From b028c3c0cc1fd10446621984569ef38baef00970 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 15 Apr 2025 12:33:14 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-g854-mv2r-2r5h.json | 6 ++- .../GHSA-46h9-fw88-xg28.json | 6 ++- .../GHSA-496p-8p53-pf9q.json | 36 ++++++++++++++ .../GHSA-4ggw-vj5v-vmmr.json | 36 ++++++++++++++ .../GHSA-5872-x52x-q96j.json | 36 ++++++++++++++ .../GHSA-5c99-5p26-3hr3.json | 36 ++++++++++++++ .../GHSA-5cg8-h9x2-9pr7.json | 3 +- .../GHSA-6hpm-6635-ff29.json | 36 ++++++++++++++ .../GHSA-6jv7-mvg8-7rm7.json | 36 ++++++++++++++ .../GHSA-6xhm-99g5-jqxm.json | 3 +- .../GHSA-7529-g7rg-78rw.json | 36 ++++++++++++++ .../GHSA-7gg5-pghg-4cqq.json | 40 ++++++++++++++++ .../GHSA-7qjh-m8m2-899r.json | 36 ++++++++++++++ .../GHSA-7v3q-fc37-v2cj.json | 36 ++++++++++++++ .../GHSA-8gp9-8pvw-2fjq.json | 36 ++++++++++++++ .../GHSA-9q43-jrc4-8mmg.json | 36 ++++++++++++++ .../GHSA-c8fr-pr74-j8mq.json | 36 ++++++++++++++ .../GHSA-ggp5-cmc4-x9q4.json | 6 ++- .../GHSA-mcrr-hrpg-6h99.json | 36 ++++++++++++++ .../GHSA-mgcw-m7m8-h679.json | 36 ++++++++++++++ .../GHSA-mjvr-cp58-pc6w.json | 36 ++++++++++++++ .../GHSA-mr53-ppcx-5xqw.json | 36 ++++++++++++++ .../GHSA-p8mv-f94r-2px4.json | 6 ++- .../GHSA-p924-2pc5-694x.json | 36 ++++++++++++++ .../GHSA-pcc7-3x8r-4957.json | 36 ++++++++++++++ .../GHSA-rv8x-mr8q-qqx3.json | 36 ++++++++++++++ .../GHSA-vgmf-pg9p-7hrx.json | 36 ++++++++++++++ .../GHSA-wfm6-6f2v-8xgw.json | 36 ++++++++++++++ .../GHSA-wmjp-wr28-6g9h.json | 48 +++++++++++++++++++ .../GHSA-xhqv-r4f7-v88g.json | 40 ++++++++++++++++ 30 files changed, 908 insertions(+), 6 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-496p-8p53-pf9q/GHSA-496p-8p53-pf9q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4ggw-vj5v-vmmr/GHSA-4ggw-vj5v-vmmr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5872-x52x-q96j/GHSA-5872-x52x-q96j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5c99-5p26-3hr3/GHSA-5c99-5p26-3hr3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6hpm-6635-ff29/GHSA-6hpm-6635-ff29.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6jv7-mvg8-7rm7/GHSA-6jv7-mvg8-7rm7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7529-g7rg-78rw/GHSA-7529-g7rg-78rw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7gg5-pghg-4cqq/GHSA-7gg5-pghg-4cqq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7qjh-m8m2-899r/GHSA-7qjh-m8m2-899r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7v3q-fc37-v2cj/GHSA-7v3q-fc37-v2cj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8gp9-8pvw-2fjq/GHSA-8gp9-8pvw-2fjq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9q43-jrc4-8mmg/GHSA-9q43-jrc4-8mmg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c8fr-pr74-j8mq/GHSA-c8fr-pr74-j8mq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mcrr-hrpg-6h99/GHSA-mcrr-hrpg-6h99.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mgcw-m7m8-h679/GHSA-mgcw-m7m8-h679.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mjvr-cp58-pc6w/GHSA-mjvr-cp58-pc6w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mr53-ppcx-5xqw/GHSA-mr53-ppcx-5xqw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p924-2pc5-694x/GHSA-p924-2pc5-694x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pcc7-3x8r-4957/GHSA-pcc7-3x8r-4957.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rv8x-mr8q-qqx3/GHSA-rv8x-mr8q-qqx3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vgmf-pg9p-7hrx/GHSA-vgmf-pg9p-7hrx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wfm6-6f2v-8xgw/GHSA-wfm6-6f2v-8xgw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wmjp-wr28-6g9h/GHSA-wmjp-wr28-6g9h.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xhqv-r4f7-v88g/GHSA-xhqv-r4f7-v88g.json diff --git a/advisories/unreviewed/2023/07/GHSA-g854-mv2r-2r5h/GHSA-g854-mv2r-2r5h.json b/advisories/unreviewed/2023/07/GHSA-g854-mv2r-2r5h/GHSA-g854-mv2r-2r5h.json index 35f0b1b9b57..87f5c8c7437 100644 --- a/advisories/unreviewed/2023/07/GHSA-g854-mv2r-2r5h/GHSA-g854-mv2r-2r5h.json +++ b/advisories/unreviewed/2023/07/GHSA-g854-mv2r-2r5h/GHSA-g854-mv2r-2r5h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g854-mv2r-2r5h", - "modified": "2024-04-04T06:20:14Z", + "modified": "2025-04-15T12:30:24Z", "published": "2023-07-24T18:30:44Z", "aliases": [ "CVE-2023-3640" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3640" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6583" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-3640" diff --git a/advisories/unreviewed/2025/04/GHSA-46h9-fw88-xg28/GHSA-46h9-fw88-xg28.json b/advisories/unreviewed/2025/04/GHSA-46h9-fw88-xg28/GHSA-46h9-fw88-xg28.json index 1cc239ce444..92c78e96c70 100644 --- a/advisories/unreviewed/2025/04/GHSA-46h9-fw88-xg28/GHSA-46h9-fw88-xg28.json +++ b/advisories/unreviewed/2025/04/GHSA-46h9-fw88-xg28/GHSA-46h9-fw88-xg28.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-46h9-fw88-xg28", - "modified": "2025-04-14T18:31:49Z", + "modified": "2025-04-15T12:30:24Z", "published": "2025-04-14T18:31:49Z", "aliases": [ "CVE-2025-22371" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://cisrt.divd.nl/CVE-2025-22371" }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2025-22371" + }, { "type": "WEB", "url": "https://csirt.divd.nl/DIVD-2025-00001" diff --git a/advisories/unreviewed/2025/04/GHSA-496p-8p53-pf9q/GHSA-496p-8p53-pf9q.json b/advisories/unreviewed/2025/04/GHSA-496p-8p53-pf9q/GHSA-496p-8p53-pf9q.json new file mode 100644 index 00000000000..9fc2dd44502 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-496p-8p53-pf9q/GHSA-496p-8p53-pf9q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-496p-8p53-pf9q", + "modified": "2025-04-15T12:30:25Z", + "published": "2025-04-15T12:30:25Z", + "aliases": [ + "CVE-2025-30962" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound FS Poster allows Reflected XSS. This issue affects FS Poster: from n/a through 6.5.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30962" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fs-poster/vulnerability/wordpress-fs-poster-plugin-6-5-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T12:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4ggw-vj5v-vmmr/GHSA-4ggw-vj5v-vmmr.json b/advisories/unreviewed/2025/04/GHSA-4ggw-vj5v-vmmr/GHSA-4ggw-vj5v-vmmr.json new file mode 100644 index 00000000000..8a9f5f40e46 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4ggw-vj5v-vmmr/GHSA-4ggw-vj5v-vmmr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4ggw-vj5v-vmmr", + "modified": "2025-04-15T12:30:24Z", + "published": "2025-04-15T12:30:24Z", + "aliases": [ + "CVE-2025-26741" + ], + "details": "Missing Authorization vulnerability in AWEOS GmbH Email Notifications for Updates allows Privilege Escalation. This issue affects Email Notifications for Updates: from n/a through 1.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26741" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-update-mail-notification/vulnerability/wordpress-email-notifications-for-updates-1-1-6-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5872-x52x-q96j/GHSA-5872-x52x-q96j.json b/advisories/unreviewed/2025/04/GHSA-5872-x52x-q96j/GHSA-5872-x52x-q96j.json new file mode 100644 index 00000000000..5df354c07a1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5872-x52x-q96j/GHSA-5872-x52x-q96j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5872-x52x-q96j", + "modified": "2025-04-15T12:30:24Z", + "published": "2025-04-15T12:30:24Z", + "aliases": [ + "CVE-2025-26982" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric-Oliver Mächler DSGVO Youtube allows DOM-Based XSS. This issue affects DSGVO Youtube: from n/a through 1.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26982" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dsgvo-youtube/vulnerability/wordpress-dsgvo-youtube-plugin-1-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T12:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5c99-5p26-3hr3/GHSA-5c99-5p26-3hr3.json b/advisories/unreviewed/2025/04/GHSA-5c99-5p26-3hr3/GHSA-5c99-5p26-3hr3.json new file mode 100644 index 00000000000..de2ba99824e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5c99-5p26-3hr3/GHSA-5c99-5p26-3hr3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c99-5p26-3hr3", + "modified": "2025-04-15T12:30:24Z", + "published": "2025-04-15T12:30:24Z", + "aliases": [ + "CVE-2025-26744" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound JetBlog allows DOM-Based XSS. This issue affects JetBlog: from n/a through 2.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26744" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jet-blog/vulnerability/wordpress-jetblog-plugin-2-4-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5cg8-h9x2-9pr7/GHSA-5cg8-h9x2-9pr7.json b/advisories/unreviewed/2025/04/GHSA-5cg8-h9x2-9pr7/GHSA-5cg8-h9x2-9pr7.json index 86ce8bbf758..b2363b80a47 100644 --- a/advisories/unreviewed/2025/04/GHSA-5cg8-h9x2-9pr7/GHSA-5cg8-h9x2-9pr7.json +++ b/advisories/unreviewed/2025/04/GHSA-5cg8-h9x2-9pr7/GHSA-5cg8-h9x2-9pr7.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-6hpm-6635-ff29/GHSA-6hpm-6635-ff29.json b/advisories/unreviewed/2025/04/GHSA-6hpm-6635-ff29/GHSA-6hpm-6635-ff29.json new file mode 100644 index 00000000000..827c0670063 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6hpm-6635-ff29/GHSA-6hpm-6635-ff29.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hpm-6635-ff29", + "modified": "2025-04-15T12:30:25Z", + "published": "2025-04-15T12:30:25Z", + "aliases": [ + "CVE-2025-26944" + ], + "details": "Missing Authorization vulnerability in NotFound JetPopup allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects JetPopup: from n/a through 2.0.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26944" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jet-popup/vulnerability/wordpress-jetpopup-2-0-11-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T12:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6jv7-mvg8-7rm7/GHSA-6jv7-mvg8-7rm7.json b/advisories/unreviewed/2025/04/GHSA-6jv7-mvg8-7rm7/GHSA-6jv7-mvg8-7rm7.json new file mode 100644 index 00000000000..82eaeecf6a0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6jv7-mvg8-7rm7/GHSA-6jv7-mvg8-7rm7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jv7-mvg8-7rm7", + "modified": "2025-04-15T12:30:25Z", + "published": "2025-04-15T12:30:25Z", + "aliases": [ + "CVE-2025-26992" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fatcatapps Landing Page Cat allows Reflected XSS. This issue affects Landing Page Cat: from n/a through 1.7.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26992" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/landing-page-cat/vulnerability/wordpress-landing-page-cat-plugin-1-7-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T12:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6xhm-99g5-jqxm/GHSA-6xhm-99g5-jqxm.json b/advisories/unreviewed/2025/04/GHSA-6xhm-99g5-jqxm/GHSA-6xhm-99g5-jqxm.json index ab805d75b84..efab9cd1a69 100644 --- a/advisories/unreviewed/2025/04/GHSA-6xhm-99g5-jqxm/GHSA-6xhm-99g5-jqxm.json +++ b/advisories/unreviewed/2025/04/GHSA-6xhm-99g5-jqxm/GHSA-6xhm-99g5-jqxm.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-7529-g7rg-78rw/GHSA-7529-g7rg-78rw.json b/advisories/unreviewed/2025/04/GHSA-7529-g7rg-78rw/GHSA-7529-g7rg-78rw.json new file mode 100644 index 00000000000..85680d9a8d6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7529-g7rg-78rw/GHSA-7529-g7rg-78rw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7529-g7rg-78rw", + "modified": "2025-04-15T12:30:25Z", + "published": "2025-04-15T12:30:25Z", + "aliases": [ + "CVE-2025-26959" + ], + "details": "Missing Authorization vulnerability in Quý Lê 91 Administrator Z allows Privilege Escalation. This issue affects Administrator Z: from n/a through 2025.03.24.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26959" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/administrator-z/vulnerability/wordpress-administrator-z-2025-03-24-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T12:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7gg5-pghg-4cqq/GHSA-7gg5-pghg-4cqq.json b/advisories/unreviewed/2025/04/GHSA-7gg5-pghg-4cqq/GHSA-7gg5-pghg-4cqq.json new file mode 100644 index 00000000000..72d3947ae32 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7gg5-pghg-4cqq/GHSA-7gg5-pghg-4cqq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gg5-pghg-4cqq", + "modified": "2025-04-15T12:30:24Z", + "published": "2025-04-15T12:30:24Z", + "aliases": [ + "CVE-2025-32943" + ], + "details": "The vulnerability allows any authenticated user to leak the contents of arbitrary “.m3u8” files from the PeerTube server due to a path traversal in the HLS endpoint.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32943" + }, + { + "type": "WEB", + "url": "https://github.com/Chocobozzz/PeerTube/releases/tag/v7.1.1" + }, + { + "type": "WEB", + "url": "https://research.jfrog.com/vulnerabilities/peertube-hls-path-traversal" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T11:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7qjh-m8m2-899r/GHSA-7qjh-m8m2-899r.json b/advisories/unreviewed/2025/04/GHSA-7qjh-m8m2-899r/GHSA-7qjh-m8m2-899r.json new file mode 100644 index 00000000000..d780dc0dba2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7qjh-m8m2-899r/GHSA-7qjh-m8m2-899r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qjh-m8m2-899r", + "modified": "2025-04-15T12:30:25Z", + "published": "2025-04-15T12:30:25Z", + "aliases": [ + "CVE-2025-31011" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ReichertBrothers SimplyRETS Real Estate IDX allows Reflected XSS. This issue affects SimplyRETS Real Estate IDX: from n/a through 3.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31011" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simply-rets/vulnerability/wordpress-simplyrets-real-estate-idx-plugin-3-0-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T12:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7v3q-fc37-v2cj/GHSA-7v3q-fc37-v2cj.json b/advisories/unreviewed/2025/04/GHSA-7v3q-fc37-v2cj/GHSA-7v3q-fc37-v2cj.json new file mode 100644 index 00000000000..f03845cb7f3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7v3q-fc37-v2cj/GHSA-7v3q-fc37-v2cj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v3q-fc37-v2cj", + "modified": "2025-04-15T12:30:25Z", + "published": "2025-04-15T12:30:25Z", + "aliases": [ + "CVE-2025-30985" + ], + "details": "Deserialization of Untrusted Data vulnerability in NotFound GNUCommerce allows Object Injection. This issue affects GNUCommerce: from n/a through 1.5.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30985" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gnucommerce/vulnerability/wordpress-gnucommerce-plugin-1-5-4-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T12:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8gp9-8pvw-2fjq/GHSA-8gp9-8pvw-2fjq.json b/advisories/unreviewed/2025/04/GHSA-8gp9-8pvw-2fjq/GHSA-8gp9-8pvw-2fjq.json new file mode 100644 index 00000000000..0c77d1176b9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8gp9-8pvw-2fjq/GHSA-8gp9-8pvw-2fjq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gp9-8pvw-2fjq", + "modified": "2025-04-15T12:30:24Z", + "published": "2025-04-15T12:30:24Z", + "aliases": [ + "CVE-2025-26942" + ], + "details": "Missing Authorization vulnerability in NotFound JetTricks allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects JetTricks: from n/a through 1.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26942" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jet-tricks/vulnerability/wordpress-jettricks-1-5-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T12:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9q43-jrc4-8mmg/GHSA-9q43-jrc4-8mmg.json b/advisories/unreviewed/2025/04/GHSA-9q43-jrc4-8mmg/GHSA-9q43-jrc4-8mmg.json new file mode 100644 index 00000000000..1237f4b1f48 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9q43-jrc4-8mmg/GHSA-9q43-jrc4-8mmg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q43-jrc4-8mmg", + "modified": "2025-04-15T12:30:25Z", + "published": "2025-04-15T12:30:24Z", + "aliases": [ + "CVE-2025-26894" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound Coming Soon, Maintenance Mode allows PHP Local File Inclusion. This issue affects Coming Soon, Maintenance Mode: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26894" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/site-mode/vulnerability/wordpress-coming-soon-maintenance-mode-plugin-1-1-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T12:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c8fr-pr74-j8mq/GHSA-c8fr-pr74-j8mq.json b/advisories/unreviewed/2025/04/GHSA-c8fr-pr74-j8mq/GHSA-c8fr-pr74-j8mq.json new file mode 100644 index 00000000000..d8c3391db71 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c8fr-pr74-j8mq/GHSA-c8fr-pr74-j8mq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8fr-pr74-j8mq", + "modified": "2025-04-15T12:30:25Z", + "published": "2025-04-15T12:30:25Z", + "aliases": [ + "CVE-2025-26990" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in WP Royal Royal Elementor Addons allows Server Side Request Forgery. This issue affects Royal Elementor Addons: from n/a through 1.7.1006.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26990" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/royal-elementor-addons/vulnerability/wordpress-royal-elementor-addons-plugin-1-7-1006-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T12:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ggp5-cmc4-x9q4/GHSA-ggp5-cmc4-x9q4.json b/advisories/unreviewed/2025/04/GHSA-ggp5-cmc4-x9q4/GHSA-ggp5-cmc4-x9q4.json index 80b9ad0bbc8..d550ba0c85d 100644 --- a/advisories/unreviewed/2025/04/GHSA-ggp5-cmc4-x9q4/GHSA-ggp5-cmc4-x9q4.json +++ b/advisories/unreviewed/2025/04/GHSA-ggp5-cmc4-x9q4/GHSA-ggp5-cmc4-x9q4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ggp5-cmc4-x9q4", - "modified": "2025-04-14T18:31:49Z", + "modified": "2025-04-15T12:30:24Z", "published": "2025-04-14T18:31:49Z", "aliases": [ "CVE-2025-22373" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://cisrt.divd.nl/CVE-2025-22373" }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2025-22373" + }, { "type": "WEB", "url": "https://csirt.divd.nl/DIVD-2025-00001" diff --git a/advisories/unreviewed/2025/04/GHSA-mcrr-hrpg-6h99/GHSA-mcrr-hrpg-6h99.json b/advisories/unreviewed/2025/04/GHSA-mcrr-hrpg-6h99/GHSA-mcrr-hrpg-6h99.json new file mode 100644 index 00000000000..34a930086a6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mcrr-hrpg-6h99/GHSA-mcrr-hrpg-6h99.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcrr-hrpg-6h99", + "modified": "2025-04-15T12:30:24Z", + "published": "2025-04-15T12:30:24Z", + "aliases": [ + "CVE-2025-26743" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TC.K Advance WP Query Search Filter allows Reflected XSS. This issue affects Advance WP Query Search Filter: from n/a through 1.0.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26743" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advance-wp-query-search-filter/vulnerability/wordpress-advance-wp-query-search-filter-plugin-1-0-10-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mgcw-m7m8-h679/GHSA-mgcw-m7m8-h679.json b/advisories/unreviewed/2025/04/GHSA-mgcw-m7m8-h679/GHSA-mgcw-m7m8-h679.json new file mode 100644 index 00000000000..e5e3798dc70 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mgcw-m7m8-h679/GHSA-mgcw-m7m8-h679.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgcw-m7m8-h679", + "modified": "2025-04-15T12:30:25Z", + "published": "2025-04-15T12:30:25Z", + "aliases": [ + "CVE-2025-30965" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Cross Site Request Forgery. This issue affects WPJobBoard: from n/a through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30965" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpjobboard/vulnerability/wordpress-wpjobboard-plugin-5-11-1-multiple-cross-site-request-forgery-csrf-vulnerabilities-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T12:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mjvr-cp58-pc6w/GHSA-mjvr-cp58-pc6w.json b/advisories/unreviewed/2025/04/GHSA-mjvr-cp58-pc6w/GHSA-mjvr-cp58-pc6w.json new file mode 100644 index 00000000000..73dd22f2f59 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mjvr-cp58-pc6w/GHSA-mjvr-cp58-pc6w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjvr-cp58-pc6w", + "modified": "2025-04-15T12:30:25Z", + "published": "2025-04-15T12:30:25Z", + "aliases": [ + "CVE-2025-26954" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 1pluginjquery ZooEffect allows Reflected XSS. This issue affects ZooEffect: from n/a through 1.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26954" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/1-jquery-photo-gallery-slideshow-flash/vulnerability/wordpress-zooeffect-plugin-1-11-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T12:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mr53-ppcx-5xqw/GHSA-mr53-ppcx-5xqw.json b/advisories/unreviewed/2025/04/GHSA-mr53-ppcx-5xqw/GHSA-mr53-ppcx-5xqw.json new file mode 100644 index 00000000000..15474a15c22 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mr53-ppcx-5xqw/GHSA-mr53-ppcx-5xqw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr53-ppcx-5xqw", + "modified": "2025-04-15T12:30:25Z", + "published": "2025-04-15T12:30:25Z", + "aliases": [ + "CVE-2025-30964" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in EPC Photography. This issue affects Photography: from n/a through 7.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30964" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/photography/vulnerability/wordpress-photography-theme-7-5-2-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T12:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p8mv-f94r-2px4/GHSA-p8mv-f94r-2px4.json b/advisories/unreviewed/2025/04/GHSA-p8mv-f94r-2px4/GHSA-p8mv-f94r-2px4.json index 56a56f938d4..d8944f90790 100644 --- a/advisories/unreviewed/2025/04/GHSA-p8mv-f94r-2px4/GHSA-p8mv-f94r-2px4.json +++ b/advisories/unreviewed/2025/04/GHSA-p8mv-f94r-2px4/GHSA-p8mv-f94r-2px4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p8mv-f94r-2px4", - "modified": "2025-04-14T18:31:49Z", + "modified": "2025-04-15T12:30:24Z", "published": "2025-04-14T18:31:49Z", "aliases": [ "CVE-2025-22372" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://cisrt.divd.nl/CVE-2025-22372" }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2025-22372" + }, { "type": "WEB", "url": "https://csirt.divd.nl/DIVD-2025-00001" diff --git a/advisories/unreviewed/2025/04/GHSA-p924-2pc5-694x/GHSA-p924-2pc5-694x.json b/advisories/unreviewed/2025/04/GHSA-p924-2pc5-694x/GHSA-p924-2pc5-694x.json new file mode 100644 index 00000000000..b611dd6aa5b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p924-2pc5-694x/GHSA-p924-2pc5-694x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p924-2pc5-694x", + "modified": "2025-04-15T12:30:25Z", + "published": "2025-04-15T12:30:25Z", + "aliases": [ + "CVE-2025-26955" + ], + "details": "Missing Authorization vulnerability in VW Themes Industrial Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Industrial Lite: from n/a through 1.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26955" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/industrial-lite/vulnerability/wordpress-industrial-lite-theme-1-0-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T12:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pcc7-3x8r-4957/GHSA-pcc7-3x8r-4957.json b/advisories/unreviewed/2025/04/GHSA-pcc7-3x8r-4957/GHSA-pcc7-3x8r-4957.json new file mode 100644 index 00000000000..569c946e14c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pcc7-3x8r-4957/GHSA-pcc7-3x8r-4957.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcc7-3x8r-4957", + "modified": "2025-04-15T12:30:24Z", + "published": "2025-04-15T12:30:24Z", + "aliases": [ + "CVE-2025-26889" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound hockeydata LOS allows PHP Local File Inclusion. This issue affects hockeydata LOS: from n/a through 1.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26889" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hockeydata-los/vulnerability/wordpress-hockeydata-los-plugin-1-2-4-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rv8x-mr8q-qqx3/GHSA-rv8x-mr8q-qqx3.json b/advisories/unreviewed/2025/04/GHSA-rv8x-mr8q-qqx3/GHSA-rv8x-mr8q-qqx3.json new file mode 100644 index 00000000000..e6dfb06bd54 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rv8x-mr8q-qqx3/GHSA-rv8x-mr8q-qqx3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv8x-mr8q-qqx3", + "modified": "2025-04-15T12:30:25Z", + "published": "2025-04-15T12:30:25Z", + "aliases": [ + "CVE-2025-26958" + ], + "details": "Missing Authorization vulnerability in NotFound JetBlog allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects JetBlog: from n/a through 2.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26958" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jet-blog/vulnerability/wordpress-jetblog-2-4-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T12:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vgmf-pg9p-7hrx/GHSA-vgmf-pg9p-7hrx.json b/advisories/unreviewed/2025/04/GHSA-vgmf-pg9p-7hrx/GHSA-vgmf-pg9p-7hrx.json new file mode 100644 index 00000000000..d6043f55e99 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vgmf-pg9p-7hrx/GHSA-vgmf-pg9p-7hrx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgmf-pg9p-7hrx", + "modified": "2025-04-15T12:30:25Z", + "published": "2025-04-15T12:30:24Z", + "aliases": [ + "CVE-2025-26745" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RSTheme RS Elements Elementor Addon allows Stored XSS. This issue affects RS Elements Elementor Addon: from n/a through 1.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26745" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rselements-lite/vulnerability/wordpress-rs-elements-elementor-addon-plugin-1-1-5-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wfm6-6f2v-8xgw/GHSA-wfm6-6f2v-8xgw.json b/advisories/unreviewed/2025/04/GHSA-wfm6-6f2v-8xgw/GHSA-wfm6-6f2v-8xgw.json new file mode 100644 index 00000000000..84873263d6c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wfm6-6f2v-8xgw/GHSA-wfm6-6f2v-8xgw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfm6-6f2v-8xgw", + "modified": "2025-04-15T12:30:25Z", + "published": "2025-04-15T12:30:25Z", + "aliases": [ + "CVE-2025-32929" + ], + "details": "Missing Authorization vulnerability in Dmitry V. (CEO of \"UKR Solution\") Barcode Generator for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Barcode Generator for WooCommerce: from n/a through 2.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32929" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/embedding-barcodes-into-product-pages-and-orders/vulnerability/wordpress-barcode-generator-for-woocommerce-plugin-2-0-4-arbitrary-content-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T12:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wmjp-wr28-6g9h/GHSA-wmjp-wr28-6g9h.json b/advisories/unreviewed/2025/04/GHSA-wmjp-wr28-6g9h/GHSA-wmjp-wr28-6g9h.json new file mode 100644 index 00000000000..73042145f30 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wmjp-wr28-6g9h/GHSA-wmjp-wr28-6g9h.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmjp-wr28-6g9h", + "modified": "2025-04-15T12:30:24Z", + "published": "2025-04-15T12:30:24Z", + "aliases": [ + "CVE-2025-2083" + ], + "details": "The Logo Carousel Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sliderId’ parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2083" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/awesome-logo-carousel-block/tags/2.1.3/inc/classes/style.php#L86" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3271660" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/awesome-logo-carousel-block/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/604123f4-9247-489a-8fc8-478bfc697c7f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xhqv-r4f7-v88g/GHSA-xhqv-r4f7-v88g.json b/advisories/unreviewed/2025/04/GHSA-xhqv-r4f7-v88g/GHSA-xhqv-r4f7-v88g.json new file mode 100644 index 00000000000..e8b3426f424 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xhqv-r4f7-v88g/GHSA-xhqv-r4f7-v88g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhqv-r4f7-v88g", + "modified": "2025-04-15T12:30:24Z", + "published": "2025-04-15T12:30:24Z", + "aliases": [ + "CVE-2025-1688" + ], + "details": "Milestone Systems has discovered a\nsecurity vulnerability in Milestone XProtect installer that resets system\nconfiguration password after the upgrading from older versions using specific\ninstallers.\n\n\n\nThe system configuration\npassword is an additional, optional protection that is enabled on the\nManagement Server.\n\n\nTo mitigate the issue, we highly recommend updating system configuration password via GUI with a standard procedure.\n\n\n\nAny system upgraded with\n2024 R1 or 2024 R2 release installer is vulnerable to this issue.\n\n\n\nSystems upgraded from 2023\nR3 or older with version 2025 R1 and newer are not affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1688" + }, + { + "type": "WEB", + "url": "https://supportcommunity.milestonesys.com/KBRedir?art=000069835&lang=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-311" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T11:15:44Z" + } +} \ No newline at end of file