From bd9949b47fa516c87cee9abcb238b8f4760311ec Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 17 Apr 2025 18:32:14 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-qhp6-vp7c-g7xp.json | 284 ++++++++++++++++++ .../GHSA-x46h-6fmr-m5fr.json | 9 +- .../GHSA-59hr-796q-5p86.json | 1 + .../GHSA-95hc-22p8-fq93.json | 1 + .../GHSA-gv89-2pc5-vf6w.json | 4 +- .../GHSA-2m95-fcm7-gqw8.json | 3 +- .../GHSA-4ch8-jgqc-v66p.json | 4 +- .../GHSA-83qv-39gp-8f27.json | 3 +- .../GHSA-f2wx-p9mh-gf54.json | 6 +- .../GHSA-hjmg-3wv2-r885.json | 4 +- .../GHSA-w785-44wh-9wr3.json | 2 +- .../GHSA-583f-56ww-9ppj.json | 5 +- .../GHSA-c7xv-h5wg-6fq8.json | 1 + .../GHSA-p6xg-jwp4-9fj2.json | 1 + .../GHSA-cw5r-qw3x-wgpf.json | 5 +- .../GHSA-j2p8-g7vg-2chp.json | 3 +- .../GHSA-4vhv-9xc2-4v6w.json | 2 +- .../GHSA-8h58-w45f-mg3g.json | 4 +- .../GHSA-ph8w-v57g-j3g7.json | 4 +- .../GHSA-h9hg-544v-fh29.json | 15 +- .../GHSA-23pm-fv72-xcr5.json | 36 +++ .../GHSA-23w5-m3rw-wr6g.json | 36 +++ .../GHSA-23w8-x79h-65g9.json | 36 +++ .../GHSA-2822-476f-3j55.json | 36 +++ .../GHSA-2838-j456-r5r4.json | 36 +++ .../GHSA-28w3-q8xh-2jcc.json | 36 +++ .../GHSA-2hx7-28ww-956p.json | 36 +++ .../GHSA-2mpc-pm7m-qc5v.json | 36 +++ .../GHSA-2pcj-9cp4-247j.json | 36 +++ .../GHSA-2pq8-4rf3-3vh9.json | 29 ++ .../GHSA-2x5p-mrxx-5gvq.json | 36 +++ .../GHSA-327p-65jj-8ccq.json | 36 +++ .../GHSA-33mx-vpmc-fg9c.json | 36 +++ .../GHSA-346m-8hrr-v52g.json | 36 +++ .../GHSA-35qr-4q99-cqm9.json | 36 +++ .../GHSA-3f43-pmrc-xpp4.json | 36 +++ .../GHSA-3g7r-m224-xg6p.json | 36 +++ .../GHSA-3mfx-f2pw-9cf2.json | 36 +++ .../GHSA-3rff-mqc6-jp26.json | 36 +++ .../GHSA-3vgp-c7mq-fcr4.json | 36 +++ .../GHSA-3w59-qgf8-pph5.json | 36 +++ .../GHSA-3xq6-2gcp-f92p.json | 36 +++ .../GHSA-3xvx-r844-4vvj.json | 36 +++ .../GHSA-3xwg-4q4p-g43c.json | 36 +++ .../GHSA-43mw-w97r-j4p7.json | 36 +++ .../GHSA-43r2-rv47-2g9m.json | 36 +++ .../GHSA-44wg-5mf9-mm82.json | 36 +++ .../GHSA-457j-x7h3-8hjh.json | 36 +++ .../GHSA-45vg-h4f5-372w.json | 36 +++ .../GHSA-48cj-3623-7h8r.json | 36 +++ .../GHSA-4c87-7rj9-cwg4.json | 36 +++ .../GHSA-4cgx-fwrr-q3j4.json | 36 +++ .../GHSA-4fvv-p7qg-xmc7.json | 36 +++ .../GHSA-4jxj-m8qc-7mcw.json | 4 +- .../GHSA-4r9m-hpcf-jwxq.json | 36 +++ .../GHSA-4w84-6c7g-5c25.json | 4 +- .../GHSA-4w8r-4268-4w28.json | 36 +++ .../GHSA-4wcc-xwq3-8v2h.json | 36 +++ .../GHSA-4xgc-vrx4-2fj6.json | 36 +++ .../GHSA-4xwm-8vcx-7p9c.json | 37 +++ .../GHSA-52v3-pgpf-rp65.json | 36 +++ .../GHSA-57fr-4g9f-6vcf.json | 36 +++ .../GHSA-57jv-3xgg-cj27.json | 36 +++ .../GHSA-58mc-qvmr-7m6v.json | 36 +++ .../GHSA-592j-gc76-g9p7.json | 36 +++ .../GHSA-5974-c6r6-2pv9.json | 53 ++++ .../GHSA-5j8q-6h5r-c979.json | 36 +++ .../GHSA-5p4c-wfcx-pf2f.json | 36 +++ .../GHSA-5r5c-h6fq-hpjr.json | 36 +++ .../GHSA-5x7h-mx43-qfvx.json | 33 ++ .../GHSA-5xm9-4j62-2v9q.json | 36 +++ .../GHSA-5xr3-gww4-9qh3.json | 36 +++ .../GHSA-6267-hp2v-vqcw.json | 36 +++ .../GHSA-629r-2h7x-932r.json | 36 +++ .../GHSA-62jf-72gx-f298.json | 36 +++ .../GHSA-6397-25xv-gv4g.json | 36 +++ .../GHSA-677p-h2hj-9j82.json | 45 +++ .../GHSA-6f77-vc9j-7p2g.json | 36 +++ .../GHSA-6gc5-f7hf-hq2m.json | 36 +++ .../GHSA-6hgj-wvmm-72rj.json | 36 +++ .../GHSA-6pw5-42xq-2vq5.json | 36 +++ .../GHSA-6rrc-vwrv-cwxc.json | 4 +- .../GHSA-6rxq-24mf-98w2.json | 36 +++ .../GHSA-6vhq-jvxm-jhq8.json | 36 +++ .../GHSA-6wpm-4j63-64j7.json | 36 +++ .../GHSA-763p-96hq-hgr8.json | 36 +++ .../GHSA-78xp-xvw2-6rw6.json | 53 ++++ .../GHSA-7frv-63r4-2q6x.json | 36 +++ .../GHSA-7hqv-35wh-6m2v.json | 36 +++ .../GHSA-7mhq-2mfc-44w3.json | 36 +++ .../GHSA-7pc3-w35j-gvgq.json | 36 +++ .../GHSA-7qgj-r27p-g6hh.json | 36 +++ .../GHSA-7wcr-h9xc-5cxf.json | 36 +++ .../GHSA-82p7-64v9-fpv5.json | 36 +++ .../GHSA-83xp-946q-c997.json | 36 +++ .../GHSA-848p-384j-r4fv.json | 33 ++ .../GHSA-8758-c79w-6mwv.json | 36 +++ .../GHSA-87x6-4q8j-cg2m.json | 36 +++ .../GHSA-885m-7fcx-5rgv.json | 36 +++ .../GHSA-889g-6x77-qwm5.json | 36 +++ .../GHSA-8fhj-jqr7-cjg5.json | 36 +++ .../GHSA-8fwr-8w6h-3h4j.json | 36 +++ .../GHSA-8r83-4p6h-h6g7.json | 36 +++ .../GHSA-8rpr-x32h-93fc.json | 36 +++ .../GHSA-8vqc-q2gr-rr26.json | 36 +++ .../GHSA-8wv8-94vj-jvwp.json | 36 +++ .../GHSA-94c7-44v5-85pg.json | 36 +++ .../GHSA-9694-rh9v-5hh5.json | 36 +++ .../GHSA-98mq-3898-9m6j.json | 36 +++ .../GHSA-9c2q-6mfx-w35r.json | 36 +++ .../GHSA-9c48-c4p8-m8r8.json | 36 +++ .../GHSA-9f6q-c4m9-v96r.json | 36 +++ .../GHSA-9fxc-x7g9-c8xv.json | 36 +++ .../GHSA-9gfq-fqg4-f89q.json | 4 +- .../GHSA-9gjv-779r-fr7m.json | 36 +++ .../GHSA-9hx7-77wc-prp2.json | 4 +- .../GHSA-9m8j-3p8x-49jr.json | 36 +++ .../GHSA-9mhf-v33v-gx4x.json | 36 +++ .../GHSA-9r63-r7rf-2xgc.json | 36 +++ .../GHSA-9rf5-4mxj-m43c.json | 36 +++ .../GHSA-9rfc-8v8w-5p2c.json | 36 +++ .../GHSA-9w55-w4w2-33x2.json | 36 +++ .../GHSA-c2q8-7637-6wgv.json | 36 +++ .../GHSA-c34v-3g56-gx43.json | 4 +- .../GHSA-c6pg-qxgx-74q7.json | 29 ++ .../GHSA-c83m-3729-3q38.json | 36 +++ .../GHSA-chgh-cvc6-48w4.json | 36 +++ .../GHSA-cjhq-hwgq-r969.json | 36 +++ .../GHSA-cqc2-rc24-647j.json | 40 +++ .../GHSA-cvj9-jcwj-rjvx.json | 36 +++ .../GHSA-cvpj-g8p4-c6hg.json | 36 +++ .../GHSA-cxj7-585w-jfq5.json | 36 +++ .../GHSA-f6fp-39qp-wq82.json | 36 +++ .../GHSA-fg6h-m78g-fqg5.json | 36 +++ .../GHSA-fgjq-m7rr-rv3f.json | 36 +++ .../GHSA-fgr8-gcxj-6pq5.json | 37 +++ .../GHSA-fhhc-qhh4-wq9v.json | 36 +++ .../GHSA-fp58-hrm7-m9p5.json | 36 +++ .../GHSA-frxg-m9hj-2jhv.json | 36 +++ .../GHSA-fvqp-m35r-x4xm.json | 36 +++ .../GHSA-fw3f-m6cp-wxg6.json | 36 +++ .../GHSA-fx2r-qpf4-38vc.json | 36 +++ .../GHSA-fxwh-c962-39r5.json | 36 +++ .../GHSA-g275-7gx9-r8ww.json | 36 +++ .../GHSA-g2gm-9v8p-3j59.json | 36 +++ .../GHSA-g2gp-63px-3c6r.json | 36 +++ .../GHSA-g36w-5vm4-qjjc.json | 36 +++ .../GHSA-g3pp-67rc-cjg2.json | 41 +++ .../GHSA-g3pr-333m-wf2c.json | 36 +++ .../GHSA-g57c-546q-327c.json | 36 +++ .../GHSA-g5fv-rhmh-mx2p.json | 36 +++ .../GHSA-g67h-7m25-7mmv.json | 37 +++ .../GHSA-g7gw-qjjj-h26r.json | 36 +++ .../GHSA-g8r8-g7qx-p4c7.json | 29 ++ .../GHSA-g95c-54h8-86cc.json | 36 +++ .../GHSA-g9ph-q425-qq92.json | 36 +++ .../GHSA-gh9p-r2h3-q5rr.json | 36 +++ .../GHSA-gm22-hqvw-7j52.json | 15 +- .../GHSA-gp2f-qm5p-8j9p.json | 36 +++ .../GHSA-gp3q-2c8h-jhrv.json | 36 +++ .../GHSA-gpqw-ppjw-678q.json | 36 +++ .../GHSA-gr2m-j2m7-6qm7.json | 36 +++ .../GHSA-h33h-9pwh-v2h4.json | 36 +++ .../GHSA-h4fr-qhv5-6jfq.json | 1 + .../GHSA-h66v-h338-mpfm.json | 36 +++ .../GHSA-h77h-8j9x-wmj8.json | 36 +++ .../GHSA-h8pp-6w7x-wjwx.json | 36 +++ .../GHSA-h8wr-2qx3-3r42.json | 36 +++ .../GHSA-hf2f-hm5p-pq8f.json | 36 +++ .../GHSA-hg4w-h686-f7p2.json | 36 +++ .../GHSA-hgpm-55ww-xj5v.json | 36 +++ .../GHSA-hjvx-hp9r-h988.json | 33 ++ .../GHSA-hm48-f7vp-c97r.json | 36 +++ .../GHSA-hmvw-rwmj-gphw.json | 36 +++ .../GHSA-hr94-jx6q-7pcg.json | 29 ++ .../GHSA-hvjh-q752-pqqp.json | 4 +- .../GHSA-hvqh-6vfx-vr57.json | 36 +++ .../GHSA-hw2f-h9gc-5p9j.json | 36 +++ .../GHSA-hwpp-cpx2-m8fm.json | 36 +++ .../GHSA-j5fc-rph7-5xhq.json | 36 +++ .../GHSA-j5q8-m85f-2332.json | 36 +++ .../GHSA-j7vc-h8gh-c57c.json | 36 +++ .../GHSA-j9xf-4c4g-rqx3.json | 36 +++ .../GHSA-jc9q-gp3w-hgwr.json | 36 +++ .../GHSA-jhgx-8qx6-x3gx.json | 36 +++ .../GHSA-jhp8-52c5-gjpr.json | 36 +++ .../GHSA-jwc2-228h-vcwr.json | 4 +- .../GHSA-jx24-hm29-p4xm.json | 36 +++ .../GHSA-jxpg-7f4x-g2fh.json | 36 +++ .../GHSA-m2v5-59cm-cc6q.json | 36 +++ .../GHSA-m348-vxx3-44qv.json | 36 +++ .../GHSA-m734-wmxm-5gcm.json | 36 +++ .../GHSA-m8pf-j4wj-g6rg.json | 36 +++ .../GHSA-m92c-q898-572x.json | 36 +++ .../GHSA-m9j6-927r-h9xm.json | 36 +++ .../GHSA-mfwj-jp8q-988q.json | 36 +++ .../GHSA-mjhh-qxpj-86jx.json | 36 +++ .../GHSA-mm4q-vxrq-237x.json | 36 +++ .../GHSA-mr3r-8239-vc75.json | 36 +++ .../GHSA-mrgc-7pv6-7gc9.json | 40 +++ .../GHSA-mxcr-c65g-v9gr.json | 36 +++ .../GHSA-p2qr-9r96-6m43.json | 36 +++ .../GHSA-p345-jmhp-7wg2.json | 11 +- .../GHSA-p35x-v2w9-c8gg.json | 36 +++ .../GHSA-p385-g496-fwgj.json | 36 +++ .../GHSA-p84q-ch5j-7frh.json | 29 ++ .../GHSA-pf4r-g63r-22v4.json | 36 +++ .../GHSA-pg7m-r4cf-qf65.json | 36 +++ .../GHSA-pr78-wj2j-7c98.json | 36 +++ .../GHSA-pw67-xjhq-389w.json | 41 +++ .../GHSA-pwjx-j45f-297x.json | 36 +++ .../GHSA-q3rm-mwv6-5cgw.json | 36 +++ .../GHSA-q4w9-wq5p-crrq.json | 36 +++ .../GHSA-q7ph-3vqh-ww9q.json | 36 +++ .../GHSA-q7rh-q727-h4mw.json | 36 +++ .../GHSA-q8hq-xhpc-vm95.json | 29 ++ .../GHSA-q926-pj8q-72f7.json | 36 +++ .../GHSA-qfxg-9wg2-4r2v.json | 36 +++ .../GHSA-qg7m-x7h8-fwj3.json | 36 +++ .../GHSA-qgj9-7q8h-gp49.json | 37 +++ .../GHSA-qhp6-vp7c-g7xp.json | 36 --- .../GHSA-qrcg-ch7v-h2pp.json | 36 +++ .../GHSA-qv7q-mmqf-j634.json | 36 +++ .../GHSA-qvww-5m45-9x54.json | 33 ++ .../GHSA-qw3m-c4wf-4832.json | 36 +++ .../GHSA-qxwh-j7j4-29g4.json | 36 +++ .../GHSA-r5xc-x759-88vq.json | 36 +++ .../GHSA-r75q-38f6-x3q4.json | 36 +++ .../GHSA-r966-h552-5m23.json | 36 +++ .../GHSA-r97x-rr73-8hq7.json | 36 +++ .../GHSA-r9mj-87fj-738h.json | 36 +++ .../GHSA-rfw7-86w9-7qh3.json | 36 +++ .../GHSA-rg9h-f5v4-xwfp.json | 33 ++ .../GHSA-rgfv-cmfv-jcmm.json | 36 +++ .../GHSA-rm3r-mw49-623x.json | 36 +++ .../GHSA-rqqc-5wmj-43vx.json | 36 +++ .../GHSA-rx8q-xg7h-mqpc.json | 36 +++ .../GHSA-rxcr-p59f-9j2p.json | 36 +++ .../GHSA-v5hr-3xch-9h65.json | 36 +++ .../GHSA-v6gv-mxw6-5v85.json | 36 +++ .../GHSA-v8vm-8h6v-g2gc.json | 33 ++ .../GHSA-vffm-x88v-8g8q.json | 36 +++ .../GHSA-vg2x-3jwm-cf33.json | 36 +++ .../GHSA-vj5m-95mx-p87m.json | 36 +++ .../GHSA-vjp9-wj82-f2jp.json | 36 +++ .../GHSA-vp5j-wh2p-73xx.json | 36 +++ .../GHSA-vpqx-hfvj-cf26.json | 36 +++ .../GHSA-vv26-66vw-jjwc.json | 36 +++ .../GHSA-vv78-wwrv-7mgx.json | 36 +++ .../GHSA-vx4g-5f82-hww5.json | 36 +++ .../GHSA-w33v-rv28-x6m6.json | 44 +++ .../GHSA-w4pq-45h8-g86g.json | 36 +++ .../GHSA-w8fw-fj9q-vcjj.json | 36 +++ .../GHSA-w8q3-52g7-3q2f.json | 36 +++ .../GHSA-wcgh-c8p6-5fwq.json | 36 +++ .../GHSA-wgr3-wff7-cf8m.json | 36 +++ .../GHSA-wh2m-mw53-r7px.json | 36 +++ .../GHSA-wjrq-hhc6-x6hr.json | 36 +++ .../GHSA-wp8g-3fhq-9g29.json | 36 +++ .../GHSA-wr7v-fhc6-8f6q.json | 36 +++ .../GHSA-ww79-gcmc-7fqx.json | 36 +++ .../GHSA-wwhc-9g9r-776m.json | 4 +- .../GHSA-wwj8-vw56-c53c.json | 36 +++ .../GHSA-x259-v4c5-x856.json | 36 +++ .../GHSA-x29x-qf6c-w9cj.json | 4 +- .../GHSA-x4f2-5v59-538p.json | 36 +++ .../GHSA-x7h2-q5j9-qrmx.json | 36 +++ .../GHSA-x86c-4rx9-m7gw.json | 36 +++ .../GHSA-x8pm-wrg2-mqmx.json | 42 +++ .../GHSA-xcq9-mmxv-cwpf.json | 36 +++ .../GHSA-xf4p-cv5q-7933.json | 36 +++ .../GHSA-xh69-9chv-wc4v.json | 36 +++ .../GHSA-xh89-595c-x982.json | 36 +++ .../GHSA-xhhf-2q9w-4g9h.json | 36 +++ .../GHSA-xhj8-26hf-x47j.json | 36 +++ .../GHSA-xjmf-cg3p-vmcm.json | 36 +++ .../GHSA-xm4m-v38w-7fr8.json | 36 +++ .../GHSA-xqx3-w575-cg29.json | 36 +++ .../GHSA-xr64-8582-gx8c.json | 36 +++ .../GHSA-xv93-h5pv-3mpg.json | 36 +++ .../GHSA-xvr7-xmmp-p9vr.json | 36 +++ .../GHSA-xwgw-2g3g-g3q8.json | 36 +++ .../GHSA-xxrf-fc9m-h444.json | 36 +++ .../GHSA-xxvv-rw24-p2j6.json | 36 +++ 284 files changed, 9408 insertions(+), 75 deletions(-) create mode 100644 advisories/github-reviewed/2025/04/GHSA-qhp6-vp7c-g7xp/GHSA-qhp6-vp7c-g7xp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-23pm-fv72-xcr5/GHSA-23pm-fv72-xcr5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-23w5-m3rw-wr6g/GHSA-23w5-m3rw-wr6g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-23w8-x79h-65g9/GHSA-23w8-x79h-65g9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2822-476f-3j55/GHSA-2822-476f-3j55.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2838-j456-r5r4/GHSA-2838-j456-r5r4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-28w3-q8xh-2jcc/GHSA-28w3-q8xh-2jcc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2hx7-28ww-956p/GHSA-2hx7-28ww-956p.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2mpc-pm7m-qc5v/GHSA-2mpc-pm7m-qc5v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2pcj-9cp4-247j/GHSA-2pcj-9cp4-247j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2pq8-4rf3-3vh9/GHSA-2pq8-4rf3-3vh9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2x5p-mrxx-5gvq/GHSA-2x5p-mrxx-5gvq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-327p-65jj-8ccq/GHSA-327p-65jj-8ccq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-33mx-vpmc-fg9c/GHSA-33mx-vpmc-fg9c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-346m-8hrr-v52g/GHSA-346m-8hrr-v52g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-35qr-4q99-cqm9/GHSA-35qr-4q99-cqm9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3f43-pmrc-xpp4/GHSA-3f43-pmrc-xpp4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3g7r-m224-xg6p/GHSA-3g7r-m224-xg6p.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3mfx-f2pw-9cf2/GHSA-3mfx-f2pw-9cf2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3rff-mqc6-jp26/GHSA-3rff-mqc6-jp26.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3vgp-c7mq-fcr4/GHSA-3vgp-c7mq-fcr4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3w59-qgf8-pph5/GHSA-3w59-qgf8-pph5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3xq6-2gcp-f92p/GHSA-3xq6-2gcp-f92p.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3xvx-r844-4vvj/GHSA-3xvx-r844-4vvj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3xwg-4q4p-g43c/GHSA-3xwg-4q4p-g43c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-43mw-w97r-j4p7/GHSA-43mw-w97r-j4p7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-43r2-rv47-2g9m/GHSA-43r2-rv47-2g9m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-44wg-5mf9-mm82/GHSA-44wg-5mf9-mm82.json create mode 100644 advisories/unreviewed/2025/04/GHSA-457j-x7h3-8hjh/GHSA-457j-x7h3-8hjh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-45vg-h4f5-372w/GHSA-45vg-h4f5-372w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-48cj-3623-7h8r/GHSA-48cj-3623-7h8r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4c87-7rj9-cwg4/GHSA-4c87-7rj9-cwg4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4cgx-fwrr-q3j4/GHSA-4cgx-fwrr-q3j4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4fvv-p7qg-xmc7/GHSA-4fvv-p7qg-xmc7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4r9m-hpcf-jwxq/GHSA-4r9m-hpcf-jwxq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4w8r-4268-4w28/GHSA-4w8r-4268-4w28.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4wcc-xwq3-8v2h/GHSA-4wcc-xwq3-8v2h.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4xgc-vrx4-2fj6/GHSA-4xgc-vrx4-2fj6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4xwm-8vcx-7p9c/GHSA-4xwm-8vcx-7p9c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-52v3-pgpf-rp65/GHSA-52v3-pgpf-rp65.json create mode 100644 advisories/unreviewed/2025/04/GHSA-57fr-4g9f-6vcf/GHSA-57fr-4g9f-6vcf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-57jv-3xgg-cj27/GHSA-57jv-3xgg-cj27.json create mode 100644 advisories/unreviewed/2025/04/GHSA-58mc-qvmr-7m6v/GHSA-58mc-qvmr-7m6v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-592j-gc76-g9p7/GHSA-592j-gc76-g9p7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5974-c6r6-2pv9/GHSA-5974-c6r6-2pv9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5j8q-6h5r-c979/GHSA-5j8q-6h5r-c979.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5p4c-wfcx-pf2f/GHSA-5p4c-wfcx-pf2f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5r5c-h6fq-hpjr/GHSA-5r5c-h6fq-hpjr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5x7h-mx43-qfvx/GHSA-5x7h-mx43-qfvx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5xm9-4j62-2v9q/GHSA-5xm9-4j62-2v9q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5xr3-gww4-9qh3/GHSA-5xr3-gww4-9qh3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6267-hp2v-vqcw/GHSA-6267-hp2v-vqcw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-629r-2h7x-932r/GHSA-629r-2h7x-932r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-62jf-72gx-f298/GHSA-62jf-72gx-f298.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6397-25xv-gv4g/GHSA-6397-25xv-gv4g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-677p-h2hj-9j82/GHSA-677p-h2hj-9j82.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6f77-vc9j-7p2g/GHSA-6f77-vc9j-7p2g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6gc5-f7hf-hq2m/GHSA-6gc5-f7hf-hq2m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6hgj-wvmm-72rj/GHSA-6hgj-wvmm-72rj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6pw5-42xq-2vq5/GHSA-6pw5-42xq-2vq5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6rxq-24mf-98w2/GHSA-6rxq-24mf-98w2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6vhq-jvxm-jhq8/GHSA-6vhq-jvxm-jhq8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6wpm-4j63-64j7/GHSA-6wpm-4j63-64j7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-763p-96hq-hgr8/GHSA-763p-96hq-hgr8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-78xp-xvw2-6rw6/GHSA-78xp-xvw2-6rw6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7frv-63r4-2q6x/GHSA-7frv-63r4-2q6x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7hqv-35wh-6m2v/GHSA-7hqv-35wh-6m2v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7mhq-2mfc-44w3/GHSA-7mhq-2mfc-44w3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7pc3-w35j-gvgq/GHSA-7pc3-w35j-gvgq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7qgj-r27p-g6hh/GHSA-7qgj-r27p-g6hh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7wcr-h9xc-5cxf/GHSA-7wcr-h9xc-5cxf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-82p7-64v9-fpv5/GHSA-82p7-64v9-fpv5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-83xp-946q-c997/GHSA-83xp-946q-c997.json create mode 100644 advisories/unreviewed/2025/04/GHSA-848p-384j-r4fv/GHSA-848p-384j-r4fv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8758-c79w-6mwv/GHSA-8758-c79w-6mwv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-87x6-4q8j-cg2m/GHSA-87x6-4q8j-cg2m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-885m-7fcx-5rgv/GHSA-885m-7fcx-5rgv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-889g-6x77-qwm5/GHSA-889g-6x77-qwm5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8fhj-jqr7-cjg5/GHSA-8fhj-jqr7-cjg5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8fwr-8w6h-3h4j/GHSA-8fwr-8w6h-3h4j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8r83-4p6h-h6g7/GHSA-8r83-4p6h-h6g7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8rpr-x32h-93fc/GHSA-8rpr-x32h-93fc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8vqc-q2gr-rr26/GHSA-8vqc-q2gr-rr26.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8wv8-94vj-jvwp/GHSA-8wv8-94vj-jvwp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-94c7-44v5-85pg/GHSA-94c7-44v5-85pg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9694-rh9v-5hh5/GHSA-9694-rh9v-5hh5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-98mq-3898-9m6j/GHSA-98mq-3898-9m6j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9c2q-6mfx-w35r/GHSA-9c2q-6mfx-w35r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9c48-c4p8-m8r8/GHSA-9c48-c4p8-m8r8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9f6q-c4m9-v96r/GHSA-9f6q-c4m9-v96r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9fxc-x7g9-c8xv/GHSA-9fxc-x7g9-c8xv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9gjv-779r-fr7m/GHSA-9gjv-779r-fr7m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9m8j-3p8x-49jr/GHSA-9m8j-3p8x-49jr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9mhf-v33v-gx4x/GHSA-9mhf-v33v-gx4x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9r63-r7rf-2xgc/GHSA-9r63-r7rf-2xgc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9rf5-4mxj-m43c/GHSA-9rf5-4mxj-m43c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9rfc-8v8w-5p2c/GHSA-9rfc-8v8w-5p2c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9w55-w4w2-33x2/GHSA-9w55-w4w2-33x2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c2q8-7637-6wgv/GHSA-c2q8-7637-6wgv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c6pg-qxgx-74q7/GHSA-c6pg-qxgx-74q7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c83m-3729-3q38/GHSA-c83m-3729-3q38.json create mode 100644 advisories/unreviewed/2025/04/GHSA-chgh-cvc6-48w4/GHSA-chgh-cvc6-48w4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cjhq-hwgq-r969/GHSA-cjhq-hwgq-r969.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cqc2-rc24-647j/GHSA-cqc2-rc24-647j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cvj9-jcwj-rjvx/GHSA-cvj9-jcwj-rjvx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cvpj-g8p4-c6hg/GHSA-cvpj-g8p4-c6hg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cxj7-585w-jfq5/GHSA-cxj7-585w-jfq5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f6fp-39qp-wq82/GHSA-f6fp-39qp-wq82.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fg6h-m78g-fqg5/GHSA-fg6h-m78g-fqg5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fgjq-m7rr-rv3f/GHSA-fgjq-m7rr-rv3f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fgr8-gcxj-6pq5/GHSA-fgr8-gcxj-6pq5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fhhc-qhh4-wq9v/GHSA-fhhc-qhh4-wq9v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fp58-hrm7-m9p5/GHSA-fp58-hrm7-m9p5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-frxg-m9hj-2jhv/GHSA-frxg-m9hj-2jhv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fvqp-m35r-x4xm/GHSA-fvqp-m35r-x4xm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fw3f-m6cp-wxg6/GHSA-fw3f-m6cp-wxg6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fx2r-qpf4-38vc/GHSA-fx2r-qpf4-38vc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fxwh-c962-39r5/GHSA-fxwh-c962-39r5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g275-7gx9-r8ww/GHSA-g275-7gx9-r8ww.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g2gm-9v8p-3j59/GHSA-g2gm-9v8p-3j59.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g2gp-63px-3c6r/GHSA-g2gp-63px-3c6r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g36w-5vm4-qjjc/GHSA-g36w-5vm4-qjjc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g3pp-67rc-cjg2/GHSA-g3pp-67rc-cjg2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g3pr-333m-wf2c/GHSA-g3pr-333m-wf2c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g57c-546q-327c/GHSA-g57c-546q-327c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g5fv-rhmh-mx2p/GHSA-g5fv-rhmh-mx2p.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g67h-7m25-7mmv/GHSA-g67h-7m25-7mmv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g7gw-qjjj-h26r/GHSA-g7gw-qjjj-h26r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g8r8-g7qx-p4c7/GHSA-g8r8-g7qx-p4c7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g95c-54h8-86cc/GHSA-g95c-54h8-86cc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g9ph-q425-qq92/GHSA-g9ph-q425-qq92.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gh9p-r2h3-q5rr/GHSA-gh9p-r2h3-q5rr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gp2f-qm5p-8j9p/GHSA-gp2f-qm5p-8j9p.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gp3q-2c8h-jhrv/GHSA-gp3q-2c8h-jhrv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gpqw-ppjw-678q/GHSA-gpqw-ppjw-678q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gr2m-j2m7-6qm7/GHSA-gr2m-j2m7-6qm7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h33h-9pwh-v2h4/GHSA-h33h-9pwh-v2h4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h66v-h338-mpfm/GHSA-h66v-h338-mpfm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h77h-8j9x-wmj8/GHSA-h77h-8j9x-wmj8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h8pp-6w7x-wjwx/GHSA-h8pp-6w7x-wjwx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h8wr-2qx3-3r42/GHSA-h8wr-2qx3-3r42.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hf2f-hm5p-pq8f/GHSA-hf2f-hm5p-pq8f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hg4w-h686-f7p2/GHSA-hg4w-h686-f7p2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hgpm-55ww-xj5v/GHSA-hgpm-55ww-xj5v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hjvx-hp9r-h988/GHSA-hjvx-hp9r-h988.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hm48-f7vp-c97r/GHSA-hm48-f7vp-c97r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hmvw-rwmj-gphw/GHSA-hmvw-rwmj-gphw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hr94-jx6q-7pcg/GHSA-hr94-jx6q-7pcg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hvqh-6vfx-vr57/GHSA-hvqh-6vfx-vr57.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hw2f-h9gc-5p9j/GHSA-hw2f-h9gc-5p9j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hwpp-cpx2-m8fm/GHSA-hwpp-cpx2-m8fm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j5fc-rph7-5xhq/GHSA-j5fc-rph7-5xhq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j5q8-m85f-2332/GHSA-j5q8-m85f-2332.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j7vc-h8gh-c57c/GHSA-j7vc-h8gh-c57c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j9xf-4c4g-rqx3/GHSA-j9xf-4c4g-rqx3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jc9q-gp3w-hgwr/GHSA-jc9q-gp3w-hgwr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jhgx-8qx6-x3gx/GHSA-jhgx-8qx6-x3gx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jhp8-52c5-gjpr/GHSA-jhp8-52c5-gjpr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jx24-hm29-p4xm/GHSA-jx24-hm29-p4xm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jxpg-7f4x-g2fh/GHSA-jxpg-7f4x-g2fh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m2v5-59cm-cc6q/GHSA-m2v5-59cm-cc6q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m348-vxx3-44qv/GHSA-m348-vxx3-44qv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m734-wmxm-5gcm/GHSA-m734-wmxm-5gcm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m8pf-j4wj-g6rg/GHSA-m8pf-j4wj-g6rg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m92c-q898-572x/GHSA-m92c-q898-572x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m9j6-927r-h9xm/GHSA-m9j6-927r-h9xm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mfwj-jp8q-988q/GHSA-mfwj-jp8q-988q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mjhh-qxpj-86jx/GHSA-mjhh-qxpj-86jx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mm4q-vxrq-237x/GHSA-mm4q-vxrq-237x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mr3r-8239-vc75/GHSA-mr3r-8239-vc75.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mrgc-7pv6-7gc9/GHSA-mrgc-7pv6-7gc9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mxcr-c65g-v9gr/GHSA-mxcr-c65g-v9gr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p2qr-9r96-6m43/GHSA-p2qr-9r96-6m43.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p35x-v2w9-c8gg/GHSA-p35x-v2w9-c8gg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p385-g496-fwgj/GHSA-p385-g496-fwgj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p84q-ch5j-7frh/GHSA-p84q-ch5j-7frh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pf4r-g63r-22v4/GHSA-pf4r-g63r-22v4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pg7m-r4cf-qf65/GHSA-pg7m-r4cf-qf65.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pr78-wj2j-7c98/GHSA-pr78-wj2j-7c98.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pw67-xjhq-389w/GHSA-pw67-xjhq-389w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pwjx-j45f-297x/GHSA-pwjx-j45f-297x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-q3rm-mwv6-5cgw/GHSA-q3rm-mwv6-5cgw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-q4w9-wq5p-crrq/GHSA-q4w9-wq5p-crrq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-q7ph-3vqh-ww9q/GHSA-q7ph-3vqh-ww9q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-q7rh-q727-h4mw/GHSA-q7rh-q727-h4mw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-q8hq-xhpc-vm95/GHSA-q8hq-xhpc-vm95.json create mode 100644 advisories/unreviewed/2025/04/GHSA-q926-pj8q-72f7/GHSA-q926-pj8q-72f7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qfxg-9wg2-4r2v/GHSA-qfxg-9wg2-4r2v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qg7m-x7h8-fwj3/GHSA-qg7m-x7h8-fwj3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qgj9-7q8h-gp49/GHSA-qgj9-7q8h-gp49.json delete mode 100644 advisories/unreviewed/2025/04/GHSA-qhp6-vp7c-g7xp/GHSA-qhp6-vp7c-g7xp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qrcg-ch7v-h2pp/GHSA-qrcg-ch7v-h2pp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qv7q-mmqf-j634/GHSA-qv7q-mmqf-j634.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qvww-5m45-9x54/GHSA-qvww-5m45-9x54.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qw3m-c4wf-4832/GHSA-qw3m-c4wf-4832.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qxwh-j7j4-29g4/GHSA-qxwh-j7j4-29g4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r5xc-x759-88vq/GHSA-r5xc-x759-88vq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r75q-38f6-x3q4/GHSA-r75q-38f6-x3q4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r966-h552-5m23/GHSA-r966-h552-5m23.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r97x-rr73-8hq7/GHSA-r97x-rr73-8hq7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r9mj-87fj-738h/GHSA-r9mj-87fj-738h.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rfw7-86w9-7qh3/GHSA-rfw7-86w9-7qh3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rg9h-f5v4-xwfp/GHSA-rg9h-f5v4-xwfp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rgfv-cmfv-jcmm/GHSA-rgfv-cmfv-jcmm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rm3r-mw49-623x/GHSA-rm3r-mw49-623x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rqqc-5wmj-43vx/GHSA-rqqc-5wmj-43vx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rx8q-xg7h-mqpc/GHSA-rx8q-xg7h-mqpc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rxcr-p59f-9j2p/GHSA-rxcr-p59f-9j2p.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v5hr-3xch-9h65/GHSA-v5hr-3xch-9h65.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v6gv-mxw6-5v85/GHSA-v6gv-mxw6-5v85.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v8vm-8h6v-g2gc/GHSA-v8vm-8h6v-g2gc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vffm-x88v-8g8q/GHSA-vffm-x88v-8g8q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vg2x-3jwm-cf33/GHSA-vg2x-3jwm-cf33.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vj5m-95mx-p87m/GHSA-vj5m-95mx-p87m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vjp9-wj82-f2jp/GHSA-vjp9-wj82-f2jp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vp5j-wh2p-73xx/GHSA-vp5j-wh2p-73xx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vpqx-hfvj-cf26/GHSA-vpqx-hfvj-cf26.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vv26-66vw-jjwc/GHSA-vv26-66vw-jjwc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vv78-wwrv-7mgx/GHSA-vv78-wwrv-7mgx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vx4g-5f82-hww5/GHSA-vx4g-5f82-hww5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-w33v-rv28-x6m6/GHSA-w33v-rv28-x6m6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-w4pq-45h8-g86g/GHSA-w4pq-45h8-g86g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-w8fw-fj9q-vcjj/GHSA-w8fw-fj9q-vcjj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-w8q3-52g7-3q2f/GHSA-w8q3-52g7-3q2f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wcgh-c8p6-5fwq/GHSA-wcgh-c8p6-5fwq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wgr3-wff7-cf8m/GHSA-wgr3-wff7-cf8m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wh2m-mw53-r7px/GHSA-wh2m-mw53-r7px.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wjrq-hhc6-x6hr/GHSA-wjrq-hhc6-x6hr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wp8g-3fhq-9g29/GHSA-wp8g-3fhq-9g29.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wr7v-fhc6-8f6q/GHSA-wr7v-fhc6-8f6q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ww79-gcmc-7fqx/GHSA-ww79-gcmc-7fqx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wwj8-vw56-c53c/GHSA-wwj8-vw56-c53c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x259-v4c5-x856/GHSA-x259-v4c5-x856.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x4f2-5v59-538p/GHSA-x4f2-5v59-538p.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x7h2-q5j9-qrmx/GHSA-x7h2-q5j9-qrmx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x86c-4rx9-m7gw/GHSA-x86c-4rx9-m7gw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x8pm-wrg2-mqmx/GHSA-x8pm-wrg2-mqmx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xcq9-mmxv-cwpf/GHSA-xcq9-mmxv-cwpf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xf4p-cv5q-7933/GHSA-xf4p-cv5q-7933.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xh69-9chv-wc4v/GHSA-xh69-9chv-wc4v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xh89-595c-x982/GHSA-xh89-595c-x982.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xhhf-2q9w-4g9h/GHSA-xhhf-2q9w-4g9h.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xhj8-26hf-x47j/GHSA-xhj8-26hf-x47j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xjmf-cg3p-vmcm/GHSA-xjmf-cg3p-vmcm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xm4m-v38w-7fr8/GHSA-xm4m-v38w-7fr8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xqx3-w575-cg29/GHSA-xqx3-w575-cg29.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xr64-8582-gx8c/GHSA-xr64-8582-gx8c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xv93-h5pv-3mpg/GHSA-xv93-h5pv-3mpg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xvr7-xmmp-p9vr/GHSA-xvr7-xmmp-p9vr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xwgw-2g3g-g3q8/GHSA-xwgw-2g3g-g3q8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xxrf-fc9m-h444/GHSA-xxrf-fc9m-h444.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xxvv-rw24-p2j6/GHSA-xxvv-rw24-p2j6.json diff --git a/advisories/github-reviewed/2025/04/GHSA-qhp6-vp7c-g7xp/GHSA-qhp6-vp7c-g7xp.json b/advisories/github-reviewed/2025/04/GHSA-qhp6-vp7c-g7xp/GHSA-qhp6-vp7c-g7xp.json new file mode 100644 index 00000000000..248b132dd64 --- /dev/null +++ b/advisories/github-reviewed/2025/04/GHSA-qhp6-vp7c-g7xp/GHSA-qhp6-vp7c-g7xp.json @@ -0,0 +1,284 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhp6-vp7c-g7xp", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T15:32:35Z", + "aliases": [ + "CVE-2025-3760" + ], + "summary": "Liferay Cross-site Scripting vulnerability", + "details": "A stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Liferay Portal 7.2.0 through 7.4.3.129, and Liferay DXP 2024.Q4.1 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, 7.3 GA through update 36, and 7.2 GA through fix pack 20 allows remote authenticated attackers to inject malicious JavaScript into a page.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.portal.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.2.0" + }, + { + "fixed": "7.4.3.132" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.2.10.fp1" + }, + { + "last_affected": "7.2.10.fp20" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.3.10.ep1" + }, + { + "last_affected": "7.3.10.u36" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.4.13.u1" + }, + { + "last_affected": "7.4.13.u92" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2023.Q3.1" + }, + { + "last_affected": "2023.Q3.10" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2023.Q4.0" + }, + { + "last_affected": "2023.Q4.10" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2024.Q1.1" + }, + { + "fixed": "2024.Q1.13" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 2024.Q1.12" + } + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2024.Q2.0" + }, + { + "last_affected": "2024.Q2.13" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2024.Q3.1" + }, + { + "fixed": "2024.Q3.10" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 2024.Q3.9" + } + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2024.Q4.1" + }, + { + "fixed": "2025.Q1.0" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 2024.Q4.7" + } + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.2.10" + }, + { + "last_affected": "7.2.10.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.3.10.0" + }, + { + "last_affected": "7.3.10.3" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "versions": [ + "7.4.13" + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3760" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-3760" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-04-17T18:31:14Z", + "nvd_published_at": "2025-04-17T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/01/GHSA-x46h-6fmr-m5fr/GHSA-x46h-6fmr-m5fr.json b/advisories/unreviewed/2022/01/GHSA-x46h-6fmr-m5fr/GHSA-x46h-6fmr-m5fr.json index 1a8b21483fa..8dc16bb6d8c 100644 --- a/advisories/unreviewed/2022/01/GHSA-x46h-6fmr-m5fr/GHSA-x46h-6fmr-m5fr.json +++ b/advisories/unreviewed/2022/01/GHSA-x46h-6fmr-m5fr/GHSA-x46h-6fmr-m5fr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x46h-6fmr-m5fr", - "modified": "2022-02-03T00:00:23Z", + "modified": "2025-04-17T18:31:00Z", "published": "2022-01-29T00:00:44Z", "aliases": [ "CVE-2021-26264" ], "details": "A specially crafted script could cause the DeltaV Distributed Control System Controllers (All Versions) to restart and cause a denial-of-service condition.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/04/GHSA-59hr-796q-5p86/GHSA-59hr-796q-5p86.json b/advisories/unreviewed/2022/04/GHSA-59hr-796q-5p86/GHSA-59hr-796q-5p86.json index 53b0bb0420f..ab929d211a2 100644 --- a/advisories/unreviewed/2022/04/GHSA-59hr-796q-5p86/GHSA-59hr-796q-5p86.json +++ b/advisories/unreviewed/2022/04/GHSA-59hr-796q-5p86/GHSA-59hr-796q-5p86.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-693", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/04/GHSA-95hc-22p8-fq93/GHSA-95hc-22p8-fq93.json b/advisories/unreviewed/2022/04/GHSA-95hc-22p8-fq93/GHSA-95hc-22p8-fq93.json index c21674773be..0346ef5e582 100644 --- a/advisories/unreviewed/2022/04/GHSA-95hc-22p8-fq93/GHSA-95hc-22p8-fq93.json +++ b/advisories/unreviewed/2022/04/GHSA-95hc-22p8-fq93/GHSA-95hc-22p8-fq93.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-707", "CWE-74" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/04/GHSA-gv89-2pc5-vf6w/GHSA-gv89-2pc5-vf6w.json b/advisories/unreviewed/2022/04/GHSA-gv89-2pc5-vf6w/GHSA-gv89-2pc5-vf6w.json index a5ef32795cc..41e939e30cd 100644 --- a/advisories/unreviewed/2022/04/GHSA-gv89-2pc5-vf6w/GHSA-gv89-2pc5-vf6w.json +++ b/advisories/unreviewed/2022/04/GHSA-gv89-2pc5-vf6w/GHSA-gv89-2pc5-vf6w.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/07/GHSA-2m95-fcm7-gqw8/GHSA-2m95-fcm7-gqw8.json b/advisories/unreviewed/2022/07/GHSA-2m95-fcm7-gqw8/GHSA-2m95-fcm7-gqw8.json index 8e819f03847..05684997e69 100644 --- a/advisories/unreviewed/2022/07/GHSA-2m95-fcm7-gqw8/GHSA-2m95-fcm7-gqw8.json +++ b/advisories/unreviewed/2022/07/GHSA-2m95-fcm7-gqw8/GHSA-2m95-fcm7-gqw8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2m95-fcm7-gqw8", - "modified": "2022-08-05T00:00:30Z", + "modified": "2025-04-17T18:31:01Z", "published": "2022-07-29T00:00:32Z", "aliases": [ "CVE-2021-22644" @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-321", "CWE-798" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/07/GHSA-4ch8-jgqc-v66p/GHSA-4ch8-jgqc-v66p.json b/advisories/unreviewed/2022/07/GHSA-4ch8-jgqc-v66p/GHSA-4ch8-jgqc-v66p.json index ce0b83226b3..480b11e2533 100644 --- a/advisories/unreviewed/2022/07/GHSA-4ch8-jgqc-v66p/GHSA-4ch8-jgqc-v66p.json +++ b/advisories/unreviewed/2022/07/GHSA-4ch8-jgqc-v66p/GHSA-4ch8-jgqc-v66p.json @@ -26,7 +26,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-307" + "CWE-294", + "CWE-307", + "CWE-522" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/07/GHSA-83qv-39gp-8f27/GHSA-83qv-39gp-8f27.json b/advisories/unreviewed/2022/07/GHSA-83qv-39gp-8f27/GHSA-83qv-39gp-8f27.json index b17b1fb704b..c4e55d2abd0 100644 --- a/advisories/unreviewed/2022/07/GHSA-83qv-39gp-8f27/GHSA-83qv-39gp-8f27.json +++ b/advisories/unreviewed/2022/07/GHSA-83qv-39gp-8f27/GHSA-83qv-39gp-8f27.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-22" + "CWE-22", + "CWE-23" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/07/GHSA-f2wx-p9mh-gf54/GHSA-f2wx-p9mh-gf54.json b/advisories/unreviewed/2022/07/GHSA-f2wx-p9mh-gf54/GHSA-f2wx-p9mh-gf54.json index ad72d459b4f..75ce7c07276 100644 --- a/advisories/unreviewed/2022/07/GHSA-f2wx-p9mh-gf54/GHSA-f2wx-p9mh-gf54.json +++ b/advisories/unreviewed/2022/07/GHSA-f2wx-p9mh-gf54/GHSA-f2wx-p9mh-gf54.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f2wx-p9mh-gf54", - "modified": "2022-08-05T00:00:30Z", + "modified": "2025-04-17T18:31:01Z", "published": "2022-07-29T00:00:32Z", "aliases": [ "CVE-2021-22646" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/07/GHSA-hjmg-3wv2-r885/GHSA-hjmg-3wv2-r885.json b/advisories/unreviewed/2022/07/GHSA-hjmg-3wv2-r885/GHSA-hjmg-3wv2-r885.json index 4d268270824..890c541817b 100644 --- a/advisories/unreviewed/2022/07/GHSA-hjmg-3wv2-r885/GHSA-hjmg-3wv2-r885.json +++ b/advisories/unreviewed/2022/07/GHSA-hjmg-3wv2-r885/GHSA-hjmg-3wv2-r885.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/07/GHSA-w785-44wh-9wr3/GHSA-w785-44wh-9wr3.json b/advisories/unreviewed/2022/07/GHSA-w785-44wh-9wr3/GHSA-w785-44wh-9wr3.json index 54100871f91..79b26c6932f 100644 --- a/advisories/unreviewed/2022/07/GHSA-w785-44wh-9wr3/GHSA-w785-44wh-9wr3.json +++ b/advisories/unreviewed/2022/07/GHSA-w785-44wh-9wr3/GHSA-w785-44wh-9wr3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w785-44wh-9wr3", - "modified": "2022-08-05T00:00:31Z", + "modified": "2025-04-17T18:31:01Z", "published": "2022-07-28T00:00:40Z", "aliases": [ "CVE-2021-38410" diff --git a/advisories/unreviewed/2022/10/GHSA-583f-56ww-9ppj/GHSA-583f-56ww-9ppj.json b/advisories/unreviewed/2022/10/GHSA-583f-56ww-9ppj/GHSA-583f-56ww-9ppj.json index 7c3b2b48990..0c5ebb9681f 100644 --- a/advisories/unreviewed/2022/10/GHSA-583f-56ww-9ppj/GHSA-583f-56ww-9ppj.json +++ b/advisories/unreviewed/2022/10/GHSA-583f-56ww-9ppj/GHSA-583f-56ww-9ppj.json @@ -25,7 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200", + "CWE-862" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-c7xv-h5wg-6fq8/GHSA-c7xv-h5wg-6fq8.json b/advisories/unreviewed/2022/10/GHSA-c7xv-h5wg-6fq8/GHSA-c7xv-h5wg-6fq8.json index c3012300115..05fe5c32804 100644 --- a/advisories/unreviewed/2022/10/GHSA-c7xv-h5wg-6fq8/GHSA-c7xv-h5wg-6fq8.json +++ b/advisories/unreviewed/2022/10/GHSA-c7xv-h5wg-6fq8/GHSA-c7xv-h5wg-6fq8.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-862" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/10/GHSA-p6xg-jwp4-9fj2/GHSA-p6xg-jwp4-9fj2.json b/advisories/unreviewed/2022/10/GHSA-p6xg-jwp4-9fj2/GHSA-p6xg-jwp4-9fj2.json index ccc49fc6caa..2440d4ecd57 100644 --- a/advisories/unreviewed/2022/10/GHSA-p6xg-jwp4-9fj2/GHSA-p6xg-jwp4-9fj2.json +++ b/advisories/unreviewed/2022/10/GHSA-p6xg-jwp4-9fj2/GHSA-p6xg-jwp4-9fj2.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-862" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/12/GHSA-cw5r-qw3x-wgpf/GHSA-cw5r-qw3x-wgpf.json b/advisories/unreviewed/2022/12/GHSA-cw5r-qw3x-wgpf/GHSA-cw5r-qw3x-wgpf.json index 816b4195426..9ca9c086d81 100644 --- a/advisories/unreviewed/2022/12/GHSA-cw5r-qw3x-wgpf/GHSA-cw5r-qw3x-wgpf.json +++ b/advisories/unreviewed/2022/12/GHSA-cw5r-qw3x-wgpf/GHSA-cw5r-qw3x-wgpf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cw5r-qw3x-wgpf", - "modified": "2022-12-27T21:30:21Z", + "modified": "2025-04-17T18:31:03Z", "published": "2022-12-20T00:30:29Z", "aliases": [ "CVE-2022-40434" @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-79" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-j2p8-g7vg-2chp/GHSA-j2p8-g7vg-2chp.json b/advisories/unreviewed/2022/12/GHSA-j2p8-g7vg-2chp/GHSA-j2p8-g7vg-2chp.json index 8fd40a338b8..541f9cbe5d9 100644 --- a/advisories/unreviewed/2022/12/GHSA-j2p8-g7vg-2chp/GHSA-j2p8-g7vg-2chp.json +++ b/advisories/unreviewed/2022/12/GHSA-j2p8-g7vg-2chp/GHSA-j2p8-g7vg-2chp.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-74" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-4vhv-9xc2-4v6w/GHSA-4vhv-9xc2-4v6w.json b/advisories/unreviewed/2023/07/GHSA-4vhv-9xc2-4v6w/GHSA-4vhv-9xc2-4v6w.json index d87176c6739..ee76d251633 100644 --- a/advisories/unreviewed/2023/07/GHSA-4vhv-9xc2-4v6w/GHSA-4vhv-9xc2-4v6w.json +++ b/advisories/unreviewed/2023/07/GHSA-4vhv-9xc2-4v6w/GHSA-4vhv-9xc2-4v6w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4vhv-9xc2-4v6w", - "modified": "2024-04-04T05:30:56Z", + "modified": "2025-04-17T18:31:03Z", "published": "2023-07-06T19:24:05Z", "aliases": [ "CVE-2022-47208" diff --git a/advisories/unreviewed/2024/01/GHSA-8h58-w45f-mg3g/GHSA-8h58-w45f-mg3g.json b/advisories/unreviewed/2024/01/GHSA-8h58-w45f-mg3g/GHSA-8h58-w45f-mg3g.json index 3c770d04e90..e9f8f725526 100644 --- a/advisories/unreviewed/2024/01/GHSA-8h58-w45f-mg3g/GHSA-8h58-w45f-mg3g.json +++ b/advisories/unreviewed/2024/01/GHSA-8h58-w45f-mg3g/GHSA-8h58-w45f-mg3g.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/01/GHSA-ph8w-v57g-j3g7/GHSA-ph8w-v57g-j3g7.json b/advisories/unreviewed/2024/01/GHSA-ph8w-v57g-j3g7/GHSA-ph8w-v57g-j3g7.json index ee19c62697b..aa48386417b 100644 --- a/advisories/unreviewed/2024/01/GHSA-ph8w-v57g-j3g7/GHSA-ph8w-v57g-j3g7.json +++ b/advisories/unreviewed/2024/01/GHSA-ph8w-v57g-j3g7/GHSA-ph8w-v57g-j3g7.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-ph8w-v57g-j3g7", - "modified": "2024-01-11T21:31:16Z", + "modified": "2025-04-17T18:31:03Z", "published": "2024-01-08T15:30:27Z", "aliases": [ "CVE-2023-6552" ], - "details": "Lack of \"current\" GET parameter validation during the action of changing a language leads to an open redirect vulnerability.\n", + "details": "Lack of \"current\" GET parameter validation during the action of changing a language leads to an open redirect vulnerability.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2025/02/GHSA-h9hg-544v-fh29/GHSA-h9hg-544v-fh29.json b/advisories/unreviewed/2025/02/GHSA-h9hg-544v-fh29/GHSA-h9hg-544v-fh29.json index 05feff701df..92167df5f51 100644 --- a/advisories/unreviewed/2025/02/GHSA-h9hg-544v-fh29/GHSA-h9hg-544v-fh29.json +++ b/advisories/unreviewed/2025/02/GHSA-h9hg-544v-fh29/GHSA-h9hg-544v-fh29.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h9hg-544v-fh29", - "modified": "2025-02-21T18:31:14Z", + "modified": "2025-04-17T18:31:10Z", "published": "2025-02-21T18:31:14Z", "aliases": [ "CVE-2025-26014" ], "details": "A Remote Code Execution (RCE) vulnerability in Loggrove v.1.0 allows a remote attacker to execute arbitrary code via the path parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-21T17:15:14Z" diff --git a/advisories/unreviewed/2025/04/GHSA-23pm-fv72-xcr5/GHSA-23pm-fv72-xcr5.json b/advisories/unreviewed/2025/04/GHSA-23pm-fv72-xcr5/GHSA-23pm-fv72-xcr5.json new file mode 100644 index 00000000000..3b317f9faa2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-23pm-fv72-xcr5/GHSA-23pm-fv72-xcr5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23pm-fv72-xcr5", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39434" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in Scott Taylor Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Avatar: from n/a through 0.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39434" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/avatar/vulnerability/wordpress-avatar-plugin-0-1-4-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-23w5-m3rw-wr6g/GHSA-23w5-m3rw-wr6g.json b/advisories/unreviewed/2025/04/GHSA-23w5-m3rw-wr6g/GHSA-23w5-m3rw-wr6g.json new file mode 100644 index 00000000000..7ea0fa432d9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-23w5-m3rw-wr6g/GHSA-23w5-m3rw-wr6g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23w5-m3rw-wr6g", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32583" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post allows Remote Code Inclusion. This issue affects PDF 2 Post: from n/a through 2.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32583" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pdf2post/vulnerability/wordpress-pdf-2-post-plugin-2-4-0-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-23w8-x79h-65g9/GHSA-23w8-x79h-65g9.json b/advisories/unreviewed/2025/04/GHSA-23w8-x79h-65g9/GHSA-23w8-x79h-65g9.json new file mode 100644 index 00000000000..a0b6ef8ace0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-23w8-x79h-65g9/GHSA-23w8-x79h-65g9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23w8-x79h-65g9", + "modified": "2025-04-17T18:31:13Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-23906" + ], + "details": "Missing Authorization vulnerability in wpseek WordPress Dashboard Tweeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WordPress Dashboard Tweeter: from n/a through 1.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23906" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wordpress-dashboard-twitter/vulnerability/wordpress-wordpress-dashboard-tweeter-plugin-1-3-2-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2822-476f-3j55/GHSA-2822-476f-3j55.json b/advisories/unreviewed/2025/04/GHSA-2822-476f-3j55/GHSA-2822-476f-3j55.json new file mode 100644 index 00000000000..a79a61f31d8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2822-476f-3j55/GHSA-2822-476f-3j55.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2822-476f-3j55", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32620" + ], + "details": "Missing Authorization vulnerability in fromdoppler Doppler Forms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Doppler Forms: from n/a through 2.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32620" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/doppler-form/vulnerability/wordpress-doppler-forms-plugin-2-4-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2838-j456-r5r4/GHSA-2838-j456-r5r4.json b/advisories/unreviewed/2025/04/GHSA-2838-j456-r5r4/GHSA-2838-j456-r5r4.json new file mode 100644 index 00000000000..91650fdb5ba --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2838-j456-r5r4/GHSA-2838-j456-r5r4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2838-j456-r5r4", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32634" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mdedev Run Contests, Raffles, and Giveaways with ContestsWP allows Reflected XSS. This issue affects Run Contests, Raffles, and Giveaways with ContestsWP: from n/a through 2.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32634" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/contest-code-checker/vulnerability/wordpress-run-contests-raffles-and-giveaways-plugin-2-0-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-28w3-q8xh-2jcc/GHSA-28w3-q8xh-2jcc.json b/advisories/unreviewed/2025/04/GHSA-28w3-q8xh-2jcc/GHSA-28w3-q8xh-2jcc.json new file mode 100644 index 00000000000..d0d57fd4e91 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-28w3-q8xh-2jcc/GHSA-28w3-q8xh-2jcc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28w3-q8xh-2jcc", + "modified": "2025-04-17T18:31:12Z", + "published": "2025-04-17T18:31:12Z", + "aliases": [ + "CVE-2025-22655" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Caio Web Dev CWD – Stealth Links allows SQL Injection. This issue affects CWD – Stealth Links: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22655" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cwd-stealth-links/vulnerability/wordpress-cwd-stealth-links-plugin-1-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2hx7-28ww-956p/GHSA-2hx7-28ww-956p.json b/advisories/unreviewed/2025/04/GHSA-2hx7-28ww-956p/GHSA-2hx7-28ww-956p.json new file mode 100644 index 00000000000..4b7930b1745 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2hx7-28ww-956p/GHSA-2hx7-28ww-956p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hx7-28ww-956p", + "modified": "2025-04-17T18:31:21Z", + "published": "2025-04-17T18:31:21Z", + "aliases": [ + "CVE-2025-39535" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in appsbd Vitepos allows Authentication Abuse. This issue affects Vitepos: from n/a through 3.1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39535" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/vitepos-lite/vulnerability/wordpress-vitepos-3-1-7-broken-authentication-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2mpc-pm7m-qc5v/GHSA-2mpc-pm7m-qc5v.json b/advisories/unreviewed/2025/04/GHSA-2mpc-pm7m-qc5v/GHSA-2mpc-pm7m-qc5v.json new file mode 100644 index 00000000000..0d067e0dcb7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2mpc-pm7m-qc5v/GHSA-2mpc-pm7m-qc5v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mpc-pm7m-qc5v", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32660" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in JoomSky JS Job Manager allows Upload a Web Shell to a Web Server. This issue affects JS Job Manager: from n/a through 2.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32660" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/js-jobs/vulnerability/wordpress-js-job-manager-plugin-2-0-2-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2pcj-9cp4-247j/GHSA-2pcj-9cp4-247j.json b/advisories/unreviewed/2025/04/GHSA-2pcj-9cp4-247j/GHSA-2pcj-9cp4-247j.json new file mode 100644 index 00000000000..a176b1b5510 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2pcj-9cp4-247j/GHSA-2pcj-9cp4-247j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pcj-9cp4-247j", + "modified": "2025-04-17T18:31:16Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32532" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pei Yong Goh UXsniff allows Reflected XSS. This issue affects UXsniff: from n/a through 1.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32532" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ux-sniff/vulnerability/wordpress-uxsniff-plugin-1-2-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2pq8-4rf3-3vh9/GHSA-2pq8-4rf3-3vh9.json b/advisories/unreviewed/2025/04/GHSA-2pq8-4rf3-3vh9/GHSA-2pq8-4rf3-3vh9.json new file mode 100644 index 00000000000..ef90c33dbe9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2pq8-4rf3-3vh9/GHSA-2pq8-4rf3-3vh9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pq8-4rf3-3vh9", + "modified": "2025-04-17T18:31:22Z", + "published": "2025-04-17T18:31:22Z", + "aliases": [ + "CVE-2025-29181" + ], + "details": "FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29181" + }, + { + "type": "WEB", + "url": "https://gist.github.com/X1lyS/2b3f936437fb7c04b4f1e4b07468fd05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2x5p-mrxx-5gvq/GHSA-2x5p-mrxx-5gvq.json b/advisories/unreviewed/2025/04/GHSA-2x5p-mrxx-5gvq/GHSA-2x5p-mrxx-5gvq.json new file mode 100644 index 00000000000..14f67916829 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2x5p-mrxx-5gvq/GHSA-2x5p-mrxx-5gvq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2x5p-mrxx-5gvq", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32590" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tzin111 Web2application allows Reflected XSS. This issue affects Web2application: from n/a through 5.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32590" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/web2application/vulnerability/wordpress-web2application-plugin-5-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-327p-65jj-8ccq/GHSA-327p-65jj-8ccq.json b/advisories/unreviewed/2025/04/GHSA-327p-65jj-8ccq/GHSA-327p-65jj-8ccq.json new file mode 100644 index 00000000000..559f2d76b5e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-327p-65jj-8ccq/GHSA-327p-65jj-8ccq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-327p-65jj-8ccq", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-32506" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BenDlz AT Internet SmartTag allows Reflected XSS. This issue affects AT Internet SmartTag: from n/a through 0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32506" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/at-internet/vulnerability/wordpress-at-internet-smarttag-plugin-0-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-33mx-vpmc-fg9c/GHSA-33mx-vpmc-fg9c.json b/advisories/unreviewed/2025/04/GHSA-33mx-vpmc-fg9c/GHSA-33mx-vpmc-fg9c.json new file mode 100644 index 00000000000..d65eb35af6a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-33mx-vpmc-fg9c/GHSA-33mx-vpmc-fg9c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33mx-vpmc-fg9c", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:19Z", + "aliases": [ + "CVE-2025-39423" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Jenst Add to Header allows Stored XSS. This issue affects Add to Header: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39423" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/add-to-header/vulnerability/wordpress-add-to-header-plugin-1-0-csrf-to-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-346m-8hrr-v52g/GHSA-346m-8hrr-v52g.json b/advisories/unreviewed/2025/04/GHSA-346m-8hrr-v52g/GHSA-346m-8hrr-v52g.json new file mode 100644 index 00000000000..89d0b939a41 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-346m-8hrr-v52g/GHSA-346m-8hrr-v52g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-346m-8hrr-v52g", + "modified": "2025-04-17T18:31:13Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-23782" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TotalSuite TotalContest Lite allows Reflected XSS. This issue affects TotalContest Lite: from n/a through 2.8.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23782" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/totalcontest-lite/vulnerability/wordpress-totalcontest-lite-plugin-2-8-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-35qr-4q99-cqm9/GHSA-35qr-4q99-cqm9.json b/advisories/unreviewed/2025/04/GHSA-35qr-4q99-cqm9/GHSA-35qr-4q99-cqm9.json new file mode 100644 index 00000000000..22d6f5ffb65 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-35qr-4q99-cqm9/GHSA-35qr-4q99-cqm9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35qr-4q99-cqm9", + "modified": "2025-04-17T18:31:21Z", + "published": "2025-04-17T18:31:21Z", + "aliases": [ + "CVE-2025-39559" + ], + "details": "Missing Authorization vulnerability in Eivin Landa Bring Fraktguiden for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bring Fraktguiden for WooCommerce: from n/a through 1.11.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39559" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bring-fraktguiden-for-woocommerce/vulnerability/wordpress-bring-fraktguiden-for-woocommerce-plugin-1-11-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3f43-pmrc-xpp4/GHSA-3f43-pmrc-xpp4.json b/advisories/unreviewed/2025/04/GHSA-3f43-pmrc-xpp4/GHSA-3f43-pmrc-xpp4.json new file mode 100644 index 00000000000..4590f886197 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3f43-pmrc-xpp4/GHSA-3f43-pmrc-xpp4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3f43-pmrc-xpp4", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32540" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in feedify Feedify – Web Push Notifications allows Reflected XSS. This issue affects Feedify – Web Push Notifications: from n/a through 2.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32540" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/push-notification-by-feedify/vulnerability/wordpress-feedify-web-push-notifications-plugin-2-4-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3g7r-m224-xg6p/GHSA-3g7r-m224-xg6p.json b/advisories/unreviewed/2025/04/GHSA-3g7r-m224-xg6p/GHSA-3g7r-m224-xg6p.json new file mode 100644 index 00000000000..f9196e85391 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3g7r-m224-xg6p/GHSA-3g7r-m224-xg6p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g7r-m224-xg6p", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32533" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matat Technologies Deliver via Shipos for WooCommerce allows Reflected XSS. This issue affects Deliver via Shipos for WooCommerce: from n/a through 2.1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32533" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wc-shipos-delivery/vulnerability/wordpress-deliver-via-shipos-for-woocommerce-plugin-2-1-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3mfx-f2pw-9cf2/GHSA-3mfx-f2pw-9cf2.json b/advisories/unreviewed/2025/04/GHSA-3mfx-f2pw-9cf2/GHSA-3mfx-f2pw-9cf2.json new file mode 100644 index 00000000000..d6873f14624 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3mfx-f2pw-9cf2/GHSA-3mfx-f2pw-9cf2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mfx-f2pw-9cf2", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:19Z", + "aliases": [ + "CVE-2025-39430" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Alexander Rauscha mLanguage allows Stored XSS. This issue affects mLanguage: from n/a through 1.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39430" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mlanguage/vulnerability/wordpress-mlanguage-plugin-1-6-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3rff-mqc6-jp26/GHSA-3rff-mqc6-jp26.json b/advisories/unreviewed/2025/04/GHSA-3rff-mqc6-jp26/GHSA-3rff-mqc6-jp26.json new file mode 100644 index 00000000000..bb78113b97d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3rff-mqc6-jp26/GHSA-3rff-mqc6-jp26.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rff-mqc6-jp26", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32606" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Deepak Khokhar Listings for Buildium allows Stored XSS. This issue affects Listings for Buildium: from n/a through 0.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32606" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/listings-for-buildium/vulnerability/wordpress-listings-for-buildium-plugin-0-1-4-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3vgp-c7mq-fcr4/GHSA-3vgp-c7mq-fcr4.json b/advisories/unreviewed/2025/04/GHSA-3vgp-c7mq-fcr4/GHSA-3vgp-c7mq-fcr4.json new file mode 100644 index 00000000000..ef1a0c4ff58 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3vgp-c7mq-fcr4/GHSA-3vgp-c7mq-fcr4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vgp-c7mq-fcr4", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:19Z", + "aliases": [ + "CVE-2025-39417" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Eslam Mahmoud Redirect wordpress to welcome or landing page allows Stored XSS. This issue affects Redirect wordpress to welcome or landing page: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39417" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/redirect-to-welcome-or-landing-page/vulnerability/wordpress-redirect-wordpress-to-welcome-or-landing-page-plugin-2-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3w59-qgf8-pph5/GHSA-3w59-qgf8-pph5.json b/advisories/unreviewed/2025/04/GHSA-3w59-qgf8-pph5/GHSA-3w59-qgf8-pph5.json new file mode 100644 index 00000000000..71e79d2a71f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3w59-qgf8-pph5/GHSA-3w59-qgf8-pph5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w59-qgf8-pph5", + "modified": "2025-04-17T18:31:13Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-23958" + ], + "details": "Missing Authorization vulnerability in FADI MED Editor Wysiwyg Background Color allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Editor Wysiwyg Background Color: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23958" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/editor-wysiwyg-background-color/vulnerability/wordpress-editor-wysiwyg-background-color-plugin-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3xq6-2gcp-f92p/GHSA-3xq6-2gcp-f92p.json b/advisories/unreviewed/2025/04/GHSA-3xq6-2gcp-f92p/GHSA-3xq6-2gcp-f92p.json new file mode 100644 index 00000000000..431c75dc626 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3xq6-2gcp-f92p/GHSA-3xq6-2gcp-f92p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xq6-2gcp-f92p", + "modified": "2025-04-17T18:31:12Z", + "published": "2025-04-17T18:31:12Z", + "aliases": [ + "CVE-2025-22796" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in platcom WP-Asambleas allows Reflected XSS. This issue affects WP-Asambleas: from n/a through 2.85.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22796" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-asambleas/vulnerability/wordpress-wp-asambleas-plugin-2-85-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3xvx-r844-4vvj/GHSA-3xvx-r844-4vvj.json b/advisories/unreviewed/2025/04/GHSA-3xvx-r844-4vvj/GHSA-3xvx-r844-4vvj.json new file mode 100644 index 00000000000..a7068608875 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3xvx-r844-4vvj/GHSA-3xvx-r844-4vvj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xvx-r844-4vvj", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:14Z", + "aliases": [ + "CVE-2025-27293" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webparexapp Shipmozo Courier Tracking allows Reflected XSS. This issue affects Shipmozo Courier Tracking: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27293" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/webparex/vulnerability/wordpress-shipmozo-courier-tracking-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3xwg-4q4p-g43c/GHSA-3xwg-4q4p-g43c.json b/advisories/unreviewed/2025/04/GHSA-3xwg-4q4p-g43c/GHSA-3xwg-4q4p-g43c.json new file mode 100644 index 00000000000..d3216609d9b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3xwg-4q4p-g43c/GHSA-3xwg-4q4p-g43c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xwg-4q4p-g43c", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32628" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Wham Crowdfunding for WooCommerce allows Reflected XSS. This issue affects Crowdfunding for WooCommerce: from n/a through 3.1.12.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32628" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/crowdfunding-for-woocommerce/vulnerability/wordpress-crowdfunding-for-woocommerce-plugin-3-1-12-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-43mw-w97r-j4p7/GHSA-43mw-w97r-j4p7.json b/advisories/unreviewed/2025/04/GHSA-43mw-w97r-j4p7/GHSA-43mw-w97r-j4p7.json new file mode 100644 index 00000000000..53d8266cd43 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-43mw-w97r-j4p7/GHSA-43mw-w97r-j4p7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43mw-w97r-j4p7", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32564" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tomroyal Stop Registration Spam allows Reflected XSS. This issue affects Stop Registration Spam: from n/a through 1.24.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32564" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/stop-registration-spam/vulnerability/wordpress-stop-registration-spam-plugin-1-24-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-43r2-rv47-2g9m/GHSA-43r2-rv47-2g9m.json b/advisories/unreviewed/2025/04/GHSA-43r2-rv47-2g9m/GHSA-43r2-rv47-2g9m.json new file mode 100644 index 00000000000..47fe3f47b6a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-43r2-rv47-2g9m/GHSA-43r2-rv47-2g9m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43r2-rv47-2g9m", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:14Z", + "aliases": [ + "CVE-2025-27292" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPyog WPYog Documents allows Reflected XSS. This issue affects WPYog Documents: from n/a through 1.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27292" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpyog-documents/vulnerability/wordpress-wpyog-documents-plugin-1-3-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-44wg-5mf9-mm82/GHSA-44wg-5mf9-mm82.json b/advisories/unreviewed/2025/04/GHSA-44wg-5mf9-mm82/GHSA-44wg-5mf9-mm82.json new file mode 100644 index 00000000000..34e7720f949 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-44wg-5mf9-mm82/GHSA-44wg-5mf9-mm82.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44wg-5mf9-mm82", + "modified": "2025-04-17T18:31:21Z", + "published": "2025-04-17T18:31:21Z", + "aliases": [ + "CVE-2025-39568" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Arture B.V. StoreContrl Woocommerce allows Path Traversal. This issue affects StoreContrl Woocommerce: from n/a through 4.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39568" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/storecontrl-wp-connection/vulnerability/wordpress-storecontrl-woocommerce-4-1-3-arbitrary-file-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-457j-x7h3-8hjh/GHSA-457j-x7h3-8hjh.json b/advisories/unreviewed/2025/04/GHSA-457j-x7h3-8hjh/GHSA-457j-x7h3-8hjh.json new file mode 100644 index 00000000000..fe763dca713 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-457j-x7h3-8hjh/GHSA-457j-x7h3-8hjh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-457j-x7h3-8hjh", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32653" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lee Blue Cart66 Cloud allows Reflected XSS. This issue affects Cart66 Cloud: from n/a through 2.3.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32653" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cart66-cloud/vulnerability/wordpress-cart66-cloud-plugin-2-3-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-45vg-h4f5-372w/GHSA-45vg-h4f5-372w.json b/advisories/unreviewed/2025/04/GHSA-45vg-h4f5-372w/GHSA-45vg-h4f5-372w.json new file mode 100644 index 00000000000..795b28dd06f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-45vg-h4f5-372w/GHSA-45vg-h4f5-372w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45vg-h4f5-372w", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32554" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Raptive Raptive Ads allows Reflected XSS. This issue affects Raptive Ads: from n/a through 3.7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32554" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/adthrive-ads/vulnerability/wordpress-raptive-ads-plugin-3-7-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-48cj-3623-7h8r/GHSA-48cj-3623-7h8r.json b/advisories/unreviewed/2025/04/GHSA-48cj-3623-7h8r/GHSA-48cj-3623-7h8r.json new file mode 100644 index 00000000000..bed8ca93399 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-48cj-3623-7h8r/GHSA-48cj-3623-7h8r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48cj-3623-7h8r", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39438" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in momen2009 Theme Changer allows Cross Site Request Forgery. This issue affects Theme Changer: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39438" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/theme-changer/vulnerability/wordpress-theme-changer-plugin-1-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4c87-7rj9-cwg4/GHSA-4c87-7rj9-cwg4.json b/advisories/unreviewed/2025/04/GHSA-4c87-7rj9-cwg4/GHSA-4c87-7rj9-cwg4.json new file mode 100644 index 00000000000..39e2f80a880 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4c87-7rj9-cwg4/GHSA-4c87-7rj9-cwg4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c87-7rj9-cwg4", + "modified": "2025-04-17T18:31:16Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32513" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in totalprocessing Nomupay Payment Processing Gateway allows Reflected XSS. This issue affects Nomupay Payment Processing Gateway: from n/a through 7.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32513" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/totalprocessing-card-payments/vulnerability/wordpress-total-processing-card-payments-for-woocommerce-plugin-7-1-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4cgx-fwrr-q3j4/GHSA-4cgx-fwrr-q3j4.json b/advisories/unreviewed/2025/04/GHSA-4cgx-fwrr-q3j4/GHSA-4cgx-fwrr-q3j4.json new file mode 100644 index 00000000000..d68fc32e3bd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4cgx-fwrr-q3j4/GHSA-4cgx-fwrr-q3j4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cgx-fwrr-q3j4", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:14Z", + "aliases": [ + "CVE-2025-27286" + ], + "details": "Deserialization of Untrusted Data vulnerability in saoshyant1994 Saoshyant Slider allows Object Injection. This issue affects Saoshyant Slider: from n/a through 3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27286" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/saoshyant-slider/vulnerability/wordpress-saoshyant-slider-plugin-3-0-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4fvv-p7qg-xmc7/GHSA-4fvv-p7qg-xmc7.json b/advisories/unreviewed/2025/04/GHSA-4fvv-p7qg-xmc7/GHSA-4fvv-p7qg-xmc7.json new file mode 100644 index 00000000000..13b6611d43e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4fvv-p7qg-xmc7/GHSA-4fvv-p7qg-xmc7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fvv-p7qg-xmc7", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32652" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in solacewp Solace Extra allows Using Malicious Files. This issue affects Solace Extra: from n/a through 1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32652" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/solace-extra/vulnerability/wordpress-solace-extra-plugin-1-3-1-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4jxj-m8qc-7mcw/GHSA-4jxj-m8qc-7mcw.json b/advisories/unreviewed/2025/04/GHSA-4jxj-m8qc-7mcw/GHSA-4jxj-m8qc-7mcw.json index 86207e975fc..059c1e9c41b 100644 --- a/advisories/unreviewed/2025/04/GHSA-4jxj-m8qc-7mcw/GHSA-4jxj-m8qc-7mcw.json +++ b/advisories/unreviewed/2025/04/GHSA-4jxj-m8qc-7mcw/GHSA-4jxj-m8qc-7mcw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-843" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-4r9m-hpcf-jwxq/GHSA-4r9m-hpcf-jwxq.json b/advisories/unreviewed/2025/04/GHSA-4r9m-hpcf-jwxq/GHSA-4r9m-hpcf-jwxq.json new file mode 100644 index 00000000000..00a209a6605 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4r9m-hpcf-jwxq/GHSA-4r9m-hpcf-jwxq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r9m-hpcf-jwxq", + "modified": "2025-04-17T18:31:21Z", + "published": "2025-04-17T18:31:21Z", + "aliases": [ + "CVE-2025-39594" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Arigato Autoresponder and Newsletter allows Reflected XSS. This issue affects Arigato Autoresponder and Newsletter: from n/a through 2.7.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39594" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bft-autoresponder/vulnerability/wordpress-arigato-autoresponder-and-newsletter-plugin-2-7-2-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4w84-6c7g-5c25/GHSA-4w84-6c7g-5c25.json b/advisories/unreviewed/2025/04/GHSA-4w84-6c7g-5c25/GHSA-4w84-6c7g-5c25.json index e938804cb91..dc5d08b21d3 100644 --- a/advisories/unreviewed/2025/04/GHSA-4w84-6c7g-5c25/GHSA-4w84-6c7g-5c25.json +++ b/advisories/unreviewed/2025/04/GHSA-4w84-6c7g-5c25/GHSA-4w84-6c7g-5c25.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-4w8r-4268-4w28/GHSA-4w8r-4268-4w28.json b/advisories/unreviewed/2025/04/GHSA-4w8r-4268-4w28/GHSA-4w8r-4268-4w28.json new file mode 100644 index 00000000000..21660a86446 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4w8r-4268-4w28/GHSA-4w8r-4268-4w28.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4w8r-4268-4w28", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32638" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weptile ShopApper allows Stored XSS. This issue affects ShopApper: from n/a through 0.4.39.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32638" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mobile-app-for-woocommerce/vulnerability/wordpress-shopapper-plugin-0-4-37-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4wcc-xwq3-8v2h/GHSA-4wcc-xwq3-8v2h.json b/advisories/unreviewed/2025/04/GHSA-4wcc-xwq3-8v2h/GHSA-4wcc-xwq3-8v2h.json new file mode 100644 index 00000000000..e0eaaed5c38 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4wcc-xwq3-8v2h/GHSA-4wcc-xwq3-8v2h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wcc-xwq3-8v2h", + "modified": "2025-04-17T18:31:21Z", + "published": "2025-04-17T18:31:21Z", + "aliases": [ + "CVE-2025-39551" + ], + "details": "Deserialization of Untrusted Data vulnerability in Mahmudul Hasan Arif FluentBoards allows Object Injection. This issue affects FluentBoards: from n/a through 1.47.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39551" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fluent-boards/vulnerability/wordpress-fluentboards-1-47-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4xgc-vrx4-2fj6/GHSA-4xgc-vrx4-2fj6.json b/advisories/unreviewed/2025/04/GHSA-4xgc-vrx4-2fj6/GHSA-4xgc-vrx4-2fj6.json new file mode 100644 index 00000000000..c0a88504cbd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4xgc-vrx4-2fj6/GHSA-4xgc-vrx4-2fj6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xgc-vrx4-2fj6", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32613" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Debug Log Manager allows Stored XSS. This issue affects Debug Log Manager: from n/a through 2.3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32613" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/debug-log-manager/vulnerability/wordpress-debug-log-manager-plugin-2-3-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4xwm-8vcx-7p9c/GHSA-4xwm-8vcx-7p9c.json b/advisories/unreviewed/2025/04/GHSA-4xwm-8vcx-7p9c/GHSA-4xwm-8vcx-7p9c.json new file mode 100644 index 00000000000..960d775731a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4xwm-8vcx-7p9c/GHSA-4xwm-8vcx-7p9c.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xwm-8vcx-7p9c", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-29042" + ], + "details": "An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the function 0x42232c", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29042" + }, + { + "type": "WEB", + "url": "https://gist.github.com/xyqer1/841e78a3c4029808dac8c439595a1358" + }, + { + "type": "WEB", + "url": "https://github.com/xyqer1/Dlink-dir-823x-set_prohibiting-macaddr-CommandInjection" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-52v3-pgpf-rp65/GHSA-52v3-pgpf-rp65.json b/advisories/unreviewed/2025/04/GHSA-52v3-pgpf-rp65/GHSA-52v3-pgpf-rp65.json new file mode 100644 index 00000000000..0d4cee81464 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-52v3-pgpf-rp65/GHSA-52v3-pgpf-rp65.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52v3-pgpf-rp65", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-27313" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bernd Altmeier Google Maps GPX Viewer allows Reflected XSS. This issue affects Google Maps GPX Viewer: from n/a through 3.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27313" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/google-maps-gpx-viewer/vulnerability/wordpress-google-maps-gpx-viewer-plugin-3-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-57fr-4g9f-6vcf/GHSA-57fr-4g9f-6vcf.json b/advisories/unreviewed/2025/04/GHSA-57fr-4g9f-6vcf/GHSA-57fr-4g9f-6vcf.json new file mode 100644 index 00000000000..39c36302bf9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-57fr-4g9f-6vcf/GHSA-57fr-4g9f-6vcf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57fr-4g9f-6vcf", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-31030" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jbhovik Ray Enterprise Translation allows PHP Local File Inclusion. This issue affects Ray Enterprise Translation: from n/a through 1.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31030" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lingotek-translation/vulnerability/wordpress-ray-enterprise-translation-1-7-0-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-57jv-3xgg-cj27/GHSA-57jv-3xgg-cj27.json b/advisories/unreviewed/2025/04/GHSA-57jv-3xgg-cj27/GHSA-57jv-3xgg-cj27.json new file mode 100644 index 00000000000..5904189d219 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-57jv-3xgg-cj27/GHSA-57jv-3xgg-cj27.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57jv-3xgg-cj27", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39441" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in swedish boy Dashboard Notepads allows Stored XSS. This issue affects Dashboard Notepads: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39441" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dashboard-notepads/vulnerability/wordpress-dashboard-notepads-plugin-1-2-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-58mc-qvmr-7m6v/GHSA-58mc-qvmr-7m6v.json b/advisories/unreviewed/2025/04/GHSA-58mc-qvmr-7m6v/GHSA-58mc-qvmr-7m6v.json new file mode 100644 index 00000000000..48b505f953e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-58mc-qvmr-7m6v/GHSA-58mc-qvmr-7m6v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58mc-qvmr-7m6v", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32605" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in expresstechsoftware MemberPress Discord Addon allows Reflected XSS. This issue affects MemberPress Discord Addon: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32605" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/expresstechsoftwares-memberpress-discord-add-on/vulnerability/wordpress-memberpress-discord-addon-plugin-1-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-592j-gc76-g9p7/GHSA-592j-gc76-g9p7.json b/advisories/unreviewed/2025/04/GHSA-592j-gc76-g9p7/GHSA-592j-gc76-g9p7.json new file mode 100644 index 00000000000..37c1fd1b3d8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-592j-gc76-g9p7/GHSA-592j-gc76-g9p7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-592j-gc76-g9p7", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:14Z", + "aliases": [ + "CVE-2025-24651" + ], + "details": "Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration allows Retrieve Embedded Sensitive Data. This issue affects WordPress Backup & Migration: from n/a through 1.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24651" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-migration-duplicator/vulnerability/wordpress-webtoffee-wp-backup-and-migration-plugin-1-5-3-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5974-c6r6-2pv9/GHSA-5974-c6r6-2pv9.json b/advisories/unreviewed/2025/04/GHSA-5974-c6r6-2pv9/GHSA-5974-c6r6-2pv9.json new file mode 100644 index 00000000000..f1d2b535995 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5974-c6r6-2pv9/GHSA-5974-c6r6-2pv9.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5974-c6r6-2pv9", + "modified": "2025-04-17T18:31:22Z", + "published": "2025-04-17T18:31:22Z", + "aliases": [ + "CVE-2020-36789" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context\n\nIf a driver calls can_get_echo_skb() during a hardware IRQ (which is often, but\nnot always, the case), the 'WARN_ON(in_irq)' in\nnet/core/skbuff.c#skb_release_head_state() might be triggered, under network\ncongestion circumstances, together with the potential risk of a NULL pointer\ndereference.\n\nThe root cause of this issue is the call to kfree_skb() instead of\ndev_kfree_skb_irq() in net/core/dev.c#enqueue_to_backlog().\n\nThis patch prevents the skb to be freed within the call to netif_rx() by\nincrementing its reference count with skb_get(). The skb is finally freed by\none of the in-irq-context safe functions: dev_consume_skb_any() or\ndev_kfree_skb_any(). The \"any\" version is used because some drivers might call\ncan_get_echo_skb() in a normal context.\n\nThe reason for this issue to occur is that initially, in the core network\nstack, loopback skb were not supposed to be received in hardware IRQ context.\nThe CAN stack is an exeption.\n\nThis bug was previously reported back in 2017 in [1] but the proposed patch\nnever got accepted.\n\nWhile [1] directly modifies net/core/dev.c, we try to propose here a\nsmoother modification local to CAN network stack (the assumption\nbehind is that only CAN devices are affected by this issue).\n\n[1] http://lore.kernel.org/r/57a3ffb6-3309-3ad5-5a34-e93c3fe3614d@cetitec.com", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-36789" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2283f79b22684d2812e5c76fc2280aae00390365" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/248b71ce92d4f3a574b2537f9838f48e892618f4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3a922a85701939624484e7f2fd07d32beed00d25" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/451187b20431924d13fcfecc500d7cd2d9951bac" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7e4cf2ec0ca236c3e5f904239cec6efe1f3baf22" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/87530b557affe01c764de32dbeb58cdf47234574" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ab46748bf98864f9c3f5559060bf8caf9df2b41e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5j8q-6h5r-c979/GHSA-5j8q-6h5r-c979.json b/advisories/unreviewed/2025/04/GHSA-5j8q-6h5r-c979/GHSA-5j8q-6h5r-c979.json new file mode 100644 index 00000000000..fce4355f316 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5j8q-6h5r-c979/GHSA-5j8q-6h5r-c979.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5j8q-6h5r-c979", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-31018" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FireDrum FireDrum Email Marketing allows Reflected XSS. This issue affects FireDrum Email Marketing: from n/a through 1.64.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31018" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/firedrum-email-marketing/vulnerability/wordpress-firedrum-email-marketing-plugin-1-64-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5p4c-wfcx-pf2f/GHSA-5p4c-wfcx-pf2f.json b/advisories/unreviewed/2025/04/GHSA-5p4c-wfcx-pf2f/GHSA-5p4c-wfcx-pf2f.json new file mode 100644 index 00000000000..1d015d405e0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5p4c-wfcx-pf2f/GHSA-5p4c-wfcx-pf2f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5p4c-wfcx-pf2f", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:19Z", + "aliases": [ + "CVE-2025-32682" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG Lite allows Upload a Web Shell to a Web Server. This issue affects MapSVG Lite: from n/a through 8.5.34.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32682" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mapsvg-lite-interactive-vector-maps/vulnerability/wordpress-mapsvg-lite-plugin-8-5-32-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5r5c-h6fq-hpjr/GHSA-5r5c-h6fq-hpjr.json b/advisories/unreviewed/2025/04/GHSA-5r5c-h6fq-hpjr/GHSA-5r5c-h6fq-hpjr.json new file mode 100644 index 00000000000..0d17d6ca334 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5r5c-h6fq-hpjr/GHSA-5r5c-h6fq-hpjr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r5c-h6fq-hpjr", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:14Z", + "aliases": [ + "CVE-2025-26968" + ], + "details": "Missing Authorization vulnerability in webbernaut Cloak Front End Email allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Cloak Front End Email: from n/a through 1.9.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26968" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cloak-front-end-email/vulnerability/wordpress-cloak-front-end-email-1-9-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5x7h-mx43-qfvx/GHSA-5x7h-mx43-qfvx.json b/advisories/unreviewed/2025/04/GHSA-5x7h-mx43-qfvx/GHSA-5x7h-mx43-qfvx.json new file mode 100644 index 00000000000..d9bd57d180b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5x7h-mx43-qfvx/GHSA-5x7h-mx43-qfvx.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5x7h-mx43-qfvx", + "modified": "2025-04-17T18:31:23Z", + "published": "2025-04-17T18:31:23Z", + "aliases": [ + "CVE-2025-25454" + ], + "details": "Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanSpeed2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25454" + }, + { + "type": "WEB", + "url": "https://gist.github.com/xyqer1/491bfd8b9b0868977dca66ab6ce238d2" + }, + { + "type": "WEB", + "url": "https://github.com/xyqer1/Tenda-AC10-AdvSetMacMtuWan-wanSpeed2-StackOverflow" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5xm9-4j62-2v9q/GHSA-5xm9-4j62-2v9q.json b/advisories/unreviewed/2025/04/GHSA-5xm9-4j62-2v9q/GHSA-5xm9-4j62-2v9q.json new file mode 100644 index 00000000000..792cbf7d821 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5xm9-4j62-2v9q/GHSA-5xm9-4j62-2v9q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xm9-4j62-2v9q", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-24624" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasTech HT Event allows Reflected XSS. This issue affects HT Event: from n/a through 1.4.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24624" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ht-event/vulnerability/wordpress-ht-event-wordpress-event-manager-plugin-for-elementor-plugin-1-4-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5xr3-gww4-9qh3/GHSA-5xr3-gww4-9qh3.json b/advisories/unreviewed/2025/04/GHSA-5xr3-gww4-9qh3/GHSA-5xr3-gww4-9qh3.json new file mode 100644 index 00000000000..833b9a5285b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5xr3-gww4-9qh3/GHSA-5xr3-gww4-9qh3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xr3-gww4-9qh3", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39519" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rtpHarry Bulk Page Stub Creator allows Reflected XSS. This issue affects Bulk Page Stub Creator: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39519" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bulk-page-stub-creator/vulnerability/wordpress-bulk-page-stub-creator-plugin-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6267-hp2v-vqcw/GHSA-6267-hp2v-vqcw.json b/advisories/unreviewed/2025/04/GHSA-6267-hp2v-vqcw/GHSA-6267-hp2v-vqcw.json new file mode 100644 index 00000000000..aa92a78d6c5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6267-hp2v-vqcw/GHSA-6267-hp2v-vqcw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6267-hp2v-vqcw", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:19Z", + "aliases": [ + "CVE-2025-39415" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Jayesh Parejiya Social Media Links allows Stored XSS. This issue affects Social Media Links: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39415" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/social-media-links/vulnerability/wordpress-social-media-links-plugin-1-0-3-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-629r-2h7x-932r/GHSA-629r-2h7x-932r.json b/advisories/unreviewed/2025/04/GHSA-629r-2h7x-932r/GHSA-629r-2h7x-932r.json new file mode 100644 index 00000000000..07e2d235470 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-629r-2h7x-932r/GHSA-629r-2h7x-932r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-629r-2h7x-932r", + "modified": "2025-04-17T18:31:13Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-24621" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes allows Reflected XSS. This issue affects Arconix Shortcodes: from n/a through 2.1.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24621" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/arconix-shortcodes/vulnerability/wordpress-arconix-shortcodes-plugin-2-1-15-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-62jf-72gx-f298/GHSA-62jf-72gx-f298.json b/advisories/unreviewed/2025/04/GHSA-62jf-72gx-f298/GHSA-62jf-72gx-f298.json new file mode 100644 index 00000000000..f2c8cc8257b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-62jf-72gx-f298/GHSA-62jf-72gx-f298.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62jf-72gx-f298", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39433" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in beke_ro Bknewsticker allows Stored XSS. This issue affects Bknewsticker: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39433" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bknewsticker/vulnerability/wordpress-bknewsticker-plugin-1-0-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6397-25xv-gv4g/GHSA-6397-25xv-gv4g.json b/advisories/unreviewed/2025/04/GHSA-6397-25xv-gv4g/GHSA-6397-25xv-gv4g.json new file mode 100644 index 00000000000..2c52eb52f63 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6397-25xv-gv4g/GHSA-6397-25xv-gv4g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6397-25xv-gv4g", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-32507" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aakif Kadiwala Event Espresso – Custom Email Template Shortcode allows Reflected XSS. This issue affects Event Espresso – Custom Email Template Shortcode: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32507" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/email-shortcode/vulnerability/wordpress-event-espresso-plugin-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-677p-h2hj-9j82/GHSA-677p-h2hj-9j82.json b/advisories/unreviewed/2025/04/GHSA-677p-h2hj-9j82/GHSA-677p-h2hj-9j82.json new file mode 100644 index 00000000000..fcfca0386e6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-677p-h2hj-9j82/GHSA-677p-h2hj-9j82.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-677p-h2hj-9j82", + "modified": "2025-04-17T18:31:23Z", + "published": "2025-04-17T18:31:22Z", + "aliases": [ + "CVE-2021-47669" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: vxcan: vxcan_xmit: fix use after free bug\n\nAfter calling netif_rx_ni(skb), dereferencing skb is unsafe.\nEspecially, the canfd_frame cfd which aliases skb memory is accessed\nafter the netif_rx_ni().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47669" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6d6dcf2399cdd26f7f5426ca8dd8366b7f2ca105" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/75854cad5d80976f6ea0f0431f8cedd3bcc475cb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9b820875a32a3443d67bfd368e93038354e98052" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a24476b37167816e6352ca1a2cf3769847774f70" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e771a874076115df8bff27d325edfd2340e4ec69" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6f77-vc9j-7p2g/GHSA-6f77-vc9j-7p2g.json b/advisories/unreviewed/2025/04/GHSA-6f77-vc9j-7p2g/GHSA-6f77-vc9j-7p2g.json new file mode 100644 index 00000000000..335286a13bb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6f77-vc9j-7p2g/GHSA-6f77-vc9j-7p2g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f77-vc9j-7p2g", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-27337" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kontur Fontsampler allows Reflected XSS. This issue affects Fontsampler: from n/a through 0.4.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27337" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fontsampler/vulnerability/wordpress-fontsampler-plugin-0-4-14-csrf-to-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6gc5-f7hf-hq2m/GHSA-6gc5-f7hf-hq2m.json b/advisories/unreviewed/2025/04/GHSA-6gc5-f7hf-hq2m/GHSA-6gc5-f7hf-hq2m.json new file mode 100644 index 00000000000..bbeaf0cdd22 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6gc5-f7hf-hq2m/GHSA-6gc5-f7hf-hq2m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gc5-f7hf-hq2m", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39442" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in MessageMetric Review Wave – Google Places Reviews allows Stored XSS. This issue affects Review Wave – Google Places Reviews: from n/a through 1.4.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39442" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/review-wave-google-places-reviews/vulnerability/wordpress-review-wave-google-places-reviews-plugin-1-4-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6hgj-wvmm-72rj/GHSA-6hgj-wvmm-72rj.json b/advisories/unreviewed/2025/04/GHSA-6hgj-wvmm-72rj/GHSA-6hgj-wvmm-72rj.json new file mode 100644 index 00000000000..2fb9dde6a50 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6hgj-wvmm-72rj/GHSA-6hgj-wvmm-72rj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hgj-wvmm-72rj", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:19Z", + "aliases": [ + "CVE-2025-39420" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ruudkok WP Twitter Button allows Stored XSS. This issue affects WP Twitter Button: from n/a through 1.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39420" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-twitter-button/vulnerability/wordpress-wp-twitter-button-plugin-1-4-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6pw5-42xq-2vq5/GHSA-6pw5-42xq-2vq5.json b/advisories/unreviewed/2025/04/GHSA-6pw5-42xq-2vq5/GHSA-6pw5-42xq-2vq5.json new file mode 100644 index 00000000000..84297907142 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6pw5-42xq-2vq5/GHSA-6pw5-42xq-2vq5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pw5-42xq-2vq5", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39461" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nawawi Jamili Docket Cache allows PHP Local File Inclusion. This issue affects Docket Cache: from n/a through 24.07.02.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39461" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/docket-cache/vulnerability/wordpress-docket-cache-plugin-24-07-02-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6rrc-vwrv-cwxc/GHSA-6rrc-vwrv-cwxc.json b/advisories/unreviewed/2025/04/GHSA-6rrc-vwrv-cwxc/GHSA-6rrc-vwrv-cwxc.json index cacfbdc02df..5e1eaf8bd6e 100644 --- a/advisories/unreviewed/2025/04/GHSA-6rrc-vwrv-cwxc/GHSA-6rrc-vwrv-cwxc.json +++ b/advisories/unreviewed/2025/04/GHSA-6rrc-vwrv-cwxc/GHSA-6rrc-vwrv-cwxc.json @@ -28,7 +28,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-362" + ], "severity": null, "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-6rxq-24mf-98w2/GHSA-6rxq-24mf-98w2.json b/advisories/unreviewed/2025/04/GHSA-6rxq-24mf-98w2/GHSA-6rxq-24mf-98w2.json new file mode 100644 index 00000000000..e0cfdb59974 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6rxq-24mf-98w2/GHSA-6rxq-24mf-98w2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rxq-24mf-98w2", + "modified": "2025-04-17T18:31:16Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32520" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M. Ali Saleem WordPress Health and Server Condition – Integrated with Google Page Speed allows Reflected XSS. This issue affects WordPress Health and Server Condition – Integrated with Google Page Speed: from n/a through 4.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32520" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-condition/vulnerability/wordpress-wordpress-health-and-server-condition-plugin-4-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6vhq-jvxm-jhq8/GHSA-6vhq-jvxm-jhq8.json b/advisories/unreviewed/2025/04/GHSA-6vhq-jvxm-jhq8/GHSA-6vhq-jvxm-jhq8.json new file mode 100644 index 00000000000..298bfb125ab --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6vhq-jvxm-jhq8/GHSA-6vhq-jvxm-jhq8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vhq-jvxm-jhq8", + "modified": "2025-04-17T18:31:13Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-24640" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan-Lucian Stefancu Empty Tags Remover allows Reflected XSS. This issue affects Empty Tags Remover: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24640" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/empty-tags-remover/vulnerability/wordpress-empty-tags-remover-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6wpm-4j63-64j7/GHSA-6wpm-4j63-64j7.json b/advisories/unreviewed/2025/04/GHSA-6wpm-4j63-64j7/GHSA-6wpm-4j63-64j7.json new file mode 100644 index 00000000000..e848d7c95e6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6wpm-4j63-64j7/GHSA-6wpm-4j63-64j7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wpm-4j63-64j7", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:19Z", + "aliases": [ + "CVE-2025-32686" + ], + "details": "Deserialization of Untrusted Data vulnerability in WP Speedo Team Members allows Object Injection. This issue affects Team Members: from n/a through 3.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32686" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wps-team/vulnerability/wordpress-team-members-3-4-0-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-763p-96hq-hgr8/GHSA-763p-96hq-hgr8.json b/advisories/unreviewed/2025/04/GHSA-763p-96hq-hgr8/GHSA-763p-96hq-hgr8.json new file mode 100644 index 00000000000..d4f98d8830e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-763p-96hq-hgr8/GHSA-763p-96hq-hgr8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-763p-96hq-hgr8", + "modified": "2025-04-17T18:31:13Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-24586" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bitsstech Shipment Tracker for Woocommerce allows Reflected XSS. This issue affects Shipment Tracker for Woocommerce: from n/a through 1.4.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24586" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/shipment-tracker-for-woocommerce/vulnerability/wordpress-shipment-tracker-for-woocommerce-plugin-1-4-23-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-78xp-xvw2-6rw6/GHSA-78xp-xvw2-6rw6.json b/advisories/unreviewed/2025/04/GHSA-78xp-xvw2-6rw6/GHSA-78xp-xvw2-6rw6.json new file mode 100644 index 00000000000..b7ef802d394 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-78xp-xvw2-6rw6/GHSA-78xp-xvw2-6rw6.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78xp-xvw2-6rw6", + "modified": "2025-04-17T18:31:22Z", + "published": "2025-04-17T18:31:22Z", + "aliases": [ + "CVE-2021-47668" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: dev: can_restart: fix use after free bug\n\nAfter calling netif_rx_ni(skb), dereferencing skb is unsafe.\nEspecially, the can_frame cf which aliases skb memory is accessed\nafter the netif_rx_ni() in:\n stats->rx_bytes += cf->len;\n\nReordering the lines solves the issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47668" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/03f16c5075b22c8902d2af739969e878b0879c94" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/08ab951787098ae0b6c0364aeea7a8138226f234" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/260925a0b7d2da5449f8ecfd02c1405e0c8a45b8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/593c072b7b3c4d7044416eb039d9ad706bedd67a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/92668d28c7e6a7a2ba07df287669ffcdf650c421" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ac48ef15826e83f4206c47add61072e8fc76d328" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bbc6847b9b8978b520f62fbc7c68c54ef0f8d282" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7frv-63r4-2q6x/GHSA-7frv-63r4-2q6x.json b/advisories/unreviewed/2025/04/GHSA-7frv-63r4-2q6x/GHSA-7frv-63r4-2q6x.json new file mode 100644 index 00000000000..73384c6d550 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7frv-63r4-2q6x/GHSA-7frv-63r4-2q6x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7frv-63r4-2q6x", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:19Z", + "aliases": [ + "CVE-2025-39428" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maros Pristas Gravity Forms CSS Themes with Fontawesome and Placeholders allows Stored XSS. This issue affects Gravity Forms CSS Themes with Fontawesome and Placeholders: from n/a through 8.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39428" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gravity-forms-css-themes-with-fontawesome-and-placeholder-support/vulnerability/wordpress-gravity-forms-css-themes-with-fontawesome-and-placeholders-plugin-8-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7hqv-35wh-6m2v/GHSA-7hqv-35wh-6m2v.json b/advisories/unreviewed/2025/04/GHSA-7hqv-35wh-6m2v/GHSA-7hqv-35wh-6m2v.json new file mode 100644 index 00000000000..87475518624 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7hqv-35wh-6m2v/GHSA-7hqv-35wh-6m2v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hqv-35wh-6m2v", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:14Z", + "aliases": [ + "CVE-2025-27288" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BjornW File Icons allows Reflected XSS. This issue affects File Icons: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27288" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/file-icons/vulnerability/wordpress-file-icons-plugin-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7mhq-2mfc-44w3/GHSA-7mhq-2mfc-44w3.json b/advisories/unreviewed/2025/04/GHSA-7mhq-2mfc-44w3/GHSA-7mhq-2mfc-44w3.json new file mode 100644 index 00000000000..83b119be1c7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7mhq-2mfc-44w3/GHSA-7mhq-2mfc-44w3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mhq-2mfc-44w3", + "modified": "2025-04-17T18:31:21Z", + "published": "2025-04-17T18:31:21Z", + "aliases": [ + "CVE-2025-39533" + ], + "details": "Missing Authorization vulnerability in Starfish Reviews Starfish Review Generation & Marketing allows Privilege Escalation. This issue affects Starfish Review Generation & Marketing: from n/a through 3.1.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39533" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/starfish-reviews/vulnerability/wordpress-starfish-review-generation-marketing-plugin-3-1-14-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7pc3-w35j-gvgq/GHSA-7pc3-w35j-gvgq.json b/advisories/unreviewed/2025/04/GHSA-7pc3-w35j-gvgq/GHSA-7pc3-w35j-gvgq.json new file mode 100644 index 00000000000..bfca11cc75d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7pc3-w35j-gvgq/GHSA-7pc3-w35j-gvgq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pc3-w35j-gvgq", + "modified": "2025-04-17T18:31:16Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32521" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CoolHappy Cool Flipbox – Shortcode & Gutenberg Block allows Reflected XSS. This issue affects Cool Flipbox – Shortcode & Gutenberg Block: from n/a through 1.8.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32521" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/flip-boxes/vulnerability/wordpress-cool-flipbox-plugin-1-8-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7qgj-r27p-g6hh/GHSA-7qgj-r27p-g6hh.json b/advisories/unreviewed/2025/04/GHSA-7qgj-r27p-g6hh/GHSA-7qgj-r27p-g6hh.json new file mode 100644 index 00000000000..871f855097d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7qgj-r27p-g6hh/GHSA-7qgj-r27p-g6hh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qgj-r27p-g6hh", + "modified": "2025-04-17T18:31:21Z", + "published": "2025-04-17T18:31:21Z", + "aliases": [ + "CVE-2025-39558" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks allows Reflected XSS. This issue affects CRM Perks: from n/a through 1.1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39558" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/support-x/vulnerability/wordpress-crm-perks-plugin-1-1-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7wcr-h9xc-5cxf/GHSA-7wcr-h9xc-5cxf.json b/advisories/unreviewed/2025/04/GHSA-7wcr-h9xc-5cxf/GHSA-7wcr-h9xc-5cxf.json new file mode 100644 index 00000000000..f6ecf235d43 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7wcr-h9xc-5cxf/GHSA-7wcr-h9xc-5cxf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wcr-h9xc-5cxf", + "modified": "2025-04-17T18:31:13Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-24539" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in debounce DeBounce Email Validator allows Reflected XSS. This issue affects DeBounce Email Validator: from n/a through 5.6.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24539" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/debounce-io-email-validator/vulnerability/wordpress-debounce-email-validator-plugin-5-6-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-82p7-64v9-fpv5/GHSA-82p7-64v9-fpv5.json b/advisories/unreviewed/2025/04/GHSA-82p7-64v9-fpv5/GHSA-82p7-64v9-fpv5.json new file mode 100644 index 00000000000..a3562dc1128 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-82p7-64v9-fpv5/GHSA-82p7-64v9-fpv5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82p7-64v9-fpv5", + "modified": "2025-04-17T18:31:21Z", + "published": "2025-04-17T18:31:21Z", + "aliases": [ + "CVE-2025-39542" + ], + "details": "Incorrect Privilege Assignment vulnerability in Jauhari Xelion Xelion Webchat allows Privilege Escalation. This issue affects Xelion Webchat: from n/a through 9.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39542" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/xelion-webchat/vulnerability/wordpress-xelion-webchat-9-1-0-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-83xp-946q-c997/GHSA-83xp-946q-c997.json b/advisories/unreviewed/2025/04/GHSA-83xp-946q-c997/GHSA-83xp-946q-c997.json new file mode 100644 index 00000000000..0d358791684 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-83xp-946q-c997/GHSA-83xp-946q-c997.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83xp-946q-c997", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:19Z", + "aliases": [ + "CVE-2025-39422" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in PResponsive WP Social Bookmarking allows Stored XSS. This issue affects WP Social Bookmarking: from n/a through 3.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39422" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-social-bookmarking/vulnerability/wordpress-wp-social-bookmarking-plugin-3-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-848p-384j-r4fv/GHSA-848p-384j-r4fv.json b/advisories/unreviewed/2025/04/GHSA-848p-384j-r4fv/GHSA-848p-384j-r4fv.json new file mode 100644 index 00000000000..75f2e39012d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-848p-384j-r4fv/GHSA-848p-384j-r4fv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-848p-384j-r4fv", + "modified": "2025-04-17T18:31:23Z", + "published": "2025-04-17T18:31:23Z", + "aliases": [ + "CVE-2025-29722" + ], + "details": "A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticated users. The issue exists due to missing CSRF protection on sensitive endpoints.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29722" + }, + { + "type": "WEB", + "url": "https://github.com/cypherdavy/CVE-2025-29722" + }, + { + "type": "WEB", + "url": "https://github.com/yassmittal/Commercify" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8758-c79w-6mwv/GHSA-8758-c79w-6mwv.json b/advisories/unreviewed/2025/04/GHSA-8758-c79w-6mwv/GHSA-8758-c79w-6mwv.json new file mode 100644 index 00000000000..c05c6a0396e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8758-c79w-6mwv/GHSA-8758-c79w-6mwv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8758-c79w-6mwv", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-27302" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Claudio Adrian Marrero CHATLIVE allows SQL Injection. This issue affects CHATLIVE: from n/a through 2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27302" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/chatlive/vulnerability/wordpress-chatlive-plugin-2-0-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-87x6-4q8j-cg2m/GHSA-87x6-4q8j-cg2m.json b/advisories/unreviewed/2025/04/GHSA-87x6-4q8j-cg2m/GHSA-87x6-4q8j-cg2m.json new file mode 100644 index 00000000000..2a9734f4964 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-87x6-4q8j-cg2m/GHSA-87x6-4q8j-cg2m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87x6-4q8j-cg2m", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:14Z", + "aliases": [ + "CVE-2025-27299" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Asia MyTicket Events allows Path Traversal. This issue affects MyTicket Events: from n/a through 1.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27299" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/myticket-events/vulnerability/wordpress-myticket-events-plugin-1-2-4-non-arbitrary-file-read-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-885m-7fcx-5rgv/GHSA-885m-7fcx-5rgv.json b/advisories/unreviewed/2025/04/GHSA-885m-7fcx-5rgv/GHSA-885m-7fcx-5rgv.json new file mode 100644 index 00000000000..9c2ed5354ac --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-885m-7fcx-5rgv/GHSA-885m-7fcx-5rgv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-885m-7fcx-5rgv", + "modified": "2025-04-17T18:31:21Z", + "published": "2025-04-17T18:31:21Z", + "aliases": [ + "CVE-2025-39596" + ], + "details": "Weak Authentication vulnerability in Quentn.com GmbH Quentn WP allows Privilege Escalation. This issue affects Quentn WP: from n/a through 1.2.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39596" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quentn-wp/vulnerability/wordpress-quentn-wp-1-2-8-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1390" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-889g-6x77-qwm5/GHSA-889g-6x77-qwm5.json b/advisories/unreviewed/2025/04/GHSA-889g-6x77-qwm5/GHSA-889g-6x77-qwm5.json new file mode 100644 index 00000000000..c91666df2e0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-889g-6x77-qwm5/GHSA-889g-6x77-qwm5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-889g-6x77-qwm5", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-27343" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webilop WooCommerce HTML5 Video allows Reflected XSS. This issue affects WooCommerce HTML5 Video: from n/a through 1.7.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27343" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-html5-video/vulnerability/wordpress-woocommerce-html5-video-plugin-1-7-10-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8fhj-jqr7-cjg5/GHSA-8fhj-jqr7-cjg5.json b/advisories/unreviewed/2025/04/GHSA-8fhj-jqr7-cjg5/GHSA-8fhj-jqr7-cjg5.json new file mode 100644 index 00000000000..49e0f57f67c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8fhj-jqr7-cjg5/GHSA-8fhj-jqr7-cjg5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fhj-jqr7-cjg5", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32622" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTP-less OTP-less one tap Sign in allows Reflected XSS. This issue affects OTP-less one tap Sign in: from n/a through 2.0.58.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32622" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/otpless/vulnerability/wordpress-otp-less-one-tap-sign-in-plugin-2-0-57-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8fwr-8w6h-3h4j/GHSA-8fwr-8w6h-3h4j.json b/advisories/unreviewed/2025/04/GHSA-8fwr-8w6h-3h4j/GHSA-8fwr-8w6h-3h4j.json new file mode 100644 index 00000000000..73c2b23fe9f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8fwr-8w6h-3h4j/GHSA-8fwr-8w6h-3h4j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fwr-8w6h-3h4j", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32647" + ], + "details": "Deserialization of Untrusted Data vulnerability in PickPlugins Question Answer allows Object Injection. This issue affects Question Answer: from n/a through 1.2.70.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32647" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/question-answer/vulnerability/wordpress-question-answer-plugin-1-2-70-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8r83-4p6h-h6g7/GHSA-8r83-4p6h-h6g7.json b/advisories/unreviewed/2025/04/GHSA-8r83-4p6h-h6g7/GHSA-8r83-4p6h-h6g7.json new file mode 100644 index 00000000000..dabb2ef2bee --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8r83-4p6h-h6g7/GHSA-8r83-4p6h-h6g7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r83-4p6h-h6g7", + "modified": "2025-04-17T18:31:16Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32512" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revampcrm Revamp CRM for WooCommerce allows Reflected XSS. This issue affects Revamp CRM for WooCommerce: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32512" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/revampcrm-woocommerce/vulnerability/wordpress-revamp-crm-for-woocommerce-plugin-1-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8rpr-x32h-93fc/GHSA-8rpr-x32h-93fc.json b/advisories/unreviewed/2025/04/GHSA-8rpr-x32h-93fc/GHSA-8rpr-x32h-93fc.json new file mode 100644 index 00000000000..c53c51f8779 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8rpr-x32h-93fc/GHSA-8rpr-x32h-93fc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rpr-x32h-93fc", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32561" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in plugins.club WP_DEBUG Toggle allows Reflected XSS. This issue affects WP_DEBUG Toggle: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32561" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/enable-wp-debug-toggle/vulnerability/wordpress-wp-debug-toggle-plugin-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8vqc-q2gr-rr26/GHSA-8vqc-q2gr-rr26.json b/advisories/unreviewed/2025/04/GHSA-8vqc-q2gr-rr26/GHSA-8vqc-q2gr-rr26.json new file mode 100644 index 00000000000..7227fd0a006 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8vqc-q2gr-rr26/GHSA-8vqc-q2gr-rr26.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vqc-q2gr-rr26", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:14Z", + "aliases": [ + "CVE-2025-27289" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Antoine Guillien Restrict Taxonomies allows Reflected XSS. This issue affects Restrict Taxonomies: from n/a through 1.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27289" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/restrict-taxonomies/vulnerability/wordpress-restrict-taxonomies-plugin-1-3-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8wv8-94vj-jvwp/GHSA-8wv8-94vj-jvwp.json b/advisories/unreviewed/2025/04/GHSA-8wv8-94vj-jvwp/GHSA-8wv8-94vj-jvwp.json new file mode 100644 index 00000000000..9cc710e41e9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8wv8-94vj-jvwp/GHSA-8wv8-94vj-jvwp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wv8-94vj-jvwp", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:14Z", + "aliases": [ + "CVE-2025-27291" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxgallery WordPress Photo Gallery – Image Gallery allows Reflected XSS. This issue affects WordPress Photo Gallery – Image Gallery: from n/a through 2.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27291" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/photo-image-gallery/vulnerability/wordpress-photo-gallery-image-gallery-plugin-2-0-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-94c7-44v5-85pg/GHSA-94c7-44v5-85pg.json b/advisories/unreviewed/2025/04/GHSA-94c7-44v5-85pg/GHSA-94c7-44v5-85pg.json new file mode 100644 index 00000000000..b032c4ccd20 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-94c7-44v5-85pg/GHSA-94c7-44v5-85pg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94c7-44v5-85pg", + "modified": "2025-04-17T18:31:16Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32504" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in silvasoft Silvasoft boekhouden allows Reflected XSS. This issue affects Silvasoft boekhouden: from n/a through 3.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32504" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/silvasoft-boekhouden/vulnerability/wordpress-silvasoft-boekhouden-plugin-3-0-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9694-rh9v-5hh5/GHSA-9694-rh9v-5hh5.json b/advisories/unreviewed/2025/04/GHSA-9694-rh9v-5hh5/GHSA-9694-rh9v-5hh5.json new file mode 100644 index 00000000000..a3deaffbd73 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9694-rh9v-5hh5/GHSA-9694-rh9v-5hh5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9694-rh9v-5hh5", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39452" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themewinter WPCafe allows PHP Local File Inclusion. This issue affects WPCafe: from n/a through 2.2.32.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39452" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-cafe/vulnerability/wordpress-wpcafe-plugin-2-2-32-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-98mq-3898-9m6j/GHSA-98mq-3898-9m6j.json b/advisories/unreviewed/2025/04/GHSA-98mq-3898-9m6j/GHSA-98mq-3898-9m6j.json new file mode 100644 index 00000000000..5fd5e35cc2b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-98mq-3898-9m6j/GHSA-98mq-3898-9m6j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98mq-3898-9m6j", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-24655" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Wishlist allows Reflected XSS. This issue affects Wishlist: from n/a through 1.0.39.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24655" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wishlist/vulnerability/wordpress-wishlist-plugin-1-0-39-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9c2q-6mfx-w35r/GHSA-9c2q-6mfx-w35r.json b/advisories/unreviewed/2025/04/GHSA-9c2q-6mfx-w35r/GHSA-9c2q-6mfx-w35r.json new file mode 100644 index 00000000000..a1ae230b92c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9c2q-6mfx-w35r/GHSA-9c2q-6mfx-w35r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9c2q-6mfx-w35r", + "modified": "2025-04-17T18:31:13Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-24583" + ], + "details": "Missing Authorization vulnerability in AA Web Servant 12 Step Meeting List allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects 12 Step Meeting List: from n/a through 3.16.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24583" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/12-step-meeting-list/vulnerability/wordpress-12-step-meeting-list-plugin-3-16-5-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9c48-c4p8-m8r8/GHSA-9c48-c4p8-m8r8.json b/advisories/unreviewed/2025/04/GHSA-9c48-c4p8-m8r8/GHSA-9c48-c4p8-m8r8.json new file mode 100644 index 00000000000..f96bfc0dd51 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9c48-c4p8-m8r8/GHSA-9c48-c4p8-m8r8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9c48-c4p8-m8r8", + "modified": "2025-04-17T18:31:12Z", + "published": "2025-04-17T18:31:12Z", + "aliases": [ + "CVE-2025-22692" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rachanaS Sponsered Link allows Reflected XSS. This issue affects Sponsered Link: from n/a through 4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22692" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sponsered-link/vulnerability/wordpress-sponsered-link-plugin-4-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9f6q-c4m9-v96r/GHSA-9f6q-c4m9-v96r.json b/advisories/unreviewed/2025/04/GHSA-9f6q-c4m9-v96r/GHSA-9f6q-c4m9-v96r.json new file mode 100644 index 00000000000..dd67074d820 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9f6q-c4m9-v96r/GHSA-9f6q-c4m9-v96r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f6q-c4m9-v96r", + "modified": "2025-04-17T18:31:13Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-24553" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Akadrama Shipping with Venipak for WooCommerce allows Reflected XSS. This issue affects Shipping with Venipak for WooCommerce: from n/a through 1.22.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24553" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wc-venipak-shipping/vulnerability/wordpress-shipping-with-venipak-for-woocommerce-plugin-1-22-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9fxc-x7g9-c8xv/GHSA-9fxc-x7g9-c8xv.json b/advisories/unreviewed/2025/04/GHSA-9fxc-x7g9-c8xv/GHSA-9fxc-x7g9-c8xv.json new file mode 100644 index 00000000000..9ea8fee8945 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9fxc-x7g9-c8xv/GHSA-9fxc-x7g9-c8xv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fxc-x7g9-c8xv", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32646" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Question Answer allows Reflected XSS. This issue affects Question Answer: from n/a through 1.2.70.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32646" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/question-answer/vulnerability/wordpress-question-answer-plugin-1-2-70-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9gfq-fqg4-f89q/GHSA-9gfq-fqg4-f89q.json b/advisories/unreviewed/2025/04/GHSA-9gfq-fqg4-f89q/GHSA-9gfq-fqg4-f89q.json index 13fcd037c75..c9b13698338 100644 --- a/advisories/unreviewed/2025/04/GHSA-9gfq-fqg4-f89q/GHSA-9gfq-fqg4-f89q.json +++ b/advisories/unreviewed/2025/04/GHSA-9gfq-fqg4-f89q/GHSA-9gfq-fqg4-f89q.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-290" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-9gjv-779r-fr7m/GHSA-9gjv-779r-fr7m.json b/advisories/unreviewed/2025/04/GHSA-9gjv-779r-fr7m/GHSA-9gjv-779r-fr7m.json new file mode 100644 index 00000000000..5168859d968 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9gjv-779r-fr7m/GHSA-9gjv-779r-fr7m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gjv-779r-fr7m", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32548" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in borisolhor Hamburger Icon Menu Lite allows Reflected XSS. This issue affects Hamburger Icon Menu Lite: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32548" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hamburger-icon-menu-lite/vulnerability/wordpress-hamburger-icon-menu-lite-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9hx7-77wc-prp2/GHSA-9hx7-77wc-prp2.json b/advisories/unreviewed/2025/04/GHSA-9hx7-77wc-prp2/GHSA-9hx7-77wc-prp2.json index e2cf6e348c2..f6d731179f0 100644 --- a/advisories/unreviewed/2025/04/GHSA-9hx7-77wc-prp2/GHSA-9hx7-77wc-prp2.json +++ b/advisories/unreviewed/2025/04/GHSA-9hx7-77wc-prp2/GHSA-9hx7-77wc-prp2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-9m8j-3p8x-49jr/GHSA-9m8j-3p8x-49jr.json b/advisories/unreviewed/2025/04/GHSA-9m8j-3p8x-49jr/GHSA-9m8j-3p8x-49jr.json new file mode 100644 index 00000000000..5e7963a99d3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9m8j-3p8x-49jr/GHSA-9m8j-3p8x-49jr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m8j-3p8x-49jr", + "modified": "2025-04-17T18:31:16Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32527" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pey22 T&P Gallery Slider allows Stored XSS. This issue affects T&P Gallery Slider: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32527" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tp-gallery-slider/vulnerability/wordpress-t-p-gallery-slider-plugin-1-2-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9mhf-v33v-gx4x/GHSA-9mhf-v33v-gx4x.json b/advisories/unreviewed/2025/04/GHSA-9mhf-v33v-gx4x/GHSA-9mhf-v33v-gx4x.json new file mode 100644 index 00000000000..f106100566e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9mhf-v33v-gx4x/GHSA-9mhf-v33v-gx4x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mhf-v33v-gx4x", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39455" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ip2location IP2Location Variables allows Reflected XSS. This issue affects IP2Location Variables: from n/a through 2.9.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39455" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ip2location-variables/vulnerability/wordpress-ip2location-variables-plugin-2-9-5-csrf-to-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9r63-r7rf-2xgc/GHSA-9r63-r7rf-2xgc.json b/advisories/unreviewed/2025/04/GHSA-9r63-r7rf-2xgc/GHSA-9r63-r7rf-2xgc.json new file mode 100644 index 00000000000..a038750f57f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9r63-r7rf-2xgc/GHSA-9r63-r7rf-2xgc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r63-r7rf-2xgc", + "modified": "2025-04-17T18:31:16Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32516" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ilGhera Related Videos for JW Player allows Reflected XSS. This issue affects Related Videos for JW Player: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32516" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/related-videos-for-jw-player/vulnerability/wordpress-related-videos-for-jw-player-plugin-1-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9rf5-4mxj-m43c/GHSA-9rf5-4mxj-m43c.json b/advisories/unreviewed/2025/04/GHSA-9rf5-4mxj-m43c/GHSA-9rf5-4mxj-m43c.json new file mode 100644 index 00000000000..448cd3dd775 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9rf5-4mxj-m43c/GHSA-9rf5-4mxj-m43c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rf5-4mxj-m43c", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-27346" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gerrygooner Rebuild Permalinks allows Reflected XSS. This issue affects Rebuild Permalinks: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27346" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rebuild-permalinks/vulnerability/wordpress-rebuild-permalinks-plugin-1-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9rfc-8v8w-5p2c/GHSA-9rfc-8v8w-5p2c.json b/advisories/unreviewed/2025/04/GHSA-9rfc-8v8w-5p2c/GHSA-9rfc-8v8w-5p2c.json new file mode 100644 index 00000000000..09079cec90b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9rfc-8v8w-5p2c/GHSA-9rfc-8v8w-5p2c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rfc-8v8w-5p2c", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32666" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hive Support Hive Support allows Reflected XSS. This issue affects Hive Support: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32666" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hive-support/vulnerability/wordpress-hive-support-plugin-1-2-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9w55-w4w2-33x2/GHSA-9w55-w4w2-33x2.json b/advisories/unreviewed/2025/04/GHSA-9w55-w4w2-33x2/GHSA-9w55-w4w2-33x2.json new file mode 100644 index 00000000000..03fe05025f7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9w55-w4w2-33x2/GHSA-9w55-w4w2-33x2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9w55-w4w2-33x2", + "modified": "2025-04-17T18:31:16Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32535" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digireturn DN Shipping by Weight for WooCommerce allows Reflected XSS. This issue affects DN Shipping by Weight for WooCommerce: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32535" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dn-shipping-by-weight/vulnerability/wordpress-dn-shipping-by-weight-for-woocommerce-plugin-1-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c2q8-7637-6wgv/GHSA-c2q8-7637-6wgv.json b/advisories/unreviewed/2025/04/GHSA-c2q8-7637-6wgv/GHSA-c2q8-7637-6wgv.json new file mode 100644 index 00000000000..fec135915a0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c2q8-7637-6wgv/GHSA-c2q8-7637-6wgv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2q8-7637-6wgv", + "modified": "2025-04-17T18:31:21Z", + "published": "2025-04-17T18:31:21Z", + "aliases": [ + "CVE-2025-39588" + ], + "details": "Deserialization of Untrusted Data vulnerability in bdthemes Ultimate Store Kit Elementor Addons allows Object Injection. This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39588" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-store-kit/vulnerability/wordpress-ultimate-store-kit-elementor-addons-2-4-0-deserialization-of-untrusted-data-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c34v-3g56-gx43/GHSA-c34v-3g56-gx43.json b/advisories/unreviewed/2025/04/GHSA-c34v-3g56-gx43/GHSA-c34v-3g56-gx43.json index eba7f9e4606..94f63116ade 100644 --- a/advisories/unreviewed/2025/04/GHSA-c34v-3g56-gx43/GHSA-c34v-3g56-gx43.json +++ b/advisories/unreviewed/2025/04/GHSA-c34v-3g56-gx43/GHSA-c34v-3g56-gx43.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-306" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-c6pg-qxgx-74q7/GHSA-c6pg-qxgx-74q7.json b/advisories/unreviewed/2025/04/GHSA-c6pg-qxgx-74q7/GHSA-c6pg-qxgx-74q7.json new file mode 100644 index 00000000000..f18da9a71c7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c6pg-qxgx-74q7/GHSA-c6pg-qxgx-74q7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6pg-qxgx-74q7", + "modified": "2025-04-17T18:31:22Z", + "published": "2025-04-17T18:31:22Z", + "aliases": [ + "CVE-2025-29662" + ], + "details": "A RCE vulnerability in the core application in LandChat 3.25.12.18 allows an unauthenticated attacker to execute system code via remote network access.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29662" + }, + { + "type": "WEB", + "url": "https://github.com/landchat/LandChat/issues/5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c83m-3729-3q38/GHSA-c83m-3729-3q38.json b/advisories/unreviewed/2025/04/GHSA-c83m-3729-3q38/GHSA-c83m-3729-3q38.json new file mode 100644 index 00000000000..6b6ebf48260 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c83m-3729-3q38/GHSA-c83m-3729-3q38.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c83m-3729-3q38", + "modified": "2025-04-17T18:31:16Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32530" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Swings Wallet System for WooCommerce allows Reflected XSS. This issue affects Wallet System for WooCommerce: from n/a through 2.6.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32530" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wallet-system-for-woocommerce/vulnerability/wordpress-wallet-system-for-woocommerce-plugin-2-6-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-chgh-cvc6-48w4/GHSA-chgh-cvc6-48w4.json b/advisories/unreviewed/2025/04/GHSA-chgh-cvc6-48w4/GHSA-chgh-cvc6-48w4.json new file mode 100644 index 00000000000..7163ade04df --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-chgh-cvc6-48w4/GHSA-chgh-cvc6-48w4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chgh-cvc6-48w4", + "modified": "2025-04-17T18:31:21Z", + "published": "2025-04-17T18:31:21Z", + "aliases": [ + "CVE-2025-39587" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix Cost Calculator Builder allows SQL Injection. This issue affects Cost Calculator Builder: from n/a through 3.2.65.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39587" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cost-calculator-builder/vulnerability/wordpress-cost-calculator-builder-3-2-65-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cjhq-hwgq-r969/GHSA-cjhq-hwgq-r969.json b/advisories/unreviewed/2025/04/GHSA-cjhq-hwgq-r969/GHSA-cjhq-hwgq-r969.json new file mode 100644 index 00000000000..ff53c5bcb3e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cjhq-hwgq-r969/GHSA-cjhq-hwgq-r969.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjhq-hwgq-r969", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32655" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in DevriX Restrict User Registration allows Stored XSS. This issue affects Restrict User Registration: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32655" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/restrict-user-registration/vulnerability/wordpress-restrict-user-registration-plugin-1-0-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cqc2-rc24-647j/GHSA-cqc2-rc24-647j.json b/advisories/unreviewed/2025/04/GHSA-cqc2-rc24-647j/GHSA-cqc2-rc24-647j.json new file mode 100644 index 00000000000..0ce0f809aae --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cqc2-rc24-647j/GHSA-cqc2-rc24-647j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqc2-rc24-647j", + "modified": "2025-04-17T18:31:23Z", + "published": "2025-04-17T18:31:23Z", + "aliases": [ + "CVE-2025-26269" + ], + "details": "DragonflyDB Dragonfly through 1.28.2 allows authenticated users to cause a denial of service (daemon crash) via a Lua library command that references a large negative integer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26269" + }, + { + "type": "WEB", + "url": "https://github.com/dragonflydb/dragonfly/issues/4468" + }, + { + "type": "WEB", + "url": "https://github.com/dragonflydb/dragonfly/commit/4612aec9a78e3f604e6fb19bee51acde89723308" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cvj9-jcwj-rjvx/GHSA-cvj9-jcwj-rjvx.json b/advisories/unreviewed/2025/04/GHSA-cvj9-jcwj-rjvx/GHSA-cvj9-jcwj-rjvx.json new file mode 100644 index 00000000000..2728be8235c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cvj9-jcwj-rjvx/GHSA-cvj9-jcwj-rjvx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvj9-jcwj-rjvx", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-27319" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ivan82 User List allows Reflected XSS. This issue affects User List: from n/a through 1.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27319" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/user-list/vulnerability/wordpress-user-list-plugin-1-5-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cvpj-g8p4-c6hg/GHSA-cvpj-g8p4-c6hg.json b/advisories/unreviewed/2025/04/GHSA-cvpj-g8p4-c6hg/GHSA-cvpj-g8p4-c6hg.json new file mode 100644 index 00000000000..bb72f146ece --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cvpj-g8p4-c6hg/GHSA-cvpj-g8p4-c6hg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvpj-g8p4-c6hg", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32552" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory MSRP (RRP) Pricing for WooCommerce allows Reflected XSS. This issue affects MSRP (RRP) Pricing for WooCommerce: from n/a through 1.8.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32552" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/msrp-for-woocommerce/vulnerability/wordpress-msrp-rrp-pricing-for-woocommerce-plugin-1-7-12-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cxj7-585w-jfq5/GHSA-cxj7-585w-jfq5.json b/advisories/unreviewed/2025/04/GHSA-cxj7-585w-jfq5/GHSA-cxj7-585w-jfq5.json new file mode 100644 index 00000000000..418ca75bb34 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cxj7-585w-jfq5/GHSA-cxj7-585w-jfq5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxj7-585w-jfq5", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-27324" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 17track 17TRACK for WooCommerce allows Reflected XSS. This issue affects 17TRACK for WooCommerce: from n/a through 1.2.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27324" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/17track/vulnerability/wordpress-17track-for-woocommerce-plugin-1-2-10-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f6fp-39qp-wq82/GHSA-f6fp-39qp-wq82.json b/advisories/unreviewed/2025/04/GHSA-f6fp-39qp-wq82/GHSA-f6fp-39qp-wq82.json new file mode 100644 index 00000000000..3c2d9f565c2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f6fp-39qp-wq82/GHSA-f6fp-39qp-wq82.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6fp-39qp-wq82", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32670" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark Parnell Spark GF Failed Submissions allows Reflected XSS. This issue affects Spark GF Failed Submissions: from n/a through 1.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32670" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/spark-gf-failed-submissions/vulnerability/wordpress-spark-gf-failed-submissions-plugin-1-3-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fg6h-m78g-fqg5/GHSA-fg6h-m78g-fqg5.json b/advisories/unreviewed/2025/04/GHSA-fg6h-m78g-fqg5/GHSA-fg6h-m78g-fqg5.json new file mode 100644 index 00000000000..6ae2189c162 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fg6h-m78g-fqg5/GHSA-fg6h-m78g-fqg5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg6h-m78g-fqg5", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32557" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rico Macchi WP Featured Screenshot allows Reflected XSS. This issue affects WP Featured Screenshot: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32557" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-featured-screenshot/vulnerability/wordpress-wp-featured-screenshot-plugin-1-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fgjq-m7rr-rv3f/GHSA-fgjq-m7rr-rv3f.json b/advisories/unreviewed/2025/04/GHSA-fgjq-m7rr-rv3f/GHSA-fgjq-m7rr-rv3f.json new file mode 100644 index 00000000000..f33f460cce2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fgjq-m7rr-rv3f/GHSA-fgjq-m7rr-rv3f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgjq-m7rr-rv3f", + "modified": "2025-04-17T18:31:21Z", + "published": "2025-04-17T18:31:21Z", + "aliases": [ + "CVE-2025-39562" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Payment Form for PayPal Pro allows Stored XSS. This issue affects Payment Form for PayPal Pro: from n/a through 1.1.72.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39562" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/payment-form-for-paypal-pro/vulnerability/wordpress-payment-form-for-paypal-pro-1-1-72-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fgr8-gcxj-6pq5/GHSA-fgr8-gcxj-6pq5.json b/advisories/unreviewed/2025/04/GHSA-fgr8-gcxj-6pq5/GHSA-fgr8-gcxj-6pq5.json new file mode 100644 index 00000000000..2b5d3cb95a3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fgr8-gcxj-6pq5/GHSA-fgr8-gcxj-6pq5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgr8-gcxj-6pq5", + "modified": "2025-04-17T18:31:23Z", + "published": "2025-04-17T18:31:22Z", + "aliases": [ + "CVE-2021-47671" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: etas_es58x: es58x_rx_err_msg(): fix memory leak in error path\n\nIn es58x_rx_err_msg(), if can->do_set_mode() fails, the function\ndirectly returns without calling netif_rx(skb). This means that the\nskb previously allocated by alloc_can_err_skb() is not freed. In other\nterms, this is a memory leak.\n\nThis patch simply removes the return statement in the error branch and\nlet the function continue.\n\nIssue was found with GCC -fanalyzer, please follow the link below for\ndetails.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47671" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4f389e1276a5389c92cef860c9fde8e1c802a871" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7eb0881aec26099089f12ae850aebd93190b1dfe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d9447f768bc8c60623e4bb3ce65b8f4654d33a50" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fhhc-qhh4-wq9v/GHSA-fhhc-qhh4-wq9v.json b/advisories/unreviewed/2025/04/GHSA-fhhc-qhh4-wq9v/GHSA-fhhc-qhh4-wq9v.json new file mode 100644 index 00000000000..972e21bfc93 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fhhc-qhh4-wq9v/GHSA-fhhc-qhh4-wq9v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhhc-qhh4-wq9v", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39457" + ], + "details": "Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Booking and Rental Manager: from n/a through 2.2.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39457" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/booking-and-rental-manager-for-woocommerce/vulnerability/wordpress-booking-and-rental-manager-plugin-2-2-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fp58-hrm7-m9p5/GHSA-fp58-hrm7-m9p5.json b/advisories/unreviewed/2025/04/GHSA-fp58-hrm7-m9p5/GHSA-fp58-hrm7-m9p5.json new file mode 100644 index 00000000000..ba934b50c48 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fp58-hrm7-m9p5/GHSA-fp58-hrm7-m9p5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp58-hrm7-m9p5", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39439" + ], + "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Markus Drubba wpLike2Get allows Retrieve Embedded Sensitive Data. This issue affects wpLike2Get: from n/a through 1.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39439" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wplike2get/vulnerability/wordpress-wplike2get-plugin-1-2-9-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-frxg-m9hj-2jhv/GHSA-frxg-m9hj-2jhv.json b/advisories/unreviewed/2025/04/GHSA-frxg-m9hj-2jhv/GHSA-frxg-m9hj-2jhv.json new file mode 100644 index 00000000000..21ec117e90a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-frxg-m9hj-2jhv/GHSA-frxg-m9hj-2jhv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frxg-m9hj-2jhv", + "modified": "2025-04-17T18:31:16Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32528" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in maximevalette iCal Feeds allows Reflected XSS. This issue affects iCal Feeds: from n/a through 1.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32528" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ical-feeds/vulnerability/wordpress-ical-feeds-plugin-1-5-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fvqp-m35r-x4xm/GHSA-fvqp-m35r-x4xm.json b/advisories/unreviewed/2025/04/GHSA-fvqp-m35r-x4xm/GHSA-fvqp-m35r-x4xm.json new file mode 100644 index 00000000000..5e5975b31d0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fvqp-m35r-x4xm/GHSA-fvqp-m35r-x4xm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvqp-m35r-x4xm", + "modified": "2025-04-17T18:31:21Z", + "published": "2025-04-17T18:31:21Z", + "aliases": [ + "CVE-2025-39583" + ], + "details": "Missing Authorization vulnerability in berthaai BERTHA AI allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects BERTHA AI: from n/a through 1.12.10.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39583" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bertha-ai-free/vulnerability/wordpress-bertha-ai-1-12-10-2-arbitrary-content-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fw3f-m6cp-wxg6/GHSA-fw3f-m6cp-wxg6.json b/advisories/unreviewed/2025/04/GHSA-fw3f-m6cp-wxg6/GHSA-fw3f-m6cp-wxg6.json new file mode 100644 index 00000000000..bc0d0d68e8b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fw3f-m6cp-wxg6/GHSA-fw3f-m6cp-wxg6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw3f-m6cp-wxg6", + "modified": "2025-04-17T18:31:13Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-24581" + ], + "details": "Missing Authorization vulnerability in Themefic Instantio allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Instantio: from n/a through 3.3.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24581" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/instantio/vulnerability/wordpress-instantio-plugin-3-3-7-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fx2r-qpf4-38vc/GHSA-fx2r-qpf4-38vc.json b/advisories/unreviewed/2025/04/GHSA-fx2r-qpf4-38vc/GHSA-fx2r-qpf4-38vc.json new file mode 100644 index 00000000000..fb54b86158a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fx2r-qpf4-38vc/GHSA-fx2r-qpf4-38vc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fx2r-qpf4-38vc", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39456" + ], + "details": "Missing Authorization vulnerability in iTRON WP Logger allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Logger: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39456" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-data-logger/vulnerability/wordpress-wp-logger-plugin-2-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fxwh-c962-39r5/GHSA-fxwh-c962-39r5.json b/advisories/unreviewed/2025/04/GHSA-fxwh-c962-39r5/GHSA-fxwh-c962-39r5.json new file mode 100644 index 00000000000..33ca05b7f50 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fxwh-c962-39r5/GHSA-fxwh-c962-39r5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxwh-c962-39r5", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32572" + ], + "details": "Deserialization of Untrusted Data vulnerability in Climax Themes Kata Plus allows Object Injection. This issue affects Kata Plus: from n/a through 1.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32572" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/kata-plus/vulnerability/wordpress-kata-plus-addons-for-elementor-widgets-extensions-and-templates-plugin-1-5-0-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g275-7gx9-r8ww/GHSA-g275-7gx9-r8ww.json b/advisories/unreviewed/2025/04/GHSA-g275-7gx9-r8ww/GHSA-g275-7gx9-r8ww.json new file mode 100644 index 00000000000..c2322409d8b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g275-7gx9-r8ww/GHSA-g275-7gx9-r8ww.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g275-7gx9-r8ww", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39437" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Boone Gorges Anthologize allows Cross Site Request Forgery. This issue affects Anthologize: from n/a through 0.8.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39437" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/anthologize/vulnerability/wordpress-anthologize-plugin-0-8-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g2gm-9v8p-3j59/GHSA-g2gm-9v8p-3j59.json b/advisories/unreviewed/2025/04/GHSA-g2gm-9v8p-3j59/GHSA-g2gm-9v8p-3j59.json new file mode 100644 index 00000000000..1832708d7f7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g2gm-9v8p-3j59/GHSA-g2gm-9v8p-3j59.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2gm-9v8p-3j59", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39440" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Rajesh Broken Links Remover allows Stored XSS. This issue affects Broken Links Remover: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39440" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/broken-links-remover/vulnerability/wordpress-broken-links-remover-plugin-1-2-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g2gp-63px-3c6r/GHSA-g2gp-63px-3c6r.json b/advisories/unreviewed/2025/04/GHSA-g2gp-63px-3c6r/GHSA-g2gp-63px-3c6r.json new file mode 100644 index 00000000000..8496e9cfcda --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g2gp-63px-3c6r/GHSA-g2gp-63px-3c6r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2gp-63px-3c6r", + "modified": "2025-04-17T18:31:13Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-23773" + ], + "details": "Missing Authorization vulnerability in mingocommerce Delete All Posts allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Delete All Posts: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23773" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/delele-all/vulnerability/wordpress-delete-all-posts-plugin-1-1-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g36w-5vm4-qjjc/GHSA-g36w-5vm4-qjjc.json b/advisories/unreviewed/2025/04/GHSA-g36w-5vm4-qjjc/GHSA-g36w-5vm4-qjjc.json new file mode 100644 index 00000000000..33b33f89b58 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g36w-5vm4-qjjc/GHSA-g36w-5vm4-qjjc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g36w-5vm4-qjjc", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32658" + ], + "details": "Deserialization of Untrusted Data vulnerability in wpWax HelpGent allows Object Injection. This issue affects HelpGent: from n/a through 2.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32658" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/helpgent/vulnerability/wordpress-helpgent-plugin-2-2-4-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g3pp-67rc-cjg2/GHSA-g3pp-67rc-cjg2.json b/advisories/unreviewed/2025/04/GHSA-g3pp-67rc-cjg2/GHSA-g3pp-67rc-cjg2.json new file mode 100644 index 00000000000..590e51fa3ef --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g3pp-67rc-cjg2/GHSA-g3pp-67rc-cjg2.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3pp-67rc-cjg2", + "modified": "2025-04-17T18:31:23Z", + "published": "2025-04-17T18:31:22Z", + "aliases": [ + "CVE-2021-47670" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: peak_usb: fix use after free bugs\n\nAfter calling peak_usb_netif_rx_ni(skb), dereferencing skb is unsafe.\nEspecially, the can_frame cf which aliases skb memory is accessed\nafter the peak_usb_netif_rx_ni().\n\nReordering the lines solves the issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47670" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/50aca891d7a554db0901b245167cd653d73aaa71" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5408824636fa0dfedb9ecb0d94abd573131bfbbe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ddd1416f44130377798c1430b76503513b7497c2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ec939c13c3fff2114479769c8380b7f1a54feca9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g3pr-333m-wf2c/GHSA-g3pr-333m-wf2c.json b/advisories/unreviewed/2025/04/GHSA-g3pr-333m-wf2c/GHSA-g3pr-333m-wf2c.json new file mode 100644 index 00000000000..059f48b14b1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g3pr-333m-wf2c/GHSA-g3pr-333m-wf2c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3pr-333m-wf2c", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32578" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mapro Collins Coming Soon Countdown allows Reflected XSS. This issue affects Coming Soon Countdown: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32578" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/coming-soon-countdown/vulnerability/wordpress-coming-soon-countdown-plugin-2-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g57c-546q-327c/GHSA-g57c-546q-327c.json b/advisories/unreviewed/2025/04/GHSA-g57c-546q-327c/GHSA-g57c-546q-327c.json new file mode 100644 index 00000000000..372668e82e6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g57c-546q-327c/GHSA-g57c-546q-327c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g57c-546q-327c", + "modified": "2025-04-17T18:31:16Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32531" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix FAQ allows Reflected XSS. This issue affects Arconix FAQ: from n/a through 1.9.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32531" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/arconix-faq/vulnerability/wordpress-arconix-faq-plugin-1-9-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g5fv-rhmh-mx2p/GHSA-g5fv-rhmh-mx2p.json b/advisories/unreviewed/2025/04/GHSA-g5fv-rhmh-mx2p/GHSA-g5fv-rhmh-mx2p.json new file mode 100644 index 00000000000..226d644a788 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g5fv-rhmh-mx2p/GHSA-g5fv-rhmh-mx2p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5fv-rhmh-mx2p", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:19Z", + "aliases": [ + "CVE-2025-39431" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Aaron Forgue Amazon Showcase WordPress Plugin allows Stored XSS. This issue affects Amazon Showcase WordPress Plugin: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39431" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/amazon-showcase-wordpress-widget/vulnerability/wordpress-amazon-showcase-wordpress-plugin-plugin-2-2-csrf-to-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g67h-7m25-7mmv/GHSA-g67h-7m25-7mmv.json b/advisories/unreviewed/2025/04/GHSA-g67h-7m25-7mmv/GHSA-g67h-7m25-7mmv.json new file mode 100644 index 00000000000..c98dce381c7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g67h-7m25-7mmv/GHSA-g67h-7m25-7mmv.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g67h-7m25-7mmv", + "modified": "2025-04-17T18:31:22Z", + "published": "2025-04-17T18:31:22Z", + "aliases": [ + "CVE-2025-29039" + ], + "details": "An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x41dda8", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29039" + }, + { + "type": "WEB", + "url": "https://gist.github.com/xyqer1/734fd1d93e4c08cea55dcb1e8b189a2b" + }, + { + "type": "WEB", + "url": "https://github.com/xyqer1/Dlink-dir-823x-set_ntp-year-CommandInjection" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T17:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g7gw-qjjj-h26r/GHSA-g7gw-qjjj-h26r.json b/advisories/unreviewed/2025/04/GHSA-g7gw-qjjj-h26r/GHSA-g7gw-qjjj-h26r.json new file mode 100644 index 00000000000..0a58adfca67 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g7gw-qjjj-h26r/GHSA-g7gw-qjjj-h26r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7gw-qjjj-h26r", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32560" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mohammad I. Okfie WP-Hijri allows Reflected XSS. This issue affects WP-Hijri: from n/a through 1.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32560" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-hijri/vulnerability/wordpress-wp-hijri-plugin-1-5-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g8r8-g7qx-p4c7/GHSA-g8r8-g7qx-p4c7.json b/advisories/unreviewed/2025/04/GHSA-g8r8-g7qx-p4c7/GHSA-g8r8-g7qx-p4c7.json new file mode 100644 index 00000000000..8ce1077645c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g8r8-g7qx-p4c7/GHSA-g8r8-g7qx-p4c7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8r8-g7qx-p4c7", + "modified": "2025-04-17T18:31:23Z", + "published": "2025-04-17T18:31:23Z", + "aliases": [ + "CVE-2025-28009" + ], + "details": "A SQL Injection vulnerability exists in the `u` parameter of the progress-body-weight.php endpoint of Dietiqa App v1.0.20.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28009" + }, + { + "type": "WEB", + "url": "https://github.com/beardenx/CVE-2025-28009" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g95c-54h8-86cc/GHSA-g95c-54h8-86cc.json b/advisories/unreviewed/2025/04/GHSA-g95c-54h8-86cc/GHSA-g95c-54h8-86cc.json new file mode 100644 index 00000000000..97b53cb4eaa --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g95c-54h8-86cc/GHSA-g95c-54h8-86cc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g95c-54h8-86cc", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:14Z", + "aliases": [ + "CVE-2025-27285" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Easy Form by AYS allows Reflected XSS. This issue affects Easy Form by AYS: from n/a through 2.6.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27285" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-form/vulnerability/wordpress-easy-form-by-ays-plugin-2-6-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g9ph-q425-qq92/GHSA-g9ph-q425-qq92.json b/advisories/unreviewed/2025/04/GHSA-g9ph-q425-qq92/GHSA-g9ph-q425-qq92.json new file mode 100644 index 00000000000..15e339a566d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g9ph-q425-qq92/GHSA-g9ph-q425-qq92.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9ph-q425-qq92", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32602" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aiiddqd WooMS allows Reflected XSS. This issue affects WooMS: from n/a through 9.12.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32602" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wooms/vulnerability/wordpress-wooms-plugin-9-12-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gh9p-r2h3-q5rr/GHSA-gh9p-r2h3-q5rr.json b/advisories/unreviewed/2025/04/GHSA-gh9p-r2h3-q5rr/GHSA-gh9p-r2h3-q5rr.json new file mode 100644 index 00000000000..b4d8fd01133 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gh9p-r2h3-q5rr/GHSA-gh9p-r2h3-q5rr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh9p-r2h3-q5rr", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39443" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Soft8Soft LLC Verge3D allows Cross Site Request Forgery. This issue affects Verge3D: from n/a through 4.9.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39443" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/verge3d/vulnerability/wordpress-verge3d-plugin-4-9-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gm22-hqvw-7j52/GHSA-gm22-hqvw-7j52.json b/advisories/unreviewed/2025/04/GHSA-gm22-hqvw-7j52/GHSA-gm22-hqvw-7j52.json index 8793d803759..59be4d5d717 100644 --- a/advisories/unreviewed/2025/04/GHSA-gm22-hqvw-7j52/GHSA-gm22-hqvw-7j52.json +++ b/advisories/unreviewed/2025/04/GHSA-gm22-hqvw-7j52/GHSA-gm22-hqvw-7j52.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gm22-hqvw-7j52", - "modified": "2025-04-17T00:30:26Z", + "modified": "2025-04-17T18:31:11Z", "published": "2025-04-17T00:30:25Z", "aliases": [ "CVE-2025-1566" ], "details": "DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 129.0.6668.36 allows network observers to expose plaintext DNS queries via failure to properly tunnel DNS traffic during VPN state transitions.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1319" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T23:15:44Z" diff --git a/advisories/unreviewed/2025/04/GHSA-gp2f-qm5p-8j9p/GHSA-gp2f-qm5p-8j9p.json b/advisories/unreviewed/2025/04/GHSA-gp2f-qm5p-8j9p/GHSA-gp2f-qm5p-8j9p.json new file mode 100644 index 00000000000..cf8642685e4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gp2f-qm5p-8j9p/GHSA-gp2f-qm5p-8j9p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gp2f-qm5p-8j9p", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32611" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in We Are De WooCommerce TBC Credit Card Payment Gateway (Free) allows Reflected XSS. This issue affects WooCommerce TBC Credit Card Payment Gateway (Free): from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32611" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-tbc-payment-gateway/vulnerability/wordpress-woocommerce-tbc-credit-card-payment-gateway-free-plugin-2-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gp3q-2c8h-jhrv/GHSA-gp3q-2c8h-jhrv.json b/advisories/unreviewed/2025/04/GHSA-gp3q-2c8h-jhrv/GHSA-gp3q-2c8h-jhrv.json new file mode 100644 index 00000000000..9e896145d51 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gp3q-2c8h-jhrv/GHSA-gp3q-2c8h-jhrv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gp3q-2c8h-jhrv", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:14Z", + "aliases": [ + "CVE-2025-24752" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor allows Reflected XSS. This issue affects Essential Addons for Elementor: from n/a through 6.0.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24752" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/essential-addons-for-elementor-lite/vulnerability/wordpress-essential-addons-for-elementor-plugin-6-0-14-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gpqw-ppjw-678q/GHSA-gpqw-ppjw-678q.json b/advisories/unreviewed/2025/04/GHSA-gpqw-ppjw-678q/GHSA-gpqw-ppjw-678q.json new file mode 100644 index 00000000000..455d32d44f0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gpqw-ppjw-678q/GHSA-gpqw-ppjw-678q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpqw-ppjw-678q", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-27338" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in graphems List Urls allows Reflected XSS. This issue affects List Urls: from n/a through 0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27338" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/list-urls/vulnerability/wordpress-list-urls-plugin-0-2-csrf-to-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gr2m-j2m7-6qm7/GHSA-gr2m-j2m7-6qm7.json b/advisories/unreviewed/2025/04/GHSA-gr2m-j2m7-6qm7/GHSA-gr2m-j2m7-6qm7.json new file mode 100644 index 00000000000..82cd31010c3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gr2m-j2m7-6qm7/GHSA-gr2m-j2m7-6qm7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr2m-j2m7-6qm7", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32609" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Picture-Planet GmbH Verowa Connect allows Reflected XSS. This issue affects Verowa Connect: from n/a through 3.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32609" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/verowa-connect/vulnerability/wordpress-verowa-connect-plugin-3-0-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h33h-9pwh-v2h4/GHSA-h33h-9pwh-v2h4.json b/advisories/unreviewed/2025/04/GHSA-h33h-9pwh-v2h4/GHSA-h33h-9pwh-v2h4.json new file mode 100644 index 00000000000..b4266bb1af3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h33h-9pwh-v2h4/GHSA-h33h-9pwh-v2h4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h33h-9pwh-v2h4", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-27322" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bappa Mal QR Code for WooCommerce allows Reflected XSS. This issue affects QR Code for WooCommerce: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27322" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wc-qr-codes/vulnerability/wordpress-qr-code-for-woocommerce-plugin-1-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h4fr-qhv5-6jfq/GHSA-h4fr-qhv5-6jfq.json b/advisories/unreviewed/2025/04/GHSA-h4fr-qhv5-6jfq/GHSA-h4fr-qhv5-6jfq.json index 6f2e998eae6..aa8ae468cd8 100644 --- a/advisories/unreviewed/2025/04/GHSA-h4fr-qhv5-6jfq/GHSA-h4fr-qhv5-6jfq.json +++ b/advisories/unreviewed/2025/04/GHSA-h4fr-qhv5-6jfq/GHSA-h4fr-qhv5-6jfq.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-94" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2025/04/GHSA-h66v-h338-mpfm/GHSA-h66v-h338-mpfm.json b/advisories/unreviewed/2025/04/GHSA-h66v-h338-mpfm/GHSA-h66v-h338-mpfm.json new file mode 100644 index 00000000000..7c2942a6117 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h66v-h338-mpfm/GHSA-h66v-h338-mpfm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h66v-h338-mpfm", + "modified": "2025-04-17T18:31:13Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-24619" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webheadcoder WP Log Action allows Reflected XSS. This issue affects WP Log Action: from n/a through 0.51.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24619" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-log-action/vulnerability/wordpress-wp-log-action-plugin-0-51-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h77h-8j9x-wmj8/GHSA-h77h-8j9x-wmj8.json b/advisories/unreviewed/2025/04/GHSA-h77h-8j9x-wmj8/GHSA-h77h-8j9x-wmj8.json new file mode 100644 index 00000000000..5fca9f7c29b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h77h-8j9x-wmj8/GHSA-h77h-8j9x-wmj8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h77h-8j9x-wmj8", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-27333" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alvego Protected wp-login allows Reflected XSS. This issue affects Protected wp-login: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27333" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/protected-wp-login/vulnerability/wordpress-protected-wp-login-plugin-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h8pp-6w7x-wjwx/GHSA-h8pp-6w7x-wjwx.json b/advisories/unreviewed/2025/04/GHSA-h8pp-6w7x-wjwx/GHSA-h8pp-6w7x-wjwx.json new file mode 100644 index 00000000000..9915c6452b8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h8pp-6w7x-wjwx/GHSA-h8pp-6w7x-wjwx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8pp-6w7x-wjwx", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:19Z", + "aliases": [ + "CVE-2025-32674" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Product Excel Import Export & Bulk Edit for WooCommerce allows Reflected XSS. This issue affects Product Excel Import Export & Bulk Edit for WooCommerce: from n/a through 4.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32674" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/webd-woocommerce-product-excel-importer-bulk-edit/vulnerability/wordpress-product-excel-import-export-bulk-edit-for-woocommerce-plugin-4-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h8wr-2qx3-3r42/GHSA-h8wr-2qx3-3r42.json b/advisories/unreviewed/2025/04/GHSA-h8wr-2qx3-3r42/GHSA-h8wr-2qx3-3r42.json new file mode 100644 index 00000000000..294140b9ff0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h8wr-2qx3-3r42/GHSA-h8wr-2qx3-3r42.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8wr-2qx3-3r42", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32594" + ], + "details": "Insertion of Sensitive Information Into Sent Data vulnerability in WPMinds Simple WP Events allows Retrieve Embedded Sensitive Data. This issue affects Simple WP Events: from n/a through 1.8.17.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32594" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-wp-events/vulnerability/wordpress-simple-wp-events-plugin-1-8-17-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hf2f-hm5p-pq8f/GHSA-hf2f-hm5p-pq8f.json b/advisories/unreviewed/2025/04/GHSA-hf2f-hm5p-pq8f/GHSA-hf2f-hm5p-pq8f.json new file mode 100644 index 00000000000..b9027611f78 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hf2f-hm5p-pq8f/GHSA-hf2f-hm5p-pq8f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf2f-hm5p-pq8f", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39521" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashish Ajani Contact Form vCard Generator allows Reflected XSS. This issue affects Contact Form vCard Generator: from n/a through 2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39521" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/contact-form-vcard-generator/vulnerability/wordpress-contact-form-vcard-generator-plugin-2-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hg4w-h686-f7p2/GHSA-hg4w-h686-f7p2.json b/advisories/unreviewed/2025/04/GHSA-hg4w-h686-f7p2/GHSA-hg4w-h686-f7p2.json new file mode 100644 index 00000000000..40fe55025ee --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hg4w-h686-f7p2/GHSA-hg4w-h686-f7p2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hg4w-h686-f7p2", + "modified": "2025-04-17T18:31:16Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32508" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ComMotion Course Booking System allows Reflected XSS. This issue affects Course Booking System: from n/a through 6.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32508" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/course-booking-system/vulnerability/wordpress-course-booking-system-plugin-6-0-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hgpm-55ww-xj5v/GHSA-hgpm-55ww-xj5v.json b/advisories/unreviewed/2025/04/GHSA-hgpm-55ww-xj5v/GHSA-hgpm-55ww-xj5v.json new file mode 100644 index 00000000000..15d6598fce2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hgpm-55ww-xj5v/GHSA-hgpm-55ww-xj5v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgpm-55ww-xj5v", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:14Z", + "aliases": [ + "CVE-2025-27283" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in rockgod100 Theme File Duplicator allows Path Traversal. This issue affects Theme File Duplicator: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27283" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/theme-file-duplicator/vulnerability/wordpress-theme-file-duplicator-plugin-1-3-arbitrary-file-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hjvx-hp9r-h988/GHSA-hjvx-hp9r-h988.json b/advisories/unreviewed/2025/04/GHSA-hjvx-hp9r-h988/GHSA-hjvx-hp9r-h988.json new file mode 100644 index 00000000000..ef114595246 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hjvx-hp9r-h988/GHSA-hjvx-hp9r-h988.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjvx-hp9r-h988", + "modified": "2025-04-17T18:31:22Z", + "published": "2025-04-17T18:31:22Z", + "aliases": [ + "CVE-2024-40124" + ], + "details": "Pydio Core <= 8.2.5 is vulnerable to Cross Site Scripting (XSS) via the New URL Bookmark feature.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40124" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Xib3rR4dAr/711195d5793bfbb4364dc179ecaae25d" + }, + { + "type": "WEB", + "url": "https://pydio.com/en/community/releases/pydio-core/pydio-core-pydio-enterprise-825-hotfix-824" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T17:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hm48-f7vp-c97r/GHSA-hm48-f7vp-c97r.json b/advisories/unreviewed/2025/04/GHSA-hm48-f7vp-c97r/GHSA-hm48-f7vp-c97r.json new file mode 100644 index 00000000000..f35245350f7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hm48-f7vp-c97r/GHSA-hm48-f7vp-c97r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hm48-f7vp-c97r", + "modified": "2025-04-17T18:31:16Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32546" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in gtlwpdev All push notification for WP allows Reflected XSS. This issue affects All push notification for WP: from n/a through 1.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32546" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/all-push-notification/vulnerability/wordpress-all-push-notification-for-wp-plugin-1-5-3-csrf-to-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hmvw-rwmj-gphw/GHSA-hmvw-rwmj-gphw.json b/advisories/unreviewed/2025/04/GHSA-hmvw-rwmj-gphw/GHSA-hmvw-rwmj-gphw.json new file mode 100644 index 00000000000..6b52435c4a6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hmvw-rwmj-gphw/GHSA-hmvw-rwmj-gphw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmvw-rwmj-gphw", + "modified": "2025-04-17T18:31:12Z", + "published": "2025-04-17T18:31:12Z", + "aliases": [ + "CVE-2024-12530" + ], + "details": "Uncontrolled Search Path Element vulnerability in OpenText Secure Content Manager on Windows allows DLL Side-Loading.This issue affects Secure Content Manager: 23.4.\n\nEnd-users can potentially exploit the vulnerability to execute malicious code in the trusted context of the thick-client application.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12530" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000040073?" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hr94-jx6q-7pcg/GHSA-hr94-jx6q-7pcg.json b/advisories/unreviewed/2025/04/GHSA-hr94-jx6q-7pcg/GHSA-hr94-jx6q-7pcg.json new file mode 100644 index 00000000000..5f8d3a7b330 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hr94-jx6q-7pcg/GHSA-hr94-jx6q-7pcg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hr94-jx6q-7pcg", + "modified": "2025-04-17T18:31:22Z", + "published": "2025-04-17T18:31:22Z", + "aliases": [ + "CVE-2025-29661" + ], + "details": "Litepubl CMS <= 7.0.9 is vulnerable to RCE in admin/service/run.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29661" + }, + { + "type": "WEB", + "url": "https://github.com/litepubl/cms/issues/1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hvjh-q752-pqqp/GHSA-hvjh-q752-pqqp.json b/advisories/unreviewed/2025/04/GHSA-hvjh-q752-pqqp/GHSA-hvjh-q752-pqqp.json index 96661f98ae0..5104cb29d96 100644 --- a/advisories/unreviewed/2025/04/GHSA-hvjh-q752-pqqp/GHSA-hvjh-q752-pqqp.json +++ b/advisories/unreviewed/2025/04/GHSA-hvjh-q752-pqqp/GHSA-hvjh-q752-pqqp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-hvqh-6vfx-vr57/GHSA-hvqh-6vfx-vr57.json b/advisories/unreviewed/2025/04/GHSA-hvqh-6vfx-vr57/GHSA-hvqh-6vfx-vr57.json new file mode 100644 index 00000000000..d843c7ff5bf --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hvqh-6vfx-vr57/GHSA-hvqh-6vfx-vr57.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvqh-6vfx-vr57", + "modified": "2025-04-17T18:31:21Z", + "published": "2025-04-17T18:31:21Z", + "aliases": [ + "CVE-2025-39586" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid allows SQL Injection. This issue affects ProfileGrid : from n/a through 5.9.4.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39586" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/profilegrid-user-profiles-groups-and-communities/vulnerability/wordpress-profilegrid-5-9-4-8-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hw2f-h9gc-5p9j/GHSA-hw2f-h9gc-5p9j.json b/advisories/unreviewed/2025/04/GHSA-hw2f-h9gc-5p9j/GHSA-hw2f-h9gc-5p9j.json new file mode 100644 index 00000000000..5eaa0def098 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hw2f-h9gc-5p9j/GHSA-hw2f-h9gc-5p9j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hw2f-h9gc-5p9j", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-24670" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dhanendran Rajagopal Term Taxonomy Converter allows Reflected XSS. This issue affects Term Taxonomy Converter: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24670" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/term-taxonomy-converter/vulnerability/wordpress-term-taxonomy-converter-plugin-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hwpp-cpx2-m8fm/GHSA-hwpp-cpx2-m8fm.json b/advisories/unreviewed/2025/04/GHSA-hwpp-cpx2-m8fm/GHSA-hwpp-cpx2-m8fm.json new file mode 100644 index 00000000000..4105d1503db --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hwpp-cpx2-m8fm/GHSA-hwpp-cpx2-m8fm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwpp-cpx2-m8fm", + "modified": "2025-04-17T18:31:16Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32529" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iONE360 iONE360 configurator allows Reflected XSS. This issue affects iONE360 configurator: from n/a through 2.0.56.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32529" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ione360-configurator/vulnerability/wordpress-ione360-configurator-plugin-2-0-56-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j5fc-rph7-5xhq/GHSA-j5fc-rph7-5xhq.json b/advisories/unreviewed/2025/04/GHSA-j5fc-rph7-5xhq/GHSA-j5fc-rph7-5xhq.json new file mode 100644 index 00000000000..4190652901e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j5fc-rph7-5xhq/GHSA-j5fc-rph7-5xhq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5fc-rph7-5xhq", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32662" + ], + "details": "Deserialization of Untrusted Data vulnerability in Stylemix uListing allows Object Injection. This issue affects uListing: from n/a through 2.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32662" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ulisting/vulnerability/wordpress-ulisting-plugin-2-1-9-deserialization-of-untrusted-data-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j5q8-m85f-2332/GHSA-j5q8-m85f-2332.json b/advisories/unreviewed/2025/04/GHSA-j5q8-m85f-2332/GHSA-j5q8-m85f-2332.json new file mode 100644 index 00000000000..54a78de71f9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j5q8-m85f-2332/GHSA-j5q8-m85f-2332.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5q8-m85f-2332", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:19Z", + "aliases": [ + "CVE-2025-39414" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Mike spam-stopper allows Stored XSS. This issue affects spam-stopper: from n/a through 3.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39414" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/spam-stopper/vulnerability/wordpress-spam-stopper-plugin-3-1-3-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j7vc-h8gh-c57c/GHSA-j7vc-h8gh-c57c.json b/advisories/unreviewed/2025/04/GHSA-j7vc-h8gh-c57c/GHSA-j7vc-h8gh-c57c.json new file mode 100644 index 00000000000..b0ae06a8765 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j7vc-h8gh-c57c/GHSA-j7vc-h8gh-c57c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7vc-h8gh-c57c", + "modified": "2025-04-17T18:31:13Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-24548" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Autoglot Autoglot – Automatic WordPress Translation allows Reflected XSS. This issue affects Autoglot – Automatic WordPress Translation: from n/a through 2.4.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24548" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/autoglot/vulnerability/wordpress-autoglot-automatic-wordpress-translation-plugin-2-4-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j9xf-4c4g-rqx3/GHSA-j9xf-4c4g-rqx3.json b/advisories/unreviewed/2025/04/GHSA-j9xf-4c4g-rqx3/GHSA-j9xf-4c4g-rqx3.json new file mode 100644 index 00000000000..0c730ce0276 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j9xf-4c4g-rqx3/GHSA-j9xf-4c4g-rqx3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9xf-4c4g-rqx3", + "modified": "2025-04-17T18:31:16Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32522" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPExperts.io License Manager for WooCommerce allows Reflected XSS. This issue affects License Manager for WooCommerce: from n/a through 3.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32522" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/license-manager-for-woocommerce/vulnerability/wordpress-license-manager-for-woocommerce-plugin-3-0-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jc9q-gp3w-hgwr/GHSA-jc9q-gp3w-hgwr.json b/advisories/unreviewed/2025/04/GHSA-jc9q-gp3w-hgwr/GHSA-jc9q-gp3w-hgwr.json new file mode 100644 index 00000000000..0891a45958d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jc9q-gp3w-hgwr/GHSA-jc9q-gp3w-hgwr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc9q-gp3w-hgwr", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:19Z", + "aliases": [ + "CVE-2025-39424" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in simplemaps Simple Maps allows Stored XSS. This issue affects Simple Maps: from n/a through 0.98.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39424" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/interactive-maps/vulnerability/wordpress-simple-maps-plugin-0-98-csrf-to-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jhgx-8qx6-x3gx/GHSA-jhgx-8qx6-x3gx.json b/advisories/unreviewed/2025/04/GHSA-jhgx-8qx6-x3gx/GHSA-jhgx-8qx6-x3gx.json new file mode 100644 index 00000000000..aaf4e6c8ff7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jhgx-8qx6-x3gx/GHSA-jhgx-8qx6-x3gx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhgx-8qx6-x3gx", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:14Z", + "aliases": [ + "CVE-2025-27284" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in divspark Flagged Content allows Reflected XSS. This issue affects Flagged Content: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27284" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/flagged-content/vulnerability/wordpress-flagged-content-plugin-1-0-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jhp8-52c5-gjpr/GHSA-jhp8-52c5-gjpr.json b/advisories/unreviewed/2025/04/GHSA-jhp8-52c5-gjpr/GHSA-jhp8-52c5-gjpr.json new file mode 100644 index 00000000000..464d5a2f146 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jhp8-52c5-gjpr/GHSA-jhp8-52c5-gjpr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhp8-52c5-gjpr", + "modified": "2025-04-17T18:31:13Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-24645" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rob Scott Eazy Under Construction allows Reflected XSS. This issue affects Eazy Under Construction: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24645" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/eazy-under-construction/vulnerability/wordpress-eazy-under-construction-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jwc2-228h-vcwr/GHSA-jwc2-228h-vcwr.json b/advisories/unreviewed/2025/04/GHSA-jwc2-228h-vcwr/GHSA-jwc2-228h-vcwr.json index 6575d0e20d8..f81ac933cc1 100644 --- a/advisories/unreviewed/2025/04/GHSA-jwc2-228h-vcwr/GHSA-jwc2-228h-vcwr.json +++ b/advisories/unreviewed/2025/04/GHSA-jwc2-228h-vcwr/GHSA-jwc2-228h-vcwr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-jx24-hm29-p4xm/GHSA-jx24-hm29-p4xm.json b/advisories/unreviewed/2025/04/GHSA-jx24-hm29-p4xm/GHSA-jx24-hm29-p4xm.json new file mode 100644 index 00000000000..ef474245e51 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jx24-hm29-p4xm/GHSA-jx24-hm29-p4xm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jx24-hm29-p4xm", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:19Z", + "aliases": [ + "CVE-2025-39421" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Mustafa KUCUK WP Sticky Side Buttons allows Stored XSS. This issue affects WP Sticky Side Buttons: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39421" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-sticky-side-buttons/vulnerability/wordpress-wp-sticky-side-buttons-plugin-2-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jxpg-7f4x-g2fh/GHSA-jxpg-7f4x-g2fh.json b/advisories/unreviewed/2025/04/GHSA-jxpg-7f4x-g2fh/GHSA-jxpg-7f4x-g2fh.json new file mode 100644 index 00000000000..54f1df79316 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jxpg-7f4x-g2fh/GHSA-jxpg-7f4x-g2fh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxpg-7f4x-g2fh", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:14Z", + "aliases": [ + "CVE-2025-24737" + ], + "details": "Missing Authorization vulnerability in Mat Bao Corporation WP Helper Premium allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WP Helper Premium: from n/a through 4.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24737" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-helper-lite/vulnerability/wordpress-wp-helper-premium-plugin-4-6-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m2v5-59cm-cc6q/GHSA-m2v5-59cm-cc6q.json b/advisories/unreviewed/2025/04/GHSA-m2v5-59cm-cc6q/GHSA-m2v5-59cm-cc6q.json new file mode 100644 index 00000000000..5a137b63212 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m2v5-59cm-cc6q/GHSA-m2v5-59cm-cc6q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2v5-59cm-cc6q", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:14Z", + "aliases": [ + "CVE-2025-27282" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in rockgod100 Theme File Duplicator allows Using Malicious Files. This issue affects Theme File Duplicator: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27282" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/theme-file-duplicator/vulnerability/wordpress-theme-file-duplicator-plugin-1-3-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m348-vxx3-44qv/GHSA-m348-vxx3-44qv.json b/advisories/unreviewed/2025/04/GHSA-m348-vxx3-44qv/GHSA-m348-vxx3-44qv.json new file mode 100644 index 00000000000..d5470898fac --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m348-vxx3-44qv/GHSA-m348-vxx3-44qv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m348-vxx3-44qv", + "modified": "2025-04-17T18:31:21Z", + "published": "2025-04-17T18:31:21Z", + "aliases": [ + "CVE-2025-39550" + ], + "details": "Deserialization of Untrusted Data vulnerability in Shahjahan Jewel FluentCommunity allows Object Injection. This issue affects FluentCommunity: from n/a through 1.2.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39550" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fluent-community/vulnerability/wordpress-fluentcommunity-1-2-15-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m734-wmxm-5gcm/GHSA-m734-wmxm-5gcm.json b/advisories/unreviewed/2025/04/GHSA-m734-wmxm-5gcm/GHSA-m734-wmxm-5gcm.json new file mode 100644 index 00000000000..580d15a481f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m734-wmxm-5gcm/GHSA-m734-wmxm-5gcm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m734-wmxm-5gcm", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32625" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pootlepress Mobile Pages allows Reflected XSS. This issue affects Mobile Pages: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32625" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mobile-pages/vulnerability/wordpress-mobile-blocks-plugin-1-0-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m8pf-j4wj-g6rg/GHSA-m8pf-j4wj-g6rg.json b/advisories/unreviewed/2025/04/GHSA-m8pf-j4wj-g6rg/GHSA-m8pf-j4wj-g6rg.json new file mode 100644 index 00000000000..cf477c9a1a8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m8pf-j4wj-g6rg/GHSA-m8pf-j4wj-g6rg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8pf-j4wj-g6rg", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32566" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashraful Sarkar Naiem License For Envato allows Reflected XSS. This issue affects License For Envato: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32566" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/license-envato/vulnerability/wordpress-license-for-envato-plugin-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m92c-q898-572x/GHSA-m92c-q898-572x.json b/advisories/unreviewed/2025/04/GHSA-m92c-q898-572x/GHSA-m92c-q898-572x.json new file mode 100644 index 00000000000..a83fe7dddb0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m92c-q898-572x/GHSA-m92c-q898-572x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m92c-q898-572x", + "modified": "2025-04-17T18:31:22Z", + "published": "2025-04-17T18:31:22Z", + "aliases": [ + "CVE-2025-2947" + ], + "details": "IBM i 7.6 \n\ncontains a privilege escalation vulnerability due to incorrect profile swapping in an OS command.  A malicious actor can use the command to elevate privileges to gain root access to the host operating system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2947" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7231025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-278" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m9j6-927r-h9xm/GHSA-m9j6-927r-h9xm.json b/advisories/unreviewed/2025/04/GHSA-m9j6-927r-h9xm/GHSA-m9j6-927r-h9xm.json new file mode 100644 index 00000000000..92e81125346 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m9j6-927r-h9xm/GHSA-m9j6-927r-h9xm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9j6-927r-h9xm", + "modified": "2025-04-17T18:31:16Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32511" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Excellent Dynamics Make Email Customizer for WooCommerce allows Reflected XSS. This issue affects Make Email Customizer for WooCommerce: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32511" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/make-email-customizer-for-woocommerce/vulnerability/wordpress-make-email-customizer-for-woocommerce-plugin-1-0-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mfwj-jp8q-988q/GHSA-mfwj-jp8q-988q.json b/advisories/unreviewed/2025/04/GHSA-mfwj-jp8q-988q/GHSA-mfwj-jp8q-988q.json new file mode 100644 index 00000000000..2cf25e95bb5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mfwj-jp8q-988q/GHSA-mfwj-jp8q-988q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfwj-jp8q-988q", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32649" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gb-plugins GB Gallery Slideshow allows Reflected XSS. This issue affects GB Gallery Slideshow: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32649" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gb-gallery-slideshow/vulnerability/wordpress-gb-gallery-slideshow-plugin-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mjhh-qxpj-86jx/GHSA-mjhh-qxpj-86jx.json b/advisories/unreviewed/2025/04/GHSA-mjhh-qxpj-86jx/GHSA-mjhh-qxpj-86jx.json new file mode 100644 index 00000000000..da02337bd5f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mjhh-qxpj-86jx/GHSA-mjhh-qxpj-86jx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjhh-qxpj-86jx", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32626" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Job Manager allows SQL Injection. This issue affects JS Job Manager: from n/a through 2.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32626" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/js-jobs/vulnerability/wordpress-js-job-manager-plugin-2-0-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mm4q-vxrq-237x/GHSA-mm4q-vxrq-237x.json b/advisories/unreviewed/2025/04/GHSA-mm4q-vxrq-237x/GHSA-mm4q-vxrq-237x.json new file mode 100644 index 00000000000..80d7d21c29c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mm4q-vxrq-237x/GHSA-mm4q-vxrq-237x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm4q-vxrq-237x", + "modified": "2025-04-17T18:31:21Z", + "published": "2025-04-17T18:31:21Z", + "aliases": [ + "CVE-2025-39554" + ], + "details": "Missing Authorization vulnerability in Elliot Sowersby / RelyWP AI Text to Speech allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AI Text to Speech: from n/a through 3.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39554" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ai-text-to-speech/vulnerability/wordpress-ai-text-to-speech-plugin-3-0-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mr3r-8239-vc75/GHSA-mr3r-8239-vc75.json b/advisories/unreviewed/2025/04/GHSA-mr3r-8239-vc75/GHSA-mr3r-8239-vc75.json new file mode 100644 index 00000000000..701ebd9c6a9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mr3r-8239-vc75/GHSA-mr3r-8239-vc75.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr3r-8239-vc75", + "modified": "2025-04-17T18:31:12Z", + "published": "2025-04-17T18:31:12Z", + "aliases": [ + "CVE-2025-22771" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Studio Hyperset The Great Firewords of China allows Stored XSS. This issue affects The Great Firewords of China: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22771" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sensitive-chinese-words-scanner/vulnerability/wordpress-the-great-firewords-of-china-plugin-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mrgc-7pv6-7gc9/GHSA-mrgc-7pv6-7gc9.json b/advisories/unreviewed/2025/04/GHSA-mrgc-7pv6-7gc9/GHSA-mrgc-7pv6-7gc9.json new file mode 100644 index 00000000000..0e78ff403b8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mrgc-7pv6-7gc9/GHSA-mrgc-7pv6-7gc9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrgc-7pv6-7gc9", + "modified": "2025-04-17T18:31:23Z", + "published": "2025-04-17T18:31:23Z", + "aliases": [ + "CVE-2025-28101" + ], + "details": "An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to delete article titles created by other users via supplying a crafted POST request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28101" + }, + { + "type": "WEB", + "url": "https://github.com/DogukanUrker/flaskBlog/issues/130" + }, + { + "type": "WEB", + "url": "https://gist.github.com/coleak2021/cecfc757bc77038717c3e7b40e2d66ce" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mxcr-c65g-v9gr/GHSA-mxcr-c65g-v9gr.json b/advisories/unreviewed/2025/04/GHSA-mxcr-c65g-v9gr/GHSA-mxcr-c65g-v9gr.json new file mode 100644 index 00000000000..131eeae65d3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mxcr-c65g-v9gr/GHSA-mxcr-c65g-v9gr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxcr-c65g-v9gr", + "modified": "2025-04-17T18:31:12Z", + "published": "2025-04-17T18:31:12Z", + "aliases": [ + "CVE-2025-22636" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vicente Ruiz Gálvez VR-Frases allows Reflected XSS. This issue affects VR-Frases: from n/a through 3.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22636" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/vr-frases/vulnerability/wordpress-vr-frases-plugin-3-0-1-reflected-xss-to-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p2qr-9r96-6m43/GHSA-p2qr-9r96-6m43.json b/advisories/unreviewed/2025/04/GHSA-p2qr-9r96-6m43/GHSA-p2qr-9r96-6m43.json new file mode 100644 index 00000000000..fc0ea7ffbb3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p2qr-9r96-6m43/GHSA-p2qr-9r96-6m43.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2qr-9r96-6m43", + "modified": "2025-04-17T18:31:21Z", + "published": "2025-04-17T18:31:21Z", + "aliases": [ + "CVE-2025-39567" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shamalli Web Directory Free allows Reflected XSS. This issue affects Web Directory Free: from n/a through 1.7.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39567" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/web-directory-free/vulnerability/wordpress-web-directory-free-plugin-1-7-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p345-jmhp-7wg2/GHSA-p345-jmhp-7wg2.json b/advisories/unreviewed/2025/04/GHSA-p345-jmhp-7wg2/GHSA-p345-jmhp-7wg2.json index bacb6f6fff8..f299ed968b0 100644 --- a/advisories/unreviewed/2025/04/GHSA-p345-jmhp-7wg2/GHSA-p345-jmhp-7wg2.json +++ b/advisories/unreviewed/2025/04/GHSA-p345-jmhp-7wg2/GHSA-p345-jmhp-7wg2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p345-jmhp-7wg2", - "modified": "2025-04-17T06:30:35Z", + "modified": "2025-04-17T18:31:12Z", "published": "2025-04-17T06:30:35Z", "aliases": [ "CVE-2024-11924" ], "details": "The Icegram Express formerly known as Email Subscribers WordPress plugin before 5.7.52 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T06:15:42Z" diff --git a/advisories/unreviewed/2025/04/GHSA-p35x-v2w9-c8gg/GHSA-p35x-v2w9-c8gg.json b/advisories/unreviewed/2025/04/GHSA-p35x-v2w9-c8gg/GHSA-p35x-v2w9-c8gg.json new file mode 100644 index 00000000000..3c48acd3a87 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p35x-v2w9-c8gg/GHSA-p35x-v2w9-c8gg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p35x-v2w9-c8gg", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32639" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wecantrack Affiliate Links Lite allows Reflected XSS. This issue affects Affiliate Links Lite: from n/a through 3.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32639" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/affiliate-links/vulnerability/wordpress-affiliate-links-plugin-3-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p385-g496-fwgj/GHSA-p385-g496-fwgj.json b/advisories/unreviewed/2025/04/GHSA-p385-g496-fwgj/GHSA-p385-g496-fwgj.json new file mode 100644 index 00000000000..923ce00a3fe --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p385-g496-fwgj/GHSA-p385-g496-fwgj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p385-g496-fwgj", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32615" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Clinked Clinked Client Portal allows Reflected XSS. This issue affects Clinked Client Portal: from n/a through 1.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32615" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/clinked-client-portal/vulnerability/wordpress-clinked-client-portal-plugin-1-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p84q-ch5j-7frh/GHSA-p84q-ch5j-7frh.json b/advisories/unreviewed/2025/04/GHSA-p84q-ch5j-7frh/GHSA-p84q-ch5j-7frh.json new file mode 100644 index 00000000000..5135d7a7260 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p84q-ch5j-7frh/GHSA-p84q-ch5j-7frh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p84q-ch5j-7frh", + "modified": "2025-04-17T18:31:23Z", + "published": "2025-04-17T18:31:22Z", + "aliases": [ + "CVE-2024-55211" + ], + "details": "An issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55211" + }, + { + "type": "WEB", + "url": "https://github.com/micaelmaciel/CVE-2024-55211" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pf4r-g63r-22v4/GHSA-pf4r-g63r-22v4.json b/advisories/unreviewed/2025/04/GHSA-pf4r-g63r-22v4/GHSA-pf4r-g63r-22v4.json new file mode 100644 index 00000000000..dab02e04b08 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pf4r-g63r-22v4/GHSA-pf4r-g63r-22v4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf4r-g63r-22v4", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32593" + ], + "details": "Missing Authorization vulnerability in Bytes Technolab Add Product Frontend for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Add Product Frontend for WooCommerce: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32593" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/add-product-frontend-for-woocommerce/vulnerability/wordpress-add-product-frontend-for-woocommerce-plugin-1-0-6-arbitrary-content-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pg7m-r4cf-qf65/GHSA-pg7m-r4cf-qf65.json b/advisories/unreviewed/2025/04/GHSA-pg7m-r4cf-qf65/GHSA-pg7m-r4cf-qf65.json new file mode 100644 index 00000000000..13afa960add --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pg7m-r4cf-qf65/GHSA-pg7m-r4cf-qf65.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg7m-r4cf-qf65", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39532" + ], + "details": "Missing Authorization vulnerability in spicethemes Spice Blocks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Spice Blocks: from n/a through 2.0.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39532" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/spice-blocks/vulnerability/wordpress-spice-blocks-2-0-7-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pr78-wj2j-7c98/GHSA-pr78-wj2j-7c98.json b/advisories/unreviewed/2025/04/GHSA-pr78-wj2j-7c98/GHSA-pr78-wj2j-7c98.json new file mode 100644 index 00000000000..fa0db8eca6c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pr78-wj2j-7c98/GHSA-pr78-wj2j-7c98.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pr78-wj2j-7c98", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32648" + ], + "details": "Incorrect Privilege Assignment vulnerability in Projectopia Projectopia allows Privilege Escalation. This issue affects Projectopia: from n/a through 5.1.16.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32648" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/projectopia-core/vulnerability/wordpress-projectopia-project-magement-plugin-5-1-15-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pw67-xjhq-389w/GHSA-pw67-xjhq-389w.json b/advisories/unreviewed/2025/04/GHSA-pw67-xjhq-389w/GHSA-pw67-xjhq-389w.json new file mode 100644 index 00000000000..f9df0e93ceb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pw67-xjhq-389w/GHSA-pw67-xjhq-389w.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw67-xjhq-389w", + "modified": "2025-04-17T18:31:23Z", + "published": "2025-04-17T18:31:23Z", + "aliases": [ + "CVE-2024-53924" + ], + "details": "Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell, such as one beginning with the =IF(A1=200, eval(\"__import__('os').system( substring.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53924" + }, + { + "type": "WEB", + "url": "https://gist.github.com/aelmosalamy/cb098e61939718d2bb248fd1cc94f287" + }, + { + "type": "WEB", + "url": "https://github.com/dgorissen/pycel" + }, + { + "type": "WEB", + "url": "https://github.com/stephenrauch/pycel" + }, + { + "type": "WEB", + "url": "https://pypi.org/project/pycel" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pwjx-j45f-297x/GHSA-pwjx-j45f-297x.json b/advisories/unreviewed/2025/04/GHSA-pwjx-j45f-297x/GHSA-pwjx-j45f-297x.json new file mode 100644 index 00000000000..c80c40cfa4f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pwjx-j45f-297x/GHSA-pwjx-j45f-297x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwjx-j45f-297x", + "modified": "2025-04-17T18:31:13Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-23448" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dastan800 visualslider Sldier allows Reflected XSS. This issue affects visualslider Sldier: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23448" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/visual-slider/vulnerability/wordpress-visualslider-sldier-plugin-1-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q3rm-mwv6-5cgw/GHSA-q3rm-mwv6-5cgw.json b/advisories/unreviewed/2025/04/GHSA-q3rm-mwv6-5cgw/GHSA-q3rm-mwv6-5cgw.json new file mode 100644 index 00000000000..9dba6222fa5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q3rm-mwv6-5cgw/GHSA-q3rm-mwv6-5cgw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3rm-mwv6-5cgw", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-27308" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmstactics WP Video Posts allows Reflected XSS. This issue affects WP Video Posts: from n/a through 3.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27308" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-video-posts/vulnerability/wordpress-wp-video-posts-plugin-3-5-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q4w9-wq5p-crrq/GHSA-q4w9-wq5p-crrq.json b/advisories/unreviewed/2025/04/GHSA-q4w9-wq5p-crrq/GHSA-q4w9-wq5p-crrq.json new file mode 100644 index 00000000000..6565cc1e2ce --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q4w9-wq5p-crrq/GHSA-q4w9-wq5p-crrq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4w9-wq5p-crrq", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-27309" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeannot Muller flickr-slideshow-wrapper allows Stored XSS. This issue affects flickr-slideshow-wrapper: from n/a through 5.4.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27309" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/flickr-slideshow-wrapper/vulnerability/wordpress-flickr-slideshow-wrapper-plugin-5-4-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q7ph-3vqh-ww9q/GHSA-q7ph-3vqh-ww9q.json b/advisories/unreviewed/2025/04/GHSA-q7ph-3vqh-ww9q/GHSA-q7ph-3vqh-ww9q.json new file mode 100644 index 00000000000..b102db0a865 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q7ph-3vqh-ww9q/GHSA-q7ph-3vqh-ww9q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7ph-3vqh-ww9q", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32562" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com WP Easy Poll allows Reflected XSS. This issue affects WP Easy Poll: from n/a through 2.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32562" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-easy-poll-afo/vulnerability/wordpress-wp-easy-poll-plugin-2-2-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q7rh-q727-h4mw/GHSA-q7rh-q727-h4mw.json b/advisories/unreviewed/2025/04/GHSA-q7rh-q727-h4mw/GHSA-q7rh-q727-h4mw.json new file mode 100644 index 00000000000..25bf6f146fd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q7rh-q727-h4mw/GHSA-q7rh-q727-h4mw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7rh-q727-h4mw", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:14Z", + "aliases": [ + "CVE-2025-27287" + ], + "details": "Deserialization of Untrusted Data vulnerability in ssvadim SS Quiz allows Object Injection. This issue affects SS Quiz: from n/a through 2.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27287" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ssquiz/vulnerability/wordpress-ss-quiz-plugin-2-0-5-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q8hq-xhpc-vm95/GHSA-q8hq-xhpc-vm95.json b/advisories/unreviewed/2025/04/GHSA-q8hq-xhpc-vm95/GHSA-q8hq-xhpc-vm95.json new file mode 100644 index 00000000000..e84b1915adf --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q8hq-xhpc-vm95/GHSA-q8hq-xhpc-vm95.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8hq-xhpc-vm95", + "modified": "2025-04-17T18:31:22Z", + "published": "2025-04-17T18:31:22Z", + "aliases": [ + "CVE-2025-29180" + ], + "details": "In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability. The url_prefix, domain, and my_website POST parameters are directly concatenated into SQL statements without filtering.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29180" + }, + { + "type": "WEB", + "url": "https://gist.github.com/X1lyS/5075ba1e6bebff26fcd58609493fd5f2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T17:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q926-pj8q-72f7/GHSA-q926-pj8q-72f7.json b/advisories/unreviewed/2025/04/GHSA-q926-pj8q-72f7/GHSA-q926-pj8q-72f7.json new file mode 100644 index 00000000000..f3c4f5dc9ce --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q926-pj8q-72f7/GHSA-q926-pj8q-72f7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q926-pj8q-72f7", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39435" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in davidfcarr My Marginalia allows Stored XSS. This issue affects My Marginalia: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39435" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/my-marginalia/vulnerability/wordpress-my-marginalia-plugin-1-0-6-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qfxg-9wg2-4r2v/GHSA-qfxg-9wg2-4r2v.json b/advisories/unreviewed/2025/04/GHSA-qfxg-9wg2-4r2v/GHSA-qfxg-9wg2-4r2v.json new file mode 100644 index 00000000000..243f2d8e3fd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qfxg-9wg2-4r2v/GHSA-qfxg-9wg2-4r2v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfxg-9wg2-4r2v", + "modified": "2025-04-17T18:31:16Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32545" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in SOFTAGON WooCommerce Products without featured images allows Reflected XSS. This issue affects WooCommerce Products without featured images: from n/a through 0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32545" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-products-without-featured-images/vulnerability/wordpress-woocommerce-products-without-featured-images-plugin-0-1-csrf-to-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qg7m-x7h8-fwj3/GHSA-qg7m-x7h8-fwj3.json b/advisories/unreviewed/2025/04/GHSA-qg7m-x7h8-fwj3/GHSA-qg7m-x7h8-fwj3.json new file mode 100644 index 00000000000..da167350e54 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qg7m-x7h8-fwj3/GHSA-qg7m-x7h8-fwj3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg7m-x7h8-fwj3", + "modified": "2025-04-17T18:31:16Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32526" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allows Reflected XSS. This issue affects Zephyr Project Manager: from n/a through 3.3.101.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32526" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/zephyr-project-manager/vulnerability/wordpress-zephyr-project-manager-plugin-3-3-105-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qgj9-7q8h-gp49/GHSA-qgj9-7q8h-gp49.json b/advisories/unreviewed/2025/04/GHSA-qgj9-7q8h-gp49/GHSA-qgj9-7q8h-gp49.json new file mode 100644 index 00000000000..1a1871c5a24 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qgj9-7q8h-gp49/GHSA-qgj9-7q8h-gp49.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgj9-7q8h-gp49", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-29043" + ], + "details": "An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29043" + }, + { + "type": "WEB", + "url": "https://gist.github.com/xyqer1/d5a5b18743b7a2fcbc0f93001d8e2ad9" + }, + { + "type": "WEB", + "url": "https://github.com/xyqer1/Dlink-dir-823x-diag_traceroute-target_addr-CommandInjection" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qhp6-vp7c-g7xp/GHSA-qhp6-vp7c-g7xp.json b/advisories/unreviewed/2025/04/GHSA-qhp6-vp7c-g7xp/GHSA-qhp6-vp7c-g7xp.json deleted file mode 100644 index e56ddecfca5..00000000000 --- a/advisories/unreviewed/2025/04/GHSA-qhp6-vp7c-g7xp/GHSA-qhp6-vp7c-g7xp.json +++ /dev/null @@ -1,36 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-qhp6-vp7c-g7xp", - "modified": "2025-04-17T15:32:35Z", - "published": "2025-04-17T15:32:35Z", - "aliases": [ - "CVE-2025-3760" - ], - "details": "A stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Liferay Portal 7.2.0 through 7.4.3.129, and Liferay DXP 2024.Q4.1 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, 7.3 GA through update 36, and 7.2 GA through fix pack 20 allows remote authenticated attackers to inject malicious JavaScript into a page.", - "severity": [ - { - "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3760" - }, - { - "type": "WEB", - "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-3760" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-04-17T13:15:41Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qrcg-ch7v-h2pp/GHSA-qrcg-ch7v-h2pp.json b/advisories/unreviewed/2025/04/GHSA-qrcg-ch7v-h2pp/GHSA-qrcg-ch7v-h2pp.json new file mode 100644 index 00000000000..9d25c46a7f3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qrcg-ch7v-h2pp/GHSA-qrcg-ch7v-h2pp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrcg-ch7v-h2pp", + "modified": "2025-04-17T18:31:12Z", + "published": "2025-04-17T18:31:12Z", + "aliases": [ + "CVE-2025-23443" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Claire Ryan Author Showcase allows Reflected XSS. This issue affects Author Showcase: from n/a through 1.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23443" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/author-showcase/vulnerability/wordpress-author-showcase-plugin-1-4-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qv7q-mmqf-j634/GHSA-qv7q-mmqf-j634.json b/advisories/unreviewed/2025/04/GHSA-qv7q-mmqf-j634/GHSA-qv7q-mmqf-j634.json new file mode 100644 index 00000000000..882fb19db86 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qv7q-mmqf-j634/GHSA-qv7q-mmqf-j634.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv7q-mmqf-j634", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39444" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in maxfoundry MaxButtons allows Stored XSS. This issue affects MaxButtons: from n/a through 9.8.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39444" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/maxbuttons/vulnerability/wordpress-maxbuttons-plugin-9-8-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qvww-5m45-9x54/GHSA-qvww-5m45-9x54.json b/advisories/unreviewed/2025/04/GHSA-qvww-5m45-9x54/GHSA-qvww-5m45-9x54.json new file mode 100644 index 00000000000..0a44e5fbb0c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qvww-5m45-9x54/GHSA-qvww-5m45-9x54.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvww-5m45-9x54", + "modified": "2025-04-17T18:31:23Z", + "published": "2025-04-17T18:31:23Z", + "aliases": [ + "CVE-2025-25455" + ], + "details": "Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanMTU2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25455" + }, + { + "type": "WEB", + "url": "https://gist.github.com/xyqer1/6c865a9ec44b4797e78b6765cd5c84e5" + }, + { + "type": "WEB", + "url": "https://github.com/xyqer1/Tenda-AC10-AdvSetMacMtuWan-wanMTU2-StackOverflow" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qw3m-c4wf-4832/GHSA-qw3m-c4wf-4832.json b/advisories/unreviewed/2025/04/GHSA-qw3m-c4wf-4832/GHSA-qw3m-c4wf-4832.json new file mode 100644 index 00000000000..992e47c50e5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qw3m-c4wf-4832/GHSA-qw3m-c4wf-4832.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw3m-c4wf-4832", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32651" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in serpednet SERPed.net allows Reflected XSS. This issue affects SERPed.net: from n/a through 4.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32651" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/serped-net/vulnerability/wordpress-serped-net-plugin-4-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qxwh-j7j4-29g4/GHSA-qxwh-j7j4-29g4.json b/advisories/unreviewed/2025/04/GHSA-qxwh-j7j4-29g4/GHSA-qxwh-j7j4-29g4.json new file mode 100644 index 00000000000..cbf11c58753 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qxwh-j7j4-29g4/GHSA-qxwh-j7j4-29g4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxwh-j7j4-29g4", + "modified": "2025-04-17T18:31:13Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-24577" + ], + "details": "Missing Authorization vulnerability in Ays Pro Poll Maker allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Poll Maker: from n/a through 5.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24577" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/poll-maker/vulnerability/wordpress-poll-maker-plugin-5-5-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r5xc-x759-88vq/GHSA-r5xc-x759-88vq.json b/advisories/unreviewed/2025/04/GHSA-r5xc-x759-88vq/GHSA-r5xc-x759-88vq.json new file mode 100644 index 00000000000..1f3bd0f6037 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r5xc-x759-88vq/GHSA-r5xc-x759-88vq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5xc-x759-88vq", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:19Z", + "aliases": [ + "CVE-2025-39425" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in pixelgrade Style Manager allows Cross Site Request Forgery. This issue affects Style Manager: from n/a through 2.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39425" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/style-manager/vulnerability/wordpress-style-manager-plugin-2-2-7-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r75q-38f6-x3q4/GHSA-r75q-38f6-x3q4.json b/advisories/unreviewed/2025/04/GHSA-r75q-38f6-x3q4/GHSA-r75q-38f6-x3q4.json new file mode 100644 index 00000000000..cee808b5ee2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r75q-38f6-x3q4/GHSA-r75q-38f6-x3q4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r75q-38f6-x3q4", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32596" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in Rameez Iqbal Real Estate Manager allows Code Injection. This issue affects Real Estate Manager: from n/a through 7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32596" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/real-estate-manager/vulnerability/wordpress-real-estate-manager-plugin-7-3-arbitrary-code-execution-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r966-h552-5m23/GHSA-r966-h552-5m23.json b/advisories/unreviewed/2025/04/GHSA-r966-h552-5m23/GHSA-r966-h552-5m23.json new file mode 100644 index 00000000000..0adcd984c7e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r966-h552-5m23/GHSA-r966-h552-5m23.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r966-h552-5m23", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32635" + ], + "details": "Insertion of Sensitive Information Into Sent Data vulnerability in Hive Support Hive Support allows Retrieve Embedded Sensitive Data. This issue affects Hive Support: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32635" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hive-support/vulnerability/wordpress-hive-support-plugin-1-2-2-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r97x-rr73-8hq7/GHSA-r97x-rr73-8hq7.json b/advisories/unreviewed/2025/04/GHSA-r97x-rr73-8hq7/GHSA-r97x-rr73-8hq7.json new file mode 100644 index 00000000000..9f62bf72768 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r97x-rr73-8hq7/GHSA-r97x-rr73-8hq7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r97x-rr73-8hq7", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-31006" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arete-it Activity Reactions For Buddypress allows Reflected XSS. This issue affects Activity Reactions For Buddypress: from n/a through 1.0.22.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31006" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/activity-reactions-for-buddypress/vulnerability/wordpress-activity-reactions-for-buddypress-plugin-1-0-22-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r9mj-87fj-738h/GHSA-r9mj-87fj-738h.json b/advisories/unreviewed/2025/04/GHSA-r9mj-87fj-738h/GHSA-r9mj-87fj-738h.json new file mode 100644 index 00000000000..de150a13446 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r9mj-87fj-738h/GHSA-r9mj-87fj-738h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9mj-87fj-738h", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-31380" + ], + "details": "Weak Password Recovery Mechanism for Forgotten Password vulnerability in videowhisper Paid Videochat Turnkey Site allows Password Recovery Exploitation. This issue affects Paid Videochat Turnkey Site: from n/a through 7.3.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31380" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ppv-live-webcams/vulnerability/wordpress-paid-videochat-turnkey-site-7-3-5-broken-authentication-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-640" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rfw7-86w9-7qh3/GHSA-rfw7-86w9-7qh3.json b/advisories/unreviewed/2025/04/GHSA-rfw7-86w9-7qh3/GHSA-rfw7-86w9-7qh3.json new file mode 100644 index 00000000000..be1a66a465f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rfw7-86w9-7qh3/GHSA-rfw7-86w9-7qh3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfw7-86w9-7qh3", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39432" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in antonchanning bbPress2 shortcode whitelist allows Stored XSS. This issue affects bbPress2 shortcode whitelist: from n/a through 2.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39432" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bbpress2-shortcode-whitelist/vulnerability/wordpress-bbpress2-shortcode-whitelist-plugin-2-2-1-csrf-to-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rg9h-f5v4-xwfp/GHSA-rg9h-f5v4-xwfp.json b/advisories/unreviewed/2025/04/GHSA-rg9h-f5v4-xwfp/GHSA-rg9h-f5v4-xwfp.json new file mode 100644 index 00000000000..24268872196 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rg9h-f5v4-xwfp/GHSA-rg9h-f5v4-xwfp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg9h-f5v4-xwfp", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:14Z", + "aliases": [ + "CVE-2025-25457" + ], + "details": "Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via cloneType2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25457" + }, + { + "type": "WEB", + "url": "https://gist.github.com/xyqer1/f69ebbdec019cacf5870ea55e25780a4" + }, + { + "type": "WEB", + "url": "https://github.com/xyqer1/Tenda-AC10-AdvSetMacMtuWan-cloneType2-StackOverflow" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rgfv-cmfv-jcmm/GHSA-rgfv-cmfv-jcmm.json b/advisories/unreviewed/2025/04/GHSA-rgfv-cmfv-jcmm/GHSA-rgfv-cmfv-jcmm.json new file mode 100644 index 00000000000..175003bbd02 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rgfv-cmfv-jcmm/GHSA-rgfv-cmfv-jcmm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgfv-cmfv-jcmm", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32573" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kiotviet KiotViet Sync allows SQL Injection. This issue affects KiotViet Sync: from n/a through 1.8.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32573" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/kiotvietsync/vulnerability/wordpress-kiotviet-sync-plugin-1-8-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rm3r-mw49-623x/GHSA-rm3r-mw49-623x.json b/advisories/unreviewed/2025/04/GHSA-rm3r-mw49-623x/GHSA-rm3r-mw49-623x.json new file mode 100644 index 00000000000..9c7c9e58fdc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rm3r-mw49-623x/GHSA-rm3r-mw49-623x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rm3r-mw49-623x", + "modified": "2025-04-17T18:31:12Z", + "published": "2025-04-17T18:31:12Z", + "aliases": [ + "CVE-2025-22340" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 Data Dash allows Stored XSS. This issue affects Data Dash: from n/a through 1.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22340" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/data-dash/vulnerability/wordpress-data-dash-plugin-1-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rqqc-5wmj-43vx/GHSA-rqqc-5wmj-43vx.json b/advisories/unreviewed/2025/04/GHSA-rqqc-5wmj-43vx/GHSA-rqqc-5wmj-43vx.json new file mode 100644 index 00000000000..0fa87757866 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rqqc-5wmj-43vx/GHSA-rqqc-5wmj-43vx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqqc-5wmj-43vx", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32592" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 TableOn – WordPress Posts Table Filterable allows Stored XSS. This issue affects TableOn – WordPress Posts Table Filterable: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32592" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/posts-table-filterable/vulnerability/wordpress-tableon-plugin-1-0-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rx8q-xg7h-mqpc/GHSA-rx8q-xg7h-mqpc.json b/advisories/unreviewed/2025/04/GHSA-rx8q-xg7h-mqpc/GHSA-rx8q-xg7h-mqpc.json new file mode 100644 index 00000000000..1b9b9d580bd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rx8q-xg7h-mqpc/GHSA-rx8q-xg7h-mqpc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx8q-xg7h-mqpc", + "modified": "2025-04-17T18:31:13Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-23855" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fyljp SpiderDisplay allows Reflected XSS. This issue affects SpiderDisplay: from n/a through 1.9.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23855" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/spiderdisplay/vulnerability/wordpress-spiderdisplay-plugin-1-9-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rxcr-p59f-9j2p/GHSA-rxcr-p59f-9j2p.json b/advisories/unreviewed/2025/04/GHSA-rxcr-p59f-9j2p/GHSA-rxcr-p59f-9j2p.json new file mode 100644 index 00000000000..5515935884b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rxcr-p59f-9j2p/GHSA-rxcr-p59f-9j2p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxcr-p59f-9j2p", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39464" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rtowebsites AdminQuickbar allows Reflected XSS. This issue affects AdminQuickbar: from n/a through 1.9.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39464" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/adminquickbar/vulnerability/wordpress-adminquickbar-plugin-1-9-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v5hr-3xch-9h65/GHSA-v5hr-3xch-9h65.json b/advisories/unreviewed/2025/04/GHSA-v5hr-3xch-9h65/GHSA-v5hr-3xch-9h65.json new file mode 100644 index 00000000000..83060dde888 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v5hr-3xch-9h65/GHSA-v5hr-3xch-9h65.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5hr-3xch-9h65", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32544" + ], + "details": "Missing Authorization vulnerability in The Right Software WooCommerce Loyal Customers allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WooCommerce Loyal Customers: from n/a through 2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32544" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-loyal-customer/vulnerability/wordpress-woocommerce-loyal-customers-plugin-2-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v6gv-mxw6-5v85/GHSA-v6gv-mxw6-5v85.json b/advisories/unreviewed/2025/04/GHSA-v6gv-mxw6-5v85/GHSA-v6gv-mxw6-5v85.json new file mode 100644 index 00000000000..03808298605 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v6gv-mxw6-5v85/GHSA-v6gv-mxw6-5v85.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6gv-mxw6-5v85", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:14Z", + "aliases": [ + "CVE-2025-24637" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Beacon Lead Magnets and Lead Capture allows Reflected XSS. This issue affects Beacon Lead Magnets and Lead Capture: from n/a through 1.5.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24637" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/beacon-by/vulnerability/wordpress-beacon-lead-magnets-and-lead-capture-plugin-1-5-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v8vm-8h6v-g2gc/GHSA-v8vm-8h6v-g2gc.json b/advisories/unreviewed/2025/04/GHSA-v8vm-8h6v-g2gc/GHSA-v8vm-8h6v-g2gc.json new file mode 100644 index 00000000000..2bee43c0b17 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v8vm-8h6v-g2gc/GHSA-v8vm-8h6v-g2gc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8vm-8h6v-g2gc", + "modified": "2025-04-17T18:31:12Z", + "published": "2025-04-17T18:31:12Z", + "aliases": [ + "CVE-2024-56518" + ], + "details": "Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelcast-client XML document (aka a client configuration file), which can be uploaded at the /cluster-connections URI.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56518" + }, + { + "type": "WEB", + "url": "https://docs.hazelcast.com/management-center/6.0-snapshot/getting-started/install" + }, + { + "type": "WEB", + "url": "https://gist.github.com/azraelxuemo/c3d42739aa3306a41111ef603dc65b4c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vffm-x88v-8g8q/GHSA-vffm-x88v-8g8q.json b/advisories/unreviewed/2025/04/GHSA-vffm-x88v-8g8q/GHSA-vffm-x88v-8g8q.json new file mode 100644 index 00000000000..3191a8fab07 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vffm-x88v-8g8q/GHSA-vffm-x88v-8g8q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vffm-x88v-8g8q", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32582" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EXEIdeas International WP AutoKeyword allows Stored XSS. This issue affects WP AutoKeyword: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32582" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-autokeyword/vulnerability/wordpress-wp-autokeyword-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vg2x-3jwm-cf33/GHSA-vg2x-3jwm-cf33.json b/advisories/unreviewed/2025/04/GHSA-vg2x-3jwm-cf33/GHSA-vg2x-3jwm-cf33.json new file mode 100644 index 00000000000..167afbe68e6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vg2x-3jwm-cf33/GHSA-vg2x-3jwm-cf33.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg2x-3jwm-cf33", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39462" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in teamzt Smart Agreements allows PHP Local File Inclusion. This issue affects Smart Agreements: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39462" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/smart-agreements/vulnerability/wordpress-smart-agreements-plugin-1-0-3-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vj5m-95mx-p87m/GHSA-vj5m-95mx-p87m.json b/advisories/unreviewed/2025/04/GHSA-vj5m-95mx-p87m/GHSA-vj5m-95mx-p87m.json new file mode 100644 index 00000000000..4948069ee4c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vj5m-95mx-p87m/GHSA-vj5m-95mx-p87m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vj5m-95mx-p87m", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32588" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Credova Financial Credova_Financial allows Reflected XSS. This issue affects Credova_Financial: from n/a through 2.4.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32588" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/credova-financial/vulnerability/wordpress-credova-financial-plugin-2-4-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vjp9-wj82-f2jp/GHSA-vjp9-wj82-f2jp.json b/advisories/unreviewed/2025/04/GHSA-vjp9-wj82-f2jp/GHSA-vjp9-wj82-f2jp.json new file mode 100644 index 00000000000..71e9d3b80f4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vjp9-wj82-f2jp/GHSA-vjp9-wj82-f2jp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjp9-wj82-f2jp", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-27345" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Deetronix Booking Ultra Pro allows Reflected XSS. This issue affects Booking Ultra Pro: from n/a through 1.1.19.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27345" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/booking-ultra-pro/vulnerability/wordpress-booking-ultra-pro-plugin-1-1-18-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vp5j-wh2p-73xx/GHSA-vp5j-wh2p-73xx.json b/advisories/unreviewed/2025/04/GHSA-vp5j-wh2p-73xx/GHSA-vp5j-wh2p-73xx.json new file mode 100644 index 00000000000..02896199cf0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vp5j-wh2p-73xx/GHSA-vp5j-wh2p-73xx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp5j-wh2p-73xx", + "modified": "2025-04-17T18:31:12Z", + "published": "2025-04-17T18:31:12Z", + "aliases": [ + "CVE-2025-22774" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRUDLab CRUDLab Scroll to Top allows Reflected XSS. This issue affects CRUDLab Scroll to Top: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22774" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/crudlab-scroll-to-top/vulnerability/wordpress-crudlab-scroll-to-top-plugin-1-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vpqx-hfvj-cf26/GHSA-vpqx-hfvj-cf26.json b/advisories/unreviewed/2025/04/GHSA-vpqx-hfvj-cf26/GHSA-vpqx-hfvj-cf26.json new file mode 100644 index 00000000000..e5bdd4db057 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vpqx-hfvj-cf26/GHSA-vpqx-hfvj-cf26.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpqx-hfvj-cf26", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:14Z", + "aliases": [ + "CVE-2025-27295" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpion Live css allows Stored XSS. This issue affects Live css: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27295" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/css-live/vulnerability/wordpress-live-css-plugin-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vv26-66vw-jjwc/GHSA-vv26-66vw-jjwc.json b/advisories/unreviewed/2025/04/GHSA-vv26-66vw-jjwc/GHSA-vv26-66vw-jjwc.json new file mode 100644 index 00000000000..30bc94e11bc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vv26-66vw-jjwc/GHSA-vv26-66vw-jjwc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv26-66vw-jjwc", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-27314" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kush Sharma Kush Micro News allows Stored XSS. This issue affects Kush Micro News: from n/a through 1.6.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27314" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/kush-micro-news/vulnerability/wordpress-kush-micro-news-plugin-1-6-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vv78-wwrv-7mgx/GHSA-vv78-wwrv-7mgx.json b/advisories/unreviewed/2025/04/GHSA-vv78-wwrv-7mgx/GHSA-vv78-wwrv-7mgx.json new file mode 100644 index 00000000000..c1a5ad087c0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vv78-wwrv-7mgx/GHSA-vv78-wwrv-7mgx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv78-wwrv-7mgx", + "modified": "2025-04-17T18:31:13Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-24550" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JobScore Job Manager allows Stored XSS. This issue affects Job Manager: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24550" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/job-manager-by-jobscore/vulnerability/wordpress-job-manager-plugin-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vx4g-5f82-hww5/GHSA-vx4g-5f82-hww5.json b/advisories/unreviewed/2025/04/GHSA-vx4g-5f82-hww5/GHSA-vx4g-5f82-hww5.json new file mode 100644 index 00000000000..1fd672e1729 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vx4g-5f82-hww5/GHSA-vx4g-5f82-hww5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx4g-5f82-hww5", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-27310" + ], + "details": "Missing Authorization vulnerability in Radius of Thought Page and Post Lister allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Page and Post Lister: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27310" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/page-and-post-lister/vulnerability/wordpress-page-and-post-lister-plugin-1-2-1-arbitrary-content-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w33v-rv28-x6m6/GHSA-w33v-rv28-x6m6.json b/advisories/unreviewed/2025/04/GHSA-w33v-rv28-x6m6/GHSA-w33v-rv28-x6m6.json new file mode 100644 index 00000000000..68de2225a93 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w33v-rv28-x6m6/GHSA-w33v-rv28-x6m6.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w33v-rv28-x6m6", + "modified": "2025-04-17T18:31:23Z", + "published": "2025-04-17T18:31:23Z", + "aliases": [ + "CVE-2025-26268" + ], + "details": "DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. The validity of the scan cursor was not checked.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26268" + }, + { + "type": "WEB", + "url": "https://github.com/dragonflydb/dragonfly/issues/4466" + }, + { + "type": "WEB", + "url": "https://github.com/dragonflydb/dragonfly/commit/d1fac0f912edb323a2bdd6404c518cda21eac243" + }, + { + "type": "WEB", + "url": "https://github.com/dragonflydb/dragonfly/compare/v1.26.4...v1.27.0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-392" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w4pq-45h8-g86g/GHSA-w4pq-45h8-g86g.json b/advisories/unreviewed/2025/04/GHSA-w4pq-45h8-g86g/GHSA-w4pq-45h8-g86g.json new file mode 100644 index 00000000000..fe4fdde0a86 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w4pq-45h8-g86g/GHSA-w4pq-45h8-g86g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4pq-45h8-g86g", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:19Z", + "aliases": [ + "CVE-2025-39416" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ichi translit it! allows Stored XSS. This issue affects translit it!: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39416" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/translit-it/vulnerability/wordpress-translit-it-plugin-1-6-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w8fw-fj9q-vcjj/GHSA-w8fw-fj9q-vcjj.json b/advisories/unreviewed/2025/04/GHSA-w8fw-fj9q-vcjj/GHSA-w8fw-fj9q-vcjj.json new file mode 100644 index 00000000000..f1260546735 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w8fw-fj9q-vcjj/GHSA-w8fw-fj9q-vcjj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8fw-fj9q-vcjj", + "modified": "2025-04-17T18:31:22Z", + "published": "2025-04-17T18:31:22Z", + "aliases": [ + "CVE-2025-32415" + ], + "details": "In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32415" + }, + { + "type": "WEB", + "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/890" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w8q3-52g7-3q2f/GHSA-w8q3-52g7-3q2f.json b/advisories/unreviewed/2025/04/GHSA-w8q3-52g7-3q2f/GHSA-w8q3-52g7-3q2f.json new file mode 100644 index 00000000000..77dd7bca573 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w8q3-52g7-3q2f/GHSA-w8q3-52g7-3q2f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8q3-52g7-3q2f", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32604" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sajjad Aslani AWSA Shipping allows Reflected XSS. This issue affects AWSA Shipping: from n/a through 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32604" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/awsa-shipping/vulnerability/wordpress-awsa-shipping-plugin-1-3-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wcgh-c8p6-5fwq/GHSA-wcgh-c8p6-5fwq.json b/advisories/unreviewed/2025/04/GHSA-wcgh-c8p6-5fwq/GHSA-wcgh-c8p6-5fwq.json new file mode 100644 index 00000000000..179d1ee4785 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wcgh-c8p6-5fwq/GHSA-wcgh-c8p6-5fwq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcgh-c8p6-5fwq", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32637" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ketanajani WP Donate allows Stored XSS. This issue affects WP Donate: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32637" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-donate/vulnerability/wordpress-wp-donate-plugin-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wgr3-wff7-cf8m/GHSA-wgr3-wff7-cf8m.json b/advisories/unreviewed/2025/04/GHSA-wgr3-wff7-cf8m/GHSA-wgr3-wff7-cf8m.json new file mode 100644 index 00000000000..136d2ca390e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wgr3-wff7-cf8m/GHSA-wgr3-wff7-cf8m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgr3-wff7-cf8m", + "modified": "2025-04-17T18:31:21Z", + "published": "2025-04-17T18:31:21Z", + "aliases": [ + "CVE-2025-39595" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Quentn.com GmbH Quentn WP allows SQL Injection. This issue affects Quentn WP: from n/a through 1.2.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39595" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quentn-wp/vulnerability/wordpress-quentn-wp-1-2-8-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wh2m-mw53-r7px/GHSA-wh2m-mw53-r7px.json b/advisories/unreviewed/2025/04/GHSA-wh2m-mw53-r7px/GHSA-wh2m-mw53-r7px.json new file mode 100644 index 00000000000..3a2eb5aa452 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wh2m-mw53-r7px/GHSA-wh2m-mw53-r7px.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh2m-mw53-r7px", + "modified": "2025-04-17T18:31:12Z", + "published": "2025-04-17T18:31:12Z", + "aliases": [ + "CVE-2025-22565" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bill Zimmerman vooPlayer v4 allows Reflected XSS. This issue affects vooPlayer v4: from n/a through 4.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22565" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/vooplayer/vulnerability/wordpress-vooplayer-v4-plugin-4-0-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wjrq-hhc6-x6hr/GHSA-wjrq-hhc6-x6hr.json b/advisories/unreviewed/2025/04/GHSA-wjrq-hhc6-x6hr/GHSA-wjrq-hhc6-x6hr.json new file mode 100644 index 00000000000..80fc7bf979b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wjrq-hhc6-x6hr/GHSA-wjrq-hhc6-x6hr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjrq-hhc6-x6hr", + "modified": "2025-04-17T18:31:12Z", + "published": "2025-04-17T18:31:12Z", + "aliases": [ + "CVE-2025-22651" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wppluginboxdev Stylish Google Sheet Reader allows Reflected XSS. This issue affects Stylish Google Sheet Reader: from n/a through 4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22651" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/stylish-google-sheet-reader/vulnerability/wordpress-stylish-google-sheet-reader-plugin-4-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wp8g-3fhq-9g29/GHSA-wp8g-3fhq-9g29.json b/advisories/unreviewed/2025/04/GHSA-wp8g-3fhq-9g29/GHSA-wp8g-3fhq-9g29.json new file mode 100644 index 00000000000..9562d8b486a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wp8g-3fhq-9g29/GHSA-wp8g-3fhq-9g29.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp8g-3fhq-9g29", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:19Z", + "aliases": [ + "CVE-2025-39418" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ajayver RSS Manager allows Stored XSS. This issue affects RSS Manager: from n/a through 0.06.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39418" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rss-manager/vulnerability/wordpress-rss-manager-plugin-0-06-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wr7v-fhc6-8f6q/GHSA-wr7v-fhc6-8f6q.json b/advisories/unreviewed/2025/04/GHSA-wr7v-fhc6-8f6q/GHSA-wr7v-fhc6-8f6q.json new file mode 100644 index 00000000000..f1ab8582d68 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wr7v-fhc6-8f6q/GHSA-wr7v-fhc6-8f6q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr7v-fhc6-8f6q", + "modified": "2025-04-17T18:31:21Z", + "published": "2025-04-17T18:31:21Z", + "aliases": [ + "CVE-2025-39569" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in taskbuilder Taskbuilder allows Blind SQL Injection. This issue affects Taskbuilder: from n/a through 4.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39569" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/taskbuilder/vulnerability/wordpress-taskbuilder-4-0-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ww79-gcmc-7fqx/GHSA-ww79-gcmc-7fqx.json b/advisories/unreviewed/2025/04/GHSA-ww79-gcmc-7fqx/GHSA-ww79-gcmc-7fqx.json new file mode 100644 index 00000000000..71b84a71584 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ww79-gcmc-7fqx/GHSA-ww79-gcmc-7fqx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww79-gcmc-7fqx", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:19Z", + "aliases": [ + "CVE-2025-39419" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in David Miller Revision Diet allows Stored XSS. This issue affects Revision Diet: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39419" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/revision-diet/vulnerability/wordpress-revision-diet-plugin-1-0-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wwhc-9g9r-776m/GHSA-wwhc-9g9r-776m.json b/advisories/unreviewed/2025/04/GHSA-wwhc-9g9r-776m/GHSA-wwhc-9g9r-776m.json index 13b60e98195..90cdf1ba76c 100644 --- a/advisories/unreviewed/2025/04/GHSA-wwhc-9g9r-776m/GHSA-wwhc-9g9r-776m.json +++ b/advisories/unreviewed/2025/04/GHSA-wwhc-9g9r-776m/GHSA-wwhc-9g9r-776m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-wwj8-vw56-c53c/GHSA-wwj8-vw56-c53c.json b/advisories/unreviewed/2025/04/GHSA-wwj8-vw56-c53c/GHSA-wwj8-vw56-c53c.json new file mode 100644 index 00000000000..8ac92a3e5f0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wwj8-vw56-c53c/GHSA-wwj8-vw56-c53c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwj8-vw56-c53c", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39527" + ], + "details": "Deserialization of Untrusted Data vulnerability in bestwebsoft Rating by BestWebSoft allows Object Injection. This issue affects Rating by BestWebSoft: from n/a through 1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39527" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rating-bws/vulnerability/wordpress-rating-by-bestwebsoft-1-7-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x259-v4c5-x856/GHSA-x259-v4c5-x856.json b/advisories/unreviewed/2025/04/GHSA-x259-v4c5-x856/GHSA-x259-v4c5-x856.json new file mode 100644 index 00000000000..1de1d9d1dbe --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x259-v4c5-x856/GHSA-x259-v4c5-x856.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x259-v4c5-x856", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39526" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nicdark Hotel Booking allows PHP Local File Inclusion. This issue affects Hotel Booking: from n/a through 3.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39526" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nd-booking/vulnerability/wordpress-hotel-booking-plugin-3-6-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x29x-qf6c-w9cj/GHSA-x29x-qf6c-w9cj.json b/advisories/unreviewed/2025/04/GHSA-x29x-qf6c-w9cj/GHSA-x29x-qf6c-w9cj.json index 23d234afe6c..48937229d23 100644 --- a/advisories/unreviewed/2025/04/GHSA-x29x-qf6c-w9cj/GHSA-x29x-qf6c-w9cj.json +++ b/advisories/unreviewed/2025/04/GHSA-x29x-qf6c-w9cj/GHSA-x29x-qf6c-w9cj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-x4f2-5v59-538p/GHSA-x4f2-5v59-538p.json b/advisories/unreviewed/2025/04/GHSA-x4f2-5v59-538p/GHSA-x4f2-5v59-538p.json new file mode 100644 index 00000000000..cfe57b4ad92 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x4f2-5v59-538p/GHSA-x4f2-5v59-538p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4f2-5v59-538p", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:19Z", + "aliases": [ + "CVE-2025-39426" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in illow illow – Cookies Consent allows Cross Site Request Forgery. This issue affects illow – Cookies Consent: from n/a through 0.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39426" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lgpd-compliant-cookie-banner/vulnerability/wordpress-illow-cookies-consent-plugin-0-2-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x7h2-q5j9-qrmx/GHSA-x7h2-q5j9-qrmx.json b/advisories/unreviewed/2025/04/GHSA-x7h2-q5j9-qrmx/GHSA-x7h2-q5j9-qrmx.json new file mode 100644 index 00000000000..4f270aeffc5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x7h2-q5j9-qrmx/GHSA-x7h2-q5j9-qrmx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7h2-q5j9-qrmx", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32630" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CMSJunkie - WordPress Business Directory Plugins WP-BusinessDirectory allows Reflected XSS. This issue affects WP-BusinessDirectory: from n/a through 3.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32630" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-businessdirectory/vulnerability/wordpress-wp-businessdirectory-plugin-3-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x86c-4rx9-m7gw/GHSA-x86c-4rx9-m7gw.json b/advisories/unreviewed/2025/04/GHSA-x86c-4rx9-m7gw/GHSA-x86c-4rx9-m7gw.json new file mode 100644 index 00000000000..25a548a1070 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x86c-4rx9-m7gw/GHSA-x86c-4rx9-m7gw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x86c-4rx9-m7gw", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-27354" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phil88530 Simple Email Subscriber allows Reflected XSS. This issue affects Simple Email Subscriber: from n/a through 2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27354" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-email-subscriber/vulnerability/wordpress-simple-email-subscriber-plugin-2-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x8pm-wrg2-mqmx/GHSA-x8pm-wrg2-mqmx.json b/advisories/unreviewed/2025/04/GHSA-x8pm-wrg2-mqmx/GHSA-x8pm-wrg2-mqmx.json new file mode 100644 index 00000000000..12e7bc1accc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x8pm-wrg2-mqmx/GHSA-x8pm-wrg2-mqmx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8pm-wrg2-mqmx", + "modified": "2025-04-17T18:31:12Z", + "published": "2025-04-17T18:31:12Z", + "aliases": [ + "CVE-2024-55238" + ], + "details": "OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the WorkflowDAO interface. The workflowtype and status parameters can be used to build a SQL query.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55238" + }, + { + "type": "WEB", + "url": "https://gist.github.com/javadk/68c597cdb94768dab31a3219c2ad9904" + }, + { + "type": "WEB", + "url": "https://github.com/open-metadata/OpenMetadata/blob/98945cb2db87ebb325d3a72131f049abffcba345/openmetadata-service/src/main/java/org/openmetadata/service/jdbi3/CollectionDAO.java#L4243" + }, + { + "type": "WEB", + "url": "https://github.com/open-metadata/OpenMetadata/blob/98945cb2db87ebb325d3a72131f049abffcba345/openmetadata-service/src/main/java/org/openmetadata/service/jdbi3/CollectionDAO.java#L4247" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xcq9-mmxv-cwpf/GHSA-xcq9-mmxv-cwpf.json b/advisories/unreviewed/2025/04/GHSA-xcq9-mmxv-cwpf/GHSA-xcq9-mmxv-cwpf.json new file mode 100644 index 00000000000..d89d2113cdf --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xcq9-mmxv-cwpf/GHSA-xcq9-mmxv-cwpf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcq9-mmxv-cwpf", + "modified": "2025-04-17T18:31:15Z", + "published": "2025-04-17T18:31:15Z", + "aliases": [ + "CVE-2025-32490" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebsiteDefender wp secure allows Stored XSS. This issue affects wp secure: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32490" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-secure-by-sitesecuritymonitorcom/vulnerability/wordpress-wp-secure-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xf4p-cv5q-7933/GHSA-xf4p-cv5q-7933.json b/advisories/unreviewed/2025/04/GHSA-xf4p-cv5q-7933/GHSA-xf4p-cv5q-7933.json new file mode 100644 index 00000000000..6cf0a7f8338 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xf4p-cv5q-7933/GHSA-xf4p-cv5q-7933.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xf4p-cv5q-7933", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32608" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Movylo Movylo Marketing Automation allows Reflected XSS. This issue affects Movylo Marketing Automation: from n/a through 2.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32608" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/movylo-widget/vulnerability/wordpress-movylo-marketing-automation-plugin-2-0-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xh69-9chv-wc4v/GHSA-xh69-9chv-wc4v.json b/advisories/unreviewed/2025/04/GHSA-xh69-9chv-wc4v/GHSA-xh69-9chv-wc4v.json new file mode 100644 index 00000000000..ace25ad52a9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xh69-9chv-wc4v/GHSA-xh69-9chv-wc4v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh69-9chv-wc4v", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:19Z", + "aliases": [ + "CVE-2025-39429" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Földesi, Mihály Széchenyi 2020 Logo allows PHP Local File Inclusion. This issue affects Széchenyi 2020 Logo: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39429" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/szechenyi-2020-logo/vulnerability/wordpress-szechenyi-2020-logo-1-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xh89-595c-x982/GHSA-xh89-595c-x982.json b/advisories/unreviewed/2025/04/GHSA-xh89-595c-x982/GHSA-xh89-595c-x982.json new file mode 100644 index 00000000000..11323f3956c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xh89-595c-x982/GHSA-xh89-595c-x982.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh89-595c-x982", + "modified": "2025-04-17T18:31:19Z", + "published": "2025-04-17T18:31:19Z", + "aliases": [ + "CVE-2025-39427" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beth Tucker Long WP Post to PDF Enhanced allows Stored XSS. This issue affects WP Post to PDF Enhanced: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39427" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-post-to-pdf-enhanced/vulnerability/wordpress-wp-post-to-pdf-enhanced-plugin-1-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xhhf-2q9w-4g9h/GHSA-xhhf-2q9w-4g9h.json b/advisories/unreviewed/2025/04/GHSA-xhhf-2q9w-4g9h/GHSA-xhhf-2q9w-4g9h.json new file mode 100644 index 00000000000..d6f5f3858cb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xhhf-2q9w-4g9h/GHSA-xhhf-2q9w-4g9h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhhf-2q9w-4g9h", + "modified": "2025-04-17T18:31:17Z", + "published": "2025-04-17T18:31:17Z", + "aliases": [ + "CVE-2025-32571" + ], + "details": "Deserialization of Untrusted Data vulnerability in turitop TuriTop Booking System allows Object Injection. This issue affects TuriTop Booking System: from n/a through 1.0.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32571" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/turitop-booking-system/vulnerability/wordpress-turitop-booking-system-plugin-1-0-10-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xhj8-26hf-x47j/GHSA-xhj8-26hf-x47j.json b/advisories/unreviewed/2025/04/GHSA-xhj8-26hf-x47j/GHSA-xhj8-26hf-x47j.json new file mode 100644 index 00000000000..f926b721c2d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xhj8-26hf-x47j/GHSA-xhj8-26hf-x47j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhj8-26hf-x47j", + "modified": "2025-04-17T18:31:21Z", + "published": "2025-04-17T18:31:21Z", + "aliases": [ + "CVE-2025-39580" + ], + "details": "Missing Authorization vulnerability in jidaikobo Dashi allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Dashi: from n/a through 3.1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39580" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dashi/vulnerability/wordpress-dashi-3-1-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xjmf-cg3p-vmcm/GHSA-xjmf-cg3p-vmcm.json b/advisories/unreviewed/2025/04/GHSA-xjmf-cg3p-vmcm/GHSA-xjmf-cg3p-vmcm.json new file mode 100644 index 00000000000..eceae540344 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xjmf-cg3p-vmcm/GHSA-xjmf-cg3p-vmcm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjmf-cg3p-vmcm", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32636" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in matthewrubin Local Magic allows SQL Injection. This issue affects Local Magic: from n/a through 2.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32636" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/local-magic/vulnerability/wordpress-local-magic-plugin-2-6-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xm4m-v38w-7fr8/GHSA-xm4m-v38w-7fr8.json b/advisories/unreviewed/2025/04/GHSA-xm4m-v38w-7fr8/GHSA-xm4m-v38w-7fr8.json new file mode 100644 index 00000000000..1d35db704f7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xm4m-v38w-7fr8/GHSA-xm4m-v38w-7fr8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xm4m-v38w-7fr8", + "modified": "2025-04-17T18:31:16Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32514" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cscode WooCommerce Estimate and Quote allows Reflected XSS. This issue affects WooCommerce Estimate and Quote: from n/a through 1.0.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32514" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wc-estimate-and-quote/vulnerability/wordpress-woocommerce-estimate-and-quote-plugin-1-0-2-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xqx3-w575-cg29/GHSA-xqx3-w575-cg29.json b/advisories/unreviewed/2025/04/GHSA-xqx3-w575-cg29/GHSA-xqx3-w575-cg29.json new file mode 100644 index 00000000000..40f3a10abcc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xqx3-w575-cg29/GHSA-xqx3-w575-cg29.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqx3-w575-cg29", + "modified": "2025-04-17T18:31:18Z", + "published": "2025-04-17T18:31:18Z", + "aliases": [ + "CVE-2025-32665" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebbyTemplate Office Locator allows SQL Injection. This issue affects Office Locator: from n/a through 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32665" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/office-locator/vulnerability/wordpress-office-locator-plugin-1-3-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xr64-8582-gx8c/GHSA-xr64-8582-gx8c.json b/advisories/unreviewed/2025/04/GHSA-xr64-8582-gx8c/GHSA-xr64-8582-gx8c.json new file mode 100644 index 00000000000..ce7b5eebbb6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xr64-8582-gx8c/GHSA-xr64-8582-gx8c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr64-8582-gx8c", + "modified": "2025-04-17T18:31:16Z", + "published": "2025-04-17T18:31:16Z", + "aliases": [ + "CVE-2025-32515" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in terminalafrica Terminal Africa allows Reflected XSS. This issue affects Terminal Africa: from n/a through 1.13.17.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32515" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/terminal-africa/vulnerability/wordpress-terminal-africa-plugin-1-13-17-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xv93-h5pv-3mpg/GHSA-xv93-h5pv-3mpg.json b/advisories/unreviewed/2025/04/GHSA-xv93-h5pv-3mpg/GHSA-xv93-h5pv-3mpg.json new file mode 100644 index 00000000000..fd5d153b796 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xv93-h5pv-3mpg/GHSA-xv93-h5pv-3mpg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv93-h5pv-3mpg", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39453" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in algol.plus Advanced Dynamic Pricing for WooCommerce allows Cross Site Request Forgery. This issue affects Advanced Dynamic Pricing for WooCommerce: from n/a through 4.9.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39453" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-dynamic-pricing-for-woocommerce/vulnerability/wordpress-advanced-dynamic-pricing-for-woocommerce-plugin-4-9-3-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xvr7-xmmp-p9vr/GHSA-xvr7-xmmp-p9vr.json b/advisories/unreviewed/2025/04/GHSA-xvr7-xmmp-p9vr/GHSA-xvr7-xmmp-p9vr.json new file mode 100644 index 00000000000..2db9aa1cd9a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xvr7-xmmp-p9vr/GHSA-xvr7-xmmp-p9vr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvr7-xmmp-p9vr", + "modified": "2025-04-17T18:31:14Z", + "published": "2025-04-17T18:31:14Z", + "aliases": [ + "CVE-2025-24745" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RadiusTheme Classified Listing allows Reflected XSS. This issue affects Classified Listing: from n/a through 4.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24745" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/classified-listing/vulnerability/wordpress-classified-listing-plugin-4-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xwgw-2g3g-g3q8/GHSA-xwgw-2g3g-g3q8.json b/advisories/unreviewed/2025/04/GHSA-xwgw-2g3g-g3q8/GHSA-xwgw-2g3g-g3q8.json new file mode 100644 index 00000000000..b9ae269ac79 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xwgw-2g3g-g3q8/GHSA-xwgw-2g3g-g3q8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwgw-2g3g-g3q8", + "modified": "2025-04-17T18:31:13Z", + "published": "2025-04-17T18:31:13Z", + "aliases": [ + "CVE-2025-23858" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hiren Patel Custom Users Order allows Reflected XSS. This issue affects Custom Users Order: from n/a through 4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23858" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/custom-users-order/vulnerability/wordpress-custom-users-order-plugin-4-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xxrf-fc9m-h444/GHSA-xxrf-fc9m-h444.json b/advisories/unreviewed/2025/04/GHSA-xxrf-fc9m-h444/GHSA-xxrf-fc9m-h444.json new file mode 100644 index 00000000000..24abf0c28a2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xxrf-fc9m-h444/GHSA-xxrf-fc9m-h444.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxrf-fc9m-h444", + "modified": "2025-04-17T18:31:20Z", + "published": "2025-04-17T18:31:20Z", + "aliases": [ + "CVE-2025-39436" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw allows Using Malicious Files. This issue affects I Draw: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39436" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/idraw/vulnerability/wordpress-i-draw-1-0-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xxvv-rw24-p2j6/GHSA-xxvv-rw24-p2j6.json b/advisories/unreviewed/2025/04/GHSA-xxvv-rw24-p2j6/GHSA-xxvv-rw24-p2j6.json new file mode 100644 index 00000000000..42a02293373 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xxvv-rw24-p2j6/GHSA-xxvv-rw24-p2j6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxvv-rw24-p2j6", + "modified": "2025-04-17T18:31:22Z", + "published": "2025-04-17T18:31:22Z", + "aliases": [ + "CVE-2025-43012" + ], + "details": "In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43012" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T16:15:59Z" + } +} \ No newline at end of file