From 81f2e9de059039012ee84b55e5f8aa5a4e5e060f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 31 Jan 2025 09:33:46 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-3gwv-4x73-6mhr.json | 36 +++++++++++++ .../GHSA-3v8f-5jj4-3qc5.json | 48 +++++++++++++++++ .../GHSA-3wcx-x5mh-phrw.json | 52 +++++++++++++++++++ .../GHSA-5vw3-ggxc-mhgp.json | 36 +++++++++++++ .../GHSA-6gjr-g247-wx36.json | 36 +++++++++++++ .../GHSA-6qcc-737v-m9qh.json | 36 +++++++++++++ .../GHSA-6rhg-vhrp-9m3v.json | 36 +++++++++++++ .../GHSA-6rrq-g2q3-65vf.json | 36 +++++++++++++ .../GHSA-6v52-q272-7v4c.json | 36 +++++++++++++ .../GHSA-7589-56rw-w69r.json | 36 +++++++++++++ .../GHSA-7v98-3wqp-vmf2.json | 36 +++++++++++++ .../GHSA-868q-37w2-4c3c.json | 36 +++++++++++++ .../GHSA-8h4m-j8cx-m745.json | 36 +++++++++++++ .../GHSA-8r53-pwcx-5g4r.json | 36 +++++++++++++ .../GHSA-8x4h-hw3h-4f96.json | 36 +++++++++++++ .../GHSA-8x8w-wppw-fv2m.json | 36 +++++++++++++ .../GHSA-9m45-3rc4-v6vf.json | 36 +++++++++++++ .../GHSA-c6f7-p55x-4c7m.json | 36 +++++++++++++ .../GHSA-fmxm-pfh7-h2hg.json | 36 +++++++++++++ .../GHSA-g24j-2hhc-r9j5.json | 36 +++++++++++++ .../GHSA-g4gf-c254-xc2x.json | 36 +++++++++++++ .../GHSA-g57p-76xm-cq36.json | 36 +++++++++++++ .../GHSA-gfhv-g3gh-4ghj.json | 36 +++++++++++++ .../GHSA-h8m7-2486-6973.json | 36 +++++++++++++ .../GHSA-hgmc-9jrx-7ph6.json | 36 +++++++++++++ .../GHSA-hgqf-4mmj-wchc.json | 36 +++++++++++++ .../GHSA-j5f7-j84g-95gx.json | 36 +++++++++++++ .../GHSA-p7wc-5x23-73f7.json | 36 +++++++++++++ .../GHSA-pg5x-hfc4-9689.json | 36 +++++++++++++ .../GHSA-pqj8-m475-cv44.json | 36 +++++++++++++ .../GHSA-q4fm-7j7j-cwcm.json | 36 +++++++++++++ .../GHSA-qhmx-28rr-pmwf.json | 36 +++++++++++++ .../GHSA-qwg6-xhp2-3c8q.json | 36 +++++++++++++ .../GHSA-rv26-4v2m-ch64.json | 36 +++++++++++++ .../GHSA-v6gq-6928-vx8w.json | 44 ++++++++++++++++ .../GHSA-vffm-x767-w2x7.json | 36 +++++++++++++ .../GHSA-vfm5-j9j6-rgv2.json | 36 +++++++++++++ .../GHSA-w87q-vx98-wx4h.json | 48 +++++++++++++++++ .../GHSA-wwwq-jmfm-4f5c.json | 40 ++++++++++++++ 39 files changed, 1456 insertions(+) create mode 100644 advisories/unreviewed/2025/01/GHSA-3gwv-4x73-6mhr/GHSA-3gwv-4x73-6mhr.json create mode 100644 advisories/unreviewed/2025/01/GHSA-3v8f-5jj4-3qc5/GHSA-3v8f-5jj4-3qc5.json create mode 100644 advisories/unreviewed/2025/01/GHSA-3wcx-x5mh-phrw/GHSA-3wcx-x5mh-phrw.json create mode 100644 advisories/unreviewed/2025/01/GHSA-5vw3-ggxc-mhgp/GHSA-5vw3-ggxc-mhgp.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6gjr-g247-wx36/GHSA-6gjr-g247-wx36.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6qcc-737v-m9qh/GHSA-6qcc-737v-m9qh.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6rhg-vhrp-9m3v/GHSA-6rhg-vhrp-9m3v.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6rrq-g2q3-65vf/GHSA-6rrq-g2q3-65vf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6v52-q272-7v4c/GHSA-6v52-q272-7v4c.json create mode 100644 advisories/unreviewed/2025/01/GHSA-7589-56rw-w69r/GHSA-7589-56rw-w69r.json create mode 100644 advisories/unreviewed/2025/01/GHSA-7v98-3wqp-vmf2/GHSA-7v98-3wqp-vmf2.json create mode 100644 advisories/unreviewed/2025/01/GHSA-868q-37w2-4c3c/GHSA-868q-37w2-4c3c.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8h4m-j8cx-m745/GHSA-8h4m-j8cx-m745.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8r53-pwcx-5g4r/GHSA-8r53-pwcx-5g4r.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8x4h-hw3h-4f96/GHSA-8x4h-hw3h-4f96.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8x8w-wppw-fv2m/GHSA-8x8w-wppw-fv2m.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9m45-3rc4-v6vf/GHSA-9m45-3rc4-v6vf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-c6f7-p55x-4c7m/GHSA-c6f7-p55x-4c7m.json create mode 100644 advisories/unreviewed/2025/01/GHSA-fmxm-pfh7-h2hg/GHSA-fmxm-pfh7-h2hg.json create mode 100644 advisories/unreviewed/2025/01/GHSA-g24j-2hhc-r9j5/GHSA-g24j-2hhc-r9j5.json create mode 100644 advisories/unreviewed/2025/01/GHSA-g4gf-c254-xc2x/GHSA-g4gf-c254-xc2x.json create mode 100644 advisories/unreviewed/2025/01/GHSA-g57p-76xm-cq36/GHSA-g57p-76xm-cq36.json create mode 100644 advisories/unreviewed/2025/01/GHSA-gfhv-g3gh-4ghj/GHSA-gfhv-g3gh-4ghj.json create mode 100644 advisories/unreviewed/2025/01/GHSA-h8m7-2486-6973/GHSA-h8m7-2486-6973.json create mode 100644 advisories/unreviewed/2025/01/GHSA-hgmc-9jrx-7ph6/GHSA-hgmc-9jrx-7ph6.json create mode 100644 advisories/unreviewed/2025/01/GHSA-hgqf-4mmj-wchc/GHSA-hgqf-4mmj-wchc.json create mode 100644 advisories/unreviewed/2025/01/GHSA-j5f7-j84g-95gx/GHSA-j5f7-j84g-95gx.json create mode 100644 advisories/unreviewed/2025/01/GHSA-p7wc-5x23-73f7/GHSA-p7wc-5x23-73f7.json create mode 100644 advisories/unreviewed/2025/01/GHSA-pg5x-hfc4-9689/GHSA-pg5x-hfc4-9689.json create mode 100644 advisories/unreviewed/2025/01/GHSA-pqj8-m475-cv44/GHSA-pqj8-m475-cv44.json create mode 100644 advisories/unreviewed/2025/01/GHSA-q4fm-7j7j-cwcm/GHSA-q4fm-7j7j-cwcm.json create mode 100644 advisories/unreviewed/2025/01/GHSA-qhmx-28rr-pmwf/GHSA-qhmx-28rr-pmwf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-qwg6-xhp2-3c8q/GHSA-qwg6-xhp2-3c8q.json create mode 100644 advisories/unreviewed/2025/01/GHSA-rv26-4v2m-ch64/GHSA-rv26-4v2m-ch64.json create mode 100644 advisories/unreviewed/2025/01/GHSA-v6gq-6928-vx8w/GHSA-v6gq-6928-vx8w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-vffm-x767-w2x7/GHSA-vffm-x767-w2x7.json create mode 100644 advisories/unreviewed/2025/01/GHSA-vfm5-j9j6-rgv2/GHSA-vfm5-j9j6-rgv2.json create mode 100644 advisories/unreviewed/2025/01/GHSA-w87q-vx98-wx4h/GHSA-w87q-vx98-wx4h.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wwwq-jmfm-4f5c/GHSA-wwwq-jmfm-4f5c.json diff --git a/advisories/unreviewed/2025/01/GHSA-3gwv-4x73-6mhr/GHSA-3gwv-4x73-6mhr.json b/advisories/unreviewed/2025/01/GHSA-3gwv-4x73-6mhr/GHSA-3gwv-4x73-6mhr.json new file mode 100644 index 00000000000..6bf7c9144c8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3gwv-4x73-6mhr/GHSA-3gwv-4x73-6mhr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gwv-4x73-6mhr", + "modified": "2025-01-31T09:31:52Z", + "published": "2025-01-31T09:31:52Z", + "aliases": [ + "CVE-2025-24632" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce allows Reflected XSS. This issue affects Advanced Dynamic Pricing for WooCommerce: from n/a through 4.9.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24632" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-dynamic-pricing-for-woocommerce/vulnerability/wordpress-advanced-dynamic-pricing-for-woocommerce-plugin-4-9-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3v8f-5jj4-3qc5/GHSA-3v8f-5jj4-3qc5.json b/advisories/unreviewed/2025/01/GHSA-3v8f-5jj4-3qc5/GHSA-3v8f-5jj4-3qc5.json new file mode 100644 index 00000000000..dd850fe7d8a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3v8f-5jj4-3qc5/GHSA-3v8f-5jj4-3qc5.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3v8f-5jj4-3qc5", + "modified": "2025-01-31T09:31:50Z", + "published": "2025-01-31T09:31:50Z", + "aliases": [ + "CVE-2024-13157" + ], + "details": "The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Podcast RSS Feed in all versions up to, and including, 5.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13157" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/mp3-music-player-by-sonaar/trunk/includes/class-sonaar-music-widget.php#L1733" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3231414" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/mp3-music-player-by-sonaar/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/547325ad-0b01-42d5-b47c-362044587395?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3wcx-x5mh-phrw/GHSA-3wcx-x5mh-phrw.json b/advisories/unreviewed/2025/01/GHSA-3wcx-x5mh-phrw/GHSA-3wcx-x5mh-phrw.json new file mode 100644 index 00000000000..ad191ef18dd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3wcx-x5mh-phrw/GHSA-3wcx-x5mh-phrw.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wcx-x5mh-phrw", + "modified": "2025-01-31T09:31:49Z", + "published": "2025-01-31T09:31:49Z", + "aliases": [ + "CVE-2024-13530" + ], + "details": "The Custom Login Page Styler – Limit Login Attempts – Restrict Content With Login – Redirect After Login – Change Login URL – Sign in , Sign out plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the lps_handle_delete_all_logs(), lps_handle_delete_login_log(), and lps_handle_end_session() functions in all versions up to, and including, 7.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete login logs and end user sessions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13530" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/login-page-styler/tags/7.1.2/loginPageStylerLogSettings.php#L111" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/login-page-styler/tags/7.1.2/loginPageStylerLogSettings.php#L122" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3232237%40login-page-styler&new=3232237%40login-page-styler&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/login-page-styler" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a143d611-9e22-49d1-9a9f-12f1c45685c4?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T08:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5vw3-ggxc-mhgp/GHSA-5vw3-ggxc-mhgp.json b/advisories/unreviewed/2025/01/GHSA-5vw3-ggxc-mhgp/GHSA-5vw3-ggxc-mhgp.json new file mode 100644 index 00000000000..ce0690b1a8a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5vw3-ggxc-mhgp/GHSA-5vw3-ggxc-mhgp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vw3-ggxc-mhgp", + "modified": "2025-01-31T09:31:52Z", + "published": "2025-01-31T09:31:52Z", + "aliases": [ + "CVE-2025-24686" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss User Registration Forms RegistrationMagic allows Reflected XSS. This issue affects RegistrationMagic: from n/a through 6.0.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24686" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/custom-registration-form-builder-with-submission-manager/vulnerability/wordpress-registrationmagic-plugin-6-0-3-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6gjr-g247-wx36/GHSA-6gjr-g247-wx36.json b/advisories/unreviewed/2025/01/GHSA-6gjr-g247-wx36/GHSA-6gjr-g247-wx36.json new file mode 100644 index 00000000000..1d64a0eb9f3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6gjr-g247-wx36/GHSA-6gjr-g247-wx36.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gjr-g247-wx36", + "modified": "2025-01-31T09:31:50Z", + "published": "2025-01-31T09:31:50Z", + "aliases": [ + "CVE-2024-44055" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in NotFound Oshine Modules. This issue affects Oshine Modules: from n/a through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44055" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/oshine-modules/vulnerability/wordpress-oshine-modules-plugin-3-3-6-unauthenticated-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6qcc-737v-m9qh/GHSA-6qcc-737v-m9qh.json b/advisories/unreviewed/2025/01/GHSA-6qcc-737v-m9qh/GHSA-6qcc-737v-m9qh.json new file mode 100644 index 00000000000..7ba7b16fd88 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6qcc-737v-m9qh/GHSA-6qcc-737v-m9qh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qcc-737v-m9qh", + "modified": "2025-01-31T09:31:51Z", + "published": "2025-01-31T09:31:51Z", + "aliases": [ + "CVE-2025-22757" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard CodeBard Help Desk allows Stored XSS. This issue affects CodeBard Help Desk: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22757" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/codebard-help-desk/vulnerability/wordpress-codebard-help-desk-plugin-1-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6rhg-vhrp-9m3v/GHSA-6rhg-vhrp-9m3v.json b/advisories/unreviewed/2025/01/GHSA-6rhg-vhrp-9m3v/GHSA-6rhg-vhrp-9m3v.json new file mode 100644 index 00000000000..26c1ee12459 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6rhg-vhrp-9m3v/GHSA-6rhg-vhrp-9m3v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rhg-vhrp-9m3v", + "modified": "2025-01-31T09:31:51Z", + "published": "2025-01-31T09:31:51Z", + "aliases": [ + "CVE-2025-23978" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ninos Ego FlashCounter allows Stored XSS. This issue affects FlashCounter: from n/a through 1.1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23978" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/flashcounter/vulnerability/wordpress-flashcounter-plugin-1-1-8-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6rrq-g2q3-65vf/GHSA-6rrq-g2q3-65vf.json b/advisories/unreviewed/2025/01/GHSA-6rrq-g2q3-65vf/GHSA-6rrq-g2q3-65vf.json new file mode 100644 index 00000000000..e812342c07e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6rrq-g2q3-65vf/GHSA-6rrq-g2q3-65vf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rrq-g2q3-65vf", + "modified": "2025-01-31T09:31:52Z", + "published": "2025-01-31T09:31:52Z", + "aliases": [ + "CVE-2025-23987" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodegearThemes Designer allows DOM-Based XSS. This issue affects Designer: from n/a through 1.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23987" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/designer/vulnerability/wordpress-designer-plugin-1-6-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6v52-q272-7v4c/GHSA-6v52-q272-7v4c.json b/advisories/unreviewed/2025/01/GHSA-6v52-q272-7v4c/GHSA-6v52-q272-7v4c.json new file mode 100644 index 00000000000..532a10bb6bc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6v52-q272-7v4c/GHSA-6v52-q272-7v4c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v52-q272-7v4c", + "modified": "2025-01-31T09:31:52Z", + "published": "2025-01-31T09:31:52Z", + "aliases": [ + "CVE-2025-24710" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcel Pol Gwolle Guestbook allows Reflected XSS. This issue affects Gwolle Guestbook: from n/a through 4.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24710" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gwolle-gb/vulnerability/wordpress-gwolle-guestbook-plugin-4-7-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7589-56rw-w69r/GHSA-7589-56rw-w69r.json b/advisories/unreviewed/2025/01/GHSA-7589-56rw-w69r/GHSA-7589-56rw-w69r.json new file mode 100644 index 00000000000..3015061afef --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7589-56rw-w69r/GHSA-7589-56rw-w69r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7589-56rw-w69r", + "modified": "2025-01-31T09:31:52Z", + "published": "2025-01-31T09:31:52Z", + "aliases": [ + "CVE-2025-24749" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Overt Software Solutions LTD EZPZ SAML SP Single Sign On (SSO) allows Cross Site Request Forgery. This issue affects EZPZ SAML SP Single Sign On (SSO): from n/a through 1.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24749" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ezpz-sp/vulnerability/wordpress-ezpz-saml-sp-single-sign-on-sso-plugin-1-2-5-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7v98-3wqp-vmf2/GHSA-7v98-3wqp-vmf2.json b/advisories/unreviewed/2025/01/GHSA-7v98-3wqp-vmf2/GHSA-7v98-3wqp-vmf2.json new file mode 100644 index 00000000000..648ec830397 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7v98-3wqp-vmf2/GHSA-7v98-3wqp-vmf2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v98-3wqp-vmf2", + "modified": "2025-01-31T09:31:51Z", + "published": "2025-01-31T09:31:51Z", + "aliases": [ + "CVE-2025-22564" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Faaiq Pretty Url allows Reflected XSS. This issue affects Pretty Url: from n/a through 1.5.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22564" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pretty-url/vulnerability/wordpress-pretty-url-plugin-1-5-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-868q-37w2-4c3c/GHSA-868q-37w2-4c3c.json b/advisories/unreviewed/2025/01/GHSA-868q-37w2-4c3c/GHSA-868q-37w2-4c3c.json new file mode 100644 index 00000000000..8d86c3bd0cf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-868q-37w2-4c3c/GHSA-868q-37w2-4c3c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-868q-37w2-4c3c", + "modified": "2025-01-31T09:31:52Z", + "published": "2025-01-31T09:31:52Z", + "aliases": [ + "CVE-2025-24549" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Mahbubur Rahman Post Meta allows Reflected XSS. This issue affects Post Meta: from n/a through 1.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24549" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/post-meta/vulnerability/wordpress-post-meta-plugin-1-0-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8h4m-j8cx-m745/GHSA-8h4m-j8cx-m745.json b/advisories/unreviewed/2025/01/GHSA-8h4m-j8cx-m745/GHSA-8h4m-j8cx-m745.json new file mode 100644 index 00000000000..e64776d6239 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8h4m-j8cx-m745/GHSA-8h4m-j8cx-m745.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h4m-j8cx-m745", + "modified": "2025-01-31T09:31:51Z", + "published": "2025-01-31T09:31:51Z", + "aliases": [ + "CVE-2025-23759" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leduchuy89vn Affiliate Tools Việt Nam allows Reflected XSS. This issue affects Affiliate Tools Việt Nam: from n/a through 0.3.17.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23759" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/affiliate-tools-viet-nam/vulnerability/wordpress-affiliate-tools-viet-nam-plugin-0-3-17-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8r53-pwcx-5g4r/GHSA-8r53-pwcx-5g4r.json b/advisories/unreviewed/2025/01/GHSA-8r53-pwcx-5g4r/GHSA-8r53-pwcx-5g4r.json new file mode 100644 index 00000000000..c14fb4519fa --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8r53-pwcx-5g4r/GHSA-8r53-pwcx-5g4r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r53-pwcx-5g4r", + "modified": "2025-01-31T09:31:50Z", + "published": "2025-01-31T09:31:50Z", + "aliases": [ + "CVE-2025-22332" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bryan Shanaver @ fiftyandfifty.org CloudFlare(R) Cache Purge allows Reflected XSS. This issue affects CloudFlare(R) Cache Purge: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22332" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cloudflare-cache-purge/vulnerability/wordpress-cloudflare-r-cache-purge-plugin-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8x4h-hw3h-4f96/GHSA-8x4h-hw3h-4f96.json b/advisories/unreviewed/2025/01/GHSA-8x4h-hw3h-4f96/GHSA-8x4h-hw3h-4f96.json new file mode 100644 index 00000000000..4b8e3344114 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8x4h-hw3h-4f96/GHSA-8x4h-hw3h-4f96.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x4h-hw3h-4f96", + "modified": "2025-01-31T09:31:52Z", + "published": "2025-01-31T09:31:52Z", + "aliases": [ + "CVE-2025-24563" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGlow Cleanup – Directory Listing & Classifieds WordPress Plugin allows Reflected XSS. This issue affects Cleanup – Directory Listing & Classifieds WordPress Plugin: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24563" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cleanup-light/vulnerability/wordpress-cleanup-directory-listing-classifieds-plugin-1-0-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8x8w-wppw-fv2m/GHSA-8x8w-wppw-fv2m.json b/advisories/unreviewed/2025/01/GHSA-8x8w-wppw-fv2m/GHSA-8x8w-wppw-fv2m.json new file mode 100644 index 00000000000..385a96d99ed --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8x8w-wppw-fv2m/GHSA-8x8w-wppw-fv2m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x8w-wppw-fv2m", + "modified": "2025-01-31T09:31:52Z", + "published": "2025-01-31T09:31:52Z", + "aliases": [ + "CVE-2025-24535" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SKT Themes SKT Donation allows Reflected XSS. This issue affects SKT Donation: from n/a through 1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24535" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/skt-donation/vulnerability/wordpress-skt-donation-plugin-1-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9m45-3rc4-v6vf/GHSA-9m45-3rc4-v6vf.json b/advisories/unreviewed/2025/01/GHSA-9m45-3rc4-v6vf/GHSA-9m45-3rc4-v6vf.json new file mode 100644 index 00000000000..0eeeece4f22 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9m45-3rc4-v6vf/GHSA-9m45-3rc4-v6vf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m45-3rc4-v6vf", + "modified": "2025-01-31T09:31:52Z", + "published": "2025-01-31T09:31:52Z", + "aliases": [ + "CVE-2025-24560" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Awesome TOGI Awesome Event Booking allows Reflected XSS. This issue affects Awesome Event Booking: from n/a through 2.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24560" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/awesome-event-booking/vulnerability/wordpress-awesome-event-booking-plugin-2-7-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c6f7-p55x-4c7m/GHSA-c6f7-p55x-4c7m.json b/advisories/unreviewed/2025/01/GHSA-c6f7-p55x-4c7m/GHSA-c6f7-p55x-4c7m.json new file mode 100644 index 00000000000..961009d0f0f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c6f7-p55x-4c7m/GHSA-c6f7-p55x-4c7m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6f7-p55x-4c7m", + "modified": "2025-01-31T09:31:52Z", + "published": "2025-01-31T09:31:52Z", + "aliases": [ + "CVE-2025-23989" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi - SabLab Internal Link Builder allows Cross Site Request Forgery. This issue affects Internal Link Builder: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23989" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/internal-link-builder/vulnerability/wordpress-internal-link-builder-plugin-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fmxm-pfh7-h2hg/GHSA-fmxm-pfh7-h2hg.json b/advisories/unreviewed/2025/01/GHSA-fmxm-pfh7-h2hg/GHSA-fmxm-pfh7-h2hg.json new file mode 100644 index 00000000000..ca7613c01c5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fmxm-pfh7-h2hg/GHSA-fmxm-pfh7-h2hg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmxm-pfh7-h2hg", + "modified": "2025-01-31T09:31:52Z", + "published": "2025-01-31T09:31:52Z", + "aliases": [ + "CVE-2025-24718" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SWIT WP Sessions Time Monitoring Full Automatic allows Reflected XSS. This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24718" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/activitytime/vulnerability/wordpress-wp-sessions-time-monitoring-full-automatic-plugin-1-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g24j-2hhc-r9j5/GHSA-g24j-2hhc-r9j5.json b/advisories/unreviewed/2025/01/GHSA-g24j-2hhc-r9j5/GHSA-g24j-2hhc-r9j5.json new file mode 100644 index 00000000000..08dd95573ac --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g24j-2hhc-r9j5/GHSA-g24j-2hhc-r9j5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g24j-2hhc-r9j5", + "modified": "2025-01-31T09:31:52Z", + "published": "2025-01-31T09:31:52Z", + "aliases": [ + "CVE-2025-24551" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OneTeamSoftware Radio Buttons and Swatches for WooCommerce allows Reflected XSS. This issue affects Radio Buttons and Swatches for WooCommerce: from n/a through 1.1.20.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24551" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/variations-radio-buttons-for-woocommerce/vulnerability/wordpress-radio-buttons-and-swatches-for-woocommerce-plugin-1-1-20-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g4gf-c254-xc2x/GHSA-g4gf-c254-xc2x.json b/advisories/unreviewed/2025/01/GHSA-g4gf-c254-xc2x/GHSA-g4gf-c254-xc2x.json new file mode 100644 index 00000000000..f5360a370c7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g4gf-c254-xc2x/GHSA-g4gf-c254-xc2x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4gf-c254-xc2x", + "modified": "2025-01-31T09:31:51Z", + "published": "2025-01-31T09:31:51Z", + "aliases": [ + "CVE-2025-23977" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Bhaskar Dhote Post Carousel Slider allows Stored XSS. This issue affects Post Carousel Slider: from n/a through 2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23977" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/post-carousel-slider/vulnerability/wordpress-post-carousel-slider-plugin-2-0-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g57p-76xm-cq36/GHSA-g57p-76xm-cq36.json b/advisories/unreviewed/2025/01/GHSA-g57p-76xm-cq36/GHSA-g57p-76xm-cq36.json new file mode 100644 index 00000000000..a2141b1e2d3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g57p-76xm-cq36/GHSA-g57p-76xm-cq36.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g57p-76xm-cq36", + "modified": "2025-01-31T09:31:51Z", + "published": "2025-01-31T09:31:51Z", + "aliases": [ + "CVE-2025-23976" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Pedro Marcelo Issuu Panel allows Stored XSS. This issue affects Issuu Panel: from n/a through 2.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23976" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/issuu-panel/vulnerability/wordpress-issuu-panel-plugin-2-1-1-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gfhv-g3gh-4ghj/GHSA-gfhv-g3gh-4ghj.json b/advisories/unreviewed/2025/01/GHSA-gfhv-g3gh-4ghj/GHSA-gfhv-g3gh-4ghj.json new file mode 100644 index 00000000000..af65ec561f7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gfhv-g3gh-4ghj/GHSA-gfhv-g3gh-4ghj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfhv-g3gh-4ghj", + "modified": "2025-01-31T09:31:51Z", + "published": "2025-01-31T09:31:51Z", + "aliases": [ + "CVE-2025-23985" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Brainvireinfo Dynamic URL SEO allows Cross Site Request Forgery. This issue affects Dynamic URL SEO: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23985" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dynamic-url-seo/vulnerability/wordpress-dynamic-url-seo-plugin-1-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h8m7-2486-6973/GHSA-h8m7-2486-6973.json b/advisories/unreviewed/2025/01/GHSA-h8m7-2486-6973/GHSA-h8m7-2486-6973.json new file mode 100644 index 00000000000..6f75857e0af --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h8m7-2486-6973/GHSA-h8m7-2486-6973.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8m7-2486-6973", + "modified": "2025-01-31T09:31:52Z", + "published": "2025-01-31T09:31:52Z", + "aliases": [ + "CVE-2025-24608" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD Mail Queue allows Reflected XSS. This issue affects GD Mail Queue: from n/a through 4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24608" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gd-mail-queue/vulnerability/wordpress-gd-mail-queue-plugin-4-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hgmc-9jrx-7ph6/GHSA-hgmc-9jrx-7ph6.json b/advisories/unreviewed/2025/01/GHSA-hgmc-9jrx-7ph6/GHSA-hgmc-9jrx-7ph6.json new file mode 100644 index 00000000000..5f50857766e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hgmc-9jrx-7ph6/GHSA-hgmc-9jrx-7ph6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgmc-9jrx-7ph6", + "modified": "2025-01-31T09:31:51Z", + "published": "2025-01-31T09:31:50Z", + "aliases": [ + "CVE-2025-22341" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mohammad Hossein Aghanabi Hide Login+ allows Reflected XSS. This issue affects Hide Login+: from n/a through 3.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22341" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hide-login/vulnerability/wordpress-hide-login-plugin-3-5-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hgqf-4mmj-wchc/GHSA-hgqf-4mmj-wchc.json b/advisories/unreviewed/2025/01/GHSA-hgqf-4mmj-wchc/GHSA-hgqf-4mmj-wchc.json new file mode 100644 index 00000000000..153104d6330 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hgqf-4mmj-wchc/GHSA-hgqf-4mmj-wchc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgqf-4mmj-wchc", + "modified": "2025-01-31T09:31:51Z", + "published": "2025-01-31T09:31:51Z", + "aliases": [ + "CVE-2025-22720" + ], + "details": "Missing Authorization vulnerability in MagePeople Team Booking and Rental Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Booking and Rental Manager: from n/a through 2.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22720" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/booking-and-rental-manager-for-woocommerce/vulnerability/wordpress-wprently-wordpress-plugin-plugin-2-2-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j5f7-j84g-95gx/GHSA-j5f7-j84g-95gx.json b/advisories/unreviewed/2025/01/GHSA-j5f7-j84g-95gx/GHSA-j5f7-j84g-95gx.json new file mode 100644 index 00000000000..e3fbc4060ca --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j5f7-j84g-95gx/GHSA-j5f7-j84g-95gx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5f7-j84g-95gx", + "modified": "2025-01-31T09:31:52Z", + "published": "2025-01-31T09:31:52Z", + "aliases": [ + "CVE-2025-24534" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emili Castells DPortfolio allows Reflected XSS. This issue affects DPortfolio: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24534" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dportfolio/vulnerability/wordpress-dportfolio-plugin-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p7wc-5x23-73f7/GHSA-p7wc-5x23-73f7.json b/advisories/unreviewed/2025/01/GHSA-p7wc-5x23-73f7/GHSA-p7wc-5x23-73f7.json new file mode 100644 index 00000000000..1b9ceb4a1e1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p7wc-5x23-73f7/GHSA-p7wc-5x23-73f7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7wc-5x23-73f7", + "modified": "2025-01-31T09:31:52Z", + "published": "2025-01-31T09:31:52Z", + "aliases": [ + "CVE-2025-24609" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PortOne PORTONE 우커머스 결제 allows Reflected XSS. This issue affects PORTONE 우커머스 결제: from n/a through 3.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24609" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/iamport-for-woocommerce/vulnerability/wordpress-portone-plugin-3-2-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pg5x-hfc4-9689/GHSA-pg5x-hfc4-9689.json b/advisories/unreviewed/2025/01/GHSA-pg5x-hfc4-9689/GHSA-pg5x-hfc4-9689.json new file mode 100644 index 00000000000..957b9aa1e35 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pg5x-hfc4-9689/GHSA-pg5x-hfc4-9689.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg5x-hfc4-9689", + "modified": "2025-01-31T09:31:52Z", + "published": "2025-01-31T09:31:52Z", + "aliases": [ + "CVE-2025-24597" + ], + "details": "Insertion of Sensitive Information Into Sent Data vulnerability in UkrSolution Barcode Generator for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects Barcode Generator for WooCommerce: from n/a through 2.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24597" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/embedding-barcodes-into-product-pages-and-orders/vulnerability/wordpress-barcode-generator-for-woocommerce-plugin-2-0-2-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pqj8-m475-cv44/GHSA-pqj8-m475-cv44.json b/advisories/unreviewed/2025/01/GHSA-pqj8-m475-cv44/GHSA-pqj8-m475-cv44.json new file mode 100644 index 00000000000..67bbca9ab8a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pqj8-m475-cv44/GHSA-pqj8-m475-cv44.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqj8-m475-cv44", + "modified": "2025-01-31T09:31:51Z", + "published": "2025-01-31T09:31:51Z", + "aliases": [ + "CVE-2025-23671" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fabio Savina WP OpenSearch allows Stored XSS. This issue affects WP OpenSearch: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23671" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-opensearch/vulnerability/wordpress-wp-opensearch-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q4fm-7j7j-cwcm/GHSA-q4fm-7j7j-cwcm.json b/advisories/unreviewed/2025/01/GHSA-q4fm-7j7j-cwcm/GHSA-q4fm-7j7j-cwcm.json new file mode 100644 index 00000000000..e6fa0e12318 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q4fm-7j7j-cwcm/GHSA-q4fm-7j7j-cwcm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4fm-7j7j-cwcm", + "modified": "2025-01-31T09:31:52Z", + "published": "2025-01-31T09:31:52Z", + "aliases": [ + "CVE-2025-23990" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in jablonczay Scroll Styler. This issue affects Scroll Styler: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23990" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/scroll-styler/vulnerability/wordpress-scroll-styler-plugin-1-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qhmx-28rr-pmwf/GHSA-qhmx-28rr-pmwf.json b/advisories/unreviewed/2025/01/GHSA-qhmx-28rr-pmwf/GHSA-qhmx-28rr-pmwf.json new file mode 100644 index 00000000000..38030b12006 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qhmx-28rr-pmwf/GHSA-qhmx-28rr-pmwf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhmx-28rr-pmwf", + "modified": "2025-01-31T09:31:52Z", + "published": "2025-01-31T09:31:52Z", + "aliases": [ + "CVE-2025-24635" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paytm Paytm Payment Donation allows Reflected XSS. This issue affects Paytm Payment Donation: from n/a through 2.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24635" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/paytm-donation/vulnerability/wordpress-paytm-donation-plugin-plugin-2-3-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qwg6-xhp2-3c8q/GHSA-qwg6-xhp2-3c8q.json b/advisories/unreviewed/2025/01/GHSA-qwg6-xhp2-3c8q/GHSA-qwg6-xhp2-3c8q.json new file mode 100644 index 00000000000..31c733d3535 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qwg6-xhp2-3c8q/GHSA-qwg6-xhp2-3c8q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwg6-xhp2-3c8q", + "modified": "2025-01-31T09:31:50Z", + "published": "2025-01-31T09:31:50Z", + "aliases": [ + "CVE-2025-22265" + ], + "details": "Missing Authorization vulnerability in mgplugin EMI Calculator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EMI Calculator: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22265" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/emi-calculator/vulnerability/wordpress-emi-calculator-plugin-1-1-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rv26-4v2m-ch64/GHSA-rv26-4v2m-ch64.json b/advisories/unreviewed/2025/01/GHSA-rv26-4v2m-ch64/GHSA-rv26-4v2m-ch64.json new file mode 100644 index 00000000000..e6fef97c79a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rv26-4v2m-ch64/GHSA-rv26-4v2m-ch64.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv26-4v2m-ch64", + "modified": "2025-01-31T09:31:49Z", + "published": "2025-01-31T09:31:49Z", + "aliases": [ + "CVE-2024-53007" + ], + "details": "Bentley Systems ProjectWise Integration Server before 10.00.03.288 allows unintended SQL query execution by an authenticated user via an API call.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53007" + }, + { + "type": "WEB", + "url": "https://www.bentley.com/advisories/be-2024-0002" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-648" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T08:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v6gq-6928-vx8w/GHSA-v6gq-6928-vx8w.json b/advisories/unreviewed/2025/01/GHSA-v6gq-6928-vx8w/GHSA-v6gq-6928-vx8w.json new file mode 100644 index 00000000000..4c62740737c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v6gq-6928-vx8w/GHSA-v6gq-6928-vx8w.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6gq-6928-vx8w", + "modified": "2025-01-31T09:31:49Z", + "published": "2025-01-31T09:31:49Z", + "aliases": [ + "CVE-2024-13623" + ], + "details": "The Order Export for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.24 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory which can contain exported order information. The plugin is only vulnerable when 'Order data storage' is set to 'WordPress posts storage (legacy)', and cannot be exploited when the default option of 'High-performance order storage' is enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13623" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/order-export-and-more-for-woocommerce/trunk/inc/JEMEXP_Order.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3230283" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/18d6dffd-8df3-4611-ad94-6d806aa7328a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vffm-x767-w2x7/GHSA-vffm-x767-w2x7.json b/advisories/unreviewed/2025/01/GHSA-vffm-x767-w2x7/GHSA-vffm-x767-w2x7.json new file mode 100644 index 00000000000..21de2fb7503 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vffm-x767-w2x7/GHSA-vffm-x767-w2x7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vffm-x767-w2x7", + "modified": "2025-01-31T09:31:51Z", + "published": "2025-01-31T09:31:51Z", + "aliases": [ + "CVE-2025-23980" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in James Andrews Full Circle allows Stored XSS. This issue affects Full Circle: from n/a through 0.5.7.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23980" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/full-circle/vulnerability/wordpress-full-circle-plugin-0-5-7-8-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vfm5-j9j6-rgv2/GHSA-vfm5-j9j6-rgv2.json b/advisories/unreviewed/2025/01/GHSA-vfm5-j9j6-rgv2/GHSA-vfm5-j9j6-rgv2.json new file mode 100644 index 00000000000..e966f05b27a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vfm5-j9j6-rgv2/GHSA-vfm5-j9j6-rgv2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfm5-j9j6-rgv2", + "modified": "2025-01-31T09:31:51Z", + "published": "2025-01-31T09:31:51Z", + "aliases": [ + "CVE-2025-23596" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Notifikacie.sk Notifikácie.sk allows Reflected XSS. This issue affects Notifikácie.sk: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23596" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/notifikacie-sk/vulnerability/wordpress-notifikacie-sk-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w87q-vx98-wx4h/GHSA-w87q-vx98-wx4h.json b/advisories/unreviewed/2025/01/GHSA-w87q-vx98-wx4h/GHSA-w87q-vx98-wx4h.json new file mode 100644 index 00000000000..b5626f6a1e7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w87q-vx98-wx4h/GHSA-w87q-vx98-wx4h.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w87q-vx98-wx4h", + "modified": "2025-01-31T09:31:50Z", + "published": "2025-01-31T09:31:50Z", + "aliases": [ + "CVE-2024-13566" + ], + "details": "The WP DataTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 0.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13566" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-datatable/trunk/shortcode.php#L42" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3231842" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wp-datatable/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9ad96faa-cbc2-46c3-a8e6-afa6744ada86?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T09:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wwwq-jmfm-4f5c/GHSA-wwwq-jmfm-4f5c.json b/advisories/unreviewed/2025/01/GHSA-wwwq-jmfm-4f5c/GHSA-wwwq-jmfm-4f5c.json new file mode 100644 index 00000000000..ef3c83a14fa --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wwwq-jmfm-4f5c/GHSA-wwwq-jmfm-4f5c.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwwq-jmfm-4f5c", + "modified": "2025-01-31T09:31:49Z", + "published": "2025-01-31T09:31:49Z", + "aliases": [ + "CVE-2024-52875" + ], + "details": "An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertException.cs and /nonauth/guestConfirm.cs and /nonauth/expiration.cs pages is not properly sanitized before being used to generate a Location HTTP header in a 302 HTTP response. This can be exploited to perform Open Redirect or HTTP Response Splitting attacks, which in turn lead to Reflected Cross-Site Scripting (XSS). Remote command execution can be achieved by leveraging the upgrade feature in the admin interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52875" + }, + { + "type": "WEB", + "url": "https://karmainsecurity.com/hacking-kerio-control-via-cve-2024-52875" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Dec/15" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-113" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-31T08:15:07Z" + } +} \ No newline at end of file