From 6516898ff54a279a20e5e75937cf4af8bdc1e455 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 1 Apr 2025 15:33:38 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-5v6f-5gpq-2628.json | 4 +- .../GHSA-76r9-q8j4-x44w.json | 4 +- .../GHSA-8f7f-g9cj-hq6g.json | 1 + .../GHSA-j3w3-rrqq-mpx3.json | 4 +- .../GHSA-pq6j-95q4-4mhj.json | 4 +- .../GHSA-wcg7-2m9x-3hgh.json | 4 +- .../GHSA-246w-8f59-4f74.json | 6 ++- .../GHSA-43p8-gcp3-q7w4.json | 4 +- .../GHSA-h7g2-m8qw-9mfj.json | 4 +- .../GHSA-j4j6-xqv7-cqrg.json | 4 +- .../GHSA-q8g6-6p5x-cv9v.json | 4 +- .../GHSA-gq6r-j83x-w77v.json | 4 +- .../GHSA-mvc5-vcrh-v937.json | 4 +- .../GHSA-29w3-4r4c-4fmm.json | 15 ++++-- .../GHSA-429p-hfv2-984f.json | 15 ++++-- .../GHSA-4r7f-8mqg-24xx.json | 15 ++++-- .../GHSA-57fm-4q7w-88cr.json | 15 ++++-- .../GHSA-59v2-78g4-8w49.json | 11 +++-- .../GHSA-c7qr-fxvv-x4fh.json | 2 +- .../GHSA-gx79-fmcg-96m2.json | 15 ++++-- .../GHSA-hmpw-vvvc-x4mh.json | 15 ++++-- .../GHSA-qfr9-7c9v-fq5r.json | 15 ++++-- .../GHSA-2775-28vw-wjvg.json | 36 ++++++++++++++ .../GHSA-29rw-r45r-xcv9.json | 36 ++++++++++++++ .../GHSA-2cgh-f33f-2mv2.json | 36 ++++++++++++++ .../GHSA-2f7m-9j2c-gwvw.json | 37 ++++++++++++++ .../GHSA-2fxx-w44v-7wmw.json | 29 +++++++++++ .../GHSA-2mp5-jmvp-3q28.json | 36 ++++++++++++++ .../GHSA-2p25-vjp8-gcmp.json | 36 ++++++++++++++ .../GHSA-2xcc-3vq7-mvjp.json | 15 ++++-- .../GHSA-378r-2hmj-3r7x.json | 11 +++-- .../GHSA-37xw-5m35-w77m.json | 36 ++++++++++++++ .../GHSA-387v-qw2x-rwg8.json | 15 ++++-- .../GHSA-39g6-x4x8-5jcm.json | 11 +++-- .../GHSA-39gg-7hcx-j4h8.json | 36 ++++++++++++++ .../GHSA-39pr-gwj2-95p4.json | 36 ++++++++++++++ .../GHSA-3fq9-h6m7-6g68.json | 36 ++++++++++++++ .../GHSA-3g2g-jmh9-pfcp.json | 15 ++++-- .../GHSA-3hww-w3cw-c9cm.json | 36 ++++++++++++++ .../GHSA-3mx9-7xh4-v774.json | 36 ++++++++++++++ .../GHSA-3q6x-j6f7-rvxv.json | 36 ++++++++++++++ .../GHSA-3r3q-9qg7-7937.json | 36 ++++++++++++++ .../GHSA-3r56-gc76-cxqc.json | 36 ++++++++++++++ .../GHSA-3rqj-ff24-wjg9.json | 36 ++++++++++++++ .../GHSA-3v65-m7jv-mqrv.json | 36 ++++++++++++++ .../GHSA-3w56-mg6p-g5gj.json | 36 ++++++++++++++ .../GHSA-3wrf-j36w-8whq.json | 36 ++++++++++++++ .../GHSA-3x3h-5m6c-8hcx.json | 36 ++++++++++++++ .../GHSA-425v-6qh8-hmjx.json | 36 ++++++++++++++ .../GHSA-454c-45cm-g8w3.json | 36 ++++++++++++++ .../GHSA-469w-q8hj-3hr3.json | 15 ++++-- .../GHSA-4fvc-w7pw-48q6.json | 36 ++++++++++++++ .../GHSA-4v39-rw5r-p8jm.json | 36 ++++++++++++++ .../GHSA-532m-842f-wrr5.json | 36 ++++++++++++++ .../GHSA-544j-rcj5-8jv9.json | 36 ++++++++++++++ .../GHSA-54m6-4vf2-299g.json | 36 ++++++++++++++ .../GHSA-54qx-vgv3-pm7v.json | 36 ++++++++++++++ .../GHSA-57qh-fhxw-gqhr.json | 36 ++++++++++++++ .../GHSA-57xv-4vp5-7v49.json | 37 ++++++++++++++ .../GHSA-59wj-h89p-37x9.json | 15 ++++-- .../GHSA-5fm8-89vw-3fp2.json | 36 ++++++++++++++ .../GHSA-5q47-p7mr-gqmx.json | 36 ++++++++++++++ .../GHSA-5qvg-xp2f-fp45.json | 3 +- .../GHSA-5v8r-67h5-p4jj.json | 37 ++++++++++++++ .../GHSA-5w8w-w4rf-vhcw.json | 36 ++++++++++++++ .../GHSA-5wrm-m47r-jv84.json | 15 ++++-- .../GHSA-5xff-m446-cjf6.json | 36 ++++++++++++++ .../GHSA-62f2-58pp-q2wg.json | 3 +- .../GHSA-66xv-mwqh-8qmp.json | 36 ++++++++++++++ .../GHSA-6899-3jg3-5qw2.json | 36 ++++++++++++++ .../GHSA-6j6v-wqw3-w5pp.json | 36 ++++++++++++++ .../GHSA-6q93-rcg3-j5m7.json | 36 ++++++++++++++ .../GHSA-6vw3-5cc7-rmc7.json | 36 ++++++++++++++ .../GHSA-6wg6-rm5x-68cp.json | 36 ++++++++++++++ .../GHSA-6x6q-4c96-mpg8.json | 36 ++++++++++++++ .../GHSA-75jh-c6rj-5xh5.json | 36 ++++++++++++++ .../GHSA-77gh-vf7j-vj79.json | 36 ++++++++++++++ .../GHSA-78fp-h4q6-qmjg.json | 15 ++++-- .../GHSA-793h-885v-rxrh.json | 15 ++++-- .../GHSA-799g-3g44-3g9m.json | 45 +++++++++++++++++ .../GHSA-79p3-p2hc-84mg.json | 36 ++++++++++++++ .../GHSA-79r3-3rmc-6vjr.json | 36 ++++++++++++++ .../GHSA-7fpm-c83j-p8vv.json | 36 ++++++++++++++ .../GHSA-7g9x-v864-75f3.json | 15 ++++-- .../GHSA-7hw6-mmqm-76jx.json | 36 ++++++++++++++ .../GHSA-7hxq-4w6w-xgc9.json | 15 ++++-- .../GHSA-7mmq-w7cm-cxxj.json | 15 ++++-- .../GHSA-892g-82wc-7r8q.json | 3 +- .../GHSA-8cq7-m6j9-qw55.json | 36 ++++++++++++++ .../GHSA-8fhq-4v9j-268j.json | 36 ++++++++++++++ .../GHSA-8h8h-4h46-6wx3.json | 15 ++++-- .../GHSA-8jhg-mp96-62f4.json | 36 ++++++++++++++ .../GHSA-8m6g-gw2g-4vv5.json | 36 ++++++++++++++ .../GHSA-8r67-g36f-9mp8.json | 36 ++++++++++++++ .../GHSA-8r77-rxc7-qgvv.json | 45 +++++++++++++++++ .../GHSA-8r93-wf77-r46q.json | 36 ++++++++++++++ .../GHSA-8vj6-35g2-pjp7.json | 36 ++++++++++++++ .../GHSA-8w29-wh58-hrm4.json | 15 ++++-- .../GHSA-93hf-9xg9-w4v7.json | 36 ++++++++++++++ .../GHSA-95xg-2wgr-4p8c.json | 36 ++++++++++++++ .../GHSA-962p-7v75-7qmf.json | 36 ++++++++++++++ .../GHSA-9cp2-r8w6-r4vm.json | 11 +++-- .../GHSA-9f34-hg9w-62vg.json | 11 +++-- .../GHSA-9fr8-m4rq-565w.json | 36 ++++++++++++++ .../GHSA-9hjm-gm4c-vqqv.json | 15 ++++-- .../GHSA-9w9x-35h7-p37h.json | 36 ++++++++++++++ .../GHSA-9wvq-7hmr-957m.json | 36 ++++++++++++++ .../GHSA-c3hg-7pq7-vq3v.json | 36 ++++++++++++++ .../GHSA-c4r6-g2f6-2hq4.json | 36 ++++++++++++++ .../GHSA-ccfr-8pjp-64mv.json | 36 ++++++++++++++ .../GHSA-cchf-wff5-x435.json | 36 ++++++++++++++ .../GHSA-cfwh-jq9v-p2x2.json | 36 ++++++++++++++ .../GHSA-cp57-26m4-r4m3.json | 36 ++++++++++++++ .../GHSA-cqpc-66w4-95wh.json | 36 ++++++++++++++ .../GHSA-cqxv-6v33-64xx.json | 15 ++++-- .../GHSA-crwm-v9wf-m9pg.json | 15 ++++-- .../GHSA-cw4p-m5cc-276x.json | 36 ++++++++++++++ .../GHSA-cwxf-h86q-7q6r.json | 36 ++++++++++++++ .../GHSA-cx2j-f74w-54vq.json | 36 ++++++++++++++ .../GHSA-f2w5-9h42-g5cp.json | 36 ++++++++++++++ .../GHSA-f43p-rf84-7ggr.json | 36 ++++++++++++++ .../GHSA-f587-8mf8-x559.json | 36 ++++++++++++++ .../GHSA-f6cx-5vq5-842w.json | 36 ++++++++++++++ .../GHSA-ff7g-r4f4-qg7v.json | 15 ++++-- .../GHSA-fh2c-6f24-gr49.json | 36 ++++++++++++++ .../GHSA-fhx2-xjjw-gf46.json | 36 ++++++++++++++ .../GHSA-fm5m-98hc-jv89.json | 36 ++++++++++++++ .../GHSA-fqrv-m6p4-qfhh.json | 36 ++++++++++++++ .../GHSA-fr93-gm36-82pj.json | 36 ++++++++++++++ .../GHSA-frrr-xgqj-649g.json | 15 ++++-- .../GHSA-fw2v-8868-mpvm.json | 36 ++++++++++++++ .../GHSA-fx96-8pvm-r9jw.json | 36 ++++++++++++++ .../GHSA-g3r7-w9gq-5v84.json | 15 ++++-- .../GHSA-g79q-4pjf-cmvv.json | 36 ++++++++++++++ .../GHSA-ghpr-7v2r-qpx3.json | 36 ++++++++++++++ .../GHSA-gmf5-x3rp-c8p7.json | 36 ++++++++++++++ .../GHSA-gmw9-8h79-pvq5.json | 15 ++++-- .../GHSA-gpqx-3365-9jc7.json | 36 ++++++++++++++ .../GHSA-gq7f-h24x-gv8x.json | 36 ++++++++++++++ .../GHSA-gqq6-pwhg-228f.json | 36 ++++++++++++++ .../GHSA-gqqx-qfhj-4fx6.json | 36 ++++++++++++++ .../GHSA-gvwv-9mwf-hg22.json | 15 ++++-- .../GHSA-gw3m-4x3x-q7gc.json | 36 ++++++++++++++ .../GHSA-gw73-hwr2-4qrm.json | 15 ++++-- .../GHSA-gwhv-vwh6-9335.json | 36 ++++++++++++++ .../GHSA-h3xj-xc3c-cvpm.json | 37 ++++++++++++++ .../GHSA-h4xc-8mr6-vjh8.json | 36 ++++++++++++++ .../GHSA-h54m-8jjr-7jf8.json | 36 ++++++++++++++ .../GHSA-h576-hrw7-8mwg.json | 36 ++++++++++++++ .../GHSA-h94m-mjfh-2g77.json | 15 ++++-- .../GHSA-hcm9-4hpj-8jv9.json | 36 ++++++++++++++ .../GHSA-hfhj-x3c5-7mgv.json | 29 +++++++++++ .../GHSA-hh57-6jp9-f58c.json | 36 ++++++++++++++ .../GHSA-hhqx-qxvc-gw42.json | 36 ++++++++++++++ .../GHSA-hjj2-mj64-427v.json | 36 ++++++++++++++ .../GHSA-hp5h-mhh6-jhx4.json | 36 ++++++++++++++ .../GHSA-hqj2-c48q-x9m8.json | 36 ++++++++++++++ .../GHSA-hqrg-2p9v-rv84.json | 36 ++++++++++++++ .../GHSA-hvqr-qm4r-c5hx.json | 36 ++++++++++++++ .../GHSA-j34j-434j-r63c.json | 15 ++++-- .../GHSA-j7j3-j385-mfpx.json | 15 ++++-- .../GHSA-j8fj-wjcc-r62c.json | 36 ++++++++++++++ .../GHSA-jcg4-vmx5-vfm2.json | 36 ++++++++++++++ .../GHSA-jjwv-8654-h4h3.json | 36 ++++++++++++++ .../GHSA-jpj3-4vjw-5jmq.json | 36 ++++++++++++++ .../GHSA-jq4h-8p8p-vchg.json | 15 ++++-- .../GHSA-jrgv-pmf9-6qg5.json | 3 +- .../GHSA-jrrj-28wq-8v79.json | 36 ++++++++++++++ .../GHSA-jvjx-g9gr-qvr9.json | 36 ++++++++++++++ .../GHSA-jw49-5g4r-c94w.json | 11 +++-- .../GHSA-m2fw-cvrc-qphg.json | 36 ++++++++++++++ .../GHSA-m34p-f62r-g5gv.json | 36 ++++++++++++++ .../GHSA-m4g9-f5jj-53v7.json | 36 ++++++++++++++ .../GHSA-m4gw-jg94-hxh8.json | 36 ++++++++++++++ .../GHSA-m8rc-32w6-g64q.json | 36 ++++++++++++++ .../GHSA-mggf-7x7r-5cph.json | 36 ++++++++++++++ .../GHSA-mjcf-4j4v-r58f.json | 36 ++++++++++++++ .../GHSA-mjg4-f5q4-pchv.json | 36 ++++++++++++++ .../GHSA-mp8x-jgr7-fr7f.json | 36 ++++++++++++++ .../GHSA-mq5x-p6pm-hm5x.json | 36 ++++++++++++++ .../GHSA-mx5q-c52x-ghjq.json | 36 ++++++++++++++ .../GHSA-mx63-53w3-p55h.json | 36 ++++++++++++++ .../GHSA-p249-r342-v3rg.json | 36 ++++++++++++++ .../GHSA-p549-c3cg-f4qm.json | 33 +++++++++++++ .../GHSA-p572-fmvq-cqvf.json | 36 ++++++++++++++ .../GHSA-p5r8-47qx-x497.json | 49 +++++++++++++++++++ .../GHSA-p6h2-gw2p-3837.json | 36 ++++++++++++++ .../GHSA-p85h-h5h6-5xrq.json | 36 ++++++++++++++ .../GHSA-pc2x-x254-v8p4.json | 36 ++++++++++++++ .../GHSA-ph57-fhvc-5x8p.json | 36 ++++++++++++++ .../GHSA-px6w-64v3-j7gp.json | 36 ++++++++++++++ .../GHSA-q4p7-87j5-56xv.json | 36 ++++++++++++++ .../GHSA-q6jw-4hgf-xx92.json | 36 ++++++++++++++ .../GHSA-qc63-7rf8-9p8x.json | 36 ++++++++++++++ .../GHSA-qrx7-4fmv-56wc.json | 11 +++-- .../GHSA-qvv4-xwrq-f5qv.json | 34 +++++++++++++ .../GHSA-qx9q-mw3x-qjh6.json | 36 ++++++++++++++ .../GHSA-qxhm-5vqv-9j5q.json | 15 ++++-- .../GHSA-r67p-5vv5-qw2q.json | 36 ++++++++++++++ .../GHSA-r94p-hcr3-3qp9.json | 36 ++++++++++++++ .../GHSA-r9x5-x5m3-2xrf.json | 36 ++++++++++++++ .../GHSA-rc27-pgc8-phj2.json | 36 ++++++++++++++ .../GHSA-rh2r-j62v-h8x5.json | 36 ++++++++++++++ .../GHSA-rh3m-2p8j-6cf7.json | 15 ++++-- .../GHSA-rh6q-6p7c-c4fc.json | 36 ++++++++++++++ .../GHSA-rmww-278f-6fpv.json | 36 ++++++++++++++ .../GHSA-rp52-2w9h-29c9.json | 36 ++++++++++++++ .../GHSA-rppw-g286-fr24.json | 36 ++++++++++++++ .../GHSA-rpxq-378c-2wpg.json | 36 ++++++++++++++ .../GHSA-rqp3-mh44-cf98.json | 15 ++++-- .../GHSA-rrx2-wcx5-4wcq.json | 36 ++++++++++++++ .../GHSA-rw6m-2rv9-w377.json | 36 ++++++++++++++ .../GHSA-rwvj-3jx7-frmw.json | 15 ++++-- .../GHSA-rx3c-2g3m-g6mc.json | 36 ++++++++++++++ .../GHSA-v3qr-7hm5-5r4j.json | 15 ++++-- .../GHSA-v43j-97r2-rhf5.json | 36 ++++++++++++++ .../GHSA-v7jj-vhq2-vgc8.json | 15 ++++-- .../GHSA-v892-g2jf-5q7g.json | 36 ++++++++++++++ .../GHSA-vg87-mcfx-5m8m.json | 36 ++++++++++++++ .../GHSA-vhg6-m6c8-39c2.json | 43 ++++++++++++++++ .../GHSA-vhq9-x7cx-387j.json | 15 ++++-- .../GHSA-vm8m-rr8q-8rjw.json | 15 ++++-- .../GHSA-vmh7-68x6-gw3h.json | 15 ++++-- .../GHSA-vwmv-cx3v-9rvw.json | 36 ++++++++++++++ .../GHSA-vxqw-pv3j-g765.json | 36 ++++++++++++++ .../GHSA-vxrm-x722-93pv.json | 36 ++++++++++++++ .../GHSA-w5p4-prg7-wvr7.json | 36 ++++++++++++++ .../GHSA-wccc-m55j-r27w.json | 36 ++++++++++++++ .../GHSA-wcfr-cg3h-82r8.json | 36 ++++++++++++++ .../GHSA-wcmp-v3vv-5mr6.json | 36 ++++++++++++++ .../GHSA-whhr-6p94-vcj4.json | 15 ++++-- .../GHSA-wr75-hw2j-2jxm.json | 15 ++++-- .../GHSA-x289-c764-465j.json | 36 ++++++++++++++ .../GHSA-x2cq-24wc-g3f9.json | 36 ++++++++++++++ .../GHSA-x565-5fj6-vgvv.json | 36 ++++++++++++++ .../GHSA-x84x-rvq8-4mx4.json | 11 +++-- .../GHSA-x9r2-q3j2-f6x6.json | 36 ++++++++++++++ .../GHSA-xjr3-qv95-pmw4.json | 15 ++++-- .../GHSA-xmf4-8m9h-6vvh.json | 15 ++++-- .../GHSA-xqh5-95vp-q7f3.json | 36 ++++++++++++++ .../GHSA-xwxj-5cm4-pc27.json | 36 ++++++++++++++ .../GHSA-xxcr-5qmm-8wfp.json | 15 ++++-- 242 files changed, 6731 insertions(+), 234 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-2775-28vw-wjvg/GHSA-2775-28vw-wjvg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-29rw-r45r-xcv9/GHSA-29rw-r45r-xcv9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2cgh-f33f-2mv2/GHSA-2cgh-f33f-2mv2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2f7m-9j2c-gwvw/GHSA-2f7m-9j2c-gwvw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2fxx-w44v-7wmw/GHSA-2fxx-w44v-7wmw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2mp5-jmvp-3q28/GHSA-2mp5-jmvp-3q28.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2p25-vjp8-gcmp/GHSA-2p25-vjp8-gcmp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-37xw-5m35-w77m/GHSA-37xw-5m35-w77m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-39gg-7hcx-j4h8/GHSA-39gg-7hcx-j4h8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-39pr-gwj2-95p4/GHSA-39pr-gwj2-95p4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3fq9-h6m7-6g68/GHSA-3fq9-h6m7-6g68.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3hww-w3cw-c9cm/GHSA-3hww-w3cw-c9cm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3mx9-7xh4-v774/GHSA-3mx9-7xh4-v774.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3q6x-j6f7-rvxv/GHSA-3q6x-j6f7-rvxv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3r3q-9qg7-7937/GHSA-3r3q-9qg7-7937.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3r56-gc76-cxqc/GHSA-3r56-gc76-cxqc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3rqj-ff24-wjg9/GHSA-3rqj-ff24-wjg9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3v65-m7jv-mqrv/GHSA-3v65-m7jv-mqrv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3w56-mg6p-g5gj/GHSA-3w56-mg6p-g5gj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3wrf-j36w-8whq/GHSA-3wrf-j36w-8whq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3x3h-5m6c-8hcx/GHSA-3x3h-5m6c-8hcx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-425v-6qh8-hmjx/GHSA-425v-6qh8-hmjx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-454c-45cm-g8w3/GHSA-454c-45cm-g8w3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4fvc-w7pw-48q6/GHSA-4fvc-w7pw-48q6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4v39-rw5r-p8jm/GHSA-4v39-rw5r-p8jm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-532m-842f-wrr5/GHSA-532m-842f-wrr5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-544j-rcj5-8jv9/GHSA-544j-rcj5-8jv9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-54m6-4vf2-299g/GHSA-54m6-4vf2-299g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-54qx-vgv3-pm7v/GHSA-54qx-vgv3-pm7v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-57qh-fhxw-gqhr/GHSA-57qh-fhxw-gqhr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-57xv-4vp5-7v49/GHSA-57xv-4vp5-7v49.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5fm8-89vw-3fp2/GHSA-5fm8-89vw-3fp2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5q47-p7mr-gqmx/GHSA-5q47-p7mr-gqmx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5v8r-67h5-p4jj/GHSA-5v8r-67h5-p4jj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5w8w-w4rf-vhcw/GHSA-5w8w-w4rf-vhcw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5xff-m446-cjf6/GHSA-5xff-m446-cjf6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-66xv-mwqh-8qmp/GHSA-66xv-mwqh-8qmp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6899-3jg3-5qw2/GHSA-6899-3jg3-5qw2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6j6v-wqw3-w5pp/GHSA-6j6v-wqw3-w5pp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6q93-rcg3-j5m7/GHSA-6q93-rcg3-j5m7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6vw3-5cc7-rmc7/GHSA-6vw3-5cc7-rmc7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6wg6-rm5x-68cp/GHSA-6wg6-rm5x-68cp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6x6q-4c96-mpg8/GHSA-6x6q-4c96-mpg8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-75jh-c6rj-5xh5/GHSA-75jh-c6rj-5xh5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-77gh-vf7j-vj79/GHSA-77gh-vf7j-vj79.json create mode 100644 advisories/unreviewed/2025/04/GHSA-799g-3g44-3g9m/GHSA-799g-3g44-3g9m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-79p3-p2hc-84mg/GHSA-79p3-p2hc-84mg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-79r3-3rmc-6vjr/GHSA-79r3-3rmc-6vjr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7fpm-c83j-p8vv/GHSA-7fpm-c83j-p8vv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7hw6-mmqm-76jx/GHSA-7hw6-mmqm-76jx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8cq7-m6j9-qw55/GHSA-8cq7-m6j9-qw55.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8fhq-4v9j-268j/GHSA-8fhq-4v9j-268j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8jhg-mp96-62f4/GHSA-8jhg-mp96-62f4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8m6g-gw2g-4vv5/GHSA-8m6g-gw2g-4vv5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8r67-g36f-9mp8/GHSA-8r67-g36f-9mp8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8r77-rxc7-qgvv/GHSA-8r77-rxc7-qgvv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8r93-wf77-r46q/GHSA-8r93-wf77-r46q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8vj6-35g2-pjp7/GHSA-8vj6-35g2-pjp7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-93hf-9xg9-w4v7/GHSA-93hf-9xg9-w4v7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-95xg-2wgr-4p8c/GHSA-95xg-2wgr-4p8c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-962p-7v75-7qmf/GHSA-962p-7v75-7qmf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9fr8-m4rq-565w/GHSA-9fr8-m4rq-565w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9w9x-35h7-p37h/GHSA-9w9x-35h7-p37h.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9wvq-7hmr-957m/GHSA-9wvq-7hmr-957m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c3hg-7pq7-vq3v/GHSA-c3hg-7pq7-vq3v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c4r6-g2f6-2hq4/GHSA-c4r6-g2f6-2hq4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ccfr-8pjp-64mv/GHSA-ccfr-8pjp-64mv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cchf-wff5-x435/GHSA-cchf-wff5-x435.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cfwh-jq9v-p2x2/GHSA-cfwh-jq9v-p2x2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cp57-26m4-r4m3/GHSA-cp57-26m4-r4m3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cqpc-66w4-95wh/GHSA-cqpc-66w4-95wh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cw4p-m5cc-276x/GHSA-cw4p-m5cc-276x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cwxf-h86q-7q6r/GHSA-cwxf-h86q-7q6r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cx2j-f74w-54vq/GHSA-cx2j-f74w-54vq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f2w5-9h42-g5cp/GHSA-f2w5-9h42-g5cp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f43p-rf84-7ggr/GHSA-f43p-rf84-7ggr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f587-8mf8-x559/GHSA-f587-8mf8-x559.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f6cx-5vq5-842w/GHSA-f6cx-5vq5-842w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fh2c-6f24-gr49/GHSA-fh2c-6f24-gr49.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fhx2-xjjw-gf46/GHSA-fhx2-xjjw-gf46.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fm5m-98hc-jv89/GHSA-fm5m-98hc-jv89.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fqrv-m6p4-qfhh/GHSA-fqrv-m6p4-qfhh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fr93-gm36-82pj/GHSA-fr93-gm36-82pj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fw2v-8868-mpvm/GHSA-fw2v-8868-mpvm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fx96-8pvm-r9jw/GHSA-fx96-8pvm-r9jw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g79q-4pjf-cmvv/GHSA-g79q-4pjf-cmvv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ghpr-7v2r-qpx3/GHSA-ghpr-7v2r-qpx3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gmf5-x3rp-c8p7/GHSA-gmf5-x3rp-c8p7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gpqx-3365-9jc7/GHSA-gpqx-3365-9jc7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gq7f-h24x-gv8x/GHSA-gq7f-h24x-gv8x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gqq6-pwhg-228f/GHSA-gqq6-pwhg-228f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gqqx-qfhj-4fx6/GHSA-gqqx-qfhj-4fx6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gw3m-4x3x-q7gc/GHSA-gw3m-4x3x-q7gc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gwhv-vwh6-9335/GHSA-gwhv-vwh6-9335.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h3xj-xc3c-cvpm/GHSA-h3xj-xc3c-cvpm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h4xc-8mr6-vjh8/GHSA-h4xc-8mr6-vjh8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h54m-8jjr-7jf8/GHSA-h54m-8jjr-7jf8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h576-hrw7-8mwg/GHSA-h576-hrw7-8mwg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hcm9-4hpj-8jv9/GHSA-hcm9-4hpj-8jv9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hfhj-x3c5-7mgv/GHSA-hfhj-x3c5-7mgv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hh57-6jp9-f58c/GHSA-hh57-6jp9-f58c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hhqx-qxvc-gw42/GHSA-hhqx-qxvc-gw42.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hjj2-mj64-427v/GHSA-hjj2-mj64-427v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hp5h-mhh6-jhx4/GHSA-hp5h-mhh6-jhx4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hqj2-c48q-x9m8/GHSA-hqj2-c48q-x9m8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hqrg-2p9v-rv84/GHSA-hqrg-2p9v-rv84.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hvqr-qm4r-c5hx/GHSA-hvqr-qm4r-c5hx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j8fj-wjcc-r62c/GHSA-j8fj-wjcc-r62c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jcg4-vmx5-vfm2/GHSA-jcg4-vmx5-vfm2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jjwv-8654-h4h3/GHSA-jjwv-8654-h4h3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jpj3-4vjw-5jmq/GHSA-jpj3-4vjw-5jmq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jrrj-28wq-8v79/GHSA-jrrj-28wq-8v79.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jvjx-g9gr-qvr9/GHSA-jvjx-g9gr-qvr9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m2fw-cvrc-qphg/GHSA-m2fw-cvrc-qphg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m34p-f62r-g5gv/GHSA-m34p-f62r-g5gv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m4g9-f5jj-53v7/GHSA-m4g9-f5jj-53v7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m4gw-jg94-hxh8/GHSA-m4gw-jg94-hxh8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m8rc-32w6-g64q/GHSA-m8rc-32w6-g64q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mggf-7x7r-5cph/GHSA-mggf-7x7r-5cph.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mjcf-4j4v-r58f/GHSA-mjcf-4j4v-r58f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mjg4-f5q4-pchv/GHSA-mjg4-f5q4-pchv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mp8x-jgr7-fr7f/GHSA-mp8x-jgr7-fr7f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mq5x-p6pm-hm5x/GHSA-mq5x-p6pm-hm5x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mx5q-c52x-ghjq/GHSA-mx5q-c52x-ghjq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mx63-53w3-p55h/GHSA-mx63-53w3-p55h.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p249-r342-v3rg/GHSA-p249-r342-v3rg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p549-c3cg-f4qm/GHSA-p549-c3cg-f4qm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p572-fmvq-cqvf/GHSA-p572-fmvq-cqvf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p5r8-47qx-x497/GHSA-p5r8-47qx-x497.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p6h2-gw2p-3837/GHSA-p6h2-gw2p-3837.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p85h-h5h6-5xrq/GHSA-p85h-h5h6-5xrq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pc2x-x254-v8p4/GHSA-pc2x-x254-v8p4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ph57-fhvc-5x8p/GHSA-ph57-fhvc-5x8p.json create mode 100644 advisories/unreviewed/2025/04/GHSA-px6w-64v3-j7gp/GHSA-px6w-64v3-j7gp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-q4p7-87j5-56xv/GHSA-q4p7-87j5-56xv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-q6jw-4hgf-xx92/GHSA-q6jw-4hgf-xx92.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qc63-7rf8-9p8x/GHSA-qc63-7rf8-9p8x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qvv4-xwrq-f5qv/GHSA-qvv4-xwrq-f5qv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qx9q-mw3x-qjh6/GHSA-qx9q-mw3x-qjh6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r67p-5vv5-qw2q/GHSA-r67p-5vv5-qw2q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r94p-hcr3-3qp9/GHSA-r94p-hcr3-3qp9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r9x5-x5m3-2xrf/GHSA-r9x5-x5m3-2xrf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rc27-pgc8-phj2/GHSA-rc27-pgc8-phj2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rh2r-j62v-h8x5/GHSA-rh2r-j62v-h8x5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rh6q-6p7c-c4fc/GHSA-rh6q-6p7c-c4fc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rmww-278f-6fpv/GHSA-rmww-278f-6fpv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rp52-2w9h-29c9/GHSA-rp52-2w9h-29c9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rppw-g286-fr24/GHSA-rppw-g286-fr24.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rpxq-378c-2wpg/GHSA-rpxq-378c-2wpg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rrx2-wcx5-4wcq/GHSA-rrx2-wcx5-4wcq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rw6m-2rv9-w377/GHSA-rw6m-2rv9-w377.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rx3c-2g3m-g6mc/GHSA-rx3c-2g3m-g6mc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v43j-97r2-rhf5/GHSA-v43j-97r2-rhf5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v892-g2jf-5q7g/GHSA-v892-g2jf-5q7g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vg87-mcfx-5m8m/GHSA-vg87-mcfx-5m8m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vhg6-m6c8-39c2/GHSA-vhg6-m6c8-39c2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vwmv-cx3v-9rvw/GHSA-vwmv-cx3v-9rvw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vxqw-pv3j-g765/GHSA-vxqw-pv3j-g765.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vxrm-x722-93pv/GHSA-vxrm-x722-93pv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-w5p4-prg7-wvr7/GHSA-w5p4-prg7-wvr7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wccc-m55j-r27w/GHSA-wccc-m55j-r27w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wcfr-cg3h-82r8/GHSA-wcfr-cg3h-82r8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wcmp-v3vv-5mr6/GHSA-wcmp-v3vv-5mr6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x289-c764-465j/GHSA-x289-c764-465j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x2cq-24wc-g3f9/GHSA-x2cq-24wc-g3f9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x565-5fj6-vgvv/GHSA-x565-5fj6-vgvv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x9r2-q3j2-f6x6/GHSA-x9r2-q3j2-f6x6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xqh5-95vp-q7f3/GHSA-xqh5-95vp-q7f3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xwxj-5cm4-pc27/GHSA-xwxj-5cm4-pc27.json diff --git a/advisories/unreviewed/2023/01/GHSA-5v6f-5gpq-2628/GHSA-5v6f-5gpq-2628.json b/advisories/unreviewed/2023/01/GHSA-5v6f-5gpq-2628/GHSA-5v6f-5gpq-2628.json index 33817c54c24..4fc1ca1ad98 100644 --- a/advisories/unreviewed/2023/01/GHSA-5v6f-5gpq-2628/GHSA-5v6f-5gpq-2628.json +++ b/advisories/unreviewed/2023/01/GHSA-5v6f-5gpq-2628/GHSA-5v6f-5gpq-2628.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-76r9-q8j4-x44w/GHSA-76r9-q8j4-x44w.json b/advisories/unreviewed/2023/01/GHSA-76r9-q8j4-x44w/GHSA-76r9-q8j4-x44w.json index f92e78702b0..d0639cf4440 100644 --- a/advisories/unreviewed/2023/01/GHSA-76r9-q8j4-x44w/GHSA-76r9-q8j4-x44w.json +++ b/advisories/unreviewed/2023/01/GHSA-76r9-q8j4-x44w/GHSA-76r9-q8j4-x44w.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-668" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-8f7f-g9cj-hq6g/GHSA-8f7f-g9cj-hq6g.json b/advisories/unreviewed/2023/01/GHSA-8f7f-g9cj-hq6g/GHSA-8f7f-g9cj-hq6g.json index d9fe08f649d..0a7fa0deafd 100644 --- a/advisories/unreviewed/2023/01/GHSA-8f7f-g9cj-hq6g/GHSA-8f7f-g9cj-hq6g.json +++ b/advisories/unreviewed/2023/01/GHSA-8f7f-g9cj-hq6g/GHSA-8f7f-g9cj-hq6g.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/01/GHSA-j3w3-rrqq-mpx3/GHSA-j3w3-rrqq-mpx3.json b/advisories/unreviewed/2023/01/GHSA-j3w3-rrqq-mpx3/GHSA-j3w3-rrqq-mpx3.json index 6db7b49da74..d159f7f8f33 100644 --- a/advisories/unreviewed/2023/01/GHSA-j3w3-rrqq-mpx3/GHSA-j3w3-rrqq-mpx3.json +++ b/advisories/unreviewed/2023/01/GHSA-j3w3-rrqq-mpx3/GHSA-j3w3-rrqq-mpx3.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-912" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-pq6j-95q4-4mhj/GHSA-pq6j-95q4-4mhj.json b/advisories/unreviewed/2023/01/GHSA-pq6j-95q4-4mhj/GHSA-pq6j-95q4-4mhj.json index e67823dbd01..199b3b9239b 100644 --- a/advisories/unreviewed/2023/01/GHSA-pq6j-95q4-4mhj/GHSA-pq6j-95q4-4mhj.json +++ b/advisories/unreviewed/2023/01/GHSA-pq6j-95q4-4mhj/GHSA-pq6j-95q4-4mhj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-617" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-wcg7-2m9x-3hgh/GHSA-wcg7-2m9x-3hgh.json b/advisories/unreviewed/2023/01/GHSA-wcg7-2m9x-3hgh/GHSA-wcg7-2m9x-3hgh.json index 10d6d307789..3f0c0805c83 100644 --- a/advisories/unreviewed/2023/01/GHSA-wcg7-2m9x-3hgh/GHSA-wcg7-2m9x-3hgh.json +++ b/advisories/unreviewed/2023/01/GHSA-wcg7-2m9x-3hgh/GHSA-wcg7-2m9x-3hgh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-668" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-246w-8f59-4f74/GHSA-246w-8f59-4f74.json b/advisories/unreviewed/2024/02/GHSA-246w-8f59-4f74/GHSA-246w-8f59-4f74.json index 96540649e4f..0368f345c56 100644 --- a/advisories/unreviewed/2024/02/GHSA-246w-8f59-4f74/GHSA-246w-8f59-4f74.json +++ b/advisories/unreviewed/2024/02/GHSA-246w-8f59-4f74/GHSA-246w-8f59-4f74.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-246w-8f59-4f74", - "modified": "2024-02-29T03:33:15Z", + "modified": "2025-04-01T15:31:19Z", "published": "2024-02-29T03:33:14Z", "aliases": [ "CVE-2023-6923" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-43p8-gcp3-q7w4/GHSA-43p8-gcp3-q7w4.json b/advisories/unreviewed/2024/02/GHSA-43p8-gcp3-q7w4/GHSA-43p8-gcp3-q7w4.json index c0059978a0d..a120d03ca6d 100644 --- a/advisories/unreviewed/2024/02/GHSA-43p8-gcp3-q7w4/GHSA-43p8-gcp3-q7w4.json +++ b/advisories/unreviewed/2024/02/GHSA-43p8-gcp3-q7w4/GHSA-43p8-gcp3-q7w4.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-43p8-gcp3-q7w4", - "modified": "2024-02-29T03:33:18Z", + "modified": "2025-04-01T15:31:20Z", "published": "2024-02-29T03:33:18Z", "aliases": [ "CVE-2024-25931" ], - "details": "Cross-Site Request Forgery (CSRF) vulnerability in Heureka Group Heureka.This issue affects Heureka: from n/a through 1.0.8.\n\n", + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Heureka Group Heureka.This issue affects Heureka: from n/a through 1.0.8.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-h7g2-m8qw-9mfj/GHSA-h7g2-m8qw-9mfj.json b/advisories/unreviewed/2024/02/GHSA-h7g2-m8qw-9mfj/GHSA-h7g2-m8qw-9mfj.json index 41c3773ca71..061eb2dfefd 100644 --- a/advisories/unreviewed/2024/02/GHSA-h7g2-m8qw-9mfj/GHSA-h7g2-m8qw-9mfj.json +++ b/advisories/unreviewed/2024/02/GHSA-h7g2-m8qw-9mfj/GHSA-h7g2-m8qw-9mfj.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-h7g2-m8qw-9mfj", - "modified": "2024-02-28T18:30:32Z", + "modified": "2025-04-01T15:31:18Z", "published": "2024-02-28T18:30:32Z", "aliases": [ "CVE-2023-52223" ], - "details": "Cross-Site Request Forgery (CSRF) vulnerability in MailerLite MailerLite – WooCommerce integration.This issue affects MailerLite – WooCommerce integration: from n/a through 2.0.8.\n\n", + "details": "Cross-Site Request Forgery (CSRF) vulnerability in MailerLite MailerLite – WooCommerce integration.This issue affects MailerLite – WooCommerce integration: from n/a through 2.0.8.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-j4j6-xqv7-cqrg/GHSA-j4j6-xqv7-cqrg.json b/advisories/unreviewed/2024/02/GHSA-j4j6-xqv7-cqrg/GHSA-j4j6-xqv7-cqrg.json index 7914a2b976e..673382aea7f 100644 --- a/advisories/unreviewed/2024/02/GHSA-j4j6-xqv7-cqrg/GHSA-j4j6-xqv7-cqrg.json +++ b/advisories/unreviewed/2024/02/GHSA-j4j6-xqv7-cqrg/GHSA-j4j6-xqv7-cqrg.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-j4j6-xqv7-cqrg", - "modified": "2024-02-29T03:33:18Z", + "modified": "2025-04-01T15:31:20Z", "published": "2024-02-29T03:33:18Z", "aliases": [ "CVE-2024-25932" ], - "details": "Cross-Site Request Forgery (CSRF) vulnerability in Manish Kumar Agarwal Change Table Prefix.This issue affects Change Table Prefix: from n/a through 2.0.\n\n", + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Manish Kumar Agarwal Change Table Prefix.This issue affects Change Table Prefix: from n/a through 2.0.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-q8g6-6p5x-cv9v/GHSA-q8g6-6p5x-cv9v.json b/advisories/unreviewed/2024/02/GHSA-q8g6-6p5x-cv9v/GHSA-q8g6-6p5x-cv9v.json index 1b5a3bac606..880659f00f1 100644 --- a/advisories/unreviewed/2024/02/GHSA-q8g6-6p5x-cv9v/GHSA-q8g6-6p5x-cv9v.json +++ b/advisories/unreviewed/2024/02/GHSA-q8g6-6p5x-cv9v/GHSA-q8g6-6p5x-cv9v.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-q8g6-6p5x-cv9v", - "modified": "2024-02-29T06:30:33Z", + "modified": "2025-04-01T15:31:22Z", "published": "2024-02-29T06:30:33Z", "aliases": [ "CVE-2024-1437" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in José Fernandez Adsmonetizer allows Reflected XSS.This issue affects Adsmonetizer: from n/a through 3.1.2.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in José Fernandez Adsmonetizer allows Reflected XSS.This issue affects Adsmonetizer: from n/a through 3.1.2.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-gq6r-j83x-w77v/GHSA-gq6r-j83x-w77v.json b/advisories/unreviewed/2024/03/GHSA-gq6r-j83x-w77v/GHSA-gq6r-j83x-w77v.json index b3c9b6e63ee..7f38308a827 100644 --- a/advisories/unreviewed/2024/03/GHSA-gq6r-j83x-w77v/GHSA-gq6r-j83x-w77v.json +++ b/advisories/unreviewed/2024/03/GHSA-gq6r-j83x-w77v/GHSA-gq6r-j83x-w77v.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-mvc5-vcrh-v937/GHSA-mvc5-vcrh-v937.json b/advisories/unreviewed/2024/04/GHSA-mvc5-vcrh-v937/GHSA-mvc5-vcrh-v937.json index 383085b84fe..66a2b3ffbe5 100644 --- a/advisories/unreviewed/2024/04/GHSA-mvc5-vcrh-v937/GHSA-mvc5-vcrh-v937.json +++ b/advisories/unreviewed/2024/04/GHSA-mvc5-vcrh-v937/GHSA-mvc5-vcrh-v937.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-29w3-4r4c-4fmm/GHSA-29w3-4r4c-4fmm.json b/advisories/unreviewed/2025/03/GHSA-29w3-4r4c-4fmm/GHSA-29w3-4r4c-4fmm.json index 490e364a592..8541fdcf690 100644 --- a/advisories/unreviewed/2025/03/GHSA-29w3-4r4c-4fmm/GHSA-29w3-4r4c-4fmm.json +++ b/advisories/unreviewed/2025/03/GHSA-29w3-4r4c-4fmm/GHSA-29w3-4r4c-4fmm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-29w3-4r4c-4fmm", - "modified": "2025-03-31T15:30:48Z", + "modified": "2025-04-01T15:31:29Z", "published": "2025-03-31T15:30:48Z", "aliases": [ "CVE-2025-22940" ], "details": "Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T15:15:43Z" diff --git a/advisories/unreviewed/2025/03/GHSA-429p-hfv2-984f/GHSA-429p-hfv2-984f.json b/advisories/unreviewed/2025/03/GHSA-429p-hfv2-984f/GHSA-429p-hfv2-984f.json index 5fb42685f8d..ed3d4aa237b 100644 --- a/advisories/unreviewed/2025/03/GHSA-429p-hfv2-984f/GHSA-429p-hfv2-984f.json +++ b/advisories/unreviewed/2025/03/GHSA-429p-hfv2-984f/GHSA-429p-hfv2-984f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-429p-hfv2-984f", - "modified": "2025-03-31T15:30:48Z", + "modified": "2025-04-01T15:31:29Z", "published": "2025-03-31T15:30:48Z", "aliases": [ "CVE-2025-22938" ], "details": "Adtran 411 ONT L80.00.0011.M2 was discovered to contain weak default passwords.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1393" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T15:15:43Z" diff --git a/advisories/unreviewed/2025/03/GHSA-4r7f-8mqg-24xx/GHSA-4r7f-8mqg-24xx.json b/advisories/unreviewed/2025/03/GHSA-4r7f-8mqg-24xx/GHSA-4r7f-8mqg-24xx.json index aa81ea7a64e..ab15e9e6f39 100644 --- a/advisories/unreviewed/2025/03/GHSA-4r7f-8mqg-24xx/GHSA-4r7f-8mqg-24xx.json +++ b/advisories/unreviewed/2025/03/GHSA-4r7f-8mqg-24xx/GHSA-4r7f-8mqg-24xx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4r7f-8mqg-24xx", - "modified": "2025-03-29T00:31:35Z", + "modified": "2025-04-01T15:31:29Z", "published": "2025-03-29T00:31:35Z", "aliases": [ "CVE-2025-28097" ], "details": "OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-28T22:15:18Z" diff --git a/advisories/unreviewed/2025/03/GHSA-57fm-4q7w-88cr/GHSA-57fm-4q7w-88cr.json b/advisories/unreviewed/2025/03/GHSA-57fm-4q7w-88cr/GHSA-57fm-4q7w-88cr.json index 91d6111ddc0..cd0dc40119b 100644 --- a/advisories/unreviewed/2025/03/GHSA-57fm-4q7w-88cr/GHSA-57fm-4q7w-88cr.json +++ b/advisories/unreviewed/2025/03/GHSA-57fm-4q7w-88cr/GHSA-57fm-4q7w-88cr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-57fm-4q7w-88cr", - "modified": "2025-03-28T15:31:56Z", + "modified": "2025-04-01T15:31:29Z", "published": "2025-03-28T15:31:56Z", "aliases": [ "CVE-2024-48615" ], "details": "Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-28T15:15:45Z" diff --git a/advisories/unreviewed/2025/03/GHSA-59v2-78g4-8w49/GHSA-59v2-78g4-8w49.json b/advisories/unreviewed/2025/03/GHSA-59v2-78g4-8w49/GHSA-59v2-78g4-8w49.json index cfc3daaef96..7c52f60f686 100644 --- a/advisories/unreviewed/2025/03/GHSA-59v2-78g4-8w49/GHSA-59v2-78g4-8w49.json +++ b/advisories/unreviewed/2025/03/GHSA-59v2-78g4-8w49/GHSA-59v2-78g4-8w49.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-59v2-78g4-8w49", - "modified": "2025-03-26T18:30:51Z", + "modified": "2025-04-01T15:31:29Z", "published": "2025-03-26T18:30:51Z", "aliases": [ "CVE-2025-2600" ], "details": "Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated password to use the ELEVATED_PASSWORD variable even though not allowed by the \"Allow password in variable policy\". \n\n\n\n\n\nThis issue affects Remote Desktop Manager versions from 2025.1.24 through 2025.1.25, and all versions up to 2024.3.29.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-285" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-26T18:15:26Z" diff --git a/advisories/unreviewed/2025/03/GHSA-c7qr-fxvv-x4fh/GHSA-c7qr-fxvv-x4fh.json b/advisories/unreviewed/2025/03/GHSA-c7qr-fxvv-x4fh/GHSA-c7qr-fxvv-x4fh.json index 61665e03642..fb2a92d2713 100644 --- a/advisories/unreviewed/2025/03/GHSA-c7qr-fxvv-x4fh/GHSA-c7qr-fxvv-x4fh.json +++ b/advisories/unreviewed/2025/03/GHSA-c7qr-fxvv-x4fh/GHSA-c7qr-fxvv-x4fh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c7qr-fxvv-x4fh", - "modified": "2025-03-27T18:31:27Z", + "modified": "2025-04-01T15:31:29Z", "published": "2025-03-27T18:31:27Z", "aliases": [ "CVE-2023-52990" diff --git a/advisories/unreviewed/2025/03/GHSA-gx79-fmcg-96m2/GHSA-gx79-fmcg-96m2.json b/advisories/unreviewed/2025/03/GHSA-gx79-fmcg-96m2/GHSA-gx79-fmcg-96m2.json index 7490f26b624..6ce45054221 100644 --- a/advisories/unreviewed/2025/03/GHSA-gx79-fmcg-96m2/GHSA-gx79-fmcg-96m2.json +++ b/advisories/unreviewed/2025/03/GHSA-gx79-fmcg-96m2/GHSA-gx79-fmcg-96m2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gx79-fmcg-96m2", - "modified": "2025-03-31T15:30:48Z", + "modified": "2025-04-01T15:31:29Z", "published": "2025-03-31T15:30:48Z", "aliases": [ "CVE-2025-22939" ], "details": "A command injection vulnerability in the telnet service of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T15:15:43Z" diff --git a/advisories/unreviewed/2025/03/GHSA-hmpw-vvvc-x4mh/GHSA-hmpw-vvvc-x4mh.json b/advisories/unreviewed/2025/03/GHSA-hmpw-vvvc-x4mh/GHSA-hmpw-vvvc-x4mh.json index d8e61bb139b..c3b903efedf 100644 --- a/advisories/unreviewed/2025/03/GHSA-hmpw-vvvc-x4mh/GHSA-hmpw-vvvc-x4mh.json +++ b/advisories/unreviewed/2025/03/GHSA-hmpw-vvvc-x4mh/GHSA-hmpw-vvvc-x4mh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hmpw-vvvc-x4mh", - "modified": "2025-03-31T15:30:48Z", + "modified": "2025-04-01T15:31:29Z", "published": "2025-03-31T15:30:48Z", "aliases": [ "CVE-2025-22937" ], "details": "An issue in Adtran 411 ONT vL80.00.0011.M2 allows attackers to escalate privileges via unspecified vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T15:15:43Z" diff --git a/advisories/unreviewed/2025/03/GHSA-qfr9-7c9v-fq5r/GHSA-qfr9-7c9v-fq5r.json b/advisories/unreviewed/2025/03/GHSA-qfr9-7c9v-fq5r/GHSA-qfr9-7c9v-fq5r.json index 33c3c3fd098..8ba0b76ddac 100644 --- a/advisories/unreviewed/2025/03/GHSA-qfr9-7c9v-fq5r/GHSA-qfr9-7c9v-fq5r.json +++ b/advisories/unreviewed/2025/03/GHSA-qfr9-7c9v-fq5r/GHSA-qfr9-7c9v-fq5r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qfr9-7c9v-fq5r", - "modified": "2025-03-31T15:30:48Z", + "modified": "2025-04-01T15:31:29Z", "published": "2025-03-31T15:30:48Z", "aliases": [ "CVE-2025-22941" ], "details": "A command injection vulnerability in the web interface of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T15:15:43Z" diff --git a/advisories/unreviewed/2025/04/GHSA-2775-28vw-wjvg/GHSA-2775-28vw-wjvg.json b/advisories/unreviewed/2025/04/GHSA-2775-28vw-wjvg/GHSA-2775-28vw-wjvg.json new file mode 100644 index 00000000000..42f4432ca69 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2775-28vw-wjvg/GHSA-2775-28vw-wjvg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2775-28vw-wjvg", + "modified": "2025-04-01T15:31:43Z", + "published": "2025-04-01T15:31:42Z", + "aliases": [ + "CVE-2025-31839" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in digireturn DN Footer Contacts allows Cross Site Request Forgery. This issue affects DN Footer Contacts: from n/a through 1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31839" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dn-footer-contacts/vulnerability/wordpress-footer-contacts-bar-plugin-1-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-29rw-r45r-xcv9/GHSA-29rw-r45r-xcv9.json b/advisories/unreviewed/2025/04/GHSA-29rw-r45r-xcv9/GHSA-29rw-r45r-xcv9.json new file mode 100644 index 00000000000..34781cb05ea --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-29rw-r45r-xcv9/GHSA-29rw-r45r-xcv9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29rw-r45r-xcv9", + "modified": "2025-04-01T15:31:42Z", + "published": "2025-04-01T15:31:42Z", + "aliases": [ + "CVE-2025-31830" + ], + "details": "Missing Authorization vulnerability in Uriahs Victor Printus allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Printus: from n/a through 1.2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31830" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/printus-cloud-printing-for-woocommerce/vulnerability/wordpress-printus-plugin-1-2-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2cgh-f33f-2mv2/GHSA-2cgh-f33f-2mv2.json b/advisories/unreviewed/2025/04/GHSA-2cgh-f33f-2mv2/GHSA-2cgh-f33f-2mv2.json new file mode 100644 index 00000000000..121db1e4e9e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2cgh-f33f-2mv2/GHSA-2cgh-f33f-2mv2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cgh-f33f-2mv2", + "modified": "2025-04-01T15:31:35Z", + "published": "2025-04-01T15:31:35Z", + "aliases": [ + "CVE-2025-1658" + ], + "details": "A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1658" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0002" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2f7m-9j2c-gwvw/GHSA-2f7m-9j2c-gwvw.json b/advisories/unreviewed/2025/04/GHSA-2f7m-9j2c-gwvw/GHSA-2f7m-9j2c-gwvw.json new file mode 100644 index 00000000000..72998734fa4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2f7m-9j2c-gwvw/GHSA-2f7m-9j2c-gwvw.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f7m-9j2c-gwvw", + "modified": "2025-04-01T15:31:36Z", + "published": "2025-04-01T15:31:36Z", + "aliases": [ + "CVE-2025-3034" + ], + "details": "Memory safety bugs present in Firefox 136 and Thunderbird 136. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 137 and Thunderbird < 137.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3034" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1894100%2C1934086%2C1950360" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-20" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-23" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2fxx-w44v-7wmw/GHSA-2fxx-w44v-7wmw.json b/advisories/unreviewed/2025/04/GHSA-2fxx-w44v-7wmw/GHSA-2fxx-w44v-7wmw.json new file mode 100644 index 00000000000..357cadc28e6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2fxx-w44v-7wmw/GHSA-2fxx-w44v-7wmw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fxx-w44v-7wmw", + "modified": "2025-04-01T15:31:36Z", + "published": "2025-04-01T15:31:36Z", + "aliases": [ + "CVE-2025-28395" + ], + "details": "D-LINK DI-8100 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_road_asp function via the host_ip parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28395" + }, + { + "type": "WEB", + "url": "https://github.com/Fizz-L/Vulnerability-report/blob/main/DI-8100Buffer%20overflow.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2mp5-jmvp-3q28/GHSA-2mp5-jmvp-3q28.json b/advisories/unreviewed/2025/04/GHSA-2mp5-jmvp-3q28/GHSA-2mp5-jmvp-3q28.json new file mode 100644 index 00000000000..266b278e0a0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2mp5-jmvp-3q28/GHSA-2mp5-jmvp-3q28.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mp5-jmvp-3q28", + "modified": "2025-04-01T15:31:39Z", + "published": "2025-04-01T15:31:39Z", + "aliases": [ + "CVE-2025-31782" + ], + "details": "Missing Authorization vulnerability in pupunzi mb.YTPlayer allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects mb.YTPlayer: from n/a through 3.3.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31782" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpmbytplayer/vulnerability/wordpress-mb-ytplayer-plugin-3-3-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2p25-vjp8-gcmp/GHSA-2p25-vjp8-gcmp.json b/advisories/unreviewed/2025/04/GHSA-2p25-vjp8-gcmp/GHSA-2p25-vjp8-gcmp.json new file mode 100644 index 00000000000..c4d052add9a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2p25-vjp8-gcmp/GHSA-2p25-vjp8-gcmp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2p25-vjp8-gcmp", + "modified": "2025-04-01T15:31:38Z", + "published": "2025-04-01T15:31:38Z", + "aliases": [ + "CVE-2025-31763" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Preliot Cache control by Cacholong allows Cross Site Request Forgery. This issue affects Cache control by Cacholong: from n/a through 5.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31763" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cache-control-by-cacholong/vulnerability/wordpress-cache-control-by-cacholong-plugin-5-4-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2xcc-3vq7-mvjp/GHSA-2xcc-3vq7-mvjp.json b/advisories/unreviewed/2025/04/GHSA-2xcc-3vq7-mvjp/GHSA-2xcc-3vq7-mvjp.json index 4241534090a..7231adda9ed 100644 --- a/advisories/unreviewed/2025/04/GHSA-2xcc-3vq7-mvjp/GHSA-2xcc-3vq7-mvjp.json +++ b/advisories/unreviewed/2025/04/GHSA-2xcc-3vq7-mvjp/GHSA-2xcc-3vq7-mvjp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2xcc-3vq7-mvjp", - "modified": "2025-04-01T00:30:42Z", + "modified": "2025-04-01T15:31:32Z", "published": "2025-04-01T00:30:42Z", "aliases": [ "CVE-2025-30434" ], "details": "The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.4 and iPadOS 18.4. Processing a maliciously crafted file may lead to a cross site scripting attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:25Z" diff --git a/advisories/unreviewed/2025/04/GHSA-378r-2hmj-3r7x/GHSA-378r-2hmj-3r7x.json b/advisories/unreviewed/2025/04/GHSA-378r-2hmj-3r7x/GHSA-378r-2hmj-3r7x.json index 7248c44053e..01e5f9b2be9 100644 --- a/advisories/unreviewed/2025/04/GHSA-378r-2hmj-3r7x/GHSA-378r-2hmj-3r7x.json +++ b/advisories/unreviewed/2025/04/GHSA-378r-2hmj-3r7x/GHSA-378r-2hmj-3r7x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-378r-2hmj-3r7x", - "modified": "2025-04-01T00:30:37Z", + "modified": "2025-04-01T15:31:30Z", "published": "2025-04-01T00:30:37Z", "aliases": [ "CVE-2025-24203" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:18Z" diff --git a/advisories/unreviewed/2025/04/GHSA-37xw-5m35-w77m/GHSA-37xw-5m35-w77m.json b/advisories/unreviewed/2025/04/GHSA-37xw-5m35-w77m/GHSA-37xw-5m35-w77m.json new file mode 100644 index 00000000000..6aac86fc664 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-37xw-5m35-w77m/GHSA-37xw-5m35-w77m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37xw-5m35-w77m", + "modified": "2025-04-01T15:31:44Z", + "published": "2025-04-01T15:31:44Z", + "aliases": [ + "CVE-2025-31868" + ], + "details": "Missing Authorization vulnerability in JoomSky JS Job Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JS Job Manager: from n/a through 2.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31868" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/js-jobs/vulnerability/wordpress-js-job-manager-plugin-2-0-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-387v-qw2x-rwg8/GHSA-387v-qw2x-rwg8.json b/advisories/unreviewed/2025/04/GHSA-387v-qw2x-rwg8/GHSA-387v-qw2x-rwg8.json index b9f6735a180..6e7a2137bd4 100644 --- a/advisories/unreviewed/2025/04/GHSA-387v-qw2x-rwg8/GHSA-387v-qw2x-rwg8.json +++ b/advisories/unreviewed/2025/04/GHSA-387v-qw2x-rwg8/GHSA-387v-qw2x-rwg8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-387v-qw2x-rwg8", - "modified": "2025-04-01T00:30:40Z", + "modified": "2025-04-01T15:31:30Z", "published": "2025-04-01T00:30:40Z", "aliases": [ "CVE-2025-24260" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker in a privileged position may be able to perform a denial-of-service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:22Z" diff --git a/advisories/unreviewed/2025/04/GHSA-39g6-x4x8-5jcm/GHSA-39g6-x4x8-5jcm.json b/advisories/unreviewed/2025/04/GHSA-39g6-x4x8-5jcm/GHSA-39g6-x4x8-5jcm.json index 265a5025476..763b286151c 100644 --- a/advisories/unreviewed/2025/04/GHSA-39g6-x4x8-5jcm/GHSA-39g6-x4x8-5jcm.json +++ b/advisories/unreviewed/2025/04/GHSA-39g6-x4x8-5jcm/GHSA-39g6-x4x8-5jcm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-39g6-x4x8-5jcm", - "modified": "2025-04-01T00:30:35Z", + "modified": "2025-04-01T15:31:29Z", "published": "2025-04-01T00:30:35Z", "aliases": [ "CVE-2025-3057" ], "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, from 11.1.0 before 11.1.3.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T22:15:23Z" diff --git a/advisories/unreviewed/2025/04/GHSA-39gg-7hcx-j4h8/GHSA-39gg-7hcx-j4h8.json b/advisories/unreviewed/2025/04/GHSA-39gg-7hcx-j4h8/GHSA-39gg-7hcx-j4h8.json new file mode 100644 index 00000000000..04071041274 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-39gg-7hcx-j4h8/GHSA-39gg-7hcx-j4h8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39gg-7hcx-j4h8", + "modified": "2025-04-01T15:31:41Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31809" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Labinator Labinator Content Types Duplicator allows Cross Site Request Forgery. This issue affects Labinator Content Types Duplicator: from n/a through 1.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31809" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/labinator-content-types-duplicator/vulnerability/wordpress-labinator-content-types-duplicator-plugin-1-1-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-39pr-gwj2-95p4/GHSA-39pr-gwj2-95p4.json b/advisories/unreviewed/2025/04/GHSA-39pr-gwj2-95p4/GHSA-39pr-gwj2-95p4.json new file mode 100644 index 00000000000..a7cfbf38d9a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-39pr-gwj2-95p4/GHSA-39pr-gwj2-95p4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39pr-gwj2-95p4", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31877" + ], + "details": "Missing Authorization vulnerability in Magnigenie RestroPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RestroPress: from n/a through 3.1.8.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31877" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/restropress/vulnerability/wordpress-restropress-plugin-3-1-8-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3fq9-h6m7-6g68/GHSA-3fq9-h6m7-6g68.json b/advisories/unreviewed/2025/04/GHSA-3fq9-h6m7-6g68/GHSA-3fq9-h6m7-6g68.json new file mode 100644 index 00000000000..bd907da0685 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3fq9-h6m7-6g68/GHSA-3fq9-h6m7-6g68.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fq9-h6m7-6g68", + "modified": "2025-04-01T15:31:43Z", + "published": "2025-04-01T15:31:43Z", + "aliases": [ + "CVE-2025-31850" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RedefiningTheWeb PDF Generator Addon for Elementor Page Builder allows Stored XSS. This issue affects PDF Generator Addon for Elementor Page Builder: from n/a through 1.7.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31850" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pdf-generator-addon-for-elementor-page-builder/vulnerability/wordpress-pdf-generator-addon-for-elementor-page-builder-plugin-1-7-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3g2g-jmh9-pfcp/GHSA-3g2g-jmh9-pfcp.json b/advisories/unreviewed/2025/04/GHSA-3g2g-jmh9-pfcp/GHSA-3g2g-jmh9-pfcp.json index 78d4ef651f6..d25b59632c2 100644 --- a/advisories/unreviewed/2025/04/GHSA-3g2g-jmh9-pfcp/GHSA-3g2g-jmh9-pfcp.json +++ b/advisories/unreviewed/2025/04/GHSA-3g2g-jmh9-pfcp/GHSA-3g2g-jmh9-pfcp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3g2g-jmh9-pfcp", - "modified": "2025-04-01T00:30:38Z", + "modified": "2025-04-01T15:31:30Z", "published": "2025-04-01T00:30:38Z", "aliases": [ "CVE-2025-24233" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to read or write to protected files.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-3hww-w3cw-c9cm/GHSA-3hww-w3cw-c9cm.json b/advisories/unreviewed/2025/04/GHSA-3hww-w3cw-c9cm/GHSA-3hww-w3cw-c9cm.json new file mode 100644 index 00000000000..35a2cf23357 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3hww-w3cw-c9cm/GHSA-3hww-w3cw-c9cm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hww-w3cw-c9cm", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31885" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Floeter Hyperlink Group Block allows DOM-Based XSS. This issue affects Hyperlink Group Block: from n/a through 2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31885" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hyperlink-group-block/vulnerability/wordpress-hyperlink-group-block-plugin-2-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3mx9-7xh4-v774/GHSA-3mx9-7xh4-v774.json b/advisories/unreviewed/2025/04/GHSA-3mx9-7xh4-v774/GHSA-3mx9-7xh4-v774.json new file mode 100644 index 00000000000..1f3b94b8c5f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3mx9-7xh4-v774/GHSA-3mx9-7xh4-v774.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mx9-7xh4-v774", + "modified": "2025-04-01T15:31:43Z", + "published": "2025-04-01T15:31:43Z", + "aliases": [ + "CVE-2025-31844" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical Blocks allows Stored XSS. This issue affects Magical Blocks: from n/a through 1.0.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31844" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/magical-blocks/vulnerability/wordpress-magical-blocks-plugin-1-0-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3q6x-j6f7-rvxv/GHSA-3q6x-j6f7-rvxv.json b/advisories/unreviewed/2025/04/GHSA-3q6x-j6f7-rvxv/GHSA-3q6x-j6f7-rvxv.json new file mode 100644 index 00000000000..27b76dae271 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3q6x-j6f7-rvxv/GHSA-3q6x-j6f7-rvxv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q6x-j6f7-rvxv", + "modified": "2025-04-01T15:31:41Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31813" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Website366.com WPSHARE247 Elementor Addons allows Stored XSS. This issue affects WPSHARE247 Elementor Addons: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31813" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpshare247-elementor-addons/vulnerability/wordpress-wpshare247-elementor-addons-plugin-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3r3q-9qg7-7937/GHSA-3r3q-9qg7-7937.json b/advisories/unreviewed/2025/04/GHSA-3r3q-9qg7-7937/GHSA-3r3q-9qg7-7937.json new file mode 100644 index 00000000000..34f466531cc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3r3q-9qg7-7937/GHSA-3r3q-9qg7-7937.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3r3q-9qg7-7937", + "modified": "2025-04-01T15:31:42Z", + "published": "2025-04-01T15:31:42Z", + "aliases": [ + "CVE-2025-31831" + ], + "details": "Missing Authorization vulnerability in Team AtomChat AtomChat allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AtomChat: from n/a through 1.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31831" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/atomchat/vulnerability/wordpress-atomchat-plugin-1-1-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3r56-gc76-cxqc/GHSA-3r56-gc76-cxqc.json b/advisories/unreviewed/2025/04/GHSA-3r56-gc76-cxqc/GHSA-3r56-gc76-cxqc.json new file mode 100644 index 00000000000..df8b9ebdd1f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3r56-gc76-cxqc/GHSA-3r56-gc76-cxqc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3r56-gc76-cxqc", + "modified": "2025-04-01T15:31:40Z", + "published": "2025-04-01T15:31:40Z", + "aliases": [ + "CVE-2025-31787" + ], + "details": "Missing Authorization vulnerability in Brady Vercher Cue allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Cue: from n/a through 2.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31787" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cue/vulnerability/wordpress-cue-by-audiotheme-com-plugin-2-4-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3rqj-ff24-wjg9/GHSA-3rqj-ff24-wjg9.json b/advisories/unreviewed/2025/04/GHSA-3rqj-ff24-wjg9/GHSA-3rqj-ff24-wjg9.json new file mode 100644 index 00000000000..fd0b8e48903 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3rqj-ff24-wjg9/GHSA-3rqj-ff24-wjg9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rqj-ff24-wjg9", + "modified": "2025-04-01T15:31:44Z", + "published": "2025-04-01T15:31:44Z", + "aliases": [ + "CVE-2025-31865" + ], + "details": "Missing Authorization vulnerability in CartBoss SMS Abandoned Cart Recovery ✦ CartBoss allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SMS Abandoned Cart Recovery ✦ CartBoss: from n/a through 4.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31865" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cartboss/vulnerability/wordpress-cartboss-plugin-4-1-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3v65-m7jv-mqrv/GHSA-3v65-m7jv-mqrv.json b/advisories/unreviewed/2025/04/GHSA-3v65-m7jv-mqrv/GHSA-3v65-m7jv-mqrv.json new file mode 100644 index 00000000000..3521bfe07e4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3v65-m7jv-mqrv/GHSA-3v65-m7jv-mqrv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3v65-m7jv-mqrv", + "modified": "2025-04-01T15:31:39Z", + "published": "2025-04-01T15:31:39Z", + "aliases": [ + "CVE-2025-31780" + ], + "details": "Missing Authorization vulnerability in Andy Stratton Append Content allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Append Content: from n/a through 2.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31780" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/append-content/vulnerability/wordpress-append-content-plugin-2-1-1-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3w56-mg6p-g5gj/GHSA-3w56-mg6p-g5gj.json b/advisories/unreviewed/2025/04/GHSA-3w56-mg6p-g5gj/GHSA-3w56-mg6p-g5gj.json new file mode 100644 index 00000000000..f1209b8e1ff --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3w56-mg6p-g5gj/GHSA-3w56-mg6p-g5gj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w56-mg6p-g5gj", + "modified": "2025-04-01T15:31:40Z", + "published": "2025-04-01T15:31:40Z", + "aliases": [ + "CVE-2025-31791" + ], + "details": "Missing Authorization vulnerability in Oliver Boyers Pin Generator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pin Generator: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31791" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pin-generator/vulnerability/wordpress-pin-generator-plugin-2-0-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3wrf-j36w-8whq/GHSA-3wrf-j36w-8whq.json b/advisories/unreviewed/2025/04/GHSA-3wrf-j36w-8whq/GHSA-3wrf-j36w-8whq.json new file mode 100644 index 00000000000..7f1139bee02 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3wrf-j36w-8whq/GHSA-3wrf-j36w-8whq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wrf-j36w-8whq", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31874" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay WebberZone Snippetz allows Stored XSS. This issue affects WebberZone Snippetz: from n/a through 2.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31874" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/add-to-all/vulnerability/wordpress-webberzone-snippetz-plugin-2-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3x3h-5m6c-8hcx/GHSA-3x3h-5m6c-8hcx.json b/advisories/unreviewed/2025/04/GHSA-3x3h-5m6c-8hcx/GHSA-3x3h-5m6c-8hcx.json new file mode 100644 index 00000000000..786e27793a9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3x3h-5m6c-8hcx/GHSA-3x3h-5m6c-8hcx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x3h-5m6c-8hcx", + "modified": "2025-04-01T15:31:42Z", + "published": "2025-04-01T15:31:42Z", + "aliases": [ + "CVE-2025-31835" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brice Capobianco WP Plugin Info Card allows DOM-Based XSS. This issue affects WP Plugin Info Card: from n/a through 5.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31835" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-plugin-info-card/vulnerability/wordpress-wp-plugin-info-card-plugin-5-2-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-425v-6qh8-hmjx/GHSA-425v-6qh8-hmjx.json b/advisories/unreviewed/2025/04/GHSA-425v-6qh8-hmjx/GHSA-425v-6qh8-hmjx.json new file mode 100644 index 00000000000..b9e99ede4ff --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-425v-6qh8-hmjx/GHSA-425v-6qh8-hmjx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-425v-6qh8-hmjx", + "modified": "2025-04-01T15:31:39Z", + "published": "2025-04-01T15:31:39Z", + "aliases": [ + "CVE-2025-31773" + ], + "details": "Missing Authorization vulnerability in cedcommerce Ship Per Product allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Ship Per Product: from n/a through 2.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31773" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ship-per-product/vulnerability/wordpress-ship-per-product-plugin-2-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-454c-45cm-g8w3/GHSA-454c-45cm-g8w3.json b/advisories/unreviewed/2025/04/GHSA-454c-45cm-g8w3/GHSA-454c-45cm-g8w3.json new file mode 100644 index 00000000000..7003395c7c5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-454c-45cm-g8w3/GHSA-454c-45cm-g8w3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-454c-45cm-g8w3", + "modified": "2025-04-01T15:31:46Z", + "published": "2025-04-01T15:31:46Z", + "aliases": [ + "CVE-2025-31910" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems BookingPress allows SQL Injection. This issue affects BookingPress: from n/a through 1.1.28.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31910" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bookingpress-appointment-booking/vulnerability/wordpress-bookingpress-plugin-1-1-28-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-469w-q8hj-3hr3/GHSA-469w-q8hj-3hr3.json b/advisories/unreviewed/2025/04/GHSA-469w-q8hj-3hr3/GHSA-469w-q8hj-3hr3.json index 603c032907d..72ccc0b4a41 100644 --- a/advisories/unreviewed/2025/04/GHSA-469w-q8hj-3hr3/GHSA-469w-q8hj-3hr3.json +++ b/advisories/unreviewed/2025/04/GHSA-469w-q8hj-3hr3/GHSA-469w-q8hj-3hr3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-469w-q8hj-3hr3", - "modified": "2025-04-01T00:30:38Z", + "modified": "2025-04-01T15:31:30Z", "published": "2025-04-01T00:30:38Z", "aliases": [ "CVE-2025-24231" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-4fvc-w7pw-48q6/GHSA-4fvc-w7pw-48q6.json b/advisories/unreviewed/2025/04/GHSA-4fvc-w7pw-48q6/GHSA-4fvc-w7pw-48q6.json new file mode 100644 index 00000000000..8bf437d1a1e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4fvc-w7pw-48q6/GHSA-4fvc-w7pw-48q6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fvc-w7pw-48q6", + "modified": "2025-04-01T15:31:38Z", + "published": "2025-04-01T15:31:38Z", + "aliases": [ + "CVE-2025-31752" + ], + "details": "Missing Authorization vulnerability in termel Bulk Fields Editor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bulk Fields Editor: from n/a through 1.8.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31752" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bulk-user-editor/vulnerability/wordpress-bulk-fields-editor-plugin-1-8-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4v39-rw5r-p8jm/GHSA-4v39-rw5r-p8jm.json b/advisories/unreviewed/2025/04/GHSA-4v39-rw5r-p8jm/GHSA-4v39-rw5r-p8jm.json new file mode 100644 index 00000000000..1e5ef75c720 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4v39-rw5r-p8jm/GHSA-4v39-rw5r-p8jm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v39-rw5r-p8jm", + "modified": "2025-04-01T15:31:39Z", + "published": "2025-04-01T15:31:39Z", + "aliases": [ + "CVE-2025-31771" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sultan Nasir Uddin Team Members for Elementor Page Builder allows Stored XSS. This issue affects Team Members for Elementor Page Builder: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31771" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/team-members-for-elementor/vulnerability/wordpress-team-members-for-elementor-page-builder-plugin-1-0-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-532m-842f-wrr5/GHSA-532m-842f-wrr5.json b/advisories/unreviewed/2025/04/GHSA-532m-842f-wrr5/GHSA-532m-842f-wrr5.json new file mode 100644 index 00000000000..8896684b945 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-532m-842f-wrr5/GHSA-532m-842f-wrr5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-532m-842f-wrr5", + "modified": "2025-04-01T15:31:44Z", + "published": "2025-04-01T15:31:44Z", + "aliases": [ + "CVE-2025-31859" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Feedbucket Feedbucket – Website Feedback Tool allows Cross Site Request Forgery. This issue affects Feedbucket – Website Feedback Tool: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31859" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/feedbucket/vulnerability/wordpress-feedbucket-website-feedback-tool-plugin-1-0-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-544j-rcj5-8jv9/GHSA-544j-rcj5-8jv9.json b/advisories/unreviewed/2025/04/GHSA-544j-rcj5-8jv9/GHSA-544j-rcj5-8jv9.json new file mode 100644 index 00000000000..3ee344cfdf0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-544j-rcj5-8jv9/GHSA-544j-rcj5-8jv9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-544j-rcj5-8jv9", + "modified": "2025-04-01T15:31:37Z", + "published": "2025-04-01T15:31:37Z", + "aliases": [ + "CVE-2025-31732" + ], + "details": "Missing Authorization vulnerability in gb-plugins GB Gallery Slideshow allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GB Gallery Slideshow: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31732" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gb-gallery-slideshow/vulnerability/wordpress-gb-gallery-slideshow-plugin-1-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-54m6-4vf2-299g/GHSA-54m6-4vf2-299g.json b/advisories/unreviewed/2025/04/GHSA-54m6-4vf2-299g/GHSA-54m6-4vf2-299g.json new file mode 100644 index 00000000000..ee90b4a8dd9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-54m6-4vf2-299g/GHSA-54m6-4vf2-299g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54m6-4vf2-299g", + "modified": "2025-04-01T15:31:42Z", + "published": "2025-04-01T15:31:42Z", + "aliases": [ + "CVE-2025-31832" + ], + "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Beee ACF City Selector allows Retrieve Embedded Sensitive Data. This issue affects ACF City Selector: from n/a through 1.16.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31832" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/acf-city-selector/vulnerability/wordpress-acf-city-selector-plugin-1-16-0-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-54qx-vgv3-pm7v/GHSA-54qx-vgv3-pm7v.json b/advisories/unreviewed/2025/04/GHSA-54qx-vgv3-pm7v/GHSA-54qx-vgv3-pm7v.json new file mode 100644 index 00000000000..acecb1fb30f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-54qx-vgv3-pm7v/GHSA-54qx-vgv3-pm7v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54qx-vgv3-pm7v", + "modified": "2025-04-01T15:31:43Z", + "published": "2025-04-01T15:31:43Z", + "aliases": [ + "CVE-2025-31852" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in N-Media Bulk Product Sync allows Cross Site Request Forgery. This issue affects Bulk Product Sync: from n/a through 8.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31852" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sync-wc-google/vulnerability/wordpress-bulk-product-sync-plugin-8-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-57qh-fhxw-gqhr/GHSA-57qh-fhxw-gqhr.json b/advisories/unreviewed/2025/04/GHSA-57qh-fhxw-gqhr/GHSA-57qh-fhxw-gqhr.json new file mode 100644 index 00000000000..069576dc224 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-57qh-fhxw-gqhr/GHSA-57qh-fhxw-gqhr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57qh-fhxw-gqhr", + "modified": "2025-04-01T15:31:43Z", + "published": "2025-04-01T15:31:42Z", + "aliases": [ + "CVE-2025-31837" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Codeus WP Proposals allows Stored XSS. This issue affects WP Proposals: from n/a through 2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31837" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-proposals/vulnerability/wordpress-wp-proposals-plugin-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-57xv-4vp5-7v49/GHSA-57xv-4vp5-7v49.json b/advisories/unreviewed/2025/04/GHSA-57xv-4vp5-7v49/GHSA-57xv-4vp5-7v49.json new file mode 100644 index 00000000000..e2f7ddcb441 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-57xv-4vp5-7v49/GHSA-57xv-4vp5-7v49.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57xv-4vp5-7v49", + "modified": "2025-04-01T15:31:36Z", + "published": "2025-04-01T15:31:36Z", + "aliases": [ + "CVE-2025-3033" + ], + "details": "After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. \n*This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 137 and Thunderbird < 137.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3033" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1950056" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-20" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-23" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-59wj-h89p-37x9/GHSA-59wj-h89p-37x9.json b/advisories/unreviewed/2025/04/GHSA-59wj-h89p-37x9/GHSA-59wj-h89p-37x9.json index 53df2a45fb9..53ee1844ce6 100644 --- a/advisories/unreviewed/2025/04/GHSA-59wj-h89p-37x9/GHSA-59wj-h89p-37x9.json +++ b/advisories/unreviewed/2025/04/GHSA-59wj-h89p-37x9/GHSA-59wj-h89p-37x9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-59wj-h89p-37x9", - "modified": "2025-04-01T00:30:43Z", + "modified": "2025-04-01T15:31:33Z", "published": "2025-04-01T00:30:42Z", "aliases": [ "CVE-2025-30457" ], "details": "This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to create symlinks to protected regions of the disk.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-59" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:27Z" diff --git a/advisories/unreviewed/2025/04/GHSA-5fm8-89vw-3fp2/GHSA-5fm8-89vw-3fp2.json b/advisories/unreviewed/2025/04/GHSA-5fm8-89vw-3fp2/GHSA-5fm8-89vw-3fp2.json new file mode 100644 index 00000000000..c6d5b8a9370 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5fm8-89vw-3fp2/GHSA-5fm8-89vw-3fp2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fm8-89vw-3fp2", + "modified": "2025-04-01T15:31:39Z", + "published": "2025-04-01T15:31:39Z", + "aliases": [ + "CVE-2025-31783" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leartes.NET Leartes TRY Exchange Rates allows Stored XSS. This issue affects Leartes TRY Exchange Rates: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31783" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/leartes-try-exchange-rates/vulnerability/wordpress-leartes-try-exchange-rates-plugin-2-1-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5q47-p7mr-gqmx/GHSA-5q47-p7mr-gqmx.json b/advisories/unreviewed/2025/04/GHSA-5q47-p7mr-gqmx/GHSA-5q47-p7mr-gqmx.json new file mode 100644 index 00000000000..12427cf4ac7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5q47-p7mr-gqmx/GHSA-5q47-p7mr-gqmx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5q47-p7mr-gqmx", + "modified": "2025-04-01T15:31:38Z", + "published": "2025-04-01T15:31:38Z", + "aliases": [ + "CVE-2025-31755" + ], + "details": "Missing Authorization vulnerability in josselynj pCloud Backup allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects pCloud Backup: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31755" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pcloud-backup/vulnerability/wordpress-pcloud-backup-plugin-1-0-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5qvg-xp2f-fp45/GHSA-5qvg-xp2f-fp45.json b/advisories/unreviewed/2025/04/GHSA-5qvg-xp2f-fp45/GHSA-5qvg-xp2f-fp45.json index 280eb4d75b2..49de5d5ddf5 100644 --- a/advisories/unreviewed/2025/04/GHSA-5qvg-xp2f-fp45/GHSA-5qvg-xp2f-fp45.json +++ b/advisories/unreviewed/2025/04/GHSA-5qvg-xp2f-fp45/GHSA-5qvg-xp2f-fp45.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-22" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-5v8r-67h5-p4jj/GHSA-5v8r-67h5-p4jj.json b/advisories/unreviewed/2025/04/GHSA-5v8r-67h5-p4jj/GHSA-5v8r-67h5-p4jj.json new file mode 100644 index 00000000000..d7dcc1cc5fc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5v8r-67h5-p4jj/GHSA-5v8r-67h5-p4jj.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v8r-67h5-p4jj", + "modified": "2025-04-01T15:31:36Z", + "published": "2025-04-01T15:31:36Z", + "aliases": [ + "CVE-2025-3031" + ], + "details": "An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability affects Firefox < 137 and Thunderbird < 137.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3031" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1947141" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-20" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-23" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5w8w-w4rf-vhcw/GHSA-5w8w-w4rf-vhcw.json b/advisories/unreviewed/2025/04/GHSA-5w8w-w4rf-vhcw/GHSA-5w8w-w4rf-vhcw.json new file mode 100644 index 00000000000..e1966fa2c41 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5w8w-w4rf-vhcw/GHSA-5w8w-w4rf-vhcw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w8w-w4rf-vhcw", + "modified": "2025-04-01T15:31:43Z", + "published": "2025-04-01T15:31:43Z", + "aliases": [ + "CVE-2025-31856" + ], + "details": "Missing Authorization vulnerability in brainvireinfo Export All Post Meta allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Export All Post Meta: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31856" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/export-all-post-meta/vulnerability/wordpress-export-all-post-meta-plugin-1-2-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5wrm-m47r-jv84/GHSA-5wrm-m47r-jv84.json b/advisories/unreviewed/2025/04/GHSA-5wrm-m47r-jv84/GHSA-5wrm-m47r-jv84.json index 6cb9bd921b3..82f915168e3 100644 --- a/advisories/unreviewed/2025/04/GHSA-5wrm-m47r-jv84/GHSA-5wrm-m47r-jv84.json +++ b/advisories/unreviewed/2025/04/GHSA-5wrm-m47r-jv84/GHSA-5wrm-m47r-jv84.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5wrm-m47r-jv84", - "modified": "2025-04-01T00:30:40Z", + "modified": "2025-04-01T15:31:31Z", "published": "2025-04-01T00:30:40Z", "aliases": [ "CVE-2025-24269" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4. An app may be able to cause unexpected system termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:23Z" diff --git a/advisories/unreviewed/2025/04/GHSA-5xff-m446-cjf6/GHSA-5xff-m446-cjf6.json b/advisories/unreviewed/2025/04/GHSA-5xff-m446-cjf6/GHSA-5xff-m446-cjf6.json new file mode 100644 index 00000000000..a23b095a04b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5xff-m446-cjf6/GHSA-5xff-m446-cjf6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xff-m446-cjf6", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31878" + ], + "details": "Missing Authorization vulnerability in Dmitry V. (CEO of \"UKR Solution\") UPC/EAN/GTIN Code Generator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects UPC/EAN/GTIN Code Generator: from n/a through 2.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31878" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/upc-ean-barcode-generator/vulnerability/wordpress-upc-ean-gtin-code-generator-plugin-2-0-2-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-62f2-58pp-q2wg/GHSA-62f2-58pp-q2wg.json b/advisories/unreviewed/2025/04/GHSA-62f2-58pp-q2wg/GHSA-62f2-58pp-q2wg.json index 8fc848ca199..e77cd2c227c 100644 --- a/advisories/unreviewed/2025/04/GHSA-62f2-58pp-q2wg/GHSA-62f2-58pp-q2wg.json +++ b/advisories/unreviewed/2025/04/GHSA-62f2-58pp-q2wg/GHSA-62f2-58pp-q2wg.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-416" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-66xv-mwqh-8qmp/GHSA-66xv-mwqh-8qmp.json b/advisories/unreviewed/2025/04/GHSA-66xv-mwqh-8qmp/GHSA-66xv-mwqh-8qmp.json new file mode 100644 index 00000000000..e768ee8b745 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-66xv-mwqh-8qmp/GHSA-66xv-mwqh-8qmp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66xv-mwqh-8qmp", + "modified": "2025-04-01T15:31:39Z", + "published": "2025-04-01T15:31:39Z", + "aliases": [ + "CVE-2025-31769" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in NiteoThemes CLP – Custom Login Page by NiteoThemes allows Cross Site Request Forgery. This issue affects CLP – Custom Login Page by NiteoThemes: from n/a through 1.5.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31769" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/clp-custom-login-page/vulnerability/wordpress-clp-custom-login-page-by-niteothemes-plugin-1-5-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6899-3jg3-5qw2/GHSA-6899-3jg3-5qw2.json b/advisories/unreviewed/2025/04/GHSA-6899-3jg3-5qw2/GHSA-6899-3jg3-5qw2.json new file mode 100644 index 00000000000..d908db905ea --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6899-3jg3-5qw2/GHSA-6899-3jg3-5qw2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6899-3jg3-5qw2", + "modified": "2025-04-01T15:31:41Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31817" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPWheels BlockWheels allows DOM-Based XSS. This issue affects BlockWheels: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31817" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/blockwheels/vulnerability/wordpress-blockwheels-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6j6v-wqw3-w5pp/GHSA-6j6v-wqw3-w5pp.json b/advisories/unreviewed/2025/04/GHSA-6j6v-wqw3-w5pp/GHSA-6j6v-wqw3-w5pp.json new file mode 100644 index 00000000000..c1bb0f6e102 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6j6v-wqw3-w5pp/GHSA-6j6v-wqw3-w5pp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j6v-wqw3-w5pp", + "modified": "2025-04-01T15:31:38Z", + "published": "2025-04-01T15:31:38Z", + "aliases": [ + "CVE-2025-31754" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DobsonDev DobsonDev Shortcodes allows Stored XSS. This issue affects DobsonDev Shortcodes: from n/a through 2.1.12.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31754" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dobsondev-shortcodes/vulnerability/wordpress-dobsondev-shortcodes-plugin-2-1-12-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6q93-rcg3-j5m7/GHSA-6q93-rcg3-j5m7.json b/advisories/unreviewed/2025/04/GHSA-6q93-rcg3-j5m7/GHSA-6q93-rcg3-j5m7.json new file mode 100644 index 00000000000..ba0e29b0f6f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6q93-rcg3-j5m7/GHSA-6q93-rcg3-j5m7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q93-rcg3-j5m7", + "modified": "2025-04-01T15:31:40Z", + "published": "2025-04-01T15:31:40Z", + "aliases": [ + "CVE-2025-31796" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in TheInnovs Team ElementsCSS Addons for Elementor allows Server Side Request Forgery. This issue affects ElementsCSS Addons for Elementor: from n/a through 1.0.8.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31796" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/css-for-elementor/vulnerability/wordpress-elementscss-addons-for-elementor-plugin-1-0-8-7-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6vw3-5cc7-rmc7/GHSA-6vw3-5cc7-rmc7.json b/advisories/unreviewed/2025/04/GHSA-6vw3-5cc7-rmc7/GHSA-6vw3-5cc7-rmc7.json new file mode 100644 index 00000000000..a58595ca091 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6vw3-5cc7-rmc7/GHSA-6vw3-5cc7-rmc7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vw3-5cc7-rmc7", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31879" + ], + "details": "Missing Authorization vulnerability in Dmitry V. (CEO of \"UKR Solution\") Barcode Generator for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Barcode Generator for WooCommerce: from n/a through 2.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31879" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/embedding-barcodes-into-product-pages-and-orders/vulnerability/wordpress-barcode-generator-for-woocommerce-plugin-2-0-4-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6wg6-rm5x-68cp/GHSA-6wg6-rm5x-68cp.json b/advisories/unreviewed/2025/04/GHSA-6wg6-rm5x-68cp/GHSA-6wg6-rm5x-68cp.json new file mode 100644 index 00000000000..33da77bcfe6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6wg6-rm5x-68cp/GHSA-6wg6-rm5x-68cp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wg6-rm5x-68cp", + "modified": "2025-04-01T15:31:46Z", + "published": "2025-04-01T15:31:46Z", + "aliases": [ + "CVE-2025-31908" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Sami Ahmed Siddiqui JSON Structuring Markup allows Stored XSS. This issue affects JSON Structuring Markup: from n/a through 0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31908" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/json-structuring-markup/vulnerability/wordpress-json-structuring-markup-plugin-0-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6x6q-4c96-mpg8/GHSA-6x6q-4c96-mpg8.json b/advisories/unreviewed/2025/04/GHSA-6x6q-4c96-mpg8/GHSA-6x6q-4c96-mpg8.json new file mode 100644 index 00000000000..631f0ed00a9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6x6q-4c96-mpg8/GHSA-6x6q-4c96-mpg8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6x6q-4c96-mpg8", + "modified": "2025-04-01T15:31:42Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31814" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in OwnerRez OwnerRez allows Cross Site Request Forgery. This issue affects OwnerRez: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31814" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ownerrez/vulnerability/wordpress-ownerrez-plugin-1-2-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-75jh-c6rj-5xh5/GHSA-75jh-c6rj-5xh5.json b/advisories/unreviewed/2025/04/GHSA-75jh-c6rj-5xh5/GHSA-75jh-c6rj-5xh5.json new file mode 100644 index 00000000000..bc64224c8d7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-75jh-c6rj-5xh5/GHSA-75jh-c6rj-5xh5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75jh-c6rj-5xh5", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31891" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gosign Gosign – Posts Slider Block allows Stored XSS. This issue affects Gosign – Posts Slider Block: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31891" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gosign-posts-slider-block/vulnerability/wordpress-gosign-posts-slider-block-plugin-1-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-77gh-vf7j-vj79/GHSA-77gh-vf7j-vj79.json b/advisories/unreviewed/2025/04/GHSA-77gh-vf7j-vj79/GHSA-77gh-vf7j-vj79.json new file mode 100644 index 00000000000..abe8d57caae --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-77gh-vf7j-vj79/GHSA-77gh-vf7j-vj79.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77gh-vf7j-vj79", + "modified": "2025-04-01T15:31:43Z", + "published": "2025-04-01T15:31:43Z", + "aliases": [ + "CVE-2025-31853" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnenschein Smartarget Popup allows Stored XSS. This issue affects Smartarget Popup: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31853" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/smartarget-popup/vulnerability/wordpress-smartarget-popup-plugin-1-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-78fp-h4q6-qmjg/GHSA-78fp-h4q6-qmjg.json b/advisories/unreviewed/2025/04/GHSA-78fp-h4q6-qmjg/GHSA-78fp-h4q6-qmjg.json index da389a78e5e..055aae783ce 100644 --- a/advisories/unreviewed/2025/04/GHSA-78fp-h4q6-qmjg/GHSA-78fp-h4q6-qmjg.json +++ b/advisories/unreviewed/2025/04/GHSA-78fp-h4q6-qmjg/GHSA-78fp-h4q6-qmjg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-78fp-h4q6-qmjg", - "modified": "2025-04-01T00:30:43Z", + "modified": "2025-04-01T15:31:33Z", "published": "2025-04-01T00:30:43Z", "aliases": [ "CVE-2025-30458" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to read files outside of its sandbox.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:27Z" diff --git a/advisories/unreviewed/2025/04/GHSA-793h-885v-rxrh/GHSA-793h-885v-rxrh.json b/advisories/unreviewed/2025/04/GHSA-793h-885v-rxrh/GHSA-793h-885v-rxrh.json index 4ef1e61417f..7332575338d 100644 --- a/advisories/unreviewed/2025/04/GHSA-793h-885v-rxrh/GHSA-793h-885v-rxrh.json +++ b/advisories/unreviewed/2025/04/GHSA-793h-885v-rxrh/GHSA-793h-885v-rxrh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-793h-885v-rxrh", - "modified": "2025-04-01T00:30:36Z", + "modified": "2025-04-01T15:31:30Z", "published": "2025-04-01T00:30:36Z", "aliases": [ "CVE-2025-24180" ], "details": "The issue was addressed with improved input validation. This issue is fixed in Safari 18.4, visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A malicious website may be able to claim WebAuthn credentials from another website that shares a registrable suffix.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:17Z" diff --git a/advisories/unreviewed/2025/04/GHSA-799g-3g44-3g9m/GHSA-799g-3g44-3g9m.json b/advisories/unreviewed/2025/04/GHSA-799g-3g44-3g9m/GHSA-799g-3g44-3g9m.json new file mode 100644 index 00000000000..a7195fbc1ac --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-799g-3g44-3g9m/GHSA-799g-3g44-3g9m.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-799g-3g44-3g9m", + "modified": "2025-04-01T15:31:36Z", + "published": "2025-04-01T15:31:36Z", + "aliases": [ + "CVE-2025-3029" + ], + "details": "A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird ESR < 128.9.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3029" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1952213" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-20" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-22" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-23" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-24" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-79p3-p2hc-84mg/GHSA-79p3-p2hc-84mg.json b/advisories/unreviewed/2025/04/GHSA-79p3-p2hc-84mg/GHSA-79p3-p2hc-84mg.json new file mode 100644 index 00000000000..571e947cbff --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-79p3-p2hc-84mg/GHSA-79p3-p2hc-84mg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79p3-p2hc-84mg", + "modified": "2025-04-01T15:31:42Z", + "published": "2025-04-01T15:31:42Z", + "aliases": [ + "CVE-2025-31826" + ], + "details": "Missing Authorization vulnerability in Anzar Ahmed Ni WooCommerce Cost Of Goods allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ni WooCommerce Cost Of Goods: from n/a through 3.2.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31826" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ni-woocommerce-cost-of-goods/vulnerability/wordpress-ni-woocommerce-cost-of-goods-plugin-3-2-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-79r3-3rmc-6vjr/GHSA-79r3-3rmc-6vjr.json b/advisories/unreviewed/2025/04/GHSA-79r3-3rmc-6vjr/GHSA-79r3-3rmc-6vjr.json new file mode 100644 index 00000000000..701297553c7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-79r3-3rmc-6vjr/GHSA-79r3-3rmc-6vjr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79r3-3rmc-6vjr", + "modified": "2025-04-01T15:31:44Z", + "published": "2025-04-01T15:31:43Z", + "aliases": [ + "CVE-2025-31860" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPeka WP AdCenter allows Stored XSS. This issue affects WP AdCenter: from n/a through 2.5.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31860" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpadcenter/vulnerability/wordpress-wp-adcenter-plugin-2-5-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7fpm-c83j-p8vv/GHSA-7fpm-c83j-p8vv.json b/advisories/unreviewed/2025/04/GHSA-7fpm-c83j-p8vv/GHSA-7fpm-c83j-p8vv.json new file mode 100644 index 00000000000..dd2e527d84c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7fpm-c83j-p8vv/GHSA-7fpm-c83j-p8vv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fpm-c83j-p8vv", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31897" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arrow Plugins Arrow Custom Feed for Twitter allows Stored XSS. This issue affects Arrow Custom Feed for Twitter: from n/a through 1.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31897" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/arrow-twitter-feed/vulnerability/wordpress-arrow-custom-feed-for-twitter-plugin-1-5-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7g9x-v864-75f3/GHSA-7g9x-v864-75f3.json b/advisories/unreviewed/2025/04/GHSA-7g9x-v864-75f3/GHSA-7g9x-v864-75f3.json index 16fde73c017..f1f986a987e 100644 --- a/advisories/unreviewed/2025/04/GHSA-7g9x-v864-75f3/GHSA-7g9x-v864-75f3.json +++ b/advisories/unreviewed/2025/04/GHSA-7g9x-v864-75f3/GHSA-7g9x-v864-75f3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7g9x-v864-75f3", - "modified": "2025-04-01T00:30:40Z", + "modified": "2025-04-01T15:31:31Z", "published": "2025-04-01T00:30:40Z", "aliases": [ "CVE-2025-24256" ], "details": "The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to disclose kernel memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:22Z" diff --git a/advisories/unreviewed/2025/04/GHSA-7hw6-mmqm-76jx/GHSA-7hw6-mmqm-76jx.json b/advisories/unreviewed/2025/04/GHSA-7hw6-mmqm-76jx/GHSA-7hw6-mmqm-76jx.json new file mode 100644 index 00000000000..ef185c73a8e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7hw6-mmqm-76jx/GHSA-7hw6-mmqm-76jx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hw6-mmqm-76jx", + "modified": "2025-04-01T15:31:38Z", + "published": "2025-04-01T15:31:38Z", + "aliases": [ + "CVE-2025-31756" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in tuyennv TZ PlusGallery allows Cross Site Request Forgery. This issue affects TZ PlusGallery: from n/a through 1.5.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31756" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tz-plus-gallery/vulnerability/wordpress-tz-plusgallery-plugin-1-5-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7hxq-4w6w-xgc9/GHSA-7hxq-4w6w-xgc9.json b/advisories/unreviewed/2025/04/GHSA-7hxq-4w6w-xgc9/GHSA-7hxq-4w6w-xgc9.json index b6b2759755e..7e794c1e0ea 100644 --- a/advisories/unreviewed/2025/04/GHSA-7hxq-4w6w-xgc9/GHSA-7hxq-4w6w-xgc9.json +++ b/advisories/unreviewed/2025/04/GHSA-7hxq-4w6w-xgc9/GHSA-7hxq-4w6w-xgc9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7hxq-4w6w-xgc9", - "modified": "2025-04-01T00:30:40Z", + "modified": "2025-04-01T15:31:31Z", "published": "2025-04-01T00:30:40Z", "aliases": [ "CVE-2025-24264" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.4, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, Safari 18.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:23Z" diff --git a/advisories/unreviewed/2025/04/GHSA-7mmq-w7cm-cxxj/GHSA-7mmq-w7cm-cxxj.json b/advisories/unreviewed/2025/04/GHSA-7mmq-w7cm-cxxj/GHSA-7mmq-w7cm-cxxj.json index 047ba65497d..1d969ea2c8f 100644 --- a/advisories/unreviewed/2025/04/GHSA-7mmq-w7cm-cxxj/GHSA-7mmq-w7cm-cxxj.json +++ b/advisories/unreviewed/2025/04/GHSA-7mmq-w7cm-cxxj/GHSA-7mmq-w7cm-cxxj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7mmq-w7cm-cxxj", - "modified": "2025-04-01T00:30:42Z", + "modified": "2025-04-01T15:31:32Z", "published": "2025-04-01T00:30:42Z", "aliases": [ "CVE-2025-30435" ], "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.4. A sandboxed app may be able to access sensitive user data in system logs.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:25Z" diff --git a/advisories/unreviewed/2025/04/GHSA-892g-82wc-7r8q/GHSA-892g-82wc-7r8q.json b/advisories/unreviewed/2025/04/GHSA-892g-82wc-7r8q/GHSA-892g-82wc-7r8q.json index a87c71f15e4..be2a84018bd 100644 --- a/advisories/unreviewed/2025/04/GHSA-892g-82wc-7r8q/GHSA-892g-82wc-7r8q.json +++ b/advisories/unreviewed/2025/04/GHSA-892g-82wc-7r8q/GHSA-892g-82wc-7r8q.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-59" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-8cq7-m6j9-qw55/GHSA-8cq7-m6j9-qw55.json b/advisories/unreviewed/2025/04/GHSA-8cq7-m6j9-qw55/GHSA-8cq7-m6j9-qw55.json new file mode 100644 index 00000000000..44b0b935f35 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8cq7-m6j9-qw55/GHSA-8cq7-m6j9-qw55.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cq7-m6j9-qw55", + "modified": "2025-04-01T15:31:44Z", + "published": "2025-04-01T15:31:43Z", + "aliases": [ + "CVE-2025-31854" + ], + "details": "Missing Authorization vulnerability in Sharaz Shahid Simple Sticky Add To Cart For WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple Sticky Add To Cart For WooCommerce: from n/a through 1.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31854" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sticky-add-to-cart-woo/vulnerability/wordpress-simple-sticky-add-to-cart-for-woocommerce-plugin-1-4-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8fhq-4v9j-268j/GHSA-8fhq-4v9j-268j.json b/advisories/unreviewed/2025/04/GHSA-8fhq-4v9j-268j/GHSA-8fhq-4v9j-268j.json new file mode 100644 index 00000000000..9f129eee7c3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8fhq-4v9j-268j/GHSA-8fhq-4v9j-268j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fhq-4v9j-268j", + "modified": "2025-04-01T15:31:37Z", + "published": "2025-04-01T15:31:37Z", + "aliases": [ + "CVE-2025-31731" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Philip John Author Bio Shortcode allows Stored XSS. This issue affects Author Bio Shortcode: from n/a through 2.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31731" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/author-bio-shortcode/vulnerability/wordpress-author-bio-shortcode-plugin-2-5-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8h8h-4h46-6wx3/GHSA-8h8h-4h46-6wx3.json b/advisories/unreviewed/2025/04/GHSA-8h8h-4h46-6wx3/GHSA-8h8h-4h46-6wx3.json index c8467c2dab4..1456a414c37 100644 --- a/advisories/unreviewed/2025/04/GHSA-8h8h-4h46-6wx3/GHSA-8h8h-4h46-6wx3.json +++ b/advisories/unreviewed/2025/04/GHSA-8h8h-4h46-6wx3/GHSA-8h8h-4h46-6wx3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8h8h-4h46-6wx3", - "modified": "2025-04-01T00:30:39Z", + "modified": "2025-04-01T15:31:30Z", "published": "2025-04-01T00:30:39Z", "aliases": [ "CVE-2025-24237" ], "details": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause unexpected system termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-8jhg-mp96-62f4/GHSA-8jhg-mp96-62f4.json b/advisories/unreviewed/2025/04/GHSA-8jhg-mp96-62f4/GHSA-8jhg-mp96-62f4.json new file mode 100644 index 00000000000..417f7ce1f3c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8jhg-mp96-62f4/GHSA-8jhg-mp96-62f4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jhg-mp96-62f4", + "modified": "2025-04-01T15:31:43Z", + "published": "2025-04-01T15:31:43Z", + "aliases": [ + "CVE-2025-31848" + ], + "details": "Missing Authorization vulnerability in WPFactory WordPress Adverts Plugin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WordPress Adverts Plugin: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31848" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/adverts-click-tracker/vulnerability/wordpress-wordpress-adverts-plugin-plugin-1-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8m6g-gw2g-4vv5/GHSA-8m6g-gw2g-4vv5.json b/advisories/unreviewed/2025/04/GHSA-8m6g-gw2g-4vv5/GHSA-8m6g-gw2g-4vv5.json new file mode 100644 index 00000000000..a3791e33de7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8m6g-gw2g-4vv5/GHSA-8m6g-gw2g-4vv5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m6g-gw2g-4vv5", + "modified": "2025-04-01T15:31:40Z", + "published": "2025-04-01T15:31:40Z", + "aliases": [ + "CVE-2025-31793" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Forms allows Stored XSS. This issue affects Piotnet Forms: from n/a through 1.0.30.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31793" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/piotnetforms/vulnerability/wordpress-piotnet-forms-plugin-1-0-30-cross-site-scripting-xss-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8r67-g36f-9mp8/GHSA-8r67-g36f-9mp8.json b/advisories/unreviewed/2025/04/GHSA-8r67-g36f-9mp8/GHSA-8r67-g36f-9mp8.json new file mode 100644 index 00000000000..73b111729aa --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8r67-g36f-9mp8/GHSA-8r67-g36f-9mp8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r67-g36f-9mp8", + "modified": "2025-04-01T15:31:42Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31823" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpoperations WPoperation Elementor Addons allows Stored XSS. This issue affects WPoperation Elementor Addons: from n/a through 1.1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31823" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpop-elementor-addons/vulnerability/wordpress-wpoperation-elementor-addons-plugin-1-1-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8r77-rxc7-qgvv/GHSA-8r77-rxc7-qgvv.json b/advisories/unreviewed/2025/04/GHSA-8r77-rxc7-qgvv/GHSA-8r77-rxc7-qgvv.json new file mode 100644 index 00000000000..405bffb139c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8r77-rxc7-qgvv/GHSA-8r77-rxc7-qgvv.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r77-rxc7-qgvv", + "modified": "2025-04-01T15:31:36Z", + "published": "2025-04-01T15:31:36Z", + "aliases": [ + "CVE-2025-3030" + ], + "details": "Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird ESR < 128.9.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3030" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1850615%2C1932468%2C1942551%2C1951017%2C1951494" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-20" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-22" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-23" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-24" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8r93-wf77-r46q/GHSA-8r93-wf77-r46q.json b/advisories/unreviewed/2025/04/GHSA-8r93-wf77-r46q/GHSA-8r93-wf77-r46q.json new file mode 100644 index 00000000000..464a514eb41 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8r93-wf77-r46q/GHSA-8r93-wf77-r46q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r93-wf77-r46q", + "modified": "2025-04-01T15:31:41Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31818" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ContentBot.ai ContentBot AI Writer allows Stored XSS. This issue affects ContentBot AI Writer: from n/a through 1.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31818" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/content-bot/vulnerability/wordpress-contentbot-ai-writer-plugin-1-2-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8vj6-35g2-pjp7/GHSA-8vj6-35g2-pjp7.json b/advisories/unreviewed/2025/04/GHSA-8vj6-35g2-pjp7/GHSA-8vj6-35g2-pjp7.json new file mode 100644 index 00000000000..47f876fa56a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8vj6-35g2-pjp7/GHSA-8vj6-35g2-pjp7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vj6-35g2-pjp7", + "modified": "2025-04-01T15:31:38Z", + "published": "2025-04-01T15:31:38Z", + "aliases": [ + "CVE-2025-31749" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPelite HMH Footer Builder For Elementor allows Stored XSS. This issue affects HMH Footer Builder For Elementor: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31749" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hmh-footer-builder-for-elementor/vulnerability/wordpress-hmh-footer-builder-for-elementor-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8w29-wh58-hrm4/GHSA-8w29-wh58-hrm4.json b/advisories/unreviewed/2025/04/GHSA-8w29-wh58-hrm4/GHSA-8w29-wh58-hrm4.json index 22b8332a688..b1f147500e9 100644 --- a/advisories/unreviewed/2025/04/GHSA-8w29-wh58-hrm4/GHSA-8w29-wh58-hrm4.json +++ b/advisories/unreviewed/2025/04/GHSA-8w29-wh58-hrm4/GHSA-8w29-wh58-hrm4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8w29-wh58-hrm4", - "modified": "2025-04-01T00:30:37Z", + "modified": "2025-04-01T15:31:30Z", "published": "2025-04-01T00:30:37Z", "aliases": [ "CVE-2025-24199" ], "details": "An uncontrolled format string issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause a denial-of-service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:18Z" diff --git a/advisories/unreviewed/2025/04/GHSA-93hf-9xg9-w4v7/GHSA-93hf-9xg9-w4v7.json b/advisories/unreviewed/2025/04/GHSA-93hf-9xg9-w4v7/GHSA-93hf-9xg9-w4v7.json new file mode 100644 index 00000000000..bef38e1884f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-93hf-9xg9-w4v7/GHSA-93hf-9xg9-w4v7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93hf-9xg9-w4v7", + "modified": "2025-04-01T15:31:39Z", + "published": "2025-04-01T15:31:38Z", + "aliases": [ + "CVE-2025-31766" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PhotoShelter PhotoShelter for Photographers Blog Feed Plugin allows Stored XSS. This issue affects PhotoShelter for Photographers Blog Feed Plugin: from n/a through 1.5.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31766" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/photoshelter-official-plugin/vulnerability/wordpress-photoshelter-for-photographers-blog-feed-plugin-1-5-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-95xg-2wgr-4p8c/GHSA-95xg-2wgr-4p8c.json b/advisories/unreviewed/2025/04/GHSA-95xg-2wgr-4p8c/GHSA-95xg-2wgr-4p8c.json new file mode 100644 index 00000000000..389466d08c0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-95xg-2wgr-4p8c/GHSA-95xg-2wgr-4p8c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95xg-2wgr-4p8c", + "modified": "2025-04-01T15:31:38Z", + "published": "2025-04-01T15:31:38Z", + "aliases": [ + "CVE-2025-31760" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snapwidget SnapWidget Social Photo Feed Widget allows DOM-Based XSS. This issue affects SnapWidget Social Photo Feed Widget: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31760" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/snapwidget-wp-instagram-widget/vulnerability/wordpress-snapwidget-social-photo-feed-widget-plugin-1-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-962p-7v75-7qmf/GHSA-962p-7v75-7qmf.json b/advisories/unreviewed/2025/04/GHSA-962p-7v75-7qmf/GHSA-962p-7v75-7qmf.json new file mode 100644 index 00000000000..6b5d431e590 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-962p-7v75-7qmf/GHSA-962p-7v75-7qmf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-962p-7v75-7qmf", + "modified": "2025-04-01T15:31:38Z", + "published": "2025-04-01T15:31:38Z", + "aliases": [ + "CVE-2025-31742" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PixelDima Dima Take Action allows Stored XSS. This issue affects Dima Take Action: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31742" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dima-take-action/vulnerability/wordpress-dima-take-action-plugin-1-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9cp2-r8w6-r4vm/GHSA-9cp2-r8w6-r4vm.json b/advisories/unreviewed/2025/04/GHSA-9cp2-r8w6-r4vm/GHSA-9cp2-r8w6-r4vm.json index 73e11d34f29..978b04c8cc9 100644 --- a/advisories/unreviewed/2025/04/GHSA-9cp2-r8w6-r4vm/GHSA-9cp2-r8w6-r4vm.json +++ b/advisories/unreviewed/2025/04/GHSA-9cp2-r8w6-r4vm/GHSA-9cp2-r8w6-r4vm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9cp2-r8w6-r4vm", - "modified": "2025-04-01T06:30:44Z", + "modified": "2025-04-01T15:31:35Z", "published": "2025-04-01T06:30:44Z", "aliases": [ "CVE-2025-1986" ], "details": "The Gutentor WordPress plugin before 3.4.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T06:15:48Z" diff --git a/advisories/unreviewed/2025/04/GHSA-9f34-hg9w-62vg/GHSA-9f34-hg9w-62vg.json b/advisories/unreviewed/2025/04/GHSA-9f34-hg9w-62vg/GHSA-9f34-hg9w-62vg.json index aafeebb1d8d..3e4b89ab6b9 100644 --- a/advisories/unreviewed/2025/04/GHSA-9f34-hg9w-62vg/GHSA-9f34-hg9w-62vg.json +++ b/advisories/unreviewed/2025/04/GHSA-9f34-hg9w-62vg/GHSA-9f34-hg9w-62vg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9f34-hg9w-62vg", - "modified": "2025-04-01T00:30:36Z", + "modified": "2025-04-01T15:31:29Z", "published": "2025-04-01T00:30:36Z", "aliases": [ "CVE-2025-24178" ], "details": "This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to break out of its sandbox.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -41,7 +46,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:16Z" diff --git a/advisories/unreviewed/2025/04/GHSA-9fr8-m4rq-565w/GHSA-9fr8-m4rq-565w.json b/advisories/unreviewed/2025/04/GHSA-9fr8-m4rq-565w/GHSA-9fr8-m4rq-565w.json new file mode 100644 index 00000000000..b8c8a21ab67 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9fr8-m4rq-565w/GHSA-9fr8-m4rq-565w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fr8-m4rq-565w", + "modified": "2025-04-01T15:31:41Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31811" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xtreeme Planyo online reservation system allows Stored XSS. This issue affects Planyo online reservation system: from n/a through 3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31811" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/planyo-online-reservation-system/vulnerability/wordpress-planyo-online-reservation-system-plugin-3-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9hjm-gm4c-vqqv/GHSA-9hjm-gm4c-vqqv.json b/advisories/unreviewed/2025/04/GHSA-9hjm-gm4c-vqqv/GHSA-9hjm-gm4c-vqqv.json index ee6c260d950..d3e86bf9450 100644 --- a/advisories/unreviewed/2025/04/GHSA-9hjm-gm4c-vqqv/GHSA-9hjm-gm4c-vqqv.json +++ b/advisories/unreviewed/2025/04/GHSA-9hjm-gm4c-vqqv/GHSA-9hjm-gm4c-vqqv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9hjm-gm4c-vqqv", - "modified": "2025-04-01T00:30:36Z", + "modified": "2025-04-01T15:31:30Z", "published": "2025-04-01T00:30:36Z", "aliases": [ "CVE-2025-24190" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:17Z" diff --git a/advisories/unreviewed/2025/04/GHSA-9w9x-35h7-p37h/GHSA-9w9x-35h7-p37h.json b/advisories/unreviewed/2025/04/GHSA-9w9x-35h7-p37h/GHSA-9w9x-35h7-p37h.json new file mode 100644 index 00000000000..c9febf8a1d6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9w9x-35h7-p37h/GHSA-9w9x-35h7-p37h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9w9x-35h7-p37h", + "modified": "2025-04-01T15:31:43Z", + "published": "2025-04-01T15:31:43Z", + "aliases": [ + "CVE-2025-31855" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in softnwords SMM API allows Stored XSS. This issue affects SMM API: from n/a through 6.0.27.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31855" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/smm-api/vulnerability/wordpress-smm-api-plugin-6-0-27-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9wvq-7hmr-957m/GHSA-9wvq-7hmr-957m.json b/advisories/unreviewed/2025/04/GHSA-9wvq-7hmr-957m/GHSA-9wvq-7hmr-957m.json new file mode 100644 index 00000000000..b47d3c8c374 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9wvq-7hmr-957m/GHSA-9wvq-7hmr-957m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wvq-7hmr-957m", + "modified": "2025-04-01T15:31:37Z", + "published": "2025-04-01T15:31:37Z", + "aliases": [ + "CVE-2025-31744" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpszaki Lightweight and Responsive Youtube Embed allows Stored XSS. This issue affects Lightweight and Responsive Youtube Embed: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31744" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lightweight-and-responsive-youtube-embed/vulnerability/wordpress-lightweight-and-responsive-youtube-embed-plugin-1-0-0-stored-cross-site-scripting-xss-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c3hg-7pq7-vq3v/GHSA-c3hg-7pq7-vq3v.json b/advisories/unreviewed/2025/04/GHSA-c3hg-7pq7-vq3v/GHSA-c3hg-7pq7-vq3v.json new file mode 100644 index 00000000000..1b035c1ea77 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c3hg-7pq7-vq3v/GHSA-c3hg-7pq7-vq3v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3hg-7pq7-vq3v", + "modified": "2025-04-01T15:31:37Z", + "published": "2025-04-01T15:31:37Z", + "aliases": [ + "CVE-2025-31734" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Simple Post Expiration allows DOM-Based XSS. This issue affects Simple Post Expiration: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31734" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-post-expiration/vulnerability/wordpress-simple-post-expiration-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c4r6-g2f6-2hq4/GHSA-c4r6-g2f6-2hq4.json b/advisories/unreviewed/2025/04/GHSA-c4r6-g2f6-2hq4/GHSA-c4r6-g2f6-2hq4.json new file mode 100644 index 00000000000..55e59f0e450 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c4r6-g2f6-2hq4/GHSA-c4r6-g2f6-2hq4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4r6-g2f6-2hq4", + "modified": "2025-04-01T15:31:40Z", + "published": "2025-04-01T15:31:40Z", + "aliases": [ + "CVE-2025-31786" + ], + "details": "Missing Authorization vulnerability in Travis Simple Icons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple Icons: from n/a through 2.8.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31786" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-icons/vulnerability/wordpress-simple-icons-plugin-2-8-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ccfr-8pjp-64mv/GHSA-ccfr-8pjp-64mv.json b/advisories/unreviewed/2025/04/GHSA-ccfr-8pjp-64mv/GHSA-ccfr-8pjp-64mv.json new file mode 100644 index 00000000000..c7bac04e72e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ccfr-8pjp-64mv/GHSA-ccfr-8pjp-64mv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccfr-8pjp-64mv", + "modified": "2025-04-01T15:31:41Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31803" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Neteuro Turisbook Booking System allows Stored XSS. This issue affects Turisbook Booking System: from n/a through 1.3.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31803" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/turisbook-booking-system/vulnerability/wordpress-turisbook-booking-system-plugin-1-3-7-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cchf-wff5-x435/GHSA-cchf-wff5-x435.json b/advisories/unreviewed/2025/04/GHSA-cchf-wff5-x435/GHSA-cchf-wff5-x435.json new file mode 100644 index 00000000000..f142bdb350a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cchf-wff5-x435/GHSA-cchf-wff5-x435.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cchf-wff5-x435", + "modified": "2025-04-01T15:31:43Z", + "published": "2025-04-01T15:31:43Z", + "aliases": [ + "CVE-2025-31845" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rohit Choudhary Theme Duplicator allows Cross Site Request Forgery. This issue affects Theme Duplicator: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31845" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/theme-duplicator/vulnerability/wordpress-theme-duplicator-plugin-1-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cfwh-jq9v-p2x2/GHSA-cfwh-jq9v-p2x2.json b/advisories/unreviewed/2025/04/GHSA-cfwh-jq9v-p2x2/GHSA-cfwh-jq9v-p2x2.json new file mode 100644 index 00000000000..114deeeec3a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cfwh-jq9v-p2x2/GHSA-cfwh-jq9v-p2x2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfwh-jq9v-p2x2", + "modified": "2025-04-01T15:31:41Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31822" + ], + "details": "Missing Authorization vulnerability in Ashish Ajani WP Simple HTML Sitemap allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Simple HTML Sitemap: from n/a through 3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31822" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-simple-html-sitemap/vulnerability/wordpress-wordpress-simple-html-sitemap-plugin-3-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cp57-26m4-r4m3/GHSA-cp57-26m4-r4m3.json b/advisories/unreviewed/2025/04/GHSA-cp57-26m4-r4m3/GHSA-cp57-26m4-r4m3.json new file mode 100644 index 00000000000..c2499528176 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cp57-26m4-r4m3/GHSA-cp57-26m4-r4m3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp57-26m4-r4m3", + "modified": "2025-04-01T15:31:37Z", + "published": "2025-04-01T15:31:37Z", + "aliases": [ + "CVE-2025-31740" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aThemeArt News, Magazine and Blog Elements allows Stored XSS. This issue affects News, Magazine and Blog Elements: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31740" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/news-magazine-and-blog-elements/vulnerability/wordpress-news-magazine-and-blog-elements-plugin-1-3-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cqpc-66w4-95wh/GHSA-cqpc-66w4-95wh.json b/advisories/unreviewed/2025/04/GHSA-cqpc-66w4-95wh/GHSA-cqpc-66w4-95wh.json new file mode 100644 index 00000000000..703ffa47ece --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cqpc-66w4-95wh/GHSA-cqpc-66w4-95wh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqpc-66w4-95wh", + "modified": "2025-04-01T15:31:38Z", + "published": "2025-04-01T15:31:38Z", + "aliases": [ + "CVE-2025-31759" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BooSpot Boo Recipes allows Stored XSS. This issue affects Boo Recipes: from n/a through 2.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31759" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/boo-recipes/vulnerability/wordpress-boo-recipes-plugin-2-4-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cqxv-6v33-64xx/GHSA-cqxv-6v33-64xx.json b/advisories/unreviewed/2025/04/GHSA-cqxv-6v33-64xx/GHSA-cqxv-6v33-64xx.json index 4061b3d160f..d3bce264b9d 100644 --- a/advisories/unreviewed/2025/04/GHSA-cqxv-6v33-64xx/GHSA-cqxv-6v33-64xx.json +++ b/advisories/unreviewed/2025/04/GHSA-cqxv-6v33-64xx/GHSA-cqxv-6v33-64xx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cqxv-6v33-64xx", - "modified": "2025-04-01T00:30:40Z", + "modified": "2025-04-01T15:31:31Z", "published": "2025-04-01T00:30:40Z", "aliases": [ "CVE-2025-24265" ], "details": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause unexpected system termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:23Z" diff --git a/advisories/unreviewed/2025/04/GHSA-crwm-v9wf-m9pg/GHSA-crwm-v9wf-m9pg.json b/advisories/unreviewed/2025/04/GHSA-crwm-v9wf-m9pg/GHSA-crwm-v9wf-m9pg.json index 4996b8ae10a..e1aac5e7b4c 100644 --- a/advisories/unreviewed/2025/04/GHSA-crwm-v9wf-m9pg/GHSA-crwm-v9wf-m9pg.json +++ b/advisories/unreviewed/2025/04/GHSA-crwm-v9wf-m9pg/GHSA-crwm-v9wf-m9pg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-crwm-v9wf-m9pg", - "modified": "2025-04-01T00:30:39Z", + "modified": "2025-04-01T15:31:31Z", "published": "2025-04-01T00:30:39Z", "aliases": [ "CVE-2025-24245" ], "details": "This issue was addressed by adding a delay between verification code attempts. This issue is fixed in macOS Sequoia 15.4. A malicious app may be able to access a user's saved passwords.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:21Z" diff --git a/advisories/unreviewed/2025/04/GHSA-cw4p-m5cc-276x/GHSA-cw4p-m5cc-276x.json b/advisories/unreviewed/2025/04/GHSA-cw4p-m5cc-276x/GHSA-cw4p-m5cc-276x.json new file mode 100644 index 00000000000..70e978bf233 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cw4p-m5cc-276x/GHSA-cw4p-m5cc-276x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cw4p-m5cc-276x", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31875" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluginic FancyPost allows DOM-Based XSS. This issue affects FancyPost: from n/a through 6.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31875" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/post-block/vulnerability/wordpress-fancypost-plugin-6-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cwxf-h86q-7q6r/GHSA-cwxf-h86q-7q6r.json b/advisories/unreviewed/2025/04/GHSA-cwxf-h86q-7q6r/GHSA-cwxf-h86q-7q6r.json new file mode 100644 index 00000000000..d292b636a95 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cwxf-h86q-7q6r/GHSA-cwxf-h86q-7q6r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwxf-h86q-7q6r", + "modified": "2025-04-01T15:31:42Z", + "published": "2025-04-01T15:31:42Z", + "aliases": [ + "CVE-2025-31836" + ], + "details": "Missing Authorization vulnerability in matthewrubin Review Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Review Manager: from n/a through 2.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31836" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/review-manager/vulnerability/wordpress-review-manager-plugin-2-2-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cx2j-f74w-54vq/GHSA-cx2j-f74w-54vq.json b/advisories/unreviewed/2025/04/GHSA-cx2j-f74w-54vq/GHSA-cx2j-f74w-54vq.json new file mode 100644 index 00000000000..43becc0fb4a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cx2j-f74w-54vq/GHSA-cx2j-f74w-54vq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx2j-f74w-54vq", + "modified": "2025-04-01T15:31:41Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31810" + ], + "details": "Missing Authorization vulnerability in PickPlugins Question Answer allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Question Answer: from n/a through 1.2.70.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31810" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/question-answer/vulnerability/wordpress-question-answer-plugin-1-2-70-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f2w5-9h42-g5cp/GHSA-f2w5-9h42-g5cp.json b/advisories/unreviewed/2025/04/GHSA-f2w5-9h42-g5cp/GHSA-f2w5-9h42-g5cp.json new file mode 100644 index 00000000000..16e30ae6585 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f2w5-9h42-g5cp/GHSA-f2w5-9h42-g5cp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2w5-9h42-g5cp", + "modified": "2025-04-01T15:31:38Z", + "published": "2025-04-01T15:31:38Z", + "aliases": [ + "CVE-2025-31747" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in milan.latinovic WP Chrono allows DOM-Based XSS. This issue affects WP Chrono: from n/a through 1.5.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31747" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-chrono/vulnerability/wordpress-wp-chrono-plugin-1-5-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f43p-rf84-7ggr/GHSA-f43p-rf84-7ggr.json b/advisories/unreviewed/2025/04/GHSA-f43p-rf84-7ggr/GHSA-f43p-rf84-7ggr.json new file mode 100644 index 00000000000..c5547052a26 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f43p-rf84-7ggr/GHSA-f43p-rf84-7ggr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f43p-rf84-7ggr", + "modified": "2025-04-01T15:31:38Z", + "published": "2025-04-01T15:31:38Z", + "aliases": [ + "CVE-2025-31750" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in doit Breaking News WP allows Stored XSS. This issue affects Breaking News WP: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31750" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/breaking-news-wp/vulnerability/wordpress-breaking-news-wp-plugin-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f587-8mf8-x559/GHSA-f587-8mf8-x559.json b/advisories/unreviewed/2025/04/GHSA-f587-8mf8-x559/GHSA-f587-8mf8-x559.json new file mode 100644 index 00000000000..0946506aca6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f587-8mf8-x559/GHSA-f587-8mf8-x559.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f587-8mf8-x559", + "modified": "2025-04-01T15:31:44Z", + "published": "2025-04-01T15:31:44Z", + "aliases": [ + "CVE-2025-31869" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor allows Stored XSS. This issue affects Black Widgets For Elementor: from n/a through 1.3.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31869" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/black-widgets/vulnerability/wordpress-black-widgets-for-elementor-plugin-1-3-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f6cx-5vq5-842w/GHSA-f6cx-5vq5-842w.json b/advisories/unreviewed/2025/04/GHSA-f6cx-5vq5-842w/GHSA-f6cx-5vq5-842w.json new file mode 100644 index 00000000000..8e257c5bcc4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f6cx-5vq5-842w/GHSA-f6cx-5vq5-842w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6cx-5vq5-842w", + "modified": "2025-04-01T15:31:37Z", + "published": "2025-04-01T15:31:37Z", + "aliases": [ + "CVE-2025-31730" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DigitalCourt Marketer Addons allows Stored XSS. This issue affects Marketer Addons: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31730" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/marketer-addons/vulnerability/wordpress-marketer-addons-plugin-1-0-1-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ff7g-r4f4-qg7v/GHSA-ff7g-r4f4-qg7v.json b/advisories/unreviewed/2025/04/GHSA-ff7g-r4f4-qg7v/GHSA-ff7g-r4f4-qg7v.json index 598ae01eed1..8940f6ca3e8 100644 --- a/advisories/unreviewed/2025/04/GHSA-ff7g-r4f4-qg7v/GHSA-ff7g-r4f4-qg7v.json +++ b/advisories/unreviewed/2025/04/GHSA-ff7g-r4f4-qg7v/GHSA-ff7g-r4f4-qg7v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ff7g-r4f4-qg7v", - "modified": "2025-04-01T00:30:38Z", + "modified": "2025-04-01T15:31:30Z", "published": "2025-04-01T00:30:38Z", "aliases": [ "CVE-2025-24217" ], "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.4 and iPadOS 18.4, tvOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:19Z" diff --git a/advisories/unreviewed/2025/04/GHSA-fh2c-6f24-gr49/GHSA-fh2c-6f24-gr49.json b/advisories/unreviewed/2025/04/GHSA-fh2c-6f24-gr49/GHSA-fh2c-6f24-gr49.json new file mode 100644 index 00000000000..43fa0fb5654 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fh2c-6f24-gr49/GHSA-fh2c-6f24-gr49.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh2c-6f24-gr49", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31880" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Stylemix Pearl allows Cross Site Request Forgery. This issue affects Pearl: from n/a through 1.3.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31880" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pearl-header-builder/vulnerability/wordpress-pearl-plugin-1-3-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fhx2-xjjw-gf46/GHSA-fhx2-xjjw-gf46.json b/advisories/unreviewed/2025/04/GHSA-fhx2-xjjw-gf46/GHSA-fhx2-xjjw-gf46.json new file mode 100644 index 00000000000..47a90e83781 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fhx2-xjjw-gf46/GHSA-fhx2-xjjw-gf46.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhx2-xjjw-gf46", + "modified": "2025-04-01T15:31:37Z", + "published": "2025-04-01T15:31:37Z", + "aliases": [ + "CVE-2025-31733" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Boot Div WP Sitemap allows Stored XSS. This issue affects WP Sitemap: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31733" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpsitemap/vulnerability/wordpress-wp-sitemap-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fm5m-98hc-jv89/GHSA-fm5m-98hc-jv89.json b/advisories/unreviewed/2025/04/GHSA-fm5m-98hc-jv89/GHSA-fm5m-98hc-jv89.json new file mode 100644 index 00000000000..3c97ece269b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fm5m-98hc-jv89/GHSA-fm5m-98hc-jv89.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm5m-98hc-jv89", + "modified": "2025-04-01T15:31:38Z", + "published": "2025-04-01T15:31:38Z", + "aliases": [ + "CVE-2025-31745" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arni Cinco Subscription Form for Feedblitz allows Stored XSS. This issue affects Subscription Form for Feedblitz: from n/a through 1.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31745" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/feedblitz-email-subscription/vulnerability/wordpress-subscription-form-for-feedblitz-plugin-1-0-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fqrv-m6p4-qfhh/GHSA-fqrv-m6p4-qfhh.json b/advisories/unreviewed/2025/04/GHSA-fqrv-m6p4-qfhh/GHSA-fqrv-m6p4-qfhh.json new file mode 100644 index 00000000000..794d4622584 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fqrv-m6p4-qfhh/GHSA-fqrv-m6p4-qfhh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqrv-m6p4-qfhh", + "modified": "2025-04-01T15:31:40Z", + "published": "2025-04-01T15:31:40Z", + "aliases": [ + "CVE-2025-31797" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Sprout Clients allows Stored XSS. This issue affects Sprout Clients: from n/a through 3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31797" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sprout-clients/vulnerability/wordpress-sprout-clients-plugin-3-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fr93-gm36-82pj/GHSA-fr93-gm36-82pj.json b/advisories/unreviewed/2025/04/GHSA-fr93-gm36-82pj/GHSA-fr93-gm36-82pj.json new file mode 100644 index 00000000000..71398025b24 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fr93-gm36-82pj/GHSA-fr93-gm36-82pj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr93-gm36-82pj", + "modified": "2025-04-01T15:31:39Z", + "published": "2025-04-01T15:31:39Z", + "aliases": [ + "CVE-2025-31761" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DEJAN Hypotext allows Stored XSS. This issue affects Hypotext: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31761" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hypotext/vulnerability/wordpress-hypotext-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-frrr-xgqj-649g/GHSA-frrr-xgqj-649g.json b/advisories/unreviewed/2025/04/GHSA-frrr-xgqj-649g/GHSA-frrr-xgqj-649g.json index 7d65efd6928..92a69a23d51 100644 --- a/advisories/unreviewed/2025/04/GHSA-frrr-xgqj-649g/GHSA-frrr-xgqj-649g.json +++ b/advisories/unreviewed/2025/04/GHSA-frrr-xgqj-649g/GHSA-frrr-xgqj-649g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-frrr-xgqj-649g", - "modified": "2025-04-01T00:30:37Z", + "modified": "2025-04-01T15:31:30Z", "published": "2025-04-01T00:30:37Z", "aliases": [ "CVE-2025-24210" ], "details": "A logic error was addressed with improved error handling. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Parsing an image may lead to disclosure of user information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-783" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:18Z" diff --git a/advisories/unreviewed/2025/04/GHSA-fw2v-8868-mpvm/GHSA-fw2v-8868-mpvm.json b/advisories/unreviewed/2025/04/GHSA-fw2v-8868-mpvm/GHSA-fw2v-8868-mpvm.json new file mode 100644 index 00000000000..5bcdce2708f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fw2v-8868-mpvm/GHSA-fw2v-8868-mpvm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw2v-8868-mpvm", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31904" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Infoway LLC Ebook Downloader allows Cross Site Request Forgery. This issue affects Ebook Downloader: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31904" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ebook-downloader/vulnerability/wordpress-ebook-downloader-plugin-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fx96-8pvm-r9jw/GHSA-fx96-8pvm-r9jw.json b/advisories/unreviewed/2025/04/GHSA-fx96-8pvm-r9jw/GHSA-fx96-8pvm-r9jw.json new file mode 100644 index 00000000000..68884de68bf --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fx96-8pvm-r9jw/GHSA-fx96-8pvm-r9jw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fx96-8pvm-r9jw", + "modified": "2025-04-01T15:31:42Z", + "published": "2025-04-01T15:31:42Z", + "aliases": [ + "CVE-2025-31829" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devscred ShopCred allows DOM-Based XSS. This issue affects ShopCred: from n/a through 1.2.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31829" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/shopcred/vulnerability/wordpress-shopcred-plugin-1-2-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g3r7-w9gq-5v84/GHSA-g3r7-w9gq-5v84.json b/advisories/unreviewed/2025/04/GHSA-g3r7-w9gq-5v84/GHSA-g3r7-w9gq-5v84.json index 0c03cb29f2c..1e93b6f1004 100644 --- a/advisories/unreviewed/2025/04/GHSA-g3r7-w9gq-5v84/GHSA-g3r7-w9gq-5v84.json +++ b/advisories/unreviewed/2025/04/GHSA-g3r7-w9gq-5v84/GHSA-g3r7-w9gq-5v84.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g3r7-w9gq-5v84", - "modified": "2025-04-01T00:30:38Z", + "modified": "2025-04-01T15:31:30Z", "published": "2025-04-01T00:30:38Z", "aliases": [ "CVE-2025-24215" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access private information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:19Z" diff --git a/advisories/unreviewed/2025/04/GHSA-g79q-4pjf-cmvv/GHSA-g79q-4pjf-cmvv.json b/advisories/unreviewed/2025/04/GHSA-g79q-4pjf-cmvv/GHSA-g79q-4pjf-cmvv.json new file mode 100644 index 00000000000..159a2c085f0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g79q-4pjf-cmvv/GHSA-g79q-4pjf-cmvv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g79q-4pjf-cmvv", + "modified": "2025-04-01T15:31:40Z", + "published": "2025-04-01T15:31:40Z", + "aliases": [ + "CVE-2025-31798" + ], + "details": "Missing Authorization vulnerability in publitio Publitio allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Publitio: from n/a through 2.1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31798" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/publitio/vulnerability/wordpress-publitio-plugin-2-1-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ghpr-7v2r-qpx3/GHSA-ghpr-7v2r-qpx3.json b/advisories/unreviewed/2025/04/GHSA-ghpr-7v2r-qpx3/GHSA-ghpr-7v2r-qpx3.json new file mode 100644 index 00000000000..b92ddd55b05 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ghpr-7v2r-qpx3/GHSA-ghpr-7v2r-qpx3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghpr-7v2r-qpx3", + "modified": "2025-04-01T15:31:41Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31820" + ], + "details": "Missing Authorization vulnerability in webdevstudios Automatic Featured Images from Videos allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Automatic Featured Images from Videos: from n/a through 1.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31820" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/automatic-featured-images-from-videos/vulnerability/wordpress-automatic-featured-images-from-videos-plugin-1-2-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gmf5-x3rp-c8p7/GHSA-gmf5-x3rp-c8p7.json b/advisories/unreviewed/2025/04/GHSA-gmf5-x3rp-c8p7/GHSA-gmf5-x3rp-c8p7.json new file mode 100644 index 00000000000..3d54a9d73b9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gmf5-x3rp-c8p7/GHSA-gmf5-x3rp-c8p7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmf5-x3rp-c8p7", + "modified": "2025-04-01T15:31:44Z", + "published": "2025-04-01T15:31:44Z", + "aliases": [ + "CVE-2025-31861" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPOrbit Support Perfect Font Awesome Integration allows Stored XSS. This issue affects Perfect Font Awesome Integration: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31861" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/perfect-font-awesome-integration/vulnerability/wordpress-perfect-font-awesome-integration-plugin-2-2-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gmw9-8h79-pvq5/GHSA-gmw9-8h79-pvq5.json b/advisories/unreviewed/2025/04/GHSA-gmw9-8h79-pvq5/GHSA-gmw9-8h79-pvq5.json index f1495e28a46..95e24cd3fda 100644 --- a/advisories/unreviewed/2025/04/GHSA-gmw9-8h79-pvq5/GHSA-gmw9-8h79-pvq5.json +++ b/advisories/unreviewed/2025/04/GHSA-gmw9-8h79-pvq5/GHSA-gmw9-8h79-pvq5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gmw9-8h79-pvq5", - "modified": "2025-04-01T00:30:39Z", + "modified": "2025-04-01T15:31:30Z", "published": "2025-04-01T00:30:39Z", "aliases": [ "CVE-2025-24240" ], "details": "A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access user-sensitive data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:21Z" diff --git a/advisories/unreviewed/2025/04/GHSA-gpqx-3365-9jc7/GHSA-gpqx-3365-9jc7.json b/advisories/unreviewed/2025/04/GHSA-gpqx-3365-9jc7/GHSA-gpqx-3365-9jc7.json new file mode 100644 index 00000000000..3cde1505483 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gpqx-3365-9jc7/GHSA-gpqx-3365-9jc7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpqx-3365-9jc7", + "modified": "2025-04-01T15:31:37Z", + "published": "2025-04-01T15:31:37Z", + "aliases": [ + "CVE-2025-31738" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yazamodeveloper LeadQuizzes allows Stored XSS. This issue affects LeadQuizzes: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31738" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/leadquizzes/vulnerability/wordpress-leadquizzes-plugin-1-1-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gq7f-h24x-gv8x/GHSA-gq7f-h24x-gv8x.json b/advisories/unreviewed/2025/04/GHSA-gq7f-h24x-gv8x/GHSA-gq7f-h24x-gv8x.json new file mode 100644 index 00000000000..95ee7935e7c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gq7f-h24x-gv8x/GHSA-gq7f-h24x-gv8x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq7f-h24x-gv8x", + "modified": "2025-04-01T15:31:38Z", + "published": "2025-04-01T15:31:38Z", + "aliases": [ + "CVE-2025-31762" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andreyazimov Sheet2Site allows Stored XSS. This issue affects Sheet2Site: from n/a through 1.0.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31762" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sheet2site/vulnerability/wordpress-sheet2site-plugin-1-0-18-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gqq6-pwhg-228f/GHSA-gqq6-pwhg-228f.json b/advisories/unreviewed/2025/04/GHSA-gqq6-pwhg-228f/GHSA-gqq6-pwhg-228f.json new file mode 100644 index 00000000000..2e380afdc62 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gqq6-pwhg-228f/GHSA-gqq6-pwhg-228f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqq6-pwhg-228f", + "modified": "2025-04-01T15:31:42Z", + "published": "2025-04-01T15:31:42Z", + "aliases": [ + "CVE-2025-31824" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Wombat Plugins WP Optin Wheel allows Server Side Request Forgery. This issue affects WP Optin Wheel: from n/a through 1.4.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31824" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-optin-wheel/vulnerability/wordpress-wp-optin-wheel-plugin-1-4-7-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gqqx-qfhj-4fx6/GHSA-gqqx-qfhj-4fx6.json b/advisories/unreviewed/2025/04/GHSA-gqqx-qfhj-4fx6/GHSA-gqqx-qfhj-4fx6.json new file mode 100644 index 00000000000..7005fb5274d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gqqx-qfhj-4fx6/GHSA-gqqx-qfhj-4fx6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqqx-qfhj-4fx6", + "modified": "2025-04-01T15:31:40Z", + "published": "2025-04-01T15:31:40Z", + "aliases": [ + "CVE-2025-31790" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Binsaifullah Posten allows DOM-Based XSS. This issue affects Posten: from n/a through 0.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31790" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/posten-post-blocks/vulnerability/wordpress-posten-plugin-0-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gvwv-9mwf-hg22/GHSA-gvwv-9mwf-hg22.json b/advisories/unreviewed/2025/04/GHSA-gvwv-9mwf-hg22/GHSA-gvwv-9mwf-hg22.json index 7fec2c23450..e030c3abdfe 100644 --- a/advisories/unreviewed/2025/04/GHSA-gvwv-9mwf-hg22/GHSA-gvwv-9mwf-hg22.json +++ b/advisories/unreviewed/2025/04/GHSA-gvwv-9mwf-hg22/GHSA-gvwv-9mwf-hg22.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gvwv-9mwf-hg22", - "modified": "2025-04-01T00:30:42Z", + "modified": "2025-04-01T15:31:32Z", "published": "2025-04-01T00:30:42Z", "aliases": [ "CVE-2025-30439" ], "details": "The issue was addressed with improved checks. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An attacker with physical access to a locked device may be able to view sensitive user information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:25Z" diff --git a/advisories/unreviewed/2025/04/GHSA-gw3m-4x3x-q7gc/GHSA-gw3m-4x3x-q7gc.json b/advisories/unreviewed/2025/04/GHSA-gw3m-4x3x-q7gc/GHSA-gw3m-4x3x-q7gc.json new file mode 100644 index 00000000000..10af90d3398 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gw3m-4x3x-q7gc/GHSA-gw3m-4x3x-q7gc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gw3m-4x3x-q7gc", + "modified": "2025-04-01T15:31:39Z", + "published": "2025-04-01T15:31:39Z", + "aliases": [ + "CVE-2025-31767" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Post Custom Templates Lite allows Stored XSS. This issue affects Post Custom Templates Lite: from n/a through 1.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31767" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/post-custom-templates-lite/vulnerability/wordpress-post-custom-templates-lite-plugin-1-14-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gw73-hwr2-4qrm/GHSA-gw73-hwr2-4qrm.json b/advisories/unreviewed/2025/04/GHSA-gw73-hwr2-4qrm/GHSA-gw73-hwr2-4qrm.json index 69adc71f88b..6673b4adfea 100644 --- a/advisories/unreviewed/2025/04/GHSA-gw73-hwr2-4qrm/GHSA-gw73-hwr2-4qrm.json +++ b/advisories/unreviewed/2025/04/GHSA-gw73-hwr2-4qrm/GHSA-gw73-hwr2-4qrm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gw73-hwr2-4qrm", - "modified": "2025-04-01T00:30:42Z", + "modified": "2025-04-01T15:31:32Z", "published": "2025-04-01T00:30:42Z", "aliases": [ "CVE-2025-30443" ], "details": "A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access user-sensitive data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:26Z" diff --git a/advisories/unreviewed/2025/04/GHSA-gwhv-vwh6-9335/GHSA-gwhv-vwh6-9335.json b/advisories/unreviewed/2025/04/GHSA-gwhv-vwh6-9335/GHSA-gwhv-vwh6-9335.json new file mode 100644 index 00000000000..8e5c58ee59a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gwhv-vwh6-9335/GHSA-gwhv-vwh6-9335.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwhv-vwh6-9335", + "modified": "2025-04-01T15:31:41Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31816" + ], + "details": "Missing Authorization vulnerability in pietro Mobile App Canvas allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mobile App Canvas: from n/a through 3.8.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31816" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mobile-app/vulnerability/wordpress-mobile-app-canvas-plugin-3-8-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h3xj-xc3c-cvpm/GHSA-h3xj-xc3c-cvpm.json b/advisories/unreviewed/2025/04/GHSA-h3xj-xc3c-cvpm/GHSA-h3xj-xc3c-cvpm.json new file mode 100644 index 00000000000..e5a5cfdf437 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h3xj-xc3c-cvpm/GHSA-h3xj-xc3c-cvpm.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3xj-xc3c-cvpm", + "modified": "2025-04-01T15:31:36Z", + "published": "2025-04-01T15:31:36Z", + "aliases": [ + "CVE-2025-3032" + ], + "details": "Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability affects Firefox < 137 and Thunderbird < 137.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3032" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1949987" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-20" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-23" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h4xc-8mr6-vjh8/GHSA-h4xc-8mr6-vjh8.json b/advisories/unreviewed/2025/04/GHSA-h4xc-8mr6-vjh8/GHSA-h4xc-8mr6-vjh8.json new file mode 100644 index 00000000000..b2f466a7b88 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h4xc-8mr6-vjh8/GHSA-h4xc-8mr6-vjh8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4xc-8mr6-vjh8", + "modified": "2025-04-01T15:31:44Z", + "published": "2025-04-01T15:31:44Z", + "aliases": [ + "CVE-2025-31866" + ], + "details": "Missing Authorization vulnerability in Ship Depot ShipDepot for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ShipDepot for WooCommerce: from n/a through 1.2.19.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31866" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ship-depot/vulnerability/wordpress-shipdepot-for-woocommerce-plugin-1-2-19-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h54m-8jjr-7jf8/GHSA-h54m-8jjr-7jf8.json b/advisories/unreviewed/2025/04/GHSA-h54m-8jjr-7jf8/GHSA-h54m-8jjr-7jf8.json new file mode 100644 index 00000000000..99fd104d743 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h54m-8jjr-7jf8/GHSA-h54m-8jjr-7jf8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h54m-8jjr-7jf8", + "modified": "2025-04-01T15:31:40Z", + "published": "2025-04-01T15:31:40Z", + "aliases": [ + "CVE-2025-31799" + ], + "details": "Missing Authorization vulnerability in publitio Publitio allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Publitio: from n/a through 2.1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31799" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/publitio/vulnerability/wordpress-publitio-plugin-2-1-8-broken-access-control-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h576-hrw7-8mwg/GHSA-h576-hrw7-8mwg.json b/advisories/unreviewed/2025/04/GHSA-h576-hrw7-8mwg/GHSA-h576-hrw7-8mwg.json new file mode 100644 index 00000000000..145c72bd247 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h576-hrw7-8mwg/GHSA-h576-hrw7-8mwg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h576-hrw7-8mwg", + "modified": "2025-04-01T15:31:41Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31815" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devscred Design Blocks allows Stored XSS. This issue affects Design Blocks: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31815" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/exclusive-blocks/vulnerability/wordpress-design-blocks-plugin-1-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h94m-mjfh-2g77/GHSA-h94m-mjfh-2g77.json b/advisories/unreviewed/2025/04/GHSA-h94m-mjfh-2g77/GHSA-h94m-mjfh-2g77.json index 29adf7479f4..63a3f40f335 100644 --- a/advisories/unreviewed/2025/04/GHSA-h94m-mjfh-2g77/GHSA-h94m-mjfh-2g77.json +++ b/advisories/unreviewed/2025/04/GHSA-h94m-mjfh-2g77/GHSA-h94m-mjfh-2g77.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h94m-mjfh-2g77", - "modified": "2025-04-01T00:30:39Z", + "modified": "2025-04-01T15:31:31Z", "published": "2025-04-01T00:30:39Z", "aliases": [ "CVE-2025-24247" ], "details": "A type confusion issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker may be able to cause unexpected app termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:21Z" diff --git a/advisories/unreviewed/2025/04/GHSA-hcm9-4hpj-8jv9/GHSA-hcm9-4hpj-8jv9.json b/advisories/unreviewed/2025/04/GHSA-hcm9-4hpj-8jv9/GHSA-hcm9-4hpj-8jv9.json new file mode 100644 index 00000000000..d626f135dfc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hcm9-4hpj-8jv9/GHSA-hcm9-4hpj-8jv9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcm9-4hpj-8jv9", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31872" + ], + "details": "Missing Authorization vulnerability in Galaxy Weblinks WP Clone any post type allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Clone any post type: from n/a through 3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31872" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-clone-any-post-type/vulnerability/wordpress-wp-clone-any-post-type-plugin-3-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hfhj-x3c5-7mgv/GHSA-hfhj-x3c5-7mgv.json b/advisories/unreviewed/2025/04/GHSA-hfhj-x3c5-7mgv/GHSA-hfhj-x3c5-7mgv.json new file mode 100644 index 00000000000..1e33b74988f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hfhj-x3c5-7mgv/GHSA-hfhj-x3c5-7mgv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfhj-x3c5-7mgv", + "modified": "2025-04-01T15:31:36Z", + "published": "2025-04-01T15:31:36Z", + "aliases": [ + "CVE-2025-28398" + ], + "details": "D-LINK DI-8100 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the remot_ip parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28398" + }, + { + "type": "WEB", + "url": "https://github.com/Fizz-L/Vulnerability-report/blob/main/DI-8100Buffer%20overflow2.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T14:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hh57-6jp9-f58c/GHSA-hh57-6jp9-f58c.json b/advisories/unreviewed/2025/04/GHSA-hh57-6jp9-f58c/GHSA-hh57-6jp9-f58c.json new file mode 100644 index 00000000000..cdcd7b2c14a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hh57-6jp9-f58c/GHSA-hh57-6jp9-f58c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh57-6jp9-f58c", + "modified": "2025-04-01T15:31:44Z", + "published": "2025-04-01T15:31:44Z", + "aliases": [ + "CVE-2025-31870" + ], + "details": "Missing Authorization vulnerability in EXEIdeas International WP AutoKeyword allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP AutoKeyword: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31870" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-autokeyword/vulnerability/wordpress-wp-autokeyword-plugin-1-0-arbitrary-content-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hhqx-qxvc-gw42/GHSA-hhqx-qxvc-gw42.json b/advisories/unreviewed/2025/04/GHSA-hhqx-qxvc-gw42/GHSA-hhqx-qxvc-gw42.json new file mode 100644 index 00000000000..9bcb089257b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hhqx-qxvc-gw42/GHSA-hhqx-qxvc-gw42.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhqx-qxvc-gw42", + "modified": "2025-04-01T15:31:40Z", + "published": "2025-04-01T15:31:39Z", + "aliases": [ + "CVE-2025-31779" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Jonathan Daggerhart Query Wrangler allows Cross Site Request Forgery. This issue affects Query Wrangler: from n/a through 1.5.53.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31779" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/query-wrangler/vulnerability/wordpress-query-wrangler-plugin-1-5-53-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hjj2-mj64-427v/GHSA-hjj2-mj64-427v.json b/advisories/unreviewed/2025/04/GHSA-hjj2-mj64-427v/GHSA-hjj2-mj64-427v.json new file mode 100644 index 00000000000..99f0454779e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hjj2-mj64-427v/GHSA-hjj2-mj64-427v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjj2-mj64-427v", + "modified": "2025-04-01T15:31:37Z", + "published": "2025-04-01T15:31:37Z", + "aliases": [ + "CVE-2025-31735" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in C. Johnson Footnotes for WordPress allows Stored XSS. This issue affects Footnotes for WordPress: from n/a through 2016.1230.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31735" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/footnotes-for-wordpress/vulnerability/wordpress-footnotes-for-wordpress-plugin-2016-1230-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hp5h-mhh6-jhx4/GHSA-hp5h-mhh6-jhx4.json b/advisories/unreviewed/2025/04/GHSA-hp5h-mhh6-jhx4/GHSA-hp5h-mhh6-jhx4.json new file mode 100644 index 00000000000..b40a66ed40c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hp5h-mhh6-jhx4/GHSA-hp5h-mhh6-jhx4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp5h-mhh6-jhx4", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31892" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum WP Crowdfunding allows Stored XSS. This issue affects WP Crowdfunding: from n/a through 2.1.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31892" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-crowdfunding/vulnerability/wordpress-wp-crowdfunding-plugin-2-1-13-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hqj2-c48q-x9m8/GHSA-hqj2-c48q-x9m8.json b/advisories/unreviewed/2025/04/GHSA-hqj2-c48q-x9m8/GHSA-hqj2-c48q-x9m8.json new file mode 100644 index 00000000000..84e47a6f186 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hqj2-c48q-x9m8/GHSA-hqj2-c48q-x9m8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqj2-c48q-x9m8", + "modified": "2025-04-01T15:31:36Z", + "published": "2025-04-01T15:31:36Z", + "aliases": [ + "CVE-2025-31408" + ], + "details": "Missing Authorization vulnerability in Zoho Flow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho Flow: from n/a through 2.13.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31408" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/zoho-flow/vulnerability/wordpress-zoho-flow-plugin-2-13-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hqrg-2p9v-rv84/GHSA-hqrg-2p9v-rv84.json b/advisories/unreviewed/2025/04/GHSA-hqrg-2p9v-rv84/GHSA-hqrg-2p9v-rv84.json new file mode 100644 index 00000000000..62631e6c016 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hqrg-2p9v-rv84/GHSA-hqrg-2p9v-rv84.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqrg-2p9v-rv84", + "modified": "2025-04-01T15:31:41Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31808" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in IT Path Solutions SCSS WP Editor allows Cross Site Request Forgery. This issue affects SCSS WP Editor: from n/a through 1.1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31808" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/scss-wp-editor/vulnerability/wordpress-scss-wp-editor-plugin-1-1-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hvqr-qm4r-c5hx/GHSA-hvqr-qm4r-c5hx.json b/advisories/unreviewed/2025/04/GHSA-hvqr-qm4r-c5hx/GHSA-hvqr-qm4r-c5hx.json new file mode 100644 index 00000000000..5d168c975af --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hvqr-qm4r-c5hx/GHSA-hvqr-qm4r-c5hx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvqr-qm4r-c5hx", + "modified": "2025-04-01T15:31:46Z", + "published": "2025-04-01T15:31:46Z", + "aliases": [ + "CVE-2025-31906" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ProfitShare.ro WP Profitshare allows Stored XSS. This issue affects WP Profitshare: from n/a through 1.4.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31906" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-profitshare/vulnerability/wordpress-wp-profitshare-plugin-1-4-9-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j34j-434j-r63c/GHSA-j34j-434j-r63c.json b/advisories/unreviewed/2025/04/GHSA-j34j-434j-r63c/GHSA-j34j-434j-r63c.json index 62036f1c1c8..8a3ae4650cf 100644 --- a/advisories/unreviewed/2025/04/GHSA-j34j-434j-r63c/GHSA-j34j-434j-r63c.json +++ b/advisories/unreviewed/2025/04/GHSA-j34j-434j-r63c/GHSA-j34j-434j-r63c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j34j-434j-r63c", - "modified": "2025-04-01T00:30:37Z", + "modified": "2025-04-01T15:31:30Z", "published": "2025-04-01T00:30:37Z", "aliases": [ "CVE-2025-24204" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:18Z" diff --git a/advisories/unreviewed/2025/04/GHSA-j7j3-j385-mfpx/GHSA-j7j3-j385-mfpx.json b/advisories/unreviewed/2025/04/GHSA-j7j3-j385-mfpx/GHSA-j7j3-j385-mfpx.json index 775a9f606b5..a68d3b17a9e 100644 --- a/advisories/unreviewed/2025/04/GHSA-j7j3-j385-mfpx/GHSA-j7j3-j385-mfpx.json +++ b/advisories/unreviewed/2025/04/GHSA-j7j3-j385-mfpx/GHSA-j7j3-j385-mfpx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j7j3-j385-mfpx", - "modified": "2025-04-01T00:30:40Z", + "modified": "2025-04-01T15:31:30Z", "published": "2025-04-01T00:30:40Z", "aliases": [ "CVE-2025-24253" ], "details": "This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access protected user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:22Z" diff --git a/advisories/unreviewed/2025/04/GHSA-j8fj-wjcc-r62c/GHSA-j8fj-wjcc-r62c.json b/advisories/unreviewed/2025/04/GHSA-j8fj-wjcc-r62c/GHSA-j8fj-wjcc-r62c.json new file mode 100644 index 00000000000..19786990880 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j8fj-wjcc-r62c/GHSA-j8fj-wjcc-r62c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8fj-wjcc-r62c", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31888" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WPExperts.io WP Multistore Locator allows Cross Site Request Forgery. This issue affects WP Multistore Locator: from n/a through 2.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31888" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-multi-store-locator/vulnerability/wordpress-wp-multi-store-locator-plugin-2-5-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jcg4-vmx5-vfm2/GHSA-jcg4-vmx5-vfm2.json b/advisories/unreviewed/2025/04/GHSA-jcg4-vmx5-vfm2/GHSA-jcg4-vmx5-vfm2.json new file mode 100644 index 00000000000..f4b8a608537 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jcg4-vmx5-vfm2/GHSA-jcg4-vmx5-vfm2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcg4-vmx5-vfm2", + "modified": "2025-04-01T15:31:44Z", + "published": "2025-04-01T15:31:43Z", + "aliases": [ + "CVE-2025-31851" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in markkinchin Beds24 Online Booking allows Stored XSS. This issue affects Beds24 Online Booking: from n/a through 2.0.26.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31851" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/beds24-online-booking/vulnerability/wordpress-beds24-online-booking-plugin-2-0-26-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jjwv-8654-h4h3/GHSA-jjwv-8654-h4h3.json b/advisories/unreviewed/2025/04/GHSA-jjwv-8654-h4h3/GHSA-jjwv-8654-h4h3.json new file mode 100644 index 00000000000..74172a4d825 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jjwv-8654-h4h3/GHSA-jjwv-8654-h4h3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjwv-8654-h4h3", + "modified": "2025-04-01T15:31:41Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31801" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maksym Marko MX Time Zone Clocks allows Reflected XSS. This issue affects MX Time Zone Clocks: from n/a through 5.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31801" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mx-time-zone-clocks/vulnerability/wordpress-mx-time-zone-clocks-plugin-5-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jpj3-4vjw-5jmq/GHSA-jpj3-4vjw-5jmq.json b/advisories/unreviewed/2025/04/GHSA-jpj3-4vjw-5jmq/GHSA-jpj3-4vjw-5jmq.json new file mode 100644 index 00000000000..72e09377b0a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jpj3-4vjw-5jmq/GHSA-jpj3-4vjw-5jmq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpj3-4vjw-5jmq", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31883" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPWebinarSystem WebinarPress allows Stored XSS. This issue affects WebinarPress: from n/a through 1.33.27.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31883" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-webinarsystem/vulnerability/wordpress-webinarpress-plugin-1-33-27-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jq4h-8p8p-vchg/GHSA-jq4h-8p8p-vchg.json b/advisories/unreviewed/2025/04/GHSA-jq4h-8p8p-vchg/GHSA-jq4h-8p8p-vchg.json index b1d5a92b7f5..aa9ffdee4eb 100644 --- a/advisories/unreviewed/2025/04/GHSA-jq4h-8p8p-vchg/GHSA-jq4h-8p8p-vchg.json +++ b/advisories/unreviewed/2025/04/GHSA-jq4h-8p8p-vchg/GHSA-jq4h-8p8p-vchg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jq4h-8p8p-vchg", - "modified": "2025-04-01T00:30:38Z", + "modified": "2025-04-01T15:31:30Z", "published": "2025-04-01T00:30:38Z", "aliases": [ "CVE-2025-24226" ], "details": "The issue was addressed with improved checks. This issue is fixed in Xcode 16.3. A malicious app may be able to access private information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:19Z" diff --git a/advisories/unreviewed/2025/04/GHSA-jrgv-pmf9-6qg5/GHSA-jrgv-pmf9-6qg5.json b/advisories/unreviewed/2025/04/GHSA-jrgv-pmf9-6qg5/GHSA-jrgv-pmf9-6qg5.json index c59ef12af74..978e0aae678 100644 --- a/advisories/unreviewed/2025/04/GHSA-jrgv-pmf9-6qg5/GHSA-jrgv-pmf9-6qg5.json +++ b/advisories/unreviewed/2025/04/GHSA-jrgv-pmf9-6qg5/GHSA-jrgv-pmf9-6qg5.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-59" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-jrrj-28wq-8v79/GHSA-jrrj-28wq-8v79.json b/advisories/unreviewed/2025/04/GHSA-jrrj-28wq-8v79/GHSA-jrrj-28wq-8v79.json new file mode 100644 index 00000000000..508080a6af9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jrrj-28wq-8v79/GHSA-jrrj-28wq-8v79.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrrj-28wq-8v79", + "modified": "2025-04-01T15:31:40Z", + "published": "2025-04-01T15:31:40Z", + "aliases": [ + "CVE-2025-31785" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Clearbit Clearbit Reveal allows Cross Site Request Forgery. This issue affects Clearbit Reveal: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31785" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/clearbit/vulnerability/wordpress-clearbit-reveal-plugin-1-0-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jvjx-g9gr-qvr9/GHSA-jvjx-g9gr-qvr9.json b/advisories/unreviewed/2025/04/GHSA-jvjx-g9gr-qvr9/GHSA-jvjx-g9gr-qvr9.json new file mode 100644 index 00000000000..d43e282af4d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jvjx-g9gr-qvr9/GHSA-jvjx-g9gr-qvr9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvjx-g9gr-qvr9", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31884" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP CMS Ninja Norse Rune Oracle Plugin allows Stored XSS. This issue affects Norse Rune Oracle Plugin: from n/a through 1.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31884" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/norse-runes-oracle/vulnerability/wordpress-norse-rune-oracle-plugin-plugin-1-4-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jw49-5g4r-c94w/GHSA-jw49-5g4r-c94w.json b/advisories/unreviewed/2025/04/GHSA-jw49-5g4r-c94w/GHSA-jw49-5g4r-c94w.json index c1753c38656..06a811f61a3 100644 --- a/advisories/unreviewed/2025/04/GHSA-jw49-5g4r-c94w/GHSA-jw49-5g4r-c94w.json +++ b/advisories/unreviewed/2025/04/GHSA-jw49-5g4r-c94w/GHSA-jw49-5g4r-c94w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jw49-5g4r-c94w", - "modified": "2025-04-01T06:30:44Z", + "modified": "2025-04-01T15:31:35Z", "published": "2025-04-01T06:30:44Z", "aliases": [ "CVE-2025-2048" ], "details": "The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks and download arbitrary files on the server", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T06:15:48Z" diff --git a/advisories/unreviewed/2025/04/GHSA-m2fw-cvrc-qphg/GHSA-m2fw-cvrc-qphg.json b/advisories/unreviewed/2025/04/GHSA-m2fw-cvrc-qphg/GHSA-m2fw-cvrc-qphg.json new file mode 100644 index 00000000000..13fa3534486 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m2fw-cvrc-qphg/GHSA-m2fw-cvrc-qphg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2fw-cvrc-qphg", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31882" + ], + "details": "Missing Authorization vulnerability in WPWebinarSystem WebinarPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WebinarPress: from n/a through 1.33.27.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31882" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-webinarsystem/vulnerability/wordpress-wordpress-webinar-plugin-1-33-27-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m34p-f62r-g5gv/GHSA-m34p-f62r-g5gv.json b/advisories/unreviewed/2025/04/GHSA-m34p-f62r-g5gv/GHSA-m34p-f62r-g5gv.json new file mode 100644 index 00000000000..49bfc14b677 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m34p-f62r-g5gv/GHSA-m34p-f62r-g5gv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m34p-f62r-g5gv", + "modified": "2025-04-01T15:31:42Z", + "published": "2025-04-01T15:31:42Z", + "aliases": [ + "CVE-2025-31834" + ], + "details": "Missing Authorization vulnerability in themeglow JobBoard Job listing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobBoard Job listing: from n/a through 1.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31834" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/job-board-light/vulnerability/wordpress-jobboard-job-listing-plugin-plugin-1-2-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m4g9-f5jj-53v7/GHSA-m4g9-f5jj-53v7.json b/advisories/unreviewed/2025/04/GHSA-m4g9-f5jj-53v7/GHSA-m4g9-f5jj-53v7.json new file mode 100644 index 00000000000..79009643d6c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m4g9-f5jj-53v7/GHSA-m4g9-f5jj-53v7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4g9-f5jj-53v7", + "modified": "2025-04-01T15:31:41Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31804" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DraftPress Team Follow Us Badges allows Stored XSS. This issue affects Follow Us Badges: from n/a through 3.1.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31804" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpsite-follow-us-badges/vulnerability/wordpress-follow-us-badges-plugin-3-1-11-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m4gw-jg94-hxh8/GHSA-m4gw-jg94-hxh8.json b/advisories/unreviewed/2025/04/GHSA-m4gw-jg94-hxh8/GHSA-m4gw-jg94-hxh8.json new file mode 100644 index 00000000000..6208a4cd1c0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m4gw-jg94-hxh8/GHSA-m4gw-jg94-hxh8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4gw-jg94-hxh8", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31895" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in paulrosen ABC Notation allows Stored XSS. This issue affects ABC Notation: from n/a through 6.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31895" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/abc-notation/vulnerability/wordpress-abc-notation-plugin-6-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m8rc-32w6-g64q/GHSA-m8rc-32w6-g64q.json b/advisories/unreviewed/2025/04/GHSA-m8rc-32w6-g64q/GHSA-m8rc-32w6-g64q.json new file mode 100644 index 00000000000..1cc92f5db6e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m8rc-32w6-g64q/GHSA-m8rc-32w6-g64q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8rc-32w6-g64q", + "modified": "2025-04-01T15:31:43Z", + "published": "2025-04-01T15:31:42Z", + "aliases": [ + "CVE-2025-31843" + ], + "details": "Missing Authorization vulnerability in Wilson OpenAI Tools for WordPress & WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects OpenAI Tools for WordPress & WooCommerce: from n/a through 2.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31843" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/openai-tools-for-wp-wc/vulnerability/wordpress-openai-tools-for-wordpress-woocommerce-plugin-2-1-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mggf-7x7r-5cph/GHSA-mggf-7x7r-5cph.json b/advisories/unreviewed/2025/04/GHSA-mggf-7x7r-5cph/GHSA-mggf-7x7r-5cph.json new file mode 100644 index 00000000000..275638a1118 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mggf-7x7r-5cph/GHSA-mggf-7x7r-5cph.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mggf-7x7r-5cph", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31886" + ], + "details": "Missing Authorization vulnerability in Repuso Social proof testimonials and reviews by Repuso allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Social proof testimonials and reviews by Repuso: from n/a through 5.21.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31886" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/social-testimonials-and-reviews-widget/vulnerability/wordpress-social-proof-testimonials-and-reviews-by-repuso-plugin-5-21-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mjcf-4j4v-r58f/GHSA-mjcf-4j4v-r58f.json b/advisories/unreviewed/2025/04/GHSA-mjcf-4j4v-r58f/GHSA-mjcf-4j4v-r58f.json new file mode 100644 index 00000000000..2fef4b3a35e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mjcf-4j4v-r58f/GHSA-mjcf-4j4v-r58f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjcf-4j4v-r58f", + "modified": "2025-04-01T15:31:41Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31807" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in CloudRedux Product Notices for WooCommerce allows Cross Site Request Forgery. This issue affects Product Notices for WooCommerce: from n/a through 1.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31807" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/product-notices-for-woocommerce/vulnerability/wordpress-product-notices-for-woocommerce-plugin-1-3-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mjg4-f5q4-pchv/GHSA-mjg4-f5q4-pchv.json b/advisories/unreviewed/2025/04/GHSA-mjg4-f5q4-pchv/GHSA-mjg4-f5q4-pchv.json new file mode 100644 index 00000000000..07806e71370 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mjg4-f5q4-pchv/GHSA-mjg4-f5q4-pchv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjg4-f5q4-pchv", + "modified": "2025-04-01T15:31:40Z", + "published": "2025-04-01T15:31:40Z", + "aliases": [ + "CVE-2025-31792" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Forms allows Stored XSS. This issue affects Piotnet Forms: from n/a through 1.0.30.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31792" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/piotnetforms/vulnerability/wordpress-piotnet-forms-plugin-1-0-30-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mp8x-jgr7-fr7f/GHSA-mp8x-jgr7-fr7f.json b/advisories/unreviewed/2025/04/GHSA-mp8x-jgr7-fr7f/GHSA-mp8x-jgr7-fr7f.json new file mode 100644 index 00000000000..6e9017b63c4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mp8x-jgr7-fr7f/GHSA-mp8x-jgr7-fr7f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp8x-jgr7-fr7f", + "modified": "2025-04-01T15:31:41Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31805" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Systems Gutena Kit – Gutenberg Blocks and Templates allows Stored XSS. This issue affects Gutena Kit – Gutenberg Blocks and Templates: from n/a through 2.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31805" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gutena-kit/vulnerability/wordpress-gutena-kit-plugin-2-0-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mq5x-p6pm-hm5x/GHSA-mq5x-p6pm-hm5x.json b/advisories/unreviewed/2025/04/GHSA-mq5x-p6pm-hm5x/GHSA-mq5x-p6pm-hm5x.json new file mode 100644 index 00000000000..9d0f1d33a7f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mq5x-p6pm-hm5x/GHSA-mq5x-p6pm-hm5x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq5x-p6pm-hm5x", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31871" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Galaxy Weblinks WP Clone any post type allows Phishing. This issue affects WP Clone any post type: from n/a through 3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31871" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-clone-any-post-type/vulnerability/wordpress-wp-clone-any-post-type-plugin-3-4-open-redirect-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mx5q-c52x-ghjq/GHSA-mx5q-c52x-ghjq.json b/advisories/unreviewed/2025/04/GHSA-mx5q-c52x-ghjq/GHSA-mx5q-c52x-ghjq.json new file mode 100644 index 00000000000..92b189713ca --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mx5q-c52x-ghjq/GHSA-mx5q-c52x-ghjq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx5q-c52x-ghjq", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31890" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mashi Simple Map No Api allows Stored XSS. This issue affects Simple Map No Api: from n/a through 1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31890" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-map-no-api/vulnerability/wordpress-simple-map-no-api-plugin-1-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mx63-53w3-p55h/GHSA-mx63-53w3-p55h.json b/advisories/unreviewed/2025/04/GHSA-mx63-53w3-p55h/GHSA-mx63-53w3-p55h.json new file mode 100644 index 00000000000..d72a25ff4df --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mx63-53w3-p55h/GHSA-mx63-53w3-p55h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx63-53w3-p55h", + "modified": "2025-04-01T15:31:37Z", + "published": "2025-04-01T15:31:37Z", + "aliases": [ + "CVE-2025-31743" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpszaki Lightweight and Responsive Youtube Embed allows Stored XSS. This issue affects Lightweight and Responsive Youtube Embed: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31743" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lightweight-and-responsive-youtube-embed/vulnerability/wordpress-lightweight-and-responsive-youtube-embed-plugin-1-0-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p249-r342-v3rg/GHSA-p249-r342-v3rg.json b/advisories/unreviewed/2025/04/GHSA-p249-r342-v3rg/GHSA-p249-r342-v3rg.json new file mode 100644 index 00000000000..71bd7f01194 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p249-r342-v3rg/GHSA-p249-r342-v3rg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p249-r342-v3rg", + "modified": "2025-04-01T15:31:39Z", + "published": "2025-04-01T15:31:39Z", + "aliases": [ + "CVE-2025-31778" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in raphaelheide Donate Me allows Reflected XSS. This issue affects Donate Me: from n/a through 1.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31778" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/donate-me/vulnerability/wordpress-donate-me-plugin-1-2-5-stored-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p549-c3cg-f4qm/GHSA-p549-c3cg-f4qm.json b/advisories/unreviewed/2025/04/GHSA-p549-c3cg-f4qm/GHSA-p549-c3cg-f4qm.json new file mode 100644 index 00000000000..328b0ce5a73 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p549-c3cg-f4qm/GHSA-p549-c3cg-f4qm.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p549-c3cg-f4qm", + "modified": "2025-04-01T15:31:36Z", + "published": "2025-04-01T15:31:36Z", + "aliases": [ + "CVE-2025-3035" + ], + "details": "By first using the AI chatbot in one tab and later activating it in another tab, the document title of the previous tab would leak into the chat prompt. This vulnerability affects Firefox < 137.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3035" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1952268" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-20" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p572-fmvq-cqvf/GHSA-p572-fmvq-cqvf.json b/advisories/unreviewed/2025/04/GHSA-p572-fmvq-cqvf/GHSA-p572-fmvq-cqvf.json new file mode 100644 index 00000000000..c07b94f9a1d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p572-fmvq-cqvf/GHSA-p572-fmvq-cqvf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p572-fmvq-cqvf", + "modified": "2025-04-01T15:31:41Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31806" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uSystems Webling allows Stored XSS. This issue affects Webling: from n/a through 3.9.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31806" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/webling/vulnerability/wordpress-webling-plugin-3-9-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p5r8-47qx-x497/GHSA-p5r8-47qx-x497.json b/advisories/unreviewed/2025/04/GHSA-p5r8-47qx-x497/GHSA-p5r8-47qx-x497.json new file mode 100644 index 00000000000..6929d539458 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p5r8-47qx-x497/GHSA-p5r8-47qx-x497.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5r8-47qx-x497", + "modified": "2025-04-01T15:31:36Z", + "published": "2025-04-01T15:31:36Z", + "aliases": [ + "CVE-2025-3028" + ], + "details": "JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability affects Firefox < 137, Firefox ESR < 115.22, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird ESR < 128.9.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3028" + }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1941002" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-20" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-21" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-22" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-23" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-24" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p6h2-gw2p-3837/GHSA-p6h2-gw2p-3837.json b/advisories/unreviewed/2025/04/GHSA-p6h2-gw2p-3837/GHSA-p6h2-gw2p-3837.json new file mode 100644 index 00000000000..2806395abbe --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p6h2-gw2p-3837/GHSA-p6h2-gw2p-3837.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6h2-gw2p-3837", + "modified": "2025-04-01T15:31:39Z", + "published": "2025-04-01T15:31:39Z", + "aliases": [ + "CVE-2025-31775" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in smackcoders Google SEO Pressor Snippet allows Cross Site Request Forgery. This issue affects Google SEO Pressor Snippet: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31775" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/google-seo-author-snippets/vulnerability/wordpress-google-seo-pressor-for-rich-snippets-plugin-2-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p85h-h5h6-5xrq/GHSA-p85h-h5h6-5xrq.json b/advisories/unreviewed/2025/04/GHSA-p85h-h5h6-5xrq/GHSA-p85h-h5h6-5xrq.json new file mode 100644 index 00000000000..540a31de80b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p85h-h5h6-5xrq/GHSA-p85h-h5h6-5xrq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p85h-h5h6-5xrq", + "modified": "2025-04-01T15:31:41Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31821" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in formsintegrations Integration of Zoho CRM and Contact Form 7 allows Phishing. This issue affects Integration of Zoho CRM and Contact Form 7: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31821" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/integration-of-zoho-crm-and-contact-form-7/vulnerability/wordpress-integration-of-zoho-crm-and-contact-form-7-plugin-1-0-6-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pc2x-x254-v8p4/GHSA-pc2x-x254-v8p4.json b/advisories/unreviewed/2025/04/GHSA-pc2x-x254-v8p4/GHSA-pc2x-x254-v8p4.json new file mode 100644 index 00000000000..f46866005f1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pc2x-x254-v8p4/GHSA-pc2x-x254-v8p4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc2x-x254-v8p4", + "modified": "2025-04-01T15:31:43Z", + "published": "2025-04-01T15:31:43Z", + "aliases": [ + "CVE-2025-31838" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eventbee Eventbee RSVP Widget allows DOM-Based XSS. This issue affects Eventbee RSVP Widget: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31838" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/eventbee-rsvp-widget/vulnerability/wordpress-eventbee-rsvp-widget-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ph57-fhvc-5x8p/GHSA-ph57-fhvc-5x8p.json b/advisories/unreviewed/2025/04/GHSA-ph57-fhvc-5x8p/GHSA-ph57-fhvc-5x8p.json new file mode 100644 index 00000000000..8878b6e11c6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ph57-fhvc-5x8p/GHSA-ph57-fhvc-5x8p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ph57-fhvc-5x8p", + "modified": "2025-04-01T15:31:39Z", + "published": "2025-04-01T15:31:39Z", + "aliases": [ + "CVE-2025-31772" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify WP Modal Popup with Cookie Integration allows Stored XSS. This issue affects WP Modal Popup with Cookie Integration: from n/a through 2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31772" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-modal-popup-with-cookie-integration/vulnerability/wordpress-wp-modal-popup-with-cookie-integration-plugin-2-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-px6w-64v3-j7gp/GHSA-px6w-64v3-j7gp.json b/advisories/unreviewed/2025/04/GHSA-px6w-64v3-j7gp/GHSA-px6w-64v3-j7gp.json new file mode 100644 index 00000000000..3fc0cca259a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-px6w-64v3-j7gp/GHSA-px6w-64v3-j7gp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px6w-64v3-j7gp", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31873" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sheetdb SheetDB allows Stored XSS. This issue affects SheetDB: from n/a through 1.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31873" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sheetdb/vulnerability/wordpress-sheetdb-plugin-1-3-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q4p7-87j5-56xv/GHSA-q4p7-87j5-56xv.json b/advisories/unreviewed/2025/04/GHSA-q4p7-87j5-56xv/GHSA-q4p7-87j5-56xv.json new file mode 100644 index 00000000000..d4e970d7268 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q4p7-87j5-56xv/GHSA-q4p7-87j5-56xv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4p7-87j5-56xv", + "modified": "2025-04-01T15:31:40Z", + "published": "2025-04-01T15:31:40Z", + "aliases": [ + "CVE-2025-31788" + ], + "details": "Insertion of Sensitive Information into Log File vulnerability in smackcoders AIO Performance Profiler, Monitor, Optimize, Compress & Debug allows Retrieve Embedded Sensitive Data. This issue affects AIO Performance Profiler, Monitor, Optimize, Compress & Debug: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31788" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/all-in-one-performance-accelerator/vulnerability/wordpress-aio-performance-profiler-monitor-optimize-compress-debug-plugin-1-2-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q6jw-4hgf-xx92/GHSA-q6jw-4hgf-xx92.json b/advisories/unreviewed/2025/04/GHSA-q6jw-4hgf-xx92/GHSA-q6jw-4hgf-xx92.json new file mode 100644 index 00000000000..b3b673f1dd6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q6jw-4hgf-xx92/GHSA-q6jw-4hgf-xx92.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6jw-4hgf-xx92", + "modified": "2025-04-01T15:31:35Z", + "published": "2025-04-01T15:31:35Z", + "aliases": [ + "CVE-2025-1659" + ], + "details": "A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1659" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0002" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qc63-7rf8-9p8x/GHSA-qc63-7rf8-9p8x.json b/advisories/unreviewed/2025/04/GHSA-qc63-7rf8-9p8x/GHSA-qc63-7rf8-9p8x.json new file mode 100644 index 00000000000..8e4f937fd41 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qc63-7rf8-9p8x/GHSA-qc63-7rf8-9p8x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc63-7rf8-9p8x", + "modified": "2025-04-01T15:31:39Z", + "published": "2025-04-01T15:31:39Z", + "aliases": [ + "CVE-2025-31776" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Aphotrax Uptime Robot Plugin for WordPress allows Cross Site Request Forgery. This issue affects Uptime Robot Plugin for WordPress: from n/a through 2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31776" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/uptime-robot-monitor/vulnerability/wordpress-uptime-robot-plugin-2-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qrx7-4fmv-56wc/GHSA-qrx7-4fmv-56wc.json b/advisories/unreviewed/2025/04/GHSA-qrx7-4fmv-56wc/GHSA-qrx7-4fmv-56wc.json index f065710ca7a..0d4bd0eeb04 100644 --- a/advisories/unreviewed/2025/04/GHSA-qrx7-4fmv-56wc/GHSA-qrx7-4fmv-56wc.json +++ b/advisories/unreviewed/2025/04/GHSA-qrx7-4fmv-56wc/GHSA-qrx7-4fmv-56wc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qrx7-4fmv-56wc", - "modified": "2025-04-01T00:30:36Z", + "modified": "2025-04-01T15:31:30Z", "published": "2025-04-01T00:30:36Z", "aliases": [ "CVE-2025-24192" ], "details": "A script imports issue was addressed with improved isolation. This issue is fixed in Safari 18.4, visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. Visiting a website may leak sensitive data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:17Z" diff --git a/advisories/unreviewed/2025/04/GHSA-qvv4-xwrq-f5qv/GHSA-qvv4-xwrq-f5qv.json b/advisories/unreviewed/2025/04/GHSA-qvv4-xwrq-f5qv/GHSA-qvv4-xwrq-f5qv.json new file mode 100644 index 00000000000..44f2a545066 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qvv4-xwrq-f5qv/GHSA-qvv4-xwrq-f5qv.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvv4-xwrq-f5qv", + "modified": "2025-04-01T15:31:36Z", + "published": "2025-04-01T15:31:36Z", + "aliases": [ + "CVE-2025-22231" + ], + "details": "VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can escalate their privileges to root on the appliance running VMware Aria Operations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22231" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25541" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qx9q-mw3x-qjh6/GHSA-qx9q-mw3x-qjh6.json b/advisories/unreviewed/2025/04/GHSA-qx9q-mw3x-qjh6/GHSA-qx9q-mw3x-qjh6.json new file mode 100644 index 00000000000..04ae54c04d4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qx9q-mw3x-qjh6/GHSA-qx9q-mw3x-qjh6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qx9q-mw3x-qjh6", + "modified": "2025-04-01T15:31:39Z", + "published": "2025-04-01T15:31:39Z", + "aliases": [ + "CVE-2025-31770" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Content Manager Light allows Stored XSS. This issue affects Content Manager Light: from n/a through 3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31770" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/content-manager-light/vulnerability/wordpress-content-manager-light-plugin-3-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qxhm-5vqv-9j5q/GHSA-qxhm-5vqv-9j5q.json b/advisories/unreviewed/2025/04/GHSA-qxhm-5vqv-9j5q/GHSA-qxhm-5vqv-9j5q.json index b46d87cff47..2d06df6af56 100644 --- a/advisories/unreviewed/2025/04/GHSA-qxhm-5vqv-9j5q/GHSA-qxhm-5vqv-9j5q.json +++ b/advisories/unreviewed/2025/04/GHSA-qxhm-5vqv-9j5q/GHSA-qxhm-5vqv-9j5q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qxhm-5vqv-9j5q", - "modified": "2025-04-01T00:30:43Z", + "modified": "2025-04-01T15:31:34Z", "published": "2025-04-01T00:30:43Z", "aliases": [ "CVE-2025-30463" ], "details": "The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:27Z" diff --git a/advisories/unreviewed/2025/04/GHSA-r67p-5vv5-qw2q/GHSA-r67p-5vv5-qw2q.json b/advisories/unreviewed/2025/04/GHSA-r67p-5vv5-qw2q/GHSA-r67p-5vv5-qw2q.json new file mode 100644 index 00000000000..e2bbb3a35d3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r67p-5vv5-qw2q/GHSA-r67p-5vv5-qw2q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r67p-5vv5-qw2q", + "modified": "2025-04-01T15:31:43Z", + "published": "2025-04-01T15:31:43Z", + "aliases": [ + "CVE-2025-31847" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themelooks mFolio Lite allows DOM-Based XSS. This issue affects mFolio Lite: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31847" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mfolio-lite/vulnerability/wordpress-mfolio-lite-plugin-1-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r94p-hcr3-3qp9/GHSA-r94p-hcr3-3qp9.json b/advisories/unreviewed/2025/04/GHSA-r94p-hcr3-3qp9/GHSA-r94p-hcr3-3qp9.json new file mode 100644 index 00000000000..6ad781f5e09 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r94p-hcr3-3qp9/GHSA-r94p-hcr3-3qp9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r94p-hcr3-3qp9", + "modified": "2025-04-01T15:31:35Z", + "published": "2025-04-01T15:31:35Z", + "aliases": [ + "CVE-2025-1660" + ], + "details": "A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1660" + }, + { + "type": "WEB", + "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0002" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r9x5-x5m3-2xrf/GHSA-r9x5-x5m3-2xrf.json b/advisories/unreviewed/2025/04/GHSA-r9x5-x5m3-2xrf/GHSA-r9x5-x5m3-2xrf.json new file mode 100644 index 00000000000..47252b2ee81 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r9x5-x5m3-2xrf/GHSA-r9x5-x5m3-2xrf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9x5-x5m3-2xrf", + "modified": "2025-04-01T15:31:38Z", + "published": "2025-04-01T15:31:38Z", + "aliases": [ + "CVE-2025-31748" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpopal Opal Portfolio allows Stored XSS. This issue affects Opal Portfolio: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31748" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/opal-portfolios/vulnerability/wordpress-opal-portfolio-plugin-1-0-4-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rc27-pgc8-phj2/GHSA-rc27-pgc8-phj2.json b/advisories/unreviewed/2025/04/GHSA-rc27-pgc8-phj2/GHSA-rc27-pgc8-phj2.json new file mode 100644 index 00000000000..8ccc744dfae --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rc27-pgc8-phj2/GHSA-rc27-pgc8-phj2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rc27-pgc8-phj2", + "modified": "2025-04-01T15:31:44Z", + "published": "2025-04-01T15:31:44Z", + "aliases": [ + "CVE-2025-31867" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Job Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JS Job Manager: from n/a through 2.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31867" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/js-jobs/vulnerability/wordpress-js-job-manager-plugin-2-0-2-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rh2r-j62v-h8x5/GHSA-rh2r-j62v-h8x5.json b/advisories/unreviewed/2025/04/GHSA-rh2r-j62v-h8x5/GHSA-rh2r-j62v-h8x5.json new file mode 100644 index 00000000000..4af213f6ada --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rh2r-j62v-h8x5/GHSA-rh2r-j62v-h8x5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh2r-j62v-h8x5", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31894" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infoway LLC Ebook Downloader allows Stored XSS. This issue affects Ebook Downloader: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31894" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ebook-downloader/vulnerability/wordpress-ebook-downloader-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rh3m-2p8j-6cf7/GHSA-rh3m-2p8j-6cf7.json b/advisories/unreviewed/2025/04/GHSA-rh3m-2p8j-6cf7/GHSA-rh3m-2p8j-6cf7.json index 03fdd0c18b9..2dea3fe5b00 100644 --- a/advisories/unreviewed/2025/04/GHSA-rh3m-2p8j-6cf7/GHSA-rh3m-2p8j-6cf7.json +++ b/advisories/unreviewed/2025/04/GHSA-rh3m-2p8j-6cf7/GHSA-rh3m-2p8j-6cf7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rh3m-2p8j-6cf7", - "modified": "2025-04-01T00:30:44Z", + "modified": "2025-04-01T15:31:34Z", "published": "2025-04-01T00:30:44Z", "aliases": [ "CVE-2025-31183" ], "details": "The issue was addressed with improved restriction of data container access. This issue is fixed in macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, tvOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:28Z" diff --git a/advisories/unreviewed/2025/04/GHSA-rh6q-6p7c-c4fc/GHSA-rh6q-6p7c-c4fc.json b/advisories/unreviewed/2025/04/GHSA-rh6q-6p7c-c4fc/GHSA-rh6q-6p7c-c4fc.json new file mode 100644 index 00000000000..a115a120eea --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rh6q-6p7c-c4fc/GHSA-rh6q-6p7c-c4fc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh6q-6p7c-c4fc", + "modified": "2025-04-01T15:31:39Z", + "published": "2025-04-01T15:31:39Z", + "aliases": [ + "CVE-2025-31784" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rudy Susanto Embed Extended – Embed Maps, Videos, Websites, Source Codes, and more allows Cross Site Request Forgery. This issue affects Embed Extended – Embed Maps, Videos, Websites, Source Codes, and more: from n/a through 1.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31784" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/embed-extended/vulnerability/wordpress-embed-extended-embed-maps-videos-websites-source-codes-and-more-plugin-1-4-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rmww-278f-6fpv/GHSA-rmww-278f-6fpv.json b/advisories/unreviewed/2025/04/GHSA-rmww-278f-6fpv/GHSA-rmww-278f-6fpv.json new file mode 100644 index 00000000000..44d2234d8a0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rmww-278f-6fpv/GHSA-rmww-278f-6fpv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmww-278f-6fpv", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31881" + ], + "details": "Missing Authorization vulnerability in Stylemix Pearl allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pearl: from n/a through 1.3.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31881" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pearl-header-builder/vulnerability/wordpress-pearl-plugin-1-3-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rp52-2w9h-29c9/GHSA-rp52-2w9h-29c9.json b/advisories/unreviewed/2025/04/GHSA-rp52-2w9h-29c9/GHSA-rp52-2w9h-29c9.json new file mode 100644 index 00000000000..866197fc614 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rp52-2w9h-29c9/GHSA-rp52-2w9h-29c9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rp52-2w9h-29c9", + "modified": "2025-04-01T15:31:40Z", + "published": "2025-04-01T15:31:40Z", + "aliases": [ + "CVE-2025-31781" + ], + "details": "Missing Authorization vulnerability in ahmadshyk Gift Cards for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Gift Cards for WooCommerce: from n/a through 1.5.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31781" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-giftcards/vulnerability/wordpress-gift-cards-for-woocommerce-plugin-1-5-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rppw-g286-fr24/GHSA-rppw-g286-fr24.json b/advisories/unreviewed/2025/04/GHSA-rppw-g286-fr24/GHSA-rppw-g286-fr24.json new file mode 100644 index 00000000000..bc61ef7f897 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rppw-g286-fr24/GHSA-rppw-g286-fr24.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rppw-g286-fr24", + "modified": "2025-04-01T15:31:43Z", + "published": "2025-04-01T15:31:43Z", + "aliases": [ + "CVE-2025-31840" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in digireturn Simple Fixed Notice allows Cross Site Request Forgery. This issue affects Simple Fixed Notice: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31840" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dn-cookie-notice/vulnerability/wordpress-simple-fixed-notice-plugin-1-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rpxq-378c-2wpg/GHSA-rpxq-378c-2wpg.json b/advisories/unreviewed/2025/04/GHSA-rpxq-378c-2wpg/GHSA-rpxq-378c-2wpg.json new file mode 100644 index 00000000000..26739d471de --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rpxq-378c-2wpg/GHSA-rpxq-378c-2wpg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpxq-378c-2wpg", + "modified": "2025-04-01T15:31:43Z", + "published": "2025-04-01T15:31:43Z", + "aliases": [ + "CVE-2025-31857" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWax Directorist AddonsKit for Elementor allows Stored XSS. This issue affects Directorist AddonsKit for Elementor: from n/a through 1.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31857" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/addonskit-for-elementor/vulnerability/wordpress-directorist-addonskit-for-elementor-plugin-1-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rqp3-mh44-cf98/GHSA-rqp3-mh44-cf98.json b/advisories/unreviewed/2025/04/GHSA-rqp3-mh44-cf98/GHSA-rqp3-mh44-cf98.json index 021e6675f9f..d3ff3053dad 100644 --- a/advisories/unreviewed/2025/04/GHSA-rqp3-mh44-cf98/GHSA-rqp3-mh44-cf98.json +++ b/advisories/unreviewed/2025/04/GHSA-rqp3-mh44-cf98/GHSA-rqp3-mh44-cf98.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rqp3-mh44-cf98", - "modified": "2025-04-01T00:30:43Z", + "modified": "2025-04-01T15:31:33Z", "published": "2025-04-01T00:30:43Z", "aliases": [ "CVE-2025-30462" ], "details": "A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Apps that appear to use App Sandbox may be able to launch without restrictions.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:27Z" diff --git a/advisories/unreviewed/2025/04/GHSA-rrx2-wcx5-4wcq/GHSA-rrx2-wcx5-4wcq.json b/advisories/unreviewed/2025/04/GHSA-rrx2-wcx5-4wcq/GHSA-rrx2-wcx5-4wcq.json new file mode 100644 index 00000000000..ea77b78ca62 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rrx2-wcx5-4wcq/GHSA-rrx2-wcx5-4wcq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrx2-wcx5-4wcq", + "modified": "2025-04-01T15:31:39Z", + "published": "2025-04-01T15:31:38Z", + "aliases": [ + "CVE-2025-31764" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Preliot Cache control by Cacholong allows Stored XSS. This issue affects Cache control by Cacholong: from n/a through 5.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31764" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cache-control-by-cacholong/vulnerability/wordpress-cache-control-by-cacholong-plugin-5-4-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rw6m-2rv9-w377/GHSA-rw6m-2rv9-w377.json b/advisories/unreviewed/2025/04/GHSA-rw6m-2rv9-w377/GHSA-rw6m-2rv9-w377.json new file mode 100644 index 00000000000..a068f26aa9e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rw6m-2rv9-w377/GHSA-rw6m-2rv9-w377.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw6m-2rv9-w377", + "modified": "2025-04-01T15:31:44Z", + "published": "2025-04-01T15:31:44Z", + "aliases": [ + "CVE-2025-31864" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Out the Box Beam me up Scotty – Back to Top Button allows Stored XSS. This issue affects Beam me up Scotty – Back to Top Button: from n/a through 1.0.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31864" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/beam-me-up-scotty/vulnerability/wordpress-beam-me-up-scotty-back-to-top-button-plugin-1-0-23-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rwvj-3jx7-frmw/GHSA-rwvj-3jx7-frmw.json b/advisories/unreviewed/2025/04/GHSA-rwvj-3jx7-frmw/GHSA-rwvj-3jx7-frmw.json index 67f8c68f8dd..94f2c0d44c7 100644 --- a/advisories/unreviewed/2025/04/GHSA-rwvj-3jx7-frmw/GHSA-rwvj-3jx7-frmw.json +++ b/advisories/unreviewed/2025/04/GHSA-rwvj-3jx7-frmw/GHSA-rwvj-3jx7-frmw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rwvj-3jx7-frmw", - "modified": "2025-04-01T00:30:44Z", + "modified": "2025-04-01T15:31:34Z", "published": "2025-04-01T00:30:44Z", "aliases": [ "CVE-2025-31182" ], "details": "This issue was addressed with improved handling of symlinks. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to delete files for which it does not have permission.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:28Z" diff --git a/advisories/unreviewed/2025/04/GHSA-rx3c-2g3m-g6mc/GHSA-rx3c-2g3m-g6mc.json b/advisories/unreviewed/2025/04/GHSA-rx3c-2g3m-g6mc/GHSA-rx3c-2g3m-g6mc.json new file mode 100644 index 00000000000..565980fffec --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rx3c-2g3m-g6mc/GHSA-rx3c-2g3m-g6mc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx3c-2g3m-g6mc", + "modified": "2025-04-01T15:31:38Z", + "published": "2025-04-01T15:31:38Z", + "aliases": [ + "CVE-2025-31751" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in doit Breaking News WP allows Cross Site Request Forgery. This issue affects Breaking News WP: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31751" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/breaking-news-wp/vulnerability/wordpress-breaking-news-wp-plugin-1-3-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v3qr-7hm5-5r4j/GHSA-v3qr-7hm5-5r4j.json b/advisories/unreviewed/2025/04/GHSA-v3qr-7hm5-5r4j/GHSA-v3qr-7hm5-5r4j.json index 144b1d6d3e1..8d1a9a0c9bd 100644 --- a/advisories/unreviewed/2025/04/GHSA-v3qr-7hm5-5r4j/GHSA-v3qr-7hm5-5r4j.json +++ b/advisories/unreviewed/2025/04/GHSA-v3qr-7hm5-5r4j/GHSA-v3qr-7hm5-5r4j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v3qr-7hm5-5r4j", - "modified": "2025-04-01T00:30:38Z", + "modified": "2025-04-01T15:31:30Z", "published": "2025-04-01T00:30:38Z", "aliases": [ "CVE-2025-24228" ], "details": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to execute arbitrary code with kernel privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-v43j-97r2-rhf5/GHSA-v43j-97r2-rhf5.json b/advisories/unreviewed/2025/04/GHSA-v43j-97r2-rhf5/GHSA-v43j-97r2-rhf5.json new file mode 100644 index 00000000000..6e7bf3aee3d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v43j-97r2-rhf5/GHSA-v43j-97r2-rhf5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v43j-97r2-rhf5", + "modified": "2025-04-01T15:31:37Z", + "published": "2025-04-01T15:31:37Z", + "aliases": [ + "CVE-2025-31737" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dxladner Client Showcase allows Stored XSS. This issue affects Client Showcase: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31737" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/client-showcase/vulnerability/wordpress-client-showcase-plugin-1-2-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v7jj-vhq2-vgc8/GHSA-v7jj-vhq2-vgc8.json b/advisories/unreviewed/2025/04/GHSA-v7jj-vhq2-vgc8/GHSA-v7jj-vhq2-vgc8.json index 2e093fffa6f..f6fcdd04ba1 100644 --- a/advisories/unreviewed/2025/04/GHSA-v7jj-vhq2-vgc8/GHSA-v7jj-vhq2-vgc8.json +++ b/advisories/unreviewed/2025/04/GHSA-v7jj-vhq2-vgc8/GHSA-v7jj-vhq2-vgc8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v7jj-vhq2-vgc8", - "modified": "2025-04-01T00:30:40Z", + "modified": "2025-04-01T15:31:31Z", "published": "2025-04-01T00:30:40Z", "aliases": [ "CVE-2025-24266" ], "details": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause unexpected system termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:23Z" diff --git a/advisories/unreviewed/2025/04/GHSA-v892-g2jf-5q7g/GHSA-v892-g2jf-5q7g.json b/advisories/unreviewed/2025/04/GHSA-v892-g2jf-5q7g/GHSA-v892-g2jf-5q7g.json new file mode 100644 index 00000000000..365d232a426 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v892-g2jf-5q7g/GHSA-v892-g2jf-5q7g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v892-g2jf-5q7g", + "modified": "2025-04-01T15:31:41Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31812" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomas BuddyPress Members Only allows Stored XSS. This issue affects BuddyPress Members Only: from n/a through 3.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31812" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/buddypress-members-only/vulnerability/wordpress-buddypress-members-only-plugin-3-5-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vg87-mcfx-5m8m/GHSA-vg87-mcfx-5m8m.json b/advisories/unreviewed/2025/04/GHSA-vg87-mcfx-5m8m/GHSA-vg87-mcfx-5m8m.json new file mode 100644 index 00000000000..0a5c4c82752 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vg87-mcfx-5m8m/GHSA-vg87-mcfx-5m8m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg87-mcfx-5m8m", + "modified": "2025-04-01T15:31:39Z", + "published": "2025-04-01T15:31:39Z", + "aliases": [ + "CVE-2025-31765" + ], + "details": "Missing Authorization vulnerability in themeqx GDPR Cookie Notice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GDPR Cookie Notice: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31765" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gdpr-cookie-notice/vulnerability/wordpress-gdpr-cookie-notice-plugin-1-2-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vhg6-m6c8-39c2/GHSA-vhg6-m6c8-39c2.json b/advisories/unreviewed/2025/04/GHSA-vhg6-m6c8-39c2/GHSA-vhg6-m6c8-39c2.json new file mode 100644 index 00000000000..7b0ad264162 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vhg6-m6c8-39c2/GHSA-vhg6-m6c8-39c2.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhg6-m6c8-39c2", + "modified": "2025-04-01T15:31:37Z", + "published": "2025-04-01T15:31:37Z", + "aliases": [ + "CVE-2025-30676" + ], + "details": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz.\n\nThis issue affects Apache OFBiz: before 18.12.19.\n\nUsers are recommended to upgrade to version 18.12.19, which fixes the issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30676" + }, + { + "type": "WEB", + "url": "https://issues.apache.org/jira/browse/OFBIZ-13219" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/8d718qt8dqthnw1gmyxsq8glfdjklnjf" + }, + { + "type": "WEB", + "url": "https://ofbiz.apache.org/download.html" + }, + { + "type": "WEB", + "url": "https://ofbiz.apache.org/security.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vhq9-x7cx-387j/GHSA-vhq9-x7cx-387j.json b/advisories/unreviewed/2025/04/GHSA-vhq9-x7cx-387j/GHSA-vhq9-x7cx-387j.json index d162a5af3b1..ad04c178467 100644 --- a/advisories/unreviewed/2025/04/GHSA-vhq9-x7cx-387j/GHSA-vhq9-x7cx-387j.json +++ b/advisories/unreviewed/2025/04/GHSA-vhq9-x7cx-387j/GHSA-vhq9-x7cx-387j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vhq9-x7cx-387j", - "modified": "2025-04-01T00:30:36Z", + "modified": "2025-04-01T15:31:30Z", "published": "2025-04-01T00:30:36Z", "aliases": [ "CVE-2025-24195" ], "details": "An integer overflow was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A user may be able to elevate privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:17Z" diff --git a/advisories/unreviewed/2025/04/GHSA-vm8m-rr8q-8rjw/GHSA-vm8m-rr8q-8rjw.json b/advisories/unreviewed/2025/04/GHSA-vm8m-rr8q-8rjw/GHSA-vm8m-rr8q-8rjw.json index 8e86eeee00a..af6ab340425 100644 --- a/advisories/unreviewed/2025/04/GHSA-vm8m-rr8q-8rjw/GHSA-vm8m-rr8q-8rjw.json +++ b/advisories/unreviewed/2025/04/GHSA-vm8m-rr8q-8rjw/GHSA-vm8m-rr8q-8rjw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vm8m-rr8q-8rjw", - "modified": "2025-04-01T00:30:43Z", + "modified": "2025-04-01T15:31:33Z", "published": "2025-04-01T00:30:43Z", "aliases": [ "CVE-2025-30455" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access private information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:27Z" diff --git a/advisories/unreviewed/2025/04/GHSA-vmh7-68x6-gw3h/GHSA-vmh7-68x6-gw3h.json b/advisories/unreviewed/2025/04/GHSA-vmh7-68x6-gw3h/GHSA-vmh7-68x6-gw3h.json index dca62459188..3288fa9d923 100644 --- a/advisories/unreviewed/2025/04/GHSA-vmh7-68x6-gw3h/GHSA-vmh7-68x6-gw3h.json +++ b/advisories/unreviewed/2025/04/GHSA-vmh7-68x6-gw3h/GHSA-vmh7-68x6-gw3h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vmh7-68x6-gw3h", - "modified": "2025-04-01T00:30:36Z", + "modified": "2025-04-01T15:31:30Z", "published": "2025-04-01T00:30:36Z", "aliases": [ "CVE-2025-24181" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access protected user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:17Z" diff --git a/advisories/unreviewed/2025/04/GHSA-vwmv-cx3v-9rvw/GHSA-vwmv-cx3v-9rvw.json b/advisories/unreviewed/2025/04/GHSA-vwmv-cx3v-9rvw/GHSA-vwmv-cx3v-9rvw.json new file mode 100644 index 00000000000..af41e78c4e4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vwmv-cx3v-9rvw/GHSA-vwmv-cx3v-9rvw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwmv-cx3v-9rvw", + "modified": "2025-04-01T15:31:41Z", + "published": "2025-04-01T15:31:41Z", + "aliases": [ + "CVE-2025-31802" + ], + "details": "Missing Authorization vulnerability in Shiptimize Shiptimize for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Shiptimize for WooCommerce: from n/a through 3.1.86.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31802" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/shiptimize-for-woocommerce/vulnerability/wordpress-shiptimize-for-woocommerce-plugin-3-1-86-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vxqw-pv3j-g765/GHSA-vxqw-pv3j-g765.json b/advisories/unreviewed/2025/04/GHSA-vxqw-pv3j-g765/GHSA-vxqw-pv3j-g765.json new file mode 100644 index 00000000000..da051060614 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vxqw-pv3j-g765/GHSA-vxqw-pv3j-g765.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxqw-pv3j-g765", + "modified": "2025-04-01T15:31:44Z", + "published": "2025-04-01T15:31:44Z", + "aliases": [ + "CVE-2025-31863" + ], + "details": "Missing Authorization vulnerability in inspry Agency Toolkit allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Agency Toolkit: from n/a through 1.0.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31863" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/agency-toolkit/vulnerability/wordpress-agency-toolkit-plugin-1-0-23-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vxrm-x722-93pv/GHSA-vxrm-x722-93pv.json b/advisories/unreviewed/2025/04/GHSA-vxrm-x722-93pv/GHSA-vxrm-x722-93pv.json new file mode 100644 index 00000000000..02c85f5edc1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vxrm-x722-93pv/GHSA-vxrm-x722-93pv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxrm-x722-93pv", + "modified": "2025-04-01T15:31:38Z", + "published": "2025-04-01T15:31:38Z", + "aliases": [ + "CVE-2025-31757" + ], + "details": "Missing Authorization vulnerability in BinaryCarpenter Free Woocommerce Product Table View allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Free Woocommerce Product Table View: from n/a through 1.78.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31757" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/free-product-table-for-woocommerce/vulnerability/wordpress-free-woocommerce-product-table-view-plugin-1-78-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w5p4-prg7-wvr7/GHSA-w5p4-prg7-wvr7.json b/advisories/unreviewed/2025/04/GHSA-w5p4-prg7-wvr7/GHSA-w5p4-prg7-wvr7.json new file mode 100644 index 00000000000..611e0d3b8a5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w5p4-prg7-wvr7/GHSA-w5p4-prg7-wvr7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5p4-prg7-wvr7", + "modified": "2025-04-01T15:31:43Z", + "published": "2025-04-01T15:31:43Z", + "aliases": [ + "CVE-2025-31842" + ], + "details": "Insertion of Sensitive Information Into Sent Data vulnerability in viralloops Viral Loops WP Integration allows Retrieve Embedded Sensitive Data. This issue affects Viral Loops WP Integration: from n/a through 3.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31842" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/viral-loops-wp-integration/vulnerability/wordpress-viral-loops-wp-integration-plugin-3-4-0-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wccc-m55j-r27w/GHSA-wccc-m55j-r27w.json b/advisories/unreviewed/2025/04/GHSA-wccc-m55j-r27w/GHSA-wccc-m55j-r27w.json new file mode 100644 index 00000000000..404c6957d9a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wccc-m55j-r27w/GHSA-wccc-m55j-r27w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wccc-m55j-r27w", + "modified": "2025-04-01T15:31:40Z", + "published": "2025-04-01T15:31:40Z", + "aliases": [ + "CVE-2025-31774" + ], + "details": "Missing Authorization vulnerability in WebProtect.ai Astra Security Suite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Astra Security Suite: from n/a through 0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31774" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/getastra/vulnerability/wordpress-astra-security-suite-plugin-0-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wcfr-cg3h-82r8/GHSA-wcfr-cg3h-82r8.json b/advisories/unreviewed/2025/04/GHSA-wcfr-cg3h-82r8/GHSA-wcfr-cg3h-82r8.json new file mode 100644 index 00000000000..5fc41b0dc8e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wcfr-cg3h-82r8/GHSA-wcfr-cg3h-82r8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcfr-cg3h-82r8", + "modified": "2025-04-01T15:31:39Z", + "published": "2025-04-01T15:31:39Z", + "aliases": [ + "CVE-2025-31777" + ], + "details": "Missing Authorization vulnerability in BeastThemes Clockinator Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Clockinator Lite: from n/a through 1.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31777" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/clockify-lite/vulnerability/wordpress-clockinator-lite-plugin-1-0-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wcmp-v3vv-5mr6/GHSA-wcmp-v3vv-5mr6.json b/advisories/unreviewed/2025/04/GHSA-wcmp-v3vv-5mr6/GHSA-wcmp-v3vv-5mr6.json new file mode 100644 index 00000000000..650bddb6930 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wcmp-v3vv-5mr6/GHSA-wcmp-v3vv-5mr6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcmp-v3vv-5mr6", + "modified": "2025-04-01T15:31:43Z", + "published": "2025-04-01T15:31:43Z", + "aliases": [ + "CVE-2025-31849" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fbtemplates Nemesis All-in-One allows Stored XSS. This issue affects Nemesis All-in-One: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31849" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nemesis-all-in-one/vulnerability/wordpress-nemesis-all-in-one-newspaper-builder-elementor-extention-plugin-1-1-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-whhr-6p94-vcj4/GHSA-whhr-6p94-vcj4.json b/advisories/unreviewed/2025/04/GHSA-whhr-6p94-vcj4/GHSA-whhr-6p94-vcj4.json index 84a0bafcb83..fb0fee372e6 100644 --- a/advisories/unreviewed/2025/04/GHSA-whhr-6p94-vcj4/GHSA-whhr-6p94-vcj4.json +++ b/advisories/unreviewed/2025/04/GHSA-whhr-6p94-vcj4/GHSA-whhr-6p94-vcj4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-whhr-6p94-vcj4", - "modified": "2025-04-01T00:30:41Z", + "modified": "2025-04-01T15:31:32Z", "published": "2025-04-01T00:30:41Z", "aliases": [ "CVE-2025-30429" ], "details": "A path handling issue was addressed with improved validation. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to break out of its sandbox.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:25Z" diff --git a/advisories/unreviewed/2025/04/GHSA-wr75-hw2j-2jxm/GHSA-wr75-hw2j-2jxm.json b/advisories/unreviewed/2025/04/GHSA-wr75-hw2j-2jxm/GHSA-wr75-hw2j-2jxm.json index 200bb4226af..d5d3443fcbf 100644 --- a/advisories/unreviewed/2025/04/GHSA-wr75-hw2j-2jxm/GHSA-wr75-hw2j-2jxm.json +++ b/advisories/unreviewed/2025/04/GHSA-wr75-hw2j-2jxm/GHSA-wr75-hw2j-2jxm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wr75-hw2j-2jxm", - "modified": "2025-04-01T00:30:43Z", + "modified": "2025-04-01T15:31:33Z", "published": "2025-04-01T00:30:43Z", "aliases": [ "CVE-2025-30454" ], "details": "A path handling issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, tvOS 18.4, macOS Sequoia 15.4. A malicious app may be able to access private information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:26Z" diff --git a/advisories/unreviewed/2025/04/GHSA-x289-c764-465j/GHSA-x289-c764-465j.json b/advisories/unreviewed/2025/04/GHSA-x289-c764-465j/GHSA-x289-c764-465j.json new file mode 100644 index 00000000000..36a4130aa09 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x289-c764-465j/GHSA-x289-c764-465j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x289-c764-465j", + "modified": "2025-04-01T15:31:45Z", + "published": "2025-04-01T15:31:45Z", + "aliases": [ + "CVE-2025-31887" + ], + "details": "Missing Authorization vulnerability in zookatron MyBookProgress by Stormhill Media allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MyBookProgress by Stormhill Media: from n/a through 1.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31887" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mybookprogress/vulnerability/wordpress-mybookprogress-plugin-1-0-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x2cq-24wc-g3f9/GHSA-x2cq-24wc-g3f9.json b/advisories/unreviewed/2025/04/GHSA-x2cq-24wc-g3f9/GHSA-x2cq-24wc-g3f9.json new file mode 100644 index 00000000000..a6e9ab7aa67 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x2cq-24wc-g3f9/GHSA-x2cq-24wc-g3f9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2cq-24wc-g3f9", + "modified": "2025-04-01T15:31:42Z", + "published": "2025-04-01T15:31:42Z", + "aliases": [ + "CVE-2025-31828" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in alextselegidis Easy!Appointments allows Cross Site Request Forgery. This issue affects Easy!Appointments: from n/a through 1.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31828" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easyappointments/vulnerability/wordpress-easy-appointments-plugin-1-4-2-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x565-5fj6-vgvv/GHSA-x565-5fj6-vgvv.json b/advisories/unreviewed/2025/04/GHSA-x565-5fj6-vgvv/GHSA-x565-5fj6-vgvv.json new file mode 100644 index 00000000000..b25ed1a55fa --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x565-5fj6-vgvv/GHSA-x565-5fj6-vgvv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x565-5fj6-vgvv", + "modified": "2025-04-01T15:31:44Z", + "published": "2025-04-01T15:31:44Z", + "aliases": [ + "CVE-2025-31862" + ], + "details": "Missing Authorization vulnerability in PickPlugins Job Board Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Job Board Manager: from n/a through 2.1.60.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31862" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/job-board-manager/vulnerability/wordpress-job-board-manager-plugin-2-1-60-broken-access-control-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x84x-rvq8-4mx4/GHSA-x84x-rvq8-4mx4.json b/advisories/unreviewed/2025/04/GHSA-x84x-rvq8-4mx4/GHSA-x84x-rvq8-4mx4.json index e9d4d9eb7d5..5514e55e1de 100644 --- a/advisories/unreviewed/2025/04/GHSA-x84x-rvq8-4mx4/GHSA-x84x-rvq8-4mx4.json +++ b/advisories/unreviewed/2025/04/GHSA-x84x-rvq8-4mx4/GHSA-x84x-rvq8-4mx4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x84x-rvq8-4mx4", - "modified": "2025-04-01T00:30:37Z", + "modified": "2025-04-01T15:31:30Z", "published": "2025-04-01T00:30:37Z", "aliases": [ "CVE-2025-24212" ], "details": "This issue was addressed with improved checks. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to break out of its sandbox.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -45,7 +50,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:19Z" diff --git a/advisories/unreviewed/2025/04/GHSA-x9r2-q3j2-f6x6/GHSA-x9r2-q3j2-f6x6.json b/advisories/unreviewed/2025/04/GHSA-x9r2-q3j2-f6x6/GHSA-x9r2-q3j2-f6x6.json new file mode 100644 index 00000000000..873cd639a6d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x9r2-q3j2-f6x6/GHSA-x9r2-q3j2-f6x6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9r2-q3j2-f6x6", + "modified": "2025-04-01T15:31:43Z", + "published": "2025-04-01T15:31:43Z", + "aliases": [ + "CVE-2025-31846" + ], + "details": "Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Theater for WordPress: from n/a through 0.18.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31846" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/theatre/vulnerability/wordpress-theater-for-wordpress-plugin-0-18-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xjr3-qv95-pmw4/GHSA-xjr3-qv95-pmw4.json b/advisories/unreviewed/2025/04/GHSA-xjr3-qv95-pmw4/GHSA-xjr3-qv95-pmw4.json index 53f87300502..58161551b1a 100644 --- a/advisories/unreviewed/2025/04/GHSA-xjr3-qv95-pmw4/GHSA-xjr3-qv95-pmw4.json +++ b/advisories/unreviewed/2025/04/GHSA-xjr3-qv95-pmw4/GHSA-xjr3-qv95-pmw4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xjr3-qv95-pmw4", - "modified": "2025-04-01T00:30:40Z", + "modified": "2025-04-01T15:31:31Z", "published": "2025-04-01T00:30:40Z", "aliases": [ "CVE-2025-24273" ], "details": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause unexpected system termination or corrupt kernel memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:23Z" diff --git a/advisories/unreviewed/2025/04/GHSA-xmf4-8m9h-6vvh/GHSA-xmf4-8m9h-6vvh.json b/advisories/unreviewed/2025/04/GHSA-xmf4-8m9h-6vvh/GHSA-xmf4-8m9h-6vvh.json index 66219dd4c14..4939114177e 100644 --- a/advisories/unreviewed/2025/04/GHSA-xmf4-8m9h-6vvh/GHSA-xmf4-8m9h-6vvh.json +++ b/advisories/unreviewed/2025/04/GHSA-xmf4-8m9h-6vvh/GHSA-xmf4-8m9h-6vvh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xmf4-8m9h-6vvh", - "modified": "2025-04-01T00:30:44Z", + "modified": "2025-04-01T15:31:34Z", "published": "2025-04-01T00:30:44Z", "aliases": [ "CVE-2025-31194" ], "details": "An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A Shortcut may run with admin privileges without authentication.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:29Z" diff --git a/advisories/unreviewed/2025/04/GHSA-xqh5-95vp-q7f3/GHSA-xqh5-95vp-q7f3.json b/advisories/unreviewed/2025/04/GHSA-xqh5-95vp-q7f3/GHSA-xqh5-95vp-q7f3.json new file mode 100644 index 00000000000..3ce69eeaa8e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xqh5-95vp-q7f3/GHSA-xqh5-95vp-q7f3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqh5-95vp-q7f3", + "modified": "2025-04-01T15:31:42Z", + "published": "2025-04-01T15:31:42Z", + "aliases": [ + "CVE-2025-31833" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in themeglow JobBoard Job listing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobBoard Job listing: from n/a through 1.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31833" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/job-board-light/vulnerability/wordpress-jobboard-job-listing-plugin-plugin-1-2-7-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xwxj-5cm4-pc27/GHSA-xwxj-5cm4-pc27.json b/advisories/unreviewed/2025/04/GHSA-xwxj-5cm4-pc27/GHSA-xwxj-5cm4-pc27.json new file mode 100644 index 00000000000..a3704658dfb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xwxj-5cm4-pc27/GHSA-xwxj-5cm4-pc27.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwxj-5cm4-pc27", + "modified": "2025-04-01T15:31:37Z", + "published": "2025-04-01T15:31:37Z", + "aliases": [ + "CVE-2025-31741" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Filtr8 Easy Magazine allows DOM-Based XSS. This issue affects Easy Magazine: from n/a through 2.1.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31741" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/filtr8-magazine/vulnerability/wordpress-easy-magazine-plugin-2-1-13-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T15:16:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xxcr-5qmm-8wfp/GHSA-xxcr-5qmm-8wfp.json b/advisories/unreviewed/2025/04/GHSA-xxcr-5qmm-8wfp/GHSA-xxcr-5qmm-8wfp.json index dab631f9e67..32bb31350c3 100644 --- a/advisories/unreviewed/2025/04/GHSA-xxcr-5qmm-8wfp/GHSA-xxcr-5qmm-8wfp.json +++ b/advisories/unreviewed/2025/04/GHSA-xxcr-5qmm-8wfp/GHSA-xxcr-5qmm-8wfp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xxcr-5qmm-8wfp", - "modified": "2025-04-01T00:30:38Z", + "modified": "2025-04-01T15:31:30Z", "published": "2025-04-01T00:30:38Z", "aliases": [ "CVE-2025-24232" ], "details": "This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access arbitrary files.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:20Z"