diff --git a/advisories/unreviewed/2022/10/GHSA-3hfv-3383-4hvp/GHSA-3hfv-3383-4hvp.json b/advisories/unreviewed/2022/10/GHSA-3hfv-3383-4hvp/GHSA-3hfv-3383-4hvp.json index 2abb7b78612..92b9d914138 100644 --- a/advisories/unreviewed/2022/10/GHSA-3hfv-3383-4hvp/GHSA-3hfv-3383-4hvp.json +++ b/advisories/unreviewed/2022/10/GHSA-3hfv-3383-4hvp/GHSA-3hfv-3383-4hvp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3hfv-3383-4hvp", - "modified": "2022-10-18T19:00:34Z", + "modified": "2025-05-15T21:31:14Z", "published": "2022-10-14T12:00:23Z", "aliases": [ "CVE-2022-42719" @@ -31,6 +31,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GGHENNMLCWIQV2LLA56BJNFIUZ7WB4IY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S2KTU5LFZNQS7YNGE56MT46VHMXL3DD2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VNN3VFQPECS6D4PS6ZWD7AFXTOSJDSSR" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GGHENNMLCWIQV2LLA56BJNFIUZ7WB4IY" diff --git a/advisories/unreviewed/2022/10/GHSA-6976-m887-r48h/GHSA-6976-m887-r48h.json b/advisories/unreviewed/2022/10/GHSA-6976-m887-r48h/GHSA-6976-m887-r48h.json index dc3f13553ab..2c33a7731b6 100644 --- a/advisories/unreviewed/2022/10/GHSA-6976-m887-r48h/GHSA-6976-m887-r48h.json +++ b/advisories/unreviewed/2022/10/GHSA-6976-m887-r48h/GHSA-6976-m887-r48h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6976-m887-r48h", - "modified": "2022-10-17T19:00:28Z", + "modified": "2025-05-15T21:31:14Z", "published": "2022-10-14T12:00:23Z", "aliases": [ "CVE-2022-42721" @@ -31,6 +31,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GGHENNMLCWIQV2LLA56BJNFIUZ7WB4IY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S2KTU5LFZNQS7YNGE56MT46VHMXL3DD2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VNN3VFQPECS6D4PS6ZWD7AFXTOSJDSSR" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GGHENNMLCWIQV2LLA56BJNFIUZ7WB4IY" diff --git a/advisories/unreviewed/2022/10/GHSA-ccpm-2wgc-2rp2/GHSA-ccpm-2wgc-2rp2.json b/advisories/unreviewed/2022/10/GHSA-ccpm-2wgc-2rp2/GHSA-ccpm-2wgc-2rp2.json index dd8cb2758df..36067cf5d25 100644 --- a/advisories/unreviewed/2022/10/GHSA-ccpm-2wgc-2rp2/GHSA-ccpm-2wgc-2rp2.json +++ b/advisories/unreviewed/2022/10/GHSA-ccpm-2wgc-2rp2/GHSA-ccpm-2wgc-2rp2.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-763" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/10/GHSA-f43w-w9qr-2mwm/GHSA-f43w-w9qr-2mwm.json b/advisories/unreviewed/2022/10/GHSA-f43w-w9qr-2mwm/GHSA-f43w-w9qr-2mwm.json index 90a3bf6d1bc..3194452ff4d 100644 --- a/advisories/unreviewed/2022/10/GHSA-f43w-w9qr-2mwm/GHSA-f43w-w9qr-2mwm.json +++ b/advisories/unreviewed/2022/10/GHSA-f43w-w9qr-2mwm/GHSA-f43w-w9qr-2mwm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f43w-w9qr-2mwm", - "modified": "2022-10-17T19:00:28Z", + "modified": "2025-05-15T21:31:14Z", "published": "2022-10-14T12:00:23Z", "aliases": [ "CVE-2022-42720" @@ -31,6 +31,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GGHENNMLCWIQV2LLA56BJNFIUZ7WB4IY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S2KTU5LFZNQS7YNGE56MT46VHMXL3DD2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VNN3VFQPECS6D4PS6ZWD7AFXTOSJDSSR" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GGHENNMLCWIQV2LLA56BJNFIUZ7WB4IY" diff --git a/advisories/unreviewed/2022/10/GHSA-jpch-vfw6-pg3x/GHSA-jpch-vfw6-pg3x.json b/advisories/unreviewed/2022/10/GHSA-jpch-vfw6-pg3x/GHSA-jpch-vfw6-pg3x.json index 0fd4eb9e4a4..3d4bac30567 100644 --- a/advisories/unreviewed/2022/10/GHSA-jpch-vfw6-pg3x/GHSA-jpch-vfw6-pg3x.json +++ b/advisories/unreviewed/2022/10/GHSA-jpch-vfw6-pg3x/GHSA-jpch-vfw6-pg3x.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-404" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-pvh2-rg7g-r69p/GHSA-pvh2-rg7g-r69p.json b/advisories/unreviewed/2022/10/GHSA-pvh2-rg7g-r69p/GHSA-pvh2-rg7g-r69p.json index aae26e37d52..bcab5c489c6 100644 --- a/advisories/unreviewed/2022/10/GHSA-pvh2-rg7g-r69p/GHSA-pvh2-rg7g-r69p.json +++ b/advisories/unreviewed/2022/10/GHSA-pvh2-rg7g-r69p/GHSA-pvh2-rg7g-r69p.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/10/GHSA-v82w-q73w-95p8/GHSA-v82w-q73w-95p8.json b/advisories/unreviewed/2022/10/GHSA-v82w-q73w-95p8/GHSA-v82w-q73w-95p8.json index dc61fd356a1..24da22cef79 100644 --- a/advisories/unreviewed/2022/10/GHSA-v82w-q73w-95p8/GHSA-v82w-q73w-95p8.json +++ b/advisories/unreviewed/2022/10/GHSA-v82w-q73w-95p8/GHSA-v82w-q73w-95p8.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-459" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-hj5h-2xwv-897h/GHSA-hj5h-2xwv-897h.json b/advisories/unreviewed/2024/01/GHSA-hj5h-2xwv-897h/GHSA-hj5h-2xwv-897h.json index d73b6eb31ef..e0fd75614f9 100644 --- a/advisories/unreviewed/2024/01/GHSA-hj5h-2xwv-897h/GHSA-hj5h-2xwv-897h.json +++ b/advisories/unreviewed/2024/01/GHSA-hj5h-2xwv-897h/GHSA-hj5h-2xwv-897h.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-rgqw-78cv-wmcg/GHSA-rgqw-78cv-wmcg.json b/advisories/unreviewed/2024/01/GHSA-rgqw-78cv-wmcg/GHSA-rgqw-78cv-wmcg.json index 19125249750..2570f41992f 100644 --- a/advisories/unreviewed/2024/01/GHSA-rgqw-78cv-wmcg/GHSA-rgqw-78cv-wmcg.json +++ b/advisories/unreviewed/2024/01/GHSA-rgqw-78cv-wmcg/GHSA-rgqw-78cv-wmcg.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-23h8-ggh4-vmhv/GHSA-23h8-ggh4-vmhv.json b/advisories/unreviewed/2024/02/GHSA-23h8-ggh4-vmhv/GHSA-23h8-ggh4-vmhv.json index 2fa9a4848d1..91562365f83 100644 --- a/advisories/unreviewed/2024/02/GHSA-23h8-ggh4-vmhv/GHSA-23h8-ggh4-vmhv.json +++ b/advisories/unreviewed/2024/02/GHSA-23h8-ggh4-vmhv/GHSA-23h8-ggh4-vmhv.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-23h8-ggh4-vmhv", - "modified": "2024-02-10T06:30:18Z", + "modified": "2025-05-15T21:31:19Z", "published": "2024-02-06T21:30:26Z", "aliases": [ "CVE-2024-22240" ], - "details": "Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to sensitive information. ", + "details": "Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to sensitive information.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-3wxq-76w9-ghcp/GHSA-3wxq-76w9-ghcp.json b/advisories/unreviewed/2024/02/GHSA-3wxq-76w9-ghcp/GHSA-3wxq-76w9-ghcp.json index 0dabcce5a28..ae50f64b2e2 100644 --- a/advisories/unreviewed/2024/02/GHSA-3wxq-76w9-ghcp/GHSA-3wxq-76w9-ghcp.json +++ b/advisories/unreviewed/2024/02/GHSA-3wxq-76w9-ghcp/GHSA-3wxq-76w9-ghcp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3wxq-76w9-ghcp", - "modified": "2024-02-06T12:30:31Z", + "modified": "2025-05-15T21:31:19Z", "published": "2024-02-06T12:30:31Z", "aliases": [ "CVE-2024-24940" diff --git a/advisories/unreviewed/2024/02/GHSA-4gv8-ph4v-rwjm/GHSA-4gv8-ph4v-rwjm.json b/advisories/unreviewed/2024/02/GHSA-4gv8-ph4v-rwjm/GHSA-4gv8-ph4v-rwjm.json index a0de6db419b..e18dce488d5 100644 --- a/advisories/unreviewed/2024/02/GHSA-4gv8-ph4v-rwjm/GHSA-4gv8-ph4v-rwjm.json +++ b/advisories/unreviewed/2024/02/GHSA-4gv8-ph4v-rwjm/GHSA-4gv8-ph4v-rwjm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-5frx-8vj6-294f/GHSA-5frx-8vj6-294f.json b/advisories/unreviewed/2024/02/GHSA-5frx-8vj6-294f/GHSA-5frx-8vj6-294f.json index 94c25e89e09..d7e162e9740 100644 --- a/advisories/unreviewed/2024/02/GHSA-5frx-8vj6-294f/GHSA-5frx-8vj6-294f.json +++ b/advisories/unreviewed/2024/02/GHSA-5frx-8vj6-294f/GHSA-5frx-8vj6-294f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5frx-8vj6-294f", - "modified": "2024-02-09T09:31:31Z", + "modified": "2025-05-15T21:31:21Z", "published": "2024-02-09T09:31:31Z", "aliases": [ "CVE-2024-23749" ], "details": "KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input sanitization and validation, failure to escape special characters, and insecure system calls (at lines 2369-2390). This allows an attacker to add inputs inside the filename variable, leading to arbitrary code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,11 +26,21 @@ { "type": "WEB", "url": "http://packetstormsecurity.com/files/177031/KiTTY-0.76.1.13-Command-Injection.html" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Feb/13" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Feb/14" } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-09T08:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-8xmq-whfm-pq37/GHSA-8xmq-whfm-pq37.json b/advisories/unreviewed/2024/02/GHSA-8xmq-whfm-pq37/GHSA-8xmq-whfm-pq37.json index 03ad2afb3ad..b835702319e 100644 --- a/advisories/unreviewed/2024/02/GHSA-8xmq-whfm-pq37/GHSA-8xmq-whfm-pq37.json +++ b/advisories/unreviewed/2024/02/GHSA-8xmq-whfm-pq37/GHSA-8xmq-whfm-pq37.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-8xmq-whfm-pq37", - "modified": "2024-02-10T06:30:18Z", + "modified": "2025-05-15T21:31:19Z", "published": "2024-02-06T21:30:26Z", "aliases": [ "CVE-2024-22237" ], - "details": "Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain root access to the system. ", + "details": "Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain root access to the system.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-97vr-j4hr-qrq8/GHSA-97vr-j4hr-qrq8.json b/advisories/unreviewed/2024/02/GHSA-97vr-j4hr-qrq8/GHSA-97vr-j4hr-qrq8.json index 545444e57d5..408b8e00ddd 100644 --- a/advisories/unreviewed/2024/02/GHSA-97vr-j4hr-qrq8/GHSA-97vr-j4hr-qrq8.json +++ b/advisories/unreviewed/2024/02/GHSA-97vr-j4hr-qrq8/GHSA-97vr-j4hr-qrq8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-97vr-j4hr-qrq8", - "modified": "2024-02-07T18:30:27Z", + "modified": "2025-05-15T21:31:15Z", "published": "2024-02-02T03:30:32Z", "aliases": [ "CVE-2024-22902" diff --git a/advisories/unreviewed/2024/02/GHSA-f5c4-v2h9-f7mq/GHSA-f5c4-v2h9-f7mq.json b/advisories/unreviewed/2024/02/GHSA-f5c4-v2h9-f7mq/GHSA-f5c4-v2h9-f7mq.json index 22d4612472a..0203ce80d1a 100644 --- a/advisories/unreviewed/2024/02/GHSA-f5c4-v2h9-f7mq/GHSA-f5c4-v2h9-f7mq.json +++ b/advisories/unreviewed/2024/02/GHSA-f5c4-v2h9-f7mq/GHSA-f5c4-v2h9-f7mq.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-f5c4-v2h9-f7mq", - "modified": "2024-02-10T06:30:18Z", + "modified": "2025-05-15T21:31:19Z", "published": "2024-02-06T21:30:26Z", "aliases": [ "CVE-2024-22239" ], - "details": "Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain regular shell access. ", + "details": "Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain regular shell access.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-fgv7-7rh4-3353/GHSA-fgv7-7rh4-3353.json b/advisories/unreviewed/2024/02/GHSA-fgv7-7rh4-3353/GHSA-fgv7-7rh4-3353.json index a6c1ec8e137..7c10024d750 100644 --- a/advisories/unreviewed/2024/02/GHSA-fgv7-7rh4-3353/GHSA-fgv7-7rh4-3353.json +++ b/advisories/unreviewed/2024/02/GHSA-fgv7-7rh4-3353/GHSA-fgv7-7rh4-3353.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fgv7-7rh4-3353", - "modified": "2024-02-07T18:30:27Z", + "modified": "2025-05-15T21:31:15Z", "published": "2024-02-02T03:30:32Z", "aliases": [ "CVE-2024-22901" diff --git a/advisories/unreviewed/2024/02/GHSA-qw52-qmwq-9mjq/GHSA-qw52-qmwq-9mjq.json b/advisories/unreviewed/2024/02/GHSA-qw52-qmwq-9mjq/GHSA-qw52-qmwq-9mjq.json index 070b47280b3..6f9f60d2d76 100644 --- a/advisories/unreviewed/2024/02/GHSA-qw52-qmwq-9mjq/GHSA-qw52-qmwq-9mjq.json +++ b/advisories/unreviewed/2024/02/GHSA-qw52-qmwq-9mjq/GHSA-qw52-qmwq-9mjq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qw52-qmwq-9mjq", - "modified": "2024-02-13T21:30:28Z", + "modified": "2025-05-15T21:31:18Z", "published": "2024-02-06T00:30:27Z", "aliases": [ "CVE-2024-0797" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0797" }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3029488/profit-products-tables-for-woocommerce/trunk?contextall=1&old=3005088&old_path=%2Fprofit-products-tables-for-woocommerce%2Ftrunk" + }, { "type": "WEB", "url": "https://plugins.trac.wordpress.org/changeset/3029488/profit-products-tables-for-woocommerce/trunk?contextall=1&old=3005088&old_path=/profit-products-tables-for-woocommerce/trunk" diff --git a/advisories/unreviewed/2024/02/GHSA-r3vw-5726-q8gc/GHSA-r3vw-5726-q8gc.json b/advisories/unreviewed/2024/02/GHSA-r3vw-5726-q8gc/GHSA-r3vw-5726-q8gc.json index de92da9421d..116d90d78ae 100644 --- a/advisories/unreviewed/2024/02/GHSA-r3vw-5726-q8gc/GHSA-r3vw-5726-q8gc.json +++ b/advisories/unreviewed/2024/02/GHSA-r3vw-5726-q8gc/GHSA-r3vw-5726-q8gc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r3vw-5726-q8gc", - "modified": "2024-02-09T21:30:57Z", + "modified": "2025-05-15T21:31:15Z", "published": "2024-02-02T18:30:32Z", "aliases": [ "CVE-2024-22107" diff --git a/advisories/unreviewed/2024/02/GHSA-rv54-p5vw-c6p6/GHSA-rv54-p5vw-c6p6.json b/advisories/unreviewed/2024/02/GHSA-rv54-p5vw-c6p6/GHSA-rv54-p5vw-c6p6.json index 244d2d8daa8..9657b0019f6 100644 --- a/advisories/unreviewed/2024/02/GHSA-rv54-p5vw-c6p6/GHSA-rv54-p5vw-c6p6.json +++ b/advisories/unreviewed/2024/02/GHSA-rv54-p5vw-c6p6/GHSA-rv54-p5vw-c6p6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rv54-p5vw-c6p6", - "modified": "2024-02-13T21:30:28Z", + "modified": "2025-05-15T21:31:17Z", "published": "2024-02-06T00:30:26Z", "aliases": [ "CVE-2024-0324" diff --git a/advisories/unreviewed/2024/07/GHSA-64h4-j9cq-c2v4/GHSA-64h4-j9cq-c2v4.json b/advisories/unreviewed/2024/07/GHSA-64h4-j9cq-c2v4/GHSA-64h4-j9cq-c2v4.json index d2a9842d0cf..b75c68c9f8c 100644 --- a/advisories/unreviewed/2024/07/GHSA-64h4-j9cq-c2v4/GHSA-64h4-j9cq-c2v4.json +++ b/advisories/unreviewed/2024/07/GHSA-64h4-j9cq-c2v4/GHSA-64h4-j9cq-c2v4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-8h2w-mrjw-fq93/GHSA-8h2w-mrjw-fq93.json b/advisories/unreviewed/2024/07/GHSA-8h2w-mrjw-fq93/GHSA-8h2w-mrjw-fq93.json index 7ce2a3fcb62..a7bf33aa9a4 100644 --- a/advisories/unreviewed/2024/07/GHSA-8h2w-mrjw-fq93/GHSA-8h2w-mrjw-fq93.json +++ b/advisories/unreviewed/2024/07/GHSA-8h2w-mrjw-fq93/GHSA-8h2w-mrjw-fq93.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-c2jw-w6x7-cffr/GHSA-c2jw-w6x7-cffr.json b/advisories/unreviewed/2024/07/GHSA-c2jw-w6x7-cffr/GHSA-c2jw-w6x7-cffr.json index c59cb20f842..2c23ed03682 100644 --- a/advisories/unreviewed/2024/07/GHSA-c2jw-w6x7-cffr/GHSA-c2jw-w6x7-cffr.json +++ b/advisories/unreviewed/2024/07/GHSA-c2jw-w6x7-cffr/GHSA-c2jw-w6x7-cffr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-vq3c-gpmf-8p9q/GHSA-vq3c-gpmf-8p9q.json b/advisories/unreviewed/2024/07/GHSA-vq3c-gpmf-8p9q/GHSA-vq3c-gpmf-8p9q.json index 0d0322d4c03..ecec7191686 100644 --- a/advisories/unreviewed/2024/07/GHSA-vq3c-gpmf-8p9q/GHSA-vq3c-gpmf-8p9q.json +++ b/advisories/unreviewed/2024/07/GHSA-vq3c-gpmf-8p9q/GHSA-vq3c-gpmf-8p9q.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-2g2g-m4v5-68cr/GHSA-2g2g-m4v5-68cr.json b/advisories/unreviewed/2025/02/GHSA-2g2g-m4v5-68cr/GHSA-2g2g-m4v5-68cr.json index 2d6ab23e568..bcd38028d4c 100644 --- a/advisories/unreviewed/2025/02/GHSA-2g2g-m4v5-68cr/GHSA-2g2g-m4v5-68cr.json +++ b/advisories/unreviewed/2025/02/GHSA-2g2g-m4v5-68cr/GHSA-2g2g-m4v5-68cr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-727m-hgm4-397c/GHSA-727m-hgm4-397c.json b/advisories/unreviewed/2025/02/GHSA-727m-hgm4-397c/GHSA-727m-hgm4-397c.json index df4fa684629..dcc365ee059 100644 --- a/advisories/unreviewed/2025/02/GHSA-727m-hgm4-397c/GHSA-727m-hgm4-397c.json +++ b/advisories/unreviewed/2025/02/GHSA-727m-hgm4-397c/GHSA-727m-hgm4-397c.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-7c47-rxv3-c2fv/GHSA-7c47-rxv3-c2fv.json b/advisories/unreviewed/2025/02/GHSA-7c47-rxv3-c2fv/GHSA-7c47-rxv3-c2fv.json index 8d0ea691bd8..d44e2508488 100644 --- a/advisories/unreviewed/2025/02/GHSA-7c47-rxv3-c2fv/GHSA-7c47-rxv3-c2fv.json +++ b/advisories/unreviewed/2025/02/GHSA-7c47-rxv3-c2fv/GHSA-7c47-rxv3-c2fv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-7jc8-c5qp-jxfp/GHSA-7jc8-c5qp-jxfp.json b/advisories/unreviewed/2025/02/GHSA-7jc8-c5qp-jxfp/GHSA-7jc8-c5qp-jxfp.json index 3c318b95df9..729ff4b4664 100644 --- a/advisories/unreviewed/2025/02/GHSA-7jc8-c5qp-jxfp/GHSA-7jc8-c5qp-jxfp.json +++ b/advisories/unreviewed/2025/02/GHSA-7jc8-c5qp-jxfp/GHSA-7jc8-c5qp-jxfp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-9mmv-7xvp-7q48/GHSA-9mmv-7xvp-7q48.json b/advisories/unreviewed/2025/02/GHSA-9mmv-7xvp-7q48/GHSA-9mmv-7xvp-7q48.json index 0ce29085bc3..4dce76a7489 100644 --- a/advisories/unreviewed/2025/02/GHSA-9mmv-7xvp-7q48/GHSA-9mmv-7xvp-7q48.json +++ b/advisories/unreviewed/2025/02/GHSA-9mmv-7xvp-7q48/GHSA-9mmv-7xvp-7q48.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-gxwp-4448-26fp/GHSA-gxwp-4448-26fp.json b/advisories/unreviewed/2025/02/GHSA-gxwp-4448-26fp/GHSA-gxwp-4448-26fp.json index 290a727878b..dfa1f39026c 100644 --- a/advisories/unreviewed/2025/02/GHSA-gxwp-4448-26fp/GHSA-gxwp-4448-26fp.json +++ b/advisories/unreviewed/2025/02/GHSA-gxwp-4448-26fp/GHSA-gxwp-4448-26fp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-pqch-79w5-3vfc/GHSA-pqch-79w5-3vfc.json b/advisories/unreviewed/2025/02/GHSA-pqch-79w5-3vfc/GHSA-pqch-79w5-3vfc.json index 8ef462f14fb..f6779e7e221 100644 --- a/advisories/unreviewed/2025/02/GHSA-pqch-79w5-3vfc/GHSA-pqch-79w5-3vfc.json +++ b/advisories/unreviewed/2025/02/GHSA-pqch-79w5-3vfc/GHSA-pqch-79w5-3vfc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-v9mp-cw5f-943w/GHSA-v9mp-cw5f-943w.json b/advisories/unreviewed/2025/02/GHSA-v9mp-cw5f-943w/GHSA-v9mp-cw5f-943w.json index 1c4b4ad9a06..116f8e4dbcd 100644 --- a/advisories/unreviewed/2025/02/GHSA-v9mp-cw5f-943w/GHSA-v9mp-cw5f-943w.json +++ b/advisories/unreviewed/2025/02/GHSA-v9mp-cw5f-943w/GHSA-v9mp-cw5f-943w.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-8wr6-crxg-xffx/GHSA-8wr6-crxg-xffx.json b/advisories/unreviewed/2025/03/GHSA-8wr6-crxg-xffx/GHSA-8wr6-crxg-xffx.json index a17e1f54559..78731a22aeb 100644 --- a/advisories/unreviewed/2025/03/GHSA-8wr6-crxg-xffx/GHSA-8wr6-crxg-xffx.json +++ b/advisories/unreviewed/2025/03/GHSA-8wr6-crxg-xffx/GHSA-8wr6-crxg-xffx.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-c993-hrcm-4cp8/GHSA-c993-hrcm-4cp8.json b/advisories/unreviewed/2025/03/GHSA-c993-hrcm-4cp8/GHSA-c993-hrcm-4cp8.json index 706e6579e02..dd518779fb6 100644 --- a/advisories/unreviewed/2025/03/GHSA-c993-hrcm-4cp8/GHSA-c993-hrcm-4cp8.json +++ b/advisories/unreviewed/2025/03/GHSA-c993-hrcm-4cp8/GHSA-c993-hrcm-4cp8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-ffm9-v534-h8c2/GHSA-ffm9-v534-h8c2.json b/advisories/unreviewed/2025/03/GHSA-ffm9-v534-h8c2/GHSA-ffm9-v534-h8c2.json index 41803a66349..a01a863031d 100644 --- a/advisories/unreviewed/2025/03/GHSA-ffm9-v534-h8c2/GHSA-ffm9-v534-h8c2.json +++ b/advisories/unreviewed/2025/03/GHSA-ffm9-v534-h8c2/GHSA-ffm9-v534-h8c2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-hrqr-gcfr-cq9h/GHSA-hrqr-gcfr-cq9h.json b/advisories/unreviewed/2025/03/GHSA-hrqr-gcfr-cq9h/GHSA-hrqr-gcfr-cq9h.json index 0dd1dc99cb6..7d8ba725b8f 100644 --- a/advisories/unreviewed/2025/03/GHSA-hrqr-gcfr-cq9h/GHSA-hrqr-gcfr-cq9h.json +++ b/advisories/unreviewed/2025/03/GHSA-hrqr-gcfr-cq9h/GHSA-hrqr-gcfr-cq9h.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-jv5x-w5jr-8gvf/GHSA-jv5x-w5jr-8gvf.json b/advisories/unreviewed/2025/03/GHSA-jv5x-w5jr-8gvf/GHSA-jv5x-w5jr-8gvf.json index b409f70c08a..3a19a022c32 100644 --- a/advisories/unreviewed/2025/03/GHSA-jv5x-w5jr-8gvf/GHSA-jv5x-w5jr-8gvf.json +++ b/advisories/unreviewed/2025/03/GHSA-jv5x-w5jr-8gvf/GHSA-jv5x-w5jr-8gvf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-pf92-gxmq-pgwp/GHSA-pf92-gxmq-pgwp.json b/advisories/unreviewed/2025/03/GHSA-pf92-gxmq-pgwp/GHSA-pf92-gxmq-pgwp.json index e72ddcd1cbb..62dc842d878 100644 --- a/advisories/unreviewed/2025/03/GHSA-pf92-gxmq-pgwp/GHSA-pf92-gxmq-pgwp.json +++ b/advisories/unreviewed/2025/03/GHSA-pf92-gxmq-pgwp/GHSA-pf92-gxmq-pgwp.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-q27q-f4wr-gh4j/GHSA-q27q-f4wr-gh4j.json b/advisories/unreviewed/2025/03/GHSA-q27q-f4wr-gh4j/GHSA-q27q-f4wr-gh4j.json index f6b4e539731..c5fd9d837b4 100644 --- a/advisories/unreviewed/2025/03/GHSA-q27q-f4wr-gh4j/GHSA-q27q-f4wr-gh4j.json +++ b/advisories/unreviewed/2025/03/GHSA-q27q-f4wr-gh4j/GHSA-q27q-f4wr-gh4j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-qgrj-c4rv-c2r5/GHSA-qgrj-c4rv-c2r5.json b/advisories/unreviewed/2025/03/GHSA-qgrj-c4rv-c2r5/GHSA-qgrj-c4rv-c2r5.json index 5d5c3a9481b..2ad3dfd2bdd 100644 --- a/advisories/unreviewed/2025/03/GHSA-qgrj-c4rv-c2r5/GHSA-qgrj-c4rv-c2r5.json +++ b/advisories/unreviewed/2025/03/GHSA-qgrj-c4rv-c2r5/GHSA-qgrj-c4rv-c2r5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-2x46-9926-54cg/GHSA-2x46-9926-54cg.json b/advisories/unreviewed/2025/04/GHSA-2x46-9926-54cg/GHSA-2x46-9926-54cg.json index f230dc665fd..52a9f1c414f 100644 --- a/advisories/unreviewed/2025/04/GHSA-2x46-9926-54cg/GHSA-2x46-9926-54cg.json +++ b/advisories/unreviewed/2025/04/GHSA-2x46-9926-54cg/GHSA-2x46-9926-54cg.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-6qwv-wfwp-j22f/GHSA-6qwv-wfwp-j22f.json b/advisories/unreviewed/2025/04/GHSA-6qwv-wfwp-j22f/GHSA-6qwv-wfwp-j22f.json index 9e275770889..c877297b80b 100644 --- a/advisories/unreviewed/2025/04/GHSA-6qwv-wfwp-j22f/GHSA-6qwv-wfwp-j22f.json +++ b/advisories/unreviewed/2025/04/GHSA-6qwv-wfwp-j22f/GHSA-6qwv-wfwp-j22f.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-8h58-9hjg-3xqh/GHSA-8h58-9hjg-3xqh.json b/advisories/unreviewed/2025/04/GHSA-8h58-9hjg-3xqh/GHSA-8h58-9hjg-3xqh.json index 32506d4dedb..234ba17a71a 100644 --- a/advisories/unreviewed/2025/04/GHSA-8h58-9hjg-3xqh/GHSA-8h58-9hjg-3xqh.json +++ b/advisories/unreviewed/2025/04/GHSA-8h58-9hjg-3xqh/GHSA-8h58-9hjg-3xqh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8h58-9hjg-3xqh", - "modified": "2025-04-10T15:31:48Z", + "modified": "2025-05-15T21:31:25Z", "published": "2025-04-10T09:30:23Z", "aliases": [ "CVE-2024-13896" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1333" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-fc2p-qppw-qq2v/GHSA-fc2p-qppw-qq2v.json b/advisories/unreviewed/2025/04/GHSA-fc2p-qppw-qq2v/GHSA-fc2p-qppw-qq2v.json index 34e03d8e941..f4f918a29c8 100644 --- a/advisories/unreviewed/2025/04/GHSA-fc2p-qppw-qq2v/GHSA-fc2p-qppw-qq2v.json +++ b/advisories/unreviewed/2025/04/GHSA-fc2p-qppw-qq2v/GHSA-fc2p-qppw-qq2v.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-502" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-gh4m-j6cx-fcjx/GHSA-gh4m-j6cx-fcjx.json b/advisories/unreviewed/2025/04/GHSA-gh4m-j6cx-fcjx/GHSA-gh4m-j6cx-fcjx.json index 20f6cb66b4c..c599a4ca0a6 100644 --- a/advisories/unreviewed/2025/04/GHSA-gh4m-j6cx-fcjx/GHSA-gh4m-j6cx-fcjx.json +++ b/advisories/unreviewed/2025/04/GHSA-gh4m-j6cx-fcjx/GHSA-gh4m-j6cx-fcjx.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-w67q-cmfr-rmhr/GHSA-w67q-cmfr-rmhr.json b/advisories/unreviewed/2025/04/GHSA-w67q-cmfr-rmhr/GHSA-w67q-cmfr-rmhr.json index 3165e97469f..055283bbb96 100644 --- a/advisories/unreviewed/2025/04/GHSA-w67q-cmfr-rmhr/GHSA-w67q-cmfr-rmhr.json +++ b/advisories/unreviewed/2025/04/GHSA-w67q-cmfr-rmhr/GHSA-w67q-cmfr-rmhr.json @@ -38,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-352", "CWE-79" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/05/GHSA-2377-3h83-ch9w/GHSA-2377-3h83-ch9w.json b/advisories/unreviewed/2025/05/GHSA-2377-3h83-ch9w/GHSA-2377-3h83-ch9w.json new file mode 100644 index 00000000000..374b361ff61 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2377-3h83-ch9w/GHSA-2377-3h83-ch9w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2377-3h83-ch9w", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-12874" + ], + "details": "The Top Comments WordPress plugin through 1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12874" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/7cc14a87-4605-49f6-9d51-0b9eb57e6c9d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-23vm-fxf4-h89x/GHSA-23vm-fxf4-h89x.json b/advisories/unreviewed/2025/05/GHSA-23vm-fxf4-h89x/GHSA-23vm-fxf4-h89x.json new file mode 100644 index 00000000000..88e29933012 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-23vm-fxf4-h89x/GHSA-23vm-fxf4-h89x.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23vm-fxf4-h89x", + "modified": "2025-05-15T21:31:26Z", + "published": "2025-05-15T21:31:26Z", + "aliases": [ + "CVE-2023-5529" + ], + "details": "The Advanced Page Visit Counter WordPress plugin before 8.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5529" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/095c9c35-2618-4f90-8435-a3c34f0bb7f1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-244m-98g9-4pg8/GHSA-244m-98g9-4pg8.json b/advisories/unreviewed/2025/05/GHSA-244m-98g9-4pg8/GHSA-244m-98g9-4pg8.json new file mode 100644 index 00000000000..855afc14c40 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-244m-98g9-4pg8/GHSA-244m-98g9-4pg8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-244m-98g9-4pg8", + "modified": "2025-05-15T21:31:34Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2025-1288" + ], + "details": "The WOOEXIM WordPress plugin through 5.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make an unauthenticated user vulnerable to reflected XSS via a CSRF attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1288" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/175af35d-6972-42c9-b7ac-913ce1fbac64" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-28c7-hwc8-phgm/GHSA-28c7-hwc8-phgm.json b/advisories/unreviewed/2025/05/GHSA-28c7-hwc8-phgm/GHSA-28c7-hwc8-phgm.json new file mode 100644 index 00000000000..41fbc8ad71b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-28c7-hwc8-phgm/GHSA-28c7-hwc8-phgm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28c7-hwc8-phgm", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-12735" + ], + "details": "The Advance Post Prefix WordPress plugin through 1.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins and above to perform SQL injection attacks", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12735" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/1b355399-e92b-46aa-ada1-95e99fc03976" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-28cc-3w24-mfvx/GHSA-28cc-3w24-mfvx.json b/advisories/unreviewed/2025/05/GHSA-28cc-3w24-mfvx/GHSA-28cc-3w24-mfvx.json new file mode 100644 index 00000000000..dfddeb3bb4b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-28cc-3w24-mfvx/GHSA-28cc-3w24-mfvx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28cc-3w24-mfvx", + "modified": "2025-05-15T21:31:34Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2024-9838" + ], + "details": "The Auto Affiliate Links WordPress plugin before 6.4.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9838" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/3cc0ff78-b310-40a4-899c-15fecbb345c5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-28fx-qww6-g655/GHSA-28fx-qww6-g655.json b/advisories/unreviewed/2025/05/GHSA-28fx-qww6-g655/GHSA-28fx-qww6-g655.json new file mode 100644 index 00000000000..c2b74d0bf39 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-28fx-qww6-g655/GHSA-28fx-qww6-g655.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28fx-qww6-g655", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-10362" + ], + "details": "The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.9.1 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10362" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/701f653b-a0c3-49b4-972e-f26c3633ad92" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2cw7-7rj8-j2x7/GHSA-2cw7-7rj8-j2x7.json b/advisories/unreviewed/2025/05/GHSA-2cw7-7rj8-j2x7/GHSA-2cw7-7rj8-j2x7.json new file mode 100644 index 00000000000..0871e38776d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2cw7-7rj8-j2x7/GHSA-2cw7-7rj8-j2x7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cw7-7rj8-j2x7", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-8082" + ], + "details": "The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8082" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/47b2cd60-9ac4-49cf-8ca9-7d90656fc397" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2g6g-hhqw-63q5/GHSA-2g6g-hhqw-63q5.json b/advisories/unreviewed/2025/05/GHSA-2g6g-hhqw-63q5/GHSA-2g6g-hhqw-63q5.json new file mode 100644 index 00000000000..3abda7160b0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2g6g-hhqw-63q5/GHSA-2g6g-hhqw-63q5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2g6g-hhqw-63q5", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-12282" + ], + "details": "The WordPress连接微博 WordPress plugin through 2.5.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12282" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/2d81f038-e2bb-4906-a954-78dc971ed793" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2gpg-rr9p-jqp9/GHSA-2gpg-rr9p-jqp9.json b/advisories/unreviewed/2025/05/GHSA-2gpg-rr9p-jqp9/GHSA-2gpg-rr9p-jqp9.json new file mode 100644 index 00000000000..5a103e236ac --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2gpg-rr9p-jqp9/GHSA-2gpg-rr9p-jqp9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gpg-rr9p-jqp9", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-8426" + ], + "details": "The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8426" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/f81b7478-c775-45ff-bbb8-d13c3f58acc6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2v7w-p95j-mfhp/GHSA-2v7w-p95j-mfhp.json b/advisories/unreviewed/2025/05/GHSA-2v7w-p95j-mfhp/GHSA-2v7w-p95j-mfhp.json new file mode 100644 index 00000000000..76a753208cf --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2v7w-p95j-mfhp/GHSA-2v7w-p95j-mfhp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v7w-p95j-mfhp", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:26Z", + "aliases": [ + "CVE-2023-6030" + ], + "details": "The LogDash Activity Log WordPress plugin before 1.1.4 hooks the wp_login_failed function (from src/Hooks/Users.php) in order to log failed login attempts to the database but it doesn't escape the username when it perform some SQL request leading to a SQL injection vulnerability which can be exploited using time-based technique by unauthenticated attacker", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6030" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/b658e403-006c-4555-b1b2-3603e44f4411" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2w83-9v42-r6h5/GHSA-2w83-9v42-r6h5.json b/advisories/unreviewed/2025/05/GHSA-2w83-9v42-r6h5/GHSA-2w83-9v42-r6h5.json new file mode 100644 index 00000000000..4337c98191a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2w83-9v42-r6h5/GHSA-2w83-9v42-r6h5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w83-9v42-r6h5", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-10818" + ], + "details": "The JSFiddle Shortcode WordPress plugin before 1.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10818" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/aafd152c-1a05-4191-a1bc-b802d801ca03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3262-4hm9-mq8q/GHSA-3262-4hm9-mq8q.json b/advisories/unreviewed/2025/05/GHSA-3262-4hm9-mq8q/GHSA-3262-4hm9-mq8q.json new file mode 100644 index 00000000000..b3f7038d78e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3262-4hm9-mq8q/GHSA-3262-4hm9-mq8q.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3262-4hm9-mq8q", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-13127" + ], + "details": "The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13127" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/003ac248-74db-4b83-af0b-aa37ffb9b3d3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-32jx-cx53-vp3r/GHSA-32jx-cx53-vp3r.json b/advisories/unreviewed/2025/05/GHSA-32jx-cx53-vp3r/GHSA-32jx-cx53-vp3r.json new file mode 100644 index 00000000000..90f16e05e4b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-32jx-cx53-vp3r/GHSA-32jx-cx53-vp3r.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32jx-cx53-vp3r", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-11373" + ], + "details": "The Connexion Logs WordPress plugin through 3.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11373" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/e9ef847f-3a3f-4030-828b-78db0044e142" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-33f2-v5w3-mmvw/GHSA-33f2-v5w3-mmvw.json b/advisories/unreviewed/2025/05/GHSA-33f2-v5w3-mmvw/GHSA-33f2-v5w3-mmvw.json new file mode 100644 index 00000000000..48df88280d5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-33f2-v5w3-mmvw/GHSA-33f2-v5w3-mmvw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33f2-v5w3-mmvw", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:31Z", + "aliases": [ + "CVE-2024-6665" + ], + "details": "The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6665" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/a0b3335f-6e04-402f-8cfd-fc4c62e52168" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-345f-895w-jg76/GHSA-345f-895w-jg76.json b/advisories/unreviewed/2025/05/GHSA-345f-895w-jg76/GHSA-345f-895w-jg76.json new file mode 100644 index 00000000000..9998a65b9ad --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-345f-895w-jg76/GHSA-345f-895w-jg76.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-345f-895w-jg76", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2023-7228" + ], + "details": "The illi Link Party! WordPress plugin through 1.0 does not sanitise and escape some parameters, which could allow unauthenticated vistors to perform Cross-Site Scripting attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7228" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/1ddf1271-3826-44e2-8408-cfbe9c3cc547" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-353c-hm8f-g46h/GHSA-353c-hm8f-g46h.json b/advisories/unreviewed/2025/05/GHSA-353c-hm8f-g46h/GHSA-353c-hm8f-g46h.json new file mode 100644 index 00000000000..718d453a964 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-353c-hm8f-g46h/GHSA-353c-hm8f-g46h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-353c-hm8f-g46h", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-12722" + ], + "details": "The Twitter Bootstrap Collapse aka Accordian Shortcode WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12722" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c3be5990-ca89-4ac4-baae-49af55df9d57" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-36rh-228q-4mhv/GHSA-36rh-228q-4mhv.json b/advisories/unreviewed/2025/05/GHSA-36rh-228q-4mhv/GHSA-36rh-228q-4mhv.json new file mode 100644 index 00000000000..ed3576039a6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-36rh-228q-4mhv/GHSA-36rh-228q-4mhv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36rh-228q-4mhv", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-8854" + ], + "details": "The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8854" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/bffe0f75-33a2-4270-af13-835b8eb65688" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-37c5-cj42-grq7/GHSA-37c5-cj42-grq7.json b/advisories/unreviewed/2025/05/GHSA-37c5-cj42-grq7/GHSA-37c5-cj42-grq7.json new file mode 100644 index 00000000000..a31d94ed095 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-37c5-cj42-grq7/GHSA-37c5-cj42-grq7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37c5-cj42-grq7", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-7758" + ], + "details": "The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could allow high privilege users of contributor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7758" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/0bf39a29-a605-407b-9ab0-a82437d16153" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3h8r-96mm-7vvg/GHSA-3h8r-96mm-7vvg.json b/advisories/unreviewed/2025/05/GHSA-3h8r-96mm-7vvg/GHSA-3h8r-96mm-7vvg.json new file mode 100644 index 00000000000..cac8b7e9c6f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3h8r-96mm-7vvg/GHSA-3h8r-96mm-7vvg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3h8r-96mm-7vvg", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-9662" + ], + "details": "The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9662" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/dfa6ff7d-c0dc-4118-afe0-587a24c76f12" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3m52-6qc2-vwqh/GHSA-3m52-6qc2-vwqh.json b/advisories/unreviewed/2025/05/GHSA-3m52-6qc2-vwqh/GHSA-3m52-6qc2-vwqh.json new file mode 100644 index 00000000000..48197b89948 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3m52-6qc2-vwqh/GHSA-3m52-6qc2-vwqh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3m52-6qc2-vwqh", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-8702" + ], + "details": "The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8702" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/2199ef66-25bd-4eb4-a675-d8b30f047847" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3q32-7qwj-m73v/GHSA-3q32-7qwj-m73v.json b/advisories/unreviewed/2025/05/GHSA-3q32-7qwj-m73v/GHSA-3q32-7qwj-m73v.json new file mode 100644 index 00000000000..abbaa32b672 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3q32-7qwj-m73v/GHSA-3q32-7qwj-m73v.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q32-7qwj-m73v", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:31Z", + "aliases": [ + "CVE-2024-6667" + ], + "details": "The KBucket: Your Curated Content in WordPress plugin before 4.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6667" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d2b8ca6c-2b14-4d72-8e39-0f3ca5c23f56" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3vx5-jr5m-gpmq/GHSA-3vx5-jr5m-gpmq.json b/advisories/unreviewed/2025/05/GHSA-3vx5-jr5m-gpmq/GHSA-3vx5-jr5m-gpmq.json new file mode 100644 index 00000000000..9781bdfdf4a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3vx5-jr5m-gpmq/GHSA-3vx5-jr5m-gpmq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vx5-jr5m-gpmq", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-11719" + ], + "details": "The tarteaucitron-wp WordPress plugin before 0.3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11719" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/64c2a296-5fc6-450e-a12d-75cbf8b73e3a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-42p9-p46j-wc9w/GHSA-42p9-p46j-wc9w.json b/advisories/unreviewed/2025/05/GHSA-42p9-p46j-wc9w/GHSA-42p9-p46j-wc9w.json new file mode 100644 index 00000000000..4c43315aa04 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-42p9-p46j-wc9w/GHSA-42p9-p46j-wc9w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42p9-p46j-wc9w", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-13823" + ], + "details": "The 360 Product Rotation WordPress plugin through 1.5.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13823" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/dcfd8a03-0a04-4fd1-986d-1e816b1fad19" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-485p-wc8p-j3jv/GHSA-485p-wc8p-j3jv.json b/advisories/unreviewed/2025/05/GHSA-485p-wc8p-j3jv/GHSA-485p-wc8p-j3jv.json new file mode 100644 index 00000000000..b82830364e4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-485p-wc8p-j3jv/GHSA-485p-wc8p-j3jv.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-485p-wc8p-j3jv", + "modified": "2025-05-15T21:31:35Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2025-4715" + ], + "details": "A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /pages/view_application.php. The manipulation of the argument cid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4715" + }, + { + "type": "WEB", + "url": "https://github.com/lanxia0/CVE/issues/9" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309013" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309013" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.568295" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4g4f-j7gv-ph46/GHSA-4g4f-j7gv-ph46.json b/advisories/unreviewed/2025/05/GHSA-4g4f-j7gv-ph46/GHSA-4g4f-j7gv-ph46.json new file mode 100644 index 00000000000..7b020024f4a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4g4f-j7gv-ph46/GHSA-4g4f-j7gv-ph46.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g4f-j7gv-ph46", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-12733" + ], + "details": "The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12733" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/61be935e-ecb4-45be-8553-65877dd42569" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4gr5-vxg2-5c62/GHSA-4gr5-vxg2-5c62.json b/advisories/unreviewed/2025/05/GHSA-4gr5-vxg2-5c62/GHSA-4gr5-vxg2-5c62.json new file mode 100644 index 00000000000..f2817df0036 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4gr5-vxg2-5c62/GHSA-4gr5-vxg2-5c62.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gr5-vxg2-5c62", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-12716" + ], + "details": "The Simple Basic Contact Form WordPress plugin before 20250114 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12716" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/a9fa48f1-d7fd-4968-a122-937803f186a2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4jfp-89f3-9pw7/GHSA-4jfp-89f3-9pw7.json b/advisories/unreviewed/2025/05/GHSA-4jfp-89f3-9pw7/GHSA-4jfp-89f3-9pw7.json new file mode 100644 index 00000000000..c2af8787420 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4jfp-89f3-9pw7/GHSA-4jfp-89f3-9pw7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jfp-89f3-9pw7", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2023-7088" + ], + "details": "The Add SVG Support for Media Uploader | inventivo WordPress plugin through 1.0.5 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7088" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/8f515e36-9072-4fc4-9d2f-d50f1adde626" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4jg8-qc3w-j5hx/GHSA-4jg8-qc3w-j5hx.json b/advisories/unreviewed/2025/05/GHSA-4jg8-qc3w-j5hx/GHSA-4jg8-qc3w-j5hx.json new file mode 100644 index 00000000000..23078ea1e40 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4jg8-qc3w-j5hx/GHSA-4jg8-qc3w-j5hx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jg8-qc3w-j5hx", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-7556" + ], + "details": "The Simple Share WordPress plugin through 0.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7556" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/89ccbe24-be15-4b13-883a-48d6da9c8ffa" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4p3r-7jgv-wgrw/GHSA-4p3r-7jgv-wgrw.json b/advisories/unreviewed/2025/05/GHSA-4p3r-7jgv-wgrw/GHSA-4p3r-7jgv-wgrw.json new file mode 100644 index 00000000000..89fa19cfd14 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4p3r-7jgv-wgrw/GHSA-4p3r-7jgv-wgrw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p3r-7jgv-wgrw", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2024-10054" + ], + "details": "The Happyforms WordPress plugin before 1.26.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10054" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/5a9fd64b-3207-4acb-92ff-1cca08c41ac9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4v78-7jx6-mhrg/GHSA-4v78-7jx6-mhrg.json b/advisories/unreviewed/2025/05/GHSA-4v78-7jx6-mhrg/GHSA-4v78-7jx6-mhrg.json new file mode 100644 index 00000000000..5a9a8a1d199 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4v78-7jx6-mhrg/GHSA-4v78-7jx6-mhrg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v78-7jx6-mhrg", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-11267" + ], + "details": "The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with Contributor to perform SQL injection attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11267" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/fcbdc11a-a194-46e4-8c22-11010b98fdab" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4vxm-8pm4-5h85/GHSA-4vxm-8pm4-5h85.json b/advisories/unreviewed/2025/05/GHSA-4vxm-8pm4-5h85/GHSA-4vxm-8pm4-5h85.json new file mode 100644 index 00000000000..aa8c2c05a35 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4vxm-8pm4-5h85/GHSA-4vxm-8pm4-5h85.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vxm-8pm4-5h85", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2023-7229" + ], + "details": "The illi Link Party! WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7229" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d16f6ba0-a47d-413f-a6d4-058910441009" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4x2h-w98x-4p25/GHSA-4x2h-w98x-4p25.json b/advisories/unreviewed/2025/05/GHSA-4x2h-w98x-4p25/GHSA-4x2h-w98x-4p25.json new file mode 100644 index 00000000000..6a0993f1d02 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4x2h-w98x-4p25/GHSA-4x2h-w98x-4p25.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x2h-w98x-4p25", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-12873" + ], + "details": "The Custom Field Manager WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12873" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/3e82d45f-7b8f-424e-a8d7-be64f5acf65e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5336-w9c9-9274/GHSA-5336-w9c9-9274.json b/advisories/unreviewed/2025/05/GHSA-5336-w9c9-9274/GHSA-5336-w9c9-9274.json new file mode 100644 index 00000000000..a93d46c3c60 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5336-w9c9-9274/GHSA-5336-w9c9-9274.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5336-w9c9-9274", + "modified": "2025-05-15T21:31:34Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2025-1303" + ], + "details": "The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1303" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/35181798-4f21-4c8d-bb6e-61eb13683a74" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-559f-7rvx-wm9p/GHSA-559f-7rvx-wm9p.json b/advisories/unreviewed/2025/05/GHSA-559f-7rvx-wm9p/GHSA-559f-7rvx-wm9p.json new file mode 100644 index 00000000000..4d8be00bf8f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-559f-7rvx-wm9p/GHSA-559f-7rvx-wm9p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-559f-7rvx-wm9p", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-5440" + ], + "details": "The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5440" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/52fdc271-96f2-4e25-9df2-29a3ce06328c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-55w8-3v67-vrph/GHSA-55w8-3v67-vrph.json b/advisories/unreviewed/2025/05/GHSA-55w8-3v67-vrph/GHSA-55w8-3v67-vrph.json new file mode 100644 index 00000000000..ee375d82845 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-55w8-3v67-vrph/GHSA-55w8-3v67-vrph.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55w8-3v67-vrph", + "modified": "2025-05-15T21:31:22Z", + "published": "2025-05-15T21:31:22Z", + "aliases": [ + "CVE-2024-13628" + ], + "details": "The WP Pricing Table WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13628" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/34d6c8a2-e70d-485c-a217-4a569c16b079" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-57c2-2x5j-8gpq/GHSA-57c2-2x5j-8gpq.json b/advisories/unreviewed/2025/05/GHSA-57c2-2x5j-8gpq/GHSA-57c2-2x5j-8gpq.json new file mode 100644 index 00000000000..0113c6f5b29 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-57c2-2x5j-8gpq/GHSA-57c2-2x5j-8gpq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57c2-2x5j-8gpq", + "modified": "2025-05-15T21:31:34Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2025-2247" + ], + "details": "The WP-PManager WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2247" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/3974c5c3-887e-46bd-aad7-4f3169bff6de" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-57rv-fpf7-pch9/GHSA-57rv-fpf7-pch9.json b/advisories/unreviewed/2025/05/GHSA-57rv-fpf7-pch9/GHSA-57rv-fpf7-pch9.json new file mode 100644 index 00000000000..a62d0918fa3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-57rv-fpf7-pch9/GHSA-57rv-fpf7-pch9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57rv-fpf7-pch9", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-10631" + ], + "details": "The Countdown Timer for WordPress Block Editor WordPress plugin through 1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10631" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/b153fb5e-7df2-491b-b61b-6f90314c7b04" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5c34-m5vc-78j5/GHSA-5c34-m5vc-78j5.json b/advisories/unreviewed/2025/05/GHSA-5c34-m5vc-78j5/GHSA-5c34-m5vc-78j5.json new file mode 100644 index 00000000000..5abe128075e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5c34-m5vc-78j5/GHSA-5c34-m5vc-78j5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c34-m5vc-78j5", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-8284" + ], + "details": "The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8284" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/93e38b8c-8a2e-4264-b520-ebdbe995d61e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5gjw-c85q-72c7/GHSA-5gjw-c85q-72c7.json b/advisories/unreviewed/2025/05/GHSA-5gjw-c85q-72c7/GHSA-5gjw-c85q-72c7.json new file mode 100644 index 00000000000..cbd3f3fa105 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5gjw-c85q-72c7/GHSA-5gjw-c85q-72c7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gjw-c85q-72c7", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2024-10009" + ], + "details": "The Melapress File Monitor WordPress plugin before 2.1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10009" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c2b1f9f4-d5f3-4975-afd1-50eaf193e2ab" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5qff-4269-vc22/GHSA-5qff-4269-vc22.json b/advisories/unreviewed/2025/05/GHSA-5qff-4269-vc22/GHSA-5qff-4269-vc22.json new file mode 100644 index 00000000000..77cd4cc3583 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5qff-4269-vc22/GHSA-5qff-4269-vc22.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qff-4269-vc22", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-12770" + ], + "details": "The WP ULike WordPress plugin before 4.7.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12770" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/e21f6a4e-f385-411b-8d91-0f38f9e6cdd3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-62xj-j866-fwp8/GHSA-62xj-j866-fwp8.json b/advisories/unreviewed/2025/05/GHSA-62xj-j866-fwp8/GHSA-62xj-j866-fwp8.json new file mode 100644 index 00000000000..4fe8018f90f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-62xj-j866-fwp8/GHSA-62xj-j866-fwp8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62xj-j866-fwp8", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-11843" + ], + "details": "The Panorama WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11843" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/0dd41559-d88a-4018-a0f0-c8944b6d6f0a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-63hr-jqx6-r6hw/GHSA-63hr-jqx6-r6hw.json b/advisories/unreviewed/2025/05/GHSA-63hr-jqx6-r6hw/GHSA-63hr-jqx6-r6hw.json new file mode 100644 index 00000000000..5ac7a484727 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-63hr-jqx6-r6hw/GHSA-63hr-jqx6-r6hw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63hr-jqx6-r6hw", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-13729" + ], + "details": "The Podlove Podcast Publisher WordPress plugin before 4.1.24 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13729" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/2feed26b-ef02-4954-ab9d-8b0f958b0ef1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6545-29c2-j2r5/GHSA-6545-29c2-j2r5.json b/advisories/unreviewed/2025/05/GHSA-6545-29c2-j2r5/GHSA-6545-29c2-j2r5.json new file mode 100644 index 00000000000..e8a013c7bc3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6545-29c2-j2r5/GHSA-6545-29c2-j2r5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6545-29c2-j2r5", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-13313" + ], + "details": "The AWeber WordPress plugin through 7.3.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13313" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/cc35b2f4-f1f1-4ed3-91b2-025bd5848b29" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6925-xwwp-qwh5/GHSA-6925-xwwp-qwh5.json b/advisories/unreviewed/2025/05/GHSA-6925-xwwp-qwh5/GHSA-6925-xwwp-qwh5.json new file mode 100644 index 00000000000..0dfd2145b65 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6925-xwwp-qwh5/GHSA-6925-xwwp-qwh5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6925-xwwp-qwh5", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-8286" + ], + "details": "The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting visit logs via CSRF attacks", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8286" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/628bbac0-76b1-4666-9c00-bae84b48f85c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-69rr-vrmw-qwxp/GHSA-69rr-vrmw-qwxp.json b/advisories/unreviewed/2025/05/GHSA-69rr-vrmw-qwxp/GHSA-69rr-vrmw-qwxp.json new file mode 100644 index 00000000000..683fd146246 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-69rr-vrmw-qwxp/GHSA-69rr-vrmw-qwxp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69rr-vrmw-qwxp", + "modified": "2025-05-15T21:31:34Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2025-1454" + ], + "details": "The Ninja Pages WordPress plugin through 1.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1454" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/0089f813-82fa-4ffc-acd6-a70e67edc8ea" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-69xj-9qh4-v9hv/GHSA-69xj-9qh4-v9hv.json b/advisories/unreviewed/2025/05/GHSA-69xj-9qh4-v9hv/GHSA-69xj-9qh4-v9hv.json new file mode 100644 index 00000000000..0744b12d432 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-69xj-9qh4-v9hv/GHSA-69xj-9qh4-v9hv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69xj-9qh4-v9hv", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-12725" + ], + "details": "The Clasify Classified Listing WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12725" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/a174c640-6994-4028-a8a3-c470d5612304" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6c4h-4fjm-m75j/GHSA-6c4h-4fjm-m75j.json b/advisories/unreviewed/2025/05/GHSA-6c4h-4fjm-m75j/GHSA-6c4h-4fjm-m75j.json new file mode 100644 index 00000000000..102b9368e75 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6c4h-4fjm-m75j/GHSA-6c4h-4fjm-m75j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c4h-4fjm-m75j", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-8542" + ], + "details": "The Everest Forms WordPress plugin before 3.0.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8542" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/e5f94dcf-a6dc-4c4c-acb6-1a7ead701053" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6p5x-4w46-32gx/GHSA-6p5x-4w46-32gx.json b/advisories/unreviewed/2025/05/GHSA-6p5x-4w46-32gx/GHSA-6p5x-4w46-32gx.json new file mode 100644 index 00000000000..3a052386e65 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6p5x-4w46-32gx/GHSA-6p5x-4w46-32gx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p5x-4w46-32gx", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-4665" + ], + "details": "The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4665" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/50b78cac-cad1-4526-9655-ae0440739796" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6vhr-vrr2-gfrx/GHSA-6vhr-vrr2-gfrx.json b/advisories/unreviewed/2025/05/GHSA-6vhr-vrr2-gfrx/GHSA-6vhr-vrr2-gfrx.json new file mode 100644 index 00000000000..01708068ac7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6vhr-vrr2-gfrx/GHSA-6vhr-vrr2-gfrx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vhr-vrr2-gfrx", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-8620" + ], + "details": "The MapPress Maps for WordPress plugin before 2.93 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8620" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d8b0ddd8-0380-4185-aa00-8437e2b617ad" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-728g-2vgp-mc3v/GHSA-728g-2vgp-mc3v.json b/advisories/unreviewed/2025/05/GHSA-728g-2vgp-mc3v/GHSA-728g-2vgp-mc3v.json new file mode 100644 index 00000000000..0ae7135a29f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-728g-2vgp-mc3v/GHSA-728g-2vgp-mc3v.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-728g-2vgp-mc3v", + "modified": "2025-05-15T21:31:35Z", + "published": "2025-05-15T21:31:35Z", + "aliases": [ + "CVE-2025-4720" + ], + "details": "A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file academic/core/drop_student.php. The manipulation of the argument img leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4720" + }, + { + "type": "WEB", + "url": "https://github.com/Xiaoyi-ing/CVE/issues/4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309022" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309022" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.569855" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-75cj-c4x9-c5qh/GHSA-75cj-c4x9-c5qh.json b/advisories/unreviewed/2025/05/GHSA-75cj-c4x9-c5qh/GHSA-75cj-c4x9-c5qh.json new file mode 100644 index 00000000000..ceff1f7ba07 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-75cj-c4x9-c5qh/GHSA-75cj-c4x9-c5qh.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75cj-c4x9-c5qh", + "modified": "2025-05-15T21:31:35Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2025-4721" + ], + "details": "A vulnerability was found in itsourcecode Placement Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /drive.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4721" + }, + { + "type": "WEB", + "url": "https://github.com/byxs0x0/cve/issues/3" + }, + { + "type": "WEB", + "url": "https://itsourcecode.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309023" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309023" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.569945" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-75jq-cq85-m7jx/GHSA-75jq-cq85-m7jx.json b/advisories/unreviewed/2025/05/GHSA-75jq-cq85-m7jx/GHSA-75jq-cq85-m7jx.json new file mode 100644 index 00000000000..450c12ec36b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-75jq-cq85-m7jx/GHSA-75jq-cq85-m7jx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75jq-cq85-m7jx", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-11221" + ], + "details": "The Full Screen (Page) Background Image Slideshow WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11221" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/810c2c94-5d35-419c-a993-07a0c7064ce6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-764c-3vwj-x87m/GHSA-764c-3vwj-x87m.json b/advisories/unreviewed/2025/05/GHSA-764c-3vwj-x87m/GHSA-764c-3vwj-x87m.json new file mode 100644 index 00000000000..e7d15c80b23 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-764c-3vwj-x87m/GHSA-764c-3vwj-x87m.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-764c-3vwj-x87m", + "modified": "2025-05-15T21:31:34Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2024-9709" + ], + "details": "The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9709" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/9d535434-6512-44cb-8198-c105062df2b8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-76h7-whc6-vxcf/GHSA-76h7-whc6-vxcf.json b/advisories/unreviewed/2025/05/GHSA-76h7-whc6-vxcf/GHSA-76h7-whc6-vxcf.json new file mode 100644 index 00000000000..ef054c22b97 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-76h7-whc6-vxcf/GHSA-76h7-whc6-vxcf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76h7-whc6-vxcf", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2024-0249" + ], + "details": "The Advanced Schedule Posts WordPress plugin through 2.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admins.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0249" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/e7ee3e73-1086-421f-b586-d415a45a6c8e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-78rr-5vrh-jhqh/GHSA-78rr-5vrh-jhqh.json b/advisories/unreviewed/2025/05/GHSA-78rr-5vrh-jhqh/GHSA-78rr-5vrh-jhqh.json index e7b684211f7..cce01069a7b 100644 --- a/advisories/unreviewed/2025/05/GHSA-78rr-5vrh-jhqh/GHSA-78rr-5vrh-jhqh.json +++ b/advisories/unreviewed/2025/05/GHSA-78rr-5vrh-jhqh/GHSA-78rr-5vrh-jhqh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-78rr-5vrh-jhqh", - "modified": "2025-05-14T21:31:17Z", + "modified": "2025-05-15T21:31:26Z", "published": "2025-05-14T21:31:17Z", "aliases": [ "CVE-2025-0131" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://security.paloaltonetworks.com/CVE-2025-0131" + }, + { + "type": "WEB", + "url": "https://www.opswat.com/docs/mdsdk/release-notes/cve-2025-0131" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-79vg-2g4j-h2vr/GHSA-79vg-2g4j-h2vr.json b/advisories/unreviewed/2025/05/GHSA-79vg-2g4j-h2vr/GHSA-79vg-2g4j-h2vr.json new file mode 100644 index 00000000000..b991a9114f4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-79vg-2g4j-h2vr/GHSA-79vg-2g4j-h2vr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79vg-2g4j-h2vr", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-8619" + ], + "details": "The Ajax Search Lite WordPress plugin before 4.12.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8619" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/84f6733e-028a-4288-b01a-7578a4a89dbe" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7f2q-g84r-xq9f/GHSA-7f2q-g84r-xq9f.json b/advisories/unreviewed/2025/05/GHSA-7f2q-g84r-xq9f/GHSA-7f2q-g84r-xq9f.json new file mode 100644 index 00000000000..da786aa77a3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7f2q-g84r-xq9f/GHSA-7f2q-g84r-xq9f.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f2q-g84r-xq9f", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2023-7174" + ], + "details": "The aBitGone CommentSafe WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7174" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/9c1c6d61-5588-4c21-95f6-2818c4f5c355" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7fp8-7q2p-mmxm/GHSA-7fp8-7q2p-mmxm.json b/advisories/unreviewed/2025/05/GHSA-7fp8-7q2p-mmxm/GHSA-7fp8-7q2p-mmxm.json new file mode 100644 index 00000000000..21077c4f681 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7fp8-7q2p-mmxm/GHSA-7fp8-7q2p-mmxm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fp8-7q2p-mmxm", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-3996" + ], + "details": "The Smart Post Show WordPress plugin before 2.4.28 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3996" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/4035e3f9-89fe-49e1-8aa2-55ab3f1aa528" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7fvh-65xr-g9fx/GHSA-7fvh-65xr-g9fx.json b/advisories/unreviewed/2025/05/GHSA-7fvh-65xr-g9fx/GHSA-7fvh-65xr-g9fx.json new file mode 100644 index 00000000000..d7280bf8f89 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7fvh-65xr-g9fx/GHSA-7fvh-65xr-g9fx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fvh-65xr-g9fx", + "modified": "2025-05-15T21:31:34Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2025-0687" + ], + "details": "The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0687" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/3c1e21e1-32f2-4a20-9262-80e1cdab534d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7gvw-8492-45cx/GHSA-7gvw-8492-45cx.json b/advisories/unreviewed/2025/05/GHSA-7gvw-8492-45cx/GHSA-7gvw-8492-45cx.json new file mode 100644 index 00000000000..d981c28de8a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7gvw-8492-45cx/GHSA-7gvw-8492-45cx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gvw-8492-45cx", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-11189" + ], + "details": "The Social Share And Social Locker WordPress plugin before 1.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11189" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/f3d1473a-6d25-447d-af27-f315323fdd62" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7h9p-m872-c67m/GHSA-7h9p-m872-c67m.json b/advisories/unreviewed/2025/05/GHSA-7h9p-m872-c67m/GHSA-7h9p-m872-c67m.json new file mode 100644 index 00000000000..9620ff23bf6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7h9p-m872-c67m/GHSA-7h9p-m872-c67m.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7h9p-m872-c67m", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-11269" + ], + "details": "The AHAthat Plugin WordPress plugin through 1.6 does not sanitize and escape a parameter before using it in a SQL statement, allowing Admin to perform SQL injection attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11269" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/3ad89687-adb0-4c45-938c-0c18fda7f36f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7pq2-p2r6-3h8r/GHSA-7pq2-p2r6-3h8r.json b/advisories/unreviewed/2025/05/GHSA-7pq2-p2r6-3h8r/GHSA-7pq2-p2r6-3h8r.json new file mode 100644 index 00000000000..a21243b94aa --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7pq2-p2r6-3h8r/GHSA-7pq2-p2r6-3h8r.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pq2-p2r6-3h8r", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-9238" + ], + "details": "The AVIF Uploader WordPress plugin before 1.1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9238" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/a7de0cf6-3064-4595-9037-f8407fe40724" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7rv8-qgm5-32cr/GHSA-7rv8-qgm5-32cr.json b/advisories/unreviewed/2025/05/GHSA-7rv8-qgm5-32cr/GHSA-7rv8-qgm5-32cr.json new file mode 100644 index 00000000000..5cab2883746 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7rv8-qgm5-32cr/GHSA-7rv8-qgm5-32cr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rv8-qgm5-32cr", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2023-7297" + ], + "details": "The TwitterPosts WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7297" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/3632dfa1-2948-4622-a8fd-31edb8b22383" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7vrj-wjmg-rqm2/GHSA-7vrj-wjmg-rqm2.json b/advisories/unreviewed/2025/05/GHSA-7vrj-wjmg-rqm2/GHSA-7vrj-wjmg-rqm2.json new file mode 100644 index 00000000000..33d8974d0ae --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7vrj-wjmg-rqm2/GHSA-7vrj-wjmg-rqm2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vrj-wjmg-rqm2", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-7761" + ], + "details": "In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7761" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/ae8c1c91-3574-4da5-b5dc-d4e3feccac7e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7wxh-2hv2-977q/GHSA-7wxh-2hv2-977q.json b/advisories/unreviewed/2025/05/GHSA-7wxh-2hv2-977q/GHSA-7wxh-2hv2-977q.json new file mode 100644 index 00000000000..2654e685704 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7wxh-2hv2-977q/GHSA-7wxh-2hv2-977q.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wxh-2hv2-977q", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-13616" + ], + "details": "The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13616" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/44b3a2d9-a2e1-43dd-b27a-1ad9d6015c9b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7x4v-3vr9-6h78/GHSA-7x4v-3vr9-6h78.json b/advisories/unreviewed/2025/05/GHSA-7x4v-3vr9-6h78/GHSA-7x4v-3vr9-6h78.json new file mode 100644 index 00000000000..98577beeee3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7x4v-3vr9-6h78/GHSA-7x4v-3vr9-6h78.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x4v-3vr9-6h78", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-12739" + ], + "details": "The Mobile Contact Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12739" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/5492f1b2-481b-472a-82d3-949f85c8dc70" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-857x-55vg-m6q9/GHSA-857x-55vg-m6q9.json b/advisories/unreviewed/2025/05/GHSA-857x-55vg-m6q9/GHSA-857x-55vg-m6q9.json new file mode 100644 index 00000000000..24ca5168609 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-857x-55vg-m6q9/GHSA-857x-55vg-m6q9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-857x-55vg-m6q9", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-9599" + ], + "details": "The Popup Box WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9599" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/9e8a2659-7a6c-4528-b0b2-64d462485b43" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-85gf-c2vf-vgjh/GHSA-85gf-c2vf-vgjh.json b/advisories/unreviewed/2025/05/GHSA-85gf-c2vf-vgjh/GHSA-85gf-c2vf-vgjh.json new file mode 100644 index 00000000000..74e0e06deda --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-85gf-c2vf-vgjh/GHSA-85gf-c2vf-vgjh.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85gf-c2vf-vgjh", + "modified": "2025-05-15T21:31:26Z", + "published": "2025-05-15T21:31:26Z", + "aliases": [ + "CVE-2025-4714" + ], + "details": "A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is an unknown function of the file /pages/reprint.php. The manipulation of the argument sid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4714" + }, + { + "type": "WEB", + "url": "https://github.com/lanxia0/CVE/issues/8" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309012" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309012" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.568294" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T19:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-86pc-jx85-mvrw/GHSA-86pc-jx85-mvrw.json b/advisories/unreviewed/2025/05/GHSA-86pc-jx85-mvrw/GHSA-86pc-jx85-mvrw.json index 17de2880383..135fbdebf07 100644 --- a/advisories/unreviewed/2025/05/GHSA-86pc-jx85-mvrw/GHSA-86pc-jx85-mvrw.json +++ b/advisories/unreviewed/2025/05/GHSA-86pc-jx85-mvrw/GHSA-86pc-jx85-mvrw.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-86pc-jx85-mvrw", - "modified": "2025-05-13T21:30:53Z", + "modified": "2025-05-15T21:31:25Z", "published": "2025-05-13T18:30:58Z", "aliases": [ "CVE-2025-4660" ], "details": "A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access controls on a named pipe. The pipe is accessible to the Everyone group and does not restrict remote connections, allowing any network-based attacker to connect without authentication. By interacting with this pipe, an attacker can redirect the agent to communicate with a rogue server that can issue commands via the SecureConnector Agent. \n\n\n\nThis does not impact Linux or OSX Secure Connector.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Amber" diff --git a/advisories/unreviewed/2025/05/GHSA-8739-hw43-vjmr/GHSA-8739-hw43-vjmr.json b/advisories/unreviewed/2025/05/GHSA-8739-hw43-vjmr/GHSA-8739-hw43-vjmr.json new file mode 100644 index 00000000000..702ac8a3e99 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8739-hw43-vjmr/GHSA-8739-hw43-vjmr.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8739-hw43-vjmr", + "modified": "2025-05-15T21:31:35Z", + "published": "2025-05-15T21:31:35Z", + "aliases": [ + "CVE-2025-4716" + ], + "details": "A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /pages/credit_transaction_add.php. The manipulation of the argument prod_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4716" + }, + { + "type": "WEB", + "url": "https://github.com/lanxia0/CVE/issues/10" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309014" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309014" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.568296" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-874p-6rxv-4ppg/GHSA-874p-6rxv-4ppg.json b/advisories/unreviewed/2025/05/GHSA-874p-6rxv-4ppg/GHSA-874p-6rxv-4ppg.json new file mode 100644 index 00000000000..1a285adb05e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-874p-6rxv-4ppg/GHSA-874p-6rxv-4ppg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-874p-6rxv-4ppg", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-11141" + ], + "details": "The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings and is missing CSRF protection which could allow subscribers to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11141" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/6fe3544b-fb86-43e4-9771-6e9343f9f835" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-89wf-mr2w-22xh/GHSA-89wf-mr2w-22xh.json b/advisories/unreviewed/2025/05/GHSA-89wf-mr2w-22xh/GHSA-89wf-mr2w-22xh.json new file mode 100644 index 00000000000..95475a2cde6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-89wf-mr2w-22xh/GHSA-89wf-mr2w-22xh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89wf-mr2w-22xh", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-13486" + ], + "details": "The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13486" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/cbba8346-41f6-46ee-89ae-ed9524d768ef" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8frx-qqhf-j382/GHSA-8frx-qqhf-j382.json b/advisories/unreviewed/2025/05/GHSA-8frx-qqhf-j382/GHSA-8frx-qqhf-j382.json new file mode 100644 index 00000000000..93902d5d690 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8frx-qqhf-j382/GHSA-8frx-qqhf-j382.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8frx-qqhf-j382", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:26Z", + "aliases": [ + "CVE-2025-4713" + ], + "details": "A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. This issue affects some unknown processing of the file /pages/print.php. The manipulation of the argument sid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4713" + }, + { + "type": "WEB", + "url": "https://github.com/lanxia0/CVE/issues/7" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309011" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309011" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.568293" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T19:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8jcq-cgc3-57jm/GHSA-8jcq-cgc3-57jm.json b/advisories/unreviewed/2025/05/GHSA-8jcq-cgc3-57jm/GHSA-8jcq-cgc3-57jm.json new file mode 100644 index 00000000000..32174c5644e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8jcq-cgc3-57jm/GHSA-8jcq-cgc3-57jm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jcq-cgc3-57jm", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-12734" + ], + "details": "The Advance Post Prefix WordPress plugin through 1.1.1, Advance Post Prefix WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12734" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/038b44dc-0495-4f56-ae7e-c78a265aa535" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8rgg-p4jx-9xw2/GHSA-8rgg-p4jx-9xw2.json b/advisories/unreviewed/2025/05/GHSA-8rgg-p4jx-9xw2/GHSA-8rgg-p4jx-9xw2.json new file mode 100644 index 00000000000..47687cfa786 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8rgg-p4jx-9xw2/GHSA-8rgg-p4jx-9xw2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rgg-p4jx-9xw2", + "modified": "2025-05-15T21:31:34Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2024-9879" + ], + "details": "The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9879" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/cda54097-4aec-472e-a73f-31ecb76ebb23" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8rhc-9wf9-c4f6/GHSA-8rhc-9wf9-c4f6.json b/advisories/unreviewed/2025/05/GHSA-8rhc-9wf9-c4f6/GHSA-8rhc-9wf9-c4f6.json new file mode 100644 index 00000000000..83736dc034e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8rhc-9wf9-c4f6/GHSA-8rhc-9wf9-c4f6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rhc-9wf9-c4f6", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:31Z", + "aliases": [ + "CVE-2024-6718" + ], + "details": "The PVN Auth Popup WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6718" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/7d28ea72-8c3b-4607-b877-7b10d954fef9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8wg7-qxc6-838c/GHSA-8wg7-qxc6-838c.json b/advisories/unreviewed/2025/05/GHSA-8wg7-qxc6-838c/GHSA-8wg7-qxc6-838c.json new file mode 100644 index 00000000000..3209f926bc4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8wg7-qxc6-838c/GHSA-8wg7-qxc6-838c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wg7-qxc6-838c", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-10107" + ], + "details": "The Giveaways and Contests by RafflePress WordPress plugin before 1.12.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10107" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/83590cad-6bfb-4dc7-b8fd-aecbc66f3c33" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8xj4-6h2f-28vg/GHSA-8xj4-6h2f-28vg.json b/advisories/unreviewed/2025/05/GHSA-8xj4-6h2f-28vg/GHSA-8xj4-6h2f-28vg.json new file mode 100644 index 00000000000..833efe75956 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8xj4-6h2f-28vg/GHSA-8xj4-6h2f-28vg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xj4-6h2f-28vg", + "modified": "2025-05-15T21:31:34Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2025-2203" + ], + "details": "The FunnelKit WordPress plugin before 3.10.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2203" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d553cff4-074a-44e7-aebe-e61c86ab8042" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8xqm-w2cq-fmc6/GHSA-8xqm-w2cq-fmc6.json b/advisories/unreviewed/2025/05/GHSA-8xqm-w2cq-fmc6/GHSA-8xqm-w2cq-fmc6.json new file mode 100644 index 00000000000..84c207e7cc2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8xqm-w2cq-fmc6/GHSA-8xqm-w2cq-fmc6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xqm-w2cq-fmc6", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-9233" + ], + "details": "The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9233" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/a466cea4-0ae5-44a1-9e12-bd5dbecde2f2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-928r-3p4g-rrxw/GHSA-928r-3p4g-rrxw.json b/advisories/unreviewed/2025/05/GHSA-928r-3p4g-rrxw/GHSA-928r-3p4g-rrxw.json new file mode 100644 index 00000000000..bc4e1e4a9b0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-928r-3p4g-rrxw/GHSA-928r-3p4g-rrxw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-928r-3p4g-rrxw", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2023-7239" + ], + "details": "The WP Dashboard Notes WordPress plugin before 1.0.11 does not validate that the user has access to the post_id parameter in its wpdn_update_note AJAX action. This allows users with a role of contributor and above to update notes created by other users.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7239" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/6e6afe50-27f9-41fa-a94b-f44df0850e2c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-93mr-fwrq-w2xg/GHSA-93mr-fwrq-w2xg.json b/advisories/unreviewed/2025/05/GHSA-93mr-fwrq-w2xg/GHSA-93mr-fwrq-w2xg.json new file mode 100644 index 00000000000..1629fb8eee2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-93mr-fwrq-w2xg/GHSA-93mr-fwrq-w2xg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93mr-fwrq-w2xg", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-6809" + ], + "details": "The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6809" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/60abcae5-4c89-4d48-95f8-6a80e5f06a37" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-942h-7wq8-4623/GHSA-942h-7wq8-4623.json b/advisories/unreviewed/2025/05/GHSA-942h-7wq8-4623/GHSA-942h-7wq8-4623.json new file mode 100644 index 00000000000..6326125a766 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-942h-7wq8-4623/GHSA-942h-7wq8-4623.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-942h-7wq8-4623", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2023-7196" + ], + "details": "The Ultimate Noindex Nofollow Tool WordPress plugin through 1.1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7196" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/15ea1ffd-5a0c-422c-8c9c-7b632516a156" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9495-7c48-4348/GHSA-9495-7c48-4348.json b/advisories/unreviewed/2025/05/GHSA-9495-7c48-4348/GHSA-9495-7c48-4348.json new file mode 100644 index 00000000000..3326f701c44 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9495-7c48-4348/GHSA-9495-7c48-4348.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9495-7c48-4348", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-12732" + ], + "details": "The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12732" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/bc46edd8-8d77-4567-873b-e9e90a01adcf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-94c7-f7jq-xgj6/GHSA-94c7-f7jq-xgj6.json b/advisories/unreviewed/2025/05/GHSA-94c7-f7jq-xgj6/GHSA-94c7-f7jq-xgj6.json new file mode 100644 index 00000000000..77b14c76eec --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-94c7-f7jq-xgj6/GHSA-94c7-f7jq-xgj6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94c7-f7jq-xgj6", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-13128" + ], + "details": "The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13128" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/1506a339-f85a-408a-8efa-ca83eb3b3ffb" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-96h4-8m29-phmf/GHSA-96h4-8m29-phmf.json b/advisories/unreviewed/2025/05/GHSA-96h4-8m29-phmf/GHSA-96h4-8m29-phmf.json new file mode 100644 index 00000000000..2fdf398f658 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-96h4-8m29-phmf/GHSA-96h4-8m29-phmf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96h4-8m29-phmf", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-11266" + ], + "details": "The Geocache Stat Bar Widget WordPress plugin through 0.911 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11266" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/361a4635-7e7d-483c-b2ce-a857d60d91ea" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-98qf-h3c2-3wwr/GHSA-98qf-h3c2-3wwr.json b/advisories/unreviewed/2025/05/GHSA-98qf-h3c2-3wwr/GHSA-98qf-h3c2-3wwr.json new file mode 100644 index 00000000000..8746d5c3408 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-98qf-h3c2-3wwr/GHSA-98qf-h3c2-3wwr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98qf-h3c2-3wwr", + "modified": "2025-05-15T21:31:34Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2025-0329" + ], + "details": "The AI ChatBot for WordPress WordPress plugin before 6.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0329" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/db101819-4404-46c9-a02e-b1b1b7ace11e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9fcp-xcwr-cjm9/GHSA-9fcp-xcwr-cjm9.json b/advisories/unreviewed/2025/05/GHSA-9fcp-xcwr-cjm9/GHSA-9fcp-xcwr-cjm9.json new file mode 100644 index 00000000000..f1153a5c8c9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9fcp-xcwr-cjm9/GHSA-9fcp-xcwr-cjm9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fcp-xcwr-cjm9", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-12743" + ], + "details": "The MailPoet WordPress plugin before 5.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12743" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/7945f52d-364d-438c-84f2-cf19b4250056" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9g8q-q3hj-343m/GHSA-9g8q-q3hj-343m.json b/advisories/unreviewed/2025/05/GHSA-9g8q-q3hj-343m/GHSA-9g8q-q3hj-343m.json new file mode 100644 index 00000000000..9f9e5727c74 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9g8q-q3hj-343m/GHSA-9g8q-q3hj-343m.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g8q-q3hj-343m", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:31Z", + "aliases": [ + "CVE-2024-6462" + ], + "details": "The DL Yandex Metrika WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6462" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/0880fa33-3efa-4f50-83c8-4c90cb805eb9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9m4x-m322-8xcp/GHSA-9m4x-m322-8xcp.json b/advisories/unreviewed/2025/05/GHSA-9m4x-m322-8xcp/GHSA-9m4x-m322-8xcp.json new file mode 100644 index 00000000000..671d6130cae --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9m4x-m322-8xcp/GHSA-9m4x-m322-8xcp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m4x-m322-8xcp", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-7759" + ], + "details": "The PWA for WP WordPress plugin before 1.7.72 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7759" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/6e495b39-f9ef-45dd-b839-65c71a082f2b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9mpf-r669-m5wq/GHSA-9mpf-r669-m5wq.json b/advisories/unreviewed/2025/05/GHSA-9mpf-r669-m5wq/GHSA-9mpf-r669-m5wq.json new file mode 100644 index 00000000000..a7f5e5a696c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9mpf-r669-m5wq/GHSA-9mpf-r669-m5wq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mpf-r669-m5wq", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-8617" + ], + "details": "The Quiz Maker WordPress plugin before 6.5.9.9 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8617" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/ba6b6b82-6f21-45ff-bd64-685ea8ae1b82" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9phg-gg4w-6m7h/GHSA-9phg-gg4w-6m7h.json b/advisories/unreviewed/2025/05/GHSA-9phg-gg4w-6m7h/GHSA-9phg-gg4w-6m7h.json new file mode 100644 index 00000000000..cfda7d7d32a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9phg-gg4w-6m7h/GHSA-9phg-gg4w-6m7h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9phg-gg4w-6m7h", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2023-6783" + ], + "details": "The WolfNet IDX for WordPress plugin through 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6783" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/5acd231b-4072-4ee1-9497-023465318608" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c44h-wf4g-24fr/GHSA-c44h-wf4g-24fr.json b/advisories/unreviewed/2025/05/GHSA-c44h-wf4g-24fr/GHSA-c44h-wf4g-24fr.json new file mode 100644 index 00000000000..0a6e84cdaf0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c44h-wf4g-24fr/GHSA-c44h-wf4g-24fr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c44h-wf4g-24fr", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2023-7231" + ], + "details": "The illi Link Party! WordPress plugin through 1.0 lacks proper access controls, allowing unauthenticated visitors to delete links.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7231" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/797692ce-f355-4d4a-af01-4bd9abc60a34" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c6wh-53mq-4gr9/GHSA-c6wh-53mq-4gr9.json b/advisories/unreviewed/2025/05/GHSA-c6wh-53mq-4gr9/GHSA-c6wh-53mq-4gr9.json new file mode 100644 index 00000000000..023698d6642 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c6wh-53mq-4gr9/GHSA-c6wh-53mq-4gr9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6wh-53mq-4gr9", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-12767" + ], + "details": "The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view comments on private posts", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12767" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/e8997f90-d8e9-4815-8808-aa0183443dae" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c73f-vp33-fj4h/GHSA-c73f-vp33-fj4h.json b/advisories/unreviewed/2025/05/GHSA-c73f-vp33-fj4h/GHSA-c73f-vp33-fj4h.json new file mode 100644 index 00000000000..7df03201d40 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c73f-vp33-fj4h/GHSA-c73f-vp33-fj4h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c73f-vp33-fj4h", + "modified": "2025-05-15T21:31:34Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2024-9663" + ], + "details": "The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9663" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/0dbd0927-f245-4202-b96b-e55f36a8bb30" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c8hj-rjcv-xx48/GHSA-c8hj-rjcv-xx48.json b/advisories/unreviewed/2025/05/GHSA-c8hj-rjcv-xx48/GHSA-c8hj-rjcv-xx48.json new file mode 100644 index 00000000000..1162bb81f4d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c8hj-rjcv-xx48/GHSA-c8hj-rjcv-xx48.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8hj-rjcv-xx48", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-7769" + ], + "details": "The ClickSold IDX WordPress plugin through 1.90 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7769" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/198252c2-834b-401b-98a5-2f59910d67bc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c9v2-rqm3-3g5r/GHSA-c9v2-rqm3-3g5r.json b/advisories/unreviewed/2025/05/GHSA-c9v2-rqm3-3g5r/GHSA-c9v2-rqm3-3g5r.json new file mode 100644 index 00000000000..dffa3842d11 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c9v2-rqm3-3g5r/GHSA-c9v2-rqm3-3g5r.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9v2-rqm3-3g5r", + "modified": "2025-05-15T21:31:26Z", + "published": "2025-05-15T21:31:26Z", + "aliases": [ + "CVE-2023-5932" + ], + "details": "The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5932" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/16fbca64-cc35-455e-bfef-d1f28857f991" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ccp4-cg9p-v3f5/GHSA-ccp4-cg9p-v3f5.json b/advisories/unreviewed/2025/05/GHSA-ccp4-cg9p-v3f5/GHSA-ccp4-cg9p-v3f5.json new file mode 100644 index 00000000000..813596c0d8f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-ccp4-cg9p-v3f5/GHSA-ccp4-cg9p-v3f5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccp4-cg9p-v3f5", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-8851" + ], + "details": "The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8851" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/493f3360-3155-4105-9b5c-60a8605275ab" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cg9w-78cc-f78x/GHSA-cg9w-78cc-f78x.json b/advisories/unreviewed/2025/05/GHSA-cg9w-78cc-f78x/GHSA-cg9w-78cc-f78x.json new file mode 100644 index 00000000000..5a4043c3a17 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cg9w-78cc-f78x/GHSA-cg9w-78cc-f78x.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg9w-78cc-f78x", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-10075" + ], + "details": "The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authorised users, which could allow unauthenticated users to run arbitrary shortcodes and block.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10075" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/a984976c-291a-4f68-90d4-e452605ea7d1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-chgf-rv7c-3x2f/GHSA-chgf-rv7c-3x2f.json b/advisories/unreviewed/2025/05/GHSA-chgf-rv7c-3x2f/GHSA-chgf-rv7c-3x2f.json new file mode 100644 index 00000000000..b4abd8a6f2f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-chgf-rv7c-3x2f/GHSA-chgf-rv7c-3x2f.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chgf-rv7c-3x2f", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:31Z", + "aliases": [ + "CVE-2024-6711" + ], + "details": "The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6711" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/bf431b81-2db9-4fcb-841c-9b51d1870bf8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-chqc-5pg2-gc95/GHSA-chqc-5pg2-gc95.json b/advisories/unreviewed/2025/05/GHSA-chqc-5pg2-gc95/GHSA-chqc-5pg2-gc95.json new file mode 100644 index 00000000000..e832123f3f7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-chqc-5pg2-gc95/GHSA-chqc-5pg2-gc95.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chqc-5pg2-gc95", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:31Z", + "aliases": [ + "CVE-2024-6712" + ], + "details": "The MapFig Studio WordPress plugin through 0.2.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6712" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/0346b62c-a856-4554-a24a-ef2c2943bda9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cqqm-8g3r-4grm/GHSA-cqqm-8g3r-4grm.json b/advisories/unreviewed/2025/05/GHSA-cqqm-8g3r-4grm/GHSA-cqqm-8g3r-4grm.json new file mode 100644 index 00000000000..79e87cccea2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cqqm-8g3r-4grm/GHSA-cqqm-8g3r-4grm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqqm-8g3r-4grm", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-10634" + ], + "details": "The Nokaut Offers Box WordPress plugin through 1.4.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin reset the Nokaut Offers Box WordPress plugin through 1.4.0 via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10634" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/97de2ca3-ee64-480b-a5b0-7549533c2936" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cqw5-7mc9-48hp/GHSA-cqw5-7mc9-48hp.json b/advisories/unreviewed/2025/05/GHSA-cqw5-7mc9-48hp/GHSA-cqw5-7mc9-48hp.json new file mode 100644 index 00000000000..676db9fee1c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cqw5-7mc9-48hp/GHSA-cqw5-7mc9-48hp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqw5-7mc9-48hp", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-13384" + ], + "details": "The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.24 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13384" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/f65d8a83-6ce8-40be-8633-deffd555c349" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cvpp-rmjx-5x2m/GHSA-cvpp-rmjx-5x2m.json b/advisories/unreviewed/2025/05/GHSA-cvpp-rmjx-5x2m/GHSA-cvpp-rmjx-5x2m.json index 652ffea7f2d..2646930c5e8 100644 --- a/advisories/unreviewed/2025/05/GHSA-cvpp-rmjx-5x2m/GHSA-cvpp-rmjx-5x2m.json +++ b/advisories/unreviewed/2025/05/GHSA-cvpp-rmjx-5x2m/GHSA-cvpp-rmjx-5x2m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cvpp-rmjx-5x2m", - "modified": "2025-05-14T00:32:21Z", + "modified": "2025-05-15T21:31:26Z", "published": "2025-05-14T00:32:21Z", "aliases": [ "CVE-2025-47905" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://varnish-cache.org/security/VSV00016.html" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/15/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-f2vf-33g3-fwm2/GHSA-f2vf-33g3-fwm2.json b/advisories/unreviewed/2025/05/GHSA-f2vf-33g3-fwm2/GHSA-f2vf-33g3-fwm2.json new file mode 100644 index 00000000000..d9eaeeee878 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f2vf-33g3-fwm2/GHSA-f2vf-33g3-fwm2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2vf-33g3-fwm2", + "modified": "2025-05-15T21:31:34Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2024-9882" + ], + "details": "The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9882" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/7f7667fd-6ac6-4c90-aaf0-c7862bd8e9bd" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f5ww-x9w7-q9v2/GHSA-f5ww-x9w7-q9v2.json b/advisories/unreviewed/2025/05/GHSA-f5ww-x9w7-q9v2/GHSA-f5ww-x9w7-q9v2.json new file mode 100644 index 00000000000..40e905bd75f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f5ww-x9w7-q9v2/GHSA-f5ww-x9w7-q9v2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5ww-x9w7-q9v2", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-5026" + ], + "details": "The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5026" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/a86584f6-119b-45c3-bc6e-dc18e3501db7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f87f-4wg8-gxhp/GHSA-f87f-4wg8-gxhp.json b/advisories/unreviewed/2025/05/GHSA-f87f-4wg8-gxhp/GHSA-f87f-4wg8-gxhp.json new file mode 100644 index 00000000000..4f0bdaed9f2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f87f-4wg8-gxhp/GHSA-f87f-4wg8-gxhp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f87f-4wg8-gxhp", + "modified": "2025-05-15T21:31:34Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2025-1289" + ], + "details": "The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1289" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/5a296b59-f305-49a2-88b8-fca998f2c43e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f8vr-vg6x-hfpr/GHSA-f8vr-vg6x-hfpr.json b/advisories/unreviewed/2025/05/GHSA-f8vr-vg6x-hfpr/GHSA-f8vr-vg6x-hfpr.json new file mode 100644 index 00000000000..f0fc8a35d26 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f8vr-vg6x-hfpr/GHSA-f8vr-vg6x-hfpr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8vr-vg6x-hfpr", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:31Z", + "aliases": [ + "CVE-2024-3062" + ], + "details": "The Save as Image Plugin by Pdfcrowd WordPress plugin before 3.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3062" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/1526985d-2f8f-4b2a-97f3-633c51d024b8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ffvf-jcq5-f366/GHSA-ffvf-jcq5-f366.json b/advisories/unreviewed/2025/05/GHSA-ffvf-jcq5-f366/GHSA-ffvf-jcq5-f366.json new file mode 100644 index 00000000000..3a92fc6fc0a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-ffvf-jcq5-f366/GHSA-ffvf-jcq5-f366.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffvf-jcq5-f366", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-4004" + ], + "details": "The Advanced Cron Manager WordPress plugin before 2.5.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4004" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/8e5e7040-b824-4af7-90a1-90801d12abb6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fg67-vp54-v2cw/GHSA-fg67-vp54-v2cw.json b/advisories/unreviewed/2025/05/GHSA-fg67-vp54-v2cw/GHSA-fg67-vp54-v2cw.json new file mode 100644 index 00000000000..12510ffd533 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fg67-vp54-v2cw/GHSA-fg67-vp54-v2cw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg67-vp54-v2cw", + "modified": "2025-05-15T21:31:26Z", + "published": "2025-05-15T21:31:26Z", + "aliases": [ + "CVE-2024-51666" + ], + "details": "Missing Authorization vulnerability in Automattic Tours.This issue affects Tours: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51666" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tours/vulnerability/wordpress-tours-plugin-1-0-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T19:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fpq7-6mfr-4vvq/GHSA-fpq7-6mfr-4vvq.json b/advisories/unreviewed/2025/05/GHSA-fpq7-6mfr-4vvq/GHSA-fpq7-6mfr-4vvq.json new file mode 100644 index 00000000000..e7c4920257c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fpq7-6mfr-4vvq/GHSA-fpq7-6mfr-4vvq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpq7-6mfr-4vvq", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-8245" + ], + "details": "The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8245" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/3fb6292c-502c-481a-8223-ecda03d4c3fe" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fq7q-wgm6-7rqj/GHSA-fq7q-wgm6-7rqj.json b/advisories/unreviewed/2025/05/GHSA-fq7q-wgm6-7rqj/GHSA-fq7q-wgm6-7rqj.json new file mode 100644 index 00000000000..eb120bc661b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fq7q-wgm6-7rqj/GHSA-fq7q-wgm6-7rqj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq7q-wgm6-7rqj", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-12808" + ], + "details": "The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12808" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/f1f823f5-d0f1-45a5-85c2-60208d76366e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fxpc-qmrh-7j2h/GHSA-fxpc-qmrh-7j2h.json b/advisories/unreviewed/2025/05/GHSA-fxpc-qmrh-7j2h/GHSA-fxpc-qmrh-7j2h.json new file mode 100644 index 00000000000..a9ea93b04b4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fxpc-qmrh-7j2h/GHSA-fxpc-qmrh-7j2h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxpc-qmrh-7j2h", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-11718" + ], + "details": "The tarteaucitron-wp WordPress plugin before 0.3.0 allows author level and above users to add HTML into a post/page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11718" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/02da3a49-20e4-4476-a78d-4c627994a90a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g453-c6fq-7fg3/GHSA-g453-c6fq-7fg3.json b/advisories/unreviewed/2025/05/GHSA-g453-c6fq-7fg3/GHSA-g453-c6fq-7fg3.json new file mode 100644 index 00000000000..b9d2b489fab --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g453-c6fq-7fg3/GHSA-g453-c6fq-7fg3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g453-c6fq-7fg3", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-12726" + ], + "details": "The ClipArt WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12726" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/88d748fc-6c2f-4656-99c5-c00cbed9d7e0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gc6c-44mm-v3cj/GHSA-gc6c-44mm-v3cj.json b/advisories/unreviewed/2025/05/GHSA-gc6c-44mm-v3cj/GHSA-gc6c-44mm-v3cj.json index 30d459dd6a5..15a752c4abb 100644 --- a/advisories/unreviewed/2025/05/GHSA-gc6c-44mm-v3cj/GHSA-gc6c-44mm-v3cj.json +++ b/advisories/unreviewed/2025/05/GHSA-gc6c-44mm-v3cj/GHSA-gc6c-44mm-v3cj.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-gh3q-hh33-59w3/GHSA-gh3q-hh33-59w3.json b/advisories/unreviewed/2025/05/GHSA-gh3q-hh33-59w3/GHSA-gh3q-hh33-59w3.json new file mode 100644 index 00000000000..ee9cc6dd986 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gh3q-hh33-59w3/GHSA-gh3q-hh33-59w3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh3q-hh33-59w3", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-8492" + ], + "details": "The Hustle WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8492" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c7437eba-8e91-4fcc-82a3-ff8908b36877" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gmhj-76hp-7wh3/GHSA-gmhj-76hp-7wh3.json b/advisories/unreviewed/2025/05/GHSA-gmhj-76hp-7wh3/GHSA-gmhj-76hp-7wh3.json new file mode 100644 index 00000000000..96369e80060 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gmhj-76hp-7wh3/GHSA-gmhj-76hp-7wh3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmhj-76hp-7wh3", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:31Z", + "aliases": [ + "CVE-2024-6584" + ], + "details": "The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6584" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/eaa57c8c-1cac-4903-9763-79f7f84469fa" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gprh-m7xv-mqpj/GHSA-gprh-m7xv-mqpj.json b/advisories/unreviewed/2025/05/GHSA-gprh-m7xv-mqpj/GHSA-gprh-m7xv-mqpj.json new file mode 100644 index 00000000000..509905709b4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gprh-m7xv-mqpj/GHSA-gprh-m7xv-mqpj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gprh-m7xv-mqpj", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-13621" + ], + "details": "The GDPR Framework By Data443 WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13621" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/5b48ecbb-c459-4c39-825d-61744d36f2fe" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gpv2-32pf-74f2/GHSA-gpv2-32pf-74f2.json b/advisories/unreviewed/2025/05/GHSA-gpv2-32pf-74f2/GHSA-gpv2-32pf-74f2.json new file mode 100644 index 00000000000..b42250f6929 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gpv2-32pf-74f2/GHSA-gpv2-32pf-74f2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpv2-32pf-74f2", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:31Z", + "aliases": [ + "CVE-2024-4002" + ], + "details": "The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.6.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4002" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/298b51ec-afad-4bc1-968d-76c59e55fc05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gvfm-39fx-4qm6/GHSA-gvfm-39fx-4qm6.json b/advisories/unreviewed/2025/05/GHSA-gvfm-39fx-4qm6/GHSA-gvfm-39fx-4qm6.json new file mode 100644 index 00000000000..65ee4723ba2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gvfm-39fx-4qm6/GHSA-gvfm-39fx-4qm6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvfm-39fx-4qm6", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-11109" + ], + "details": "The WP Google Review Slider WordPress plugin before 15.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11109" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/93619da1-a8d6-43b6-b1be-8d50ab6f29f7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gw62-7pm8-x49v/GHSA-gw62-7pm8-x49v.json b/advisories/unreviewed/2025/05/GHSA-gw62-7pm8-x49v/GHSA-gw62-7pm8-x49v.json new file mode 100644 index 00000000000..8148118fef1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gw62-7pm8-x49v/GHSA-gw62-7pm8-x49v.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gw62-7pm8-x49v", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-2643" + ], + "details": "The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.6.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2643" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/194ebf81-8fe4-4c74-8174-35d0ac00ac93" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gx24-fg4m-2f7m/GHSA-gx24-fg4m-2f7m.json b/advisories/unreviewed/2025/05/GHSA-gx24-fg4m-2f7m/GHSA-gx24-fg4m-2f7m.json new file mode 100644 index 00000000000..3e7b78e49d5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gx24-fg4m-2f7m/GHSA-gx24-fg4m-2f7m.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx24-fg4m-2f7m", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2024-0852" + ], + "details": "The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting it back in the admin dashboard, allowing unauthenticated users to perform Stored XSS attack against high privilege users such as admin", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0852" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/743c4d79-e1d5-4fb0-a17d-296df2c54e8a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h2f3-9263-mhpx/GHSA-h2f3-9263-mhpx.json b/advisories/unreviewed/2025/05/GHSA-h2f3-9263-mhpx/GHSA-h2f3-9263-mhpx.json new file mode 100644 index 00000000000..7e52c3a8613 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h2f3-9263-mhpx/GHSA-h2f3-9263-mhpx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2f3-9263-mhpx", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-13730" + ], + "details": "The Podlove Podcast Publisher WordPress plugin before 4.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13730" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/4541a285-a095-4178-a64b-6a859eb5034e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h58h-p5x5-v3wj/GHSA-h58h-p5x5-v3wj.json b/advisories/unreviewed/2025/05/GHSA-h58h-p5x5-v3wj/GHSA-h58h-p5x5-v3wj.json new file mode 100644 index 00000000000..141c1523eb3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h58h-p5x5-v3wj/GHSA-h58h-p5x5-v3wj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h58h-p5x5-v3wj", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2024-10098" + ], + "details": "The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10098" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/242dac1f-9a1f-4fde-b8c7-374bd451071d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h9vp-frfm-hwvq/GHSA-h9vp-frfm-hwvq.json b/advisories/unreviewed/2025/05/GHSA-h9vp-frfm-hwvq/GHSA-h9vp-frfm-hwvq.json new file mode 100644 index 00000000000..741fdb78709 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h9vp-frfm-hwvq/GHSA-h9vp-frfm-hwvq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9vp-frfm-hwvq", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-12750" + ], + "details": "The Competition Form WordPress plugin through 2.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12750" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/f3570bdc-659f-4a03-96f8-b4f9f045f910" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hc6j-5h8v-c5cg/GHSA-hc6j-5h8v-c5cg.json b/advisories/unreviewed/2025/05/GHSA-hc6j-5h8v-c5cg/GHSA-hc6j-5h8v-c5cg.json new file mode 100644 index 00000000000..8f3e6a554ca --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hc6j-5h8v-c5cg/GHSA-hc6j-5h8v-c5cg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc6j-5h8v-c5cg", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-10639" + ], + "details": "The Auto Prune Posts WordPress plugin before 3.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10639" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/efab3a36-535b-40ff-b98f-482a0e5193f1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hjxc-cj85-6rvh/GHSA-hjxc-cj85-6rvh.json b/advisories/unreviewed/2025/05/GHSA-hjxc-cj85-6rvh/GHSA-hjxc-cj85-6rvh.json new file mode 100644 index 00000000000..ffa35d40907 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hjxc-cj85-6rvh/GHSA-hjxc-cj85-6rvh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjxc-cj85-6rvh", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:31Z", + "aliases": [ + "CVE-2024-6719" + ], + "details": "The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users to update them via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6719" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/1dc7caac-a36e-4313-a8be-c6b13e564924" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hm4p-7q9f-fx6q/GHSA-hm4p-7q9f-fx6q.json b/advisories/unreviewed/2025/05/GHSA-hm4p-7q9f-fx6q/GHSA-hm4p-7q9f-fx6q.json index d04dbe7d2e7..ae96644cb0e 100644 --- a/advisories/unreviewed/2025/05/GHSA-hm4p-7q9f-fx6q/GHSA-hm4p-7q9f-fx6q.json +++ b/advisories/unreviewed/2025/05/GHSA-hm4p-7q9f-fx6q/GHSA-hm4p-7q9f-fx6q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hm4p-7q9f-fx6q", - "modified": "2025-05-15T15:31:26Z", + "modified": "2025-05-15T21:31:26Z", "published": "2025-05-15T15:31:26Z", "aliases": [ "CVE-2025-46052" ], "details": "An error-based SQL Injection (SQLi) vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL command and extract sensitive data by injecting a crafted payload into the DEL form field in a POST request to /StockCounts.php", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T14:15:30Z" diff --git a/advisories/unreviewed/2025/05/GHSA-hww8-3wf5-9mgj/GHSA-hww8-3wf5-9mgj.json b/advisories/unreviewed/2025/05/GHSA-hww8-3wf5-9mgj/GHSA-hww8-3wf5-9mgj.json new file mode 100644 index 00000000000..15ae8bc4d66 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hww8-3wf5-9mgj/GHSA-hww8-3wf5-9mgj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hww8-3wf5-9mgj", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-9236" + ], + "details": "The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9236" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/fd06ba56-37dd-4c23-ae7c-ab8de40d1645" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j25q-6375-5rxx/GHSA-j25q-6375-5rxx.json b/advisories/unreviewed/2025/05/GHSA-j25q-6375-5rxx/GHSA-j25q-6375-5rxx.json new file mode 100644 index 00000000000..2c8d61b0fea --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j25q-6375-5rxx/GHSA-j25q-6375-5rxx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j25q-6375-5rxx", + "modified": "2025-05-15T21:31:26Z", + "published": "2025-05-15T21:31:26Z", + "aliases": [ + "CVE-2025-32922" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Tobias WP2LEADS allows Stored XSS.This issue affects WP2LEADS: from n/a through 3.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32922" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp2leads/vulnerability/wordpress-wp2leads-plugin-3-5-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T19:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j2p9-f4vx-cp2g/GHSA-j2p9-f4vx-cp2g.json b/advisories/unreviewed/2025/05/GHSA-j2p9-f4vx-cp2g/GHSA-j2p9-f4vx-cp2g.json new file mode 100644 index 00000000000..8cf1c0cfc20 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j2p9-f4vx-cp2g/GHSA-j2p9-f4vx-cp2g.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2p9-f4vx-cp2g", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:31Z", + "aliases": [ + "CVE-2024-6486" + ], + "details": "The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the \"cli_path\" parameter. This allows authenticated attackers, with administrator-level permission to execute arbitrary OS commands on the server leading to remote code execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6486" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/a57c0c59-8b5c-4221-a9db-19f141650d9b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j3m2-jq2c-m776/GHSA-j3m2-jq2c-m776.json b/advisories/unreviewed/2025/05/GHSA-j3m2-jq2c-m776/GHSA-j3m2-jq2c-m776.json new file mode 100644 index 00000000000..1c942e791f7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j3m2-jq2c-m776/GHSA-j3m2-jq2c-m776.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3m2-jq2c-m776", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2023-7230" + ], + "details": "The illi Link Party! WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7230" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/402e428b-f966-4a36-ace0-d0ded9410b1d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j4jp-4rjc-6479/GHSA-j4jp-4rjc-6479.json b/advisories/unreviewed/2025/05/GHSA-j4jp-4rjc-6479/GHSA-j4jp-4rjc-6479.json new file mode 100644 index 00000000000..fe1e6adefa3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j4jp-4rjc-6479/GHSA-j4jp-4rjc-6479.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4jp-4rjc-6479", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:31Z", + "aliases": [ + "CVE-2024-6668" + ], + "details": "The ProfilePro WordPress plugin through 1.3 does not sanitise and escape some parameters and lacks proper access controls, which could allow users with a role as low as subscriber to perform Cross-Site Scripting attacks", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6668" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/8faf1409-44e6-4ebf-9a68-b5f93a5295e9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j4qf-29vf-7xcj/GHSA-j4qf-29vf-7xcj.json b/advisories/unreviewed/2025/05/GHSA-j4qf-29vf-7xcj/GHSA-j4qf-29vf-7xcj.json new file mode 100644 index 00000000000..b0451bb11b9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j4qf-29vf-7xcj/GHSA-j4qf-29vf-7xcj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4qf-29vf-7xcj", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-8397" + ], + "details": "The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Consent report' page and the malicious script is executed in the admin context.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8397" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/847fbf5d-f7cf-49fd-88bc-d7fa2a8110bd" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j54f-6g32-3jwj/GHSA-j54f-6g32-3jwj.json b/advisories/unreviewed/2025/05/GHSA-j54f-6g32-3jwj/GHSA-j54f-6g32-3jwj.json new file mode 100644 index 00000000000..658fdcffcd0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j54f-6g32-3jwj/GHSA-j54f-6g32-3jwj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j54f-6g32-3jwj", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-8703" + ], + "details": "The Z-Downloads WordPress plugin before 1.11.6 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks when accessing share URLs.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8703" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/604e990e-9bec-469e-8630-605eea74e12c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j7cm-jxq2-h8q5/GHSA-j7cm-jxq2-h8q5.json b/advisories/unreviewed/2025/05/GHSA-j7cm-jxq2-h8q5/GHSA-j7cm-jxq2-h8q5.json new file mode 100644 index 00000000000..626d734f633 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j7cm-jxq2-h8q5/GHSA-j7cm-jxq2-h8q5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7cm-jxq2-h8q5", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:31Z", + "aliases": [ + "CVE-2024-6713" + ], + "details": "The PVN Auth Popup WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6713" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/24685b19-0a44-411a-9e1b-d4d0627d7cb6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j7h5-wpgx-r8m9/GHSA-j7h5-wpgx-r8m9.json b/advisories/unreviewed/2025/05/GHSA-j7h5-wpgx-r8m9/GHSA-j7h5-wpgx-r8m9.json new file mode 100644 index 00000000000..e2a3fa9e732 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j7h5-wpgx-r8m9/GHSA-j7h5-wpgx-r8m9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7h5-wpgx-r8m9", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2023-6786" + ], + "details": "The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6786" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/f3e64947-3138-4ec4-86c4-27b5d6a5c9c2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j95r-8c72-m59j/GHSA-j95r-8c72-m59j.json b/advisories/unreviewed/2025/05/GHSA-j95r-8c72-m59j/GHSA-j95r-8c72-m59j.json new file mode 100644 index 00000000000..d8b88aa945d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j95r-8c72-m59j/GHSA-j95r-8c72-m59j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j95r-8c72-m59j", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-12680" + ], + "details": "The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12680" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/28537fbc-3c2b-40c1-85f0-8b5f94eaad51" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jr3v-9vjg-r9jw/GHSA-jr3v-9vjg-r9jw.json b/advisories/unreviewed/2025/05/GHSA-jr3v-9vjg-r9jw/GHSA-jr3v-9vjg-r9jw.json new file mode 100644 index 00000000000..391e7c9af7c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jr3v-9vjg-r9jw/GHSA-jr3v-9vjg-r9jw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr3v-9vjg-r9jw", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-10632" + ], + "details": "The Nokaut Offers Box WordPress plugin through 1.4.0 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10632" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/17afba70-f213-47f6-aea2-59288ca92549" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jxpg-5php-jfpp/GHSA-jxpg-5php-jfpp.json b/advisories/unreviewed/2025/05/GHSA-jxpg-5php-jfpp/GHSA-jxpg-5php-jfpp.json new file mode 100644 index 00000000000..1bc4e8f27af --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jxpg-5php-jfpp/GHSA-jxpg-5php-jfpp.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxpg-5php-jfpp", + "modified": "2025-05-15T21:31:35Z", + "published": "2025-05-15T21:31:35Z", + "aliases": [ + "CVE-2025-4717" + ], + "details": "A vulnerability, which was classified as critical, was found in PHPGurukul Company Visitor Management System 2.0. Affected is an unknown function of the file /visitors-form.php. The manipulation of the argument fullname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4717" + }, + { + "type": "WEB", + "url": "https://github.com/baixiaobai001/myCVE/issues/7" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309018" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309018" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.568331" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m2m5-cxxq-m4hm/GHSA-m2m5-cxxq-m4hm.json b/advisories/unreviewed/2025/05/GHSA-m2m5-cxxq-m4hm/GHSA-m2m5-cxxq-m4hm.json new file mode 100644 index 00000000000..8508d0c9543 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m2m5-cxxq-m4hm/GHSA-m2m5-cxxq-m4hm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2m5-cxxq-m4hm", + "modified": "2025-05-15T21:31:35Z", + "published": "2025-05-15T21:31:35Z", + "aliases": [ + "CVE-2025-1138" + ], + "details": "IBM InfoSphere Information Server 11.7 could disclose sensitive information to an authenticated user that could aid in further attacks against the system through a directory listing.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1138" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7230295" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-548" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T21:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m33j-944f-82fq/GHSA-m33j-944f-82fq.json b/advisories/unreviewed/2025/05/GHSA-m33j-944f-82fq/GHSA-m33j-944f-82fq.json new file mode 100644 index 00000000000..7d7cb1eab15 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m33j-944f-82fq/GHSA-m33j-944f-82fq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m33j-944f-82fq", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:31Z", + "aliases": [ + "CVE-2024-6708" + ], + "details": "The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting its content on the admin area, which allows Admin+ users to perform Cross-Site Scripting attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6708" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/b6822bd9-f9f9-41a4-ad19-019b1f03bd4c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m7hp-64f5-g5fr/GHSA-m7hp-64f5-g5fr.json b/advisories/unreviewed/2025/05/GHSA-m7hp-64f5-g5fr/GHSA-m7hp-64f5-g5fr.json new file mode 100644 index 00000000000..5baa3749ec9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m7hp-64f5-g5fr/GHSA-m7hp-64f5-g5fr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7hp-64f5-g5fr", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-8701" + ], + "details": "The events-calendar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8701" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/707d4b5b-8efe-4010-ba7d-80538545a2d5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m7mh-68hv-jwrj/GHSA-m7mh-68hv-jwrj.json b/advisories/unreviewed/2025/05/GHSA-m7mh-68hv-jwrj/GHSA-m7mh-68hv-jwrj.json new file mode 100644 index 00000000000..a6f45236f0d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m7mh-68hv-jwrj/GHSA-m7mh-68hv-jwrj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7mh-68hv-jwrj", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-8699" + ], + "details": "The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8699" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/9013351e-224f-4696-970f-eb843dc8dace" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m87q-2m67-hxxh/GHSA-m87q-2m67-hxxh.json b/advisories/unreviewed/2025/05/GHSA-m87q-2m67-hxxh/GHSA-m87q-2m67-hxxh.json new file mode 100644 index 00000000000..9172148c96c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m87q-2m67-hxxh/GHSA-m87q-2m67-hxxh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m87q-2m67-hxxh", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-8673" + ], + "details": "The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8673" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/fed2cd26-7ccb-419d-b589-978410953bf4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m8jc-qh4f-52fp/GHSA-m8jc-qh4f-52fp.json b/advisories/unreviewed/2025/05/GHSA-m8jc-qh4f-52fp/GHSA-m8jc-qh4f-52fp.json new file mode 100644 index 00000000000..01b10015c9b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m8jc-qh4f-52fp/GHSA-m8jc-qh4f-52fp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8jc-qh4f-52fp", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-10475" + ], + "details": "The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin before 1.9.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10475" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/faca59fb-6b59-45b0-8b97-c4125d9d3cb3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m9rv-9j45-vx77/GHSA-m9rv-9j45-vx77.json b/advisories/unreviewed/2025/05/GHSA-m9rv-9j45-vx77/GHSA-m9rv-9j45-vx77.json index c979c762baf..d9b2dd73cdd 100644 --- a/advisories/unreviewed/2025/05/GHSA-m9rv-9j45-vx77/GHSA-m9rv-9j45-vx77.json +++ b/advisories/unreviewed/2025/05/GHSA-m9rv-9j45-vx77/GHSA-m9rv-9j45-vx77.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m9rv-9j45-vx77", - "modified": "2025-05-15T15:31:26Z", + "modified": "2025-05-15T21:31:26Z", "published": "2025-05-15T15:31:26Z", "aliases": [ "CVE-2025-44183" ], "details": "Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the name, email, and mobile parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T14:15:30Z" diff --git a/advisories/unreviewed/2025/05/GHSA-mfvj-g4mp-wqx2/GHSA-mfvj-g4mp-wqx2.json b/advisories/unreviewed/2025/05/GHSA-mfvj-g4mp-wqx2/GHSA-mfvj-g4mp-wqx2.json new file mode 100644 index 00000000000..bac73e919a8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mfvj-g4mp-wqx2/GHSA-mfvj-g4mp-wqx2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfvj-g4mp-wqx2", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2023-7197" + ], + "details": "The Marketing Twitter Bot WordPress plugin through 1.11 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7197" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/26deaa7c-e331-42a0-9310-31d08871154c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mhfc-j5xq-qmgp/GHSA-mhfc-j5xq-qmgp.json b/advisories/unreviewed/2025/05/GHSA-mhfc-j5xq-qmgp/GHSA-mhfc-j5xq-qmgp.json new file mode 100644 index 00000000000..bc62252920b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mhfc-j5xq-qmgp/GHSA-mhfc-j5xq-qmgp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhfc-j5xq-qmgp", + "modified": "2025-05-15T21:31:26Z", + "published": "2025-05-15T21:31:26Z", + "aliases": [ + "CVE-2025-30475" + ], + "details": "Dell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper privilege management vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30475" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000317889/dsa-2025-186-security-update-for-dell-powerscale-inightiq-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T19:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mqjj-6j4c-9xw9/GHSA-mqjj-6j4c-9xw9.json b/advisories/unreviewed/2025/05/GHSA-mqjj-6j4c-9xw9/GHSA-mqjj-6j4c-9xw9.json new file mode 100644 index 00000000000..cc19a13a17f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mqjj-6j4c-9xw9/GHSA-mqjj-6j4c-9xw9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqjj-6j4c-9xw9", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-8759" + ], + "details": "The Nested Pages WordPress plugin before 3.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8759" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/3dd41ecb-d0dc-4c23-9e5b-b1f7fbaaddfd" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mx99-3943-22r2/GHSA-mx99-3943-22r2.json b/advisories/unreviewed/2025/05/GHSA-mx99-3943-22r2/GHSA-mx99-3943-22r2.json new file mode 100644 index 00000000000..b3385052f4b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mx99-3943-22r2/GHSA-mx99-3943-22r2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx99-3943-22r2", + "modified": "2025-05-15T21:31:26Z", + "published": "2025-05-15T21:31:26Z", + "aliases": [ + "CVE-2025-30476" + ], + "details": "Dell PowerScale InsightIQ, version 5.2, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30476" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000317889/dsa-2025-186-security-update-for-dell-powerscale-inightiq-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T19:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p2gx-629f-525f/GHSA-p2gx-629f-525f.json b/advisories/unreviewed/2025/05/GHSA-p2gx-629f-525f/GHSA-p2gx-629f-525f.json new file mode 100644 index 00000000000..b68e0617006 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p2gx-629f-525f/GHSA-p2gx-629f-525f.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2gx-629f-525f", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-3901" + ], + "details": "The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed to write posts (like those with the contributor role) to conduct Stored XSS attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3901" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/9502e1ac-346e-4431-90a6-61143d2df37b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p3gc-w3ww-hwwg/GHSA-p3gc-w3ww-hwwg.json b/advisories/unreviewed/2025/05/GHSA-p3gc-w3ww-hwwg/GHSA-p3gc-w3ww-hwwg.json new file mode 100644 index 00000000000..3b12200d774 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p3gc-w3ww-hwwg/GHSA-p3gc-w3ww-hwwg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3gc-w3ww-hwwg", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-11140" + ], + "details": "The Real WP Shop Lite Ajax eCommerce Shopping Cart WordPress plugin through 2.0.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11140" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/b3448dff-a839-45aa-8d5a-d359e50ab7fd" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p629-9pvp-h6f9/GHSA-p629-9pvp-h6f9.json b/advisories/unreviewed/2025/05/GHSA-p629-9pvp-h6f9/GHSA-p629-9pvp-h6f9.json new file mode 100644 index 00000000000..63faf781ece --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p629-9pvp-h6f9/GHSA-p629-9pvp-h6f9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p629-9pvp-h6f9", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-11372" + ], + "details": "The Connexion Logs WordPress plugin through 3.0.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11372" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/de74199a-001e-4388-82ae-70cfd5a49457" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p694-pgrr-cmpq/GHSA-p694-pgrr-cmpq.json b/advisories/unreviewed/2025/05/GHSA-p694-pgrr-cmpq/GHSA-p694-pgrr-cmpq.json new file mode 100644 index 00000000000..01a1de94778 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p694-pgrr-cmpq/GHSA-p694-pgrr-cmpq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p694-pgrr-cmpq", + "modified": "2025-05-15T21:31:34Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2024-9711" + ], + "details": "The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9711" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/daee95c5-006e-4a83-b92a-7faa3e89d985" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p8rv-v842-xwm4/GHSA-p8rv-v842-xwm4.json b/advisories/unreviewed/2025/05/GHSA-p8rv-v842-xwm4/GHSA-p8rv-v842-xwm4.json new file mode 100644 index 00000000000..a99a2206948 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p8rv-v842-xwm4/GHSA-p8rv-v842-xwm4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8rv-v842-xwm4", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-8031" + ], + "details": "The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloaded. This makes it possible for authenticated attackers, with admin-level access and above, to download arbitrary files that may contain sensitive information like wp-config.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8031" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c6f54e6f-0a50-424f-ae3a-00b9880d9f13" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p9xg-r2f4-c78v/GHSA-p9xg-r2f4-c78v.json b/advisories/unreviewed/2025/05/GHSA-p9xg-r2f4-c78v/GHSA-p9xg-r2f4-c78v.json new file mode 100644 index 00000000000..54e49044b4a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p9xg-r2f4-c78v/GHSA-p9xg-r2f4-c78v.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9xg-r2f4-c78v", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-7762" + ], + "details": "The Simple Job Board WordPress plugin before 2.12.6 does not prevent uploaded files from being listed, allowing unauthenticated users to access and download uploaded resumes", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7762" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/26403e72-c927-4649-b789-694a10ad0492" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pcjq-4m2m-9fw8/GHSA-pcjq-4m2m-9fw8.json b/advisories/unreviewed/2025/05/GHSA-pcjq-4m2m-9fw8/GHSA-pcjq-4m2m-9fw8.json new file mode 100644 index 00000000000..bd8e7f5fd5a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pcjq-4m2m-9fw8/GHSA-pcjq-4m2m-9fw8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcjq-4m2m-9fw8", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2023-7168" + ], + "details": "The Better Follow Button for Jetpack WordPress plugin through 8.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7168" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/715ded45-04ee-40c1-8acb-bd40d0fe30ec" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pf9g-5cwx-37fm/GHSA-pf9g-5cwx-37fm.json b/advisories/unreviewed/2025/05/GHSA-pf9g-5cwx-37fm/GHSA-pf9g-5cwx-37fm.json new file mode 100644 index 00000000000..3275ad67bcc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pf9g-5cwx-37fm/GHSA-pf9g-5cwx-37fm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf9g-5cwx-37fm", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:31Z", + "aliases": [ + "CVE-2024-4091" + ], + "details": "The Responsive Gallery Grid WordPress plugin before 2.3.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4091" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/e28e79fa-f461-41fe-ad1c-ca768ea5f982" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-phfp-9x4x-56gj/GHSA-phfp-9x4x-56gj.json b/advisories/unreviewed/2025/05/GHSA-phfp-9x4x-56gj/GHSA-phfp-9x4x-56gj.json new file mode 100644 index 00000000000..501f1040ab3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-phfp-9x4x-56gj/GHSA-phfp-9x4x-56gj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phfp-9x4x-56gj", + "modified": "2025-05-15T21:31:26Z", + "published": "2025-05-15T21:31:26Z", + "aliases": [ + "CVE-2023-2334" + ], + "details": "The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2334" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/95562684-2bb1-46f0-838c-8501db6b43ed" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-phhw-fr9r-6qv9/GHSA-phhw-fr9r-6qv9.json b/advisories/unreviewed/2025/05/GHSA-phhw-fr9r-6qv9/GHSA-phhw-fr9r-6qv9.json new file mode 100644 index 00000000000..5c88c8247af --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-phhw-fr9r-6qv9/GHSA-phhw-fr9r-6qv9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phhw-fr9r-6qv9", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-9227" + ], + "details": "The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow admin users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9227" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/bb6515b9-a316-4146-8b7d-9b70a47aa366" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-phj4-6g5f-vqcj/GHSA-phj4-6g5f-vqcj.json b/advisories/unreviewed/2025/05/GHSA-phj4-6g5f-vqcj/GHSA-phj4-6g5f-vqcj.json new file mode 100644 index 00000000000..aba7f71739c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-phj4-6g5f-vqcj/GHSA-phj4-6g5f-vqcj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phj4-6g5f-vqcj", + "modified": "2025-05-15T21:31:35Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2025-4718" + ], + "details": "A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pages/customer_add.php. The manipulation of the argument last leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4718" + }, + { + "type": "WEB", + "url": "https://github.com/usingns/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309019" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309019" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.568386" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pr6c-x44x-mpwc/GHSA-pr6c-x44x-mpwc.json b/advisories/unreviewed/2025/05/GHSA-pr6c-x44x-mpwc/GHSA-pr6c-x44x-mpwc.json new file mode 100644 index 00000000000..2063f6db102 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pr6c-x44x-mpwc/GHSA-pr6c-x44x-mpwc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pr6c-x44x-mpwc", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-13482" + ], + "details": "The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13482" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/83ae33d0-4fc1-4186-9d70-b854a16df3a7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-prfq-pmqw-27fc/GHSA-prfq-pmqw-27fc.json b/advisories/unreviewed/2025/05/GHSA-prfq-pmqw-27fc/GHSA-prfq-pmqw-27fc.json new file mode 100644 index 00000000000..43afb19f24f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-prfq-pmqw-27fc/GHSA-prfq-pmqw-27fc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prfq-pmqw-27fc", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-8398" + ], + "details": "The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8398" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/f432901f-31dd-433c-91bf-ec19fa61b6d8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-prgf-xxfj-c6gv/GHSA-prgf-xxfj-c6gv.json b/advisories/unreviewed/2025/05/GHSA-prgf-xxfj-c6gv/GHSA-prgf-xxfj-c6gv.json new file mode 100644 index 00000000000..979e812825b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-prgf-xxfj-c6gv/GHSA-prgf-xxfj-c6gv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prgf-xxfj-c6gv", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-8090" + ], + "details": "The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8090" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c9dcd450-e8ed-4058-b002-20fb3b879ee0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pvrm-g69c-c84r/GHSA-pvrm-g69c-c84r.json b/advisories/unreviewed/2025/05/GHSA-pvrm-g69c-c84r/GHSA-pvrm-g69c-c84r.json new file mode 100644 index 00000000000..fd74aa34d60 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pvrm-g69c-c84r/GHSA-pvrm-g69c-c84r.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvrm-g69c-c84r", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-8095" + ], + "details": "The BabelZ WordPress plugin through 1.1.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8095" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/56d22ad0-c5f5-488b-bc1f-73188dfc71d2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pvvp-x3x5-w98p/GHSA-pvvp-x3x5-w98p.json b/advisories/unreviewed/2025/05/GHSA-pvvp-x3x5-w98p/GHSA-pvvp-x3x5-w98p.json new file mode 100644 index 00000000000..8387dd6802a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pvvp-x3x5-w98p/GHSA-pvvp-x3x5-w98p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvvp-x3x5-w98p", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-13357" + ], + "details": "The Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high privilege users such as author to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13357" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d134bb34-6324-4bc8-943e-4e743d00fcb2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q3cq-6xv8-j4p3/GHSA-q3cq-6xv8-j4p3.json b/advisories/unreviewed/2025/05/GHSA-q3cq-6xv8-j4p3/GHSA-q3cq-6xv8-j4p3.json new file mode 100644 index 00000000000..8cb9a8a4b30 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q3cq-6xv8-j4p3/GHSA-q3cq-6xv8-j4p3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3cq-6xv8-j4p3", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-13382" + ], + "details": "The Calculated Fields Form WordPress plugin before 5.2.64 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13382" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/925de4af-fc71-45ae-8454-7e4f70be13ca" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q4jv-p3r8-p9rx/GHSA-q4jv-p3r8-p9rx.json b/advisories/unreviewed/2025/05/GHSA-q4jv-p3r8-p9rx/GHSA-q4jv-p3r8-p9rx.json new file mode 100644 index 00000000000..7496f5af9de --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q4jv-p3r8-p9rx/GHSA-q4jv-p3r8-p9rx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4jv-p3r8-p9rx", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-10504" + ], + "details": "The Contact Form, Survey, Quiz & Popup Form Builder WordPress plugin before 1.7.1 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10504" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/9a22df11-0e24-4248-a8f3-da8f23ccb313" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q4w4-v939-f8rm/GHSA-q4w4-v939-f8rm.json b/advisories/unreviewed/2025/05/GHSA-q4w4-v939-f8rm/GHSA-q4w4-v939-f8rm.json new file mode 100644 index 00000000000..7913cfbabe4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q4w4-v939-f8rm/GHSA-q4w4-v939-f8rm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4w4-v939-f8rm", + "modified": "2025-05-15T21:31:34Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2025-0688" + ], + "details": "The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0688" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/1e2b77c3-ad45-4734-998a-c1722ebd1f4f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q79f-fxqg-m9px/GHSA-q79f-fxqg-m9px.json b/advisories/unreviewed/2025/05/GHSA-q79f-fxqg-m9px/GHSA-q79f-fxqg-m9px.json new file mode 100644 index 00000000000..fddc9563a50 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q79f-fxqg-m9px/GHSA-q79f-fxqg-m9px.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q79f-fxqg-m9px", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-8094" + ], + "details": "The Ntz Antispam WordPress plugin through 2.0e does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8094" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/cacfde9e-c6fa-4918-8e59-461b67b5e979" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q8vg-jpq8-qfm6/GHSA-q8vg-jpq8-qfm6.json b/advisories/unreviewed/2025/05/GHSA-q8vg-jpq8-qfm6/GHSA-q8vg-jpq8-qfm6.json new file mode 100644 index 00000000000..c1943e510ff --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q8vg-jpq8-qfm6/GHSA-q8vg-jpq8-qfm6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8vg-jpq8-qfm6", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-8187" + ], + "details": "The Smart Post Show WordPress plugin before 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8187" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/0e51b3b5-f003-4af9-8538-95f266065e36" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qgvm-vj48-358p/GHSA-qgvm-vj48-358p.json b/advisories/unreviewed/2025/05/GHSA-qgvm-vj48-358p/GHSA-qgvm-vj48-358p.json new file mode 100644 index 00000000000..aa302dcf7e6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qgvm-vj48-358p/GHSA-qgvm-vj48-358p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgvm-vj48-358p", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:31Z", + "aliases": [ + "CVE-2024-6690" + ], + "details": "The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6690" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/09c6848d-30dc-4382-ae74-b470f586e142" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qp9v-5v7f-q6f8/GHSA-qp9v-5v7f-q6f8.json b/advisories/unreviewed/2025/05/GHSA-qp9v-5v7f-q6f8/GHSA-qp9v-5v7f-q6f8.json new file mode 100644 index 00000000000..fe05d285ed2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qp9v-5v7f-q6f8/GHSA-qp9v-5v7f-q6f8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp9v-5v7f-q6f8", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-13727" + ], + "details": "The MemberSpace WordPress plugin before 2.1.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13727" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/598d20f2-0f42-48f2-a941-0d6c5da5303e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qr28-f5f9-2wjf/GHSA-qr28-f5f9-2wjf.json b/advisories/unreviewed/2025/05/GHSA-qr28-f5f9-2wjf/GHSA-qr28-f5f9-2wjf.json new file mode 100644 index 00000000000..ba1dbe17e6f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qr28-f5f9-2wjf/GHSA-qr28-f5f9-2wjf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr28-f5f9-2wjf", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-13865" + ], + "details": "The S3Player WordPress plugin through 4.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13865" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/9cc7c5cb-983f-4593-abc5-7e224b275a23" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qrqf-gfw2-2f89/GHSA-qrqf-gfw2-2f89.json b/advisories/unreviewed/2025/05/GHSA-qrqf-gfw2-2f89/GHSA-qrqf-gfw2-2f89.json new file mode 100644 index 00000000000..28c1002f605 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qrqf-gfw2-2f89/GHSA-qrqf-gfw2-2f89.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrqf-gfw2-2f89", + "modified": "2025-05-15T21:31:34Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2024-9831" + ], + "details": "The Taskbuilder WordPress plugin before 3.0.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9831" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/390baaf8-a162-43e5-9367-0d2e979d89f7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qvqw-6658-7p9p/GHSA-qvqw-6658-7p9p.json b/advisories/unreviewed/2025/05/GHSA-qvqw-6658-7p9p/GHSA-qvqw-6658-7p9p.json new file mode 100644 index 00000000000..2fe3e0297b1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qvqw-6658-7p9p/GHSA-qvqw-6658-7p9p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvqw-6658-7p9p", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-6797" + ], + "details": "The DL Robots.txt WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6797" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/14275493-45fd-470c-958f-feded435f706" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r2r3-h6fc-5hh6/GHSA-r2r3-h6fc-5hh6.json b/advisories/unreviewed/2025/05/GHSA-r2r3-h6fc-5hh6/GHSA-r2r3-h6fc-5hh6.json new file mode 100644 index 00000000000..7f6a29a2f73 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r2r3-h6fc-5hh6/GHSA-r2r3-h6fc-5hh6.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2r3-h6fc-5hh6", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:26Z", + "aliases": [ + "CVE-2025-4712" + ], + "details": "A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerability affects unknown code of the file /pages/account_summary.php. The manipulation of the argument cid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4712" + }, + { + "type": "WEB", + "url": "https://github.com/lanxia0/CVE/issues/6" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309010" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309010" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.568292" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T19:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r3vc-752g-hj6w/GHSA-r3vc-752g-hj6w.json b/advisories/unreviewed/2025/05/GHSA-r3vc-752g-hj6w/GHSA-r3vc-752g-hj6w.json new file mode 100644 index 00000000000..c6c349830c5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r3vc-752g-hj6w/GHSA-r3vc-752g-hj6w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3vc-752g-hj6w", + "modified": "2025-05-15T21:31:26Z", + "published": "2025-05-15T21:31:26Z", + "aliases": [ + "CVE-2024-56006" + ], + "details": "Missing Authorization vulnerability in Automattic Jetpack Debug Tools.This issue affects Jetpack Debug Tools: from n/a before 2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56006" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jetpack-debug-helper/vulnerability/wordpress-jetpack-debug-tools-plugin-2-0-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T19:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r43x-w85h-p334/GHSA-r43x-w85h-p334.json b/advisories/unreviewed/2025/05/GHSA-r43x-w85h-p334/GHSA-r43x-w85h-p334.json new file mode 100644 index 00000000000..2be4989276a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r43x-w85h-p334/GHSA-r43x-w85h-p334.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r43x-w85h-p334", + "modified": "2025-05-15T21:31:34Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2025-2248" + ], + "details": "The WP-PManager WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2248" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/b470a277-f5ad-49ff-97dd-4d3ee0269e5a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r5wg-fxw7-6v36/GHSA-r5wg-fxw7-6v36.json b/advisories/unreviewed/2025/05/GHSA-r5wg-fxw7-6v36/GHSA-r5wg-fxw7-6v36.json new file mode 100644 index 00000000000..780b7f0696c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r5wg-fxw7-6v36/GHSA-r5wg-fxw7-6v36.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5wg-fxw7-6v36", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-13383" + ], + "details": "The HD Quiz WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13383" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/85bc905d-c960-4399-a879-2d18a4b03007" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r77g-4w8g-2vqq/GHSA-r77g-4w8g-2vqq.json b/advisories/unreviewed/2025/05/GHSA-r77g-4w8g-2vqq/GHSA-r77g-4w8g-2vqq.json new file mode 100644 index 00000000000..7e5ff9521f5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r77g-4w8g-2vqq/GHSA-r77g-4w8g-2vqq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r77g-4w8g-2vqq", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-12812" + ], + "details": "The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 has an issue where employees can manipulate parameters to access the data of terminated employees.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12812" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/757e76fd-830f-4d1c-8b89-dfad7c9c1f37" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rcp3-h3cv-rfv7/GHSA-rcp3-h3cv-rfv7.json b/advisories/unreviewed/2025/05/GHSA-rcp3-h3cv-rfv7/GHSA-rcp3-h3cv-rfv7.json new file mode 100644 index 00000000000..55313d5fe7f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rcp3-h3cv-rfv7/GHSA-rcp3-h3cv-rfv7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcp3-h3cv-rfv7", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2023-7195" + ], + "details": "The WP-Reply Notify WordPress plugin through 1.1 does not have a CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7195" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/72279ca0-6365-4c83-adca-4d8e5808a8c5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rf8c-553r-qgf7/GHSA-rf8c-553r-qgf7.json b/advisories/unreviewed/2025/05/GHSA-rf8c-553r-qgf7/GHSA-rf8c-553r-qgf7.json new file mode 100644 index 00000000000..ef3650b436d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rf8c-553r-qgf7/GHSA-rf8c-553r-qgf7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rf8c-553r-qgf7", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2023-6541" + ], + "details": "The Allow SVG WordPress plugin before 1.2.0 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6541" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/bbe866b8-7497-4e5c-8f59-bb8edac1dc71" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rgcv-gh4w-gxrw/GHSA-rgcv-gh4w-gxrw.json b/advisories/unreviewed/2025/05/GHSA-rgcv-gh4w-gxrw/GHSA-rgcv-gh4w-gxrw.json new file mode 100644 index 00000000000..55296d30d52 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rgcv-gh4w-gxrw/GHSA-rgcv-gh4w-gxrw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgcv-gh4w-gxrw", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-10143" + ], + "details": "The MB Custom Post Types & Custom Taxonomies WordPress plugin before 2.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10143" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/b5fd7a3e-33e4-4c73-a581-881f063855b0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rp49-qh64-pw4x/GHSA-rp49-qh64-pw4x.json b/advisories/unreviewed/2025/05/GHSA-rp49-qh64-pw4x/GHSA-rp49-qh64-pw4x.json new file mode 100644 index 00000000000..605817e92a3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rp49-qh64-pw4x/GHSA-rp49-qh64-pw4x.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rp49-qh64-pw4x", + "modified": "2025-05-15T21:31:35Z", + "published": "2025-05-15T21:31:35Z", + "aliases": [ + "CVE-2025-4719" + ], + "details": "A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/cash_transaction.php. The manipulation of the argument cid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4719" + }, + { + "type": "WEB", + "url": "https://github.com/usingns/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309020" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309020" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.568387" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rrc3-jxqw-99qh/GHSA-rrc3-jxqw-99qh.json b/advisories/unreviewed/2025/05/GHSA-rrc3-jxqw-99qh/GHSA-rrc3-jxqw-99qh.json new file mode 100644 index 00000000000..c91dc23190f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rrc3-jxqw-99qh/GHSA-rrc3-jxqw-99qh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrc3-jxqw-99qh", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-10144" + ], + "details": "The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10144" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/a83521d3-0aba-493d-8dec-e764277e69b8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rrc7-p8g9-c7vg/GHSA-rrc7-p8g9-c7vg.json b/advisories/unreviewed/2025/05/GHSA-rrc7-p8g9-c7vg/GHSA-rrc7-p8g9-c7vg.json new file mode 100644 index 00000000000..1125d4ddd06 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rrc7-p8g9-c7vg/GHSA-rrc7-p8g9-c7vg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrc7-p8g9-c7vg", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-13053" + ], + "details": "The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13053" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/1c667a70-8b38-4854-8969-2971f9c2fe79" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v364-qrc6-2qj4/GHSA-v364-qrc6-2qj4.json b/advisories/unreviewed/2025/05/GHSA-v364-qrc6-2qj4/GHSA-v364-qrc6-2qj4.json new file mode 100644 index 00000000000..dfe8bee4fb8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v364-qrc6-2qj4/GHSA-v364-qrc6-2qj4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v364-qrc6-2qj4", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-12301" + ], + "details": "The JSP Store Locator WordPress plugin through 1.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12301" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/5d93db07-415f-475b-a76d-2e12f849a4dc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v45r-44c3-w45r/GHSA-v45r-44c3-w45r.json b/advisories/unreviewed/2025/05/GHSA-v45r-44c3-w45r/GHSA-v45r-44c3-w45r.json new file mode 100644 index 00000000000..9c0641bfdec --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v45r-44c3-w45r/GHSA-v45r-44c3-w45r.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v45r-44c3-w45r", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-8009" + ], + "details": "The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8009" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/737bb010-b2fa-4bf4-b124-5fbba67cf935" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v4h8-jvp4-3vjm/GHSA-v4h8-jvp4-3vjm.json b/advisories/unreviewed/2025/05/GHSA-v4h8-jvp4-3vjm/GHSA-v4h8-jvp4-3vjm.json new file mode 100644 index 00000000000..990484711ed --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v4h8-jvp4-3vjm/GHSA-v4h8-jvp4-3vjm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4h8-jvp4-3vjm", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-11190" + ], + "details": "The jwp-a11y WordPress plugin through 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11190" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/66b914ba-4253-4849-a38a-05ab246a9a32" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v6jx-8472-465v/GHSA-v6jx-8472-465v.json b/advisories/unreviewed/2025/05/GHSA-v6jx-8472-465v/GHSA-v6jx-8472-465v.json new file mode 100644 index 00000000000..96191dfe6c4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v6jx-8472-465v/GHSA-v6jx-8472-465v.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6jx-8472-465v", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-13619" + ], + "details": "The LifterLMS WordPress plugin before 8.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13619" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/97a7e1a6-0fb3-49e9-86fc-ebb1d426fcca" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v7fp-w3f5-7445/GHSA-v7fp-w3f5-7445.json b/advisories/unreviewed/2025/05/GHSA-v7fp-w3f5-7445/GHSA-v7fp-w3f5-7445.json new file mode 100644 index 00000000000..3a60e5fb80d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v7fp-w3f5-7445/GHSA-v7fp-w3f5-7445.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7fp-w3f5-7445", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-1663" + ], + "details": "The Ultimate Noindex Nofollow Tool II WordPress plugin before 1.3.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1663" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/6d101f2b-e903-4e64-92cc-e550abb52d6f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v82c-v3v8-qq2x/GHSA-v82c-v3v8-qq2x.json b/advisories/unreviewed/2025/05/GHSA-v82c-v3v8-qq2x/GHSA-v82c-v3v8-qq2x.json new file mode 100644 index 00000000000..f1f5cab513f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v82c-v3v8-qq2x/GHSA-v82c-v3v8-qq2x.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v82c-v3v8-qq2x", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-8618" + ], + "details": "The Page Builder: Pagelayer WordPress plugin before 1.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8618" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/acddcf33-0a18-499e-b42d-c8b49f2c4de5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v884-m573-754j/GHSA-v884-m573-754j.json b/advisories/unreviewed/2025/05/GHSA-v884-m573-754j/GHSA-v884-m573-754j.json new file mode 100644 index 00000000000..e6ee52de93e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v884-m573-754j/GHSA-v884-m573-754j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v884-m573-754j", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-8050" + ], + "details": "The Custom Author Base WordPress plugin through 1.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8050" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/28c9c127-464a-4750-8b62-a9b90b01f1af" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v8j5-hjg7-w5w5/GHSA-v8j5-hjg7-w5w5.json b/advisories/unreviewed/2025/05/GHSA-v8j5-hjg7-w5w5/GHSA-v8j5-hjg7-w5w5.json new file mode 100644 index 00000000000..6ae035a45b0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v8j5-hjg7-w5w5/GHSA-v8j5-hjg7-w5w5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8j5-hjg7-w5w5", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2024-0970" + ], + "details": "This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0970" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/7df6877c-6640-41be-aacb-20c7da61e4db" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vcpp-7qvc-rxv7/GHSA-vcpp-7qvc-rxv7.json b/advisories/unreviewed/2025/05/GHSA-vcpp-7qvc-rxv7/GHSA-vcpp-7qvc-rxv7.json new file mode 100644 index 00000000000..55391a8d639 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vcpp-7qvc-rxv7/GHSA-vcpp-7qvc-rxv7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcpp-7qvc-rxv7", + "modified": "2025-05-15T21:31:26Z", + "published": "2025-05-15T21:31:26Z", + "aliases": [ + "CVE-2023-5934" + ], + "details": "The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.13 does not have CSRF check in place when importing settings from the v1, which could allow attackers to make a logged in admin update some settings via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5934" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/2a45cdba-df41-457e-bff9-2d6d89776dd0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vcr6-vwcj-r3r3/GHSA-vcr6-vwcj-r3r3.json b/advisories/unreviewed/2025/05/GHSA-vcr6-vwcj-r3r3/GHSA-vcr6-vwcj-r3r3.json new file mode 100644 index 00000000000..e247d117365 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vcr6-vwcj-r3r3/GHSA-vcr6-vwcj-r3r3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcr6-vwcj-r3r3", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:31Z", + "aliases": [ + "CVE-2024-6335" + ], + "details": "The Tracking Code Manager WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6335" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/3bfb6b3f-8642-4807-b6b3-f214b26e96c2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vf8r-rhw4-6q8g/GHSA-vf8r-rhw4-6q8g.json b/advisories/unreviewed/2025/05/GHSA-vf8r-rhw4-6q8g/GHSA-vf8r-rhw4-6q8g.json new file mode 100644 index 00000000000..cdfa0b25554 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vf8r-rhw4-6q8g/GHSA-vf8r-rhw4-6q8g.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vf8r-rhw4-6q8g", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:31Z", + "aliases": [ + "CVE-2024-6478" + ], + "details": "The CTT Expresso para WooCommerce WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6478" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/39a78741-eeae-4a27-8136-7d0bb0bf2263" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vg38-3h8m-863x/GHSA-vg38-3h8m-863x.json b/advisories/unreviewed/2025/05/GHSA-vg38-3h8m-863x/GHSA-vg38-3h8m-863x.json new file mode 100644 index 00000000000..da73d2669ea --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vg38-3h8m-863x/GHSA-vg38-3h8m-863x.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg38-3h8m-863x", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-12679" + ], + "details": "The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12679" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/7ca1438f-4269-4e34-be4a-766276a9f016" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vgrm-7j7m-pjmg/GHSA-vgrm-7j7m-pjmg.json b/advisories/unreviewed/2025/05/GHSA-vgrm-7j7m-pjmg/GHSA-vgrm-7j7m-pjmg.json new file mode 100644 index 00000000000..c0690f68882 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vgrm-7j7m-pjmg/GHSA-vgrm-7j7m-pjmg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgrm-7j7m-pjmg", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-9450" + ], + "details": "The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9450" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/f4b9568a-af74-40df-89c1-550e8515ca0a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vp5j-xp55-mrjq/GHSA-vp5j-xp55-mrjq.json b/advisories/unreviewed/2025/05/GHSA-vp5j-xp55-mrjq/GHSA-vp5j-xp55-mrjq.json new file mode 100644 index 00000000000..95403d0e04b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vp5j-xp55-mrjq/GHSA-vp5j-xp55-mrjq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp5j-xp55-mrjq", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-10149" + ], + "details": "The Social Slider Feed WordPress plugin before 2.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10149" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/1619dc4b-4e5e-4b82-820b-3c4e732db3ad" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vr72-pg8g-8362/GHSA-vr72-pg8g-8362.json b/advisories/unreviewed/2025/05/GHSA-vr72-pg8g-8362/GHSA-vr72-pg8g-8362.json new file mode 100644 index 00000000000..864c9410aef --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vr72-pg8g-8362/GHSA-vr72-pg8g-8362.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr72-pg8g-8362", + "modified": "2025-05-15T21:31:34Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2024-9765" + ], + "details": "The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9765" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c86157b0-43f3-4e82-9697-7dd9401b48d6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vxgw-vvr8-p42m/GHSA-vxgw-vvr8-p42m.json b/advisories/unreviewed/2025/05/GHSA-vxgw-vvr8-p42m/GHSA-vxgw-vvr8-p42m.json new file mode 100644 index 00000000000..4f805824fec --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vxgw-vvr8-p42m/GHSA-vxgw-vvr8-p42m.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxgw-vvr8-p42m", + "modified": "2025-05-15T21:31:27Z", + "published": "2025-05-15T21:31:27Z", + "aliases": [ + "CVE-2023-7086" + ], + "details": "The SVG Uploads Support WordPress plugin through 2.1.1 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7086" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/94954e1a-dc09-4811-b57d-b12bf69a767d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w2f5-45xv-7r8h/GHSA-w2f5-45xv-7r8h.json b/advisories/unreviewed/2025/05/GHSA-w2f5-45xv-7r8h/GHSA-w2f5-45xv-7r8h.json new file mode 100644 index 00000000000..e273e41c21a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w2f5-45xv-7r8h/GHSA-w2f5-45xv-7r8h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2f5-45xv-7r8h", + "modified": "2025-05-15T21:31:26Z", + "published": "2025-05-15T21:31:26Z", + "aliases": [ + "CVE-2025-26481" + ], + "details": "Dell PowerScale OneFS, versions 9.4.0.0 through 9.9.0.0, contains an uncontrolled resource consumption vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26481" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000256645/dsa-2024-453-security-update-for-dell-powerscale-onefs-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T19:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w3jx-4fjp-hqjc/GHSA-w3jx-4fjp-hqjc.json b/advisories/unreviewed/2025/05/GHSA-w3jx-4fjp-hqjc/GHSA-w3jx-4fjp-hqjc.json new file mode 100644 index 00000000000..45fa9e9e2e0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w3jx-4fjp-hqjc/GHSA-w3jx-4fjp-hqjc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3jx-4fjp-hqjc", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-10145" + ], + "details": "The Hubbub Lite WordPress plugin before 1.34.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10145" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/b9e2381b-3ea0-48fa-bd9c-4181ddf36389" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w4w8-5w5f-5gvr/GHSA-w4w8-5w5f-5gvr.json b/advisories/unreviewed/2025/05/GHSA-w4w8-5w5f-5gvr/GHSA-w4w8-5w5f-5gvr.json new file mode 100644 index 00000000000..c36aceb999a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w4w8-5w5f-5gvr/GHSA-w4w8-5w5f-5gvr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4w8-5w5f-5gvr", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-9645" + ], + "details": "The Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry WordPress plugin before 2.2.93 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9645" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/cfd6db83-5e7f-4631-87c3-fdcd4c64c4fe" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w589-4j7g-6889/GHSA-w589-4j7g-6889.json b/advisories/unreviewed/2025/05/GHSA-w589-4j7g-6889/GHSA-w589-4j7g-6889.json new file mode 100644 index 00000000000..46e08ed5b20 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w589-4j7g-6889/GHSA-w589-4j7g-6889.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w589-4j7g-6889", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:31Z", + "aliases": [ + "CVE-2024-6159" + ], + "details": "The Push Notification for Post and BuddyPress WordPress plugin before 1.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6159" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/de20ebda-b0bc-489e-a8d3-e9487a2b48e8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w7g4-p5vp-3m77/GHSA-w7g4-p5vp-3m77.json b/advisories/unreviewed/2025/05/GHSA-w7g4-p5vp-3m77/GHSA-w7g4-p5vp-3m77.json new file mode 100644 index 00000000000..8ee14e26683 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w7g4-p5vp-3m77/GHSA-w7g4-p5vp-3m77.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7g4-p5vp-3m77", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-8032" + ], + "details": "The Smooth Gallery Replacement WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8032" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/4c9120b1-ca81-411b-a2e2-a8d30f32a74b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w7g5-m4q3-r22v/GHSA-w7g5-m4q3-r22v.json b/advisories/unreviewed/2025/05/GHSA-w7g5-m4q3-r22v/GHSA-w7g5-m4q3-r22v.json new file mode 100644 index 00000000000..a17fd6dc8f1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w7g5-m4q3-r22v/GHSA-w7g5-m4q3-r22v.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7g5-m4q3-r22v", + "modified": "2025-05-15T21:31:34Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2025-1033" + ], + "details": "The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1033" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/cbb63e80-92aa-4e85-9d47-dc68211af97d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w97m-g6h7-95c2/GHSA-w97m-g6h7-95c2.json b/advisories/unreviewed/2025/05/GHSA-w97m-g6h7-95c2/GHSA-w97m-g6h7-95c2.json new file mode 100644 index 00000000000..7e9fc64e7f5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w97m-g6h7-95c2/GHSA-w97m-g6h7-95c2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w97m-g6h7-95c2", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-8085" + ], + "details": "The PeoplePond WordPress plugin through 1.1.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8085" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/8b43d3a2-4324-43fd-9c2a-90dbdc1d12a6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wj5c-qqg6-p7qc/GHSA-wj5c-qqg6-p7qc.json b/advisories/unreviewed/2025/05/GHSA-wj5c-qqg6-p7qc/GHSA-wj5c-qqg6-p7qc.json new file mode 100644 index 00000000000..8839a86dfe9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wj5c-qqg6-p7qc/GHSA-wj5c-qqg6-p7qc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj5c-qqg6-p7qc", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-10076" + ], + "details": "The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching image URLs to their CDN counterpart. Unfortunately, some of them may match patterns it shouldn’t, ultimately making it possible for contributor and above users to perform Stored XSS attacks", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10076" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/15f278f6-0418-4c83-b925-b1a2d8c53e2f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wjgg-2chr-56vm/GHSA-wjgg-2chr-56vm.json b/advisories/unreviewed/2025/05/GHSA-wjgg-2chr-56vm/GHSA-wjgg-2chr-56vm.json new file mode 100644 index 00000000000..0a5a6b42cd9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wjgg-2chr-56vm/GHSA-wjgg-2chr-56vm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjgg-2chr-56vm", + "modified": "2025-05-15T21:31:28Z", + "published": "2025-05-15T21:31:28Z", + "aliases": [ + "CVE-2024-10677" + ], + "details": "The BTEV WordPress plugin through 2.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10677" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/b1bd4216-798a-4e45-a0ba-3699f0af3c7a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wpp3-qg8g-86cw/GHSA-wpp3-qg8g-86cw.json b/advisories/unreviewed/2025/05/GHSA-wpp3-qg8g-86cw/GHSA-wpp3-qg8g-86cw.json new file mode 100644 index 00000000000..9489a957b50 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wpp3-qg8g-86cw/GHSA-wpp3-qg8g-86cw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpp3-qg8g-86cw", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-9390" + ], + "details": "The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9390" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/6a5308fb-83bf-4f6a-a7ef-e3e1b69aa80f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wr8q-wf72-mf6m/GHSA-wr8q-wf72-mf6m.json b/advisories/unreviewed/2025/05/GHSA-wr8q-wf72-mf6m/GHSA-wr8q-wf72-mf6m.json new file mode 100644 index 00000000000..67ba4246fac --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wr8q-wf72-mf6m/GHSA-wr8q-wf72-mf6m.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr8q-wf72-mf6m", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:31Z", + "aliases": [ + "CVE-2024-2869" + ], + "details": "The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2869" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/4093c12e-f62b-4357-8893-649cd2aaeace" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ww93-7rhp-2gf3/GHSA-ww93-7rhp-2gf3.json b/advisories/unreviewed/2025/05/GHSA-ww93-7rhp-2gf3/GHSA-ww93-7rhp-2gf3.json new file mode 100644 index 00000000000..aa34ddf82cb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-ww93-7rhp-2gf3/GHSA-ww93-7rhp-2gf3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww93-7rhp-2gf3", + "modified": "2025-05-15T21:31:34Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2025-47161" + ], + "details": "Microsoft Defender for Endpoint Elevation of Privilege Vulnerability", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47161" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47161" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x468-pj97-v469/GHSA-x468-pj97-v469.json b/advisories/unreviewed/2025/05/GHSA-x468-pj97-v469/GHSA-x468-pj97-v469.json new file mode 100644 index 00000000000..f21727122fb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x468-pj97-v469/GHSA-x468-pj97-v469.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x468-pj97-v469", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-8700" + ], + "details": "The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8700" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/8c48b657-afa1-45e6-ada6-27ee58185143" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x579-fc2r-gxmj/GHSA-x579-fc2r-gxmj.json b/advisories/unreviewed/2025/05/GHSA-x579-fc2r-gxmj/GHSA-x579-fc2r-gxmj.json new file mode 100644 index 00000000000..3dffe2ee455 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x579-fc2r-gxmj/GHSA-x579-fc2r-gxmj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x579-fc2r-gxmj", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-9182" + ], + "details": "The Maspik WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9182" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/40007323-d684-430d-a882-8b4dfb76172b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x5f2-w3c3-pvvg/GHSA-x5f2-w3c3-pvvg.json b/advisories/unreviewed/2025/05/GHSA-x5f2-w3c3-pvvg/GHSA-x5f2-w3c3-pvvg.json new file mode 100644 index 00000000000..68aee48a1cc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x5f2-w3c3-pvvg/GHSA-x5f2-w3c3-pvvg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5f2-w3c3-pvvg", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-12800" + ], + "details": "The IP Based Login WordPress plugin before 2.4.1 does not sanitise values when importing, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12800" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/8f1ceca5-3b7b-4cf0-bccd-03e204e5bfad" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x7pf-mv6r-v5x9/GHSA-x7pf-mv6r-v5x9.json b/advisories/unreviewed/2025/05/GHSA-x7pf-mv6r-v5x9/GHSA-x7pf-mv6r-v5x9.json new file mode 100644 index 00000000000..26f32c30bf8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x7pf-mv6r-v5x9/GHSA-x7pf-mv6r-v5x9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7pf-mv6r-v5x9", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-8670" + ], + "details": "The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8670" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/50665594-778b-42f5-bfba-2a249a5e0260" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x8qc-qf2g-j5w3/GHSA-x8qc-qf2g-j5w3.json b/advisories/unreviewed/2025/05/GHSA-x8qc-qf2g-j5w3/GHSA-x8qc-qf2g-j5w3.json new file mode 100644 index 00000000000..c7d3d1a7bc6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x8qc-qf2g-j5w3/GHSA-x8qc-qf2g-j5w3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8qc-qf2g-j5w3", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-11502" + ], + "details": "The Planning Center Online Giving WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11502" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d9bea52e-af32-449f-97b6-1dcfb2051bda" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x9mr-w276-h3c2/GHSA-x9mr-w276-h3c2.json b/advisories/unreviewed/2025/05/GHSA-x9mr-w276-h3c2/GHSA-x9mr-w276-h3c2.json new file mode 100644 index 00000000000..b5e7ed63566 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x9mr-w276-h3c2/GHSA-x9mr-w276-h3c2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9mr-w276-h3c2", + "modified": "2025-05-15T21:31:32Z", + "published": "2025-05-15T21:31:32Z", + "aliases": [ + "CVE-2024-7984" + ], + "details": "The Joy Of Text Lite WordPress plugin through 2.3.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7984" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/07684ecb-5662-4412-8190-7957cfcf7bd3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xc5x-xvcr-5h87/GHSA-xc5x-xvcr-5h87.json b/advisories/unreviewed/2025/05/GHSA-xc5x-xvcr-5h87/GHSA-xc5x-xvcr-5h87.json new file mode 100644 index 00000000000..105e68b45bb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xc5x-xvcr-5h87/GHSA-xc5x-xvcr-5h87.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xc5x-xvcr-5h87", + "modified": "2025-05-15T21:31:33Z", + "published": "2025-05-15T21:31:33Z", + "aliases": [ + "CVE-2024-8493" + ], + "details": "The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8493" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/561b3185-501a-4a75-b880-226b159c0431" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xqrc-6556-5gcq/GHSA-xqrc-6556-5gcq.json b/advisories/unreviewed/2025/05/GHSA-xqrc-6556-5gcq/GHSA-xqrc-6556-5gcq.json new file mode 100644 index 00000000000..a5037f2cd6f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xqrc-6556-5gcq/GHSA-xqrc-6556-5gcq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqrc-6556-5gcq", + "modified": "2025-05-15T21:31:29Z", + "published": "2025-05-15T21:31:29Z", + "aliases": [ + "CVE-2024-12724" + ], + "details": "The WP DeskLite WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12724" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/9dd3ffaa-9020-47a6-bf9a-7e1412b9e9d5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xvf2-x5rr-6g4q/GHSA-xvf2-x5rr-6g4q.json b/advisories/unreviewed/2025/05/GHSA-xvf2-x5rr-6g4q/GHSA-xvf2-x5rr-6g4q.json new file mode 100644 index 00000000000..3558424e82b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xvf2-x5rr-6g4q/GHSA-xvf2-x5rr-6g4q.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvf2-x5rr-6g4q", + "modified": "2025-05-15T21:31:31Z", + "published": "2025-05-15T21:31:31Z", + "aliases": [ + "CVE-2024-6693" + ], + "details": "The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6693" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/2b1af7eb-452a-43f4-aae9-edd8e7312fe8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xw9h-x6h4-fc8r/GHSA-xw9h-x6h4-fc8r.json b/advisories/unreviewed/2025/05/GHSA-xw9h-x6h4-fc8r/GHSA-xw9h-x6h4-fc8r.json new file mode 100644 index 00000000000..ae4246e953a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xw9h-x6h4-fc8r/GHSA-xw9h-x6h4-fc8r.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw9h-x6h4-fc8r", + "modified": "2025-05-15T21:31:30Z", + "published": "2025-05-15T21:31:30Z", + "aliases": [ + "CVE-2024-13828" + ], + "details": "The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13828" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/0f901807-9ef2-4cd3-969a-9fd23a8da371" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xwv7-jv97-x2cg/GHSA-xwv7-jv97-x2cg.json b/advisories/unreviewed/2025/05/GHSA-xwv7-jv97-x2cg/GHSA-xwv7-jv97-x2cg.json new file mode 100644 index 00000000000..c14aa3a75cd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xwv7-jv97-x2cg/GHSA-xwv7-jv97-x2cg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwv7-jv97-x2cg", + "modified": "2025-05-15T21:31:34Z", + "published": "2025-05-15T21:31:34Z", + "aliases": [ + "CVE-2025-1286" + ], + "details": "The Download HTML TinyMCE Button WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1286" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c42556c7-09b6-49ae-9f87-cbaf16e7c280" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T20:16:02Z" + } +} \ No newline at end of file