diff --git a/advisories/unreviewed/2024/11/GHSA-3wx7-g4gx-j36c/GHSA-3wx7-g4gx-j36c.json b/advisories/unreviewed/2024/11/GHSA-3wx7-g4gx-j36c/GHSA-3wx7-g4gx-j36c.json new file mode 100644 index 00000000000..c54b677b035 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3wx7-g4gx-j36c/GHSA-3wx7-g4gx-j36c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wx7-g4gx-j36c", + "modified": "2024-11-30T21:30:41Z", + "published": "2024-11-30T21:30:41Z", + "aliases": [ + "CVE-2024-53788" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Portfoliohub WordPress Portfolio Builder – Portfolio Gallery allows Stored XSS.This issue affects WordPress Portfolio Builder – Portfolio Gallery: from n/a through 1.1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53788" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/uber-grid/vulnerability/wordpress-wordpress-portfolio-builder-portfolio-gallery-plugin-1-1-7-cross-site-scripting-xss-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-30T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f9x6-g3qw-c7c4/GHSA-f9x6-g3qw-c7c4.json b/advisories/unreviewed/2024/11/GHSA-f9x6-g3qw-c7c4/GHSA-f9x6-g3qw-c7c4.json new file mode 100644 index 00000000000..f3024b6a954 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f9x6-g3qw-c7c4/GHSA-f9x6-g3qw-c7c4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9x6-g3qw-c7c4", + "modified": "2024-11-30T21:30:40Z", + "published": "2024-11-30T21:30:40Z", + "aliases": [ + "CVE-2024-53739" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cool Plugins Cryptocurrency Widgets For Elementor allows PHP Local File Inclusion.This issue affects Cryptocurrency Widgets For Elementor: from n/a through 1.6.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53739" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cryptocurrency-widgets-for-elementor/vulnerability/wordpress-cryptocurrency-widgets-for-elementor-plugin-1-6-4-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-30T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j46m-wrfx-rcw9/GHSA-j46m-wrfx-rcw9.json b/advisories/unreviewed/2024/11/GHSA-j46m-wrfx-rcw9/GHSA-j46m-wrfx-rcw9.json new file mode 100644 index 00000000000..374c752fbfe --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j46m-wrfx-rcw9/GHSA-j46m-wrfx-rcw9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j46m-wrfx-rcw9", + "modified": "2024-11-30T21:30:41Z", + "published": "2024-11-30T21:30:41Z", + "aliases": [ + "CVE-2024-53783" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Anzia Ni WooCommerce Cost Of Goods allows SQL Injection.This issue affects Ni WooCommerce Cost Of Goods: from n/a through 3.2.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53783" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ni-woocommerce-cost-of-goods/vulnerability/wordpress-ni-woocommerce-cost-of-goods-plugin-3-2-8-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-30T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jcwr-6h5w-hxfx/GHSA-jcwr-6h5w-hxfx.json b/advisories/unreviewed/2024/11/GHSA-jcwr-6h5w-hxfx/GHSA-jcwr-6h5w-hxfx.json new file mode 100644 index 00000000000..dce3167eae1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jcwr-6h5w-hxfx/GHSA-jcwr-6h5w-hxfx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcwr-6h5w-hxfx", + "modified": "2024-11-30T21:30:41Z", + "published": "2024-11-30T21:30:41Z", + "aliases": [ + "CVE-2024-53768" + ], + "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in IDE Interactive Content Audit Exporter allows Retrieve Embedded Sensitive Data.This issue affects Content Audit Exporter: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53768" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/content-audit-exporter/vulnerability/wordpress-content-audit-exporter-plugin-1-1-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-30T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-ph42-42qj-c8qg/GHSA-ph42-42qj-c8qg.json b/advisories/unreviewed/2024/11/GHSA-ph42-42qj-c8qg/GHSA-ph42-42qj-c8qg.json new file mode 100644 index 00000000000..8f7576b97bb --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-ph42-42qj-c8qg/GHSA-ph42-42qj-c8qg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ph42-42qj-c8qg", + "modified": "2024-11-30T21:30:40Z", + "published": "2024-11-30T21:30:40Z", + "aliases": [ + "CVE-2024-53738" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster allows Server Side Request Forgery.This issue affects Asset CleanUp: Page Speed Booster: from n/a through 1.3.9.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53738" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-asset-clean-up/vulnerability/wordpress-asset-cleanup-page-speed-booster-plugin-1-3-9-8-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-30T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qc9x-r48x-xr8p/GHSA-qc9x-r48x-xr8p.json b/advisories/unreviewed/2024/11/GHSA-qc9x-r48x-xr8p/GHSA-qc9x-r48x-xr8p.json new file mode 100644 index 00000000000..cce76021371 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qc9x-r48x-xr8p/GHSA-qc9x-r48x-xr8p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc9x-r48x-xr8p", + "modified": "2024-11-30T21:30:41Z", + "published": "2024-11-30T21:30:41Z", + "aliases": [ + "CVE-2024-53787" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vinoth06 Random Banner allows Stored XSS.This issue affects Random Banner: from n/a through 4.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53787" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/random-banner/vulnerability/wordpress-random-banner-plugin-4-2-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-30T21:15:16Z" + } +} \ No newline at end of file