From 9f00223e30cd27e86a7624ee90a9d54a894204d4 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 29 Apr 2024 06:32:03 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2h9f-ppj9-gcvv.json | 38 ++++++++++++ .../GHSA-349c-6q2h-wwhm.json | 38 ++++++++++++ .../GHSA-3qfm-m53j-9vq3.json | 62 +++++++++++++++++++ .../GHSA-4jwm-p35r-q67q.json | 35 +++++++++++ .../GHSA-4vm2-7x6p-rxmc.json | 43 +++++++++++++ .../GHSA-4x2c-gqrf-gvf9.json | 38 ++++++++++++ .../GHSA-7855-3hjg-5779.json | 35 +++++++++++ .../GHSA-7f66-fgh3-955x.json | 38 ++++++++++++ .../GHSA-894f-rh68-m2vm.json | 38 ++++++++++++ .../GHSA-8g9x-vm55-m3mq.json | 38 ++++++++++++ .../GHSA-c3cg-v373-7p8j.json | 43 +++++++++++++ .../GHSA-g7qj-fx7v-pm5j.json | 38 ++++++++++++ .../GHSA-g89g-74wr-qhg3.json | 38 ++++++++++++ .../GHSA-g99q-g998-c275.json | 38 ++++++++++++ .../GHSA-gwq4-xh4c-9x95.json | 38 ++++++++++++ .../GHSA-h47p-p2xw-fphp.json | 38 ++++++++++++ .../GHSA-hh44-mx2m-2w3w.json | 38 ++++++++++++ .../GHSA-jc65-rh6v-pv5p.json | 38 ++++++++++++ .../GHSA-m4rg-wp77-xw59.json | 38 ++++++++++++ .../GHSA-mw23-jwm4-23g8.json | 38 ++++++++++++ .../GHSA-phc8-j9rw-cv2q.json | 38 ++++++++++++ .../GHSA-q2pw-g7vq-q2cm.json | 38 ++++++++++++ .../GHSA-q3rr-7hjc-7c55.json | 38 ++++++++++++ .../GHSA-q59j-4j35-wm99.json | 38 ++++++++++++ .../GHSA-q8qm-w223-fx6w.json | 38 ++++++++++++ .../GHSA-rqw7-3533-cfwv.json | 38 ++++++++++++ .../GHSA-rr4m-8whr-q39q.json | 31 ++++++++++ .../GHSA-rrx7-mfpg-89v6.json | 38 ++++++++++++ .../GHSA-v43w-m78j-vr5m.json | 38 ++++++++++++ .../GHSA-v8mx-hp8h-89vc.json | 43 +++++++++++++ .../GHSA-vvjc-x5q2-8qr6.json | 38 ++++++++++++ .../GHSA-wgx8-xhfh-5ph4.json | 38 ++++++++++++ .../GHSA-xmpc-wq83-gmwh.json | 38 ++++++++++++ 33 files changed, 1280 insertions(+) create mode 100644 advisories/unreviewed/2024/04/GHSA-2h9f-ppj9-gcvv/GHSA-2h9f-ppj9-gcvv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-349c-6q2h-wwhm/GHSA-349c-6q2h-wwhm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3qfm-m53j-9vq3/GHSA-3qfm-m53j-9vq3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4jwm-p35r-q67q/GHSA-4jwm-p35r-q67q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4vm2-7x6p-rxmc/GHSA-4vm2-7x6p-rxmc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-4x2c-gqrf-gvf9/GHSA-4x2c-gqrf-gvf9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7855-3hjg-5779/GHSA-7855-3hjg-5779.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7f66-fgh3-955x/GHSA-7f66-fgh3-955x.json create mode 100644 advisories/unreviewed/2024/04/GHSA-894f-rh68-m2vm/GHSA-894f-rh68-m2vm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-8g9x-vm55-m3mq/GHSA-8g9x-vm55-m3mq.json create mode 100644 advisories/unreviewed/2024/04/GHSA-c3cg-v373-7p8j/GHSA-c3cg-v373-7p8j.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g7qj-fx7v-pm5j/GHSA-g7qj-fx7v-pm5j.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g89g-74wr-qhg3/GHSA-g89g-74wr-qhg3.json create mode 100644 advisories/unreviewed/2024/04/GHSA-g99q-g998-c275/GHSA-g99q-g998-c275.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gwq4-xh4c-9x95/GHSA-gwq4-xh4c-9x95.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h47p-p2xw-fphp/GHSA-h47p-p2xw-fphp.json create mode 100644 advisories/unreviewed/2024/04/GHSA-hh44-mx2m-2w3w/GHSA-hh44-mx2m-2w3w.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jc65-rh6v-pv5p/GHSA-jc65-rh6v-pv5p.json create mode 100644 advisories/unreviewed/2024/04/GHSA-m4rg-wp77-xw59/GHSA-m4rg-wp77-xw59.json create mode 100644 advisories/unreviewed/2024/04/GHSA-mw23-jwm4-23g8/GHSA-mw23-jwm4-23g8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-phc8-j9rw-cv2q/GHSA-phc8-j9rw-cv2q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-q2pw-g7vq-q2cm/GHSA-q2pw-g7vq-q2cm.json create mode 100644 advisories/unreviewed/2024/04/GHSA-q3rr-7hjc-7c55/GHSA-q3rr-7hjc-7c55.json create mode 100644 advisories/unreviewed/2024/04/GHSA-q59j-4j35-wm99/GHSA-q59j-4j35-wm99.json create mode 100644 advisories/unreviewed/2024/04/GHSA-q8qm-w223-fx6w/GHSA-q8qm-w223-fx6w.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rqw7-3533-cfwv/GHSA-rqw7-3533-cfwv.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rr4m-8whr-q39q/GHSA-rr4m-8whr-q39q.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rrx7-mfpg-89v6/GHSA-rrx7-mfpg-89v6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v43w-m78j-vr5m/GHSA-v43w-m78j-vr5m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-v8mx-hp8h-89vc/GHSA-v8mx-hp8h-89vc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vvjc-x5q2-8qr6/GHSA-vvjc-x5q2-8qr6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wgx8-xhfh-5ph4/GHSA-wgx8-xhfh-5ph4.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xmpc-wq83-gmwh/GHSA-xmpc-wq83-gmwh.json diff --git a/advisories/unreviewed/2024/04/GHSA-2h9f-ppj9-gcvv/GHSA-2h9f-ppj9-gcvv.json b/advisories/unreviewed/2024/04/GHSA-2h9f-ppj9-gcvv/GHSA-2h9f-ppj9-gcvv.json new file mode 100644 index 00000000000..61702c270c5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2h9f-ppj9-gcvv/GHSA-2h9f-ppj9-gcvv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2h9f-ppj9-gcvv", + "modified": "2024-04-29T06:30:43Z", + "published": "2024-04-29T06:30:43Z", + "aliases": [ + "CVE-2024-33630" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor allows Stored XSS.This issue affects Piotnet Addons For Elementor: from n/a through 2.4.26.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33630" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/piotnet-addons-for-elementor/wordpress-piotnet-addons-for-elementor-plugin-2-4-26-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-349c-6q2h-wwhm/GHSA-349c-6q2h-wwhm.json b/advisories/unreviewed/2024/04/GHSA-349c-6q2h-wwhm/GHSA-349c-6q2h-wwhm.json new file mode 100644 index 00000000000..3eba931f837 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-349c-6q2h-wwhm/GHSA-349c-6q2h-wwhm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-349c-6q2h-wwhm", + "modified": "2024-04-29T06:30:42Z", + "published": "2024-04-29T06:30:42Z", + "aliases": [ + "CVE-2024-33551" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core allows SQL Injection.This issue affects XStore Core: from n/a through 5.3.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33551" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/et-core-plugin/wordpress-xstore-core-plugin-5-3-5-unauthenticated-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3qfm-m53j-9vq3/GHSA-3qfm-m53j-9vq3.json b/advisories/unreviewed/2024/04/GHSA-3qfm-m53j-9vq3/GHSA-3qfm-m53j-9vq3.json new file mode 100644 index 00000000000..c0674a934a4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3qfm-m53j-9vq3/GHSA-3qfm-m53j-9vq3.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qfm-m53j-9vq3", + "modified": "2024-04-29T06:30:43Z", + "published": "2024-04-29T06:30:43Z", + "aliases": [ + "CVE-2024-33686" + ], + "details": "Missing Authorization vulnerability in Extend Themes Pathway, Extend Themes Hugo WP, Extend Themes Althea WP, Extend Themes Elevate WP, Extend Themes Brite, Extend Themes Colibri WP, Extend Themes Vertice.This issue affects Pathway: from n/a through 1.0.15; Hugo WP: from n/a through 1.0.8; Althea WP: from n/a through 1.0.13; Elevate WP: from n/a through 1.0.15; Brite: from n/a through 1.0.11; Colibri WP: from n/a through 1.0.94; Vertice: from n/a through 1.0.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33686" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/althea-wp/wordpress-althea-wp-theme-1-0-13-broken-access-control-vulnerability" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/brite/wordpress-brite-theme-1-0-11-broken-access-control-vulnerability" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/colibri-wp/wordpress-colibri-wp-theme-1-0-94-broken-access-control-vulnerability" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/elevate-wp/wordpress-elevate-wp-theme-1-0-15-broken-access-control-vulnerability" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/hugo-wp/wordpress-hugo-wp-theme-1-0-8-broken-access-control-vulnerability" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pathway/wordpress-pathway-theme-1-0-15-cross-site-request-forgery-csrf-vulnerability" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/vertice/wordpress-vertice-theme-1-0-7-broken-access-control-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4jwm-p35r-q67q/GHSA-4jwm-p35r-q67q.json b/advisories/unreviewed/2024/04/GHSA-4jwm-p35r-q67q/GHSA-4jwm-p35r-q67q.json new file mode 100644 index 00000000000..735caaef331 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4jwm-p35r-q67q/GHSA-4jwm-p35r-q67q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jwm-p35r-q67q", + "modified": "2024-04-29T06:30:42Z", + "published": "2024-04-29T06:30:42Z", + "aliases": [ + "CVE-2024-1905" + ], + "details": "The Smart Forms WordPress plugin before 2.6.96 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1905" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/b9a448d2-4bc2-4933-8743-58c8768a619f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4vm2-7x6p-rxmc/GHSA-4vm2-7x6p-rxmc.json b/advisories/unreviewed/2024/04/GHSA-4vm2-7x6p-rxmc/GHSA-4vm2-7x6p-rxmc.json new file mode 100644 index 00000000000..cc88c2e1924 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4vm2-7x6p-rxmc/GHSA-4vm2-7x6p-rxmc.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vm2-7x6p-rxmc", + "modified": "2024-04-29T06:30:43Z", + "published": "2024-04-29T06:30:43Z", + "aliases": [ + "CVE-2024-33905" + ], + "details": "In Telegram WebK before 2.0.0 (488), a crafted Mini Web App allows XSS via the postMessage web_app_open_link event type.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33905" + }, + { + "type": "WEB", + "url": "https://github.com/morethanwords/tweb/commit/2153ea9878668769faac8dd5931b7e0b96a9f129/src/components/popups/webApp.ts" + }, + { + "type": "WEB", + "url": "https://medium.com/%40pedbap/telegram-web-app-xss-session-hijacking-1-click-95acccdc8d90" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/04/28/4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4x2c-gqrf-gvf9/GHSA-4x2c-gqrf-gvf9.json b/advisories/unreviewed/2024/04/GHSA-4x2c-gqrf-gvf9/GHSA-4x2c-gqrf-gvf9.json new file mode 100644 index 00000000000..42a880d99d5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4x2c-gqrf-gvf9/GHSA-4x2c-gqrf-gvf9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x2c-gqrf-gvf9", + "modified": "2024-04-29T06:30:42Z", + "published": "2024-04-29T06:30:42Z", + "aliases": [ + "CVE-2024-33649" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpOpal Opal Widgets For Elementor allows Stored XSS.This issue affects Opal Widgets For Elementor: from n/a through 1.6.9.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33649" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/opal-widgets-for-elementor/wordpress-opal-widgets-for-elementor-plugin-1-6-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7855-3hjg-5779/GHSA-7855-3hjg-5779.json b/advisories/unreviewed/2024/04/GHSA-7855-3hjg-5779/GHSA-7855-3hjg-5779.json new file mode 100644 index 00000000000..43c559ef305 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7855-3hjg-5779/GHSA-7855-3hjg-5779.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7855-3hjg-5779", + "modified": "2024-04-29T06:30:42Z", + "published": "2024-04-29T06:30:42Z", + "aliases": [ + "CVE-2024-2505" + ], + "details": "The GamiPress WordPress plugin before 6.8.9's access control mechanism fails to properly restrict access to its settings, permitting Authors to manipulate requests and extend access to lower privileged users, like Subscribers, despite initial settings prohibiting such access. This vulnerability resembles broken access control, enabling unauthorized users to modify critical GamiPress WordPress plugin before 6.8.9 configurations.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2505" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/9b3d6148-ecee-4e59-84a4-3b3e9898473b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7f66-fgh3-955x/GHSA-7f66-fgh3-955x.json b/advisories/unreviewed/2024/04/GHSA-7f66-fgh3-955x/GHSA-7f66-fgh3-955x.json new file mode 100644 index 00000000000..2d0ca43f2f4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7f66-fgh3-955x/GHSA-7f66-fgh3-955x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f66-fgh3-955x", + "modified": "2024-04-29T06:30:42Z", + "published": "2024-04-29T06:30:42Z", + "aliases": [ + "CVE-2024-33540" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGrill ColorNews allows Stored XSS.This issue affects ColorNews: from n/a through 1.2.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33540" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/colornews/wordpress-colornews-theme-1-2-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-894f-rh68-m2vm/GHSA-894f-rh68-m2vm.json b/advisories/unreviewed/2024/04/GHSA-894f-rh68-m2vm/GHSA-894f-rh68-m2vm.json new file mode 100644 index 00000000000..8ca01dd89c4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-894f-rh68-m2vm/GHSA-894f-rh68-m2vm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-894f-rh68-m2vm", + "modified": "2024-04-29T06:30:42Z", + "published": "2024-04-29T06:30:42Z", + "aliases": [ + "CVE-2024-33554" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core allows Reflected XSS.This issue affects XStore Core: from n/a through 5.3.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33554" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/et-core-plugin/wordpress-xstore-core-plugin-5-3-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8g9x-vm55-m3mq/GHSA-8g9x-vm55-m3mq.json b/advisories/unreviewed/2024/04/GHSA-8g9x-vm55-m3mq/GHSA-8g9x-vm55-m3mq.json new file mode 100644 index 00000000000..71ef6bac369 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8g9x-vm55-m3mq/GHSA-8g9x-vm55-m3mq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g9x-vm55-m3mq", + "modified": "2024-04-29T06:30:42Z", + "published": "2024-04-29T06:30:42Z", + "aliases": [ + "CVE-2024-33646" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Sticky Anything allows Cross-Site Scripting (XSS).This issue affects Sticky Anything: from n/a through 2.1.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33646" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/toast-stick-anything/wordpress-sticky-anything-plugin-2-1-5-broken-access-control-to-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c3cg-v373-7p8j/GHSA-c3cg-v373-7p8j.json b/advisories/unreviewed/2024/04/GHSA-c3cg-v373-7p8j/GHSA-c3cg-v373-7p8j.json new file mode 100644 index 00000000000..546bc93bb00 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c3cg-v373-7p8j/GHSA-c3cg-v373-7p8j.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3cg-v373-7p8j", + "modified": "2024-04-29T06:30:43Z", + "published": "2024-04-29T06:30:43Z", + "aliases": [ + "CVE-2024-33904" + ], + "details": "In plugins/HookSystem.cpp in Hyprland through 0.39.1 (before 28c8561), through a race condition, a local attacker can cause execution of arbitrary assembly code by writing to a predictable temporary file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33904" + }, + { + "type": "WEB", + "url": "https://github.com/hyprwm/Hyprland/issues/5787" + }, + { + "type": "WEB", + "url": "https://github.com/hyprwm/Hyprland/commit/28c85619243e6320e75d7abcfe8244fa99d054dd" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/04/28/3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g7qj-fx7v-pm5j/GHSA-g7qj-fx7v-pm5j.json b/advisories/unreviewed/2024/04/GHSA-g7qj-fx7v-pm5j/GHSA-g7qj-fx7v-pm5j.json new file mode 100644 index 00000000000..bced2e74254 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g7qj-fx7v-pm5j/GHSA-g7qj-fx7v-pm5j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7qj-fx7v-pm5j", + "modified": "2024-04-29T06:30:42Z", + "published": "2024-04-29T06:30:42Z", + "aliases": [ + "CVE-2024-33537" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Horse WP Portfolio allows Stored XSS.This issue affects WP Portfolio: from n/a through 2.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33537" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-portfolio/wordpress-wp-portfolio-theme-2-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g89g-74wr-qhg3/GHSA-g89g-74wr-qhg3.json b/advisories/unreviewed/2024/04/GHSA-g89g-74wr-qhg3/GHSA-g89g-74wr-qhg3.json new file mode 100644 index 00000000000..6622beb6481 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g89g-74wr-qhg3/GHSA-g89g-74wr-qhg3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g89g-74wr-qhg3", + "modified": "2024-04-29T06:30:43Z", + "published": "2024-04-29T06:30:43Z", + "aliases": [ + "CVE-2024-4303" + ], + "details": "ArmorX Android APP's multi-factor authentication (MFA) for the login function is not properly implemented. Remote attackers who obtain user credentials can bypass MFA, allowing them to successfully log into the APP.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4303" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-7781-ef309-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-g99q-g998-c275/GHSA-g99q-g998-c275.json b/advisories/unreviewed/2024/04/GHSA-g99q-g998-c275/GHSA-g99q-g998-c275.json new file mode 100644 index 00000000000..8743dae3165 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-g99q-g998-c275/GHSA-g99q-g998-c275.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g99q-g998-c275", + "modified": "2024-04-29T06:30:42Z", + "published": "2024-04-29T06:30:42Z", + "aliases": [ + "CVE-2024-33559" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allows SQL Injection.This issue affects XStore: from n/a through 9.3.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33559" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/xstore/wordpress-xstore-theme-9-3-5-unauthenticated-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gwq4-xh4c-9x95/GHSA-gwq4-xh4c-9x95.json b/advisories/unreviewed/2024/04/GHSA-gwq4-xh4c-9x95/GHSA-gwq4-xh4c-9x95.json new file mode 100644 index 00000000000..3329a047a46 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gwq4-xh4c-9x95/GHSA-gwq4-xh4c-9x95.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwq4-xh4c-9x95", + "modified": "2024-04-29T06:30:42Z", + "published": "2024-04-29T06:30:42Z", + "aliases": [ + "CVE-2024-4300" + ], + "details": "E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the database configuration file path through the webpage source code without login. Accessing this path allows attacker to obtain the database credential with the highest privilege and database host IP address. With this information, attackers can connect to the database and perform actions such as adding, modifying, or deleting database contents.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4300" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-7774-fbd01-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h47p-p2xw-fphp/GHSA-h47p-p2xw-fphp.json b/advisories/unreviewed/2024/04/GHSA-h47p-p2xw-fphp/GHSA-h47p-p2xw-fphp.json new file mode 100644 index 00000000000..f32f3d85689 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h47p-p2xw-fphp/GHSA-h47p-p2xw-fphp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h47p-p2xw-fphp", + "modified": "2024-04-29T06:30:43Z", + "published": "2024-04-29T06:30:43Z", + "aliases": [ + "CVE-2024-33562" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore allows Reflected XSS.This issue affects XStore: from n/a through 9.3.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33562" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/xstore/wordpress-xstore-theme-9-3-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hh44-mx2m-2w3w/GHSA-hh44-mx2m-2w3w.json b/advisories/unreviewed/2024/04/GHSA-hh44-mx2m-2w3w/GHSA-hh44-mx2m-2w3w.json new file mode 100644 index 00000000000..bd7a7afa5f7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-hh44-mx2m-2w3w/GHSA-hh44-mx2m-2w3w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh44-mx2m-2w3w", + "modified": "2024-04-29T06:30:42Z", + "published": "2024-04-29T06:30:42Z", + "aliases": [ + "CVE-2024-4301" + ], + "details": "N-Reporter and N-Cloud, products of the N-Partner, have an OS Command Injection vulnerability. Remote attackers with normal user privilege can execute arbitrary system commands by manipulating user inputs on a specific page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4301" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-7776-035ff-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T04:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jc65-rh6v-pv5p/GHSA-jc65-rh6v-pv5p.json b/advisories/unreviewed/2024/04/GHSA-jc65-rh6v-pv5p/GHSA-jc65-rh6v-pv5p.json new file mode 100644 index 00000000000..041caabf60a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jc65-rh6v-pv5p/GHSA-jc65-rh6v-pv5p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc65-rh6v-pv5p", + "modified": "2024-04-29T06:30:42Z", + "published": "2024-04-29T06:30:42Z", + "aliases": [ + "CVE-2024-33633" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor Pro allows Reflected XSS.This issue affects Piotnet Addons For Elementor Pro: from n/a through 7.1.17.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33633" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/piotnet-addons-for-elementor-pro/wordpress-piotnet-addons-for-elementor-pro-plugin-7-1-17-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T05:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-m4rg-wp77-xw59/GHSA-m4rg-wp77-xw59.json b/advisories/unreviewed/2024/04/GHSA-m4rg-wp77-xw59/GHSA-m4rg-wp77-xw59.json new file mode 100644 index 00000000000..e5aa170ee53 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-m4rg-wp77-xw59/GHSA-m4rg-wp77-xw59.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4rg-wp77-xw59", + "modified": "2024-04-29T06:30:42Z", + "published": "2024-04-29T06:30:42Z", + "aliases": [ + "CVE-2024-33539" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Addons for Elementor (Templates, Widgets) allows Stored XSS.This issue affects WPZOOM Addons for Elementor (Templates, Widgets): from n/a through 1.1.35.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33539" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpzoom-elementor-addons/wordpress-wpzoom-addons-for-elementor-plugin-1-1-35-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mw23-jwm4-23g8/GHSA-mw23-jwm4-23g8.json b/advisories/unreviewed/2024/04/GHSA-mw23-jwm4-23g8/GHSA-mw23-jwm4-23g8.json new file mode 100644 index 00000000000..176d35c3198 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mw23-jwm4-23g8/GHSA-mw23-jwm4-23g8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw23-jwm4-23g8", + "modified": "2024-04-29T06:30:42Z", + "published": "2024-04-29T06:30:42Z", + "aliases": [ + "CVE-2024-33640" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LBell Pretty Google Calendar allows Stored XSS.This issue affects Pretty Google Calendar: from n/a through 1.7.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33640" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pretty-google-calendar/wordpress-pretty-google-calendar-plugin-1-7-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T05:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-phc8-j9rw-cv2q/GHSA-phc8-j9rw-cv2q.json b/advisories/unreviewed/2024/04/GHSA-phc8-j9rw-cv2q/GHSA-phc8-j9rw-cv2q.json new file mode 100644 index 00000000000..eec401ba991 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-phc8-j9rw-cv2q/GHSA-phc8-j9rw-cv2q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phc8-j9rw-cv2q", + "modified": "2024-04-29T06:30:43Z", + "published": "2024-04-29T06:30:43Z", + "aliases": [ + "CVE-2024-4302" + ], + "details": "Super 8 Live Chat online customer service platform fails to properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. When the message recipient views the message, they become susceptible to Cross-site Scripting (XSS) attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4302" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-7779-35562-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q2pw-g7vq-q2cm/GHSA-q2pw-g7vq-q2cm.json b/advisories/unreviewed/2024/04/GHSA-q2pw-g7vq-q2cm/GHSA-q2pw-g7vq-q2cm.json new file mode 100644 index 00000000000..24371264666 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q2pw-g7vq-q2cm/GHSA-q2pw-g7vq-q2cm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2pw-g7vq-q2cm", + "modified": "2024-04-29T06:30:43Z", + "published": "2024-04-29T06:30:43Z", + "aliases": [ + "CVE-2024-33632" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Piotnet Piotnet Addons For Elementor Pro.This issue affects Piotnet Addons For Elementor Pro: from n/a through 7.1.17.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33632" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/piotnet-addons-for-elementor-pro/wordpress-piotnet-addons-for-elementor-pro-plugin-7-1-17-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q3rr-7hjc-7c55/GHSA-q3rr-7hjc-7c55.json b/advisories/unreviewed/2024/04/GHSA-q3rr-7hjc-7c55/GHSA-q3rr-7hjc-7c55.json new file mode 100644 index 00000000000..4b296c0228f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q3rr-7hjc-7c55/GHSA-q3rr-7hjc-7c55.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3rr-7hjc-7c55", + "modified": "2024-04-29T06:30:42Z", + "published": "2024-04-29T06:30:42Z", + "aliases": [ + "CVE-2024-33645" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eftakhairul Islam & Sirajus Salayhin Easy Set Favicon allows Reflected XSS.This issue affects Easy Set Favicon: from n/a through 1.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33645" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/easy-set-favicon/wordpress-easy-set-favicon-plugin-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q59j-4j35-wm99/GHSA-q59j-4j35-wm99.json b/advisories/unreviewed/2024/04/GHSA-q59j-4j35-wm99/GHSA-q59j-4j35-wm99.json new file mode 100644 index 00000000000..2aaf37cd653 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q59j-4j35-wm99/GHSA-q59j-4j35-wm99.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q59j-4j35-wm99", + "modified": "2024-04-29T06:30:42Z", + "published": "2024-04-29T06:30:42Z", + "aliases": [ + "CVE-2024-33548" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team WZone allows Reflected XSS.This issue affects WZone: from n/a through 14.0.10.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33548" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woozone/wordpress-wzone-plugin-14-0-10-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-q8qm-w223-fx6w/GHSA-q8qm-w223-fx6w.json b/advisories/unreviewed/2024/04/GHSA-q8qm-w223-fx6w/GHSA-q8qm-w223-fx6w.json new file mode 100644 index 00000000000..c475f0ebcfe --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-q8qm-w223-fx6w/GHSA-q8qm-w223-fx6w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8qm-w223-fx6w", + "modified": "2024-04-29T06:30:43Z", + "published": "2024-04-29T06:30:43Z", + "aliases": [ + "CVE-2024-33681" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Sandor Kovacs Regenerate post permalink allows Cross-Site Scripting (XSS).This issue affects Regenerate post permalink: from n/a through 1.0.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33681" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/regenerate-post-permalinks/wordpress-regenerate-post-permalink-plugin-1-0-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rqw7-3533-cfwv/GHSA-rqw7-3533-cfwv.json b/advisories/unreviewed/2024/04/GHSA-rqw7-3533-cfwv/GHSA-rqw7-3533-cfwv.json new file mode 100644 index 00000000000..3e5808aa2de --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rqw7-3533-cfwv/GHSA-rqw7-3533-cfwv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqw7-3533-cfwv", + "modified": "2024-04-29T06:30:42Z", + "published": "2024-04-29T06:30:42Z", + "aliases": [ + "CVE-2024-33648" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wzy Media Recencio Book Reviews allows Stored XSS.This issue affects Recencio Book Reviews: from n/a through 1.66.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33648" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/recencio-book-reviews/wordpress-recencio-book-reviews-plugin-1-66-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rr4m-8whr-q39q/GHSA-rr4m-8whr-q39q.json b/advisories/unreviewed/2024/04/GHSA-rr4m-8whr-q39q/GHSA-rr4m-8whr-q39q.json new file mode 100644 index 00000000000..1b727f7171f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rr4m-8whr-q39q/GHSA-rr4m-8whr-q39q.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rr4m-8whr-q39q", + "modified": "2024-04-29T06:30:42Z", + "published": "2024-04-29T06:30:42Z", + "aliases": [ + "CVE-2024-33339" + ], + "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33339" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T05:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rrx7-mfpg-89v6/GHSA-rrx7-mfpg-89v6.json b/advisories/unreviewed/2024/04/GHSA-rrx7-mfpg-89v6/GHSA-rrx7-mfpg-89v6.json new file mode 100644 index 00000000000..791a7b1a4b8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rrx7-mfpg-89v6/GHSA-rrx7-mfpg-89v6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrx7-mfpg-89v6", + "modified": "2024-04-29T06:30:43Z", + "published": "2024-04-29T06:30:43Z", + "aliases": [ + "CVE-2024-33571" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infomaniak Staff VOD Infomaniak allows Reflected XSS.This issue affects VOD Infomaniak: from n/a through 1.5.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33571" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/vod-infomaniak/wordpress-vod-infomaniak-plugin-1-5-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v43w-m78j-vr5m/GHSA-v43w-m78j-vr5m.json b/advisories/unreviewed/2024/04/GHSA-v43w-m78j-vr5m/GHSA-v43w-m78j-vr5m.json new file mode 100644 index 00000000000..1947e5cd131 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v43w-m78j-vr5m/GHSA-v43w-m78j-vr5m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v43w-m78j-vr5m", + "modified": "2024-04-29T06:30:42Z", + "published": "2024-04-29T06:30:42Z", + "aliases": [ + "CVE-2024-33542" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in Fabio Rinaldi Crelly Slider.This issue affects Crelly Slider: from n/a through 1.4.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33542" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/crelly-slider/wordpress-crelly-slider-plugin-1-4-5-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-v8mx-hp8h-89vc/GHSA-v8mx-hp8h-89vc.json b/advisories/unreviewed/2024/04/GHSA-v8mx-hp8h-89vc/GHSA-v8mx-hp8h-89vc.json new file mode 100644 index 00000000000..ae6ee0362ff --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-v8mx-hp8h-89vc/GHSA-v8mx-hp8h-89vc.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8mx-hp8h-89vc", + "modified": "2024-04-29T06:30:42Z", + "published": "2024-04-29T06:30:42Z", + "aliases": [ + "CVE-2023-52723" + ], + "details": "In KDE libksieve before 23.03.80, kmanagesieve/session.cpp places a cleartext password in server logs because a username variable is accidentally given a password value.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52723" + }, + { + "type": "WEB", + "url": "https://invent.kde.org/pim/libksieve/-/commit/6b460ba93ac4ac503ba039d0b788ac7595120db1" + }, + { + "type": "WEB", + "url": "https://invent.kde.org/pim/libksieve/-/tags/v23.03.80" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/04/25/1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vvjc-x5q2-8qr6/GHSA-vvjc-x5q2-8qr6.json b/advisories/unreviewed/2024/04/GHSA-vvjc-x5q2-8qr6/GHSA-vvjc-x5q2-8qr6.json new file mode 100644 index 00000000000..7a27233895c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vvjc-x5q2-8qr6/GHSA-vvjc-x5q2-8qr6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvjc-x5q2-8qr6", + "modified": "2024-04-29T06:30:42Z", + "published": "2024-04-29T06:30:42Z", + "aliases": [ + "CVE-2024-33643" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kailey Lampert Advanced Most Recent Posts Mod allows Stored XSS.This issue affects Advanced Most Recent Posts Mod: from n/a through 1.6.5.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33643" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/advanced-most-recent-posts-mod/wordpress-advanced-most-recent-posts-mod-plugin-1-6-5-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T05:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wgx8-xhfh-5ph4/GHSA-wgx8-xhfh-5ph4.json b/advisories/unreviewed/2024/04/GHSA-wgx8-xhfh-5ph4/GHSA-wgx8-xhfh-5ph4.json new file mode 100644 index 00000000000..f21ee55f560 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wgx8-xhfh-5ph4/GHSA-wgx8-xhfh-5ph4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgx8-xhfh-5ph4", + "modified": "2024-04-29T06:30:41Z", + "published": "2024-04-29T06:30:41Z", + "aliases": [ + "CVE-2024-4299" + ], + "details": "The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of arbitrary system commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4299" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-7771-36c50-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xmpc-wq83-gmwh/GHSA-xmpc-wq83-gmwh.json b/advisories/unreviewed/2024/04/GHSA-xmpc-wq83-gmwh/GHSA-xmpc-wq83-gmwh.json new file mode 100644 index 00000000000..f14418521db --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xmpc-wq83-gmwh/GHSA-xmpc-wq83-gmwh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmpc-wq83-gmwh", + "modified": "2024-04-29T06:30:43Z", + "published": "2024-04-29T06:30:43Z", + "aliases": [ + "CVE-2024-33631" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor Pro allows Stored XSS.This issue affects Piotnet Addons For Elementor Pro: from n/a through 7.1.17.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33631" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/piotnet-addons-for-elementor-pro/wordpress-piotnet-addons-for-elementor-pro-plugin-7-1-17-authenticated-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-29T06:15:14Z" + } +} \ No newline at end of file