From bee0ee604fdbafe47527d2caed1458e5b1386b96 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 17 May 2025 06:31:32 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-wq26-hpcc-wh38.json | 6 +- .../GHSA-2cp7-pmqc-mq6m.json | 56 +++++++++++++++++++ .../GHSA-2gpg-rr9p-jqp9.json | 11 +++- .../GHSA-33f2-v5w3-mmvw.json | 11 +++- .../GHSA-37c5-cj42-grq7.json | 11 +++- .../GHSA-3m52-6qc2-vwqh.json | 11 +++- .../GHSA-3q32-7qwj-m73v.json | 11 +++- .../GHSA-4jg8-qc3w-j5hx.json | 11 +++- .../GHSA-4p7f-6rw5-m5v7.json | 6 +- .../GHSA-5c34-m5vc-78j5.json | 11 +++- .../GHSA-6925-xwwp-qwh5.json | 11 +++- .../GHSA-6c4h-4fjm-m75j.json | 11 +++- .../GHSA-7pq2-p2r6-3h8r.json | 11 +++- .../GHSA-7rm6-cjw9-cf8v.json | 29 ++++++++++ .../GHSA-7vrj-wjmg-rqm2.json | 11 +++- .../GHSA-8hqp-jvp3-493j.json | 40 +++++++++++++ .../GHSA-8xqm-w2cq-fmc6.json | 11 +++- .../GHSA-93mr-fwrq-w2xg.json | 11 +++- .../GHSA-96q3-fjrx-h9hh.json | 6 +- .../GHSA-9m4x-m322-8xcp.json | 11 +++- .../GHSA-9mpf-r669-m5wq.json | 11 +++- .../GHSA-c8hj-rjcv-xx48.json | 11 +++- .../GHSA-f2vf-33g3-fwm2.json | 11 +++- .../GHSA-fpq7-6mfr-4vvq.json | 11 +++- .../GHSA-gh3q-hh33-59w3.json | 11 +++- .../GHSA-gmhj-76hp-7wh3.json | 11 +++- .../GHSA-hjc2-9qw7-v75f.json | 40 +++++++++++++ .../GHSA-hww8-3wf5-9mgj.json | 11 +++- .../GHSA-j4qf-29vf-7xcj.json | 11 +++- .../GHSA-j54f-6g32-3jwj.json | 11 +++- .../GHSA-j7h5-wpgx-r8m9.json | 11 +++- .../GHSA-mqjj-6j4c-9xw9.json | 11 +++- .../GHSA-p8rv-v842-xwm4.json | 11 +++- .../GHSA-p9xg-r2f4-c78v.json | 11 +++- .../GHSA-phhw-fr9r-6qv9.json | 11 +++- .../GHSA-prfq-pmqw-27fc.json | 11 +++- .../GHSA-pv77-pr9x-9r7m.json | 40 +++++++++++++ .../GHSA-q86g-hcf4-hx9x.json | 40 +++++++++++++ .../GHSA-r48q-9g76-wf99.json | 40 +++++++++++++ .../GHSA-wf67-68fh-ggp2.json | 56 +++++++++++++++++++ .../GHSA-wfcx-m66p-g8fw.json | 56 +++++++++++++++++++ .../GHSA-wm93-qjx4-vmf3.json | 52 +++++++++++++++++ .../GHSA-wpp3-qg8g-86cw.json | 11 +++- .../GHSA-x579-fc2r-gxmj.json | 11 +++- .../GHSA-x9mr-w276-h3c2.json | 11 +++- .../GHSA-xc5x-xvcr-5h87.json | 11 +++- 46 files changed, 728 insertions(+), 102 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-2cp7-pmqc-mq6m/GHSA-2cp7-pmqc-mq6m.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7rm6-cjw9-cf8v/GHSA-7rm6-cjw9-cf8v.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8hqp-jvp3-493j/GHSA-8hqp-jvp3-493j.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hjc2-9qw7-v75f/GHSA-hjc2-9qw7-v75f.json create mode 100644 advisories/unreviewed/2025/05/GHSA-pv77-pr9x-9r7m/GHSA-pv77-pr9x-9r7m.json create mode 100644 advisories/unreviewed/2025/05/GHSA-q86g-hcf4-hx9x/GHSA-q86g-hcf4-hx9x.json create mode 100644 advisories/unreviewed/2025/05/GHSA-r48q-9g76-wf99/GHSA-r48q-9g76-wf99.json create mode 100644 advisories/unreviewed/2025/05/GHSA-wf67-68fh-ggp2/GHSA-wf67-68fh-ggp2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-wfcx-m66p-g8fw/GHSA-wfcx-m66p-g8fw.json create mode 100644 advisories/unreviewed/2025/05/GHSA-wm93-qjx4-vmf3/GHSA-wm93-qjx4-vmf3.json diff --git a/advisories/unreviewed/2025/04/GHSA-wq26-hpcc-wh38/GHSA-wq26-hpcc-wh38.json b/advisories/unreviewed/2025/04/GHSA-wq26-hpcc-wh38/GHSA-wq26-hpcc-wh38.json index 03aa0d24655..09a15f98757 100644 --- a/advisories/unreviewed/2025/04/GHSA-wq26-hpcc-wh38/GHSA-wq26-hpcc-wh38.json +++ b/advisories/unreviewed/2025/04/GHSA-wq26-hpcc-wh38/GHSA-wq26-hpcc-wh38.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wq26-hpcc-wh38", - "modified": "2025-04-08T15:31:06Z", + "modified": "2025-05-17T06:30:24Z", "published": "2025-04-08T15:31:06Z", "aliases": [ "CVE-2025-22458" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-April-2025-for-EPM-2024-and-EPM-2022-SU6" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2025/May/17" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-2cp7-pmqc-mq6m/GHSA-2cp7-pmqc-mq6m.json b/advisories/unreviewed/2025/05/GHSA-2cp7-pmqc-mq6m/GHSA-2cp7-pmqc-mq6m.json new file mode 100644 index 00000000000..0fb36327643 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2cp7-pmqc-mq6m/GHSA-2cp7-pmqc-mq6m.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cp7-pmqc-mq6m", + "modified": "2025-05-17T06:30:28Z", + "published": "2025-05-17T06:30:28Z", + "aliases": [ + "CVE-2025-4817" + ], + "details": "A vulnerability was found in Sourcecodester Doctor's Appointment System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/delete-appointment.php of the component GET Parameter Handler. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4817" + }, + { + "type": "WEB", + "url": "https://github.com/Xiaoyi-ing/CVE/issues/9" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309274" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309274" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.574178" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T04:16:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2gpg-rr9p-jqp9/GHSA-2gpg-rr9p-jqp9.json b/advisories/unreviewed/2025/05/GHSA-2gpg-rr9p-jqp9/GHSA-2gpg-rr9p-jqp9.json index 5a103e236ac..676c796895d 100644 --- a/advisories/unreviewed/2025/05/GHSA-2gpg-rr9p-jqp9/GHSA-2gpg-rr9p-jqp9.json +++ b/advisories/unreviewed/2025/05/GHSA-2gpg-rr9p-jqp9/GHSA-2gpg-rr9p-jqp9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2gpg-rr9p-jqp9", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-17T06:30:26Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-8426" ], "details": "The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:58Z" diff --git a/advisories/unreviewed/2025/05/GHSA-33f2-v5w3-mmvw/GHSA-33f2-v5w3-mmvw.json b/advisories/unreviewed/2025/05/GHSA-33f2-v5w3-mmvw/GHSA-33f2-v5w3-mmvw.json index 48df88280d5..e3e77c93d57 100644 --- a/advisories/unreviewed/2025/05/GHSA-33f2-v5w3-mmvw/GHSA-33f2-v5w3-mmvw.json +++ b/advisories/unreviewed/2025/05/GHSA-33f2-v5w3-mmvw/GHSA-33f2-v5w3-mmvw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-33f2-v5w3-mmvw", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-17T06:30:24Z", "published": "2025-05-15T21:31:31Z", "aliases": [ "CVE-2024-6665" ], "details": "The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:55Z" diff --git a/advisories/unreviewed/2025/05/GHSA-37c5-cj42-grq7/GHSA-37c5-cj42-grq7.json b/advisories/unreviewed/2025/05/GHSA-37c5-cj42-grq7/GHSA-37c5-cj42-grq7.json index a31d94ed095..2297aa850c1 100644 --- a/advisories/unreviewed/2025/05/GHSA-37c5-cj42-grq7/GHSA-37c5-cj42-grq7.json +++ b/advisories/unreviewed/2025/05/GHSA-37c5-cj42-grq7/GHSA-37c5-cj42-grq7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-37c5-cj42-grq7", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-17T06:30:24Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-7758" ], "details": "The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could allow high privilege users of contributor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:56Z" diff --git a/advisories/unreviewed/2025/05/GHSA-3m52-6qc2-vwqh/GHSA-3m52-6qc2-vwqh.json b/advisories/unreviewed/2025/05/GHSA-3m52-6qc2-vwqh/GHSA-3m52-6qc2-vwqh.json index 48197b89948..fdf032850c4 100644 --- a/advisories/unreviewed/2025/05/GHSA-3m52-6qc2-vwqh/GHSA-3m52-6qc2-vwqh.json +++ b/advisories/unreviewed/2025/05/GHSA-3m52-6qc2-vwqh/GHSA-3m52-6qc2-vwqh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3m52-6qc2-vwqh", - "modified": "2025-05-15T21:31:33Z", + "modified": "2025-05-17T06:30:26Z", "published": "2025-05-15T21:31:33Z", "aliases": [ "CVE-2024-8702" ], "details": "The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:59Z" diff --git a/advisories/unreviewed/2025/05/GHSA-3q32-7qwj-m73v/GHSA-3q32-7qwj-m73v.json b/advisories/unreviewed/2025/05/GHSA-3q32-7qwj-m73v/GHSA-3q32-7qwj-m73v.json index abbaa32b672..2b172e14d1d 100644 --- a/advisories/unreviewed/2025/05/GHSA-3q32-7qwj-m73v/GHSA-3q32-7qwj-m73v.json +++ b/advisories/unreviewed/2025/05/GHSA-3q32-7qwj-m73v/GHSA-3q32-7qwj-m73v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3q32-7qwj-m73v", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-17T06:30:24Z", "published": "2025-05-15T21:31:31Z", "aliases": [ "CVE-2024-6667" ], "details": "The KBucket: Your Curated Content in WordPress plugin before 4.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:55Z" diff --git a/advisories/unreviewed/2025/05/GHSA-4jg8-qc3w-j5hx/GHSA-4jg8-qc3w-j5hx.json b/advisories/unreviewed/2025/05/GHSA-4jg8-qc3w-j5hx/GHSA-4jg8-qc3w-j5hx.json index 23078ea1e40..0b46c3c2246 100644 --- a/advisories/unreviewed/2025/05/GHSA-4jg8-qc3w-j5hx/GHSA-4jg8-qc3w-j5hx.json +++ b/advisories/unreviewed/2025/05/GHSA-4jg8-qc3w-j5hx/GHSA-4jg8-qc3w-j5hx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4jg8-qc3w-j5hx", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-17T06:30:24Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-7556" ], "details": "The Simple Share WordPress plugin through 0.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:56Z" diff --git a/advisories/unreviewed/2025/05/GHSA-4p7f-6rw5-m5v7/GHSA-4p7f-6rw5-m5v7.json b/advisories/unreviewed/2025/05/GHSA-4p7f-6rw5-m5v7/GHSA-4p7f-6rw5-m5v7.json index 642f16366b1..935ba95f2bb 100644 --- a/advisories/unreviewed/2025/05/GHSA-4p7f-6rw5-m5v7/GHSA-4p7f-6rw5-m5v7.json +++ b/advisories/unreviewed/2025/05/GHSA-4p7f-6rw5-m5v7/GHSA-4p7f-6rw5-m5v7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4p7f-6rw5-m5v7", - "modified": "2025-05-02T15:31:48Z", + "modified": "2025-05-17T06:30:24Z", "published": "2025-05-02T15:31:47Z", "aliases": [ "CVE-2025-2605" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://www.honeywell.com/us/en/product-security#security-notices" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2025/May/19" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-5c34-m5vc-78j5/GHSA-5c34-m5vc-78j5.json b/advisories/unreviewed/2025/05/GHSA-5c34-m5vc-78j5/GHSA-5c34-m5vc-78j5.json index 5abe128075e..972c6e4f3ad 100644 --- a/advisories/unreviewed/2025/05/GHSA-5c34-m5vc-78j5/GHSA-5c34-m5vc-78j5.json +++ b/advisories/unreviewed/2025/05/GHSA-5c34-m5vc-78j5/GHSA-5c34-m5vc-78j5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5c34-m5vc-78j5", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-17T06:30:25Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-8284" ], "details": "The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:58Z" diff --git a/advisories/unreviewed/2025/05/GHSA-6925-xwwp-qwh5/GHSA-6925-xwwp-qwh5.json b/advisories/unreviewed/2025/05/GHSA-6925-xwwp-qwh5/GHSA-6925-xwwp-qwh5.json index 0dfd2145b65..9da11caf04f 100644 --- a/advisories/unreviewed/2025/05/GHSA-6925-xwwp-qwh5/GHSA-6925-xwwp-qwh5.json +++ b/advisories/unreviewed/2025/05/GHSA-6925-xwwp-qwh5/GHSA-6925-xwwp-qwh5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6925-xwwp-qwh5", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-17T06:30:25Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-8286" ], "details": "The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting visit logs via CSRF attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:58Z" diff --git a/advisories/unreviewed/2025/05/GHSA-6c4h-4fjm-m75j/GHSA-6c4h-4fjm-m75j.json b/advisories/unreviewed/2025/05/GHSA-6c4h-4fjm-m75j/GHSA-6c4h-4fjm-m75j.json index 102b9368e75..8507208afca 100644 --- a/advisories/unreviewed/2025/05/GHSA-6c4h-4fjm-m75j/GHSA-6c4h-4fjm-m75j.json +++ b/advisories/unreviewed/2025/05/GHSA-6c4h-4fjm-m75j/GHSA-6c4h-4fjm-m75j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6c4h-4fjm-m75j", - "modified": "2025-05-15T21:31:33Z", + "modified": "2025-05-17T06:30:26Z", "published": "2025-05-15T21:31:33Z", "aliases": [ "CVE-2024-8542" ], "details": "The Everest Forms WordPress plugin before 3.0.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:58Z" diff --git a/advisories/unreviewed/2025/05/GHSA-7pq2-p2r6-3h8r/GHSA-7pq2-p2r6-3h8r.json b/advisories/unreviewed/2025/05/GHSA-7pq2-p2r6-3h8r/GHSA-7pq2-p2r6-3h8r.json index a21243b94aa..23887f05539 100644 --- a/advisories/unreviewed/2025/05/GHSA-7pq2-p2r6-3h8r/GHSA-7pq2-p2r6-3h8r.json +++ b/advisories/unreviewed/2025/05/GHSA-7pq2-p2r6-3h8r/GHSA-7pq2-p2r6-3h8r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7pq2-p2r6-3h8r", - "modified": "2025-05-15T21:31:33Z", + "modified": "2025-05-17T06:30:27Z", "published": "2025-05-15T21:31:33Z", "aliases": [ "CVE-2024-9238" ], "details": "The AVIF Uploader WordPress plugin before 1.1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:16:00Z" diff --git a/advisories/unreviewed/2025/05/GHSA-7rm6-cjw9-cf8v/GHSA-7rm6-cjw9-cf8v.json b/advisories/unreviewed/2025/05/GHSA-7rm6-cjw9-cf8v/GHSA-7rm6-cjw9-cf8v.json new file mode 100644 index 00000000000..6f988c98404 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7rm6-cjw9-cf8v/GHSA-7rm6-cjw9-cf8v.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rm6-cjw9-cf8v", + "modified": "2025-05-17T06:30:28Z", + "published": "2025-05-17T06:30:28Z", + "aliases": [ + "CVE-2025-4190" + ], + "details": "The CSV Mass Importer WordPress plugin through 1.2 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4190" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/e525ece5-6e03-4aee-bf5b-6ae0b961f027" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T06:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7vrj-wjmg-rqm2/GHSA-7vrj-wjmg-rqm2.json b/advisories/unreviewed/2025/05/GHSA-7vrj-wjmg-rqm2/GHSA-7vrj-wjmg-rqm2.json index 33d8974d0ae..9e8ba201ffb 100644 --- a/advisories/unreviewed/2025/05/GHSA-7vrj-wjmg-rqm2/GHSA-7vrj-wjmg-rqm2.json +++ b/advisories/unreviewed/2025/05/GHSA-7vrj-wjmg-rqm2/GHSA-7vrj-wjmg-rqm2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7vrj-wjmg-rqm2", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-17T06:30:25Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-7761" ], "details": "In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:56Z" diff --git a/advisories/unreviewed/2025/05/GHSA-8hqp-jvp3-493j/GHSA-8hqp-jvp3-493j.json b/advisories/unreviewed/2025/05/GHSA-8hqp-jvp3-493j/GHSA-8hqp-jvp3-493j.json new file mode 100644 index 00000000000..8b28d32eac9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8hqp-jvp3-493j/GHSA-8hqp-jvp3-493j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hqp-jvp3-493j", + "modified": "2025-05-17T06:30:28Z", + "published": "2025-05-17T06:30:28Z", + "aliases": [ + "CVE-2025-4391" + ], + "details": "The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the echo_generate_featured_image() function in all versions up to, and including, 5.4.8.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4391" + }, + { + "type": "WEB", + "url": "https://codecanyon.net/item/echo-rss-feed-post-generator-plugin-for-wordpress/19486974" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/72de9f64-f3e0-4705-adc1-6c22076b382f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T06:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8xqm-w2cq-fmc6/GHSA-8xqm-w2cq-fmc6.json b/advisories/unreviewed/2025/05/GHSA-8xqm-w2cq-fmc6/GHSA-8xqm-w2cq-fmc6.json index 84c207e7cc2..6f0b91f3bc1 100644 --- a/advisories/unreviewed/2025/05/GHSA-8xqm-w2cq-fmc6/GHSA-8xqm-w2cq-fmc6.json +++ b/advisories/unreviewed/2025/05/GHSA-8xqm-w2cq-fmc6/GHSA-8xqm-w2cq-fmc6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8xqm-w2cq-fmc6", - "modified": "2025-05-15T21:31:33Z", + "modified": "2025-05-17T06:30:27Z", "published": "2025-05-15T21:31:33Z", "aliases": [ "CVE-2024-9233" ], "details": "The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:16:00Z" diff --git a/advisories/unreviewed/2025/05/GHSA-93mr-fwrq-w2xg/GHSA-93mr-fwrq-w2xg.json b/advisories/unreviewed/2025/05/GHSA-93mr-fwrq-w2xg/GHSA-93mr-fwrq-w2xg.json index 1629fb8eee2..ad4111a47d8 100644 --- a/advisories/unreviewed/2025/05/GHSA-93mr-fwrq-w2xg/GHSA-93mr-fwrq-w2xg.json +++ b/advisories/unreviewed/2025/05/GHSA-93mr-fwrq-w2xg/GHSA-93mr-fwrq-w2xg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-93mr-fwrq-w2xg", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-17T06:30:24Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-6809" ], "details": "The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:56Z" diff --git a/advisories/unreviewed/2025/05/GHSA-96q3-fjrx-h9hh/GHSA-96q3-fjrx-h9hh.json b/advisories/unreviewed/2025/05/GHSA-96q3-fjrx-h9hh/GHSA-96q3-fjrx-h9hh.json index b9fdf4ed686..4af39bbb23e 100644 --- a/advisories/unreviewed/2025/05/GHSA-96q3-fjrx-h9hh/GHSA-96q3-fjrx-h9hh.json +++ b/advisories/unreviewed/2025/05/GHSA-96q3-fjrx-h9hh/GHSA-96q3-fjrx-h9hh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-96q3-fjrx-h9hh", - "modified": "2025-05-16T18:31:06Z", + "modified": "2025-05-17T06:30:27Z", "published": "2025-05-16T18:31:06Z", "aliases": [ "CVE-2025-47916" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://karmainsecurity.com/KIS-2025-02" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2025/May/4" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-9m4x-m322-8xcp/GHSA-9m4x-m322-8xcp.json b/advisories/unreviewed/2025/05/GHSA-9m4x-m322-8xcp/GHSA-9m4x-m322-8xcp.json index 671d6130cae..472ba358ffd 100644 --- a/advisories/unreviewed/2025/05/GHSA-9m4x-m322-8xcp/GHSA-9m4x-m322-8xcp.json +++ b/advisories/unreviewed/2025/05/GHSA-9m4x-m322-8xcp/GHSA-9m4x-m322-8xcp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9m4x-m322-8xcp", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-17T06:30:25Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-7759" ], "details": "The PWA for WP WordPress plugin before 1.7.72 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:56Z" diff --git a/advisories/unreviewed/2025/05/GHSA-9mpf-r669-m5wq/GHSA-9mpf-r669-m5wq.json b/advisories/unreviewed/2025/05/GHSA-9mpf-r669-m5wq/GHSA-9mpf-r669-m5wq.json index a7f5e5a696c..bea31b7594d 100644 --- a/advisories/unreviewed/2025/05/GHSA-9mpf-r669-m5wq/GHSA-9mpf-r669-m5wq.json +++ b/advisories/unreviewed/2025/05/GHSA-9mpf-r669-m5wq/GHSA-9mpf-r669-m5wq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9mpf-r669-m5wq", - "modified": "2025-05-15T21:31:33Z", + "modified": "2025-05-17T06:30:26Z", "published": "2025-05-15T21:31:33Z", "aliases": [ "CVE-2024-8617" ], "details": "The Quiz Maker WordPress plugin before 6.5.9.9 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:58Z" diff --git a/advisories/unreviewed/2025/05/GHSA-c8hj-rjcv-xx48/GHSA-c8hj-rjcv-xx48.json b/advisories/unreviewed/2025/05/GHSA-c8hj-rjcv-xx48/GHSA-c8hj-rjcv-xx48.json index 1162bb81f4d..d3e02a1b524 100644 --- a/advisories/unreviewed/2025/05/GHSA-c8hj-rjcv-xx48/GHSA-c8hj-rjcv-xx48.json +++ b/advisories/unreviewed/2025/05/GHSA-c8hj-rjcv-xx48/GHSA-c8hj-rjcv-xx48.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c8hj-rjcv-xx48", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-17T06:30:25Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-7769" ], "details": "The ClickSold IDX WordPress plugin through 1.90 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:57Z" diff --git a/advisories/unreviewed/2025/05/GHSA-f2vf-33g3-fwm2/GHSA-f2vf-33g3-fwm2.json b/advisories/unreviewed/2025/05/GHSA-f2vf-33g3-fwm2/GHSA-f2vf-33g3-fwm2.json index d9eaeeee878..4c1e5326044 100644 --- a/advisories/unreviewed/2025/05/GHSA-f2vf-33g3-fwm2/GHSA-f2vf-33g3-fwm2.json +++ b/advisories/unreviewed/2025/05/GHSA-f2vf-33g3-fwm2/GHSA-f2vf-33g3-fwm2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f2vf-33g3-fwm2", - "modified": "2025-05-15T21:31:34Z", + "modified": "2025-05-17T06:30:27Z", "published": "2025-05-15T21:31:34Z", "aliases": [ "CVE-2024-9882" ], "details": "The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:16:01Z" diff --git a/advisories/unreviewed/2025/05/GHSA-fpq7-6mfr-4vvq/GHSA-fpq7-6mfr-4vvq.json b/advisories/unreviewed/2025/05/GHSA-fpq7-6mfr-4vvq/GHSA-fpq7-6mfr-4vvq.json index e7c4920257c..4375736b0e6 100644 --- a/advisories/unreviewed/2025/05/GHSA-fpq7-6mfr-4vvq/GHSA-fpq7-6mfr-4vvq.json +++ b/advisories/unreviewed/2025/05/GHSA-fpq7-6mfr-4vvq/GHSA-fpq7-6mfr-4vvq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fpq7-6mfr-4vvq", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-17T06:30:25Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-8245" ], "details": "The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:58Z" diff --git a/advisories/unreviewed/2025/05/GHSA-gh3q-hh33-59w3/GHSA-gh3q-hh33-59w3.json b/advisories/unreviewed/2025/05/GHSA-gh3q-hh33-59w3/GHSA-gh3q-hh33-59w3.json index ee9cc6dd986..7cc67759c64 100644 --- a/advisories/unreviewed/2025/05/GHSA-gh3q-hh33-59w3/GHSA-gh3q-hh33-59w3.json +++ b/advisories/unreviewed/2025/05/GHSA-gh3q-hh33-59w3/GHSA-gh3q-hh33-59w3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gh3q-hh33-59w3", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-17T06:30:26Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-8492" ], "details": "The Hustle WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:58Z" diff --git a/advisories/unreviewed/2025/05/GHSA-gmhj-76hp-7wh3/GHSA-gmhj-76hp-7wh3.json b/advisories/unreviewed/2025/05/GHSA-gmhj-76hp-7wh3/GHSA-gmhj-76hp-7wh3.json index 96369e80060..66f70288082 100644 --- a/advisories/unreviewed/2025/05/GHSA-gmhj-76hp-7wh3/GHSA-gmhj-76hp-7wh3.json +++ b/advisories/unreviewed/2025/05/GHSA-gmhj-76hp-7wh3/GHSA-gmhj-76hp-7wh3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gmhj-76hp-7wh3", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-17T06:30:24Z", "published": "2025-05-15T21:31:31Z", "aliases": [ "CVE-2024-6584" ], "details": "The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:55Z" diff --git a/advisories/unreviewed/2025/05/GHSA-hjc2-9qw7-v75f/GHSA-hjc2-9qw7-v75f.json b/advisories/unreviewed/2025/05/GHSA-hjc2-9qw7-v75f/GHSA-hjc2-9qw7-v75f.json new file mode 100644 index 00000000000..a6a1714376a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hjc2-9qw7-v75f/GHSA-hjc2-9qw7-v75f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjc2-9qw7-v75f", + "modified": "2025-05-17T06:30:28Z", + "published": "2025-05-17T06:30:28Z", + "aliases": [ + "CVE-2025-3812" + ], + "details": "The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the qcld_openai_delete_training_file() function in all versions up to, and including, 13.6.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3812" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8fe1609d-17d6-4afe-90b2-5473dc9b6c3b?source=cve" + }, + { + "type": "WEB", + "url": "https://www.wpbot.pro" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T06:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hww8-3wf5-9mgj/GHSA-hww8-3wf5-9mgj.json b/advisories/unreviewed/2025/05/GHSA-hww8-3wf5-9mgj/GHSA-hww8-3wf5-9mgj.json index 15ae8bc4d66..a1585db54ec 100644 --- a/advisories/unreviewed/2025/05/GHSA-hww8-3wf5-9mgj/GHSA-hww8-3wf5-9mgj.json +++ b/advisories/unreviewed/2025/05/GHSA-hww8-3wf5-9mgj/GHSA-hww8-3wf5-9mgj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hww8-3wf5-9mgj", - "modified": "2025-05-15T21:31:33Z", + "modified": "2025-05-17T06:30:27Z", "published": "2025-05-15T21:31:33Z", "aliases": [ "CVE-2024-9236" ], "details": "The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:16:00Z" diff --git a/advisories/unreviewed/2025/05/GHSA-j4qf-29vf-7xcj/GHSA-j4qf-29vf-7xcj.json b/advisories/unreviewed/2025/05/GHSA-j4qf-29vf-7xcj/GHSA-j4qf-29vf-7xcj.json index b0451bb11b9..50180a3ccbc 100644 --- a/advisories/unreviewed/2025/05/GHSA-j4qf-29vf-7xcj/GHSA-j4qf-29vf-7xcj.json +++ b/advisories/unreviewed/2025/05/GHSA-j4qf-29vf-7xcj/GHSA-j4qf-29vf-7xcj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j4qf-29vf-7xcj", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-17T06:30:26Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-8397" ], "details": "The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Consent report' page and the malicious script is executed in the admin context.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:58Z" diff --git a/advisories/unreviewed/2025/05/GHSA-j54f-6g32-3jwj/GHSA-j54f-6g32-3jwj.json b/advisories/unreviewed/2025/05/GHSA-j54f-6g32-3jwj/GHSA-j54f-6g32-3jwj.json index 658fdcffcd0..9870264ed99 100644 --- a/advisories/unreviewed/2025/05/GHSA-j54f-6g32-3jwj/GHSA-j54f-6g32-3jwj.json +++ b/advisories/unreviewed/2025/05/GHSA-j54f-6g32-3jwj/GHSA-j54f-6g32-3jwj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j54f-6g32-3jwj", - "modified": "2025-05-15T21:31:33Z", + "modified": "2025-05-17T06:30:26Z", "published": "2025-05-15T21:31:33Z", "aliases": [ "CVE-2024-8703" ], "details": "The Z-Downloads WordPress plugin before 1.11.6 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks when accessing share URLs.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:59Z" diff --git a/advisories/unreviewed/2025/05/GHSA-j7h5-wpgx-r8m9/GHSA-j7h5-wpgx-r8m9.json b/advisories/unreviewed/2025/05/GHSA-j7h5-wpgx-r8m9/GHSA-j7h5-wpgx-r8m9.json index e2a3fa9e732..488a11f0f3f 100644 --- a/advisories/unreviewed/2025/05/GHSA-j7h5-wpgx-r8m9/GHSA-j7h5-wpgx-r8m9.json +++ b/advisories/unreviewed/2025/05/GHSA-j7h5-wpgx-r8m9/GHSA-j7h5-wpgx-r8m9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j7h5-wpgx-r8m9", - "modified": "2025-05-15T21:31:27Z", + "modified": "2025-05-17T06:30:24Z", "published": "2025-05-15T21:31:27Z", "aliases": [ "CVE-2023-6786" ], "details": "The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:29Z" diff --git a/advisories/unreviewed/2025/05/GHSA-mqjj-6j4c-9xw9/GHSA-mqjj-6j4c-9xw9.json b/advisories/unreviewed/2025/05/GHSA-mqjj-6j4c-9xw9/GHSA-mqjj-6j4c-9xw9.json index cc19a13a17f..07b4597e4b2 100644 --- a/advisories/unreviewed/2025/05/GHSA-mqjj-6j4c-9xw9/GHSA-mqjj-6j4c-9xw9.json +++ b/advisories/unreviewed/2025/05/GHSA-mqjj-6j4c-9xw9/GHSA-mqjj-6j4c-9xw9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mqjj-6j4c-9xw9", - "modified": "2025-05-15T21:31:33Z", + "modified": "2025-05-17T06:30:26Z", "published": "2025-05-15T21:31:33Z", "aliases": [ "CVE-2024-8759" ], "details": "The Nested Pages WordPress plugin before 3.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:59Z" diff --git a/advisories/unreviewed/2025/05/GHSA-p8rv-v842-xwm4/GHSA-p8rv-v842-xwm4.json b/advisories/unreviewed/2025/05/GHSA-p8rv-v842-xwm4/GHSA-p8rv-v842-xwm4.json index a99a2206948..e45ddd53e61 100644 --- a/advisories/unreviewed/2025/05/GHSA-p8rv-v842-xwm4/GHSA-p8rv-v842-xwm4.json +++ b/advisories/unreviewed/2025/05/GHSA-p8rv-v842-xwm4/GHSA-p8rv-v842-xwm4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p8rv-v842-xwm4", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-17T06:30:25Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-8031" ], "details": "The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloaded. This makes it possible for authenticated attackers, with admin-level access and above, to download arbitrary files that may contain sensitive information like wp-config.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:57Z" diff --git a/advisories/unreviewed/2025/05/GHSA-p9xg-r2f4-c78v/GHSA-p9xg-r2f4-c78v.json b/advisories/unreviewed/2025/05/GHSA-p9xg-r2f4-c78v/GHSA-p9xg-r2f4-c78v.json index 54e49044b4a..f7ca4300b55 100644 --- a/advisories/unreviewed/2025/05/GHSA-p9xg-r2f4-c78v/GHSA-p9xg-r2f4-c78v.json +++ b/advisories/unreviewed/2025/05/GHSA-p9xg-r2f4-c78v/GHSA-p9xg-r2f4-c78v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p9xg-r2f4-c78v", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-17T06:30:25Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-7762" ], "details": "The Simple Job Board WordPress plugin before 2.12.6 does not prevent uploaded files from being listed, allowing unauthenticated users to access and download uploaded resumes", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:57Z" diff --git a/advisories/unreviewed/2025/05/GHSA-phhw-fr9r-6qv9/GHSA-phhw-fr9r-6qv9.json b/advisories/unreviewed/2025/05/GHSA-phhw-fr9r-6qv9/GHSA-phhw-fr9r-6qv9.json index 5c88c8247af..df9c2d8f80d 100644 --- a/advisories/unreviewed/2025/05/GHSA-phhw-fr9r-6qv9/GHSA-phhw-fr9r-6qv9.json +++ b/advisories/unreviewed/2025/05/GHSA-phhw-fr9r-6qv9/GHSA-phhw-fr9r-6qv9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-phhw-fr9r-6qv9", - "modified": "2025-05-15T21:31:33Z", + "modified": "2025-05-17T06:30:27Z", "published": "2025-05-15T21:31:33Z", "aliases": [ "CVE-2024-9227" ], "details": "The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow admin users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:16:00Z" diff --git a/advisories/unreviewed/2025/05/GHSA-prfq-pmqw-27fc/GHSA-prfq-pmqw-27fc.json b/advisories/unreviewed/2025/05/GHSA-prfq-pmqw-27fc/GHSA-prfq-pmqw-27fc.json index 43afb19f24f..a7528da06b8 100644 --- a/advisories/unreviewed/2025/05/GHSA-prfq-pmqw-27fc/GHSA-prfq-pmqw-27fc.json +++ b/advisories/unreviewed/2025/05/GHSA-prfq-pmqw-27fc/GHSA-prfq-pmqw-27fc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-prfq-pmqw-27fc", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-17T06:30:26Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-8398" ], "details": "The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:58Z" diff --git a/advisories/unreviewed/2025/05/GHSA-pv77-pr9x-9r7m/GHSA-pv77-pr9x-9r7m.json b/advisories/unreviewed/2025/05/GHSA-pv77-pr9x-9r7m/GHSA-pv77-pr9x-9r7m.json new file mode 100644 index 00000000000..d4c80f19b1a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pv77-pr9x-9r7m/GHSA-pv77-pr9x-9r7m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv77-pr9x-9r7m", + "modified": "2025-05-17T06:30:27Z", + "published": "2025-05-17T06:30:27Z", + "aliases": [ + "CVE-2025-4194" + ], + "details": "The AlT Monitoring plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the 'ALT_Monitoring_edit' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4194" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/alt-monitoring" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b7290317-418d-4e5c-85fa-f931cc4a865b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T04:16:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q86g-hcf4-hx9x/GHSA-q86g-hcf4-hx9x.json b/advisories/unreviewed/2025/05/GHSA-q86g-hcf4-hx9x/GHSA-q86g-hcf4-hx9x.json new file mode 100644 index 00000000000..cf2f19a9d2d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q86g-hcf4-hx9x/GHSA-q86g-hcf4-hx9x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q86g-hcf4-hx9x", + "modified": "2025-05-17T06:30:28Z", + "published": "2025-05-17T06:30:28Z", + "aliases": [ + "CVE-2025-4389" + ], + "details": "The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the crawlomatic_generate_featured_image() function in all versions up to, and including, 2.6.8.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4389" + }, + { + "type": "WEB", + "url": "https://codecanyon.net/item/crawlomatic-multisite-scraper-post-generator-plugin-for-wordpress/20476010" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1283e839-8588-4a76-9c1e-61562526166d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T06:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r48q-9g76-wf99/GHSA-r48q-9g76-wf99.json b/advisories/unreviewed/2025/05/GHSA-r48q-9g76-wf99/GHSA-r48q-9g76-wf99.json new file mode 100644 index 00000000000..ff096dbdddc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r48q-9g76-wf99/GHSA-r48q-9g76-wf99.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r48q-9g76-wf99", + "modified": "2025-05-17T06:30:27Z", + "published": "2025-05-17T06:30:27Z", + "aliases": [ + "CVE-2025-4189" + ], + "details": "The Audio Comments Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on the 'audio-comments/audior-settings.php' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4189" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/audio-comments/trunk/audior-settings.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/89b12c36-e115-4f67-86e6-647dfc9fd25b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T04:16:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wf67-68fh-ggp2/GHSA-wf67-68fh-ggp2.json b/advisories/unreviewed/2025/05/GHSA-wf67-68fh-ggp2/GHSA-wf67-68fh-ggp2.json new file mode 100644 index 00000000000..e38bb3e6d45 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wf67-68fh-ggp2/GHSA-wf67-68fh-ggp2.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wf67-68fh-ggp2", + "modified": "2025-05-17T06:30:28Z", + "published": "2025-05-17T06:30:28Z", + "aliases": [ + "CVE-2025-4816" + ], + "details": "A vulnerability was found in SourceCodester Doctor's Appointment System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/appointment.php of the component GET Parameter Handler. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4816" + }, + { + "type": "WEB", + "url": "https://github.com/Xiaoyi-ing/CVE/issues/8" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309273" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309273" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.574129" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T04:16:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wfcx-m66p-g8fw/GHSA-wfcx-m66p-g8fw.json b/advisories/unreviewed/2025/05/GHSA-wfcx-m66p-g8fw/GHSA-wfcx-m66p-g8fw.json new file mode 100644 index 00000000000..eb03b0d1abe --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wfcx-m66p-g8fw/GHSA-wfcx-m66p-g8fw.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfcx-m66p-g8fw", + "modified": "2025-05-17T06:30:28Z", + "published": "2025-05-17T06:30:28Z", + "aliases": [ + "CVE-2025-4818" + ], + "details": "A vulnerability was found in SourceCodester Doctor's Appointment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/delete-doctor.php of the component GET Parameter Handler. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4818" + }, + { + "type": "WEB", + "url": "https://github.com/Xiaoyi-ing/CVE/issues/10" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309275" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309275" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.574219" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T05:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wm93-qjx4-vmf3/GHSA-wm93-qjx4-vmf3.json b/advisories/unreviewed/2025/05/GHSA-wm93-qjx4-vmf3/GHSA-wm93-qjx4-vmf3.json new file mode 100644 index 00000000000..d17cc41acaa --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wm93-qjx4-vmf3/GHSA-wm93-qjx4-vmf3.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm93-qjx4-vmf3", + "modified": "2025-05-17T06:30:28Z", + "published": "2025-05-17T06:30:28Z", + "aliases": [ + "CVE-2025-4819" + ], + "details": "A vulnerability classified as problematic has been found in y_project RuoYi 4.8.0. Affected is an unknown function of the file /monitor/online/batchForceLogout of the component Offline Logout. The manipulation of the argument ids leads to improper authorization. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4819" + }, + { + "type": "WEB", + "url": "https://github.com/chujianxin0101/vuln/issues/4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309276" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309276" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.574443" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T06:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wpp3-qg8g-86cw/GHSA-wpp3-qg8g-86cw.json b/advisories/unreviewed/2025/05/GHSA-wpp3-qg8g-86cw/GHSA-wpp3-qg8g-86cw.json index 9489a957b50..44b2fd20e49 100644 --- a/advisories/unreviewed/2025/05/GHSA-wpp3-qg8g-86cw/GHSA-wpp3-qg8g-86cw.json +++ b/advisories/unreviewed/2025/05/GHSA-wpp3-qg8g-86cw/GHSA-wpp3-qg8g-86cw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wpp3-qg8g-86cw", - "modified": "2025-05-15T21:31:33Z", + "modified": "2025-05-17T06:30:27Z", "published": "2025-05-15T21:31:33Z", "aliases": [ "CVE-2024-9390" ], "details": "The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:16:00Z" diff --git a/advisories/unreviewed/2025/05/GHSA-x579-fc2r-gxmj/GHSA-x579-fc2r-gxmj.json b/advisories/unreviewed/2025/05/GHSA-x579-fc2r-gxmj/GHSA-x579-fc2r-gxmj.json index 3dffe2ee455..eea84b91041 100644 --- a/advisories/unreviewed/2025/05/GHSA-x579-fc2r-gxmj/GHSA-x579-fc2r-gxmj.json +++ b/advisories/unreviewed/2025/05/GHSA-x579-fc2r-gxmj/GHSA-x579-fc2r-gxmj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x579-fc2r-gxmj", - "modified": "2025-05-15T21:31:33Z", + "modified": "2025-05-17T06:30:26Z", "published": "2025-05-15T21:31:33Z", "aliases": [ "CVE-2024-9182" ], "details": "The Maspik WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:16:00Z" diff --git a/advisories/unreviewed/2025/05/GHSA-x9mr-w276-h3c2/GHSA-x9mr-w276-h3c2.json b/advisories/unreviewed/2025/05/GHSA-x9mr-w276-h3c2/GHSA-x9mr-w276-h3c2.json index b5e7ed63566..446bc974adf 100644 --- a/advisories/unreviewed/2025/05/GHSA-x9mr-w276-h3c2/GHSA-x9mr-w276-h3c2.json +++ b/advisories/unreviewed/2025/05/GHSA-x9mr-w276-h3c2/GHSA-x9mr-w276-h3c2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x9mr-w276-h3c2", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-17T06:30:25Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-7984" ], "details": "The Joy Of Text Lite WordPress plugin through 2.3.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:57Z" diff --git a/advisories/unreviewed/2025/05/GHSA-xc5x-xvcr-5h87/GHSA-xc5x-xvcr-5h87.json b/advisories/unreviewed/2025/05/GHSA-xc5x-xvcr-5h87/GHSA-xc5x-xvcr-5h87.json index 105e68b45bb..402b0dfc397 100644 --- a/advisories/unreviewed/2025/05/GHSA-xc5x-xvcr-5h87/GHSA-xc5x-xvcr-5h87.json +++ b/advisories/unreviewed/2025/05/GHSA-xc5x-xvcr-5h87/GHSA-xc5x-xvcr-5h87.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xc5x-xvcr-5h87", - "modified": "2025-05-15T21:31:33Z", + "modified": "2025-05-17T06:30:26Z", "published": "2025-05-15T21:31:33Z", "aliases": [ "CVE-2024-8493" ], "details": "The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:58Z"