diff --git a/advisories/unreviewed/2022/05/GHSA-8gr9-6mc8-jj84/GHSA-8gr9-6mc8-jj84.json b/advisories/unreviewed/2022/05/GHSA-8gr9-6mc8-jj84/GHSA-8gr9-6mc8-jj84.json index eeba1a1d265..a87e960b132 100644 --- a/advisories/unreviewed/2022/05/GHSA-8gr9-6mc8-jj84/GHSA-8gr9-6mc8-jj84.json +++ b/advisories/unreviewed/2022/05/GHSA-8gr9-6mc8-jj84/GHSA-8gr9-6mc8-jj84.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8gr9-6mc8-jj84", - "modified": "2022-05-24T19:08:54Z", + "modified": "2023-11-19T00:30:25Z", "published": "2022-05-24T19:08:54Z", "aliases": [ "CVE-2020-22283" ], "details": "A buffer overflow vulnerability in the icmp6_send_response_with_addrs_and_netif() function of Free Software Foundation lwIP version git head allows attackers to access sensitive information via a crafted ICMPv6 packet.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -18,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-22283" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/11/msg00011.html" + }, { "type": "WEB", "url": "https://savannah.nongnu.org/bugs/index.php?58553" diff --git a/advisories/unreviewed/2023/11/GHSA-4gr8-q66q-jcqr/GHSA-4gr8-q66q-jcqr.json b/advisories/unreviewed/2023/11/GHSA-4gr8-q66q-jcqr/GHSA-4gr8-q66q-jcqr.json new file mode 100644 index 00000000000..b2a4e4b441b --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-4gr8-q66q-jcqr/GHSA-4gr8-q66q-jcqr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gr8-q66q-jcqr", + "modified": "2023-11-19T00:30:26Z", + "published": "2023-11-19T00:30:26Z", + "aliases": [ + "CVE-2023-41129" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Patreon Patreon WordPress.This issue affects Patreon WordPress: from n/a through 1.8.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41129" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/patreon-connect/wordpress-patreon-wordpress-plugin-1-8-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-18T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-5v2w-xx9v-q8gh/GHSA-5v2w-xx9v-q8gh.json b/advisories/unreviewed/2023/11/GHSA-5v2w-xx9v-q8gh/GHSA-5v2w-xx9v-q8gh.json new file mode 100644 index 00000000000..9abf92190a1 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-5v2w-xx9v-q8gh/GHSA-5v2w-xx9v-q8gh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v2w-xx9v-q8gh", + "modified": "2023-11-19T00:30:26Z", + "published": "2023-11-19T00:30:26Z", + "aliases": [ + "CVE-2023-25985" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Tomas | Docs | FAQ | Premium Support WordPress Tooltips.This issue affects WordPress Tooltips: from n/a through 8.2.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25985" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wordpress-tooltips/wordpress-wordpress-tooltips-plugin-8-2-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-18T23:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-7268-qqjc-4287/GHSA-7268-qqjc-4287.json b/advisories/unreviewed/2023/11/GHSA-7268-qqjc-4287/GHSA-7268-qqjc-4287.json new file mode 100644 index 00000000000..37ef2e6ea70 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-7268-qqjc-4287/GHSA-7268-qqjc-4287.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7268-qqjc-4287", + "modified": "2023-11-19T00:30:26Z", + "published": "2023-11-19T00:30:26Z", + "aliases": [ + "CVE-2023-32504" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Kainex Wise Chat.This issue affects Wise Chat: from n/a through 3.1.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32504" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wise-chat/wordpress-wise-chat-plugin-3-1-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-18T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-744h-wr4m-3wwg/GHSA-744h-wr4m-3wwg.json b/advisories/unreviewed/2023/11/GHSA-744h-wr4m-3wwg/GHSA-744h-wr4m-3wwg.json new file mode 100644 index 00000000000..6d3998d980c --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-744h-wr4m-3wwg/GHSA-744h-wr4m-3wwg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-744h-wr4m-3wwg", + "modified": "2023-11-19T00:30:25Z", + "published": "2023-11-19T00:30:25Z", + "aliases": [ + "CVE-2023-47551" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in RedNao Donations Made Easy – Smart Donations.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47551" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/smart-donations/wordpress-donations-made-easy-smart-donations-plugin-4-0-12-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-18T22:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-7v3h-7467-f5w5/GHSA-7v3h-7467-f5w5.json b/advisories/unreviewed/2023/11/GHSA-7v3h-7467-f5w5/GHSA-7v3h-7467-f5w5.json new file mode 100644 index 00000000000..cfa424ce65b --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-7v3h-7467-f5w5/GHSA-7v3h-7467-f5w5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v3h-7467-f5w5", + "modified": "2023-11-19T00:30:26Z", + "published": "2023-11-19T00:30:26Z", + "aliases": [ + "CVE-2023-47655" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi ANAC XML Bandi di Gara.This issue affects ANAC XML Bandi di Gara: from n/a through 7.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47655" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/avcp/wordpress-anac-xml-bandi-di-gara-plugin-7-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-18T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-87hw-vpm8-xxh2/GHSA-87hw-vpm8-xxh2.json b/advisories/unreviewed/2023/11/GHSA-87hw-vpm8-xxh2/GHSA-87hw-vpm8-xxh2.json new file mode 100644 index 00000000000..7049850eae5 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-87hw-vpm8-xxh2/GHSA-87hw-vpm8-xxh2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87hw-vpm8-xxh2", + "modified": "2023-11-19T00:30:26Z", + "published": "2023-11-19T00:30:26Z", + "aliases": [ + "CVE-2023-47644" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Memberships, Groups and Communities: from n/a through 5.6.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47644" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/profilegrid-user-profiles-groups-and-communities/wordpress-profilegrid-plugin-5-6-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-18T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-8jm5-wxh9-mgjr/GHSA-8jm5-wxh9-mgjr.json b/advisories/unreviewed/2023/11/GHSA-8jm5-wxh9-mgjr/GHSA-8jm5-wxh9-mgjr.json new file mode 100644 index 00000000000..801dedf43ef --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-8jm5-wxh9-mgjr/GHSA-8jm5-wxh9-mgjr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jm5-wxh9-mgjr", + "modified": "2023-11-19T00:30:26Z", + "published": "2023-11-19T00:30:26Z", + "aliases": [ + "CVE-2023-47650" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Peter Sterling Add Local Avatar.This issue affects Add Local Avatar: from n/a through 12.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47650" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/add-local-avatar/wordpress-add-local-avatar-plugin-12-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-18T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-97ww-gv43-8hmw/GHSA-97ww-gv43-8hmw.json b/advisories/unreviewed/2023/11/GHSA-97ww-gv43-8hmw/GHSA-97ww-gv43-8hmw.json new file mode 100644 index 00000000000..df8db76cc0d --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-97ww-gv43-8hmw/GHSA-97ww-gv43-8hmw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97ww-gv43-8hmw", + "modified": "2023-11-19T00:30:26Z", + "published": "2023-11-19T00:30:26Z", + "aliases": [ + "CVE-2023-32245" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WPDeveloper Essential Addons for Elementor Pro.This issue affects Essential Addons for Elementor Pro: from n/a through 5.4.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32245" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/essential-addons-elementor/wordpress-essential-addons-for-elementor-pro-plugin-5-4-8-unauthenticated-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-18T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-cfj2-49q4-43j5/GHSA-cfj2-49q4-43j5.json b/advisories/unreviewed/2023/11/GHSA-cfj2-49q4-43j5/GHSA-cfj2-49q4-43j5.json new file mode 100644 index 00000000000..a8c851eae68 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-cfj2-49q4-43j5/GHSA-cfj2-49q4-43j5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfj2-49q4-43j5", + "modified": "2023-11-19T00:30:26Z", + "published": "2023-11-19T00:30:26Z", + "aliases": [ + "CVE-2023-32514" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Himanshu Parashar Google Site Verification plugin using Meta Tag.This issue affects Google Site Verification plugin using Meta Tag: from n/a through 1.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32514" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/google-site-verification-using-meta-tag/wordpress-google-site-verification-plugin-using-meta-tag-plugin-1-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-18T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-cg22-2r83-3795/GHSA-cg22-2r83-3795.json b/advisories/unreviewed/2023/11/GHSA-cg22-2r83-3795/GHSA-cg22-2r83-3795.json new file mode 100644 index 00000000000..e929b56c64f --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-cg22-2r83-3795/GHSA-cg22-2r83-3795.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg22-2r83-3795", + "modified": "2023-11-19T00:30:25Z", + "published": "2023-11-19T00:30:25Z", + "aliases": [ + "CVE-2023-47519" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WC Product Table WooCommerce Product Table Lite.This issue affects WooCommerce Product Table Lite: from n/a through 2.6.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47519" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wc-product-table-lite/wordpress-woocommerce-product-table-lite-plugin-2-6-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-18T22:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-fh45-j2m9-4mxm/GHSA-fh45-j2m9-4mxm.json b/advisories/unreviewed/2023/11/GHSA-fh45-j2m9-4mxm/GHSA-fh45-j2m9-4mxm.json new file mode 100644 index 00000000000..c04ed5abeae --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-fh45-j2m9-4mxm/GHSA-fh45-j2m9-4mxm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh45-j2m9-4mxm", + "modified": "2023-11-19T00:30:25Z", + "published": "2023-11-19T00:30:25Z", + "aliases": [ + "CVE-2023-47553" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in User Local Inc UserHeat Plugin.This issue affects UserHeat Plugin: from n/a through 1.1.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47553" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/userheat/wordpress-userheat-plugin-plugin-1-1-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-18T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-g63g-r6gc-cxmv/GHSA-g63g-r6gc-cxmv.json b/advisories/unreviewed/2023/11/GHSA-g63g-r6gc-cxmv/GHSA-g63g-r6gc-cxmv.json new file mode 100644 index 00000000000..bf9d5f4cdd6 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-g63g-r6gc-cxmv/GHSA-g63g-r6gc-cxmv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g63g-r6gc-cxmv", + "modified": "2023-11-19T00:30:25Z", + "published": "2023-11-19T00:30:25Z", + "aliases": [ + "CVE-2023-47531" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in DroitThemes Droit Dark Mode.This issue affects Droit Dark Mode: from n/a through 1.1.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47531" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/droit-dark-mode/wordpress-droit-dark-mode-plugin-1-1-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-18T22:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-ggwr-xqfc-8r6r/GHSA-ggwr-xqfc-8r6r.json b/advisories/unreviewed/2023/11/GHSA-ggwr-xqfc-8r6r/GHSA-ggwr-xqfc-8r6r.json new file mode 100644 index 00000000000..bc8aa7b3b06 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-ggwr-xqfc-8r6r/GHSA-ggwr-xqfc-8r6r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggwr-xqfc-8r6r", + "modified": "2023-11-19T00:30:26Z", + "published": "2023-11-19T00:30:26Z", + "aliases": [ + "CVE-2023-31089" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Tradebooster Video XML Sitemap Generator.This issue affects Video XML Sitemap Generator: from n/a through 1.0.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31089" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/video-xml-sitemap-generator/wordpress-video-xml-sitemap-generator-plugin-1-0-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-18T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-hwcm-r27w-h6mp/GHSA-hwcm-r27w-h6mp.json b/advisories/unreviewed/2023/11/GHSA-hwcm-r27w-h6mp/GHSA-hwcm-r27w-h6mp.json new file mode 100644 index 00000000000..24b7aa3a325 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-hwcm-r27w-h6mp/GHSA-hwcm-r27w-h6mp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwcm-r27w-h6mp", + "modified": "2023-11-19T00:30:25Z", + "published": "2023-11-19T00:30:25Z", + "aliases": [ + "CVE-2023-47243" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in CodeMShop 코드엠샵 마이사이트 – MSHOP MY SITE.This issue affects 코드엠샵 마이사이트 – MSHOP MY SITE: from n/a through 1.1.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47243" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mshop-mysite/wordpress-mshop-my-site-plugin-1-1-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-18T22:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-jhm2-45hc-7q9f/GHSA-jhm2-45hc-7q9f.json b/advisories/unreviewed/2023/11/GHSA-jhm2-45hc-7q9f/GHSA-jhm2-45hc-7q9f.json new file mode 100644 index 00000000000..df60fc1ef0e --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-jhm2-45hc-7q9f/GHSA-jhm2-45hc-7q9f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhm2-45hc-7q9f", + "modified": "2023-11-19T00:30:26Z", + "published": "2023-11-19T00:30:26Z", + "aliases": [ + "CVE-2023-47649" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in PriceListo Best Restaurant Menu by PriceListo.This issue affects Best Restaurant Menu by PriceListo: from n/a through 1.3.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47649" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/best-restaurant-menu-by-pricelisto/wordpress-best-restaurant-menu-by-pricelisto-plugin-1-3-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-18T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-m48v-hpw2-8w3j/GHSA-m48v-hpw2-8w3j.json b/advisories/unreviewed/2023/11/GHSA-m48v-hpw2-8w3j/GHSA-m48v-hpw2-8w3j.json new file mode 100644 index 00000000000..76e0bd37827 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-m48v-hpw2-8w3j/GHSA-m48v-hpw2-8w3j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m48v-hpw2-8w3j", + "modified": "2023-11-19T00:30:26Z", + "published": "2023-11-19T00:30:26Z", + "aliases": [ + "CVE-2023-47651" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Robert Macchi WP Links Page.This issue affects WP Links Page: from n/a through 4.9.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47651" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-links-page/wordpress-wp-links-page-plugin-4-9-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-18T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-m86g-4hvg-8jxc/GHSA-m86g-4hvg-8jxc.json b/advisories/unreviewed/2023/11/GHSA-m86g-4hvg-8jxc/GHSA-m86g-4hvg-8jxc.json new file mode 100644 index 00000000000..1702918c15f --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-m86g-4hvg-8jxc/GHSA-m86g-4hvg-8jxc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m86g-4hvg-8jxc", + "modified": "2023-11-19T00:30:25Z", + "published": "2023-11-19T00:30:25Z", + "aliases": [ + "CVE-2023-47552" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Labib Ahmed Image Hover Effects – WordPress Plugin.This issue affects Image Hover Effects – WordPress Plugin: from n/a through 5.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47552" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/image-hover-effects/wordpress-image-hover-effects-plugin-5-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-18T22:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-rwmv-5cmc-6rpx/GHSA-rwmv-5cmc-6rpx.json b/advisories/unreviewed/2023/11/GHSA-rwmv-5cmc-6rpx/GHSA-rwmv-5cmc-6rpx.json new file mode 100644 index 00000000000..18d150120fb --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-rwmv-5cmc-6rpx/GHSA-rwmv-5cmc-6rpx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwmv-5cmc-6rpx", + "modified": "2023-11-19T00:30:26Z", + "published": "2023-11-19T00:30:26Z", + "aliases": [ + "CVE-2023-31075" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Arshid Easy Hide Login.This issue affects Easy Hide Login: from n/a through 1.0.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31075" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/easy-hide-login/wordpress-easy-hide-login-plugin-1-0-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-18T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-v4qp-qmv7-6wm8/GHSA-v4qp-qmv7-6wm8.json b/advisories/unreviewed/2023/11/GHSA-v4qp-qmv7-6wm8/GHSA-v4qp-qmv7-6wm8.json new file mode 100644 index 00000000000..ef428af2b07 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-v4qp-qmv7-6wm8/GHSA-v4qp-qmv7-6wm8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4qp-qmv7-6wm8", + "modified": "2023-11-19T00:30:26Z", + "published": "2023-11-19T00:30:26Z", + "aliases": [ + "CVE-2023-28780" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Yoast Yoast Local Premium.This issue affects Yoast Local Premium: from n/a through 14.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28780" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpseo-local/wordpress-yoast-seo-local-plugin-14-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-18T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-v73c-376g-v9qj/GHSA-v73c-376g-v9qj.json b/advisories/unreviewed/2023/11/GHSA-v73c-376g-v9qj/GHSA-v73c-376g-v9qj.json new file mode 100644 index 00000000000..e008ec99a90 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-v73c-376g-v9qj/GHSA-v73c-376g-v9qj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v73c-376g-v9qj", + "modified": "2023-11-19T00:30:26Z", + "published": "2023-11-19T00:30:26Z", + "aliases": [ + "CVE-2023-47556" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in James Mehorter Device Theme Switcher.This issue affects Device Theme Switcher: from n/a through 3.0.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47556" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/device-theme-switcher/wordpress-plugin-name-device-theme-switcher-plugin-3-0-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-18T22:15:08Z" + } +} \ No newline at end of file