diff --git a/advisories/unreviewed/2024/03/GHSA-2jw4-27vv-49jx/GHSA-2jw4-27vv-49jx.json b/advisories/unreviewed/2024/03/GHSA-2jw4-27vv-49jx/GHSA-2jw4-27vv-49jx.json new file mode 100644 index 00000000000..b8077e0fe3a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2jw4-27vv-49jx/GHSA-2jw4-27vv-49jx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jw4-27vv-49jx", + "modified": "2024-03-28T06:30:46Z", + "published": "2024-03-28T06:30:46Z", + "aliases": [ + "CVE-2024-30244" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.0.27.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30244" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/church-admin/wordpress-church-admin-plugin-4-0-27-sql-injection-via-shortcode-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T05:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-3vqf-26wq-v77m/GHSA-3vqf-26wq-v77m.json b/advisories/unreviewed/2024/03/GHSA-3vqf-26wq-v77m/GHSA-3vqf-26wq-v77m.json new file mode 100644 index 00000000000..61bb77f9d07 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3vqf-26wq-v77m/GHSA-3vqf-26wq-v77m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vqf-26wq-v77m", + "modified": "2024-03-28T06:30:46Z", + "published": "2024-03-28T06:30:46Z", + "aliases": [ + "CVE-2024-30230" + ], + "details": "Deserialization of Untrusted Data vulnerability in Acowebs PDF Invoices and Packing Slips For WooCommerce.This issue affects PDF Invoices and Packing Slips For WooCommerce: from n/a through 1.3.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30230" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pdf-invoices-and-packing-slips-for-woocommerce/wordpress-pdf-invoices-and-packing-slips-for-woocommerce-plugin-1-3-7-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T05:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-3wv4-w236-472m/GHSA-3wv4-w236-472m.json b/advisories/unreviewed/2024/03/GHSA-3wv4-w236-472m/GHSA-3wv4-w236-472m.json new file mode 100644 index 00000000000..b68c5140d9a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3wv4-w236-472m/GHSA-3wv4-w236-472m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wv4-w236-472m", + "modified": "2024-03-28T06:30:46Z", + "published": "2024-03-28T06:30:46Z", + "aliases": [ + "CVE-2024-30243" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tomas WordPress Tooltips.This issue affects WordPress Tooltips: from n/a before 9.4.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30243" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wordpress-tooltips/wordpress-wordpress-tooltips-plugin-9-4-5-contributor-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T05:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-488j-9qqc-xqpc/GHSA-488j-9qqc-xqpc.json b/advisories/unreviewed/2024/03/GHSA-488j-9qqc-xqpc/GHSA-488j-9qqc-xqpc.json new file mode 100644 index 00000000000..1c9ea8c93c0 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-488j-9qqc-xqpc/GHSA-488j-9qqc-xqpc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-488j-9qqc-xqpc", + "modified": "2024-03-28T06:30:46Z", + "published": "2024-03-28T06:30:46Z", + "aliases": [ + "CVE-2024-30225" + ], + "details": "Deserialization of Untrusted Data vulnerability in WPENGINE, INC. WP Migrate.This issue affects WP Migrate: from n/a through 2.6.10.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30225" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-migrate-db-pro/wordpress-wp-migrate-plugin-2-6-10-unauthenticated-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-539g-ppw2-7c4r/GHSA-539g-ppw2-7c4r.json b/advisories/unreviewed/2024/03/GHSA-539g-ppw2-7c4r/GHSA-539g-ppw2-7c4r.json new file mode 100644 index 00000000000..6acdb108792 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-539g-ppw2-7c4r/GHSA-539g-ppw2-7c4r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-539g-ppw2-7c4r", + "modified": "2024-03-28T06:30:47Z", + "published": "2024-03-28T06:30:47Z", + "aliases": [ + "CVE-2024-29100" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29100" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ai-engine/wordpress-ai-engine-plugin-2-1-4-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T06:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5w42-fg4v-hv3r/GHSA-5w42-fg4v-hv3r.json b/advisories/unreviewed/2024/03/GHSA-5w42-fg4v-hv3r/GHSA-5w42-fg4v-hv3r.json new file mode 100644 index 00000000000..1c9d6b468dd --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5w42-fg4v-hv3r/GHSA-5w42-fg4v-hv3r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w42-fg4v-hv3r", + "modified": "2024-03-28T06:30:45Z", + "published": "2024-03-28T06:30:45Z", + "aliases": [ + "CVE-2024-0672" + ], + "details": "The Pz-LinkCard WordPress plugin through 2.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0672" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/eceb6585-5969-4aa6-9908-b6bfb578190a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T05:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8qr8-8px2-rh3f/GHSA-8qr8-8px2-rh3f.json b/advisories/unreviewed/2024/03/GHSA-8qr8-8px2-rh3f/GHSA-8qr8-8px2-rh3f.json new file mode 100644 index 00000000000..fd9f274b504 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8qr8-8px2-rh3f/GHSA-8qr8-8px2-rh3f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qr8-8px2-rh3f", + "modified": "2024-03-28T06:30:46Z", + "published": "2024-03-28T06:30:46Z", + "aliases": [ + "CVE-2024-30229" + ], + "details": "Deserialization of Untrusted Data vulnerability in GiveWP.This issue affects GiveWP: from n/a through 3.4.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30229" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/give/wordpress-give-plugin-3-4-2-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T05:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8x6h-j75g-2xcw/GHSA-8x6h-j75g-2xcw.json b/advisories/unreviewed/2024/03/GHSA-8x6h-j75g-2xcw/GHSA-8x6h-j75g-2xcw.json new file mode 100644 index 00000000000..70db6ab3a95 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8x6h-j75g-2xcw/GHSA-8x6h-j75g-2xcw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x6h-j75g-2xcw", + "modified": "2024-03-28T06:30:47Z", + "published": "2024-03-28T06:30:47Z", + "aliases": [ + "CVE-2024-30200" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 BEAR allows Reflected XSS.This issue affects BEAR: from n/a through 1.1.4.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30200" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woo-bulk-editor/wordpress-bear-plugin-1-1-4-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T06:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9q54-pg8p-25cg/GHSA-9q54-pg8p-25cg.json b/advisories/unreviewed/2024/03/GHSA-9q54-pg8p-25cg/GHSA-9q54-pg8p-25cg.json new file mode 100644 index 00000000000..a9e90b6be2f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9q54-pg8p-25cg/GHSA-9q54-pg8p-25cg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q54-pg8p-25cg", + "modified": "2024-03-28T06:30:45Z", + "published": "2024-03-28T06:30:45Z", + "aliases": [ + "CVE-2024-0677" + ], + "details": "The Pz-LinkCard WordPress plugin through 2.5.1 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0677" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/0f7757c9-69fa-49db-90b0-40f0ff29bee7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T05:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9xp7-754r-wj55/GHSA-9xp7-754r-wj55.json b/advisories/unreviewed/2024/03/GHSA-9xp7-754r-wj55/GHSA-9xp7-754r-wj55.json new file mode 100644 index 00000000000..16d8cd894d6 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9xp7-754r-wj55/GHSA-9xp7-754r-wj55.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xp7-754r-wj55", + "modified": "2024-03-28T06:30:47Z", + "published": "2024-03-28T06:30:47Z", + "aliases": [ + "CVE-2024-29090" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29090" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ai-engine/wordpress-ai-engine-plugin-2-1-4-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T06:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-c7mc-vqjx-hc9c/GHSA-c7mc-vqjx-hc9c.json b/advisories/unreviewed/2024/03/GHSA-c7mc-vqjx-hc9c/GHSA-c7mc-vqjx-hc9c.json new file mode 100644 index 00000000000..59255747070 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-c7mc-vqjx-hc9c/GHSA-c7mc-vqjx-hc9c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7mc-vqjx-hc9c", + "modified": "2024-03-28T06:30:46Z", + "published": "2024-03-28T06:30:46Z", + "aliases": [ + "CVE-2024-30224" + ], + "details": "Deserialization of Untrusted Data vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30224" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wholesalex/wordpress-wholesalex-plugin-1-3-2-unauthenticated-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-ch5h-vgj6-vhx6/GHSA-ch5h-vgj6-vhx6.json b/advisories/unreviewed/2024/03/GHSA-ch5h-vgj6-vhx6/GHSA-ch5h-vgj6-vhx6.json new file mode 100644 index 00000000000..b210e8dac36 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-ch5h-vgj6-vhx6/GHSA-ch5h-vgj6-vhx6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch5h-vgj6-vhx6", + "modified": "2024-03-28T06:30:46Z", + "published": "2024-03-28T06:30:46Z", + "aliases": [ + "CVE-2023-36679" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36679" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ultimate-addons-for-gutenberg/wordpress-spectra-plugin-2-6-6-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T06:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-cq7w-x535-g68q/GHSA-cq7w-x535-g68q.json b/advisories/unreviewed/2024/03/GHSA-cq7w-x535-g68q/GHSA-cq7w-x535-g68q.json new file mode 100644 index 00000000000..bb737237c39 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-cq7w-x535-g68q/GHSA-cq7w-x535-g68q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq7w-x535-g68q", + "modified": "2024-03-28T06:30:46Z", + "published": "2024-03-28T06:30:46Z", + "aliases": [ + "CVE-2024-30245" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DecaLog.This issue affects DecaLog: from n/a through 3.9.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30245" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/decalog/wordpress-decalog-plugin-3-9-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T05:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fpr2-hvvq-5xh8/GHSA-fpr2-hvvq-5xh8.json b/advisories/unreviewed/2024/03/GHSA-fpr2-hvvq-5xh8/GHSA-fpr2-hvvq-5xh8.json new file mode 100644 index 00000000000..f29f5f1d761 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fpr2-hvvq-5xh8/GHSA-fpr2-hvvq-5xh8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpr2-hvvq-5xh8", + "modified": "2024-03-28T06:30:45Z", + "published": "2024-03-28T06:30:45Z", + "aliases": [ + "CVE-2024-0673" + ], + "details": "The Pz-LinkCard WordPress plugin through 2.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0673" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d80e725d-356a-4997-a352-33565e291fc8" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T05:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-g2wh-52rf-c663/GHSA-g2wh-52rf-c663.json b/advisories/unreviewed/2024/03/GHSA-g2wh-52rf-c663/GHSA-g2wh-52rf-c663.json new file mode 100644 index 00000000000..dab8989b8e9 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-g2wh-52rf-c663/GHSA-g2wh-52rf-c663.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2wh-52rf-c663", + "modified": "2024-03-28T06:30:46Z", + "published": "2024-03-28T06:30:46Z", + "aliases": [ + "CVE-2024-30226" + ], + "details": "Deserialization of Untrusted Data vulnerability in WPDeveloper BetterDocs.This issue affects BetterDocs: from n/a through 3.3.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30226" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/betterdocs/wordpress-betterdocs-plugin-3-3-3-unauthenticated-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-gfjh-wvfw-6j4f/GHSA-gfjh-wvfw-6j4f.json b/advisories/unreviewed/2024/03/GHSA-gfjh-wvfw-6j4f/GHSA-gfjh-wvfw-6j4f.json new file mode 100644 index 00000000000..1829f709c15 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-gfjh-wvfw-6j4f/GHSA-gfjh-wvfw-6j4f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfjh-wvfw-6j4f", + "modified": "2024-03-28T06:30:46Z", + "published": "2024-03-28T06:30:46Z", + "aliases": [ + "CVE-2024-23500" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Kadence WP Gutenberg Blocks by Kadence Blocks.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through 3.2.19.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23500" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/kadence-blocks/wordpress-kadence-blocks-plugin-3-2-19-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-j7r6-q4cc-8xh7/GHSA-j7r6-q4cc-8xh7.json b/advisories/unreviewed/2024/03/GHSA-j7r6-q4cc-8xh7/GHSA-j7r6-q4cc-8xh7.json new file mode 100644 index 00000000000..e3ff7f4c313 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-j7r6-q4cc-8xh7/GHSA-j7r6-q4cc-8xh7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7r6-q4cc-8xh7", + "modified": "2024-03-28T06:30:46Z", + "published": "2024-03-28T06:30:46Z", + "aliases": [ + "CVE-2024-30240" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Typps Calendarista.This issue affects Calendarista: from n/a through 15.5.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30240" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/calendarista/wordpress-calendarista-plugin-15-5-7-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T05:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-mc39-jq88-4r6h/GHSA-mc39-jq88-4r6h.json b/advisories/unreviewed/2024/03/GHSA-mc39-jq88-4r6h/GHSA-mc39-jq88-4r6h.json new file mode 100644 index 00000000000..076cfe60bae --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-mc39-jq88-4r6h/GHSA-mc39-jq88-4r6h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc39-jq88-4r6h", + "modified": "2024-03-28T06:30:46Z", + "published": "2024-03-28T06:30:46Z", + "aliases": [ + "CVE-2024-30237" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Supsystic Slider by Supsystic.This issue affects Slider by Supsystic: from n/a through 1.8.10.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30237" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/slider-by-supsystic/wordpress-slider-by-supsystic-plugin-1-8-10-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T05:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p546-g9xq-c75r/GHSA-p546-g9xq-c75r.json b/advisories/unreviewed/2024/03/GHSA-p546-g9xq-c75r/GHSA-p546-g9xq-c75r.json new file mode 100644 index 00000000000..daf6996a78d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p546-g9xq-c75r/GHSA-p546-g9xq-c75r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p546-g9xq-c75r", + "modified": "2024-03-28T06:30:46Z", + "published": "2024-03-28T06:30:46Z", + "aliases": [ + "CVE-2024-30241" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30241" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/profilegrid-user-profiles-groups-and-communities/wordpress-profilegrid-user-profiles-memberships-groups-and-communities-plugin-5-7-1-contributor-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T05:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-pr9j-p6wx-p73x/GHSA-pr9j-p6wx-p73x.json b/advisories/unreviewed/2024/03/GHSA-pr9j-p6wx-p73x/GHSA-pr9j-p6wx-p73x.json new file mode 100644 index 00000000000..a12ec68949d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-pr9j-p6wx-p73x/GHSA-pr9j-p6wx-p73x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pr9j-p6wx-p73x", + "modified": "2024-03-28T06:30:47Z", + "published": "2024-03-28T06:30:47Z", + "aliases": [ + "CVE-2024-30221" + ], + "details": "Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart.This issue affects Sunshine Photo Cart: from n/a through 3.1.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30221" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sunshine-photo-cart/wordpress-sunshine-photo-cart-plugin-3-1-1-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T06:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-q5v2-fhp4-5qmf/GHSA-q5v2-fhp4-5qmf.json b/advisories/unreviewed/2024/03/GHSA-q5v2-fhp4-5qmf/GHSA-q5v2-fhp4-5qmf.json new file mode 100644 index 00000000000..f516c11712d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-q5v2-fhp4-5qmf/GHSA-q5v2-fhp4-5qmf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5v2-fhp4-5qmf", + "modified": "2024-03-28T06:30:46Z", + "published": "2024-03-28T06:30:46Z", + "aliases": [ + "CVE-2024-30228" + ], + "details": "Deserialization of Untrusted Data vulnerability in Hercules Design Hercules Core.This issue affects Hercules Core : from n/a through 6.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30228" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/hercules-core/wordpress-hercules-core-plugin-6-4-subscriber-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T05:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-q672-6q37-6753/GHSA-q672-6q37-6753.json b/advisories/unreviewed/2024/03/GHSA-q672-6q37-6753/GHSA-q672-6q37-6753.json new file mode 100644 index 00000000000..e23f03b1f4d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-q672-6q37-6753/GHSA-q672-6q37-6753.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q672-6q37-6753", + "modified": "2024-03-28T06:30:46Z", + "published": "2024-03-28T06:30:46Z", + "aliases": [ + "CVE-2024-28003" + ], + "details": "Missing Authorization vulnerability in Megamenu Max Mega Menu.This issue affects Max Mega Menu: from n/a through 3.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28003" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/megamenu/wordpress-max-mega-menu-plugin-3-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qw72-jmvh-wj6r/GHSA-qw72-jmvh-wj6r.json b/advisories/unreviewed/2024/03/GHSA-qw72-jmvh-wj6r/GHSA-qw72-jmvh-wj6r.json new file mode 100644 index 00000000000..1ec9e4b27f0 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qw72-jmvh-wj6r/GHSA-qw72-jmvh-wj6r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw72-jmvh-wj6r", + "modified": "2024-03-28T06:30:46Z", + "published": "2024-03-28T06:30:46Z", + "aliases": [ + "CVE-2024-30236" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contest Gallery.This issue affects Contest Gallery: from n/a through 21.3.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30236" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/contest-gallery/wordpress-contest-gallery-plugin-21-3-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T05:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qxph-3j34-gvrj/GHSA-qxph-3j34-gvrj.json b/advisories/unreviewed/2024/03/GHSA-qxph-3j34-gvrj/GHSA-qxph-3j34-gvrj.json new file mode 100644 index 00000000000..0e2e83488a9 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qxph-3j34-gvrj/GHSA-qxph-3j34-gvrj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxph-3j34-gvrj", + "modified": "2024-03-28T06:30:47Z", + "published": "2024-03-28T06:30:47Z", + "aliases": [ + "CVE-2024-28004" + ], + "details": "Missing Authorization vulnerability in ExtendThemes Colibri Page Builder.This issue affects Colibri Page Builder: from n/a through 1.0.248.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28004" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/colibri-page-builder/wordpress-colibri-page-builder-plugin-1-0-248-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rgg3-prc9-59mw/GHSA-rgg3-prc9-59mw.json b/advisories/unreviewed/2024/03/GHSA-rgg3-prc9-59mw/GHSA-rgg3-prc9-59mw.json new file mode 100644 index 00000000000..2c7e6eef173 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rgg3-prc9-59mw/GHSA-rgg3-prc9-59mw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgg3-prc9-59mw", + "modified": "2024-03-28T06:30:45Z", + "published": "2024-03-28T06:30:45Z", + "aliases": [ + "CVE-2024-30223" + ], + "details": "Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30223" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/armember-membership/wordpress-armember-plugin-4-0-26-unauthenticated-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-w89j-gj5w-5g57/GHSA-w89j-gj5w-5g57.json b/advisories/unreviewed/2024/03/GHSA-w89j-gj5w-5g57/GHSA-w89j-gj5w-5g57.json new file mode 100644 index 00000000000..a872ee84d16 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-w89j-gj5w-5g57/GHSA-w89j-gj5w-5g57.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w89j-gj5w-5g57", + "modified": "2024-03-28T06:30:46Z", + "published": "2024-03-28T06:30:46Z", + "aliases": [ + "CVE-2023-39313" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39313" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/avada/wordpress-avada-theme-7-11-1-authenticated-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T06:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-wg8r-283g-68mr/GHSA-wg8r-283g-68mr.json b/advisories/unreviewed/2024/03/GHSA-wg8r-283g-68mr/GHSA-wg8r-283g-68mr.json new file mode 100644 index 00000000000..0271b18962d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-wg8r-283g-68mr/GHSA-wg8r-283g-68mr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg8r-283g-68mr", + "modified": "2024-03-28T06:30:46Z", + "published": "2024-03-28T06:30:46Z", + "aliases": [ + "CVE-2023-34370" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates, Brainstorm Force Premium Starter Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4; Premium Starter Templates: from n/a through 3.2.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34370" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/astra-pro-sites/wordpress-premium-starter-templates-plugin-3-2-4-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/astra-sites/wordpress-starter-templates-plugin-3-2-4-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-wjw7-pmq5-rw6m/GHSA-wjw7-pmq5-rw6m.json b/advisories/unreviewed/2024/03/GHSA-wjw7-pmq5-rw6m/GHSA-wjw7-pmq5-rw6m.json new file mode 100644 index 00000000000..0cf97decc1b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-wjw7-pmq5-rw6m/GHSA-wjw7-pmq5-rw6m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjw7-pmq5-rw6m", + "modified": "2024-03-28T06:30:46Z", + "published": "2024-03-28T06:30:46Z", + "aliases": [ + "CVE-2024-30242" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in IT Path Solutions Contact Form to Any API.This issue affects Contact Form to Any API: from n/a through 1.1.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30242" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/contact-form-to-any-api/wordpress-contact-form-to-any-api-plugin-1-1-8-subscriber-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T05:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-wm87-g64h-3474/GHSA-wm87-g64h-3474.json b/advisories/unreviewed/2024/03/GHSA-wm87-g64h-3474/GHSA-wm87-g64h-3474.json new file mode 100644 index 00000000000..8a5a14cc389 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-wm87-g64h-3474/GHSA-wm87-g64h-3474.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm87-g64h-3474", + "modified": "2024-03-28T06:30:46Z", + "published": "2024-03-28T06:30:46Z", + "aliases": [ + "CVE-2024-30227" + ], + "details": "Deserialization of Untrusted Data vulnerability in INFINITUM FORM Geo Controller.This issue affects Geo Controller: from n/a through 8.6.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30227" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cf-geoplugin/wordpress-geo-controller-plugin-8-6-4-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-xh7g-3rfm-j232/GHSA-xh7g-3rfm-j232.json b/advisories/unreviewed/2024/03/GHSA-xh7g-3rfm-j232/GHSA-xh7g-3rfm-j232.json new file mode 100644 index 00000000000..ef0bc68b939 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-xh7g-3rfm-j232/GHSA-xh7g-3rfm-j232.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh7g-3rfm-j232", + "modified": "2024-03-28T06:30:46Z", + "published": "2024-03-28T06:30:46Z", + "aliases": [ + "CVE-2024-30239" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Campaigns.This issue affects Zoho Campaigns: from n/a through 2.0.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30239" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/zoho-campaigns/wordpress-zoho-campaigns-plugin-2-0-6-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T05:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-xv65-m527-x787/GHSA-xv65-m527-x787.json b/advisories/unreviewed/2024/03/GHSA-xv65-m527-x787/GHSA-xv65-m527-x787.json new file mode 100644 index 00000000000..53fe3509b27 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-xv65-m527-x787/GHSA-xv65-m527-x787.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv65-m527-x787", + "modified": "2024-03-28T06:30:45Z", + "published": "2024-03-28T06:30:45Z", + "aliases": [ + "CVE-2024-30222" + ], + "details": "Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30222" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/armember-membership/wordpress-armember-plugin-4-0-26-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T05:15:49Z" + } +} \ No newline at end of file