diff --git a/advisories/unreviewed/2023/03/GHSA-23q5-m4p6-fg53/GHSA-23q5-m4p6-fg53.json b/advisories/unreviewed/2023/03/GHSA-23q5-m4p6-fg53/GHSA-23q5-m4p6-fg53.json index cc8bc38a8e1..595c76cb393 100644 --- a/advisories/unreviewed/2023/03/GHSA-23q5-m4p6-fg53/GHSA-23q5-m4p6-fg53.json +++ b/advisories/unreviewed/2023/03/GHSA-23q5-m4p6-fg53/GHSA-23q5-m4p6-fg53.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-416", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/03/GHSA-3557-32f5-jwv7/GHSA-3557-32f5-jwv7.json b/advisories/unreviewed/2023/03/GHSA-3557-32f5-jwv7/GHSA-3557-32f5-jwv7.json index ca8d45aac4c..822918c680a 100644 --- a/advisories/unreviewed/2023/03/GHSA-3557-32f5-jwv7/GHSA-3557-32f5-jwv7.json +++ b/advisories/unreviewed/2023/03/GHSA-3557-32f5-jwv7/GHSA-3557-32f5-jwv7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-c4q4-j9gc-fpq4/GHSA-c4q4-j9gc-fpq4.json b/advisories/unreviewed/2023/03/GHSA-c4q4-j9gc-fpq4/GHSA-c4q4-j9gc-fpq4.json index a952b745108..c96aa24e06d 100644 --- a/advisories/unreviewed/2023/03/GHSA-c4q4-j9gc-fpq4/GHSA-c4q4-j9gc-fpq4.json +++ b/advisories/unreviewed/2023/03/GHSA-c4q4-j9gc-fpq4/GHSA-c4q4-j9gc-fpq4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-703" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-wccw-c3q8-hgg2/GHSA-wccw-c3q8-hgg2.json b/advisories/unreviewed/2023/03/GHSA-wccw-c3q8-hgg2/GHSA-wccw-c3q8-hgg2.json index a14627fe113..af19447770f 100644 --- a/advisories/unreviewed/2023/03/GHSA-wccw-c3q8-hgg2/GHSA-wccw-c3q8-hgg2.json +++ b/advisories/unreviewed/2023/03/GHSA-wccw-c3q8-hgg2/GHSA-wccw-c3q8-hgg2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-34c4-jgq5-j63f/GHSA-34c4-jgq5-j63f.json b/advisories/unreviewed/2024/03/GHSA-34c4-jgq5-j63f/GHSA-34c4-jgq5-j63f.json index 48a4e40d533..4e7a716489f 100644 --- a/advisories/unreviewed/2024/03/GHSA-34c4-jgq5-j63f/GHSA-34c4-jgq5-j63f.json +++ b/advisories/unreviewed/2024/03/GHSA-34c4-jgq5-j63f/GHSA-34c4-jgq5-j63f.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-34c4-jgq5-j63f", - "modified": "2024-03-19T15:30:33Z", + "modified": "2025-02-25T15:34:34Z", "published": "2024-03-19T15:30:33Z", "aliases": [ "CVE-2024-29130" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on allows Reflected XSS.This issue affects Contact Form 7 – PayPal & Stripe Add-on: from n/a through 2.0.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on allows Reflected XSS.This issue affects Contact Form 7 – PayPal & Stripe Add-on: from n/a through 2.0.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-6h2q-2x4r-5652/GHSA-6h2q-2x4r-5652.json b/advisories/unreviewed/2024/03/GHSA-6h2q-2x4r-5652/GHSA-6h2q-2x4r-5652.json index a44c8bb6e59..27cb10eec52 100644 --- a/advisories/unreviewed/2024/03/GHSA-6h2q-2x4r-5652/GHSA-6h2q-2x4r-5652.json +++ b/advisories/unreviewed/2024/03/GHSA-6h2q-2x4r-5652/GHSA-6h2q-2x4r-5652.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-857q-p34f-mcc7/GHSA-857q-p34f-mcc7.json b/advisories/unreviewed/2024/03/GHSA-857q-p34f-mcc7/GHSA-857q-p34f-mcc7.json index c3dff1ea19d..30a6b3ae79b 100644 --- a/advisories/unreviewed/2024/03/GHSA-857q-p34f-mcc7/GHSA-857q-p34f-mcc7.json +++ b/advisories/unreviewed/2024/03/GHSA-857q-p34f-mcc7/GHSA-857q-p34f-mcc7.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-857q-p34f-mcc7", - "modified": "2024-03-19T15:30:33Z", + "modified": "2025-02-25T15:34:34Z", "published": "2024-03-19T15:30:33Z", "aliases": [ "CVE-2024-29134" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic allows Stored XSS.This issue affects Tourfic: from n/a through 2.11.8.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic allows Stored XSS.This issue affects Tourfic: from n/a through 2.11.8.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-8mfc-4wp8-57rx/GHSA-8mfc-4wp8-57rx.json b/advisories/unreviewed/2024/03/GHSA-8mfc-4wp8-57rx/GHSA-8mfc-4wp8-57rx.json index 0e8eeb4ad7c..6cb8284f3e8 100644 --- a/advisories/unreviewed/2024/03/GHSA-8mfc-4wp8-57rx/GHSA-8mfc-4wp8-57rx.json +++ b/advisories/unreviewed/2024/03/GHSA-8mfc-4wp8-57rx/GHSA-8mfc-4wp8-57rx.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-8mfc-4wp8-57rx", - "modified": "2024-03-19T15:30:34Z", + "modified": "2025-02-25T15:34:34Z", "published": "2024-03-19T15:30:33Z", "aliases": [ "CVE-2024-29135" ], - "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Tourfic.This issue affects Tourfic: from n/a through 2.11.15.\n\n", + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Tourfic.This issue affects Tourfic: from n/a through 2.11.15.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-fj65-x2p9-c7vx/GHSA-fj65-x2p9-c7vx.json b/advisories/unreviewed/2024/03/GHSA-fj65-x2p9-c7vx/GHSA-fj65-x2p9-c7vx.json index e2ff8b4c455..730b2d26f15 100644 --- a/advisories/unreviewed/2024/03/GHSA-fj65-x2p9-c7vx/GHSA-fj65-x2p9-c7vx.json +++ b/advisories/unreviewed/2024/03/GHSA-fj65-x2p9-c7vx/GHSA-fj65-x2p9-c7vx.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-fj65-x2p9-c7vx", - "modified": "2024-03-19T15:30:34Z", + "modified": "2025-02-25T15:34:34Z", "published": "2024-03-19T15:30:34Z", "aliases": [ "CVE-2024-29136" ], - "details": "Deserialization of Untrusted Data vulnerability in Themefic Tourfic.This issue affects Tourfic: from n/a through 2.11.17.\n\n", + "details": "Deserialization of Untrusted Data vulnerability in Themefic Tourfic.This issue affects Tourfic: from n/a through 2.11.17.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-qm75-22fr-fxmp/GHSA-qm75-22fr-fxmp.json b/advisories/unreviewed/2024/03/GHSA-qm75-22fr-fxmp/GHSA-qm75-22fr-fxmp.json index 66f2a75522e..7c6100fde31 100644 --- a/advisories/unreviewed/2024/03/GHSA-qm75-22fr-fxmp/GHSA-qm75-22fr-fxmp.json +++ b/advisories/unreviewed/2024/03/GHSA-qm75-22fr-fxmp/GHSA-qm75-22fr-fxmp.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-qm75-22fr-fxmp", - "modified": "2024-03-19T15:30:34Z", + "modified": "2025-02-25T15:34:35Z", "published": "2024-03-19T15:30:34Z", "aliases": [ "CVE-2024-29138" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DEV Institute Restrict User Access – Membership Plugin with Force allows Reflected XSS.This issue affects Restrict User Access – Membership Plugin with Force: from n/a through 2.5.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DEV Institute Restrict User Access – Membership Plugin with Force allows Reflected XSS.This issue affects Restrict User Access – Membership Plugin with Force: from n/a through 2.5.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-r78f-49fx-h798/GHSA-r78f-49fx-h798.json b/advisories/unreviewed/2024/03/GHSA-r78f-49fx-h798/GHSA-r78f-49fx-h798.json index 2558a8e6b96..f066d1df941 100644 --- a/advisories/unreviewed/2024/03/GHSA-r78f-49fx-h798/GHSA-r78f-49fx-h798.json +++ b/advisories/unreviewed/2024/03/GHSA-r78f-49fx-h798/GHSA-r78f-49fx-h798.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-227g-p58c-6fwx/GHSA-227g-p58c-6fwx.json b/advisories/unreviewed/2025/02/GHSA-227g-p58c-6fwx/GHSA-227g-p58c-6fwx.json new file mode 100644 index 00000000000..e12d7e61575 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-227g-p58c-6fwx/GHSA-227g-p58c-6fwx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-227g-p58c-6fwx", + "modified": "2025-02-25T15:34:39Z", + "published": "2025-02-25T15:34:39Z", + "aliases": [ + "CVE-2025-26928" + ], + "details": "Missing Authorization vulnerability in xfinitysoft Order Limit for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Order Limit for WooCommerce: from n/a through 3.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26928" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wc-order-limit-lite/vulnerability/wordpress-order-limit-for-woocommerce-plugin-3-0-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-29m8-q2f8-5742/GHSA-29m8-q2f8-5742.json b/advisories/unreviewed/2025/02/GHSA-29m8-q2f8-5742/GHSA-29m8-q2f8-5742.json new file mode 100644 index 00000000000..abed8e7a380 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-29m8-q2f8-5742/GHSA-29m8-q2f8-5742.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29m8-q2f8-5742", + "modified": "2025-02-25T15:34:39Z", + "published": "2025-02-25T15:34:39Z", + "aliases": [ + "CVE-2025-26946" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jgwhite33 WP Yelp Review Slider allows Blind SQL Injection. This issue affects WP Yelp Review Slider: from n/a through 8.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26946" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-yelp-review-slider/vulnerability/wordpress-wp-yelp-review-slider-plugin-8-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2g2g-m4v5-68cr/GHSA-2g2g-m4v5-68cr.json b/advisories/unreviewed/2025/02/GHSA-2g2g-m4v5-68cr/GHSA-2g2g-m4v5-68cr.json index 576d41d86cc..2d6ab23e568 100644 --- a/advisories/unreviewed/2025/02/GHSA-2g2g-m4v5-68cr/GHSA-2g2g-m4v5-68cr.json +++ b/advisories/unreviewed/2025/02/GHSA-2g2g-m4v5-68cr/GHSA-2g2g-m4v5-68cr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2g2g-m4v5-68cr", - "modified": "2025-02-25T06:30:52Z", + "modified": "2025-02-25T15:34:35Z", "published": "2025-02-25T06:30:52Z", "aliases": [ "CVE-2024-10545" ], "details": "The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.9 does not sanitise and escape some of its Image settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-25T06:15:23Z" diff --git a/advisories/unreviewed/2025/02/GHSA-2h7h-8366-3477/GHSA-2h7h-8366-3477.json b/advisories/unreviewed/2025/02/GHSA-2h7h-8366-3477/GHSA-2h7h-8366-3477.json new file mode 100644 index 00000000000..40b7bcd299d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2h7h-8366-3477/GHSA-2h7h-8366-3477.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2h7h-8366-3477", + "modified": "2025-02-25T15:34:38Z", + "published": "2025-02-25T15:34:38Z", + "aliases": [ + "CVE-2025-26884" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift allows Stored XSS. This issue affects Greenshift: from n/a through 10.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26884" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/greenshift-animation-and-page-builder-blocks/vulnerability/wordpress-greenshift-plugin-10-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2jxx-xg56-m29f/GHSA-2jxx-xg56-m29f.json b/advisories/unreviewed/2025/02/GHSA-2jxx-xg56-m29f/GHSA-2jxx-xg56-m29f.json new file mode 100644 index 00000000000..b2575e55085 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2jxx-xg56-m29f/GHSA-2jxx-xg56-m29f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jxx-xg56-m29f", + "modified": "2025-02-25T15:34:39Z", + "published": "2025-02-25T15:34:39Z", + "aliases": [ + "CVE-2025-26945" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Info Cards – Gutenberg block for creating Beautiful Cards allows Stored XSS. This issue affects Info Cards – Gutenberg block for creating Beautiful Cards: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26945" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/info-cards/vulnerability/wordpress-info-cards-plugin-1-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2p6r-c283-8m75/GHSA-2p6r-c283-8m75.json b/advisories/unreviewed/2025/02/GHSA-2p6r-c283-8m75/GHSA-2p6r-c283-8m75.json new file mode 100644 index 00000000000..4dadc959d65 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2p6r-c283-8m75/GHSA-2p6r-c283-8m75.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2p6r-c283-8m75", + "modified": "2025-02-25T15:34:40Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-26957" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Deetronix Affiliate Coupons allows PHP Local File Inclusion. This issue affects Affiliate Coupons: from n/a through 1.7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26957" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/affiliate-coupons/vulnerability/wordpress-affiliate-coupons-plugin-1-7-3-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2vfq-pq87-ph87/GHSA-2vfq-pq87-ph87.json b/advisories/unreviewed/2025/02/GHSA-2vfq-pq87-ph87/GHSA-2vfq-pq87-ph87.json index 37636e5621f..4c06e2be017 100644 --- a/advisories/unreviewed/2025/02/GHSA-2vfq-pq87-ph87/GHSA-2vfq-pq87-ph87.json +++ b/advisories/unreviewed/2025/02/GHSA-2vfq-pq87-ph87/GHSA-2vfq-pq87-ph87.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2vfq-pq87-ph87", - "modified": "2025-02-25T00:31:50Z", + "modified": "2025-02-25T15:34:35Z", "published": "2025-02-25T00:31:50Z", "aliases": [ "CVE-2024-56525" ], "details": "In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-24T23:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-35rf-2xxr-prvf/GHSA-35rf-2xxr-prvf.json b/advisories/unreviewed/2025/02/GHSA-35rf-2xxr-prvf/GHSA-35rf-2xxr-prvf.json new file mode 100644 index 00000000000..c6326ff94f5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-35rf-2xxr-prvf/GHSA-35rf-2xxr-prvf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35rf-2xxr-prvf", + "modified": "2025-02-25T15:34:38Z", + "published": "2025-02-25T15:34:38Z", + "aliases": [ + "CVE-2025-26911" + ], + "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bowo System Dashboard allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects System Dashboard: from n/a through 2.8.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26911" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/system-dashboard/vulnerability/wordpress-system-dashboard-plugin-2-8-18-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3c3v-6qp8-v5gc/GHSA-3c3v-6qp8-v5gc.json b/advisories/unreviewed/2025/02/GHSA-3c3v-6qp8-v5gc/GHSA-3c3v-6qp8-v5gc.json new file mode 100644 index 00000000000..75297b68142 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3c3v-6qp8-v5gc/GHSA-3c3v-6qp8-v5gc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c3v-6qp8-v5gc", + "modified": "2025-02-25T15:34:36Z", + "published": "2025-02-25T15:34:36Z", + "aliases": [ + "CVE-2024-54444" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder allows Stored XSS. This issue affects Elementor Website Builder: from n/a through 3.25.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54444" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/elementor/vulnerability/wordpress-elementor-plugin-3-25-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3gj9-56xx-rpr3/GHSA-3gj9-56xx-rpr3.json b/advisories/unreviewed/2025/02/GHSA-3gj9-56xx-rpr3/GHSA-3gj9-56xx-rpr3.json new file mode 100644 index 00000000000..551686ddf43 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3gj9-56xx-rpr3/GHSA-3gj9-56xx-rpr3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gj9-56xx-rpr3", + "modified": "2025-02-25T15:34:40Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-26980" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wired Impact Wired Impact Volunteer Management allows Stored XSS. This issue affects Wired Impact Volunteer Management: from n/a through 2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26980" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wired-impact-volunteer-management/vulnerability/wordpress-wired-impact-volunteer-management-plugin-2-5-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3r7v-9q8r-r9gj/GHSA-3r7v-9q8r-r9gj.json b/advisories/unreviewed/2025/02/GHSA-3r7v-9q8r-r9gj/GHSA-3r7v-9q8r-r9gj.json new file mode 100644 index 00000000000..1d36e992204 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3r7v-9q8r-r9gj/GHSA-3r7v-9q8r-r9gj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3r7v-9q8r-r9gj", + "modified": "2025-02-25T15:34:41Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-26993" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vito Peleg Atarim allows Reflected XSS. This issue affects Atarim: from n/a through 4.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26993" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/atarim-visual-collaboration/vulnerability/wordpress-visual-website-collaboration-atarim-plugin-4-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4g3g-74f5-mm55/GHSA-4g3g-74f5-mm55.json b/advisories/unreviewed/2025/02/GHSA-4g3g-74f5-mm55/GHSA-4g3g-74f5-mm55.json new file mode 100644 index 00000000000..20f9a886538 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4g3g-74f5-mm55/GHSA-4g3g-74f5-mm55.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g3g-74f5-mm55", + "modified": "2025-02-25T15:34:38Z", + "published": "2025-02-25T15:34:38Z", + "aliases": [ + "CVE-2025-26912" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Easy Elementor Addons allows Stored XSS. This issue affects Easy Elementor Addons: from n/a through 2.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26912" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-elementor-addons/vulnerability/wordpress-easy-elementor-addons-plugin-2-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4jjm-xjpc-v5gr/GHSA-4jjm-xjpc-v5gr.json b/advisories/unreviewed/2025/02/GHSA-4jjm-xjpc-v5gr/GHSA-4jjm-xjpc-v5gr.json new file mode 100644 index 00000000000..3cb6cbd6c51 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4jjm-xjpc-v5gr/GHSA-4jjm-xjpc-v5gr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jjm-xjpc-v5gr", + "modified": "2025-02-25T15:34:38Z", + "published": "2025-02-25T15:34:38Z", + "aliases": [ + "CVE-2025-26891" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VW THEMES Ibtana allows Stored XSS. This issue affects Ibtana: from n/a through 1.2.4.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26891" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ibtana-visual-editor/vulnerability/wordpress-ibtana-wordpress-website-builder-plugin-1-2-4-9-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4m2j-fqxw-67j3/GHSA-4m2j-fqxw-67j3.json b/advisories/unreviewed/2025/02/GHSA-4m2j-fqxw-67j3/GHSA-4m2j-fqxw-67j3.json new file mode 100644 index 00000000000..67ee6022e9d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4m2j-fqxw-67j3/GHSA-4m2j-fqxw-67j3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m2j-fqxw-67j3", + "modified": "2025-02-25T15:34:39Z", + "published": "2025-02-25T15:34:39Z", + "aliases": [ + "CVE-2025-26932" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in QuantumCloud ChatBot allows PHP Local File Inclusion. This issue affects ChatBot: from n/a through 6.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26932" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/chatbot/vulnerability/wordpress-wpbot-plugin-6-3-5-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5g2x-3x7q-7xm2/GHSA-5g2x-3x7q-7xm2.json b/advisories/unreviewed/2025/02/GHSA-5g2x-3x7q-7xm2/GHSA-5g2x-3x7q-7xm2.json new file mode 100644 index 00000000000..1c6c313d01e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5g2x-3x7q-7xm2/GHSA-5g2x-3x7q-7xm2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g2x-3x7q-7xm2", + "modified": "2025-02-25T15:34:38Z", + "published": "2025-02-25T15:34:38Z", + "aliases": [ + "CVE-2025-26896" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vpiwigo PiwigoPress allows Stored XSS. This issue affects PiwigoPress: from n/a through 2.33.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26896" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/piwigopress/vulnerability/wordpress-piwigopress-plugin-2-33-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5h5g-vj9m-mj45/GHSA-5h5g-vj9m-mj45.json b/advisories/unreviewed/2025/02/GHSA-5h5g-vj9m-mj45/GHSA-5h5g-vj9m-mj45.json new file mode 100644 index 00000000000..845f00649e7 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5h5g-vj9m-mj45/GHSA-5h5g-vj9m-mj45.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h5g-vj9m-mj45", + "modified": "2025-02-25T15:34:40Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-27000" + ], + "details": "Missing Authorization vulnerability in George Pattichis Simple Photo Feed allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple Photo Feed: from n/a through 1.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27000" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-photo-feed/vulnerability/wordpress-simple-photo-feed-plugin-1-4-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6c2p-wjpw-5q5q/GHSA-6c2p-wjpw-5q5q.json b/advisories/unreviewed/2025/02/GHSA-6c2p-wjpw-5q5q/GHSA-6c2p-wjpw-5q5q.json new file mode 100644 index 00000000000..2263c251611 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6c2p-wjpw-5q5q/GHSA-6c2p-wjpw-5q5q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c2p-wjpw-5q5q", + "modified": "2025-02-25T15:34:39Z", + "published": "2025-02-25T15:34:38Z", + "aliases": [ + "CVE-2025-26926" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in NotFound Booknetic. This issue affects Booknetic: from n/a through 4.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26926" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/booknetic/vulnerability/wordpress-booknetic-plugin-4-0-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6c9g-h78f-78xp/GHSA-6c9g-h78f-78xp.json b/advisories/unreviewed/2025/02/GHSA-6c9g-h78f-78xp/GHSA-6c9g-h78f-78xp.json new file mode 100644 index 00000000000..651995d96fb --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6c9g-h78f-78xp/GHSA-6c9g-h78f-78xp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c9g-h78f-78xp", + "modified": "2025-02-25T15:34:38Z", + "published": "2025-02-25T15:34:37Z", + "aliases": [ + "CVE-2025-26868" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fastflow Fast Flow allows Reflected XSS. This issue affects Fast Flow: from n/a through 1.2.16.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26868" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fast-flow-dashboard/vulnerability/wordpress-fast-flow-plugin-1-2-16-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-72mp-4r3x-xmr7/GHSA-72mp-4r3x-xmr7.json b/advisories/unreviewed/2025/02/GHSA-72mp-4r3x-xmr7/GHSA-72mp-4r3x-xmr7.json new file mode 100644 index 00000000000..b2259419160 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-72mp-4r3x-xmr7/GHSA-72mp-4r3x-xmr7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72mp-4r3x-xmr7", + "modified": "2025-02-25T15:34:36Z", + "published": "2025-02-25T15:34:36Z", + "aliases": [ + "CVE-2024-51539" + ], + "details": "The Dell Secure Connect Gateway (SCG) Application and Appliance, versions prior to 5.28, contains a SQL injection vulnerability due to improper neutralization of special elements used in an SQL command. This vulnerability can only be exploited locally on the affected system. A high-privilege attacker with access to the system could potentially exploit this vulnerability, leading to the disclosure of non-sensitive information that does not include any customer data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51539" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000289550/dsa-2024-464-security-update-for-dell-secure-connect-gateway-application-and-appliance-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-86f4-3c5q-987m/GHSA-86f4-3c5q-987m.json b/advisories/unreviewed/2025/02/GHSA-86f4-3c5q-987m/GHSA-86f4-3c5q-987m.json new file mode 100644 index 00000000000..5adc65243b1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-86f4-3c5q-987m/GHSA-86f4-3c5q-987m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86f4-3c5q-987m", + "modified": "2025-02-25T15:34:40Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-26974" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPExperts.io WP Multi Store Locator allows Blind SQL Injection. This issue affects WP Multi Store Locator: from n/a through 2.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26974" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-multi-store-locator/vulnerability/wordpress-wp-multi-store-locator-plugin-2-5-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9p5c-4hgp-xhpr/GHSA-9p5c-4hgp-xhpr.json b/advisories/unreviewed/2025/02/GHSA-9p5c-4hgp-xhpr/GHSA-9p5c-4hgp-xhpr.json new file mode 100644 index 00000000000..8b0c1b36f38 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9p5c-4hgp-xhpr/GHSA-9p5c-4hgp-xhpr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9p5c-4hgp-xhpr", + "modified": "2025-02-25T15:34:36Z", + "published": "2025-02-25T15:34:35Z", + "aliases": [ + "CVE-2025-1262" + ], + "details": "The Advanced Google reCaptcha plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 1.27 . This makes it possible for unauthenticated attackers to bypass the Built-in Math Captcha Verification.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1262" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3244677/advanced-google-recaptcha" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d553aab2-d441-46d6-9c01-5dcfdc48674f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-804" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9r68-vx55-75hf/GHSA-9r68-vx55-75hf.json b/advisories/unreviewed/2025/02/GHSA-9r68-vx55-75hf/GHSA-9r68-vx55-75hf.json new file mode 100644 index 00000000000..a6b17952e14 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9r68-vx55-75hf/GHSA-9r68-vx55-75hf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r68-vx55-75hf", + "modified": "2025-02-25T15:34:38Z", + "published": "2025-02-25T15:34:38Z", + "aliases": [ + "CVE-2025-26904" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gal_op WP Responsive Auto Fit Text allows DOM-Based XSS. This issue affects WP Responsive Auto Fit Text: from n/a through 0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26904" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-responsive-slab-text/vulnerability/wordpress-wp-responsive-auto-fit-text-plugin-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9r68-wc93-mhmq/GHSA-9r68-wc93-mhmq.json b/advisories/unreviewed/2025/02/GHSA-9r68-wc93-mhmq/GHSA-9r68-wc93-mhmq.json new file mode 100644 index 00000000000..48ab8d44053 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9r68-wc93-mhmq/GHSA-9r68-wc93-mhmq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r68-wc93-mhmq", + "modified": "2025-02-25T15:34:40Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-26963" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in flowdee ClickWhale allows Cross Site Request Forgery. This issue affects ClickWhale: from n/a through 2.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26963" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/clickwhale/vulnerability/wordpress-clickwhale-plugin-2-4-3-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9rw5-3hr5-p73f/GHSA-9rw5-3hr5-p73f.json b/advisories/unreviewed/2025/02/GHSA-9rw5-3hr5-p73f/GHSA-9rw5-3hr5-p73f.json new file mode 100644 index 00000000000..286b9359f8d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9rw5-3hr5-p73f/GHSA-9rw5-3hr5-p73f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rw5-3hr5-p73f", + "modified": "2025-02-25T15:34:38Z", + "published": "2025-02-25T15:34:38Z", + "aliases": [ + "CVE-2025-26905" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estatik Estatik allows PHP Local File Inclusion. This issue affects Estatik: from n/a through 4.1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26905" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/estatik/vulnerability/wordpress-estatik-plugin-4-1-9-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9wrj-rmrc-4xx8/GHSA-9wrj-rmrc-4xx8.json b/advisories/unreviewed/2025/02/GHSA-9wrj-rmrc-4xx8/GHSA-9wrj-rmrc-4xx8.json new file mode 100644 index 00000000000..3798385d760 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9wrj-rmrc-4xx8/GHSA-9wrj-rmrc-4xx8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wrj-rmrc-4xx8", + "modified": "2025-02-25T15:34:38Z", + "published": "2025-02-25T15:34:38Z", + "aliases": [ + "CVE-2025-26887" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eli EZ SQL Reports Shortcode Widget and DB Backup allows Stored XSS. This issue affects EZ SQL Reports Shortcode Widget and DB Backup: from n/a through 5.21.35.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26887" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/elisqlreports/vulnerability/wordpress-ez-sql-reports-shortcode-widget-and-db-backup-plugin-5-21-35-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cvrc-rx86-34m4/GHSA-cvrc-rx86-34m4.json b/advisories/unreviewed/2025/02/GHSA-cvrc-rx86-34m4/GHSA-cvrc-rx86-34m4.json new file mode 100644 index 00000000000..911e584ba5c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cvrc-rx86-34m4/GHSA-cvrc-rx86-34m4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvrc-rx86-34m4", + "modified": "2025-02-25T15:34:39Z", + "published": "2025-02-25T15:34:39Z", + "aliases": [ + "CVE-2025-26935" + ], + "details": "Path Traversal vulnerability in wpjobportal WP Job Portal allows PHP Local File Inclusion. This issue affects WP Job Portal: from n/a through 2.2.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26935" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-job-portal/vulnerability/wordpress-wp-job-portal-plugin-2-2-8-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f352-5m22-68mm/GHSA-f352-5m22-68mm.json b/advisories/unreviewed/2025/02/GHSA-f352-5m22-68mm/GHSA-f352-5m22-68mm.json new file mode 100644 index 00000000000..c7389464fa7 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f352-5m22-68mm/GHSA-f352-5m22-68mm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f352-5m22-68mm", + "modified": "2025-02-25T15:34:40Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-26964" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themewinter Eventin allows PHP Local File Inclusion. This issue affects Eventin: from n/a through 4.0.20.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26964" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-event-solution/vulnerability/wordpress-eventin-plugin-4-0-20-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fh22-j9rm-v87g/GHSA-fh22-j9rm-v87g.json b/advisories/unreviewed/2025/02/GHSA-fh22-j9rm-v87g/GHSA-fh22-j9rm-v87g.json new file mode 100644 index 00000000000..9a55a7c0e71 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fh22-j9rm-v87g/GHSA-fh22-j9rm-v87g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh22-j9rm-v87g", + "modified": "2025-02-25T15:34:39Z", + "published": "2025-02-25T15:34:39Z", + "aliases": [ + "CVE-2025-26931" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Software Tribulant Gallery Voting allows Stored XSS. This issue affects Tribulant Gallery Voting: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26931" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gallery-voting/vulnerability/wordpress-tribulant-gallery-voting-plugin-1-2-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fwq7-hqf7-2g8x/GHSA-fwq7-hqf7-2g8x.json b/advisories/unreviewed/2025/02/GHSA-fwq7-hqf7-2g8x/GHSA-fwq7-hqf7-2g8x.json new file mode 100644 index 00000000000..8fa492a8d52 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fwq7-hqf7-2g8x/GHSA-fwq7-hqf7-2g8x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwq7-hqf7-2g8x", + "modified": "2025-02-25T15:34:39Z", + "published": "2025-02-25T15:34:39Z", + "aliases": [ + "CVE-2025-26947" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Services Section block allows Stored XSS. This issue affects Services Section block: from n/a through 1.3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26947" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/services-section/vulnerability/wordpress-services-section-block-plugin-1-3-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g27j-r52h-rggq/GHSA-g27j-r52h-rggq.json b/advisories/unreviewed/2025/02/GHSA-g27j-r52h-rggq/GHSA-g27j-r52h-rggq.json new file mode 100644 index 00000000000..c5e028a1acd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g27j-r52h-rggq/GHSA-g27j-r52h-rggq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g27j-r52h-rggq", + "modified": "2025-02-25T15:34:40Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-26983" + ], + "details": "Missing Authorization vulnerability in WPZOOM Recipe Card Blocks for Gutenberg & Elementor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Recipe Card Blocks for Gutenberg & Elementor: from n/a through 3.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26983" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/recipe-card-blocks-by-wpzoom/vulnerability/wordpress-recipe-card-blocks-for-gutenberg-elementor-plugin-3-4-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gfgw-h5fr-fq93/GHSA-gfgw-h5fr-fq93.json b/advisories/unreviewed/2025/02/GHSA-gfgw-h5fr-fq93/GHSA-gfgw-h5fr-fq93.json new file mode 100644 index 00000000000..a95b4f044f7 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gfgw-h5fr-fq93/GHSA-gfgw-h5fr-fq93.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfgw-h5fr-fq93", + "modified": "2025-02-25T15:34:38Z", + "published": "2025-02-25T15:34:38Z", + "aliases": [ + "CVE-2025-26915" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PickPlugins Wishlist allows SQL Injection. This issue affects Wishlist: from n/a through 1.0.41.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26915" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wishlist/vulnerability/wordpress-wishlist-plugin-1-0-41-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gj3p-qm63-8c7j/GHSA-gj3p-qm63-8c7j.json b/advisories/unreviewed/2025/02/GHSA-gj3p-qm63-8c7j/GHSA-gj3p-qm63-8c7j.json new file mode 100644 index 00000000000..ffae5d4e621 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gj3p-qm63-8c7j/GHSA-gj3p-qm63-8c7j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj3p-qm63-8c7j", + "modified": "2025-02-25T15:34:40Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-26991" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ollybach WPPizza allows Reflected XSS. This issue affects WPPizza: from n/a through 3.19.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26991" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wppizza/vulnerability/wordpress-wppizza-plugin-3-19-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gx9r-c2xr-w9xw/GHSA-gx9r-c2xr-w9xw.json b/advisories/unreviewed/2025/02/GHSA-gx9r-c2xr-w9xw/GHSA-gx9r-c2xr-w9xw.json new file mode 100644 index 00000000000..44ec32564b6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gx9r-c2xr-w9xw/GHSA-gx9r-c2xr-w9xw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx9r-c2xr-w9xw", + "modified": "2025-02-25T15:34:38Z", + "published": "2025-02-25T15:34:38Z", + "aliases": [ + "CVE-2025-26907" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Estatik Mortgage Calculator Estatik allows Stored XSS. This issue affects Mortgage Calculator Estatik: from n/a through 2.0.12.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26907" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/estatik-mortgage-calculator/vulnerability/wordpress-estatik-mortgage-calculator-plugin-2-0-12-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h24v-9p5c-3937/GHSA-h24v-9p5c-3937.json b/advisories/unreviewed/2025/02/GHSA-h24v-9p5c-3937/GHSA-h24v-9p5c-3937.json new file mode 100644 index 00000000000..051a9e7e0b1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h24v-9p5c-3937/GHSA-h24v-9p5c-3937.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h24v-9p5c-3937", + "modified": "2025-02-25T15:34:37Z", + "published": "2025-02-25T15:34:37Z", + "aliases": [ + "CVE-2025-26878" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in patternsinthecloud Autoship Cloud for WooCommerce Subscription Products allows DOM-Based XSS. This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.8.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26878" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/autoship-cloud/vulnerability/wordpress-autoship-cloud-for-woocommerce-subscription-products-plugin-2-8-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hmgj-78p9-xmxw/GHSA-hmgj-78p9-xmxw.json b/advisories/unreviewed/2025/02/GHSA-hmgj-78p9-xmxw/GHSA-hmgj-78p9-xmxw.json new file mode 100644 index 00000000000..663fab01b64 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hmgj-78p9-xmxw/GHSA-hmgj-78p9-xmxw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmgj-78p9-xmxw", + "modified": "2025-02-25T15:34:37Z", + "published": "2025-02-25T15:34:37Z", + "aliases": [ + "CVE-2025-26751" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood Alphabetic Pagination allows Reflected XSS. This issue affects Alphabetic Pagination: from n/a through 3.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26751" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/alphabetic-pagination/vulnerability/wordpress-alphabetic-pagination-plugin-3-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hwmc-7532-hg76/GHSA-hwmc-7532-hg76.json b/advisories/unreviewed/2025/02/GHSA-hwmc-7532-hg76/GHSA-hwmc-7532-hg76.json new file mode 100644 index 00000000000..f2c57bd885a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hwmc-7532-hg76/GHSA-hwmc-7532-hg76.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwmc-7532-hg76", + "modified": "2025-02-25T15:34:40Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-26977" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in Ninja Team Filebird allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Filebird: from n/a through 6.4.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26977" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/filebird/vulnerability/wordpress-filebird-plugin-6-4-2-1-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hwvx-5p97-2p8g/GHSA-hwvx-5p97-2p8g.json b/advisories/unreviewed/2025/02/GHSA-hwvx-5p97-2p8g/GHSA-hwvx-5p97-2p8g.json new file mode 100644 index 00000000000..5305ad27008 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hwvx-5p97-2p8g/GHSA-hwvx-5p97-2p8g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwvx-5p97-2p8g", + "modified": "2025-02-25T15:34:40Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-26981" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in accessiBe Web Accessibility By accessiBe allows Reflected XSS. This issue affects Web Accessibility By accessiBe: from n/a through 2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26981" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/accessibe/vulnerability/wordpress-web-accessibility-by-accessibe-plugin-2-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j2hx-x2m3-3445/GHSA-j2hx-x2m3-3445.json b/advisories/unreviewed/2025/02/GHSA-j2hx-x2m3-3445/GHSA-j2hx-x2m3-3445.json new file mode 100644 index 00000000000..61fdbb0bbcb --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-j2hx-x2m3-3445/GHSA-j2hx-x2m3-3445.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2hx-x2m3-3445", + "modified": "2025-02-25T15:34:39Z", + "published": "2025-02-25T15:34:39Z", + "aliases": [ + "CVE-2025-26937" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Icon List Block allows Stored XSS. This issue affects Icon List Block: from n/a through 1.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26937" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/icon-list-block/vulnerability/wordpress-icon-list-block-plugin-1-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jhw3-vp8x-97c7/GHSA-jhw3-vp8x-97c7.json b/advisories/unreviewed/2025/02/GHSA-jhw3-vp8x-97c7/GHSA-jhw3-vp8x-97c7.json new file mode 100644 index 00000000000..e57d3872623 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jhw3-vp8x-97c7/GHSA-jhw3-vp8x-97c7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhw3-vp8x-97c7", + "modified": "2025-02-25T15:34:40Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-26965" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in ameliabooking Amelia allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Amelia: from n/a through 1.2.16.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26965" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ameliabooking/vulnerability/wordpress-amelia-plugin-1-2-16-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jp9f-55pc-9whg/GHSA-jp9f-55pc-9whg.json b/advisories/unreviewed/2025/02/GHSA-jp9f-55pc-9whg/GHSA-jp9f-55pc-9whg.json new file mode 100644 index 00000000000..52165b430a0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jp9f-55pc-9whg/GHSA-jp9f-55pc-9whg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jp9f-55pc-9whg", + "modified": "2025-02-25T15:34:40Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-26971" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ays-pro Poll Maker allows Blind SQL Injection. This issue affects Poll Maker: from n/a through 5.6.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26971" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/poll-maker/vulnerability/wordpress-poll-maker-5-6-5-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jvp8-hjp2-h9cw/GHSA-jvp8-hjp2-h9cw.json b/advisories/unreviewed/2025/02/GHSA-jvp8-hjp2-h9cw/GHSA-jvp8-hjp2-h9cw.json new file mode 100644 index 00000000000..8a095649173 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jvp8-hjp2-h9cw/GHSA-jvp8-hjp2-h9cw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvp8-hjp2-h9cw", + "modified": "2025-02-25T15:34:37Z", + "published": "2025-02-25T15:34:37Z", + "aliases": [ + "CVE-2025-26881" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Sticky Content allows Stored XSS. This issue affects Sticky Content: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26881" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sticky-menu-block/vulnerability/wordpress-sticky-content-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mhhj-jr24-qfmx/GHSA-mhhj-jr24-qfmx.json b/advisories/unreviewed/2025/02/GHSA-mhhj-jr24-qfmx/GHSA-mhhj-jr24-qfmx.json new file mode 100644 index 00000000000..e1bd2d4af65 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mhhj-jr24-qfmx/GHSA-mhhj-jr24-qfmx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhhj-jr24-qfmx", + "modified": "2025-02-25T15:34:40Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-26975" + ], + "details": "Missing Authorization vulnerability in WP Chill Strong Testimonials allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Strong Testimonials: from n/a through 3.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26975" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/strong-testimonials/vulnerability/wordpress-strong-testimonials-plugin-3-2-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mm7q-52jr-w3r4/GHSA-mm7q-52jr-w3r4.json b/advisories/unreviewed/2025/02/GHSA-mm7q-52jr-w3r4/GHSA-mm7q-52jr-w3r4.json new file mode 100644 index 00000000000..418e78333ce --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mm7q-52jr-w3r4/GHSA-mm7q-52jr-w3r4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm7q-52jr-w3r4", + "modified": "2025-02-25T15:34:40Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-26952" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Business Card Block allows Stored XSS. This issue affects Business Card Block: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26952" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/business-card-block/vulnerability/wordpress-business-card-block-plugin-1-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mqm5-8r78-969g/GHSA-mqm5-8r78-969g.json b/advisories/unreviewed/2025/02/GHSA-mqm5-8r78-969g/GHSA-mqm5-8r78-969g.json new file mode 100644 index 00000000000..33f3d8b2d2b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mqm5-8r78-969g/GHSA-mqm5-8r78-969g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqm5-8r78-969g", + "modified": "2025-02-25T15:34:40Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-26960" + ], + "details": "Missing Authorization vulnerability in enituretechnology Small Package Quotes – Unishippers Edition allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Small Package Quotes – Unishippers Edition: from n/a through 2.4.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26960" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/small-package-quotes-unishippers-edition/vulnerability/wordpress-small-package-quotes-unishippers-edition-plugin-2-4-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mrv8-gxqf-frxh/GHSA-mrv8-gxqf-frxh.json b/advisories/unreviewed/2025/02/GHSA-mrv8-gxqf-frxh/GHSA-mrv8-gxqf-frxh.json new file mode 100644 index 00000000000..2a9897b3d4b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mrv8-gxqf-frxh/GHSA-mrv8-gxqf-frxh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrv8-gxqf-frxh", + "modified": "2025-02-25T15:34:37Z", + "published": "2025-02-25T15:34:37Z", + "aliases": [ + "CVE-2025-26871" + ], + "details": "Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Essential Blocks for Gutenberg: from n/a through 4.8.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26871" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/essential-blocks/vulnerability/wordpress-essential-blocks-plugin-4-8-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mvfp-f7rf-3rg6/GHSA-mvfp-f7rf-3rg6.json b/advisories/unreviewed/2025/02/GHSA-mvfp-f7rf-3rg6/GHSA-mvfp-f7rf-3rg6.json new file mode 100644 index 00000000000..a560268dfa5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mvfp-f7rf-3rg6/GHSA-mvfp-f7rf-3rg6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvfp-f7rf-3rg6", + "modified": "2025-02-25T15:34:39Z", + "published": "2025-02-25T15:34:39Z", + "aliases": [ + "CVE-2025-26938" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Countdown Timer allows Stored XSS. This issue affects Countdown Timer: from n/a through 1.2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26938" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/countdown-time/vulnerability/wordpress-countdown-timer-block-plugin-1-2-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p883-5vm2-vwf3/GHSA-p883-5vm2-vwf3.json b/advisories/unreviewed/2025/02/GHSA-p883-5vm2-vwf3/GHSA-p883-5vm2-vwf3.json new file mode 100644 index 00000000000..a99803203b7 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p883-5vm2-vwf3/GHSA-p883-5vm2-vwf3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p883-5vm2-vwf3", + "modified": "2025-02-25T15:34:40Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-26985" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Majestic Support Majestic Support allows PHP Local File Inclusion. This issue affects Majestic Support: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26985" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/majestic-support/vulnerability/wordpress-majestic-support-plugin-1-0-6-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p88p-prg2-q6pw/GHSA-p88p-prg2-q6pw.json b/advisories/unreviewed/2025/02/GHSA-p88p-prg2-q6pw/GHSA-p88p-prg2-q6pw.json new file mode 100644 index 00000000000..ddab1280786 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p88p-prg2-q6pw/GHSA-p88p-prg2-q6pw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p88p-prg2-q6pw", + "modified": "2025-02-25T15:34:39Z", + "published": "2025-02-25T15:34:39Z", + "aliases": [ + "CVE-2025-26939" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Counters Block allows Stored XSS. This issue affects Counters Block: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26939" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/counters-block/vulnerability/wordpress-counters-block-plugin-1-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pp8v-4g4g-j2pg/GHSA-pp8v-4g4g-j2pg.json b/advisories/unreviewed/2025/02/GHSA-pp8v-4g4g-j2pg/GHSA-pp8v-4g4g-j2pg.json new file mode 100644 index 00000000000..2d569e8f658 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pp8v-4g4g-j2pg/GHSA-pp8v-4g4g-j2pg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pp8v-4g4g-j2pg", + "modified": "2025-02-25T15:34:40Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-26987" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps allows Reflected XSS. This issue affects Frontend Admin by DynamiApps: from n/a through 3.25.17.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26987" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/acf-frontend-form-element/vulnerability/wordpress-frontend-admin-by-dynamiapps-plugin-3-25-17-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pq7h-pvch-xwc2/GHSA-pq7h-pvch-xwc2.json b/advisories/unreviewed/2025/02/GHSA-pq7h-pvch-xwc2/GHSA-pq7h-pvch-xwc2.json new file mode 100644 index 00000000000..63ded53e5fb --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pq7h-pvch-xwc2/GHSA-pq7h-pvch-xwc2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq7h-pvch-xwc2", + "modified": "2025-02-25T15:34:40Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-26979" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in FunnelKit Funnel Builder by FunnelKit allows PHP Local File Inclusion. This issue affects Funnel Builder by FunnelKit: from n/a through 3.9.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26979" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/funnel-builder/vulnerability/wordpress-funnel-builder-by-funnelkit-plugin-3-9-0-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pvf6-p87j-f9jv/GHSA-pvf6-p87j-f9jv.json b/advisories/unreviewed/2025/02/GHSA-pvf6-p87j-f9jv/GHSA-pvf6-p87j-f9jv.json new file mode 100644 index 00000000000..2d38400b3a1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pvf6-p87j-f9jv/GHSA-pvf6-p87j-f9jv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvf6-p87j-f9jv", + "modified": "2025-02-25T15:34:37Z", + "published": "2025-02-25T15:34:37Z", + "aliases": [ + "CVE-2025-26753" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper VideoWhisper Live Streaming Integration allows Path Traversal. This issue affects VideoWhisper Live Streaming Integration: from n/a through 6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26753" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/videowhisper-live-streaming-integration/vulnerability/wordpress-videowhisper-live-streaming-integration-plugin-6-2-arbitrary-file-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-px82-2r9f-582r/GHSA-px82-2r9f-582r.json b/advisories/unreviewed/2025/02/GHSA-px82-2r9f-582r/GHSA-px82-2r9f-582r.json index 2b96885aa2b..fba91d3fd62 100644 --- a/advisories/unreviewed/2025/02/GHSA-px82-2r9f-582r/GHSA-px82-2r9f-582r.json +++ b/advisories/unreviewed/2025/02/GHSA-px82-2r9f-582r/GHSA-px82-2r9f-582r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-px82-2r9f-582r", - "modified": "2025-02-25T00:31:50Z", + "modified": "2025-02-25T15:34:35Z", "published": "2025-02-25T00:31:50Z", "aliases": [ "CVE-2025-22974" ], "details": "SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-24T23:15:11Z" diff --git a/advisories/unreviewed/2025/02/GHSA-qfxj-99gm-r9jr/GHSA-qfxj-99gm-r9jr.json b/advisories/unreviewed/2025/02/GHSA-qfxj-99gm-r9jr/GHSA-qfxj-99gm-r9jr.json new file mode 100644 index 00000000000..3b410f0d4c8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qfxj-99gm-r9jr/GHSA-qfxj-99gm-r9jr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfxj-99gm-r9jr", + "modified": "2025-02-25T15:34:36Z", + "published": "2025-02-25T15:34:36Z", + "aliases": [ + "CVE-2024-34036" + ], + "details": "An issue was discovered in O-RAN Near Realtime RIC I-Release. To exploit this vulnerability, an attacker can disrupt the initial connection between a gNB and the Near RT-RIC by inundating the system with a high volume of subscription requests via an xApp.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34036" + }, + { + "type": "WEB", + "url": "https://gist.github.com/fklement/3a43dbb9fb361dddd8db7703080ade0f" + }, + { + "type": "WEB", + "url": "https://jira.o-ran-sc.org/browse/RIC-1057" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qpfp-5mrm-frcc/GHSA-qpfp-5mrm-frcc.json b/advisories/unreviewed/2025/02/GHSA-qpfp-5mrm-frcc/GHSA-qpfp-5mrm-frcc.json new file mode 100644 index 00000000000..83966a1e78b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qpfp-5mrm-frcc/GHSA-qpfp-5mrm-frcc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpfp-5mrm-frcc", + "modified": "2025-02-25T15:34:39Z", + "published": "2025-02-25T15:34:39Z", + "aliases": [ + "CVE-2025-26913" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webandprint AR For WordPress allows DOM-Based XSS. This issue affects AR For WordPress: from n/a through 7.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26913" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ar-for-wordpress/vulnerability/wordpress-ar-for-wordpress-plugin-7-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qv9x-c8c9-rpr8/GHSA-qv9x-c8c9-rpr8.json b/advisories/unreviewed/2025/02/GHSA-qv9x-c8c9-rpr8/GHSA-qv9x-c8c9-rpr8.json index 81271117443..0f88f3f6d60 100644 --- a/advisories/unreviewed/2025/02/GHSA-qv9x-c8c9-rpr8/GHSA-qv9x-c8c9-rpr8.json +++ b/advisories/unreviewed/2025/02/GHSA-qv9x-c8c9-rpr8/GHSA-qv9x-c8c9-rpr8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qv9x-c8c9-rpr8", - "modified": "2025-02-07T09:31:51Z", + "modified": "2025-02-25T15:34:35Z", "published": "2025-02-07T09:31:51Z", "aliases": [ "CVE-2025-23085" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23085" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00031.html" + }, { "type": "WEB", "url": "https://nodejs.org/en/blog/vulnerability/january-2025-security-releases" diff --git a/advisories/unreviewed/2025/02/GHSA-r94p-2q37-62rw/GHSA-r94p-2q37-62rw.json b/advisories/unreviewed/2025/02/GHSA-r94p-2q37-62rw/GHSA-r94p-2q37-62rw.json new file mode 100644 index 00000000000..d37ccfdd4bf --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r94p-2q37-62rw/GHSA-r94p-2q37-62rw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r94p-2q37-62rw", + "modified": "2025-02-25T15:34:39Z", + "published": "2025-02-25T15:34:39Z", + "aliases": [ + "CVE-2025-26949" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Team Section Block allows Stored XSS. This issue affects Team Section Block: from n/a through 1.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26949" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/team-section/vulnerability/wordpress-team-section-block-plugin-1-0-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r95f-gcgq-g8xh/GHSA-r95f-gcgq-g8xh.json b/advisories/unreviewed/2025/02/GHSA-r95f-gcgq-g8xh/GHSA-r95f-gcgq-g8xh.json new file mode 100644 index 00000000000..62d03424fb2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r95f-gcgq-g8xh/GHSA-r95f-gcgq-g8xh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r95f-gcgq-g8xh", + "modified": "2025-02-25T15:34:39Z", + "published": "2025-02-25T15:34:39Z", + "aliases": [ + "CVE-2025-26948" + ], + "details": "Missing Authorization vulnerability in NotFound Pie Register Premium. This issue affects Pie Register Premium: from n/a through 3.8.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26948" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pie-register-premium/vulnerability/wordpress-pie-register-premium-plugin-3-8-3-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rg35-696m-j8xx/GHSA-rg35-696m-j8xx.json b/advisories/unreviewed/2025/02/GHSA-rg35-696m-j8xx/GHSA-rg35-696m-j8xx.json new file mode 100644 index 00000000000..fb2fcd0d403 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rg35-696m-j8xx/GHSA-rg35-696m-j8xx.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg35-696m-j8xx", + "modified": "2025-02-25T15:34:36Z", + "published": "2025-02-25T15:34:36Z", + "aliases": [ + "CVE-2024-34035" + ], + "details": "An issue was discovered in O-RAN Near Realtime RIC H-Release. To trigger the crashing of the e2mgr, an adversary must flood the system with a significant quantity of E2 Subscription Requests originating from an xApp.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34035" + }, + { + "type": "WEB", + "url": "https://gist.github.com/fklement/3a43dbb9fb361dddd8db7703080ade0f" + }, + { + "type": "WEB", + "url": "https://jira.o-ran-sc.org/browse/RIC-1056" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rjwp-6qvm-vpfv/GHSA-rjwp-6qvm-vpfv.json b/advisories/unreviewed/2025/02/GHSA-rjwp-6qvm-vpfv/GHSA-rjwp-6qvm-vpfv.json new file mode 100644 index 00000000000..e559de8ff8d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rjwp-6qvm-vpfv/GHSA-rjwp-6qvm-vpfv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjwp-6qvm-vpfv", + "modified": "2025-02-25T15:34:40Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-26962" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Easy Contact Form Lite allows Stored XSS. This issue affects Easy Contact Form Lite : from n/a through 1.1.25.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26962" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/contact-form-lite/vulnerability/wordpress-contact-form-plugin-plugin-1-1-25-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vgwx-3jv9-43q4/GHSA-vgwx-3jv9-43q4.json b/advisories/unreviewed/2025/02/GHSA-vgwx-3jv9-43q4/GHSA-vgwx-3jv9-43q4.json new file mode 100644 index 00000000000..48a0f857b04 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vgwx-3jv9-43q4/GHSA-vgwx-3jv9-43q4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgwx-3jv9-43q4", + "modified": "2025-02-25T15:34:39Z", + "published": "2025-02-25T15:34:39Z", + "aliases": [ + "CVE-2025-26943" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jürgen Müller Easy Quotes allows Blind SQL Injection. This issue affects Easy Quotes: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26943" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-quotes/vulnerability/wordpress-easy-quotes-plugin-1-2-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vh93-mv5g-532c/GHSA-vh93-mv5g-532c.json b/advisories/unreviewed/2025/02/GHSA-vh93-mv5g-532c/GHSA-vh93-mv5g-532c.json new file mode 100644 index 00000000000..882dfb95229 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vh93-mv5g-532c/GHSA-vh93-mv5g-532c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh93-mv5g-532c", + "modified": "2025-02-25T15:34:37Z", + "published": "2025-02-25T15:34:37Z", + "aliases": [ + "CVE-2025-26752" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper VideoWhisper Live Streaming Integration allows Path Traversal. This issue affects VideoWhisper Live Streaming Integration: from n/a through 6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26752" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/videowhisper-live-streaming-integration/vulnerability/wordpress-videowhisper-live-streaming-integration-plugin-6-2-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vvh6-vwvg-3f5f/GHSA-vvh6-vwvg-3f5f.json b/advisories/unreviewed/2025/02/GHSA-vvh6-vwvg-3f5f/GHSA-vvh6-vwvg-3f5f.json new file mode 100644 index 00000000000..cf7e56d1a1e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vvh6-vwvg-3f5f/GHSA-vvh6-vwvg-3f5f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvh6-vwvg-3f5f", + "modified": "2025-02-25T15:34:38Z", + "published": "2025-02-25T15:34:38Z", + "aliases": [ + "CVE-2025-26897" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Baden List Related Attachments allows DOM-Based XSS. This issue affects List Related Attachments: from n/a through 2.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26897" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/list-related-attachments-widget/vulnerability/wordpress-list-related-attachments-plugin-2-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-w24q-f26j-wfqj/GHSA-w24q-f26j-wfqj.json b/advisories/unreviewed/2025/02/GHSA-w24q-f26j-wfqj/GHSA-w24q-f26j-wfqj.json index f5d0fab232a..d6800120d85 100644 --- a/advisories/unreviewed/2025/02/GHSA-w24q-f26j-wfqj/GHSA-w24q-f26j-wfqj.json +++ b/advisories/unreviewed/2025/02/GHSA-w24q-f26j-wfqj/GHSA-w24q-f26j-wfqj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w24q-f26j-wfqj", - "modified": "2025-02-25T00:31:50Z", + "modified": "2025-02-25T15:34:35Z", "published": "2025-02-25T00:31:50Z", "aliases": [ "CVE-2024-53544" ], "details": "NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the getCookieNames method in the smarttimeplus/MySQLConnection endpoint.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-24T23:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-wgm8-7pr6-82qh/GHSA-wgm8-7pr6-82qh.json b/advisories/unreviewed/2025/02/GHSA-wgm8-7pr6-82qh/GHSA-wgm8-7pr6-82qh.json new file mode 100644 index 00000000000..9bd2b5b2504 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wgm8-7pr6-82qh/GHSA-wgm8-7pr6-82qh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgm8-7pr6-82qh", + "modified": "2025-02-25T15:34:40Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-26995" + ], + "details": "Missing Authorization vulnerability in Anton Vanyukov Market Exporter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Market Exporter: from n/a through 2.0.21.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26995" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/market-exporter/vulnerability/wordpress-market-exporter-plugin-2-0-21-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wh3x-46jx-vcmc/GHSA-wh3x-46jx-vcmc.json b/advisories/unreviewed/2025/02/GHSA-wh3x-46jx-vcmc/GHSA-wh3x-46jx-vcmc.json new file mode 100644 index 00000000000..483873eb8f2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wh3x-46jx-vcmc/GHSA-wh3x-46jx-vcmc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh3x-46jx-vcmc", + "modified": "2025-02-25T15:34:38Z", + "published": "2025-02-25T15:34:38Z", + "aliases": [ + "CVE-2025-26893" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kiran Potphode Easy Charts allows DOM-Based XSS. This issue affects Easy Charts: from n/a through 1.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26893" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-charts/vulnerability/wordpress-easy-charts-plugin-1-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wm9h-7mh6-4c6p/GHSA-wm9h-7mh6-4c6p.json b/advisories/unreviewed/2025/02/GHSA-wm9h-7mh6-4c6p/GHSA-wm9h-7mh6-4c6p.json new file mode 100644 index 00000000000..04c275c3e70 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wm9h-7mh6-4c6p/GHSA-wm9h-7mh6-4c6p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm9h-7mh6-4c6p", + "modified": "2025-02-25T15:34:38Z", + "published": "2025-02-25T15:34:38Z", + "aliases": [ + "CVE-2025-26882" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Popup Builder allows Stored XSS. This issue affects Popup Builder: from n/a through 1.1.33.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26882" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-notify-lite/vulnerability/wordpress-popup-builder-plugin-1-1-33-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x9jq-wh6c-xg75/GHSA-x9jq-wh6c-xg75.json b/advisories/unreviewed/2025/02/GHSA-x9jq-wh6c-xg75/GHSA-x9jq-wh6c-xg75.json new file mode 100644 index 00000000000..b53ba6a76f0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x9jq-wh6c-xg75/GHSA-x9jq-wh6c-xg75.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9jq-wh6c-xg75", + "modified": "2025-02-25T15:34:40Z", + "published": "2025-02-25T15:34:40Z", + "aliases": [ + "CVE-2025-26966" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in Aldo Latino PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26966" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/private-content/vulnerability/wordpress-privatecontent-plugin-8-11-5-unauthenticated-account-takeover-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xvm3-w96c-9whc/GHSA-xvm3-w96c-9whc.json b/advisories/unreviewed/2025/02/GHSA-xvm3-w96c-9whc/GHSA-xvm3-w96c-9whc.json new file mode 100644 index 00000000000..9a6347021b9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xvm3-w96c-9whc/GHSA-xvm3-w96c-9whc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvm3-w96c-9whc", + "modified": "2025-02-25T15:34:36Z", + "published": "2025-02-25T15:34:36Z", + "aliases": [ + "CVE-2024-34034" + ], + "details": "An issue was discovered in FlexRIC 2.0.0. It crashes during a Subscription Request denial-of-service (DoS) attack, triggered by an assertion error. An attacker must send a high number of E42 Subscription Requests to the Near-RT RIC component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34034" + }, + { + "type": "WEB", + "url": "https://gist.github.com/fklement/3a43dbb9fb361dddd8db7703080ade0f" + }, + { + "type": "WEB", + "url": "https://gitlab.eurecom.fr/mosaic5g/flexric/-/tags/v2.0.0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xw96-38mm-h5jg/GHSA-xw96-38mm-h5jg.json b/advisories/unreviewed/2025/02/GHSA-xw96-38mm-h5jg/GHSA-xw96-38mm-h5jg.json new file mode 100644 index 00000000000..f05c889c8a3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xw96-38mm-h5jg/GHSA-xw96-38mm-h5jg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw96-38mm-h5jg", + "modified": "2025-02-25T15:34:38Z", + "published": "2025-02-25T15:34:38Z", + "aliases": [ + "CVE-2025-26900" + ], + "details": "Deserialization of Untrusted Data vulnerability in flexmls Flexmls® IDX allows Object Injection. This issue affects Flexmls® IDX: from n/a through 3.14.27.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26900" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/flexmls-idx/vulnerability/wordpress-flexmls-idx-plugin-plugin-3-14-27-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T15:15:25Z" + } +} \ No newline at end of file