GHSA-6vwx-w44x-jp9q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vwx-w44x-jp9q", + "modified": "2025-04-01T06:30:48Z", + "published": "2025-04-01T06:30:48Z", + "aliases": [ + "CVE-2025-31024" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in randyjensen RJ Quickcharts allows SQL Injection. This issue affects RJ Quickcharts: from n/a through 0.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31024" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rj-quickcharts/vulnerability/wordpress-rj-quickcharts-plugin-0-6-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6x3m-r98v-pgc4/GHSA-6x3m-r98v-pgc4.json b/advisories/unreviewed/2025/04/GHSA-6x3m-r98v-pgc4/GHSA-6x3m-r98v-pgc4.json index 12d94dfcbf2..b10a1ca58d0 100644 --- a/advisories/unreviewed/2025/04/GHSA-6x3m-r98v-pgc4/GHSA-6x3m-r98v-pgc4.json +++ b/advisories/unreviewed/2025/04/GHSA-6x3m-r98v-pgc4/GHSA-6x3m-r98v-pgc4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6x3m-r98v-pgc4", - "modified": "2025-04-01T00:30:41Z", + "modified": "2025-04-01T06:30:43Z", "published": "2025-04-01T00:30:41Z", "aliases": [ "CVE-2025-24281" ], "details": "This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-72mh-368w-4q93/GHSA-72mh-368w-4q93.json b/advisories/unreviewed/2025/04/GHSA-72mh-368w-4q93/GHSA-72mh-368w-4q93.json new file mode 100644 index 00000000000..adb54976f12 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-72mh-368w-4q93/GHSA-72mh-368w-4q93.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72mh-368w-4q93", + "modified": "2025-04-01T06:30:48Z", + "published": "2025-04-01T06:30:48Z", + "aliases": [ + "CVE-2025-31001" + ], + "details": "Debug Messages Revealing Unnecessary Information vulnerability in TLA Media GTM Kit allows Retrieve Embedded Sensitive Data. This issue affects GTM Kit: from n/a through 2.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31001" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gtm-kit/vulnerability/wordpress-gtm-kit-plugin-2-3-1-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1295" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7345-q82m-2h46/GHSA-7345-q82m-2h46.json b/advisories/unreviewed/2025/04/GHSA-7345-q82m-2h46/GHSA-7345-q82m-2h46.json index 1ced5e4394f..cfe75056d4d 100644 --- a/advisories/unreviewed/2025/04/GHSA-7345-q82m-2h46/GHSA-7345-q82m-2h46.json +++ b/advisories/unreviewed/2025/04/GHSA-7345-q82m-2h46/GHSA-7345-q82m-2h46.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7345-q82m-2h46", - "modified": "2025-04-01T00:30:41Z", + "modified": "2025-04-01T06:30:43Z", "published": "2025-04-01T00:30:41Z", "aliases": [ "CVE-2025-30426" ], "details": "This issue was addressed with additional entitlement checks. This issue is fixed in visionOS 2.4, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to enumerate a user's installed apps.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-78vh-6phv-92x4/GHSA-78vh-6phv-92x4.json b/advisories/unreviewed/2025/04/GHSA-78vh-6phv-92x4/GHSA-78vh-6phv-92x4.json new file mode 100644 index 00000000000..edb06ffb6af --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-78vh-6phv-92x4/GHSA-78vh-6phv-92x4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78vh-6phv-92x4", + "modified": "2025-04-01T06:30:47Z", + "published": "2025-04-01T06:30:47Z", + "aliases": [ + "CVE-2025-30880" + ], + "details": "Missing Authorization vulnerability in JoomSky JS Help Desk allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JS Help Desk: from n/a through 2.9.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30880" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/js-support-ticket/vulnerability/wordpress-js-help-desk-plugin-2-9-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-79j4-wmqh-mc63/GHSA-79j4-wmqh-mc63.json b/advisories/unreviewed/2025/04/GHSA-79j4-wmqh-mc63/GHSA-79j4-wmqh-mc63.json new file mode 100644 index 00000000000..190444c180b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-79j4-wmqh-mc63/GHSA-79j4-wmqh-mc63.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79j4-wmqh-mc63", + "modified": "2025-04-01T06:30:48Z", + "published": "2025-04-01T06:30:48Z", + "aliases": [ + "CVE-2025-31074" + ], + "details": "Deserialization of Untrusted Data vulnerability in MDJM MDJM Event Management allows Object Injection. This issue affects MDJM Event Management: from n/a through 1.7.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31074" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mobile-dj-manager/vulnerability/wordpress-mdjm-event-management-plugin-1-7-5-2-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7cf8-v985-h6fc/GHSA-7cf8-v985-h6fc.json b/advisories/unreviewed/2025/04/GHSA-7cf8-v985-h6fc/GHSA-7cf8-v985-h6fc.json new file mode 100644 index 00000000000..e2faa85165e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7cf8-v985-h6fc/GHSA-7cf8-v985-h6fc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cf8-v985-h6fc", + "modified": "2025-04-01T06:30:45Z", + "published": "2025-04-01T06:30:45Z", + "aliases": [ + "CVE-2025-30544" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound OK Poster Group allows Reflected XSS. This issue affects OK Poster Group: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30544" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ok-poster-group/vulnerability/wordpress-ok-poster-group-plugin-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7m69-vxfr-pm89/GHSA-7m69-vxfr-pm89.json b/advisories/unreviewed/2025/04/GHSA-7m69-vxfr-pm89/GHSA-7m69-vxfr-pm89.json new file mode 100644 index 00000000000..1c38dd95d02 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7m69-vxfr-pm89/GHSA-7m69-vxfr-pm89.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m69-vxfr-pm89", + "modified": "2025-04-01T06:30:45Z", + "published": "2025-04-01T06:30:45Z", + "aliases": [ + "CVE-2025-30559" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Kento WordPress Stats allows Stored XSS. This issue affects Kento WordPress Stats: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30559" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/kento-wp-stats/vulnerability/wordpress-kento-wordpress-stats-plugin-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7rj9-647c-4v52/GHSA-7rj9-647c-4v52.json b/advisories/unreviewed/2025/04/GHSA-7rj9-647c-4v52/GHSA-7rj9-647c-4v52.json new file mode 100644 index 00000000000..9956700bbc4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7rj9-647c-4v52/GHSA-7rj9-647c-4v52.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rj9-647c-4v52", + "modified": "2025-04-01T06:30:47Z", + "published": "2025-04-01T06:30:47Z", + "aliases": [ + "CVE-2025-30971" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xavi Ivars XV Random Quotes allows SQL Injection. This issue affects XV Random Quotes: from n/a through 1.40.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30971" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/xv-random-quotes/vulnerability/wordpress-xv-random-quotes-plugin-1-40-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7vcj-mh9g-5wj9/GHSA-7vcj-mh9g-5wj9.json b/advisories/unreviewed/2025/04/GHSA-7vcj-mh9g-5wj9/GHSA-7vcj-mh9g-5wj9.json new file mode 100644 index 00000000000..a2a212fe3c8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7vcj-mh9g-5wj9/GHSA-7vcj-mh9g-5wj9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vcj-mh9g-5wj9", + "modified": "2025-04-01T06:30:48Z", + "published": "2025-04-01T06:30:48Z", + "aliases": [ + "CVE-2025-31087" + ], + "details": "Deserialization of Untrusted Data vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerce allows Object Injection. This issue affects Multiple Shipping And Billing Address For Woocommerce: from n/a through 1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31087" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/different-shipping-and-billing-address-for-woocommerce/vulnerability/wordpress-multiple-shipping-and-billing-address-for-woocommerce-1-5-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-863q-8r2w-ghrx/GHSA-863q-8r2w-ghrx.json b/advisories/unreviewed/2025/04/GHSA-863q-8r2w-ghrx/GHSA-863q-8r2w-ghrx.json new file mode 100644 index 00000000000..6bb4d37fe40 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-863q-8r2w-ghrx/GHSA-863q-8r2w-ghrx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-863q-8r2w-ghrx", + "modified": "2025-04-01T06:30:46Z", + "published": "2025-04-01T06:30:46Z", + "aliases": [ + "CVE-2025-30797" + ], + "details": "Missing Authorization vulnerability in bigdrop.gr Greek Multi Tool – Fix peralinks, accents, auto create menus and more allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Greek Multi Tool – Fix peralinks, accents, auto create menus and more: from n/a through 2.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30797" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/greek-multi-tool/vulnerability/wordpress-greek-multi-tool-fix-peralinks-accents-auto-create-menus-and-more-plugin-2-3-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-86w6-88w2-wqrg/GHSA-86w6-88w2-wqrg.json b/advisories/unreviewed/2025/04/GHSA-86w6-88w2-wqrg/GHSA-86w6-88w2-wqrg.json new file mode 100644 index 00000000000..c986be96293 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-86w6-88w2-wqrg/GHSA-86w6-88w2-wqrg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86w6-88w2-wqrg", + "modified": "2025-04-01T06:30:48Z", + "published": "2025-04-01T06:30:47Z", + "aliases": [ + "CVE-2025-30917" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Wham SKU Generator for WooCommerce allows Reflected XSS. This issue affects SKU Generator for WooCommerce: from n/a through 1.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30917" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sku-for-woocommerce/vulnerability/wordpress-sku-generator-for-woocommerce-plugin-1-6-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-892g-82wc-7r8q/GHSA-892g-82wc-7r8q.json b/advisories/unreviewed/2025/04/GHSA-892g-82wc-7r8q/GHSA-892g-82wc-7r8q.json index b4264a19271..a87c71f15e4 100644 --- a/advisories/unreviewed/2025/04/GHSA-892g-82wc-7r8q/GHSA-892g-82wc-7r8q.json +++ b/advisories/unreviewed/2025/04/GHSA-892g-82wc-7r8q/GHSA-892g-82wc-7r8q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-892g-82wc-7r8q", - "modified": "2025-04-01T00:30:39Z", + "modified": "2025-04-01T06:30:41Z", "published": "2025-04-01T00:30:39Z", "aliases": [ "CVE-2025-24242" ], "details": "This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app with root privileges may be able to access private information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:21Z" diff --git a/advisories/unreviewed/2025/04/GHSA-8jqc-6pw9-q43h/GHSA-8jqc-6pw9-q43h.json b/advisories/unreviewed/2025/04/GHSA-8jqc-6pw9-q43h/GHSA-8jqc-6pw9-q43h.json new file mode 100644 index 00000000000..f64e0d977c4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8jqc-6pw9-q43h/GHSA-8jqc-6pw9-q43h.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jqc-6pw9-q43h", + "modified": "2025-04-01T06:30:44Z", + "published": "2025-04-01T06:30:44Z", + "aliases": [ + "CVE-2025-1665" + ], + "details": "The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 3.11.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1665" + }, + { + "type": "WEB", + "url": "https://avada.com" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/94e373fb-b3f5-4c1b-9eaa-89747af4dc30?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-944c-jrhf-f2gx/GHSA-944c-jrhf-f2gx.json b/advisories/unreviewed/2025/04/GHSA-944c-jrhf-f2gx/GHSA-944c-jrhf-f2gx.json new file mode 100644 index 00000000000..7f7c6099731 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-944c-jrhf-f2gx/GHSA-944c-jrhf-f2gx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-944c-jrhf-f2gx", + "modified": "2025-04-01T06:30:46Z", + "published": "2025-04-01T06:30:46Z", + "aliases": [ + "CVE-2025-30876" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ads by WPQuads Ads by WPQuads allows SQL Injection. This issue affects Ads by WPQuads: from n/a through 2.0.87.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30876" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quick-adsense-reloaded/vulnerability/wordpress-ads-by-wpquads-plugin-2-0-87-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-964p-mw8f-wq7h/GHSA-964p-mw8f-wq7h.json b/advisories/unreviewed/2025/04/GHSA-964p-mw8f-wq7h/GHSA-964p-mw8f-wq7h.json new file mode 100644 index 00000000000..2409fec663b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-964p-mw8f-wq7h/GHSA-964p-mw8f-wq7h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-964p-mw8f-wq7h", + "modified": "2025-04-01T06:30:47Z", + "published": "2025-04-01T06:30:47Z", + "aliases": [ + "CVE-2025-30886" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk allows SQL Injection. This issue affects JS Help Desk: from n/a through 2.9.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30886" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/js-support-ticket/vulnerability/wordpress-js-help-desk-plugin-2-9-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9cp2-r8w6-r4vm/GHSA-9cp2-r8w6-r4vm.json b/advisories/unreviewed/2025/04/GHSA-9cp2-r8w6-r4vm/GHSA-9cp2-r8w6-r4vm.json new file mode 100644 index 00000000000..73e11d34f29 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9cp2-r8w6-r4vm/GHSA-9cp2-r8w6-r4vm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cp2-r8w6-r4vm", + "modified": "2025-04-01T06:30:44Z", + "published": "2025-04-01T06:30:44Z", + "aliases": [ + "CVE-2025-1986" + ], + "details": "The Gutentor WordPress plugin before 3.4.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1986" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/f1414750-19ee-4a5d-b255-a9c20168b716" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9h9q-hm6h-279r/GHSA-9h9q-hm6h-279r.json b/advisories/unreviewed/2025/04/GHSA-9h9q-hm6h-279r/GHSA-9h9q-hm6h-279r.json new file mode 100644 index 00000000000..e713747a313 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9h9q-hm6h-279r/GHSA-9h9q-hm6h-279r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h9q-hm6h-279r", + "modified": "2025-04-01T06:30:47Z", + "published": "2025-04-01T06:30:47Z", + "aliases": [ + "CVE-2025-30911" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in Rometheme RomethemeKit For Elementor allows Command Injection. This issue affects RomethemeKit For Elementor: from n/a through 1.5.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30911" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rometheme-for-elementor/vulnerability/wordpress-romethemekit-for-elementor-plugin-1-5-4-arbitrary-plugin-installation-activation-to-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c2pm-jwhm-8xmf/GHSA-c2pm-jwhm-8xmf.json b/advisories/unreviewed/2025/04/GHSA-c2pm-jwhm-8xmf/GHSA-c2pm-jwhm-8xmf.json new file mode 100644 index 00000000000..932c395a04b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c2pm-jwhm-8xmf/GHSA-c2pm-jwhm-8xmf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2pm-jwhm-8xmf", + "modified": "2025-04-01T06:30:46Z", + "published": "2025-04-01T06:30:46Z", + "aliases": [ + "CVE-2025-30837" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cristiano Zanca WooCommerce Fattureincloud allows Reflected XSS. This issue affects WooCommerce Fattureincloud: from n/a through 2.6.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30837" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-fattureincloud/vulnerability/wordpress-woocommerce-fattureincloud-plugin-2-6-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c4pq-jg25-393h/GHSA-c4pq-jg25-393h.json b/advisories/unreviewed/2025/04/GHSA-c4pq-jg25-393h/GHSA-c4pq-jg25-393h.json new file mode 100644 index 00000000000..95cdc85c839 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c4pq-jg25-393h/GHSA-c4pq-jg25-393h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4pq-jg25-393h", + "modified": "2025-04-01T06:30:44Z", + "published": "2025-04-01T06:30:44Z", + "aliases": [ + "CVE-2025-30547" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Tufts WP Cards allows Reflected XSS. This issue affects WP Cards: from n/a through 1.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30547" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-cards/vulnerability/wordpress-wp-cards-plugin-1-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c8pq-jfx6-w9cv/GHSA-c8pq-jfx6-w9cv.json b/advisories/unreviewed/2025/04/GHSA-c8pq-jfx6-w9cv/GHSA-c8pq-jfx6-w9cv.json new file mode 100644 index 00000000000..d239f387672 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c8pq-jfx6-w9cv/GHSA-c8pq-jfx6-w9cv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8pq-jfx6-w9cv", + "modified": "2025-04-01T06:30:45Z", + "published": "2025-04-01T06:30:45Z", + "aliases": [ + "CVE-2025-30774" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker allows SQL Injection. This issue affects Quiz Maker: from n/a through 6.6.8.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30774" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quiz-maker/vulnerability/wordpress-quiz-maker-plugin-6-6-8-7-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cx4w-v9wj-5jjv/GHSA-cx4w-v9wj-5jjv.json b/advisories/unreviewed/2025/04/GHSA-cx4w-v9wj-5jjv/GHSA-cx4w-v9wj-5jjv.json new file mode 100644 index 00000000000..c93418b0c78 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cx4w-v9wj-5jjv/GHSA-cx4w-v9wj-5jjv.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx4w-v9wj-5jjv", + "modified": "2025-04-01T06:30:44Z", + "published": "2025-04-01T06:30:44Z", + "aliases": [ + "CVE-2024-13567" + ], + "details": "The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.3.1 via the 'awesome-support' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/awesome-support directory which can contain file attachments included in support tickets. The vulnerability was partially patched in version 6.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13567" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/awesome-support/trunk/includes/file-uploader/class-file-uploader.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3250497" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3262629" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/24c54ef5-ad02-4767-bca6-f74c539d3068?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f563-pj53-h78x/GHSA-f563-pj53-h78x.json b/advisories/unreviewed/2025/04/GHSA-f563-pj53-h78x/GHSA-f563-pj53-h78x.json new file mode 100644 index 00000000000..8d136968325 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f563-pj53-h78x/GHSA-f563-pj53-h78x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f563-pj53-h78x", + "modified": "2025-04-01T06:30:45Z", + "published": "2025-04-01T06:30:45Z", + "aliases": [ + "CVE-2025-30782" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle Subscribe to Download Lite allows PHP Local File Inclusion. This issue affects Subscribe to Download Lite: from n/a through 1.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30782" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/subscribe-to-download-lite/vulnerability/wordpress-subscribe-to-download-lite-plugin-1-2-9-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f7fq-7wfp-vc3j/GHSA-f7fq-7wfp-vc3j.json b/advisories/unreviewed/2025/04/GHSA-f7fq-7wfp-vc3j/GHSA-f7fq-7wfp-vc3j.json new file mode 100644 index 00000000000..035cfecc313 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f7fq-7wfp-vc3j/GHSA-f7fq-7wfp-vc3j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7fq-7wfp-vc3j", + "modified": "2025-04-01T06:30:48Z", + "published": "2025-04-01T06:30:48Z", + "aliases": [ + "CVE-2025-31095" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in ho3einie Material Dashboard allows Authentication Bypass. This issue affects Material Dashboard: from n/a through 1.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31095" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/material-dashboard/vulnerability/wordpress-material-dashboard-1-4-5-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f8wf-6rcj-xc96/GHSA-f8wf-6rcj-xc96.json b/advisories/unreviewed/2025/04/GHSA-f8wf-6rcj-xc96/GHSA-f8wf-6rcj-xc96.json new file mode 100644 index 00000000000..9d7c413449f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f8wf-6rcj-xc96/GHSA-f8wf-6rcj-xc96.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8wf-6rcj-xc96", + "modified": "2025-04-01T06:30:46Z", + "published": "2025-04-01T06:30:46Z", + "aliases": [ + "CVE-2025-30827" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder Team Tobias WP2LEADS allows Reflected XSS. This issue affects WP2LEADS: from n/a through 3.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30827" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp2leads/vulnerability/wordpress-wp2leads-plugin-3-4-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f95p-xwh9-8625/GHSA-f95p-xwh9-8625.json b/advisories/unreviewed/2025/04/GHSA-f95p-xwh9-8625/GHSA-f95p-xwh9-8625.json new file mode 100644 index 00000000000..2e26653969a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f95p-xwh9-8625/GHSA-f95p-xwh9-8625.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f95p-xwh9-8625", + "modified": "2025-04-01T06:30:47Z", + "published": "2025-04-01T06:30:47Z", + "aliases": [ + "CVE-2025-30910" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CreativeMindsSolutions CM Download Manager allows Path Traversal. This issue affects CM Download Manager: from n/a through 2.9.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30910" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cm-download-manager/vulnerability/wordpress-cm-download-manager-plugin-2-9-6-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f9vw-5v2f-5j5q/GHSA-f9vw-5v2f-5j5q.json b/advisories/unreviewed/2025/04/GHSA-f9vw-5v2f-5j5q/GHSA-f9vw-5v2f-5j5q.json index b1d2b6a58a8..ca4e72a3ed8 100644 --- a/advisories/unreviewed/2025/04/GHSA-f9vw-5v2f-5j5q/GHSA-f9vw-5v2f-5j5q.json +++ b/advisories/unreviewed/2025/04/GHSA-f9vw-5v2f-5j5q/GHSA-f9vw-5v2f-5j5q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f9vw-5v2f-5j5q", - "modified": "2025-04-01T00:30:40Z", + "modified": "2025-04-01T06:30:42Z", "published": "2025-04-01T00:30:40Z", "aliases": [ "CVE-2025-24263" ], "details": "A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sequoia 15.4. An app may be able to observe unprotected user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:23Z" diff --git a/advisories/unreviewed/2025/04/GHSA-fpjr-fj64-243g/GHSA-fpjr-fj64-243g.json b/advisories/unreviewed/2025/04/GHSA-fpjr-fj64-243g/GHSA-fpjr-fj64-243g.json new file mode 100644 index 00000000000..95b0383086e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fpjr-fj64-243g/GHSA-fpjr-fj64-243g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpjr-fj64-243g", + "modified": "2025-04-01T06:30:45Z", + "published": "2025-04-01T06:30:45Z", + "aliases": [ + "CVE-2025-30579" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jakeii Pesapal Gateway for Woocommerce allows Reflected XSS. This issue affects Pesapal Gateway for Woocommerce: from n/a through 2.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30579" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pesapal-for-woocommerce/vulnerability/wordpress-pesapal-gateway-for-woocommerce-plugin-2-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g5m7-ph65-hj67/GHSA-g5m7-ph65-hj67.json b/advisories/unreviewed/2025/04/GHSA-g5m7-ph65-hj67/GHSA-g5m7-ph65-hj67.json index fbbc99a6b4a..f7f9c0ae1cf 100644 --- a/advisories/unreviewed/2025/04/GHSA-g5m7-ph65-hj67/GHSA-g5m7-ph65-hj67.json +++ b/advisories/unreviewed/2025/04/GHSA-g5m7-ph65-hj67/GHSA-g5m7-ph65-hj67.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g5m7-ph65-hj67", - "modified": "2025-04-01T00:30:39Z", + "modified": "2025-04-01T06:30:40Z", "published": "2025-04-01T00:30:39Z", "aliases": [ "CVE-2025-24238" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, tvOS 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to gain elevated privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:21Z" diff --git a/advisories/unreviewed/2025/04/GHSA-g88h-455w-qvww/GHSA-g88h-455w-qvww.json b/advisories/unreviewed/2025/04/GHSA-g88h-455w-qvww/GHSA-g88h-455w-qvww.json new file mode 100644 index 00000000000..0a65bd96a96 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g88h-455w-qvww/GHSA-g88h-455w-qvww.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g88h-455w-qvww", + "modified": "2025-04-01T06:30:45Z", + "published": "2025-04-01T06:30:45Z", + "aliases": [ + "CVE-2025-30613" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N-Media Nmedia MailChimp allows Stored XSS. This issue affects Nmedia MailChimp: from n/a through 5.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30613" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nmedia-mailchimp-widget/vulnerability/wordpress-nmedia-mailchimp-5-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h2wh-36m8-j3rp/GHSA-h2wh-36m8-j3rp.json b/advisories/unreviewed/2025/04/GHSA-h2wh-36m8-j3rp/GHSA-h2wh-36m8-j3rp.json index 0038cd06a82..4ab9d534e67 100644 --- a/advisories/unreviewed/2025/04/GHSA-h2wh-36m8-j3rp/GHSA-h2wh-36m8-j3rp.json +++ b/advisories/unreviewed/2025/04/GHSA-h2wh-36m8-j3rp/GHSA-h2wh-36m8-j3rp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h2wh-36m8-j3rp", - "modified": "2025-04-01T00:30:44Z", + "modified": "2025-04-01T06:30:44Z", "published": "2025-04-01T00:30:44Z", "aliases": [ "CVE-2025-31191" ], "details": "This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.5, tvOS 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:29Z" diff --git a/advisories/unreviewed/2025/04/GHSA-j9c8-34wr-822j/GHSA-j9c8-34wr-822j.json b/advisories/unreviewed/2025/04/GHSA-j9c8-34wr-822j/GHSA-j9c8-34wr-822j.json new file mode 100644 index 00000000000..043646c09a7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j9c8-34wr-822j/GHSA-j9c8-34wr-822j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9c8-34wr-822j", + "modified": "2025-04-01T06:30:46Z", + "published": "2025-04-01T06:30:46Z", + "aliases": [ + "CVE-2025-30796" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Extended The Ultimate WordPress Toolkit – WP Extended allows Reflected XSS. This issue affects The Ultimate WordPress Toolkit – WP Extended: from n/a through 3.0.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30796" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpextended/vulnerability/wordpress-the-ultimate-wordpress-toolkit-wp-extended-plugin-3-0-14-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jpx4-2v97-44rr/GHSA-jpx4-2v97-44rr.json b/advisories/unreviewed/2025/04/GHSA-jpx4-2v97-44rr/GHSA-jpx4-2v97-44rr.json new file mode 100644 index 00000000000..dbe4422f9d2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jpx4-2v97-44rr/GHSA-jpx4-2v97-44rr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpx4-2v97-44rr", + "modified": "2025-04-01T06:30:48Z", + "published": "2025-04-01T06:30:47Z", + "aliases": [ + "CVE-2025-30926" + ], + "details": "Missing Authorization vulnerability in KingAddons.com King Addons for Elementor. This issue affects King Addons for Elementor: from n/a through 24.12.58.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30926" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/king-addons/vulnerability/wordpress-king-addons-for-elementor-plugin-24-12-58-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jrgv-pmf9-6qg5/GHSA-jrgv-pmf9-6qg5.json b/advisories/unreviewed/2025/04/GHSA-jrgv-pmf9-6qg5/GHSA-jrgv-pmf9-6qg5.json index 706a724703e..c59ef12af74 100644 --- a/advisories/unreviewed/2025/04/GHSA-jrgv-pmf9-6qg5/GHSA-jrgv-pmf9-6qg5.json +++ b/advisories/unreviewed/2025/04/GHSA-jrgv-pmf9-6qg5/GHSA-jrgv-pmf9-6qg5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jrgv-pmf9-6qg5", - "modified": "2025-04-01T00:30:40Z", + "modified": "2025-04-01T06:30:42Z", "published": "2025-04-01T00:30:40Z", "aliases": [ "CVE-2025-24278" ], "details": "This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access protected user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-jw49-5g4r-c94w/GHSA-jw49-5g4r-c94w.json b/advisories/unreviewed/2025/04/GHSA-jw49-5g4r-c94w/GHSA-jw49-5g4r-c94w.json new file mode 100644 index 00000000000..c1753c38656 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jw49-5g4r-c94w/GHSA-jw49-5g4r-c94w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw49-5g4r-c94w", + "modified": "2025-04-01T06:30:44Z", + "published": "2025-04-01T06:30:44Z", + "aliases": [ + "CVE-2025-2048" + ], + "details": "The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks and download arbitrary files on the server", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2048" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/05c664e8-110e-4a31-8377-41a0422508a7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m957-8r27-px6j/GHSA-m957-8r27-px6j.json b/advisories/unreviewed/2025/04/GHSA-m957-8r27-px6j/GHSA-m957-8r27-px6j.json new file mode 100644 index 00000000000..7c7f31e324b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m957-8r27-px6j/GHSA-m957-8r27-px6j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m957-8r27-px6j", + "modified": "2025-04-01T06:30:47Z", + "published": "2025-04-01T06:30:47Z", + "aliases": [ + "CVE-2025-30901" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky JS Help Desk allows PHP Local File Inclusion. This issue affects JS Help Desk: from n/a through 2.9.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30901" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/js-support-ticket/vulnerability/wordpress-js-help-desk-plugin-2-9-2-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mcmj-q426-5fcx/GHSA-mcmj-q426-5fcx.json b/advisories/unreviewed/2025/04/GHSA-mcmj-q426-5fcx/GHSA-mcmj-q426-5fcx.json new file mode 100644 index 00000000000..5a9d0f81b9f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mcmj-q426-5fcx/GHSA-mcmj-q426-5fcx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcmj-q426-5fcx", + "modified": "2025-04-01T06:30:44Z", + "published": "2025-04-01T06:30:44Z", + "aliases": [ + "CVE-2025-0418" + ], + "details": "Valmet DNA user passwords in plain text. This practice poses a security risk as attackers who gain access to local project data can read the passwords.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:A/V:D/RE:L/U:Green" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0418" + }, + { + "type": "WEB", + "url": "https://www.valmet.com/about-us/about/research-and-development/vulnerabilityadvisories/cve-2025-0418" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-312" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T04:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mhc5-qc33-269c/GHSA-mhc5-qc33-269c.json b/advisories/unreviewed/2025/04/GHSA-mhc5-qc33-269c/GHSA-mhc5-qc33-269c.json new file mode 100644 index 00000000000..ca2b6ed7f16 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mhc5-qc33-269c/GHSA-mhc5-qc33-269c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhc5-qc33-269c", + "modified": "2025-04-01T06:30:46Z", + "published": "2025-04-01T06:30:46Z", + "aliases": [ + "CVE-2025-30808" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weblizar About Author allows Reflected XSS. This issue affects About Author: from n/a through 1.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30808" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/about-author/vulnerability/wordpress-about-author-plugin-1-6-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p323-jgm4-xm6p/GHSA-p323-jgm4-xm6p.json b/advisories/unreviewed/2025/04/GHSA-p323-jgm4-xm6p/GHSA-p323-jgm4-xm6p.json new file mode 100644 index 00000000000..d786c67e980 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p323-jgm4-xm6p/GHSA-p323-jgm4-xm6p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p323-jgm4-xm6p", + "modified": "2025-04-01T06:30:46Z", + "published": "2025-04-01T06:30:46Z", + "aliases": [ + "CVE-2025-30834" + ], + "details": "Path Traversal vulnerability in Bit Apps Bit Assist allows Path Traversal. This issue affects Bit Assist: from n/a through 1.5.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30834" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bit-assist/vulnerability/wordpress-bit-assist-plugin-1-5-4-path-traversal-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p4vm-6crq-4pg4/GHSA-p4vm-6crq-4pg4.json b/advisories/unreviewed/2025/04/GHSA-p4vm-6crq-4pg4/GHSA-p4vm-6crq-4pg4.json index 0266408c2dd..d64dbedfaac 100644 --- a/advisories/unreviewed/2025/04/GHSA-p4vm-6crq-4pg4/GHSA-p4vm-6crq-4pg4.json +++ b/advisories/unreviewed/2025/04/GHSA-p4vm-6crq-4pg4/GHSA-p4vm-6crq-4pg4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p4vm-6crq-4pg4", - "modified": "2025-04-01T00:30:36Z", + "modified": "2025-04-01T06:30:40Z", "published": "2025-04-01T00:30:35Z", "aliases": [ "CVE-2025-24170" ], "details": "A logic issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sonoma 14.7.5. An app may be able to gain root privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:16Z" diff --git a/advisories/unreviewed/2025/04/GHSA-p594-jv9h-cv8f/GHSA-p594-jv9h-cv8f.json b/advisories/unreviewed/2025/04/GHSA-p594-jv9h-cv8f/GHSA-p594-jv9h-cv8f.json new file mode 100644 index 00000000000..184586b083b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p594-jv9h-cv8f/GHSA-p594-jv9h-cv8f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p594-jv9h-cv8f", + "modified": "2025-04-01T06:30:45Z", + "published": "2025-04-01T06:30:45Z", + "aliases": [ + "CVE-2025-30563" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Tidekey allows Reflected XSS. This issue affects Tidekey: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30563" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tidekey/vulnerability/wordpress-tidekey-plugin-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p7rf-4rp4-q9q8/GHSA-p7rf-4rp4-q9q8.json b/advisories/unreviewed/2025/04/GHSA-p7rf-4rp4-q9q8/GHSA-p7rf-4rp4-q9q8.json new file mode 100644 index 00000000000..679be2caf83 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p7rf-4rp4-q9q8/GHSA-p7rf-4rp4-q9q8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7rf-4rp4-q9q8", + "modified": "2025-04-01T06:30:46Z", + "published": "2025-04-01T06:30:46Z", + "aliases": [ + "CVE-2025-30870" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine allows PHP Local File Inclusion. This issue affects WP Travel Engine: from n/a through 6.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30870" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-travel-engine/vulnerability/wordpress-wp-travel-engine-plugin-6-3-5-local-file-inclusion-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p857-5cf6-2v56/GHSA-p857-5cf6-2v56.json b/advisories/unreviewed/2025/04/GHSA-p857-5cf6-2v56/GHSA-p857-5cf6-2v56.json new file mode 100644 index 00000000000..8cfa007f0b3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p857-5cf6-2v56/GHSA-p857-5cf6-2v56.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p857-5cf6-2v56", + "modified": "2025-04-01T06:30:44Z", + "published": "2025-04-01T06:30:44Z", + "aliases": [ + "CVE-2025-0417" + ], + "details": "Lack of protection against brute force attacks in Valmet DNA visualization in DNA Operate. The possibility to make an arbitrary number of login attempts without any rate limit gives an attacker an increased chance of guessing passwords and then performing switching operations.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:D/RE:L/U:Green" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0417" + }, + { + "type": "WEB", + "url": "https://www.valmet.com/about-us/about/research-and-development/vulnerabilityadvisories/cve-2025-0417" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T04:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pmrv-wgvv-rj54/GHSA-pmrv-wgvv-rj54.json b/advisories/unreviewed/2025/04/GHSA-pmrv-wgvv-rj54/GHSA-pmrv-wgvv-rj54.json new file mode 100644 index 00000000000..9b5706660a3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pmrv-wgvv-rj54/GHSA-pmrv-wgvv-rj54.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmrv-wgvv-rj54", + "modified": "2025-04-01T06:30:45Z", + "published": "2025-04-01T06:30:45Z", + "aliases": [ + "CVE-2025-30793" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Property Hive Houzez Property Feed allows Path Traversal. This issue affects Houzez Property Feed: from n/a through 2.5.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30793" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/houzez-property-feed/vulnerability/wordpress-houzez-property-feed-plugin-2-5-4-arbitrary-file-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qg2p-qw45-xh6f/GHSA-qg2p-qw45-xh6f.json b/advisories/unreviewed/2025/04/GHSA-qg2p-qw45-xh6f/GHSA-qg2p-qw45-xh6f.json new file mode 100644 index 00000000000..2e6b353bed4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qg2p-qw45-xh6f/GHSA-qg2p-qw45-xh6f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg2p-qw45-xh6f", + "modified": "2025-04-01T06:30:45Z", + "published": "2025-04-01T06:30:45Z", + "aliases": [ + "CVE-2025-30589" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Flickr set slideshows allows SQL Injection. This issue affects Flickr set slideshows: from n/a through 0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30589" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/flickr-set-slideshows/vulnerability/wordpress-flickr-set-slideshows-0-9-sql-injection-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qm2f-w2gq-vqp6/GHSA-qm2f-w2gq-vqp6.json b/advisories/unreviewed/2025/04/GHSA-qm2f-w2gq-vqp6/GHSA-qm2f-w2gq-vqp6.json index 7213fb04910..6b692a7681a 100644 --- a/advisories/unreviewed/2025/04/GHSA-qm2f-w2gq-vqp6/GHSA-qm2f-w2gq-vqp6.json +++ b/advisories/unreviewed/2025/04/GHSA-qm2f-w2gq-vqp6/GHSA-qm2f-w2gq-vqp6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qm2f-w2gq-vqp6", - "modified": "2025-04-01T00:30:39Z", + "modified": "2025-04-01T06:30:41Z", "published": "2025-04-01T00:30:39Z", "aliases": [ "CVE-2025-24243" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Processing a maliciously crafted file may lead to arbitrary code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:21Z" diff --git a/advisories/unreviewed/2025/04/GHSA-r32r-4px4-7j36/GHSA-r32r-4px4-7j36.json b/advisories/unreviewed/2025/04/GHSA-r32r-4px4-7j36/GHSA-r32r-4px4-7j36.json index c4299f3e6ff..218bc633ccf 100644 --- a/advisories/unreviewed/2025/04/GHSA-r32r-4px4-7j36/GHSA-r32r-4px4-7j36.json +++ b/advisories/unreviewed/2025/04/GHSA-r32r-4px4-7j36/GHSA-r32r-4px4-7j36.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r32r-4px4-7j36", - "modified": "2025-04-01T00:30:42Z", + "modified": "2025-04-01T06:30:43Z", "published": "2025-04-01T00:30:42Z", "aliases": [ "CVE-2025-30447" ], "details": "The issue was resolved by sanitizing logging This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:26Z" diff --git a/advisories/unreviewed/2025/04/GHSA-rvhm-r43q-vxvx/GHSA-rvhm-r43q-vxvx.json b/advisories/unreviewed/2025/04/GHSA-rvhm-r43q-vxvx/GHSA-rvhm-r43q-vxvx.json new file mode 100644 index 00000000000..148c6925de9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rvhm-r43q-vxvx/GHSA-rvhm-r43q-vxvx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvhm-r43q-vxvx", + "modified": "2025-04-01T06:30:44Z", + "published": "2025-04-01T06:30:44Z", + "aliases": [ + "CVE-2025-2008" + ], + "details": "The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import_single_post_as_csv() function in all versions up to, and including, 7.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2008" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3261521/wp-ultimate-csv-importer/trunk/SingleImportExport.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a114faf9-cada-4132-abe3-c0137b66e276?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T05:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v5c7-2m27-87mv/GHSA-v5c7-2m27-87mv.json b/advisories/unreviewed/2025/04/GHSA-v5c7-2m27-87mv/GHSA-v5c7-2m27-87mv.json new file mode 100644 index 00000000000..69d8fe6f022 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v5c7-2m27-87mv/GHSA-v5c7-2m27-87mv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5c7-2m27-87mv", + "modified": "2025-04-01T06:30:46Z", + "published": "2025-04-01T06:30:46Z", + "aliases": [ + "CVE-2025-30869" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Parakoos Image Wall allows Reflected XSS. This issue affects Image Wall: from n/a through 3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30869" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/image-wall/vulnerability/wordpress-image-wall-plugin-3-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v8gm-mmxg-v36w/GHSA-v8gm-mmxg-v36w.json b/advisories/unreviewed/2025/04/GHSA-v8gm-mmxg-v36w/GHSA-v8gm-mmxg-v36w.json new file mode 100644 index 00000000000..e00f6c8ce2a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v8gm-mmxg-v36w/GHSA-v8gm-mmxg-v36w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8gm-mmxg-v36w", + "modified": "2025-04-01T06:30:47Z", + "published": "2025-04-01T06:30:47Z", + "aliases": [ + "CVE-2025-30878" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk allows Path Traversal. This issue affects JS Help Desk: from n/a through 2.9.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30878" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/js-support-ticket/vulnerability/wordpress-js-help-desk-plugin-2-9-2-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v8wr-33qw-vhph/GHSA-v8wr-33qw-vhph.json b/advisories/unreviewed/2025/04/GHSA-v8wr-33qw-vhph/GHSA-v8wr-33qw-vhph.json new file mode 100644 index 00000000000..1d6d01895ce --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v8wr-33qw-vhph/GHSA-v8wr-33qw-vhph.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8wr-33qw-vhph", + "modified": "2025-04-01T06:30:45Z", + "published": "2025-04-01T06:30:45Z", + "aliases": [ + "CVE-2025-30614" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Haozhe Xie Google Font Fix allows Reflected XSS. This issue affects Google Font Fix: from n/a through 2.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30614" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/google-font-fix/vulnerability/wordpress-google-font-fix-plugin-2-3-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vccw-jcwc-p44p/GHSA-vccw-jcwc-p44p.json b/advisories/unreviewed/2025/04/GHSA-vccw-jcwc-p44p/GHSA-vccw-jcwc-p44p.json index 6db1237b4d2..7ca94f9d8d6 100644 --- a/advisories/unreviewed/2025/04/GHSA-vccw-jcwc-p44p/GHSA-vccw-jcwc-p44p.json +++ b/advisories/unreviewed/2025/04/GHSA-vccw-jcwc-p44p/GHSA-vccw-jcwc-p44p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vccw-jcwc-p44p", - "modified": "2025-04-01T00:30:40Z", + "modified": "2025-04-01T06:30:41Z", "published": "2025-04-01T00:30:40Z", "aliases": [ "CVE-2025-24262" ], "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.4. A sandboxed app may be able to access sensitive user data in system logs.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:23Z" diff --git a/advisories/unreviewed/2025/04/GHSA-vmmh-qx88-m8x2/GHSA-vmmh-qx88-m8x2.json b/advisories/unreviewed/2025/04/GHSA-vmmh-qx88-m8x2/GHSA-vmmh-qx88-m8x2.json new file mode 100644 index 00000000000..16142311d5b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vmmh-qx88-m8x2/GHSA-vmmh-qx88-m8x2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmmh-qx88-m8x2", + "modified": "2025-04-01T06:30:44Z", + "published": "2025-04-01T06:30:44Z", + "aliases": [ + "CVE-2025-2007" + ], + "details": "The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteImage() function in all versions up to, and including, 7.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2007" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3261521/wp-ultimate-csv-importer/trunk/MediaHandling.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3923c732-80b5-4a04-80dd-b4d5b5e5567d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T05:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wmvg-5r8j-h4hf/GHSA-wmvg-5r8j-h4hf.json b/advisories/unreviewed/2025/04/GHSA-wmvg-5r8j-h4hf/GHSA-wmvg-5r8j-h4hf.json new file mode 100644 index 00000000000..0e0b82d2ef6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wmvg-5r8j-h4hf/GHSA-wmvg-5r8j-h4hf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmvg-5r8j-h4hf", + "modified": "2025-04-01T06:30:44Z", + "published": "2025-04-01T06:30:44Z", + "aliases": [ + "CVE-2025-22277" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in appsbd Vitepos allows Authentication Abuse. This issue affects Vitepos: from n/a through 3.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22277" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/vitepos-lite/vulnerability/wordpress-vitepos-plugin-3-1-4-broken-authentication-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wqr4-qr3f-x2r4/GHSA-wqr4-qr3f-x2r4.json b/advisories/unreviewed/2025/04/GHSA-wqr4-qr3f-x2r4/GHSA-wqr4-qr3f-x2r4.json new file mode 100644 index 00000000000..cce25adb662 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wqr4-qr3f-x2r4/GHSA-wqr4-qr3f-x2r4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqr4-qr3f-x2r4", + "modified": "2025-04-01T06:30:48Z", + "published": "2025-04-01T06:30:48Z", + "aliases": [ + "CVE-2025-31415" + ], + "details": "Missing Authorization vulnerability in YayCommerce YayExtra allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YayExtra: from n/a through 1.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31415" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/yayextra/vulnerability/wordpress-yayextra-1-5-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x9p8-fww8-8frp/GHSA-x9p8-fww8-8frp.json b/advisories/unreviewed/2025/04/GHSA-x9p8-fww8-8frp/GHSA-x9p8-fww8-8frp.json index ed38582f7f1..6998fb11d21 100644 --- a/advisories/unreviewed/2025/04/GHSA-x9p8-fww8-8frp/GHSA-x9p8-fww8-8frp.json +++ b/advisories/unreviewed/2025/04/GHSA-x9p8-fww8-8frp/GHSA-x9p8-fww8-8frp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x9p8-fww8-8frp", - "modified": "2025-04-01T00:30:39Z", + "modified": "2025-04-01T06:30:40Z", "published": "2025-04-01T00:30:39Z", "aliases": [ "CVE-2025-24239" ], "details": "A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:21Z" diff --git a/advisories/unreviewed/2025/04/GHSA-xcg2-pp7v-fm8f/GHSA-xcg2-pp7v-fm8f.json b/advisories/unreviewed/2025/04/GHSA-xcg2-pp7v-fm8f/GHSA-xcg2-pp7v-fm8f.json index 472bf34d3bf..fda1aad34c2 100644 --- a/advisories/unreviewed/2025/04/GHSA-xcg2-pp7v-fm8f/GHSA-xcg2-pp7v-fm8f.json +++ b/advisories/unreviewed/2025/04/GHSA-xcg2-pp7v-fm8f/GHSA-xcg2-pp7v-fm8f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xcg2-pp7v-fm8f", - "modified": "2025-04-01T00:30:42Z", + "modified": "2025-04-01T06:30:43Z", "published": "2025-04-01T00:30:42Z", "aliases": [ "CVE-2025-30446" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app with root privileges may be able to modify the contents of system files.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:26Z" diff --git a/advisories/unreviewed/2025/04/GHSA-xh24-4hr4-phwj/GHSA-xh24-4hr4-phwj.json b/advisories/unreviewed/2025/04/GHSA-xh24-4hr4-phwj/GHSA-xh24-4hr4-phwj.json new file mode 100644 index 00000000000..c974b0ac0ee --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xh24-4hr4-phwj/GHSA-xh24-4hr4-phwj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh24-4hr4-phwj", + "modified": "2025-04-01T06:30:45Z", + "published": "2025-04-01T06:30:45Z", + "aliases": [ + "CVE-2025-30594" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NotFound Include URL allows Path Traversal. This issue affects Include URL: from n/a through 0.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30594" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/include-url/vulnerability/wordpress-include-url-0-3-5-arbitrary-file-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xj7c-fgvc-fxmf/GHSA-xj7c-fgvc-fxmf.json b/advisories/unreviewed/2025/04/GHSA-xj7c-fgvc-fxmf/GHSA-xj7c-fgvc-fxmf.json new file mode 100644 index 00000000000..b5542ad1832 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xj7c-fgvc-fxmf/GHSA-xj7c-fgvc-fxmf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xj7c-fgvc-fxmf", + "modified": "2025-04-01T06:30:48Z", + "published": "2025-04-01T06:30:48Z", + "aliases": [ + "CVE-2025-31409" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Bridge Core allows Stored XSS. This issue affects Bridge Core: from n/a through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31409" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bridge-core/vulnerability/wordpress-bridge-core-plugin-3-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T06:15:56Z" + } +} \ No newline at end of file