diff --git a/advisories/unreviewed/2023/01/GHSA-22f3-jcv7-7v3j/GHSA-22f3-jcv7-7v3j.json b/advisories/unreviewed/2023/01/GHSA-22f3-jcv7-7v3j/GHSA-22f3-jcv7-7v3j.json index f3b6381356c..2d97ae1ee3a 100644 --- a/advisories/unreviewed/2023/01/GHSA-22f3-jcv7-7v3j/GHSA-22f3-jcv7-7v3j.json +++ b/advisories/unreviewed/2023/01/GHSA-22f3-jcv7-7v3j/GHSA-22f3-jcv7-7v3j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-22f3-jcv7-7v3j", - "modified": "2023-01-24T21:30:29Z", + "modified": "2025-04-04T18:30:27Z", "published": "2023-01-17T12:30:33Z", "aliases": [ "CVE-2023-22296" diff --git a/advisories/unreviewed/2023/01/GHSA-2c9x-whr5-j4x3/GHSA-2c9x-whr5-j4x3.json b/advisories/unreviewed/2023/01/GHSA-2c9x-whr5-j4x3/GHSA-2c9x-whr5-j4x3.json index 3ffbe84248b..c086e3f4e82 100644 --- a/advisories/unreviewed/2023/01/GHSA-2c9x-whr5-j4x3/GHSA-2c9x-whr5-j4x3.json +++ b/advisories/unreviewed/2023/01/GHSA-2c9x-whr5-j4x3/GHSA-2c9x-whr5-j4x3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2c9x-whr5-j4x3", - "modified": "2023-01-26T21:30:31Z", + "modified": "2025-04-04T18:30:32Z", "published": "2023-01-18T21:30:21Z", "aliases": [ "CVE-2022-45925" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-3vwp-294x-6v9c/GHSA-3vwp-294x-6v9c.json b/advisories/unreviewed/2023/01/GHSA-3vwp-294x-6v9c/GHSA-3vwp-294x-6v9c.json index 09b274256e6..937135ff8ac 100644 --- a/advisories/unreviewed/2023/01/GHSA-3vwp-294x-6v9c/GHSA-3vwp-294x-6v9c.json +++ b/advisories/unreviewed/2023/01/GHSA-3vwp-294x-6v9c/GHSA-3vwp-294x-6v9c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3vwp-294x-6v9c", - "modified": "2023-01-26T18:30:47Z", + "modified": "2025-04-04T18:30:31Z", "published": "2023-01-18T18:30:16Z", "aliases": [ "CVE-2023-22809" diff --git a/advisories/unreviewed/2023/01/GHSA-43pr-7gqx-7qmm/GHSA-43pr-7gqx-7qmm.json b/advisories/unreviewed/2023/01/GHSA-43pr-7gqx-7qmm/GHSA-43pr-7gqx-7qmm.json index 7d8a8efc728..b35db459a4a 100644 --- a/advisories/unreviewed/2023/01/GHSA-43pr-7gqx-7qmm/GHSA-43pr-7gqx-7qmm.json +++ b/advisories/unreviewed/2023/01/GHSA-43pr-7gqx-7qmm/GHSA-43pr-7gqx-7qmm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-43pr-7gqx-7qmm", - "modified": "2023-01-24T21:30:29Z", + "modified": "2025-04-04T18:30:26Z", "published": "2023-01-17T12:30:33Z", "aliases": [ "CVE-2023-22286" diff --git a/advisories/unreviewed/2023/01/GHSA-5fcm-cpg2-2p27/GHSA-5fcm-cpg2-2p27.json b/advisories/unreviewed/2023/01/GHSA-5fcm-cpg2-2p27/GHSA-5fcm-cpg2-2p27.json index 267d901bf96..732f6f591bb 100644 --- a/advisories/unreviewed/2023/01/GHSA-5fcm-cpg2-2p27/GHSA-5fcm-cpg2-2p27.json +++ b/advisories/unreviewed/2023/01/GHSA-5fcm-cpg2-2p27/GHSA-5fcm-cpg2-2p27.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5fcm-cpg2-2p27", - "modified": "2023-01-26T21:30:31Z", + "modified": "2025-04-04T18:30:32Z", "published": "2023-01-18T21:30:21Z", "aliases": [ "CVE-2022-45924" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-682w-9rvw-qw43/GHSA-682w-9rvw-qw43.json b/advisories/unreviewed/2023/01/GHSA-682w-9rvw-qw43/GHSA-682w-9rvw-qw43.json index 2eb6b80084f..ea86c28b180 100644 --- a/advisories/unreviewed/2023/01/GHSA-682w-9rvw-qw43/GHSA-682w-9rvw-qw43.json +++ b/advisories/unreviewed/2023/01/GHSA-682w-9rvw-qw43/GHSA-682w-9rvw-qw43.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-665", "CWE-862" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/01/GHSA-72gc-x9q7-vh7v/GHSA-72gc-x9q7-vh7v.json b/advisories/unreviewed/2023/01/GHSA-72gc-x9q7-vh7v/GHSA-72gc-x9q7-vh7v.json index 3ab82a921ff..a4e017d0e83 100644 --- a/advisories/unreviewed/2023/01/GHSA-72gc-x9q7-vh7v/GHSA-72gc-x9q7-vh7v.json +++ b/advisories/unreviewed/2023/01/GHSA-72gc-x9q7-vh7v/GHSA-72gc-x9q7-vh7v.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-7m9j-89h2-pvxf/GHSA-7m9j-89h2-pvxf.json b/advisories/unreviewed/2023/01/GHSA-7m9j-89h2-pvxf/GHSA-7m9j-89h2-pvxf.json index e8fe625db34..56210184e3d 100644 --- a/advisories/unreviewed/2023/01/GHSA-7m9j-89h2-pvxf/GHSA-7m9j-89h2-pvxf.json +++ b/advisories/unreviewed/2023/01/GHSA-7m9j-89h2-pvxf/GHSA-7m9j-89h2-pvxf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7m9j-89h2-pvxf", - "modified": "2023-01-30T18:30:29Z", + "modified": "2025-04-04T18:30:32Z", "published": "2023-01-19T00:30:30Z", "aliases": [ "CVE-2022-45923" diff --git a/advisories/unreviewed/2023/01/GHSA-7qqq-mvm4-r635/GHSA-7qqq-mvm4-r635.json b/advisories/unreviewed/2023/01/GHSA-7qqq-mvm4-r635/GHSA-7qqq-mvm4-r635.json index 0f185acc5e9..fa8440142ce 100644 --- a/advisories/unreviewed/2023/01/GHSA-7qqq-mvm4-r635/GHSA-7qqq-mvm4-r635.json +++ b/advisories/unreviewed/2023/01/GHSA-7qqq-mvm4-r635/GHSA-7qqq-mvm4-r635.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7qqq-mvm4-r635", - "modified": "2023-01-25T21:30:18Z", + "modified": "2025-04-04T18:30:32Z", "published": "2023-01-18T21:30:21Z", "aliases": [ "CVE-2022-45928" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-8788-3qj3-84j7/GHSA-8788-3qj3-84j7.json b/advisories/unreviewed/2023/01/GHSA-8788-3qj3-84j7/GHSA-8788-3qj3-84j7.json index c505ceaabcf..f7fcd0ab08f 100644 --- a/advisories/unreviewed/2023/01/GHSA-8788-3qj3-84j7/GHSA-8788-3qj3-84j7.json +++ b/advisories/unreviewed/2023/01/GHSA-8788-3qj3-84j7/GHSA-8788-3qj3-84j7.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-346", "CWE-400" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/01/GHSA-8m7r-8qq7-44rp/GHSA-8m7r-8qq7-44rp.json b/advisories/unreviewed/2023/01/GHSA-8m7r-8qq7-44rp/GHSA-8m7r-8qq7-44rp.json index 66d2274d707..4f751a348b7 100644 --- a/advisories/unreviewed/2023/01/GHSA-8m7r-8qq7-44rp/GHSA-8m7r-8qq7-44rp.json +++ b/advisories/unreviewed/2023/01/GHSA-8m7r-8qq7-44rp/GHSA-8m7r-8qq7-44rp.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-997f-v4rm-9w7m/GHSA-997f-v4rm-9w7m.json b/advisories/unreviewed/2023/01/GHSA-997f-v4rm-9w7m/GHSA-997f-v4rm-9w7m.json index 090895833f1..e53597297ac 100644 --- a/advisories/unreviewed/2023/01/GHSA-997f-v4rm-9w7m/GHSA-997f-v4rm-9w7m.json +++ b/advisories/unreviewed/2023/01/GHSA-997f-v4rm-9w7m/GHSA-997f-v4rm-9w7m.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-9pwg-jcxf-3vjr/GHSA-9pwg-jcxf-3vjr.json b/advisories/unreviewed/2023/01/GHSA-9pwg-jcxf-3vjr/GHSA-9pwg-jcxf-3vjr.json index 909b2cad501..429a72cfdc6 100644 --- a/advisories/unreviewed/2023/01/GHSA-9pwg-jcxf-3vjr/GHSA-9pwg-jcxf-3vjr.json +++ b/advisories/unreviewed/2023/01/GHSA-9pwg-jcxf-3vjr/GHSA-9pwg-jcxf-3vjr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9pwg-jcxf-3vjr", - "modified": "2023-01-26T21:30:31Z", + "modified": "2025-04-04T18:30:32Z", "published": "2023-01-18T21:30:21Z", "aliases": [ "CVE-2022-45926" diff --git a/advisories/unreviewed/2023/01/GHSA-hf4r-p94v-76j9/GHSA-hf4r-p94v-76j9.json b/advisories/unreviewed/2023/01/GHSA-hf4r-p94v-76j9/GHSA-hf4r-p94v-76j9.json index 70603802ef0..b6f490814de 100644 --- a/advisories/unreviewed/2023/01/GHSA-hf4r-p94v-76j9/GHSA-hf4r-p94v-76j9.json +++ b/advisories/unreviewed/2023/01/GHSA-hf4r-p94v-76j9/GHSA-hf4r-p94v-76j9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hf4r-p94v-76j9", - "modified": "2023-01-26T21:30:31Z", + "modified": "2025-04-04T18:30:32Z", "published": "2023-01-18T21:30:21Z", "aliases": [ "CVE-2022-45922" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-287" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-mcm8-gg2j-q8vh/GHSA-mcm8-gg2j-q8vh.json b/advisories/unreviewed/2023/01/GHSA-mcm8-gg2j-q8vh/GHSA-mcm8-gg2j-q8vh.json index 6a8a22887d0..3826c03c04d 100644 --- a/advisories/unreviewed/2023/01/GHSA-mcm8-gg2j-q8vh/GHSA-mcm8-gg2j-q8vh.json +++ b/advisories/unreviewed/2023/01/GHSA-mcm8-gg2j-q8vh/GHSA-mcm8-gg2j-q8vh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mcm8-gg2j-q8vh", - "modified": "2023-01-25T00:30:39Z", + "modified": "2025-04-04T18:30:26Z", "published": "2023-01-17T12:30:33Z", "aliases": [ "CVE-2023-22280" diff --git a/advisories/unreviewed/2023/01/GHSA-rjg6-q2fh-x6mj/GHSA-rjg6-q2fh-x6mj.json b/advisories/unreviewed/2023/01/GHSA-rjg6-q2fh-x6mj/GHSA-rjg6-q2fh-x6mj.json index a9e609cc83b..7e1c40ae07d 100644 --- a/advisories/unreviewed/2023/01/GHSA-rjg6-q2fh-x6mj/GHSA-rjg6-q2fh-x6mj.json +++ b/advisories/unreviewed/2023/01/GHSA-rjg6-q2fh-x6mj/GHSA-rjg6-q2fh-x6mj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-489" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-rp59-mwr6-m562/GHSA-rp59-mwr6-m562.json b/advisories/unreviewed/2023/01/GHSA-rp59-mwr6-m562/GHSA-rp59-mwr6-m562.json index 6381032c662..9ccf741ffaa 100644 --- a/advisories/unreviewed/2023/01/GHSA-rp59-mwr6-m562/GHSA-rp59-mwr6-m562.json +++ b/advisories/unreviewed/2023/01/GHSA-rp59-mwr6-m562/GHSA-rp59-mwr6-m562.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rp59-mwr6-m562", - "modified": "2023-01-30T15:30:36Z", + "modified": "2025-04-04T18:30:32Z", "published": "2023-01-19T00:30:30Z", "aliases": [ "CVE-2022-45927" diff --git a/advisories/unreviewed/2023/01/GHSA-w4pj-7rh2-rxw2/GHSA-w4pj-7rh2-rxw2.json b/advisories/unreviewed/2023/01/GHSA-w4pj-7rh2-rxw2/GHSA-w4pj-7rh2-rxw2.json index 89774fa5937..2d9c8091c82 100644 --- a/advisories/unreviewed/2023/01/GHSA-w4pj-7rh2-rxw2/GHSA-w4pj-7rh2-rxw2.json +++ b/advisories/unreviewed/2023/01/GHSA-w4pj-7rh2-rxw2/GHSA-w4pj-7rh2-rxw2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w4pj-7rh2-rxw2", - "modified": "2023-01-25T21:30:19Z", + "modified": "2025-04-04T18:30:31Z", "published": "2023-01-18T18:30:16Z", "aliases": [ "CVE-2022-45613" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://github.com/lithonn/bug-report/tree/main/vendors/oretnom23/bsms_ci/stored-xss" }, + { + "type": "WEB", + "url": "https://medium.com/%40just0rg/book-store-management-system-1-0-unrestricted-input-leads-to-xss-74506d42492e" + }, { "type": "WEB", "url": "https://medium.com/@just0rg/book-store-management-system-1-0-unrestricted-input-leads-to-xss-74506d42492e" diff --git a/advisories/unreviewed/2023/01/GHSA-w8m5-v6rc-xwx3/GHSA-w8m5-v6rc-xwx3.json b/advisories/unreviewed/2023/01/GHSA-w8m5-v6rc-xwx3/GHSA-w8m5-v6rc-xwx3.json index a89cb9e8880..5366038e035 100644 --- a/advisories/unreviewed/2023/01/GHSA-w8m5-v6rc-xwx3/GHSA-w8m5-v6rc-xwx3.json +++ b/advisories/unreviewed/2023/01/GHSA-w8m5-v6rc-xwx3/GHSA-w8m5-v6rc-xwx3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w8m5-v6rc-xwx3", - "modified": "2023-01-24T21:30:28Z", + "modified": "2025-04-04T18:30:27Z", "published": "2023-01-17T12:30:33Z", "aliases": [ "CVE-2023-22303" diff --git a/advisories/unreviewed/2023/01/GHSA-x479-hw9c-267v/GHSA-x479-hw9c-267v.json b/advisories/unreviewed/2023/01/GHSA-x479-hw9c-267v/GHSA-x479-hw9c-267v.json index 5657b5afdcb..8a8a5279d82 100644 --- a/advisories/unreviewed/2023/01/GHSA-x479-hw9c-267v/GHSA-x479-hw9c-267v.json +++ b/advisories/unreviewed/2023/01/GHSA-x479-hw9c-267v/GHSA-x479-hw9c-267v.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-912" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-r8hg-vj8p-8m82/GHSA-r8hg-vj8p-8m82.json b/advisories/unreviewed/2024/03/GHSA-r8hg-vj8p-8m82/GHSA-r8hg-vj8p-8m82.json index df158906754..c308b96b46d 100644 --- a/advisories/unreviewed/2024/03/GHSA-r8hg-vj8p-8m82/GHSA-r8hg-vj8p-8m82.json +++ b/advisories/unreviewed/2024/03/GHSA-r8hg-vj8p-8m82/GHSA-r8hg-vj8p-8m82.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-r8hg-vj8p-8m82", - "modified": "2024-03-25T12:30:52Z", + "modified": "2025-04-04T18:30:33Z", "published": "2024-03-25T12:30:52Z", "aliases": [ "CVE-2022-44626" ], - "details": "Missing Authorization vulnerability in Squirrly SEO Plugin by Squirrly SEO.This issue affects SEO Plugin by Squirrly SEO: from n/a through 12.1.20.\n\n", + "details": "Missing Authorization vulnerability in Squirrly SEO Plugin by Squirrly SEO.This issue affects SEO Plugin by Squirrly SEO: from n/a through 12.1.20.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-v728-2v4r-c686/GHSA-v728-2v4r-c686.json b/advisories/unreviewed/2024/03/GHSA-v728-2v4r-c686/GHSA-v728-2v4r-c686.json index c2aa2eff438..4f94cfd549a 100644 --- a/advisories/unreviewed/2024/03/GHSA-v728-2v4r-c686/GHSA-v728-2v4r-c686.json +++ b/advisories/unreviewed/2024/03/GHSA-v728-2v4r-c686/GHSA-v728-2v4r-c686.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-35" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/01/GHSA-wv44-3j27-fqq2/GHSA-wv44-3j27-fqq2.json b/advisories/unreviewed/2025/01/GHSA-wv44-3j27-fqq2/GHSA-wv44-3j27-fqq2.json index 068a3799775..0d2882420ae 100644 --- a/advisories/unreviewed/2025/01/GHSA-wv44-3j27-fqq2/GHSA-wv44-3j27-fqq2.json +++ b/advisories/unreviewed/2025/01/GHSA-wv44-3j27-fqq2/GHSA-wv44-3j27-fqq2.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-chfj-fxfr-5gj5/GHSA-chfj-fxfr-5gj5.json b/advisories/unreviewed/2025/02/GHSA-chfj-fxfr-5gj5/GHSA-chfj-fxfr-5gj5.json index 5dd9f9a863c..9c2bea03df7 100644 --- a/advisories/unreviewed/2025/02/GHSA-chfj-fxfr-5gj5/GHSA-chfj-fxfr-5gj5.json +++ b/advisories/unreviewed/2025/02/GHSA-chfj-fxfr-5gj5/GHSA-chfj-fxfr-5gj5.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-79" + "CWE-79", + "CWE-918" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-23qf-8c5g-2ccx/GHSA-23qf-8c5g-2ccx.json b/advisories/unreviewed/2025/04/GHSA-23qf-8c5g-2ccx/GHSA-23qf-8c5g-2ccx.json new file mode 100644 index 00000000000..24c72fa332f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-23qf-8c5g-2ccx/GHSA-23qf-8c5g-2ccx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23qf-8c5g-2ccx", + "modified": "2025-04-04T18:30:59Z", + "published": "2025-04-04T18:30:59Z", + "aliases": [ + "CVE-2025-32161" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryo Arkhe Blocks allows Stored XSS. This issue affects Arkhe Blocks: from n/a through 2.27.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32161" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/arkhe-blocks/vulnerability/wordpress-arkhe-blocks-2-27-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-24q7-r976-rj33/GHSA-24q7-r976-rj33.json b/advisories/unreviewed/2025/04/GHSA-24q7-r976-rj33/GHSA-24q7-r976-rj33.json new file mode 100644 index 00000000000..5a7d3a9d30d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-24q7-r976-rj33/GHSA-24q7-r976-rj33.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24q7-r976-rj33", + "modified": "2025-04-04T18:30:57Z", + "published": "2025-04-04T18:30:57Z", + "aliases": [ + "CVE-2025-32120" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Erick Danzer Easy Query – WP Query Builder allows Blind SQL Injection. This issue affects Easy Query – WP Query Builder: from n/a through 2.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32120" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-query/vulnerability/wordpress-easy-query-wp-query-builder-2-0-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-25qh-ff2q-jm3q/GHSA-25qh-ff2q-jm3q.json b/advisories/unreviewed/2025/04/GHSA-25qh-ff2q-jm3q/GHSA-25qh-ff2q-jm3q.json new file mode 100644 index 00000000000..548924c8e8f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-25qh-ff2q-jm3q/GHSA-25qh-ff2q-jm3q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25qh-ff2q-jm3q", + "modified": "2025-04-04T18:30:55Z", + "published": "2025-04-04T18:30:55Z", + "aliases": [ + "CVE-2025-32112" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Sidebar Manager Light allows Cross Site Request Forgery. This issue affects Sidebar Manager Light: from n/a through 1.1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32112" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sidebar-manager-light/vulnerability/wordpress-sidebar-manager-light-plugin-1-1-8-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-27wg-3m5v-r5fh/GHSA-27wg-3m5v-r5fh.json b/advisories/unreviewed/2025/04/GHSA-27wg-3m5v-r5fh/GHSA-27wg-3m5v-r5fh.json new file mode 100644 index 00000000000..31441f32f7b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-27wg-3m5v-r5fh/GHSA-27wg-3m5v-r5fh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27wg-3m5v-r5fh", + "modified": "2025-04-04T18:31:00Z", + "published": "2025-04-04T18:31:00Z", + "aliases": [ + "CVE-2025-32184" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes Ultimate Store Kit Elementor Addons allows Stored XSS. This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32184" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-store-kit/vulnerability/wordpress-ultimate-store-kit-elementor-addons-plugin-2-4-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-292w-2m2h-rw25/GHSA-292w-2m2h-rw25.json b/advisories/unreviewed/2025/04/GHSA-292w-2m2h-rw25/GHSA-292w-2m2h-rw25.json new file mode 100644 index 00000000000..7454203a165 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-292w-2m2h-rw25/GHSA-292w-2m2h-rw25.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-292w-2m2h-rw25", + "modified": "2025-04-04T18:30:58Z", + "published": "2025-04-04T18:30:58Z", + "aliases": [ + "CVE-2025-32137" + ], + "details": "Relative Path Traversal vulnerability in Cristián Lávaque s2Member allows Path Traversal. This issue affects s2Member: from n/a through 250214.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32137" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/s2member/vulnerability/wordpress-s2member-plugin-250214-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2936-3xwv-v4fj/GHSA-2936-3xwv-v4fj.json b/advisories/unreviewed/2025/04/GHSA-2936-3xwv-v4fj/GHSA-2936-3xwv-v4fj.json new file mode 100644 index 00000000000..3363bb71dda --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2936-3xwv-v4fj/GHSA-2936-3xwv-v4fj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2936-3xwv-v4fj", + "modified": "2025-04-04T18:31:02Z", + "published": "2025-04-04T18:31:02Z", + "aliases": [ + "CVE-2025-32207" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anzar Ahmed Ni WooCommerce Cost Of Goods allows Stored XSS. This issue affects Ni WooCommerce Cost Of Goods: from n/a through 3.2.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32207" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ni-woocommerce-cost-of-goods/vulnerability/wordpress-ni-woocommerce-cost-of-goods-plugin-3-2-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-297g-cjpm-qw2x/GHSA-297g-cjpm-qw2x.json b/advisories/unreviewed/2025/04/GHSA-297g-cjpm-qw2x/GHSA-297g-cjpm-qw2x.json new file mode 100644 index 00000000000..3a4a1ddc9a0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-297g-cjpm-qw2x/GHSA-297g-cjpm-qw2x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-297g-cjpm-qw2x", + "modified": "2025-04-04T18:31:05Z", + "published": "2025-04-04T18:31:05Z", + "aliases": [ + "CVE-2025-32257" + ], + "details": "Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration allows Retrieve Embedded Sensitive Data. This issue affects 1 Click WordPress Migration: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32257" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/1-click-migration/vulnerability/wordpress-1-click-wordpress-migration-plugin-2-1-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1258" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2hgm-xvx6-w372/GHSA-2hgm-xvx6-w372.json b/advisories/unreviewed/2025/04/GHSA-2hgm-xvx6-w372/GHSA-2hgm-xvx6-w372.json index 8a9981f7e82..f4dd1570e0c 100644 --- a/advisories/unreviewed/2025/04/GHSA-2hgm-xvx6-w372/GHSA-2hgm-xvx6-w372.json +++ b/advisories/unreviewed/2025/04/GHSA-2hgm-xvx6-w372/GHSA-2hgm-xvx6-w372.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2hgm-xvx6-w372", - "modified": "2025-04-03T21:32:59Z", + "modified": "2025-04-04T18:30:53Z", "published": "2025-04-03T21:32:59Z", "aliases": [ "CVE-2025-26818" ], "details": "Netwrix Password Secure through 9.2 allows command injection.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-03T20:15:23Z" diff --git a/advisories/unreviewed/2025/04/GHSA-2p2x-5p75-jj56/GHSA-2p2x-5p75-jj56.json b/advisories/unreviewed/2025/04/GHSA-2p2x-5p75-jj56/GHSA-2p2x-5p75-jj56.json new file mode 100644 index 00000000000..bafc2babd05 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2p2x-5p75-jj56/GHSA-2p2x-5p75-jj56.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2p2x-5p75-jj56", + "modified": "2025-04-04T18:30:57Z", + "published": "2025-04-04T18:30:57Z", + "aliases": [ + "CVE-2025-32126" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cmsMinds Pay with Contact Form 7 allows SQL Injection. This issue affects Pay with Contact Form 7: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32126" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pay-with-contact-form-7/vulnerability/wordpress-pay-with-contact-form-7-plugin-1-0-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2rmv-cg3m-3gq6/GHSA-2rmv-cg3m-3gq6.json b/advisories/unreviewed/2025/04/GHSA-2rmv-cg3m-3gq6/GHSA-2rmv-cg3m-3gq6.json new file mode 100644 index 00000000000..b028d5ca250 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2rmv-cg3m-3gq6/GHSA-2rmv-cg3m-3gq6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rmv-cg3m-3gq6", + "modified": "2025-04-04T18:31:02Z", + "published": "2025-04-04T18:31:02Z", + "aliases": [ + "CVE-2025-32219" + ], + "details": "Missing Authorization vulnerability in Syntactics, Inc. eaSYNC allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects eaSYNC: from n/a through 1.3.19.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32219" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easync-booking/vulnerability/wordpress-easync-plugin-1-3-19-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-32cc-f5gm-cv4r/GHSA-32cc-f5gm-cv4r.json b/advisories/unreviewed/2025/04/GHSA-32cc-f5gm-cv4r/GHSA-32cc-f5gm-cv4r.json new file mode 100644 index 00000000000..87ee6bcca33 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-32cc-f5gm-cv4r/GHSA-32cc-f5gm-cv4r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32cc-f5gm-cv4r", + "modified": "2025-04-04T18:30:59Z", + "published": "2025-04-04T18:30:59Z", + "aliases": [ + "CVE-2025-32148" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daisycon Daisycon prijsvergelijkers allows SQL Injection. This issue affects Daisycon prijsvergelijkers: from n/a through 4.8.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32148" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/daisycon/vulnerability/wordpress-daisycon-prijsvergelijkers-plugin-4-8-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-33p4-8hxp-x9pp/GHSA-33p4-8hxp-x9pp.json b/advisories/unreviewed/2025/04/GHSA-33p4-8hxp-x9pp/GHSA-33p4-8hxp-x9pp.json new file mode 100644 index 00000000000..a3a363e1de4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-33p4-8hxp-x9pp/GHSA-33p4-8hxp-x9pp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33p4-8hxp-x9pp", + "modified": "2025-04-04T18:31:01Z", + "published": "2025-04-04T18:31:01Z", + "aliases": [ + "CVE-2025-32200" + ], + "details": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Nikita Advanced WordPress Backgrounds allows Code Injection. This issue affects Advanced WordPress Backgrounds: from n/a through 1.12.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32200" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-backgrounds/vulnerability/wordpress-advanced-wordpress-backgrounds-plugin-1-12-4-content-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-33v3-39cv-j2g7/GHSA-33v3-39cv-j2g7.json b/advisories/unreviewed/2025/04/GHSA-33v3-39cv-j2g7/GHSA-33v3-39cv-j2g7.json new file mode 100644 index 00000000000..9c2a013600f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-33v3-39cv-j2g7/GHSA-33v3-39cv-j2g7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33v3-39cv-j2g7", + "modified": "2025-04-04T18:30:58Z", + "published": "2025-04-04T18:30:58Z", + "aliases": [ + "CVE-2025-32134" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders URL Shortify allows Stored XSS. This issue affects URL Shortify: from n/a through 1.10.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32134" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/url-shortify/vulnerability/wordpress-url-shortify-plugin-1-10-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-348f-gwqg-3m3w/GHSA-348f-gwqg-3m3w.json b/advisories/unreviewed/2025/04/GHSA-348f-gwqg-3m3w/GHSA-348f-gwqg-3m3w.json new file mode 100644 index 00000000000..280eef9f568 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-348f-gwqg-3m3w/GHSA-348f-gwqg-3m3w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-348f-gwqg-3m3w", + "modified": "2025-04-04T18:31:00Z", + "published": "2025-04-04T18:31:00Z", + "aliases": [ + "CVE-2025-32176" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GalleryCreator Gallery Blocks with Lightbox allows Stored XSS. This issue affects Gallery Blocks with Lightbox: from n/a through 3.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32176" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simply-gallery-block/vulnerability/wordpress-gallery-blocks-with-lightbox-plugin-3-2-5-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-38v2-f365-h79h/GHSA-38v2-f365-h79h.json b/advisories/unreviewed/2025/04/GHSA-38v2-f365-h79h/GHSA-38v2-f365-h79h.json index 286fbcabd12..16052356386 100644 --- a/advisories/unreviewed/2025/04/GHSA-38v2-f365-h79h/GHSA-38v2-f365-h79h.json +++ b/advisories/unreviewed/2025/04/GHSA-38v2-f365-h79h/GHSA-38v2-f365-h79h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-38v2-f365-h79h", - "modified": "2025-04-03T21:32:59Z", + "modified": "2025-04-04T18:30:53Z", "published": "2025-04-03T21:32:59Z", "aliases": [ "CVE-2025-29504" ], "details": "Insecure Permission vulnerability in student-manage 1 allows a local attacker to escalate privileges via the Unsafe permission verification.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-03T20:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-3c54-wfm9-c82p/GHSA-3c54-wfm9-c82p.json b/advisories/unreviewed/2025/04/GHSA-3c54-wfm9-c82p/GHSA-3c54-wfm9-c82p.json new file mode 100644 index 00000000000..4f45aa6bf09 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3c54-wfm9-c82p/GHSA-3c54-wfm9-c82p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c54-wfm9-c82p", + "modified": "2025-04-04T18:30:58Z", + "published": "2025-04-04T18:30:58Z", + "aliases": [ + "CVE-2025-32135" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rocketelements Split Test For Elementor allows Stored XSS. This issue affects Split Test For Elementor: from n/a through 1.8.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32135" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/split-test-for-elementor/vulnerability/wordpress-split-test-for-elementor-plugin-1-8-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3fc4-pmmp-65rw/GHSA-3fc4-pmmp-65rw.json b/advisories/unreviewed/2025/04/GHSA-3fc4-pmmp-65rw/GHSA-3fc4-pmmp-65rw.json new file mode 100644 index 00000000000..eb51a933fc1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3fc4-pmmp-65rw/GHSA-3fc4-pmmp-65rw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fc4-pmmp-65rw", + "modified": "2025-04-04T18:31:07Z", + "published": "2025-04-04T18:31:06Z", + "aliases": [ + "CVE-2025-32280" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager allows Cross Site Request Forgery. This issue affects WP Project Manager: from n/a through 2.6.22.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32280" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wedevs-project-manager/vulnerability/wordpress-wp-project-manager-plugin-2-6-22-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3m4q-2j85-4rqv/GHSA-3m4q-2j85-4rqv.json b/advisories/unreviewed/2025/04/GHSA-3m4q-2j85-4rqv/GHSA-3m4q-2j85-4rqv.json new file mode 100644 index 00000000000..bd801c4ede2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3m4q-2j85-4rqv/GHSA-3m4q-2j85-4rqv.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3m4q-2j85-4rqv", + "modified": "2025-04-04T18:31:07Z", + "published": "2025-04-04T18:31:07Z", + "aliases": [ + "CVE-2025-3253" + ], + "details": "A vulnerability was found in xujiangfei admintwo 1.0 and classified as problematic. This issue affects some unknown processing of the file /ztree/insertTree. The manipulation of the argument Name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3253" + }, + { + "type": "WEB", + "url": "https://github.com/caigo8/CVE-md/blob/main/admintwo/XSS3.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303323" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303323" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.548978" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3mfh-m3cw-mjq8/GHSA-3mfh-m3cw-mjq8.json b/advisories/unreviewed/2025/04/GHSA-3mfh-m3cw-mjq8/GHSA-3mfh-m3cw-mjq8.json new file mode 100644 index 00000000000..7029e551ebe --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3mfh-m3cw-mjq8/GHSA-3mfh-m3cw-mjq8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mfh-m3cw-mjq8", + "modified": "2025-04-04T18:31:04Z", + "published": "2025-04-04T18:31:04Z", + "aliases": [ + "CVE-2025-32252" + ], + "details": "Missing Authorization vulnerability in blackandwhitedigital WP Genealogy – Your Family History Website allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Genealogy – Your Family History Website: from n/a through 0.1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32252" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpgenealogy/vulnerability/wordpress-wp-genealogy-plugin-0-1-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3qjh-r982-mhgp/GHSA-3qjh-r982-mhgp.json b/advisories/unreviewed/2025/04/GHSA-3qjh-r982-mhgp/GHSA-3qjh-r982-mhgp.json new file mode 100644 index 00000000000..2079b318ab8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3qjh-r982-mhgp/GHSA-3qjh-r982-mhgp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qjh-r982-mhgp", + "modified": "2025-04-04T18:31:04Z", + "published": "2025-04-04T18:31:04Z", + "aliases": [ + "CVE-2025-32250" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in rollbar Rollbar allows Cross Site Request Forgery. This issue affects Rollbar: from n/a through 2.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32250" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rollbar/vulnerability/wordpress-rollbar-plugin-2-7-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-46gh-76jc-p9hf/GHSA-46gh-76jc-p9hf.json b/advisories/unreviewed/2025/04/GHSA-46gh-76jc-p9hf/GHSA-46gh-76jc-p9hf.json new file mode 100644 index 00000000000..f257966a935 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-46gh-76jc-p9hf/GHSA-46gh-76jc-p9hf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46gh-76jc-p9hf", + "modified": "2025-04-04T18:30:59Z", + "published": "2025-04-04T18:30:59Z", + "aliases": [ + "CVE-2025-32150" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rameez Iqbal Real Estate Manager allows PHP Local File Inclusion. This issue affects Real Estate Manager: from n/a through 7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32150" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/real-estate-manager/vulnerability/wordpress-real-estate-manager-plugin-7-3-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-48qm-p36x-5fv5/GHSA-48qm-p36x-5fv5.json b/advisories/unreviewed/2025/04/GHSA-48qm-p36x-5fv5/GHSA-48qm-p36x-5fv5.json new file mode 100644 index 00000000000..d4e36f65166 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-48qm-p36x-5fv5/GHSA-48qm-p36x-5fv5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48qm-p36x-5fv5", + "modified": "2025-04-04T18:31:03Z", + "published": "2025-04-04T18:31:03Z", + "aliases": [ + "CVE-2025-32231" + ], + "details": "Missing Authorization vulnerability in Bookingor Bookingor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bookingor: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32231" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bookingor/vulnerability/wordpress-bookingor-plugin-1-0-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-49p8-6x78-xh2g/GHSA-49p8-6x78-xh2g.json b/advisories/unreviewed/2025/04/GHSA-49p8-6x78-xh2g/GHSA-49p8-6x78-xh2g.json new file mode 100644 index 00000000000..3beaf72fbbe --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-49p8-6x78-xh2g/GHSA-49p8-6x78-xh2g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49p8-6x78-xh2g", + "modified": "2025-04-04T18:31:02Z", + "published": "2025-04-04T18:31:02Z", + "aliases": [ + "CVE-2025-32224" + ], + "details": "Missing Authorization vulnerability in shivammani Privyr CRM allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Privyr CRM: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32224" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/privy-crm-integration/vulnerability/wordpress-privyr-crm-plugin-1-0-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4j3j-jm2r-6hf2/GHSA-4j3j-jm2r-6hf2.json b/advisories/unreviewed/2025/04/GHSA-4j3j-jm2r-6hf2/GHSA-4j3j-jm2r-6hf2.json new file mode 100644 index 00000000000..48aa14fc03a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4j3j-jm2r-6hf2/GHSA-4j3j-jm2r-6hf2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4j3j-jm2r-6hf2", + "modified": "2025-04-04T18:31:00Z", + "published": "2025-04-04T18:31:00Z", + "aliases": [ + "CVE-2025-32175" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vektor,Inc. VK Filter Search allows Stored XSS. This issue affects VK Filter Search: from n/a through 2.14.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32175" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/vk-filter-search/vulnerability/wordpress-vk-filter-search-plugin-2-14-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4m65-68v8-frj9/GHSA-4m65-68v8-frj9.json b/advisories/unreviewed/2025/04/GHSA-4m65-68v8-frj9/GHSA-4m65-68v8-frj9.json new file mode 100644 index 00000000000..0a102971241 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4m65-68v8-frj9/GHSA-4m65-68v8-frj9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m65-68v8-frj9", + "modified": "2025-04-04T18:31:06Z", + "published": "2025-04-04T18:31:06Z", + "aliases": [ + "CVE-2025-32271" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ablancodev Woocommerce Role Pricing allows Cross Site Request Forgery. This issue affects Woocommerce Role Pricing: from n/a through 3.5.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32271" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-role-pricing/vulnerability/wordpress-woocommerce-role-pricing-plugin-3-5-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4vq9-542f-qfqx/GHSA-4vq9-542f-qfqx.json b/advisories/unreviewed/2025/04/GHSA-4vq9-542f-qfqx/GHSA-4vq9-542f-qfqx.json new file mode 100644 index 00000000000..a6a8c024b31 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4vq9-542f-qfqx/GHSA-4vq9-542f-qfqx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vq9-542f-qfqx", + "modified": "2025-04-04T18:31:03Z", + "published": "2025-04-04T18:31:03Z", + "aliases": [ + "CVE-2025-32241" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in CleverReach® Official CleverReach Plugin for WooCommerce allows Cross Site Request Forgery. This issue affects Official CleverReach Plugin for WooCommerce: from n/a through 3.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32241" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cleverreach-wc/vulnerability/wordpress-official-cleverreach-woocommerce-integration-plugin-3-4-3-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-533m-927c-58gv/GHSA-533m-927c-58gv.json b/advisories/unreviewed/2025/04/GHSA-533m-927c-58gv/GHSA-533m-927c-58gv.json new file mode 100644 index 00000000000..584b499cf2b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-533m-927c-58gv/GHSA-533m-927c-58gv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-533m-927c-58gv", + "modified": "2025-04-04T18:30:58Z", + "published": "2025-04-04T18:30:58Z", + "aliases": [ + "CVE-2025-32141" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Stylemix MasterStudy LMS allows PHP Local File Inclusion. This issue affects MasterStudy LMS: from n/a through 3.5.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32141" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/masterstudy-lms-learning-management-system/vulnerability/wordpress-masterstudy-lms-plugin-3-5-23-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-536r-2xvj-w9h5/GHSA-536r-2xvj-w9h5.json b/advisories/unreviewed/2025/04/GHSA-536r-2xvj-w9h5/GHSA-536r-2xvj-w9h5.json index f7d5b3bc38a..3f2a5607690 100644 --- a/advisories/unreviewed/2025/04/GHSA-536r-2xvj-w9h5/GHSA-536r-2xvj-w9h5.json +++ b/advisories/unreviewed/2025/04/GHSA-536r-2xvj-w9h5/GHSA-536r-2xvj-w9h5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-536r-2xvj-w9h5", - "modified": "2025-04-03T21:32:59Z", + "modified": "2025-04-04T18:30:53Z", "published": "2025-04-03T21:32:59Z", "aliases": [ "CVE-2025-26817" ], "details": "Netwrix Password Secure 9.2.0.32454 allows OS command injection.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-03T20:15:23Z" diff --git a/advisories/unreviewed/2025/04/GHSA-53fr-m6m9-h6fv/GHSA-53fr-m6m9-h6fv.json b/advisories/unreviewed/2025/04/GHSA-53fr-m6m9-h6fv/GHSA-53fr-m6m9-h6fv.json new file mode 100644 index 00000000000..7cd2755b7b5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-53fr-m6m9-h6fv/GHSA-53fr-m6m9-h6fv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53fr-m6m9-h6fv", + "modified": "2025-04-04T18:31:00Z", + "published": "2025-04-04T18:31:00Z", + "aliases": [ + "CVE-2025-32183" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Galaxy Weblinks Video Playlist For YouTube allows Stored XSS. This issue affects Video Playlist For YouTube: from n/a through 6.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32183" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/video-playlist-for-youtube/vulnerability/wordpress-video-playlist-for-youtube-plugin-6-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-55jg-j97x-gccv/GHSA-55jg-j97x-gccv.json b/advisories/unreviewed/2025/04/GHSA-55jg-j97x-gccv/GHSA-55jg-j97x-gccv.json new file mode 100644 index 00000000000..556785edc29 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-55jg-j97x-gccv/GHSA-55jg-j97x-gccv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55jg-j97x-gccv", + "modified": "2025-04-04T18:31:00Z", + "published": "2025-04-04T18:31:00Z", + "aliases": [ + "CVE-2025-32171" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imtiaz Rayhan Table Block by Tableberg allows Stored XSS. This issue affects Table Block by Tableberg: from n/a through 0.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32171" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tableberg/vulnerability/wordpress-table-block-by-tableberg-best-wordpress-table-plugin-plugin-0-6-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5834-r77w-87g8/GHSA-5834-r77w-87g8.json b/advisories/unreviewed/2025/04/GHSA-5834-r77w-87g8/GHSA-5834-r77w-87g8.json new file mode 100644 index 00000000000..0bf54ee9bac --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5834-r77w-87g8/GHSA-5834-r77w-87g8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5834-r77w-87g8", + "modified": "2025-04-04T18:31:01Z", + "published": "2025-04-04T18:31:01Z", + "aliases": [ + "CVE-2025-32192" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UltraPress Ultra Addons Lite for Elementor allows Stored XSS. This issue affects Ultra Addons Lite for Elementor: from n/a through 1.1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32192" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ut-elementor-addons-lite/vulnerability/wordpress-ultra-addons-lite-for-elementor-plugin-1-1-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-58w8-2mhp-h5r5/GHSA-58w8-2mhp-h5r5.json b/advisories/unreviewed/2025/04/GHSA-58w8-2mhp-h5r5/GHSA-58w8-2mhp-h5r5.json new file mode 100644 index 00000000000..90dfb04e5a4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-58w8-2mhp-h5r5/GHSA-58w8-2mhp-h5r5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58w8-2mhp-h5r5", + "modified": "2025-04-04T18:31:07Z", + "published": "2025-04-04T18:31:07Z", + "aliases": [ + "CVE-2025-32277" + ], + "details": "Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 3.8211.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32277" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/computer-repair-shop/vulnerability/wordpress-repairbuddy-plugin-3-8211-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5fmm-w9xf-8f6h/GHSA-5fmm-w9xf-8f6h.json b/advisories/unreviewed/2025/04/GHSA-5fmm-w9xf-8f6h/GHSA-5fmm-w9xf-8f6h.json new file mode 100644 index 00000000000..fa6dd6328ef --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5fmm-w9xf-8f6h/GHSA-5fmm-w9xf-8f6h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fmm-w9xf-8f6h", + "modified": "2025-04-04T18:31:01Z", + "published": "2025-04-04T18:31:01Z", + "aliases": [ + "CVE-2025-32190" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smartwpress Musician's Pack for Elementor allows DOM-Based XSS. This issue affects Musician's Pack for Elementor: from n/a through 1.8.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32190" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/music-pack-for-elementor/vulnerability/wordpress-musician-s-pack-for-elementor-plugin-1-8-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5j8g-xc7j-xf8r/GHSA-5j8g-xc7j-xf8r.json b/advisories/unreviewed/2025/04/GHSA-5j8g-xc7j-xf8r/GHSA-5j8g-xc7j-xf8r.json new file mode 100644 index 00000000000..4c10eefb70b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5j8g-xc7j-xf8r/GHSA-5j8g-xc7j-xf8r.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5j8g-xc7j-xf8r", + "modified": "2025-04-04T18:31:07Z", + "published": "2025-04-04T18:31:07Z", + "aliases": [ + "CVE-2025-3252" + ], + "details": "A vulnerability has been found in xujiangfei admintwo 1.0 and classified as problematic. This vulnerability affects unknown code of the file /resource/add. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3252" + }, + { + "type": "WEB", + "url": "https://github.com/caigo8/CVE-md/blob/main/admintwo/XSS2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303322" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303322" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.548976" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5mr6-5wcg-74r4/GHSA-5mr6-5wcg-74r4.json b/advisories/unreviewed/2025/04/GHSA-5mr6-5wcg-74r4/GHSA-5mr6-5wcg-74r4.json new file mode 100644 index 00000000000..4fea8e6aaa5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5mr6-5wcg-74r4/GHSA-5mr6-5wcg-74r4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mr6-5wcg-74r4", + "modified": "2025-04-04T18:30:59Z", + "published": "2025-04-04T18:30:59Z", + "aliases": [ + "CVE-2025-32147" + ], + "details": "Missing Authorization vulnerability in coothemes Easy WP Optimizer allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Easy WP Optimizer: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32147" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-wp-optimizer/vulnerability/wordpress-easy-wp-optimizer-plugin-1-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5r22-vg92-qjr6/GHSA-5r22-vg92-qjr6.json b/advisories/unreviewed/2025/04/GHSA-5r22-vg92-qjr6/GHSA-5r22-vg92-qjr6.json new file mode 100644 index 00000000000..68f6b6478af --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5r22-vg92-qjr6/GHSA-5r22-vg92-qjr6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r22-vg92-qjr6", + "modified": "2025-04-04T18:31:05Z", + "published": "2025-04-04T18:31:05Z", + "aliases": [ + "CVE-2025-32263" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in BeRocket Sequential Order Numbers for WooCommerce allows Cross Site Request Forgery. This issue affects Sequential Order Numbers for WooCommerce: from n/a through 3.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32263" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sequential-order-numbers-for-woocommerce/vulnerability/wordpress-sequential-order-numbers-for-woocommerce-plugin-3-6-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5rw3-67c7-2r72/GHSA-5rw3-67c7-2r72.json b/advisories/unreviewed/2025/04/GHSA-5rw3-67c7-2r72/GHSA-5rw3-67c7-2r72.json new file mode 100644 index 00000000000..62cfda25fd4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5rw3-67c7-2r72/GHSA-5rw3-67c7-2r72.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rw3-67c7-2r72", + "modified": "2025-04-04T18:31:00Z", + "published": "2025-04-04T18:31:00Z", + "aliases": [ + "CVE-2025-32179" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icopydoc Maps for WP allows Stored XSS. This issue affects Maps for WP: from n/a through 1.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32179" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/maps-for-wp/vulnerability/wordpress-maps-for-wp-plugin-1-2-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5v3v-4xvw-m8wx/GHSA-5v3v-4xvw-m8wx.json b/advisories/unreviewed/2025/04/GHSA-5v3v-4xvw-m8wx/GHSA-5v3v-4xvw-m8wx.json new file mode 100644 index 00000000000..ff2f9e5e823 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5v3v-4xvw-m8wx/GHSA-5v3v-4xvw-m8wx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v3v-4xvw-m8wx", + "modified": "2025-04-04T18:30:57Z", + "published": "2025-04-04T18:30:56Z", + "aliases": [ + "CVE-2025-32121" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member allows SQL Injection. This issue affects Video & Photo Gallery for Ultimate Member: from n/a through 1.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32121" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gallery-for-ultimate-member/vulnerability/wordpress-video-photo-gallery-for-ultimate-member-plugin-1-1-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-677v-x6v7-4m5c/GHSA-677v-x6v7-4m5c.json b/advisories/unreviewed/2025/04/GHSA-677v-x6v7-4m5c/GHSA-677v-x6v7-4m5c.json new file mode 100644 index 00000000000..a7ef0712d79 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-677v-x6v7-4m5c/GHSA-677v-x6v7-4m5c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-677v-x6v7-4m5c", + "modified": "2025-04-04T18:31:00Z", + "published": "2025-04-04T18:31:00Z", + "aliases": [ + "CVE-2025-32182" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spider Themes Spider Elements – Addons for Elementor allows Stored XSS. This issue affects Spider Elements – Addons for Elementor: from n/a through 1.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32182" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/spider-elements/vulnerability/wordpress-spider-elements-addons-for-elementor-plugin-1-6-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6m2c-4v24-gxm5/GHSA-6m2c-4v24-gxm5.json b/advisories/unreviewed/2025/04/GHSA-6m2c-4v24-gxm5/GHSA-6m2c-4v24-gxm5.json new file mode 100644 index 00000000000..6942265ae95 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6m2c-4v24-gxm5/GHSA-6m2c-4v24-gxm5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m2c-4v24-gxm5", + "modified": "2025-04-04T18:31:03Z", + "published": "2025-04-04T18:31:03Z", + "aliases": [ + "CVE-2025-32234" + ], + "details": "Missing Authorization vulnerability in aleswebs AdMail – Multilingual Back in-Stock Notifier for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AdMail – Multilingual Back in-Stock Notifier for WooCommerce: from n/a through 1.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32234" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/admail/vulnerability/wordpress-admail-plugin-1-7-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6r6c-8crv-p5q8/GHSA-6r6c-8crv-p5q8.json b/advisories/unreviewed/2025/04/GHSA-6r6c-8crv-p5q8/GHSA-6r6c-8crv-p5q8.json new file mode 100644 index 00000000000..2e655e1f447 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6r6c-8crv-p5q8/GHSA-6r6c-8crv-p5q8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r6c-8crv-p5q8", + "modified": "2025-04-04T18:30:58Z", + "published": "2025-04-04T18:30:58Z", + "aliases": [ + "CVE-2025-32131" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in socialintents Social Intents allows Stored XSS. This issue affects Social Intents: from n/a through 1.6.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32131" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/live-chat-support-by-social-intents/vulnerability/wordpress-social-intents-plugin-1-6-14-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6vm4-3fqc-4q75/GHSA-6vm4-3fqc-4q75.json b/advisories/unreviewed/2025/04/GHSA-6vm4-3fqc-4q75/GHSA-6vm4-3fqc-4q75.json new file mode 100644 index 00000000000..27a1bacfe1e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6vm4-3fqc-4q75/GHSA-6vm4-3fqc-4q75.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vm4-3fqc-4q75", + "modified": "2025-04-04T18:31:00Z", + "published": "2025-04-04T18:31:00Z", + "aliases": [ + "CVE-2025-32187" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Quý Lê 91 Administrator Z allows DOM-Based XSS. This issue affects Administrator Z: from n/a through 2025.03.04.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32187" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/administrator-z/vulnerability/wordpress-administrator-z-plugin-2025-03-04-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-74cg-qw7q-36rg/GHSA-74cg-qw7q-36rg.json b/advisories/unreviewed/2025/04/GHSA-74cg-qw7q-36rg/GHSA-74cg-qw7q-36rg.json new file mode 100644 index 00000000000..76eb54d92f2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-74cg-qw7q-36rg/GHSA-74cg-qw7q-36rg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74cg-qw7q-36rg", + "modified": "2025-04-04T18:31:03Z", + "published": "2025-04-04T18:31:03Z", + "aliases": [ + "CVE-2025-32235" + ], + "details": "Missing Authorization vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.9.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32235" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mp3-music-player-by-sonaar/vulnerability/wordpress-mp3-audio-player-music-player-podcast-player-radio-by-sonaar-plugin-5-9-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-75jq-9pj8-r6gp/GHSA-75jq-9pj8-r6gp.json b/advisories/unreviewed/2025/04/GHSA-75jq-9pj8-r6gp/GHSA-75jq-9pj8-r6gp.json new file mode 100644 index 00000000000..e23eb99e47c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-75jq-9pj8-r6gp/GHSA-75jq-9pj8-r6gp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75jq-9pj8-r6gp", + "modified": "2025-04-04T18:31:01Z", + "published": "2025-04-04T18:31:01Z", + "aliases": [ + "CVE-2025-32196" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blazethemes News Kit Elementor Addons allows Stored XSS. This issue affects News Kit Elementor Addons: from n/a through 1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32196" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/news-kit-elementor-addons/vulnerability/wordpress-news-kit-elementor-addons-plugin-1-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-76xx-qqcg-xq7g/GHSA-76xx-qqcg-xq7g.json b/advisories/unreviewed/2025/04/GHSA-76xx-qqcg-xq7g/GHSA-76xx-qqcg-xq7g.json new file mode 100644 index 00000000000..e1e82a7208d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-76xx-qqcg-xq7g/GHSA-76xx-qqcg-xq7g.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76xx-qqcg-xq7g", + "modified": "2025-04-04T18:31:07Z", + "published": "2025-04-04T18:31:07Z", + "aliases": [ + "CVE-2025-3258" + ], + "details": "A vulnerability classified as critical was found in PHPGurukul Old Age Home Management System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3258" + }, + { + "type": "WEB", + "url": "https://github.com/404heihei/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303328" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303328" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.549186" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-796m-gmh7-7w8m/GHSA-796m-gmh7-7w8m.json b/advisories/unreviewed/2025/04/GHSA-796m-gmh7-7w8m/GHSA-796m-gmh7-7w8m.json new file mode 100644 index 00000000000..b593ff4d188 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-796m-gmh7-7w8m/GHSA-796m-gmh7-7w8m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-796m-gmh7-7w8m", + "modified": "2025-04-04T18:30:59Z", + "published": "2025-04-04T18:30:59Z", + "aliases": [ + "CVE-2025-32166" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in John Housholder Emma for WordPress allows Stored XSS. This issue affects Emma for WordPress: from n/a through 1.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32166" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/emma-emarketing-plugin/vulnerability/wordpress-emma-for-wordpress-plugin-1-3-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7q96-rwwg-9q28/GHSA-7q96-rwwg-9q28.json b/advisories/unreviewed/2025/04/GHSA-7q96-rwwg-9q28/GHSA-7q96-rwwg-9q28.json new file mode 100644 index 00000000000..7bbedf6051c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7q96-rwwg-9q28/GHSA-7q96-rwwg-9q28.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q96-rwwg-9q28", + "modified": "2025-04-04T18:31:00Z", + "published": "2025-04-04T18:31:00Z", + "aliases": [ + "CVE-2025-32168" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeYatri Gutenify allows Stored XSS. This issue affects Gutenify: from n/a through 1.4.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32168" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gutenify/vulnerability/wordpress-gutenify-plugin-1-4-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7vqj-84j6-x8w8/GHSA-7vqj-84j6-x8w8.json b/advisories/unreviewed/2025/04/GHSA-7vqj-84j6-x8w8/GHSA-7vqj-84j6-x8w8.json new file mode 100644 index 00000000000..84db3ca5bd2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7vqj-84j6-x8w8/GHSA-7vqj-84j6-x8w8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vqj-84j6-x8w8", + "modified": "2025-04-04T18:31:06Z", + "published": "2025-04-04T18:31:06Z", + "aliases": [ + "CVE-2025-32270" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Broadstreet Broadstreet allows Cross Site Request Forgery. This issue affects Broadstreet: from n/a through 1.51.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32270" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/broadstreet/vulnerability/wordpress-broadstreet-plugin-1-51-1-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-82j2-c22m-fhxr/GHSA-82j2-c22m-fhxr.json b/advisories/unreviewed/2025/04/GHSA-82j2-c22m-fhxr/GHSA-82j2-c22m-fhxr.json new file mode 100644 index 00000000000..f823aa8dbf9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-82j2-c22m-fhxr/GHSA-82j2-c22m-fhxr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82j2-c22m-fhxr", + "modified": "2025-04-04T18:31:04Z", + "published": "2025-04-04T18:31:04Z", + "aliases": [ + "CVE-2025-32248" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in SwiftXR SwiftXR (3D/AR/VR) Viewer allows Cross Site Request Forgery. This issue affects SwiftXR (3D/AR/VR) Viewer: from n/a through 1.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32248" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/swiftxr-3darvr-viewer/vulnerability/wordpress-swiftxr-3d-ar-vr-viewer-plugin-1-0-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-87q9-v74q-pqw9/GHSA-87q9-v74q-pqw9.json b/advisories/unreviewed/2025/04/GHSA-87q9-v74q-pqw9/GHSA-87q9-v74q-pqw9.json new file mode 100644 index 00000000000..cd35f2b5e60 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-87q9-v74q-pqw9/GHSA-87q9-v74q-pqw9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87q9-v74q-pqw9", + "modified": "2025-04-04T18:31:04Z", + "published": "2025-04-04T18:31:04Z", + "aliases": [ + "CVE-2025-32251" + ], + "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in J. Tyler Wiest Jetpack Feedback Exporter allows Retrieve Embedded Sensitive Data. This issue affects Jetpack Feedback Exporter: from n/a through 1.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32251" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jetpack-feedback-exporter/vulnerability/wordpress-jetpack-feedback-exporter-1-23-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-88rv-3gw6-829j/GHSA-88rv-3gw6-829j.json b/advisories/unreviewed/2025/04/GHSA-88rv-3gw6-829j/GHSA-88rv-3gw6-829j.json new file mode 100644 index 00000000000..ef29e64bab6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-88rv-3gw6-829j/GHSA-88rv-3gw6-829j.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88rv-3gw6-829j", + "modified": "2025-04-04T18:30:55Z", + "published": "2025-04-04T18:30:55Z", + "aliases": [ + "CVE-2025-0468" + ], + "details": "Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages.\n\nUnder certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0468" + }, + { + "type": "WEB", + "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-280" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8fj5-gq7x-cfm8/GHSA-8fj5-gq7x-cfm8.json b/advisories/unreviewed/2025/04/GHSA-8fj5-gq7x-cfm8/GHSA-8fj5-gq7x-cfm8.json new file mode 100644 index 00000000000..e1092eddac5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8fj5-gq7x-cfm8/GHSA-8fj5-gq7x-cfm8.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fj5-gq7x-cfm8", + "modified": "2025-04-04T18:31:07Z", + "published": "2025-04-04T18:31:07Z", + "aliases": [ + "CVE-2025-3256" + ], + "details": "A vulnerability was found in xujiangfei admintwo 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user/updateSet. The manipulation of the argument email leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3256" + }, + { + "type": "WEB", + "url": "https://github.com/caigo8/CVE-md/blob/main/admintwo/%E6%B0%B4%E5%B9%B3%E8%B6%8A%E6%9D%83.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303326" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303326" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.549009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8gx6-vgfj-c5x8/GHSA-8gx6-vgfj-c5x8.json b/advisories/unreviewed/2025/04/GHSA-8gx6-vgfj-c5x8/GHSA-8gx6-vgfj-c5x8.json new file mode 100644 index 00000000000..69af01c4bdf --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8gx6-vgfj-c5x8/GHSA-8gx6-vgfj-c5x8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gx6-vgfj-c5x8", + "modified": "2025-04-04T18:31:04Z", + "published": "2025-04-04T18:31:04Z", + "aliases": [ + "CVE-2025-32254" + ], + "details": "Missing Authorization vulnerability in Iqonic Design WPBookit allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WPBookit: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32254" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpbookit/vulnerability/wordpress-wpbookit-plugin-1-0-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8h3v-hh74-r7p2/GHSA-8h3v-hh74-r7p2.json b/advisories/unreviewed/2025/04/GHSA-8h3v-hh74-r7p2/GHSA-8h3v-hh74-r7p2.json new file mode 100644 index 00000000000..d0973f03885 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8h3v-hh74-r7p2/GHSA-8h3v-hh74-r7p2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h3v-hh74-r7p2", + "modified": "2025-04-04T18:31:07Z", + "published": "2025-04-04T18:31:07Z", + "aliases": [ + "CVE-2025-29477" + ], + "details": "An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29477" + }, + { + "type": "WEB", + "url": "https://github.com/lmarch2/poc/blob/main/fluent-bit/fluent-bit.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8j77-2348-vgf2/GHSA-8j77-2348-vgf2.json b/advisories/unreviewed/2025/04/GHSA-8j77-2348-vgf2/GHSA-8j77-2348-vgf2.json new file mode 100644 index 00000000000..44becd12bd7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8j77-2348-vgf2/GHSA-8j77-2348-vgf2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j77-2348-vgf2", + "modified": "2025-04-04T18:31:01Z", + "published": "2025-04-04T18:31:01Z", + "aliases": [ + "CVE-2025-32189" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Best WP Developer BWD Elementor Addons allows DOM-Based XSS. This issue affects BWD Elementor Addons: from n/a through 4.3.20.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32189" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bwd-elementor-addons/vulnerability/wordpress-bwd-elementor-addons-plugin-4-3-20-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8m52-qhhm-24hg/GHSA-8m52-qhhm-24hg.json b/advisories/unreviewed/2025/04/GHSA-8m52-qhhm-24hg/GHSA-8m52-qhhm-24hg.json index 556606c153d..e88eb32be6e 100644 --- a/advisories/unreviewed/2025/04/GHSA-8m52-qhhm-24hg/GHSA-8m52-qhhm-24hg.json +++ b/advisories/unreviewed/2025/04/GHSA-8m52-qhhm-24hg/GHSA-8m52-qhhm-24hg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8m52-qhhm-24hg", - "modified": "2025-04-03T21:33:00Z", + "modified": "2025-04-04T18:30:54Z", "published": "2025-04-03T21:33:00Z", "aliases": [ "CVE-2024-45199" ], "details": "insightsoftware Hive JDBC through 2.6.13 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-03T21:15:38Z" diff --git a/advisories/unreviewed/2025/04/GHSA-8qcj-h873-c6wq/GHSA-8qcj-h873-c6wq.json b/advisories/unreviewed/2025/04/GHSA-8qcj-h873-c6wq/GHSA-8qcj-h873-c6wq.json new file mode 100644 index 00000000000..0a76c7fdf3b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8qcj-h873-c6wq/GHSA-8qcj-h873-c6wq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qcj-h873-c6wq", + "modified": "2025-04-04T18:31:05Z", + "published": "2025-04-04T18:31:05Z", + "aliases": [ + "CVE-2025-32269" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms allows Cross Site Request Forgery. This issue affects WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: from n/a through 1.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32269" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cf7-zendesk/vulnerability/wordpress-wp-zendesk-for-contact-form-7-wpforms-elementor-formidable-and-ninja-forms-plugin-1-1-3-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8wg4-h2wp-63r5/GHSA-8wg4-h2wp-63r5.json b/advisories/unreviewed/2025/04/GHSA-8wg4-h2wp-63r5/GHSA-8wg4-h2wp-63r5.json new file mode 100644 index 00000000000..2aedc1f6fb8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8wg4-h2wp-63r5/GHSA-8wg4-h2wp-63r5.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wg4-h2wp-63r5", + "modified": "2025-04-04T18:31:07Z", + "published": "2025-04-04T18:31:07Z", + "aliases": [ + "CVE-2025-3254" + ], + "details": "A vulnerability was found in xujiangfei admintwo 1.0. It has been classified as critical. Affected is an unknown function of the file /resource/add. The manipulation of the argument description leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3254" + }, + { + "type": "WEB", + "url": "https://github.com/caigo8/CVE-md/blob/main/admintwo/SSRF.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303324" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303324" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.548979" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8xvw-2mvx-v2mv/GHSA-8xvw-2mvx-v2mv.json b/advisories/unreviewed/2025/04/GHSA-8xvw-2mvx-v2mv/GHSA-8xvw-2mvx-v2mv.json new file mode 100644 index 00000000000..8ec082c09ff --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8xvw-2mvx-v2mv/GHSA-8xvw-2mvx-v2mv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xvw-2mvx-v2mv", + "modified": "2025-04-04T18:31:05Z", + "published": "2025-04-04T18:31:05Z", + "aliases": [ + "CVE-2025-32261" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Kuppuraj Advanced All in One Admin Search by WP Spotlight allows Cross Site Request Forgery. This issue affects Advanced All in One Admin Search by WP Spotlight: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32261" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-spotlight-search/vulnerability/wordpress-advanced-all-in-one-admin-search-by-wp-spotlight-1-1-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-929q-xrg8-qfjg/GHSA-929q-xrg8-qfjg.json b/advisories/unreviewed/2025/04/GHSA-929q-xrg8-qfjg/GHSA-929q-xrg8-qfjg.json new file mode 100644 index 00000000000..4c4375025ff --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-929q-xrg8-qfjg/GHSA-929q-xrg8-qfjg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-929q-xrg8-qfjg", + "modified": "2025-04-04T18:30:58Z", + "published": "2025-04-04T18:30:58Z", + "aliases": [ + "CVE-2025-32132" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelCockpit FunnelCockpit allows Stored XSS. This issue affects FunnelCockpit: from n/a through 1.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32132" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/funnelcockpit/vulnerability/wordpress-funnelcockpit-plugin-1-4-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-93w3-cpvv-66r7/GHSA-93w3-cpvv-66r7.json b/advisories/unreviewed/2025/04/GHSA-93w3-cpvv-66r7/GHSA-93w3-cpvv-66r7.json new file mode 100644 index 00000000000..c890ca90974 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-93w3-cpvv-66r7/GHSA-93w3-cpvv-66r7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93w3-cpvv-66r7", + "modified": "2025-04-04T18:30:56Z", + "published": "2025-04-04T18:30:56Z", + "aliases": [ + "CVE-2025-32113" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Renzo Tejada Libro de Reclamaciones y Quejas allows Cross Site Request Forgery. This issue affects Libro de Reclamaciones y Quejas: from n/a through 0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32113" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/libro-de-reclamaciones-y-quejas/vulnerability/wordpress-libro-de-reclamaciones-y-quejas-plugin-0-9-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9ff6-x5jh-jr5g/GHSA-9ff6-x5jh-jr5g.json b/advisories/unreviewed/2025/04/GHSA-9ff6-x5jh-jr5g/GHSA-9ff6-x5jh-jr5g.json new file mode 100644 index 00000000000..ad89907d782 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9ff6-x5jh-jr5g/GHSA-9ff6-x5jh-jr5g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9ff6-x5jh-jr5g", + "modified": "2025-04-04T18:31:01Z", + "published": "2025-04-04T18:31:01Z", + "aliases": [ + "CVE-2025-32201" + ], + "details": "Missing Authorization vulnerability in Xpro Xpro Theme Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Xpro Theme Builder: from n/a through 1.2.8.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32201" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/xpro-theme-builder/vulnerability/wordpress-xpro-theme-builder-plugin-1-2-8-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9g4v-rww4-55gf/GHSA-9g4v-rww4-55gf.json b/advisories/unreviewed/2025/04/GHSA-9g4v-rww4-55gf/GHSA-9g4v-rww4-55gf.json new file mode 100644 index 00000000000..1024f01c480 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9g4v-rww4-55gf/GHSA-9g4v-rww4-55gf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g4v-rww4-55gf", + "modified": "2025-04-04T18:31:00Z", + "published": "2025-04-04T18:31:00Z", + "aliases": [ + "CVE-2025-32177" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pgn4web Embed Chessboard allows Stored XSS. This issue affects Embed Chessboard: from n/a through 3.07.00.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32177" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/embed-chessboard/vulnerability/wordpress-embed-chessboard-plugin-3-07-00-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9grg-pp2p-gqf6/GHSA-9grg-pp2p-gqf6.json b/advisories/unreviewed/2025/04/GHSA-9grg-pp2p-gqf6/GHSA-9grg-pp2p-gqf6.json index a1b93ebf6c4..626af572f7e 100644 --- a/advisories/unreviewed/2025/04/GHSA-9grg-pp2p-gqf6/GHSA-9grg-pp2p-gqf6.json +++ b/advisories/unreviewed/2025/04/GHSA-9grg-pp2p-gqf6/GHSA-9grg-pp2p-gqf6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9grg-pp2p-gqf6", - "modified": "2025-04-03T21:32:58Z", + "modified": "2025-04-04T18:30:53Z", "published": "2025-04-03T21:32:58Z", "aliases": [ "CVE-2025-29647" ], "details": "SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-03T19:15:39Z" diff --git a/advisories/unreviewed/2025/04/GHSA-9gv6-wr9w-cj6j/GHSA-9gv6-wr9w-cj6j.json b/advisories/unreviewed/2025/04/GHSA-9gv6-wr9w-cj6j/GHSA-9gv6-wr9w-cj6j.json new file mode 100644 index 00000000000..c2c79fe51e0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9gv6-wr9w-cj6j/GHSA-9gv6-wr9w-cj6j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gv6-wr9w-cj6j", + "modified": "2025-04-04T18:31:07Z", + "published": "2025-04-04T18:31:07Z", + "aliases": [ + "CVE-2025-32278" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in wprio Table Block by RioVizual allows Cross Site Request Forgery. This issue affects Table Block by RioVizual: from n/a through 2.1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32278" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/riovizual/vulnerability/wordpress-table-block-by-riovizual-plugin-2-1-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9jwq-9jr3-cjg5/GHSA-9jwq-9jr3-cjg5.json b/advisories/unreviewed/2025/04/GHSA-9jwq-9jr3-cjg5/GHSA-9jwq-9jr3-cjg5.json new file mode 100644 index 00000000000..ebc9f924dbc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9jwq-9jr3-cjg5/GHSA-9jwq-9jr3-cjg5.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jwq-9jr3-cjg5", + "modified": "2025-04-04T18:31:07Z", + "published": "2025-04-04T18:31:07Z", + "aliases": [ + "CVE-2025-3259" + ], + "details": "A vulnerability, which was classified as critical, has been found in Tenda RX3 16.03.13.11. This issue affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3259" + }, + { + "type": "WEB", + "url": "https://sixth-action-50e.notion.site/Tenda-RX3-Buffer-Overflow-1c9f6468377380a2977cd6c3a81f453c?pvs=4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303329" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303329" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.549199" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9rf7-3m5w-rg76/GHSA-9rf7-3m5w-rg76.json b/advisories/unreviewed/2025/04/GHSA-9rf7-3m5w-rg76/GHSA-9rf7-3m5w-rg76.json new file mode 100644 index 00000000000..30b839253ae --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9rf7-3m5w-rg76/GHSA-9rf7-3m5w-rg76.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rf7-3m5w-rg76", + "modified": "2025-04-04T18:30:59Z", + "published": "2025-04-04T18:30:59Z", + "aliases": [ + "CVE-2025-32149" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in winkm89 teachPress allows SQL Injection. This issue affects teachPress: from n/a through 9.0.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32149" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/teachpress/vulnerability/wordpress-teachpress-plugin-9-0-11-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9x87-4jqq-rv7j/GHSA-9x87-4jqq-rv7j.json b/advisories/unreviewed/2025/04/GHSA-9x87-4jqq-rv7j/GHSA-9x87-4jqq-rv7j.json new file mode 100644 index 00000000000..0e72333b47e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9x87-4jqq-rv7j/GHSA-9x87-4jqq-rv7j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x87-4jqq-rv7j", + "modified": "2025-04-04T18:31:06Z", + "published": "2025-04-04T18:31:05Z", + "aliases": [ + "CVE-2025-32267" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in wpzinc Post to Social Media – WordPress to Hootsuite allows Cross Site Request Forgery. This issue affects Post to Social Media – WordPress to Hootsuite: from n/a through 1.5.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32267" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-to-hootsuite/vulnerability/wordpress-wp-to-hootsuite-plugin-1-5-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c2jh-4x26-fp6w/GHSA-c2jh-4x26-fp6w.json b/advisories/unreviewed/2025/04/GHSA-c2jh-4x26-fp6w/GHSA-c2jh-4x26-fp6w.json new file mode 100644 index 00000000000..0fef7c96e4c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c2jh-4x26-fp6w/GHSA-c2jh-4x26-fp6w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2jh-4x26-fp6w", + "modified": "2025-04-04T18:30:59Z", + "published": "2025-04-04T18:30:58Z", + "aliases": [ + "CVE-2025-32146" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky JS Job Manager allows PHP Local File Inclusion. This issue affects JS Job Manager: from n/a through 2.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32146" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/js-jobs/vulnerability/wordpress-js-job-manager-plugin-2-0-2-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c2r4-2v2x-5wfj/GHSA-c2r4-2v2x-5wfj.json b/advisories/unreviewed/2025/04/GHSA-c2r4-2v2x-5wfj/GHSA-c2r4-2v2x-5wfj.json new file mode 100644 index 00000000000..ad27702f6e0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c2r4-2v2x-5wfj/GHSA-c2r4-2v2x-5wfj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2r4-2v2x-5wfj", + "modified": "2025-04-04T18:31:02Z", + "published": "2025-04-04T18:31:02Z", + "aliases": [ + "CVE-2025-32220" + ], + "details": "Missing Authorization vulnerability in Dimitri Grassi Salon booking system allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Salon booking system: from n/a through 10.10.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32220" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/salon-booking-system/vulnerability/wordpress-salon-booking-system-plugin-10-10-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cmcg-w67x-52f7/GHSA-cmcg-w67x-52f7.json b/advisories/unreviewed/2025/04/GHSA-cmcg-w67x-52f7/GHSA-cmcg-w67x-52f7.json new file mode 100644 index 00000000000..b755afdd1ec --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cmcg-w67x-52f7/GHSA-cmcg-w67x-52f7.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmcg-w67x-52f7", + "modified": "2025-04-04T18:30:55Z", + "published": "2025-04-04T18:30:55Z", + "aliases": [ + "CVE-2025-25178" + ], + "details": "Software installed and run as a non-privileged user may conduct improper GPU system calls to cause kernel system memory corruption.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25178" + }, + { + "type": "WEB", + "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cvh4-7p68-rjpv/GHSA-cvh4-7p68-rjpv.json b/advisories/unreviewed/2025/04/GHSA-cvh4-7p68-rjpv/GHSA-cvh4-7p68-rjpv.json new file mode 100644 index 00000000000..b11be789928 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cvh4-7p68-rjpv/GHSA-cvh4-7p68-rjpv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvh4-7p68-rjpv", + "modified": "2025-04-04T18:30:59Z", + "published": "2025-04-04T18:30:59Z", + "aliases": [ + "CVE-2025-32152" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Essential Plugins by WP OnlineSupport Slider a SlidersPack allows PHP Local File Inclusion. This issue affects Slider a SlidersPack: from n/a through 2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32152" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sliderspack-all-in-one-image-sliders/vulnerability/wordpress-slider-a-sliderspack-plugin-2-3-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cx47-648v-j5r9/GHSA-cx47-648v-j5r9.json b/advisories/unreviewed/2025/04/GHSA-cx47-648v-j5r9/GHSA-cx47-648v-j5r9.json new file mode 100644 index 00000000000..6b7b48653af --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cx47-648v-j5r9/GHSA-cx47-648v-j5r9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx47-648v-j5r9", + "modified": "2025-04-04T18:31:06Z", + "published": "2025-04-04T18:31:06Z", + "aliases": [ + "CVE-2025-32273" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in freetobook Freetobook Responsive Widget allows Cross Site Request Forgery. This issue affects Freetobook Responsive Widget: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32273" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/freetobook-responsive-widget/vulnerability/wordpress-freetobook-responsive-widget-plugin-1-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f5rm-ch5r-39ch/GHSA-f5rm-ch5r-39ch.json b/advisories/unreviewed/2025/04/GHSA-f5rm-ch5r-39ch/GHSA-f5rm-ch5r-39ch.json new file mode 100644 index 00000000000..220aa9215c9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f5rm-ch5r-39ch/GHSA-f5rm-ch5r-39ch.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5rm-ch5r-39ch", + "modified": "2025-04-04T18:30:59Z", + "published": "2025-04-04T18:30:59Z", + "aliases": [ + "CVE-2025-32153" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in vinagecko VG WooCarousel allows PHP Local File Inclusion. This issue affects VG WooCarousel: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32153" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/vg-woocarousel/vulnerability/wordpress-vg-woocarousel-plugin-1-3-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f68f-69h6-5p3g/GHSA-f68f-69h6-5p3g.json b/advisories/unreviewed/2025/04/GHSA-f68f-69h6-5p3g/GHSA-f68f-69h6-5p3g.json new file mode 100644 index 00000000000..69b0c544bd9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f68f-69h6-5p3g/GHSA-f68f-69h6-5p3g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f68f-69h6-5p3g", + "modified": "2025-04-04T18:30:56Z", + "published": "2025-04-04T18:30:56Z", + "aliases": [ + "CVE-2025-32122" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix uListing allows Blind SQL Injection. This issue affects uListing: from n/a through 2.1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32122" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ulisting/vulnerability/wordpress-ulisting-plugin-2-1-9-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fv73-8xvv-v9jf/GHSA-fv73-8xvv-v9jf.json b/advisories/unreviewed/2025/04/GHSA-fv73-8xvv-v9jf/GHSA-fv73-8xvv-v9jf.json new file mode 100644 index 00000000000..8a09fc9ccd5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fv73-8xvv-v9jf/GHSA-fv73-8xvv-v9jf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv73-8xvv-v9jf", + "modified": "2025-04-04T18:31:05Z", + "published": "2025-04-04T18:31:05Z", + "aliases": [ + "CVE-2025-32264" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Saiful Islam UltraAddons Elementor Lite allows Cross Site Request Forgery. This issue affects UltraAddons Elementor Lite: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32264" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultraaddons-elementor-lite/vulnerability/wordpress-ultraaddons-elementor-addons-plugin-2-0-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g3qv-5m9r-qxx8/GHSA-g3qv-5m9r-qxx8.json b/advisories/unreviewed/2025/04/GHSA-g3qv-5m9r-qxx8/GHSA-g3qv-5m9r-qxx8.json new file mode 100644 index 00000000000..45b73983c3f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g3qv-5m9r-qxx8/GHSA-g3qv-5m9r-qxx8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3qv-5m9r-qxx8", + "modified": "2025-04-04T18:31:00Z", + "published": "2025-04-04T18:31:00Z", + "aliases": [ + "CVE-2025-32170" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stylemix Motors allows Stored XSS. This issue affects Motors: from n/a through 1.4.65.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32170" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/motors-car-dealership-classified-listings/vulnerability/wordpress-motors-plugin-1-4-65-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g3rj-fjcr-99wp/GHSA-g3rj-fjcr-99wp.json b/advisories/unreviewed/2025/04/GHSA-g3rj-fjcr-99wp/GHSA-g3rj-fjcr-99wp.json new file mode 100644 index 00000000000..3027730abc9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g3rj-fjcr-99wp/GHSA-g3rj-fjcr-99wp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3rj-fjcr-99wp", + "modified": "2025-04-04T18:31:01Z", + "published": "2025-04-04T18:31:01Z", + "aliases": [ + "CVE-2025-32204" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in rocketelements Split Test For Elementor allows SQL Injection. This issue affects Split Test For Elementor: from n/a through 1.8.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32204" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/split-test-for-elementor/vulnerability/wordpress-split-test-for-elementor-plugin-1-8-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g5xx-qr8r-vj38/GHSA-g5xx-qr8r-vj38.json b/advisories/unreviewed/2025/04/GHSA-g5xx-qr8r-vj38/GHSA-g5xx-qr8r-vj38.json new file mode 100644 index 00000000000..741bba1110b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g5xx-qr8r-vj38/GHSA-g5xx-qr8r-vj38.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5xx-qr8r-vj38", + "modified": "2025-04-04T18:31:05Z", + "published": "2025-04-04T18:31:05Z", + "aliases": [ + "CVE-2025-32265" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak JobWP allows Cross Site Request Forgery. This issue affects JobWP: from n/a through 2.3.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32265" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jobwp/vulnerability/wordpress-jobwp-plugin-2-3-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g6v8-vjjw-6747/GHSA-g6v8-vjjw-6747.json b/advisories/unreviewed/2025/04/GHSA-g6v8-vjjw-6747/GHSA-g6v8-vjjw-6747.json new file mode 100644 index 00000000000..ad797becb3e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g6v8-vjjw-6747/GHSA-g6v8-vjjw-6747.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6v8-vjjw-6747", + "modified": "2025-04-04T18:31:04Z", + "published": "2025-04-04T18:31:04Z", + "aliases": [ + "CVE-2025-32249" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in designinvento DirectoryPress allows Cross Site Request Forgery. This issue affects DirectoryPress: from n/a through 3.6.19.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32249" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/directorypress/vulnerability/wordpress-directorypress-business-directory-and-classified-ad-listing-plugin-3-6-19-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g6vh-gx55-qf59/GHSA-g6vh-gx55-qf59.json b/advisories/unreviewed/2025/04/GHSA-g6vh-gx55-qf59/GHSA-g6vh-gx55-qf59.json new file mode 100644 index 00000000000..b790e7b8c69 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g6vh-gx55-qf59/GHSA-g6vh-gx55-qf59.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6vh-gx55-qf59", + "modified": "2025-04-04T18:30:59Z", + "published": "2025-04-04T18:30:59Z", + "aliases": [ + "CVE-2025-32157" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Jakub Glos Sparkle Elementor Kit allows PHP Local File Inclusion. This issue affects Sparkle Elementor Kit: from n/a through 2.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32157" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sparkle-elementor-kit/vulnerability/wordpress-sparkle-elementor-kit-plugin-2-0-9-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g6wq-rr9q-jmfw/GHSA-g6wq-rr9q-jmfw.json b/advisories/unreviewed/2025/04/GHSA-g6wq-rr9q-jmfw/GHSA-g6wq-rr9q-jmfw.json new file mode 100644 index 00000000000..511522e4af9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g6wq-rr9q-jmfw/GHSA-g6wq-rr9q-jmfw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6wq-rr9q-jmfw", + "modified": "2025-04-04T18:30:57Z", + "published": "2025-04-04T18:30:57Z", + "aliases": [ + "CVE-2025-32127" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in onOffice GmbH onOffice for WP-Websites allows SQL Injection. This issue affects onOffice for WP-Websites: from n/a through 5.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32127" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/onoffice-for-wp-websites/vulnerability/wordpress-onoffice-for-wp-websites-plugin-5-7-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gggf-4g7x-rg56/GHSA-gggf-4g7x-rg56.json b/advisories/unreviewed/2025/04/GHSA-gggf-4g7x-rg56/GHSA-gggf-4g7x-rg56.json new file mode 100644 index 00000000000..d6cda6105ea --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gggf-4g7x-rg56/GHSA-gggf-4g7x-rg56.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gggf-4g7x-rg56", + "modified": "2025-04-04T18:31:05Z", + "published": "2025-04-04T18:31:05Z", + "aliases": [ + "CVE-2025-32262" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Robert D Payne RDP Wiki Embed allows Cross Site Request Forgery. This issue affects RDP Wiki Embed: from n/a through 1.2.20.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32262" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rdp-wiki-embed/vulnerability/wordpress-rdp-wiki-embed-plugin-1-2-20-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ghfg-9r57-chqv/GHSA-ghfg-9r57-chqv.json b/advisories/unreviewed/2025/04/GHSA-ghfg-9r57-chqv/GHSA-ghfg-9r57-chqv.json new file mode 100644 index 00000000000..81a9ca83adc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ghfg-9r57-chqv/GHSA-ghfg-9r57-chqv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghfg-9r57-chqv", + "modified": "2025-04-04T18:31:03Z", + "published": "2025-04-04T18:31:03Z", + "aliases": [ + "CVE-2025-32239" + ], + "details": "Missing Authorization vulnerability in Joao Romao Social Share Buttons & Analytics Plugin – GetSocial.io allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Social Share Buttons & Analytics Plugin – GetSocial.io: from n/a through 4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32239" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-share-buttons-analytics-by-getsocial/vulnerability/wordpress-social-share-buttons-analytics-plugin-plugin-4-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ghr2-jw52-6qr7/GHSA-ghr2-jw52-6qr7.json b/advisories/unreviewed/2025/04/GHSA-ghr2-jw52-6qr7/GHSA-ghr2-jw52-6qr7.json new file mode 100644 index 00000000000..4fcbaeaabf5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ghr2-jw52-6qr7/GHSA-ghr2-jw52-6qr7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghr2-jw52-6qr7", + "modified": "2025-04-04T18:31:01Z", + "published": "2025-04-04T18:31:01Z", + "aliases": [ + "CVE-2025-32194" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LA-Studio LA-Studio Element Kit for Elementor allows Stored XSS. This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.4.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32194" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lastudio-element-kit/vulnerability/wordpress-la-studio-element-kit-for-elementor-plugin-1-4-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gmf4-22hx-9m5j/GHSA-gmf4-22hx-9m5j.json b/advisories/unreviewed/2025/04/GHSA-gmf4-22hx-9m5j/GHSA-gmf4-22hx-9m5j.json new file mode 100644 index 00000000000..17fc425698d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gmf4-22hx-9m5j/GHSA-gmf4-22hx-9m5j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmf4-22hx-9m5j", + "modified": "2025-04-04T18:31:00Z", + "published": "2025-04-04T18:31:00Z", + "aliases": [ + "CVE-2025-32173" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks - The ultimate block collection allows Stored XSS. This issue affects B Blocks - The ultimate block collection: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32173" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/b-blocks/vulnerability/wordpress-b-blocks-the-ultimate-block-collection-plugin-2-0-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gq8p-m95r-vm25/GHSA-gq8p-m95r-vm25.json b/advisories/unreviewed/2025/04/GHSA-gq8p-m95r-vm25/GHSA-gq8p-m95r-vm25.json new file mode 100644 index 00000000000..3b552aff9ef --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gq8p-m95r-vm25/GHSA-gq8p-m95r-vm25.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq8p-m95r-vm25", + "modified": "2025-04-04T18:31:04Z", + "published": "2025-04-04T18:31:04Z", + "aliases": [ + "CVE-2025-32256" + ], + "details": "Missing Authorization vulnerability in devsoftbaltic SurveyJS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects SurveyJS: from n/a through 1.12.20.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32256" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/surveyjs/vulnerability/wordpress-surveyjs-plugin-1-12-20-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gr7j-89m8-pvcj/GHSA-gr7j-89m8-pvcj.json b/advisories/unreviewed/2025/04/GHSA-gr7j-89m8-pvcj/GHSA-gr7j-89m8-pvcj.json new file mode 100644 index 00000000000..5c1bfebf9aa --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gr7j-89m8-pvcj/GHSA-gr7j-89m8-pvcj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr7j-89m8-pvcj", + "modified": "2025-04-04T18:31:00Z", + "published": "2025-04-04T18:31:00Z", + "aliases": [ + "CVE-2025-32174" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tockify Tockify Events Calendar allows DOM-Based XSS. This issue affects Tockify Events Calendar: from n/a through 2.2.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32174" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tockify-events-calendar/vulnerability/wordpress-tockify-events-calendar-plugin-2-2-13-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h2pq-33qq-62jg/GHSA-h2pq-33qq-62jg.json b/advisories/unreviewed/2025/04/GHSA-h2pq-33qq-62jg/GHSA-h2pq-33qq-62jg.json new file mode 100644 index 00000000000..1095c17693c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h2pq-33qq-62jg/GHSA-h2pq-33qq-62jg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2pq-33qq-62jg", + "modified": "2025-04-04T18:31:00Z", + "published": "2025-04-04T18:31:00Z", + "aliases": [ + "CVE-2025-32185" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Colibri Page Builder allows Stored XSS. This issue affects Colibri Page Builder: from n/a through 1.0.319.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32185" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/colibri-page-builder/vulnerability/wordpress-colibri-page-builder-plugin-1-0-319-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h6w6-j96m-xj5x/GHSA-h6w6-j96m-xj5x.json b/advisories/unreviewed/2025/04/GHSA-h6w6-j96m-xj5x/GHSA-h6w6-j96m-xj5x.json new file mode 100644 index 00000000000..646cf5a061e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h6w6-j96m-xj5x/GHSA-h6w6-j96m-xj5x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6w6-j96m-xj5x", + "modified": "2025-04-04T18:31:01Z", + "published": "2025-04-04T18:31:01Z", + "aliases": [ + "CVE-2025-32197" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Addons For Elementor allows Stored XSS. This issue affects Piotnet Addons For Elementor: from n/a through 2.4.34.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32197" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/piotnet-addons-for-elementor/vulnerability/wordpress-piotnet-addons-for-elementor-plugin-2-4-34-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hf8j-q3q9-8v32/GHSA-hf8j-q3q9-8v32.json b/advisories/unreviewed/2025/04/GHSA-hf8j-q3q9-8v32/GHSA-hf8j-q3q9-8v32.json new file mode 100644 index 00000000000..8740a908cd5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hf8j-q3q9-8v32/GHSA-hf8j-q3q9-8v32.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf8j-q3q9-8v32", + "modified": "2025-04-04T18:31:06Z", + "published": "2025-04-04T18:31:06Z", + "aliases": [ + "CVE-2025-32272" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in PickPlugins Wishlist allows Cross Site Request Forgery. This issue affects Wishlist: from n/a through 1.0.44.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32272" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wishlist/vulnerability/wordpress-wishlist-plugin-1-0-41-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hfrv-qw39-6g2m/GHSA-hfrv-qw39-6g2m.json b/advisories/unreviewed/2025/04/GHSA-hfrv-qw39-6g2m/GHSA-hfrv-qw39-6g2m.json new file mode 100644 index 00000000000..87111386ccd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hfrv-qw39-6g2m/GHSA-hfrv-qw39-6g2m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfrv-qw39-6g2m", + "modified": "2025-04-04T18:31:04Z", + "published": "2025-04-04T18:31:04Z", + "aliases": [ + "CVE-2025-32246" + ], + "details": "Missing Authorization vulnerability in Tim Nguyen 1-Click Backup & Restore Database allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects 1-Click Backup & Restore Database: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32246" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/1-click-backup-restore-database-by-sunbytes/vulnerability/wordpress-1-click-backup-restore-database-1-0-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hgr3-5p8w-php6/GHSA-hgr3-5p8w-php6.json b/advisories/unreviewed/2025/04/GHSA-hgr3-5p8w-php6/GHSA-hgr3-5p8w-php6.json new file mode 100644 index 00000000000..3f302163aa7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hgr3-5p8w-php6/GHSA-hgr3-5p8w-php6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgr3-5p8w-php6", + "modified": "2025-04-04T18:31:00Z", + "published": "2025-04-04T18:31:00Z", + "aliases": [ + "CVE-2025-32186" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Turbo Addons Turbo Addons for Elementor allows DOM-Based XSS. This issue affects Turbo Addons for Elementor: from n/a through 1.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32186" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/turbo-addons-elementor/vulnerability/wordpress-turbo-addons-for-elementor-plugin-1-7-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hq72-23q2-wcfw/GHSA-hq72-23q2-wcfw.json b/advisories/unreviewed/2025/04/GHSA-hq72-23q2-wcfw/GHSA-hq72-23q2-wcfw.json new file mode 100644 index 00000000000..38856bf9848 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hq72-23q2-wcfw/GHSA-hq72-23q2-wcfw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hq72-23q2-wcfw", + "modified": "2025-04-04T18:31:04Z", + "published": "2025-04-04T18:31:04Z", + "aliases": [ + "CVE-2025-32253" + ], + "details": "Missing Authorization vulnerability in ComMotion Course Booking System allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Course Booking System: from n/a through 6.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32253" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/course-booking-system/vulnerability/wordpress-course-booking-system-plugin-6-0-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hx22-pmf5-66mr/GHSA-hx22-pmf5-66mr.json b/advisories/unreviewed/2025/04/GHSA-hx22-pmf5-66mr/GHSA-hx22-pmf5-66mr.json new file mode 100644 index 00000000000..4ad82e01988 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hx22-pmf5-66mr/GHSA-hx22-pmf5-66mr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx22-pmf5-66mr", + "modified": "2025-04-04T18:30:59Z", + "published": "2025-04-04T18:30:59Z", + "aliases": [ + "CVE-2025-32155" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in markkinchin Beds24 Online Booking allows PHP Local File Inclusion. This issue affects Beds24 Online Booking: from n/a through 2.0.26.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32155" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/beds24-online-booking/vulnerability/wordpress-beds24-online-booking-plugin-2-0-26-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j4wg-6qgm-492f/GHSA-j4wg-6qgm-492f.json b/advisories/unreviewed/2025/04/GHSA-j4wg-6qgm-492f/GHSA-j4wg-6qgm-492f.json new file mode 100644 index 00000000000..cf9c90c9990 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j4wg-6qgm-492f/GHSA-j4wg-6qgm-492f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4wg-6qgm-492f", + "modified": "2025-04-04T18:30:57Z", + "published": "2025-04-04T18:30:57Z", + "aliases": [ + "CVE-2025-32125" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in silvasoft Silvasoft boekhouden allows SQL Injection. This issue affects Silvasoft boekhouden: from n/a through 3.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32125" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/silvasoft-boekhouden/vulnerability/wordpress-silvasoft-boekhouden-plugin-3-0-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j69c-5pwp-3wfr/GHSA-j69c-5pwp-3wfr.json b/advisories/unreviewed/2025/04/GHSA-j69c-5pwp-3wfr/GHSA-j69c-5pwp-3wfr.json new file mode 100644 index 00000000000..09b58a98552 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j69c-5pwp-3wfr/GHSA-j69c-5pwp-3wfr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j69c-5pwp-3wfr", + "modified": "2025-04-04T18:31:05Z", + "published": "2025-04-04T18:31:05Z", + "aliases": [ + "CVE-2025-32266" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in wp-buy 404 Image Redirection (Replace Broken Images) allows Cross Site Request Forgery. This issue affects 404 Image Redirection (Replace Broken Images): from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32266" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/broken-images-redirection/vulnerability/wordpress-404-image-redirection-replace-broken-images-plugin-1-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j739-g4jp-g7r6/GHSA-j739-g4jp-g7r6.json b/advisories/unreviewed/2025/04/GHSA-j739-g4jp-g7r6/GHSA-j739-g4jp-g7r6.json index 68f303c04ab..fa7a210823a 100644 --- a/advisories/unreviewed/2025/04/GHSA-j739-g4jp-g7r6/GHSA-j739-g4jp-g7r6.json +++ b/advisories/unreviewed/2025/04/GHSA-j739-g4jp-g7r6/GHSA-j739-g4jp-g7r6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j739-g4jp-g7r6", - "modified": "2025-04-03T21:32:59Z", + "modified": "2025-04-04T18:30:53Z", "published": "2025-04-03T21:32:59Z", "aliases": [ "CVE-2024-45198" ], "details": "insightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-03T20:15:23Z" diff --git a/advisories/unreviewed/2025/04/GHSA-j95j-frq6-6x8g/GHSA-j95j-frq6-6x8g.json b/advisories/unreviewed/2025/04/GHSA-j95j-frq6-6x8g/GHSA-j95j-frq6-6x8g.json new file mode 100644 index 00000000000..71b0c8ce736 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j95j-frq6-6x8g/GHSA-j95j-frq6-6x8g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j95j-frq6-6x8g", + "modified": "2025-04-04T18:31:02Z", + "published": "2025-04-04T18:31:02Z", + "aliases": [ + "CVE-2025-32226" + ], + "details": "Missing Authorization vulnerability in Anzar Ahmed Display product variations dropdown on shop page allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Display product variations dropdown on shop page: from n/a through 1.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32226" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/display-product-variations-dropdown-on-shop-page/vulnerability/wordpress-display-product-variations-dropdown-on-shop-page-plugin-1-1-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jghv-pxcx-vxw5/GHSA-jghv-pxcx-vxw5.json b/advisories/unreviewed/2025/04/GHSA-jghv-pxcx-vxw5/GHSA-jghv-pxcx-vxw5.json new file mode 100644 index 00000000000..571a9209cda --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jghv-pxcx-vxw5/GHSA-jghv-pxcx-vxw5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jghv-pxcx-vxw5", + "modified": "2025-04-04T18:31:01Z", + "published": "2025-04-04T18:31:01Z", + "aliases": [ + "CVE-2025-32191" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webangon News Element Elementor Blog Magazine allows DOM-Based XSS. This issue affects News Element Elementor Blog Magazine: from n/a through 1.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32191" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/news-element/vulnerability/wordpress-news-element-elementor-blog-magazine-plugin-1-0-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jr69-25xg-96x8/GHSA-jr69-25xg-96x8.json b/advisories/unreviewed/2025/04/GHSA-jr69-25xg-96x8/GHSA-jr69-25xg-96x8.json new file mode 100644 index 00000000000..36dcdfe92bc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jr69-25xg-96x8/GHSA-jr69-25xg-96x8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr69-25xg-96x8", + "modified": "2025-04-04T18:31:03Z", + "published": "2025-04-04T18:31:03Z", + "aliases": [ + "CVE-2025-32229" + ], + "details": "Missing Authorization vulnerability in Bowo Variable Inspector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Variable Inspector: from n/a through 2.6.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32229" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/variable-inspector/vulnerability/wordpress-variable-inspector-plugin-2-6-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jv55-2g67-7p8f/GHSA-jv55-2g67-7p8f.json b/advisories/unreviewed/2025/04/GHSA-jv55-2g67-7p8f/GHSA-jv55-2g67-7p8f.json new file mode 100644 index 00000000000..63fd117ebfe --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jv55-2g67-7p8f/GHSA-jv55-2g67-7p8f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv55-2g67-7p8f", + "modified": "2025-04-04T18:30:59Z", + "published": "2025-04-04T18:30:59Z", + "aliases": [ + "CVE-2025-32156" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Alex Prokopenko / JustCoded Just Post Preview Widget allows PHP Local File Inclusion. This issue affects Just Post Preview Widget: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32156" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/just-post-preview/vulnerability/wordpress-just-post-preview-widget-plugin-1-1-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m3ph-v8rg-rvh5/GHSA-m3ph-v8rg-rvh5.json b/advisories/unreviewed/2025/04/GHSA-m3ph-v8rg-rvh5/GHSA-m3ph-v8rg-rvh5.json new file mode 100644 index 00000000000..13a89f2fe33 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m3ph-v8rg-rvh5/GHSA-m3ph-v8rg-rvh5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3ph-v8rg-rvh5", + "modified": "2025-04-04T18:30:59Z", + "published": "2025-04-04T18:30:59Z", + "aliases": [ + "CVE-2025-32142" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Stylemix Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.65.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32142" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/motors-car-dealership-classified-listings/vulnerability/wordpress-motors-plugin-1-4-65-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mc2j-7pmc-rf52/GHSA-mc2j-7pmc-rf52.json b/advisories/unreviewed/2025/04/GHSA-mc2j-7pmc-rf52/GHSA-mc2j-7pmc-rf52.json new file mode 100644 index 00000000000..7394cef4a46 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mc2j-7pmc-rf52/GHSA-mc2j-7pmc-rf52.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc2j-7pmc-rf52", + "modified": "2025-04-04T18:31:06Z", + "published": "2025-04-04T18:31:06Z", + "aliases": [ + "CVE-2025-32274" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in axew3 WP w3all phpBB allows Cross Site Request Forgery. This issue affects WP w3all phpBB: from n/a through 2.9.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32274" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-w3all-phpbb-integration/vulnerability/wordpress-w3all-phpbb-integration-plugin-2-9-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mpmp-h5fx-52p8/GHSA-mpmp-h5fx-52p8.json b/advisories/unreviewed/2025/04/GHSA-mpmp-h5fx-52p8/GHSA-mpmp-h5fx-52p8.json new file mode 100644 index 00000000000..551e4a4213c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mpmp-h5fx-52p8/GHSA-mpmp-h5fx-52p8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpmp-h5fx-52p8", + "modified": "2025-04-04T18:30:57Z", + "published": "2025-04-04T18:30:57Z", + "aliases": [ + "CVE-2025-32124" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eleopard Behance Portfolio Manager allows Blind SQL Injection. This issue affects Behance Portfolio Manager: from n/a through 1.7.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32124" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/portfolio-manager-powered-by-behance/vulnerability/wordpress-behance-portfolio-manager-plugin-1-7-4-sql-injection-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mwxf-44gv-v67p/GHSA-mwxf-44gv-v67p.json b/advisories/unreviewed/2025/04/GHSA-mwxf-44gv-v67p/GHSA-mwxf-44gv-v67p.json new file mode 100644 index 00000000000..076e3c82a32 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mwxf-44gv-v67p/GHSA-mwxf-44gv-v67p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwxf-44gv-v67p", + "modified": "2025-04-04T18:31:03Z", + "published": "2025-04-04T18:31:03Z", + "aliases": [ + "CVE-2025-32237" + ], + "details": "Missing Authorization vulnerability in Stylemix MasterStudy LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MasterStudy LMS: from n/a through 3.5.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32237" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/masterstudy-lms-learning-management-system/vulnerability/wordpress-masterstudy-lms-plugin-3-5-23-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p53h-9vwh-rvvp/GHSA-p53h-9vwh-rvvp.json b/advisories/unreviewed/2025/04/GHSA-p53h-9vwh-rvvp/GHSA-p53h-9vwh-rvvp.json new file mode 100644 index 00000000000..293e5023490 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p53h-9vwh-rvvp/GHSA-p53h-9vwh-rvvp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p53h-9vwh-rvvp", + "modified": "2025-04-04T18:31:07Z", + "published": "2025-04-04T18:31:07Z", + "aliases": [ + "CVE-2025-29476" + ], + "details": "Buffer Overflow vulnerability in compress_chunk_fuzzer with oss-fuzz on commit 16450518afddcb3139de627157208e49bfef6987 in c-blosc2 v.2.17.0 and before.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29476" + }, + { + "type": "WEB", + "url": "https://github.com/Blosc/c-blosc2/issues/656" + }, + { + "type": "WEB", + "url": "https://github.com/lmarch2/poc/blob/main/c-blosk2/c-blosk2.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pc87-gr23-fphr/GHSA-pc87-gr23-fphr.json b/advisories/unreviewed/2025/04/GHSA-pc87-gr23-fphr/GHSA-pc87-gr23-fphr.json new file mode 100644 index 00000000000..b3fdd125b83 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pc87-gr23-fphr/GHSA-pc87-gr23-fphr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc87-gr23-fphr", + "modified": "2025-04-04T18:31:07Z", + "published": "2025-04-04T18:31:07Z", + "aliases": [ + "CVE-2025-32276" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Quý Lê 91 Administrator Z allows Cross Site Request Forgery. This issue affects Administrator Z: from n/a through 2025.03.04.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32276" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/administrator-z/vulnerability/wordpress-administrator-z-plugin-2025-03-04-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ph8g-47w9-rcw4/GHSA-ph8g-47w9-rcw4.json b/advisories/unreviewed/2025/04/GHSA-ph8g-47w9-rcw4/GHSA-ph8g-47w9-rcw4.json new file mode 100644 index 00000000000..7c618b27ceb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ph8g-47w9-rcw4/GHSA-ph8g-47w9-rcw4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ph8g-47w9-rcw4", + "modified": "2025-04-04T18:30:59Z", + "published": "2025-04-04T18:30:59Z", + "aliases": [ + "CVE-2025-32159" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Radius Blocks allows PHP Local File Inclusion. This issue affects Radius Blocks: from n/a through 2.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32159" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/radius-blocks/vulnerability/wordpress-radius-blocks-plugin-2-2-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pp95-cm7q-h6wx/GHSA-pp95-cm7q-h6wx.json b/advisories/unreviewed/2025/04/GHSA-pp95-cm7q-h6wx/GHSA-pp95-cm7q-h6wx.json new file mode 100644 index 00000000000..049c00d0028 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pp95-cm7q-h6wx/GHSA-pp95-cm7q-h6wx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pp95-cm7q-h6wx", + "modified": "2025-04-04T18:31:01Z", + "published": "2025-04-04T18:31:01Z", + "aliases": [ + "CVE-2025-32195" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ecwid by Lightspeed Ecommerce Shopping Cart Ecwid Shopping Cart allows Stored XSS. This issue affects Ecwid Shopping Cart: from n/a through 7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32195" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ecwid-shopping-cart/vulnerability/wordpress-ecwid-shopping-cart-plugin-7-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pqc3-pghf-52f2/GHSA-pqc3-pghf-52f2.json b/advisories/unreviewed/2025/04/GHSA-pqc3-pghf-52f2/GHSA-pqc3-pghf-52f2.json new file mode 100644 index 00000000000..749fcee825a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pqc3-pghf-52f2/GHSA-pqc3-pghf-52f2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqc3-pghf-52f2", + "modified": "2025-04-04T18:31:00Z", + "published": "2025-04-04T18:31:00Z", + "aliases": [ + "CVE-2025-32178" + ], + "details": "Missing Authorization vulnerability in 6Storage 6Storage Rentals allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects 6Storage Rentals: from n/a through 2.18.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32178" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/6storage-rentals/vulnerability/wordpress-6storage-rentals-plugin-2-18-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pvvp-5478-wg5h/GHSA-pvvp-5478-wg5h.json b/advisories/unreviewed/2025/04/GHSA-pvvp-5478-wg5h/GHSA-pvvp-5478-wg5h.json new file mode 100644 index 00000000000..f607461c90a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pvvp-5478-wg5h/GHSA-pvvp-5478-wg5h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvvp-5478-wg5h", + "modified": "2025-04-04T18:30:58Z", + "published": "2025-04-04T18:30:58Z", + "aliases": [ + "CVE-2025-32133" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Secure Copy Content Protection and Content Locking allows Stored XSS. This issue affects Secure Copy Content Protection and Content Locking: from n/a through 4.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32133" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/secure-copy-content-protection/vulnerability/wordpress-secure-copy-content-protection-and-content-locking-plugin-4-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q4j8-27ch-xj8q/GHSA-q4j8-27ch-xj8q.json b/advisories/unreviewed/2025/04/GHSA-q4j8-27ch-xj8q/GHSA-q4j8-27ch-xj8q.json new file mode 100644 index 00000000000..3dc04d75ee1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q4j8-27ch-xj8q/GHSA-q4j8-27ch-xj8q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4j8-27ch-xj8q", + "modified": "2025-04-04T18:30:59Z", + "published": "2025-04-04T18:30:59Z", + "aliases": [ + "CVE-2025-32169" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Suresh Prasad Showeblogin Social allows DOM-Based XSS. This issue affects Showeblogin Social: from n/a through 7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32169" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/showeblogin-facebook-page-like-box/vulnerability/wordpress-showeblogin-social-plugin-7-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qc9g-5jj4-x87p/GHSA-qc9g-5jj4-x87p.json b/advisories/unreviewed/2025/04/GHSA-qc9g-5jj4-x87p/GHSA-qc9g-5jj4-x87p.json new file mode 100644 index 00000000000..3c485679fec --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qc9g-5jj4-x87p/GHSA-qc9g-5jj4-x87p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc9g-5jj4-x87p", + "modified": "2025-04-04T18:30:59Z", + "published": "2025-04-04T18:30:59Z", + "aliases": [ + "CVE-2025-32163" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xpro Xpro Elementor Addons allows Stored XSS. This issue affects Xpro Elementor Addons: from n/a through 1.4.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32163" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/xpro-elementor-addons/vulnerability/wordpress-xpro-elementor-addons-plugin-1-4-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qh34-6h8h-w24f/GHSA-qh34-6h8h-w24f.json b/advisories/unreviewed/2025/04/GHSA-qh34-6h8h-w24f/GHSA-qh34-6h8h-w24f.json new file mode 100644 index 00000000000..5c81d4d9629 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qh34-6h8h-w24f/GHSA-qh34-6h8h-w24f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qh34-6h8h-w24f", + "modified": "2025-04-04T18:31:00Z", + "published": "2025-04-04T18:31:00Z", + "aliases": [ + "CVE-2025-32181" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fast Simon Search, Filters & Merchandising for WooCommerce allows Stored XSS. This issue affects Search, Filters & Merchandising for WooCommerce: from n/a through 3.0.57.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32181" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/instantsearch-for-woocommerce/vulnerability/wordpress-search-filters-merchandising-for-woocommerce-plugin-3-0-57-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qjwp-6mm2-x7vg/GHSA-qjwp-6mm2-x7vg.json b/advisories/unreviewed/2025/04/GHSA-qjwp-6mm2-x7vg/GHSA-qjwp-6mm2-x7vg.json new file mode 100644 index 00000000000..8f9cf96a9fd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qjwp-6mm2-x7vg/GHSA-qjwp-6mm2-x7vg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjwp-6mm2-x7vg", + "modified": "2025-04-04T18:31:03Z", + "published": "2025-04-04T18:31:03Z", + "aliases": [ + "CVE-2025-32233" + ], + "details": "Missing Authorization vulnerability in WP Chill Revive.so – Bulk Rewrite and Republish Blog Posts allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Revive.so – Bulk Rewrite and Republish Blog Posts: from n/a through 2.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32233" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/revive-so/vulnerability/wordpress-revive-so-2-0-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qvmq-4rhq-mfvp/GHSA-qvmq-4rhq-mfvp.json b/advisories/unreviewed/2025/04/GHSA-qvmq-4rhq-mfvp/GHSA-qvmq-4rhq-mfvp.json new file mode 100644 index 00000000000..e99083cdadd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qvmq-4rhq-mfvp/GHSA-qvmq-4rhq-mfvp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvmq-4rhq-mfvp", + "modified": "2025-04-04T18:31:02Z", + "published": "2025-04-04T18:31:02Z", + "aliases": [ + "CVE-2025-32225" + ], + "details": "Missing Authorization vulnerability in WP Event Manager WP Event Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Event Manager: from n/a through 3.1.47.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32225" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-event-manager/vulnerability/wordpress-wp-event-manager-plugin-3-1-47-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qw37-cxpj-w543/GHSA-qw37-cxpj-w543.json b/advisories/unreviewed/2025/04/GHSA-qw37-cxpj-w543/GHSA-qw37-cxpj-w543.json new file mode 100644 index 00000000000..3cc5ed88841 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qw37-cxpj-w543/GHSA-qw37-cxpj-w543.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw37-cxpj-w543", + "modified": "2025-04-04T18:30:58Z", + "published": "2025-04-04T18:30:58Z", + "aliases": [ + "CVE-2025-32138" + ], + "details": "Improper Restriction of XML External Entity Reference vulnerability in supsystic Easy Google Maps allows XML Injection. This issue affects Easy Google Maps: from n/a through 1.11.17.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32138" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/google-maps-easy/vulnerability/wordpress-easy-google-maps-plugin-1-11-17-xml-external-entity-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r7mm-6h33-997h/GHSA-r7mm-6h33-997h.json b/advisories/unreviewed/2025/04/GHSA-r7mm-6h33-997h/GHSA-r7mm-6h33-997h.json new file mode 100644 index 00000000000..116c488775c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r7mm-6h33-997h/GHSA-r7mm-6h33-997h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7mm-6h33-997h", + "modified": "2025-04-04T18:30:58Z", + "published": "2025-04-04T18:30:58Z", + "aliases": [ + "CVE-2025-32129" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Risk Migitation, Inc. Welcome Bar allows Stored XSS. This issue affects Welcome Bar: from n/a through 2.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32129" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/intelly-welcome-bar/vulnerability/wordpress-welcome-bar-plugin-2-0-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r9q7-9m92-j6j6/GHSA-r9q7-9m92-j6j6.json b/advisories/unreviewed/2025/04/GHSA-r9q7-9m92-j6j6/GHSA-r9q7-9m92-j6j6.json new file mode 100644 index 00000000000..d7d729737f9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r9q7-9m92-j6j6/GHSA-r9q7-9m92-j6j6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9q7-9m92-j6j6", + "modified": "2025-04-04T18:31:00Z", + "published": "2025-04-04T18:31:00Z", + "aliases": [ + "CVE-2025-32172" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yuri Baranov YaMaps for WordPress allows Stored XSS. This issue affects YaMaps for WordPress: from n/a through 0.6.31.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32172" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/yamaps/vulnerability/wordpress-yamaps-for-wordpress-plugin-0-6-31-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rf5w-qg4q-p4q5/GHSA-rf5w-qg4q-p4q5.json b/advisories/unreviewed/2025/04/GHSA-rf5w-qg4q-p4q5/GHSA-rf5w-qg4q-p4q5.json new file mode 100644 index 00000000000..3de94b5071e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rf5w-qg4q-p4q5/GHSA-rf5w-qg4q-p4q5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rf5w-qg4q-p4q5", + "modified": "2025-04-04T18:30:56Z", + "published": "2025-04-04T18:30:56Z", + "aliases": [ + "CVE-2025-32118" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in NiteoThemes CMP – Coming Soon & Maintenance allows Using Malicious Files. This issue affects CMP – Coming Soon & Maintenance: from n/a through 4.1.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32118" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cmp-coming-soon-maintenance/vulnerability/wordpress-cmp-coming-soon-maintenance-plugin-4-1-13-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rq23-cqh4-p7xm/GHSA-rq23-cqh4-p7xm.json b/advisories/unreviewed/2025/04/GHSA-rq23-cqh4-p7xm/GHSA-rq23-cqh4-p7xm.json new file mode 100644 index 00000000000..9975cb9b109 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rq23-cqh4-p7xm/GHSA-rq23-cqh4-p7xm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq23-cqh4-p7xm", + "modified": "2025-04-04T18:31:04Z", + "published": "2025-04-04T18:31:04Z", + "aliases": [ + "CVE-2025-32255" + ], + "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ERA404 StaffList allows Retrieve Embedded Sensitive Data. This issue affects StaffList: from n/a through 3.2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32255" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/stafflist/vulnerability/wordpress-stafflist-plugin-3-2-6-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rq35-6gx7-78pq/GHSA-rq35-6gx7-78pq.json b/advisories/unreviewed/2025/04/GHSA-rq35-6gx7-78pq/GHSA-rq35-6gx7-78pq.json new file mode 100644 index 00000000000..f9b886f061e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rq35-6gx7-78pq/GHSA-rq35-6gx7-78pq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq35-6gx7-78pq", + "modified": "2025-04-04T18:30:58Z", + "published": "2025-04-04T18:30:57Z", + "aliases": [ + "CVE-2025-32130" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Risk Migitation, Inc. Posts Footer Manager allows Stored XSS. This issue affects Posts Footer Manager: from n/a through 2.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32130" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/intelly-posts-footer-manager/vulnerability/wordpress-posts-footer-manager-plugin-2-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rq4g-g53g-m5r4/GHSA-rq4g-g53g-m5r4.json b/advisories/unreviewed/2025/04/GHSA-rq4g-g53g-m5r4/GHSA-rq4g-g53g-m5r4.json new file mode 100644 index 00000000000..1c5caeafe51 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rq4g-g53g-m5r4/GHSA-rq4g-g53g-m5r4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq4g-g53g-m5r4", + "modified": "2025-04-04T18:31:01Z", + "published": "2025-04-04T18:31:01Z", + "aliases": [ + "CVE-2025-32203" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in manu225 Falling things allows SQL Injection. This issue affects Falling things: from n/a through 1.08.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32203" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/falling-things/vulnerability/wordpress-falling-things-plugin-1-08-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rwxg-r4cq-frp9/GHSA-rwxg-r4cq-frp9.json b/advisories/unreviewed/2025/04/GHSA-rwxg-r4cq-frp9/GHSA-rwxg-r4cq-frp9.json index cd5e17f33bd..f81f928810b 100644 --- a/advisories/unreviewed/2025/04/GHSA-rwxg-r4cq-frp9/GHSA-rwxg-r4cq-frp9.json +++ b/advisories/unreviewed/2025/04/GHSA-rwxg-r4cq-frp9/GHSA-rwxg-r4cq-frp9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rwxg-r4cq-frp9", - "modified": "2025-04-03T21:33:00Z", + "modified": "2025-04-04T18:30:54Z", "published": "2025-04-03T21:33:00Z", "aliases": [ "CVE-2024-47212" ], "details": "An issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API endpoint of Iglu Server and can render it completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-03T21:15:38Z" diff --git a/advisories/unreviewed/2025/04/GHSA-v6wc-q6hc-vm3q/GHSA-v6wc-q6hc-vm3q.json b/advisories/unreviewed/2025/04/GHSA-v6wc-q6hc-vm3q/GHSA-v6wc-q6hc-vm3q.json new file mode 100644 index 00000000000..d15e2da5a6c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v6wc-q6hc-vm3q/GHSA-v6wc-q6hc-vm3q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6wc-q6hc-vm3q", + "modified": "2025-04-04T18:30:59Z", + "published": "2025-04-04T18:30:59Z", + "aliases": [ + "CVE-2025-32165" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fromdoppler Doppler Forms allows Stored XSS. This issue affects Doppler Forms: from n/a through 2.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32165" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/doppler-form/vulnerability/wordpress-doppler-forms-plugin-2-4-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v857-wxc6-p2rv/GHSA-v857-wxc6-p2rv.json b/advisories/unreviewed/2025/04/GHSA-v857-wxc6-p2rv/GHSA-v857-wxc6-p2rv.json new file mode 100644 index 00000000000..8384b4caa6e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v857-wxc6-p2rv/GHSA-v857-wxc6-p2rv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v857-wxc6-p2rv", + "modified": "2025-04-04T18:31:05Z", + "published": "2025-04-04T18:31:05Z", + "aliases": [ + "CVE-2025-32258" + ], + "details": "Missing Authorization vulnerability in InfoGiants Simple Website Logo allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple Website Logo: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32258" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-website-logo/vulnerability/wordpress-simple-website-logo-plugin-1-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v9fr-mwf9-jjvx/GHSA-v9fr-mwf9-jjvx.json b/advisories/unreviewed/2025/04/GHSA-v9fr-mwf9-jjvx/GHSA-v9fr-mwf9-jjvx.json new file mode 100644 index 00000000000..d35d0346edb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v9fr-mwf9-jjvx/GHSA-v9fr-mwf9-jjvx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9fr-mwf9-jjvx", + "modified": "2025-04-04T18:31:05Z", + "published": "2025-04-04T18:31:05Z", + "aliases": [ + "CVE-2025-32268" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in www.15.to QR Code Tag for WC allows Cross Site Request Forgery. This issue affects QR Code Tag for WC: from n/a through 1.9.36.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32268" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/qr-code-tag-for-wc-from-goaskle-com/vulnerability/wordpress-qr-code-tag-for-wc-plugin-1-9-35-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vxwr-fv6m-j7vx/GHSA-vxwr-fv6m-j7vx.json b/advisories/unreviewed/2025/04/GHSA-vxwr-fv6m-j7vx/GHSA-vxwr-fv6m-j7vx.json new file mode 100644 index 00000000000..9a857d8d7d5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vxwr-fv6m-j7vx/GHSA-vxwr-fv6m-j7vx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxwr-fv6m-j7vx", + "modified": "2025-04-04T18:31:00Z", + "published": "2025-04-04T18:31:00Z", + "aliases": [ + "CVE-2025-32188" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ILLID Advanced Woo Labels allows Stored XSS. This issue affects Advanced Woo Labels: from n/a through 2.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32188" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-woo-labels/vulnerability/wordpress-advanced-woo-labels-plugin-2-14-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wf8w-j533-f8fc/GHSA-wf8w-j533-f8fc.json b/advisories/unreviewed/2025/04/GHSA-wf8w-j533-f8fc/GHSA-wf8w-j533-f8fc.json new file mode 100644 index 00000000000..f033b07e3bf --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wf8w-j533-f8fc/GHSA-wf8w-j533-f8fc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wf8w-j533-f8fc", + "modified": "2025-04-04T18:31:04Z", + "published": "2025-04-04T18:31:04Z", + "aliases": [ + "CVE-2025-32247" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ABCdatos AI Content Creator allows Cross Site Request Forgery. This issue affects AI Content Creator: from n/a through 1.2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32247" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ai-content-creator/vulnerability/wordpress-ai-content-creator-plugin-1-2-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wfhr-c5cc-3grg/GHSA-wfhr-c5cc-3grg.json b/advisories/unreviewed/2025/04/GHSA-wfhr-c5cc-3grg/GHSA-wfhr-c5cc-3grg.json new file mode 100644 index 00000000000..6b240db627d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wfhr-c5cc-3grg/GHSA-wfhr-c5cc-3grg.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfhr-c5cc-3grg", + "modified": "2025-04-04T18:31:07Z", + "published": "2025-04-04T18:31:07Z", + "aliases": [ + "CVE-2025-3257" + ], + "details": "A vulnerability classified as problematic has been found in xujiangfei admintwo 1.0. This affects an unknown part of the file /user/updateSet. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3257" + }, + { + "type": "WEB", + "url": "https://github.com/caigo8/CVE-md/blob/main/admintwo/CSRF.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303327" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303327" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.549011" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wh72-33m3-q8xj/GHSA-wh72-33m3-q8xj.json b/advisories/unreviewed/2025/04/GHSA-wh72-33m3-q8xj/GHSA-wh72-33m3-q8xj.json new file mode 100644 index 00000000000..0d49b37b449 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wh72-33m3-q8xj/GHSA-wh72-33m3-q8xj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh72-33m3-q8xj", + "modified": "2025-04-04T18:30:59Z", + "published": "2025-04-04T18:30:59Z", + "aliases": [ + "CVE-2025-32167" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devsoftbaltic SurveyJS allows Stored XSS. This issue affects SurveyJS: from n/a through 1.12.20.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32167" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/surveyjs/vulnerability/wordpress-surveyjs-plugin-1-12-20-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wjpg-22gr-ggcq/GHSA-wjpg-22gr-ggcq.json b/advisories/unreviewed/2025/04/GHSA-wjpg-22gr-ggcq/GHSA-wjpg-22gr-ggcq.json new file mode 100644 index 00000000000..c0e0c5f019a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wjpg-22gr-ggcq/GHSA-wjpg-22gr-ggcq.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjpg-22gr-ggcq", + "modified": "2025-04-04T18:31:07Z", + "published": "2025-04-04T18:31:07Z", + "aliases": [ + "CVE-2025-3255" + ], + "details": "A vulnerability was found in xujiangfei admintwo 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /user/home. The manipulation of the argument ID leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3255" + }, + { + "type": "WEB", + "url": "https://github.com/caigo8/CVE-md/blob/main/admintwo/%E6%9C%AA%E6%8E%88%E6%9D%83%E7%94%A8%E6%88%B7%E4%BF%A1%E6%81%AF%E9%81%8D%E5%8E%86.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303325" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303325" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.548986" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wq7m-v6h4-h5vf/GHSA-wq7m-v6h4-h5vf.json b/advisories/unreviewed/2025/04/GHSA-wq7m-v6h4-h5vf/GHSA-wq7m-v6h4-h5vf.json new file mode 100644 index 00000000000..41ede3e5410 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wq7m-v6h4-h5vf/GHSA-wq7m-v6h4-h5vf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq7m-v6h4-h5vf", + "modified": "2025-04-04T18:30:59Z", + "published": "2025-04-04T18:30:59Z", + "aliases": [ + "CVE-2025-32151" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Sven Lehnert BuddyForms allows PHP Local File Inclusion. This issue affects BuddyForms: from n/a through 2.8.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32151" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/buddyforms/vulnerability/wordpress-buddyforms-plugin-2-8-15-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wr37-9fm6-9669/GHSA-wr37-9fm6-9669.json b/advisories/unreviewed/2025/04/GHSA-wr37-9fm6-9669/GHSA-wr37-9fm6-9669.json new file mode 100644 index 00000000000..5753c787827 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wr37-9fm6-9669/GHSA-wr37-9fm6-9669.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr37-9fm6-9669", + "modified": "2025-04-04T18:31:02Z", + "published": "2025-04-04T18:31:02Z", + "aliases": [ + "CVE-2025-32217" + ], + "details": "Missing Authorization vulnerability in WP Messiah Ai Image Alt Text Generator for WP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ai Image Alt Text Generator for WP: from n/a through 1.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32217" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ai-image-alt-text-generator-for-wp/vulnerability/wordpress-ai-image-alt-text-generator-for-wp-plugin-1-0-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x24v-9fv7-jcfh/GHSA-x24v-9fv7-jcfh.json b/advisories/unreviewed/2025/04/GHSA-x24v-9fv7-jcfh/GHSA-x24v-9fv7-jcfh.json new file mode 100644 index 00000000000..e0dc5297aff --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x24v-9fv7-jcfh/GHSA-x24v-9fv7-jcfh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x24v-9fv7-jcfh", + "modified": "2025-04-04T18:31:03Z", + "published": "2025-04-04T18:31:03Z", + "aliases": [ + "CVE-2025-32238" + ], + "details": "Generation of Error Message Containing Sensitive Information vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita allows Retrieve Embedded Sensitive Data. This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32238" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/meeting-scheduler-by-vcita/vulnerability/wordpress-online-booking-scheduling-calendar-for-wordpress-by-vcita-plugin-4-5-2-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x3c6-fv27-mxfc/GHSA-x3c6-fv27-mxfc.json b/advisories/unreviewed/2025/04/GHSA-x3c6-fv27-mxfc/GHSA-x3c6-fv27-mxfc.json new file mode 100644 index 00000000000..eac9c476237 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x3c6-fv27-mxfc/GHSA-x3c6-fv27-mxfc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3c6-fv27-mxfc", + "modified": "2025-04-04T18:31:03Z", + "published": "2025-04-04T18:31:03Z", + "aliases": [ + "CVE-2025-32232" + ], + "details": "Missing Authorization vulnerability in ERA404 StaffList allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects StaffList: from n/a through 3.2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32232" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/stafflist/vulnerability/wordpress-stafflist-plugin-3-2-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xhfj-7xhw-r6pj/GHSA-xhfj-7xhw-r6pj.json b/advisories/unreviewed/2025/04/GHSA-xhfj-7xhw-r6pj/GHSA-xhfj-7xhw-r6pj.json new file mode 100644 index 00000000000..c1f5ae95e90 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xhfj-7xhw-r6pj/GHSA-xhfj-7xhw-r6pj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhfj-7xhw-r6pj", + "modified": "2025-04-04T18:30:59Z", + "published": "2025-04-04T18:30:59Z", + "aliases": [ + "CVE-2025-32154" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Catch Themes Catch Dark Mode allows PHP Local File Inclusion. This issue affects Catch Dark Mode: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32154" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/catch-dark-mode/vulnerability/wordpress-catch-dark-mode-plugin-1-2-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xj7c-p939-3474/GHSA-xj7c-p939-3474.json b/advisories/unreviewed/2025/04/GHSA-xj7c-p939-3474/GHSA-xj7c-p939-3474.json new file mode 100644 index 00000000000..4b663e936f4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xj7c-p939-3474/GHSA-xj7c-p939-3474.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xj7c-p939-3474", + "modified": "2025-04-04T18:31:01Z", + "published": "2025-04-04T18:31:01Z", + "aliases": [ + "CVE-2025-32193" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMinds Simple WP Events allows Stored XSS. This issue affects Simple WP Events: from n/a through 1.8.17.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32193" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-wp-events/vulnerability/wordpress-simple-wp-events-plugin-1-8-17-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xmgg-6wgj-628j/GHSA-xmgg-6wgj-628j.json b/advisories/unreviewed/2025/04/GHSA-xmgg-6wgj-628j/GHSA-xmgg-6wgj-628j.json index 25a5001ca18..beeaa3cf401 100644 --- a/advisories/unreviewed/2025/04/GHSA-xmgg-6wgj-628j/GHSA-xmgg-6wgj-628j.json +++ b/advisories/unreviewed/2025/04/GHSA-xmgg-6wgj-628j/GHSA-xmgg-6wgj-628j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xmgg-6wgj-628j", - "modified": "2025-04-03T21:32:58Z", + "modified": "2025-04-04T18:30:53Z", "published": "2025-04-03T21:32:58Z", "aliases": [ "CVE-2024-22611" ], "details": "OpenEMR 7.0.2 is vulnerable to SQL Injection via \\openemr\\library\\classes\\Pharmacy.class.php, \\controllers\\C_Pharmacy.class.php and \\openemr\\controller.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-03T19:15:39Z" diff --git a/advisories/unreviewed/2025/04/GHSA-xp3c-c34p-32qp/GHSA-xp3c-c34p-32qp.json b/advisories/unreviewed/2025/04/GHSA-xp3c-c34p-32qp/GHSA-xp3c-c34p-32qp.json new file mode 100644 index 00000000000..32522546474 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xp3c-c34p-32qp/GHSA-xp3c-c34p-32qp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xp3c-c34p-32qp", + "modified": "2025-04-04T18:30:59Z", + "published": "2025-04-04T18:30:59Z", + "aliases": [ + "CVE-2025-32162" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Morgan Kay Chamber Dashboard Business Directory allows DOM-Based XSS. This issue affects Chamber Dashboard Business Directory: from n/a through 3.3.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32162" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/chamber-dashboard-business-directory/vulnerability/wordpress-chamber-dashboard-business-directory-plugin-3-3-11-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xr2v-mvcq-w8hv/GHSA-xr2v-mvcq-w8hv.json b/advisories/unreviewed/2025/04/GHSA-xr2v-mvcq-w8hv/GHSA-xr2v-mvcq-w8hv.json new file mode 100644 index 00000000000..735a9f89a5a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xr2v-mvcq-w8hv/GHSA-xr2v-mvcq-w8hv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr2v-mvcq-w8hv", + "modified": "2025-04-04T18:30:58Z", + "published": "2025-04-04T18:30:58Z", + "aliases": [ + "CVE-2025-32136" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in activecampaign ActiveCampaign allows Stored XSS. This issue affects ActiveCampaign: from n/a through 8.1.16.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32136" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/activecampaign-subscription-forms/vulnerability/wordpress-activecampaign-plugin-8-1-16-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xrvr-j7mc-4r64/GHSA-xrvr-j7mc-4r64.json b/advisories/unreviewed/2025/04/GHSA-xrvr-j7mc-4r64/GHSA-xrvr-j7mc-4r64.json new file mode 100644 index 00000000000..cef68b6c444 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xrvr-j7mc-4r64/GHSA-xrvr-j7mc-4r64.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrvr-j7mc-4r64", + "modified": "2025-04-04T18:31:02Z", + "published": "2025-04-04T18:31:02Z", + "aliases": [ + "CVE-2025-32218" + ], + "details": "Missing Authorization vulnerability in RealMag777 TableOn – WordPress Posts Table Filterable allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects TableOn – WordPress Posts Table Filterable: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32218" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/posts-table-filterable/vulnerability/wordpress-tableon-wordpress-posts-table-filterable-plugin-1-0-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T16:15:31Z" + } +} \ No newline at end of file