diff --git a/advisories/unreviewed/2024/02/GHSA-283m-jhf4-68hp/GHSA-283m-jhf4-68hp.json b/advisories/unreviewed/2024/02/GHSA-283m-jhf4-68hp/GHSA-283m-jhf4-68hp.json new file mode 100644 index 00000000000..6db344bfdbd --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-283m-jhf4-68hp/GHSA-283m-jhf4-68hp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-283m-jhf4-68hp", + "modified": "2024-02-01T12:30:23Z", + "published": "2024-02-01T12:30:23Z", + "aliases": [ + "CVE-2023-51694" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Epiphyt Embed Privacy allows Stored XSS.This issue affects Embed Privacy: from n/a through 1.8.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51694" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/embed-privacy/wordpress-embed-privacy-plugin-1-8-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-3298-46rv-mjjj/GHSA-3298-46rv-mjjj.json b/advisories/unreviewed/2024/02/GHSA-3298-46rv-mjjj/GHSA-3298-46rv-mjjj.json new file mode 100644 index 00000000000..a12d4ca554b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-3298-46rv-mjjj/GHSA-3298-46rv-mjjj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3298-46rv-mjjj", + "modified": "2024-02-01T12:30:23Z", + "published": "2024-02-01T12:30:23Z", + "aliases": [ + "CVE-2023-51509" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login allows Reflected XSS.This issue affects RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: from n/a through 5.2.4.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51509" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/custom-registration-form-builder-with-submission-manager/wordpress-registrationmagic-plugin-5-2-4-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T12:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-457g-xg5v-227f/GHSA-457g-xg5v-227f.json b/advisories/unreviewed/2024/02/GHSA-457g-xg5v-227f/GHSA-457g-xg5v-227f.json new file mode 100644 index 00000000000..54f330ca944 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-457g-xg5v-227f/GHSA-457g-xg5v-227f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-457g-xg5v-227f", + "modified": "2024-02-01T12:30:21Z", + "published": "2024-02-01T12:30:21Z", + "aliases": [ + "CVE-2023-52188" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson Footer Putter allows Stored XSS.This issue affects Footer Putter: from n/a through 1.17.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52188" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/footer-putter/wordpress-footer-putter-plugin-1-17-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-52rw-98p2-v2g3/GHSA-52rw-98p2-v2g3.json b/advisories/unreviewed/2024/02/GHSA-52rw-98p2-v2g3/GHSA-52rw-98p2-v2g3.json new file mode 100644 index 00000000000..24b3a7cee0f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-52rw-98p2-v2g3/GHSA-52rw-98p2-v2g3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52rw-98p2-v2g3", + "modified": "2024-02-01T12:30:23Z", + "published": "2024-02-01T12:30:23Z", + "aliases": [ + "CVE-2023-51520" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPdevelop / Oplugins WP Booking Calendar allows Stored XSS.This issue affects WP Booking Calendar: from n/a before 9.7.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51520" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/booking/wordpress-booking-calendar-plugin-9-7-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T12:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-65v7-6rgc-6f27/GHSA-65v7-6rgc-6f27.json b/advisories/unreviewed/2024/02/GHSA-65v7-6rgc-6f27/GHSA-65v7-6rgc-6f27.json new file mode 100644 index 00000000000..4b33058f9b6 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-65v7-6rgc-6f27/GHSA-65v7-6rgc-6f27.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65v7-6rgc-6f27", + "modified": "2024-02-01T12:30:21Z", + "published": "2024-02-01T12:30:21Z", + "aliases": [ + "CVE-2023-52189" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jhayghost Ideal Interactive Map allows Stored XSS.This issue affects Ideal Interactive Map: from n/a through 1.2.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52189" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ideal-interactive-map/wordpress-ideal-interactive-map-plugin-1-2-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-66qc-rgfw-8hq2/GHSA-66qc-rgfw-8hq2.json b/advisories/unreviewed/2024/02/GHSA-66qc-rgfw-8hq2/GHSA-66qc-rgfw-8hq2.json new file mode 100644 index 00000000000..02a98c67770 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-66qc-rgfw-8hq2/GHSA-66qc-rgfw-8hq2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66qc-rgfw-8hq2", + "modified": "2024-02-01T12:30:23Z", + "published": "2024-02-01T12:30:23Z", + "aliases": [ + "CVE-2023-51691" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gVectors Team Comments – wpDiscuz allows Stored XSS.This issue affects Comments – wpDiscuz: from n/a through 7.6.12.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51691" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpdiscuz/wordpress-wpdiscuz-plugin-7-6-12-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-77pp-vwgv-x2jq/GHSA-77pp-vwgv-x2jq.json b/advisories/unreviewed/2024/02/GHSA-77pp-vwgv-x2jq/GHSA-77pp-vwgv-x2jq.json new file mode 100644 index 00000000000..2c642dd2036 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-77pp-vwgv-x2jq/GHSA-77pp-vwgv-x2jq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77pp-vwgv-x2jq", + "modified": "2024-02-01T12:30:22Z", + "published": "2024-02-01T12:30:22Z", + "aliases": [ + "CVE-2023-51540" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kunal Nagar Custom 404 Pro allows Stored XSS.This issue affects Custom 404 Pro: from n/a through 3.10.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51540" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/custom-404-pro/wordpress-custom-404-pro-plugin-3-10-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-85pp-8vhv-c78m/GHSA-85pp-8vhv-c78m.json b/advisories/unreviewed/2024/02/GHSA-85pp-8vhv-c78m/GHSA-85pp-8vhv-c78m.json new file mode 100644 index 00000000000..1e8ca18a0d5 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-85pp-8vhv-c78m/GHSA-85pp-8vhv-c78m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85pp-8vhv-c78m", + "modified": "2024-02-01T12:30:22Z", + "published": "2024-02-01T12:30:22Z", + "aliases": [ + "CVE-2023-51674" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More allows Stored XSS.This issue affects Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More: from n/a through 6.9.18.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51674" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/advanced-access-manager/wordpress-advanced-access-manager-plugin-6-9-18-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-c3c7-9cj5-pr3c/GHSA-c3c7-9cj5-pr3c.json b/advisories/unreviewed/2024/02/GHSA-c3c7-9cj5-pr3c/GHSA-c3c7-9cj5-pr3c.json new file mode 100644 index 00000000000..b1f17ee8490 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-c3c7-9cj5-pr3c/GHSA-c3c7-9cj5-pr3c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3c7-9cj5-pr3c", + "modified": "2024-02-01T12:30:22Z", + "published": "2024-02-01T12:30:22Z", + "aliases": [ + "CVE-2023-51536" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms – WordPress Form Builder allows Stored XSS.This issue affects CRM Perks Forms – WordPress Form Builder: from n/a through 1.1.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51536" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/crm-perks-forms/wordpress-crm-perks-forms-plugin-1-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-cc2v-m8qh-5gfq/GHSA-cc2v-m8qh-5gfq.json b/advisories/unreviewed/2024/02/GHSA-cc2v-m8qh-5gfq/GHSA-cc2v-m8qh-5gfq.json new file mode 100644 index 00000000000..56a144c84ba --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-cc2v-m8qh-5gfq/GHSA-cc2v-m8qh-5gfq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cc2v-m8qh-5gfq", + "modified": "2024-02-01T12:30:22Z", + "published": "2024-02-01T12:30:22Z", + "aliases": [ + "CVE-2024-21750" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scribit Shortcodes Finder allows Reflected XSS.This issue affects Shortcodes Finder: from n/a through 1.5.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21750" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/shortcodes-finder/wordpress-shortcodes-finder-plugin-1-5-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-frh8-cgp4-p7vp/GHSA-frh8-cgp4-p7vp.json b/advisories/unreviewed/2024/02/GHSA-frh8-cgp4-p7vp/GHSA-frh8-cgp4-p7vp.json new file mode 100644 index 00000000000..1e02aebee62 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-frh8-cgp4-p7vp/GHSA-frh8-cgp4-p7vp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frh8-cgp4-p7vp", + "modified": "2024-02-01T12:30:23Z", + "published": "2024-02-01T12:30:23Z", + "aliases": [ + "CVE-2023-51693" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Icons allows Stored XSS.This issue affects Themify Icons: from n/a through 2.0.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51693" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/themify-icons/wordpress-themify-icons-plugin-2-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-g3v7-59j8-gvqc/GHSA-g3v7-59j8-gvqc.json b/advisories/unreviewed/2024/02/GHSA-g3v7-59j8-gvqc/GHSA-g3v7-59j8-gvqc.json new file mode 100644 index 00000000000..b42dde4b16c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-g3v7-59j8-gvqc/GHSA-g3v7-59j8-gvqc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3v7-59j8-gvqc", + "modified": "2024-02-01T12:30:22Z", + "published": "2024-02-01T12:30:22Z", + "aliases": [ + "CVE-2023-52195" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Posts to Page Kerry James allows Stored XSS.This issue affects Kerry James: from n/a through 1.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52195" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/posts-to-page/wordpress-posts-to-page-plugin-1-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-g82w-9p8c-7g8q/GHSA-g82w-9p8c-7g8q.json b/advisories/unreviewed/2024/02/GHSA-g82w-9p8c-7g8q/GHSA-g82w-9p8c-7g8q.json new file mode 100644 index 00000000000..143a77b3abf --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-g82w-9p8c-7g8q/GHSA-g82w-9p8c-7g8q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g82w-9p8c-7g8q", + "modified": "2024-02-01T12:30:23Z", + "published": "2024-02-01T12:30:23Z", + "aliases": [ + "CVE-2023-51514" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codeboxr Team CBX Bookmark & Favorite allows Stored XSS.This issue affects CBX Bookmark & Favorite: from n/a through 1.7.13.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51514" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cbxwpbookmark/wordpress-cbx-bookmark-favorite-plugin-1-7-13-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T12:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-gwfv-rx78-gch3/GHSA-gwfv-rx78-gch3.json b/advisories/unreviewed/2024/02/GHSA-gwfv-rx78-gch3/GHSA-gwfv-rx78-gch3.json new file mode 100644 index 00000000000..201d4a3f5da --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-gwfv-rx78-gch3/GHSA-gwfv-rx78-gch3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwfv-rx78-gch3", + "modified": "2024-02-01T12:30:21Z", + "published": "2024-02-01T12:30:21Z", + "aliases": [ + "CVE-2023-52193" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through 1.5.23.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52193" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/live-composer-page-builder/wordpress-page-builder-live-composer-plugin-1-5-23-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-j2p8-grvm-cx5w/GHSA-j2p8-grvm-cx5w.json b/advisories/unreviewed/2024/02/GHSA-j2p8-grvm-cx5w/GHSA-j2p8-grvm-cx5w.json new file mode 100644 index 00000000000..65d56194960 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-j2p8-grvm-cx5w/GHSA-j2p8-grvm-cx5w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2p8-grvm-cx5w", + "modified": "2024-02-01T12:30:22Z", + "published": "2024-02-01T12:30:22Z", + "aliases": [ + "CVE-2023-51677" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magazine3 Schema & Structured Data for WP & AMP allows Stored XSS.This issue affects Schema & Structured Data for WP & AMP: from n/a through 1.23.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51677" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/schema-and-structured-data-for-wp/wordpress-schema-structured-data-for-wp-amp-plugin-1-23-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-jv9f-872m-gv5x/GHSA-jv9f-872m-gv5x.json b/advisories/unreviewed/2024/02/GHSA-jv9f-872m-gv5x/GHSA-jv9f-872m-gv5x.json new file mode 100644 index 00000000000..4e0d05efa0a --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-jv9f-872m-gv5x/GHSA-jv9f-872m-gv5x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv9f-872m-gv5x", + "modified": "2024-02-01T12:30:22Z", + "published": "2024-02-01T12:30:22Z", + "aliases": [ + "CVE-2023-51532" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building allows Stored XSS.This issue affects Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building: from n/a through 3.1.19.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51532" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/icegram/wordpress-icegram-engage-plugin-3-1-19-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-m3w9-hqpm-7769/GHSA-m3w9-hqpm-7769.json b/advisories/unreviewed/2024/02/GHSA-m3w9-hqpm-7769/GHSA-m3w9-hqpm-7769.json new file mode 100644 index 00000000000..18ca9f2b734 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-m3w9-hqpm-7769/GHSA-m3w9-hqpm-7769.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3w9-hqpm-7769", + "modified": "2024-02-01T12:30:22Z", + "published": "2024-02-01T12:30:22Z", + "aliases": [ + "CVE-2023-51548" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Neil Gee SlickNav Mobile Menu allows Stored XSS.This issue affects SlickNav Mobile Menu: from n/a through 1.9.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51548" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/slicknav-mobile-menu/wordpress-slicknav-mobile-menu-plugin-1-9-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mhj8-r2ff-pfwm/GHSA-mhj8-r2ff-pfwm.json b/advisories/unreviewed/2024/02/GHSA-mhj8-r2ff-pfwm/GHSA-mhj8-r2ff-pfwm.json new file mode 100644 index 00000000000..f1f8b95d230 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mhj8-r2ff-pfwm/GHSA-mhj8-r2ff-pfwm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhj8-r2ff-pfwm", + "modified": "2024-02-01T12:30:23Z", + "published": "2024-02-01T12:30:23Z", + "aliases": [ + "CVE-2023-51690" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Advanced iFrame allows Stored XSS.This issue affects Advanced iFrame: from n/a through 2023.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51690" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/advanced-iframe/wordpress-advanced-iframe-plugin-2023-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-p52j-m9w6-3m42/GHSA-p52j-m9w6-3m42.json b/advisories/unreviewed/2024/02/GHSA-p52j-m9w6-3m42/GHSA-p52j-m9w6-3m42.json new file mode 100644 index 00000000000..78976b24b70 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-p52j-m9w6-3m42/GHSA-p52j-m9w6-3m42.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p52j-m9w6-3m42", + "modified": "2024-02-01T12:30:21Z", + "published": "2024-02-01T12:30:21Z", + "aliases": [ + "CVE-2023-52175" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Uno (miunosoft) Auto Amazon Links – Amazon Associates Affiliate Plugin allows Stored XSS.This issue affects Auto Amazon Links – Amazon Associates Affiliate Plugin: from n/a through 5.1.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52175" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/amazon-auto-links/wordpress-auto-amazon-links-amazon-associates-affiliate-plugin-5-0-5-auth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-q524-mh68-7m66/GHSA-q524-mh68-7m66.json b/advisories/unreviewed/2024/02/GHSA-q524-mh68-7m66/GHSA-q524-mh68-7m66.json new file mode 100644 index 00000000000..18051b99a96 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-q524-mh68-7m66/GHSA-q524-mh68-7m66.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q524-mh68-7m66", + "modified": "2024-02-01T12:30:22Z", + "published": "2024-02-01T12:30:22Z", + "aliases": [ + "CVE-2023-51666" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Related Post allows Stored XSS.This issue affects Related Post: from n/a through 2.0.53.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51666" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/related-post/wordpress-related-post-plugin-2-0-53-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-qx7r-whpj-fwx8/GHSA-qx7r-whpj-fwx8.json b/advisories/unreviewed/2024/02/GHSA-qx7r-whpj-fwx8/GHSA-qx7r-whpj-fwx8.json new file mode 100644 index 00000000000..a9a379d0413 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-qx7r-whpj-fwx8/GHSA-qx7r-whpj-fwx8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qx7r-whpj-fwx8", + "modified": "2024-02-01T12:30:22Z", + "published": "2024-02-01T12:30:22Z", + "aliases": [ + "CVE-2023-52194" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takayuki Miyauchi oEmbed Gist allows Stored XSS.This issue affects oEmbed Gist: from n/a through 4.9.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52194" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/oembed-gist/wordpress-oembed-gist-plugin-4-9-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-r6xh-8x5q-w7v7/GHSA-r6xh-8x5q-w7v7.json b/advisories/unreviewed/2024/02/GHSA-r6xh-8x5q-w7v7/GHSA-r6xh-8x5q-w7v7.json new file mode 100644 index 00000000000..da171f7bb01 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-r6xh-8x5q-w7v7/GHSA-r6xh-8x5q-w7v7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6xh-8x5q-w7v7", + "modified": "2024-02-01T12:30:22Z", + "published": "2024-02-01T12:30:22Z", + "aliases": [ + "CVE-2024-22449" + ], + "details": "\nDell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for critical function vulnerability. A low privileged local malicious user could potentially exploit this vulnerability to gain elevated access.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22449" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000221707/dsa-2024-028-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T10:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-r92x-24fv-xvcc/GHSA-r92x-24fv-xvcc.json b/advisories/unreviewed/2024/02/GHSA-r92x-24fv-xvcc/GHSA-r92x-24fv-xvcc.json new file mode 100644 index 00000000000..827984b068b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-r92x-24fv-xvcc/GHSA-r92x-24fv-xvcc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r92x-24fv-xvcc", + "modified": "2024-02-01T12:30:23Z", + "published": "2024-02-01T12:30:23Z", + "aliases": [ + "CVE-2023-51506" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WPCS – WordPress Currency Switcher Professional allows Stored XSS.This issue affects WPCS – WordPress Currency Switcher Professional: from n/a through 1.2.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51506" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/currency-switcher/wordpress-wpcs-plugin-1-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T12:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-rjcv-w9x4-9624/GHSA-rjcv-w9x4-9624.json b/advisories/unreviewed/2024/02/GHSA-rjcv-w9x4-9624/GHSA-rjcv-w9x4-9624.json new file mode 100644 index 00000000000..1543b4b703e --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-rjcv-w9x4-9624/GHSA-rjcv-w9x4-9624.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjcv-w9x4-9624", + "modified": "2024-02-01T12:30:22Z", + "published": "2024-02-01T12:30:22Z", + "aliases": [ + "CVE-2023-51669" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Artios Media Product Code for WooCommerce allows Stored XSS.This issue affects Product Code for WooCommerce: from n/a through 1.4.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51669" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/product-code-for-woocommerce/wordpress-product-code-for-woocommerce-plugin-1-4-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-rw8w-74p5-cf2h/GHSA-rw8w-74p5-cf2h.json b/advisories/unreviewed/2024/02/GHSA-rw8w-74p5-cf2h/GHSA-rw8w-74p5-cf2h.json new file mode 100644 index 00000000000..6c229a99676 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-rw8w-74p5-cf2h/GHSA-rw8w-74p5-cf2h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw8w-74p5-cf2h", + "modified": "2024-02-01T12:30:22Z", + "published": "2024-02-01T12:30:22Z", + "aliases": [ + "CVE-2024-22430" + ], + "details": "\nDell PowerScale OneFS versions 8.2.x through 9.6.0.x contains an incorrect default permissions vulnerability. A local low privileges malicious user could potentially exploit this vulnerability, leading to denial of service.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22430" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000221707/dsa-2024-028-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T10:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v3x4-p7hr-w52x/GHSA-v3x4-p7hr-w52x.json b/advisories/unreviewed/2024/02/GHSA-v3x4-p7hr-w52x/GHSA-v3x4-p7hr-w52x.json new file mode 100644 index 00000000000..d81137bb7fc --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-v3x4-p7hr-w52x/GHSA-v3x4-p7hr-w52x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3x4-p7hr-w52x", + "modified": "2024-02-01T12:30:23Z", + "published": "2024-02-01T12:30:23Z", + "aliases": [ + "CVE-2023-51684" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Digital Downloads Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) allows Stored XSS.This issue affects Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy): from n/a through 3.2.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51684" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/easy-digital-downloads/wordpress-easy-digital-downloads-plugin-3-2-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v5vm-g52c-4v89/GHSA-v5vm-g52c-4v89.json b/advisories/unreviewed/2024/02/GHSA-v5vm-g52c-4v89/GHSA-v5vm-g52c-4v89.json new file mode 100644 index 00000000000..c2791026351 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-v5vm-g52c-4v89/GHSA-v5vm-g52c-4v89.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5vm-g52c-4v89", + "modified": "2024-02-01T12:30:21Z", + "published": "2024-02-01T12:30:21Z", + "aliases": [ + "CVE-2023-52192" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Keap Keap Official Opt-in Forms allows Stored XSS.This issue affects Keap Official Opt-in Forms: from n/a through 1.0.11.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52192" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/infusionsoft-official-opt-in-forms/wordpress-keap-official-opt-in-forms-plugin-1-0-11-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v62h-prj4-9v6m/GHSA-v62h-prj4-9v6m.json b/advisories/unreviewed/2024/02/GHSA-v62h-prj4-9v6m/GHSA-v62h-prj4-9v6m.json new file mode 100644 index 00000000000..ea0ffe036f9 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-v62h-prj4-9v6m/GHSA-v62h-prj4-9v6m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v62h-prj4-9v6m", + "modified": "2024-02-01T12:30:21Z", + "published": "2024-02-01T12:30:21Z", + "aliases": [ + "CVE-2023-52191" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Torbjon Infogram – Add charts, maps and infographics allows Stored XSS.This issue affects Infogram – Add charts, maps and infographics: from n/a through 1.6.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52191" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/infogram/wordpress-infogram-plugin-1-6-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v82p-3pq8-jrvq/GHSA-v82p-3pq8-jrvq.json b/advisories/unreviewed/2024/02/GHSA-v82p-3pq8-jrvq/GHSA-v82p-3pq8-jrvq.json new file mode 100644 index 00000000000..18672642bb1 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-v82p-3pq8-jrvq/GHSA-v82p-3pq8-jrvq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v82p-3pq8-jrvq", + "modified": "2024-02-01T12:30:23Z", + "published": "2024-02-01T12:30:23Z", + "aliases": [ + "CVE-2023-52118" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Event Manager WP User Profile Avatar allows Stored XSS.This issue affects WP User Profile Avatar: from n/a through 1.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52118" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-user-profile-avatar/wordpress-wp-user-profile-avatar-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-wj7p-x86m-qmwx/GHSA-wj7p-x86m-qmwx.json b/advisories/unreviewed/2024/02/GHSA-wj7p-x86m-qmwx/GHSA-wj7p-x86m-qmwx.json new file mode 100644 index 00000000000..bb54946f086 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-wj7p-x86m-qmwx/GHSA-wj7p-x86m-qmwx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj7p-x86m-qmwx", + "modified": "2024-02-01T12:30:22Z", + "published": "2024-02-01T12:30:22Z", + "aliases": [ + "CVE-2023-51534" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brave Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content allows Stored XSS.This issue affects Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content: from n/a through 0.6.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51534" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/brave-popup-builder/wordpress-brave-popup-plugin-0-6-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-wrq2-h2ff-mxv5/GHSA-wrq2-h2ff-mxv5.json b/advisories/unreviewed/2024/02/GHSA-wrq2-h2ff-mxv5/GHSA-wrq2-h2ff-mxv5.json new file mode 100644 index 00000000000..c496f84c826 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-wrq2-h2ff-mxv5/GHSA-wrq2-h2ff-mxv5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrq2-h2ff-mxv5", + "modified": "2024-02-01T12:30:22Z", + "published": "2024-02-01T12:30:22Z", + "aliases": [ + "CVE-2024-22148" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Smart Editor JoomUnited allows Reflected XSS.This issue affects JoomUnited: from n/a through 1.3.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22148" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-smart-editor/wordpress-wp-smart-editor-plugin-1-3-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T10:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-x5rp-83c9-9fm7/GHSA-x5rp-83c9-9fm7.json b/advisories/unreviewed/2024/02/GHSA-x5rp-83c9-9fm7/GHSA-x5rp-83c9-9fm7.json new file mode 100644 index 00000000000..e04474425b0 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-x5rp-83c9-9fm7/GHSA-x5rp-83c9-9fm7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5rp-83c9-9fm7", + "modified": "2024-02-01T12:30:23Z", + "published": "2024-02-01T12:30:23Z", + "aliases": [ + "CVE-2023-51685" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LJ Apps WP Review Slider allows Stored XSS.This issue affects WP Review Slider: from n/a through 12.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51685" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-facebook-reviews/wordpress-wp-review-slider-plugin-12-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-xq9r-2r42-w9c6/GHSA-xq9r-2r42-w9c6.json b/advisories/unreviewed/2024/02/GHSA-xq9r-2r42-w9c6/GHSA-xq9r-2r42-w9c6.json new file mode 100644 index 00000000000..418afba5ed3 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-xq9r-2r42-w9c6/GHSA-xq9r-2r42-w9c6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xq9r-2r42-w9c6", + "modified": "2024-02-01T12:30:23Z", + "published": "2024-02-01T12:30:23Z", + "aliases": [ + "CVE-2023-51689" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in naa986 Easy Video Player allows Stored XSS.This issue affects Easy Video Player: from n/a through 1.2.2.10.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51689" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/easy-video-player/wordpress-easy-video-player-plugin-1-2-2-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-xww7-5f37-vrcg/GHSA-xww7-5f37-vrcg.json b/advisories/unreviewed/2024/02/GHSA-xww7-5f37-vrcg/GHSA-xww7-5f37-vrcg.json new file mode 100644 index 00000000000..9e838a8cd94 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-xww7-5f37-vrcg/GHSA-xww7-5f37-vrcg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xww7-5f37-vrcg", + "modified": "2024-02-01T12:30:23Z", + "published": "2024-02-01T12:30:23Z", + "aliases": [ + "CVE-2023-51695" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPEverest Everest Forms – Build Contact Forms, Surveys, Polls, Application Forms, and more with Ease! allows Stored XSS.This issue affects Everest Forms – Build Contact Forms, Surveys, Polls, Application Forms, and more with Ease!: from n/a through 2.0.4.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51695" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/everest-forms/wordpress-everest-forms-plugin-2-0-4-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-01T11:15:12Z" + } +} \ No newline at end of file