From c2c945ae025516f15b65476f65ec6eb06eba967d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 16 Dec 2024 15:33:10 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-6w8c-45mh-9rvm.json | 4 +- .../GHSA-m7gg-q7qj-3r2r.json | 1 + .../GHSA-262g-fr6f-r3xc.json | 36 +++++++++++++++++ .../GHSA-2cc5-8q8w-gqw8.json | 36 +++++++++++++++++ .../GHSA-2qrr-fxgw-wwcx.json | 36 +++++++++++++++++ .../GHSA-2xv4-ch54-5wmx.json | 36 +++++++++++++++++ .../GHSA-328g-2x6r-r5fg.json | 36 +++++++++++++++++ .../GHSA-37xf-px7h-945g.json | 36 +++++++++++++++++ .../GHSA-394w-f725-94hh.json | 36 +++++++++++++++++ .../GHSA-39wc-cq75-x375.json | 36 +++++++++++++++++ .../GHSA-3jj9-9287-pj45.json | 36 +++++++++++++++++ .../GHSA-3m7j-hg3r-8fw7.json | 36 +++++++++++++++++ .../GHSA-43fx-2cfr-rfxj.json | 36 +++++++++++++++++ .../GHSA-4fg5-v4j6-7jhj.json | 36 +++++++++++++++++ .../GHSA-4mm3-32x8-9pg9.json | 36 +++++++++++++++++ .../GHSA-4r28-24qr-fj7r.json | 36 +++++++++++++++++ .../GHSA-4xrm-6vq2-f7mq.json | 36 +++++++++++++++++ .../GHSA-537w-3mmj-9pr3.json | 36 +++++++++++++++++ .../GHSA-556w-mh92-76gh.json | 36 +++++++++++++++++ .../GHSA-595w-xcwx-w23j.json | 36 +++++++++++++++++ .../GHSA-5f3c-j6m9-3fqv.json | 36 +++++++++++++++++ .../GHSA-5fcg-g7jg-hx9p.json | 36 +++++++++++++++++ .../GHSA-5h2x-fwcw-rwv2.json | 36 +++++++++++++++++ .../GHSA-5xmv-h4m3-4vx5.json | 36 +++++++++++++++++ .../GHSA-6fp6-p23m-84hh.json | 36 +++++++++++++++++ .../GHSA-6m5p-x936-73hr.json | 36 +++++++++++++++++ .../GHSA-6q8m-vq2h-r3j2.json | 36 +++++++++++++++++ .../GHSA-765j-hqm9-rj5c.json | 36 +++++++++++++++++ .../GHSA-772g-rc25-jfc4.json | 36 +++++++++++++++++ .../GHSA-7788-cmgc-rw4w.json | 36 +++++++++++++++++ .../GHSA-77ch-rvc7-4fjv.json | 36 +++++++++++++++++ .../GHSA-7q86-pv7h-63qc.json | 36 +++++++++++++++++ .../GHSA-7qpr-85r9-qfcc.json | 36 +++++++++++++++++ .../GHSA-7v7x-8p54-6fgp.json | 36 +++++++++++++++++ .../GHSA-86wm-x842-r6gc.json | 36 +++++++++++++++++ .../GHSA-8725-gx62-5qhc.json | 36 +++++++++++++++++ .../GHSA-8c5x-9gh7-8vm2.json | 36 +++++++++++++++++ .../GHSA-8ph5-4j2w-wmhg.json | 36 +++++++++++++++++ .../GHSA-8q92-x23f-rvxh.json | 36 +++++++++++++++++ .../GHSA-8rhv-37fw-8hc2.json | 36 +++++++++++++++++ .../GHSA-8rmx-gfxw-r4q8.json | 36 +++++++++++++++++ .../GHSA-8vjg-gr7v-8hv3.json | 36 +++++++++++++++++ .../GHSA-9256-qm87-9345.json | 36 +++++++++++++++++ .../GHSA-92pc-gccf-whq7.json | 36 +++++++++++++++++ .../GHSA-9656-v933-mxp7.json | 36 +++++++++++++++++ .../GHSA-97hv-pw4c-xf38.json | 36 +++++++++++++++++ .../GHSA-9fcv-79vj-hrf3.json | 36 +++++++++++++++++ .../GHSA-9pc9-px3j-hxmw.json | 36 +++++++++++++++++ .../GHSA-9pgc-34gm-jwr2.json | 36 +++++++++++++++++ .../GHSA-9qpp-96vr-f3r8.json | 36 +++++++++++++++++ .../GHSA-9xj8-533q-hxq7.json | 36 +++++++++++++++++ .../GHSA-c36x-7qg6-qwjj.json | 36 +++++++++++++++++ .../GHSA-c3hf-hhg3-xg3m.json | 36 +++++++++++++++++ .../GHSA-c68r-r29p-9xpp.json | 36 +++++++++++++++++ .../GHSA-c6pw-qh93-r927.json | 36 +++++++++++++++++ .../GHSA-c827-f4c9-92x2.json | 36 +++++++++++++++++ .../GHSA-c82h-4vv7-76g8.json | 36 +++++++++++++++++ .../GHSA-cp2j-jp3f-vjpj.json | 36 +++++++++++++++++ .../GHSA-cv8q-wprf-95p9.json | 36 +++++++++++++++++ .../GHSA-fgg3-pvqg-v5pf.json | 36 +++++++++++++++++ .../GHSA-fq38-2fgf-27mv.json | 36 +++++++++++++++++ .../GHSA-frcj-vgwr-3f9p.json | 36 +++++++++++++++++ .../GHSA-fv85-82q3-9pf8.json | 36 +++++++++++++++++ .../GHSA-fvf3-w678-5823.json | 36 +++++++++++++++++ .../GHSA-gcvm-mm2c-wrfh.json | 36 +++++++++++++++++ .../GHSA-gq6w-rgrp-976h.json | 36 +++++++++++++++++ .../GHSA-gx52-wqq6-r834.json | 36 +++++++++++++++++ .../GHSA-h32q-4pph-8pgm.json | 2 +- .../GHSA-h3fr-83x2-rwvv.json | 36 +++++++++++++++++ .../GHSA-h7r9-3wpm-8jg6.json | 36 +++++++++++++++++ .../GHSA-hj8f-99rq-2qg5.json | 36 +++++++++++++++++ .../GHSA-hjxc-5vcp-9rmf.json | 36 +++++++++++++++++ .../GHSA-hpr8-g3rf-4f89.json | 36 +++++++++++++++++ .../GHSA-hpwc-g7x9-qgm8.json | 36 +++++++++++++++++ .../GHSA-hqgq-wgpj-wxwf.json | 36 +++++++++++++++++ .../GHSA-hv8q-qqrh-ccgj.json | 36 +++++++++++++++++ .../GHSA-hwq4-qw38-h933.json | 36 +++++++++++++++++ .../GHSA-j2f8-56pc-7gmr.json | 36 +++++++++++++++++ .../GHSA-jq38-2x24-q99r.json | 36 +++++++++++++++++ .../GHSA-jr93-xph2-hggc.json | 36 +++++++++++++++++ .../GHSA-m5qp-25mc-53xj.json | 36 +++++++++++++++++ .../GHSA-mcw9-h88f-7f3f.json | 36 +++++++++++++++++ .../GHSA-mrfc-m82j-82wf.json | 36 +++++++++++++++++ .../GHSA-mv4h-62h2-5hwv.json | 36 +++++++++++++++++ .../GHSA-mwqf-g5pc-qrr8.json | 36 +++++++++++++++++ .../GHSA-mx9w-v2pf-gr86.json | 36 +++++++++++++++++ .../GHSA-p49r-xxpc-j8fj.json | 36 +++++++++++++++++ .../GHSA-p6m5-m496-hfm6.json | 36 +++++++++++++++++ .../GHSA-p7qh-jh34-85qr.json | 36 +++++++++++++++++ .../GHSA-p8cc-27cr-294h.json | 36 +++++++++++++++++ .../GHSA-pcgf-8qxw-vjpc.json | 36 +++++++++++++++++ .../GHSA-pqhv-cv76-m4hc.json | 36 +++++++++++++++++ .../GHSA-pvqx-h7hh-wp79.json | 36 +++++++++++++++++ .../GHSA-q5vw-gwwh-j8r7.json | 36 +++++++++++++++++ .../GHSA-q97w-jc54-cmqr.json | 36 +++++++++++++++++ .../GHSA-qc35-5wrm-x6wx.json | 40 +++++++++++++++++++ .../GHSA-qhgg-j635-qfw9.json | 36 +++++++++++++++++ .../GHSA-qp25-vh5m-jhp5.json | 36 +++++++++++++++++ .../GHSA-qrwq-c8cf-p4wv.json | 36 +++++++++++++++++ .../GHSA-r65p-7pcp-4hmm.json | 36 +++++++++++++++++ .../GHSA-rc8c-8v29-wf9h.json | 36 +++++++++++++++++ .../GHSA-rhhv-6w3f-j654.json | 36 +++++++++++++++++ .../GHSA-v267-h3hm-27xj.json | 36 +++++++++++++++++ .../GHSA-v3jg-qf5j-54wh.json | 36 +++++++++++++++++ .../GHSA-v3qf-fgcw-33vg.json | 36 +++++++++++++++++ .../GHSA-v5wp-6cxh-7g56.json | 36 +++++++++++++++++ .../GHSA-v846-wcv6-j9fr.json | 36 +++++++++++++++++ .../GHSA-vcjh-jjp4-2cxf.json | 36 +++++++++++++++++ .../GHSA-vcp9-mrmm-2gh8.json | 36 +++++++++++++++++ .../GHSA-vfcc-4q8x-f299.json | 36 +++++++++++++++++ .../GHSA-vg3c-gxqw-hr85.json | 36 +++++++++++++++++ .../GHSA-vhww-mm25-q8mv.json | 36 +++++++++++++++++ .../GHSA-vjr5-7gc7-rrhq.json | 36 +++++++++++++++++ .../GHSA-vpp4-4mqw-4hw7.json | 36 +++++++++++++++++ .../GHSA-w3r7-6c65-fr45.json | 36 +++++++++++++++++ .../GHSA-w4w2-7q2f-mxm4.json | 36 +++++++++++++++++ .../GHSA-w926-rj83-69p8.json | 36 +++++++++++++++++ .../GHSA-w97j-3h9r-h9rm.json | 36 +++++++++++++++++ .../GHSA-wgjj-vjmp-269h.json | 36 +++++++++++++++++ .../GHSA-wgq9-xh75-7fxc.json | 36 +++++++++++++++++ .../GHSA-wwm7-p227-pcgv.json | 36 +++++++++++++++++ .../GHSA-wx4q-8vh8-7998.json | 36 +++++++++++++++++ .../GHSA-x45w-x6jp-jg2w.json | 36 +++++++++++++++++ .../GHSA-x5hw-h4f2-565p.json | 36 +++++++++++++++++ .../GHSA-x942-9rvg-798r.json | 36 +++++++++++++++++ .../GHSA-xf96-h6wr-6499.json | 36 +++++++++++++++++ .../GHSA-xfv4-rqpc-qx97.json | 36 +++++++++++++++++ 127 files changed, 4473 insertions(+), 2 deletions(-) create mode 100644 advisories/unreviewed/2024/12/GHSA-262g-fr6f-r3xc/GHSA-262g-fr6f-r3xc.json create mode 100644 advisories/unreviewed/2024/12/GHSA-2cc5-8q8w-gqw8/GHSA-2cc5-8q8w-gqw8.json create mode 100644 advisories/unreviewed/2024/12/GHSA-2qrr-fxgw-wwcx/GHSA-2qrr-fxgw-wwcx.json create mode 100644 advisories/unreviewed/2024/12/GHSA-2xv4-ch54-5wmx/GHSA-2xv4-ch54-5wmx.json create mode 100644 advisories/unreviewed/2024/12/GHSA-328g-2x6r-r5fg/GHSA-328g-2x6r-r5fg.json create mode 100644 advisories/unreviewed/2024/12/GHSA-37xf-px7h-945g/GHSA-37xf-px7h-945g.json create mode 100644 advisories/unreviewed/2024/12/GHSA-394w-f725-94hh/GHSA-394w-f725-94hh.json create mode 100644 advisories/unreviewed/2024/12/GHSA-39wc-cq75-x375/GHSA-39wc-cq75-x375.json create mode 100644 advisories/unreviewed/2024/12/GHSA-3jj9-9287-pj45/GHSA-3jj9-9287-pj45.json create mode 100644 advisories/unreviewed/2024/12/GHSA-3m7j-hg3r-8fw7/GHSA-3m7j-hg3r-8fw7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-43fx-2cfr-rfxj/GHSA-43fx-2cfr-rfxj.json create mode 100644 advisories/unreviewed/2024/12/GHSA-4fg5-v4j6-7jhj/GHSA-4fg5-v4j6-7jhj.json create mode 100644 advisories/unreviewed/2024/12/GHSA-4mm3-32x8-9pg9/GHSA-4mm3-32x8-9pg9.json create mode 100644 advisories/unreviewed/2024/12/GHSA-4r28-24qr-fj7r/GHSA-4r28-24qr-fj7r.json create mode 100644 advisories/unreviewed/2024/12/GHSA-4xrm-6vq2-f7mq/GHSA-4xrm-6vq2-f7mq.json create mode 100644 advisories/unreviewed/2024/12/GHSA-537w-3mmj-9pr3/GHSA-537w-3mmj-9pr3.json create mode 100644 advisories/unreviewed/2024/12/GHSA-556w-mh92-76gh/GHSA-556w-mh92-76gh.json create mode 100644 advisories/unreviewed/2024/12/GHSA-595w-xcwx-w23j/GHSA-595w-xcwx-w23j.json create mode 100644 advisories/unreviewed/2024/12/GHSA-5f3c-j6m9-3fqv/GHSA-5f3c-j6m9-3fqv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-5fcg-g7jg-hx9p/GHSA-5fcg-g7jg-hx9p.json create mode 100644 advisories/unreviewed/2024/12/GHSA-5h2x-fwcw-rwv2/GHSA-5h2x-fwcw-rwv2.json create mode 100644 advisories/unreviewed/2024/12/GHSA-5xmv-h4m3-4vx5/GHSA-5xmv-h4m3-4vx5.json create mode 100644 advisories/unreviewed/2024/12/GHSA-6fp6-p23m-84hh/GHSA-6fp6-p23m-84hh.json create mode 100644 advisories/unreviewed/2024/12/GHSA-6m5p-x936-73hr/GHSA-6m5p-x936-73hr.json create mode 100644 advisories/unreviewed/2024/12/GHSA-6q8m-vq2h-r3j2/GHSA-6q8m-vq2h-r3j2.json create mode 100644 advisories/unreviewed/2024/12/GHSA-765j-hqm9-rj5c/GHSA-765j-hqm9-rj5c.json create mode 100644 advisories/unreviewed/2024/12/GHSA-772g-rc25-jfc4/GHSA-772g-rc25-jfc4.json create mode 100644 advisories/unreviewed/2024/12/GHSA-7788-cmgc-rw4w/GHSA-7788-cmgc-rw4w.json create mode 100644 advisories/unreviewed/2024/12/GHSA-77ch-rvc7-4fjv/GHSA-77ch-rvc7-4fjv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-7q86-pv7h-63qc/GHSA-7q86-pv7h-63qc.json create mode 100644 advisories/unreviewed/2024/12/GHSA-7qpr-85r9-qfcc/GHSA-7qpr-85r9-qfcc.json create mode 100644 advisories/unreviewed/2024/12/GHSA-7v7x-8p54-6fgp/GHSA-7v7x-8p54-6fgp.json create mode 100644 advisories/unreviewed/2024/12/GHSA-86wm-x842-r6gc/GHSA-86wm-x842-r6gc.json create mode 100644 advisories/unreviewed/2024/12/GHSA-8725-gx62-5qhc/GHSA-8725-gx62-5qhc.json create mode 100644 advisories/unreviewed/2024/12/GHSA-8c5x-9gh7-8vm2/GHSA-8c5x-9gh7-8vm2.json create mode 100644 advisories/unreviewed/2024/12/GHSA-8ph5-4j2w-wmhg/GHSA-8ph5-4j2w-wmhg.json create mode 100644 advisories/unreviewed/2024/12/GHSA-8q92-x23f-rvxh/GHSA-8q92-x23f-rvxh.json create mode 100644 advisories/unreviewed/2024/12/GHSA-8rhv-37fw-8hc2/GHSA-8rhv-37fw-8hc2.json create mode 100644 advisories/unreviewed/2024/12/GHSA-8rmx-gfxw-r4q8/GHSA-8rmx-gfxw-r4q8.json create mode 100644 advisories/unreviewed/2024/12/GHSA-8vjg-gr7v-8hv3/GHSA-8vjg-gr7v-8hv3.json create mode 100644 advisories/unreviewed/2024/12/GHSA-9256-qm87-9345/GHSA-9256-qm87-9345.json create mode 100644 advisories/unreviewed/2024/12/GHSA-92pc-gccf-whq7/GHSA-92pc-gccf-whq7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-9656-v933-mxp7/GHSA-9656-v933-mxp7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-97hv-pw4c-xf38/GHSA-97hv-pw4c-xf38.json create mode 100644 advisories/unreviewed/2024/12/GHSA-9fcv-79vj-hrf3/GHSA-9fcv-79vj-hrf3.json create mode 100644 advisories/unreviewed/2024/12/GHSA-9pc9-px3j-hxmw/GHSA-9pc9-px3j-hxmw.json create mode 100644 advisories/unreviewed/2024/12/GHSA-9pgc-34gm-jwr2/GHSA-9pgc-34gm-jwr2.json create mode 100644 advisories/unreviewed/2024/12/GHSA-9qpp-96vr-f3r8/GHSA-9qpp-96vr-f3r8.json create mode 100644 advisories/unreviewed/2024/12/GHSA-9xj8-533q-hxq7/GHSA-9xj8-533q-hxq7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-c36x-7qg6-qwjj/GHSA-c36x-7qg6-qwjj.json create mode 100644 advisories/unreviewed/2024/12/GHSA-c3hf-hhg3-xg3m/GHSA-c3hf-hhg3-xg3m.json create mode 100644 advisories/unreviewed/2024/12/GHSA-c68r-r29p-9xpp/GHSA-c68r-r29p-9xpp.json create mode 100644 advisories/unreviewed/2024/12/GHSA-c6pw-qh93-r927/GHSA-c6pw-qh93-r927.json create mode 100644 advisories/unreviewed/2024/12/GHSA-c827-f4c9-92x2/GHSA-c827-f4c9-92x2.json create mode 100644 advisories/unreviewed/2024/12/GHSA-c82h-4vv7-76g8/GHSA-c82h-4vv7-76g8.json create mode 100644 advisories/unreviewed/2024/12/GHSA-cp2j-jp3f-vjpj/GHSA-cp2j-jp3f-vjpj.json create mode 100644 advisories/unreviewed/2024/12/GHSA-cv8q-wprf-95p9/GHSA-cv8q-wprf-95p9.json create mode 100644 advisories/unreviewed/2024/12/GHSA-fgg3-pvqg-v5pf/GHSA-fgg3-pvqg-v5pf.json create mode 100644 advisories/unreviewed/2024/12/GHSA-fq38-2fgf-27mv/GHSA-fq38-2fgf-27mv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-frcj-vgwr-3f9p/GHSA-frcj-vgwr-3f9p.json create mode 100644 advisories/unreviewed/2024/12/GHSA-fv85-82q3-9pf8/GHSA-fv85-82q3-9pf8.json create mode 100644 advisories/unreviewed/2024/12/GHSA-fvf3-w678-5823/GHSA-fvf3-w678-5823.json create mode 100644 advisories/unreviewed/2024/12/GHSA-gcvm-mm2c-wrfh/GHSA-gcvm-mm2c-wrfh.json create mode 100644 advisories/unreviewed/2024/12/GHSA-gq6w-rgrp-976h/GHSA-gq6w-rgrp-976h.json create mode 100644 advisories/unreviewed/2024/12/GHSA-gx52-wqq6-r834/GHSA-gx52-wqq6-r834.json create mode 100644 advisories/unreviewed/2024/12/GHSA-h3fr-83x2-rwvv/GHSA-h3fr-83x2-rwvv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-h7r9-3wpm-8jg6/GHSA-h7r9-3wpm-8jg6.json create mode 100644 advisories/unreviewed/2024/12/GHSA-hj8f-99rq-2qg5/GHSA-hj8f-99rq-2qg5.json create mode 100644 advisories/unreviewed/2024/12/GHSA-hjxc-5vcp-9rmf/GHSA-hjxc-5vcp-9rmf.json create mode 100644 advisories/unreviewed/2024/12/GHSA-hpr8-g3rf-4f89/GHSA-hpr8-g3rf-4f89.json create mode 100644 advisories/unreviewed/2024/12/GHSA-hpwc-g7x9-qgm8/GHSA-hpwc-g7x9-qgm8.json create mode 100644 advisories/unreviewed/2024/12/GHSA-hqgq-wgpj-wxwf/GHSA-hqgq-wgpj-wxwf.json create mode 100644 advisories/unreviewed/2024/12/GHSA-hv8q-qqrh-ccgj/GHSA-hv8q-qqrh-ccgj.json create mode 100644 advisories/unreviewed/2024/12/GHSA-hwq4-qw38-h933/GHSA-hwq4-qw38-h933.json create mode 100644 advisories/unreviewed/2024/12/GHSA-j2f8-56pc-7gmr/GHSA-j2f8-56pc-7gmr.json create mode 100644 advisories/unreviewed/2024/12/GHSA-jq38-2x24-q99r/GHSA-jq38-2x24-q99r.json create mode 100644 advisories/unreviewed/2024/12/GHSA-jr93-xph2-hggc/GHSA-jr93-xph2-hggc.json create mode 100644 advisories/unreviewed/2024/12/GHSA-m5qp-25mc-53xj/GHSA-m5qp-25mc-53xj.json create mode 100644 advisories/unreviewed/2024/12/GHSA-mcw9-h88f-7f3f/GHSA-mcw9-h88f-7f3f.json create mode 100644 advisories/unreviewed/2024/12/GHSA-mrfc-m82j-82wf/GHSA-mrfc-m82j-82wf.json create mode 100644 advisories/unreviewed/2024/12/GHSA-mv4h-62h2-5hwv/GHSA-mv4h-62h2-5hwv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-mwqf-g5pc-qrr8/GHSA-mwqf-g5pc-qrr8.json create mode 100644 advisories/unreviewed/2024/12/GHSA-mx9w-v2pf-gr86/GHSA-mx9w-v2pf-gr86.json create mode 100644 advisories/unreviewed/2024/12/GHSA-p49r-xxpc-j8fj/GHSA-p49r-xxpc-j8fj.json create mode 100644 advisories/unreviewed/2024/12/GHSA-p6m5-m496-hfm6/GHSA-p6m5-m496-hfm6.json create mode 100644 advisories/unreviewed/2024/12/GHSA-p7qh-jh34-85qr/GHSA-p7qh-jh34-85qr.json create mode 100644 advisories/unreviewed/2024/12/GHSA-p8cc-27cr-294h/GHSA-p8cc-27cr-294h.json create mode 100644 advisories/unreviewed/2024/12/GHSA-pcgf-8qxw-vjpc/GHSA-pcgf-8qxw-vjpc.json create mode 100644 advisories/unreviewed/2024/12/GHSA-pqhv-cv76-m4hc/GHSA-pqhv-cv76-m4hc.json create mode 100644 advisories/unreviewed/2024/12/GHSA-pvqx-h7hh-wp79/GHSA-pvqx-h7hh-wp79.json create mode 100644 advisories/unreviewed/2024/12/GHSA-q5vw-gwwh-j8r7/GHSA-q5vw-gwwh-j8r7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-q97w-jc54-cmqr/GHSA-q97w-jc54-cmqr.json create mode 100644 advisories/unreviewed/2024/12/GHSA-qc35-5wrm-x6wx/GHSA-qc35-5wrm-x6wx.json create mode 100644 advisories/unreviewed/2024/12/GHSA-qhgg-j635-qfw9/GHSA-qhgg-j635-qfw9.json create mode 100644 advisories/unreviewed/2024/12/GHSA-qp25-vh5m-jhp5/GHSA-qp25-vh5m-jhp5.json create mode 100644 advisories/unreviewed/2024/12/GHSA-qrwq-c8cf-p4wv/GHSA-qrwq-c8cf-p4wv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-r65p-7pcp-4hmm/GHSA-r65p-7pcp-4hmm.json create mode 100644 advisories/unreviewed/2024/12/GHSA-rc8c-8v29-wf9h/GHSA-rc8c-8v29-wf9h.json create mode 100644 advisories/unreviewed/2024/12/GHSA-rhhv-6w3f-j654/GHSA-rhhv-6w3f-j654.json create mode 100644 advisories/unreviewed/2024/12/GHSA-v267-h3hm-27xj/GHSA-v267-h3hm-27xj.json create mode 100644 advisories/unreviewed/2024/12/GHSA-v3jg-qf5j-54wh/GHSA-v3jg-qf5j-54wh.json create mode 100644 advisories/unreviewed/2024/12/GHSA-v3qf-fgcw-33vg/GHSA-v3qf-fgcw-33vg.json create mode 100644 advisories/unreviewed/2024/12/GHSA-v5wp-6cxh-7g56/GHSA-v5wp-6cxh-7g56.json create mode 100644 advisories/unreviewed/2024/12/GHSA-v846-wcv6-j9fr/GHSA-v846-wcv6-j9fr.json create mode 100644 advisories/unreviewed/2024/12/GHSA-vcjh-jjp4-2cxf/GHSA-vcjh-jjp4-2cxf.json create mode 100644 advisories/unreviewed/2024/12/GHSA-vcp9-mrmm-2gh8/GHSA-vcp9-mrmm-2gh8.json create mode 100644 advisories/unreviewed/2024/12/GHSA-vfcc-4q8x-f299/GHSA-vfcc-4q8x-f299.json create mode 100644 advisories/unreviewed/2024/12/GHSA-vg3c-gxqw-hr85/GHSA-vg3c-gxqw-hr85.json create mode 100644 advisories/unreviewed/2024/12/GHSA-vhww-mm25-q8mv/GHSA-vhww-mm25-q8mv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-vjr5-7gc7-rrhq/GHSA-vjr5-7gc7-rrhq.json create mode 100644 advisories/unreviewed/2024/12/GHSA-vpp4-4mqw-4hw7/GHSA-vpp4-4mqw-4hw7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-w3r7-6c65-fr45/GHSA-w3r7-6c65-fr45.json create mode 100644 advisories/unreviewed/2024/12/GHSA-w4w2-7q2f-mxm4/GHSA-w4w2-7q2f-mxm4.json create mode 100644 advisories/unreviewed/2024/12/GHSA-w926-rj83-69p8/GHSA-w926-rj83-69p8.json create mode 100644 advisories/unreviewed/2024/12/GHSA-w97j-3h9r-h9rm/GHSA-w97j-3h9r-h9rm.json create mode 100644 advisories/unreviewed/2024/12/GHSA-wgjj-vjmp-269h/GHSA-wgjj-vjmp-269h.json create mode 100644 advisories/unreviewed/2024/12/GHSA-wgq9-xh75-7fxc/GHSA-wgq9-xh75-7fxc.json create mode 100644 advisories/unreviewed/2024/12/GHSA-wwm7-p227-pcgv/GHSA-wwm7-p227-pcgv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-wx4q-8vh8-7998/GHSA-wx4q-8vh8-7998.json create mode 100644 advisories/unreviewed/2024/12/GHSA-x45w-x6jp-jg2w/GHSA-x45w-x6jp-jg2w.json create mode 100644 advisories/unreviewed/2024/12/GHSA-x5hw-h4f2-565p/GHSA-x5hw-h4f2-565p.json create mode 100644 advisories/unreviewed/2024/12/GHSA-x942-9rvg-798r/GHSA-x942-9rvg-798r.json create mode 100644 advisories/unreviewed/2024/12/GHSA-xf96-h6wr-6499/GHSA-xf96-h6wr-6499.json create mode 100644 advisories/unreviewed/2024/12/GHSA-xfv4-rqpc-qx97/GHSA-xfv4-rqpc-qx97.json diff --git a/advisories/unreviewed/2024/02/GHSA-6w8c-45mh-9rvm/GHSA-6w8c-45mh-9rvm.json b/advisories/unreviewed/2024/02/GHSA-6w8c-45mh-9rvm/GHSA-6w8c-45mh-9rvm.json index 0e99dfbe748..535495a79d4 100644 --- a/advisories/unreviewed/2024/02/GHSA-6w8c-45mh-9rvm/GHSA-6w8c-45mh-9rvm.json +++ b/advisories/unreviewed/2024/02/GHSA-6w8c-45mh-9rvm/GHSA-6w8c-45mh-9rvm.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-362" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-m7gg-q7qj-3r2r/GHSA-m7gg-q7qj-3r2r.json b/advisories/unreviewed/2024/03/GHSA-m7gg-q7qj-3r2r/GHSA-m7gg-q7qj-3r2r.json index 7efb2956304..a00e36bc5c4 100644 --- a/advisories/unreviewed/2024/03/GHSA-m7gg-q7qj-3r2r/GHSA-m7gg-q7qj-3r2r.json +++ b/advisories/unreviewed/2024/03/GHSA-m7gg-q7qj-3r2r/GHSA-m7gg-q7qj-3r2r.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-262g-fr6f-r3xc/GHSA-262g-fr6f-r3xc.json b/advisories/unreviewed/2024/12/GHSA-262g-fr6f-r3xc/GHSA-262g-fr6f-r3xc.json new file mode 100644 index 00000000000..388dd2be6f4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-262g-fr6f-r3xc/GHSA-262g-fr6f-r3xc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-262g-fr6f-r3xc", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54375" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sabri Taieb Woolook allows PHP Local File Inclusion.This issue affects Woolook: from n/a through 1.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54375" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woolook/vulnerability/wordpress-woolook-plugin-1-7-0-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2cc5-8q8w-gqw8/GHSA-2cc5-8q8w-gqw8.json b/advisories/unreviewed/2024/12/GHSA-2cc5-8q8w-gqw8/GHSA-2cc5-8q8w-gqw8.json new file mode 100644 index 00000000000..aebf3ec3350 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2cc5-8q8w-gqw8/GHSA-2cc5-8q8w-gqw8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cc5-8q8w-gqw8", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-54436" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Jettochkin Jet Footer Code allows Stored XSS.This issue affects Jet Footer Code: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54436" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jet-footer-code/vulnerability/wordpress-jet-footer-code-plugin-1-4-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2qrr-fxgw-wwcx/GHSA-2qrr-fxgw-wwcx.json b/advisories/unreviewed/2024/12/GHSA-2qrr-fxgw-wwcx/GHSA-2qrr-fxgw-wwcx.json new file mode 100644 index 00000000000..bc154d04d6d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2qrr-fxgw-wwcx/GHSA-2qrr-fxgw-wwcx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qrr-fxgw-wwcx", + "modified": "2024-12-16T15:31:38Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-55998" + ], + "details": "Missing Authorization vulnerability in dusthazard Popup Surveys & Polls for WordPress (Mare.io) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Surveys & Polls for WordPress (Mare.io): from n/a through 1.36.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55998" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/popup-surveys/vulnerability/wordpress-popup-surveys-polls-for-wordpress-mare-io-plugin-1-36-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2xv4-ch54-5wmx/GHSA-2xv4-ch54-5wmx.json b/advisories/unreviewed/2024/12/GHSA-2xv4-ch54-5wmx/GHSA-2xv4-ch54-5wmx.json new file mode 100644 index 00000000000..74cf46f7a10 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2xv4-ch54-5wmx/GHSA-2xv4-ch54-5wmx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xv4-ch54-5wmx", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54396" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ryan Bet sport Free allows Cross Site Request Forgery.This issue affects Bet sport Free: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54396" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bet-sport-free/vulnerability/wordpress-bet-sport-free-plugin-1-0-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-328g-2x6r-r5fg/GHSA-328g-2x6r-r5fg.json b/advisories/unreviewed/2024/12/GHSA-328g-2x6r-r5fg/GHSA-328g-2x6r-r5fg.json new file mode 100644 index 00000000000..ce02a502ac8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-328g-2x6r-r5fg/GHSA-328g-2x6r-r5fg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-328g-2x6r-r5fg", + "modified": "2024-12-16T15:31:38Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-56011" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ilja Zaglov | IMBAA GmbH Responsive Google Maps | by imbaa allows Stored XSS.This issue affects Responsive Google Maps | by imbaa: from n/a through 1.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56011" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/responsive-google-maps/vulnerability/wordpress-responsive-google-maps-by-imbaa-plugin-1-2-5-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-37xf-px7h-945g/GHSA-37xf-px7h-945g.json b/advisories/unreviewed/2024/12/GHSA-37xf-px7h-945g/GHSA-37xf-px7h-945g.json new file mode 100644 index 00000000000..84b1a5b562f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-37xf-px7h-945g/GHSA-37xf-px7h-945g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37xf-px7h-945g", + "modified": "2024-12-16T15:31:38Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-56007" + ], + "details": "Missing Authorization vulnerability in Ram Segev Leader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Leader: from n/a through 2.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56007" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/leader/vulnerability/wordpress-leader-plugin-2-6-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-394w-f725-94hh/GHSA-394w-f725-94hh.json b/advisories/unreviewed/2024/12/GHSA-394w-f725-94hh/GHSA-394w-f725-94hh.json new file mode 100644 index 00000000000..0be510f02be --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-394w-f725-94hh/GHSA-394w-f725-94hh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-394w-f725-94hh", + "modified": "2024-12-16T15:31:38Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-55996" + ], + "details": "Missing Authorization vulnerability in Dreamfox Dreamfox Media Payment gateway per Product for Woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dreamfox Media Payment gateway per Product for Woocommerce: from n/a through 3.5.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55996" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-product-payments/vulnerability/wordpress-payment-gateway-per-product-for-woocommerce-plugin-3-5-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-39wc-cq75-x375/GHSA-39wc-cq75-x375.json b/advisories/unreviewed/2024/12/GHSA-39wc-cq75-x375/GHSA-39wc-cq75-x375.json new file mode 100644 index 00000000000..74b34f0989b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-39wc-cq75-x375/GHSA-39wc-cq75-x375.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39wc-cq75-x375", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54378" + ], + "details": "Missing Authorization vulnerability in Quietly Quietly Insights allows Privilege Escalation.This issue affects Quietly Insights: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54378" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quietly-insights/vulnerability/wordpress-quietly-insights-plugin-1-2-2-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3jj9-9287-pj45/GHSA-3jj9-9287-pj45.json b/advisories/unreviewed/2024/12/GHSA-3jj9-9287-pj45/GHSA-3jj9-9287-pj45.json new file mode 100644 index 00000000000..b706ab48df9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3jj9-9287-pj45/GHSA-3jj9-9287-pj45.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jj9-9287-pj45", + "modified": "2024-12-16T15:31:38Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-56012" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Pearlbells Flash News / Post (Responsive) allows Privilege Escalation.This issue affects Flash News / Post (Responsive): from n/a through 4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56012" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/flashnews-fading-effect-pearlbells/vulnerability/wordpress-flash-news-post-responsive-plugin-4-1-csrf-to-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3m7j-hg3r-8fw7/GHSA-3m7j-hg3r-8fw7.json b/advisories/unreviewed/2024/12/GHSA-3m7j-hg3r-8fw7/GHSA-3m7j-hg3r-8fw7.json new file mode 100644 index 00000000000..f4cb2f83099 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3m7j-hg3r-8fw7/GHSA-3m7j-hg3r-8fw7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3m7j-hg3r-8fw7", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-54438" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in GAxx Gaxx Keywords allows Stored XSS.This issue affects Gaxx Keywords: from n/a through 0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54438" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gaxx-keywords/vulnerability/wordpress-gaxx-keywords-plugin-0-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-43fx-2cfr-rfxj/GHSA-43fx-2cfr-rfxj.json b/advisories/unreviewed/2024/12/GHSA-43fx-2cfr-rfxj/GHSA-43fx-2cfr-rfxj.json new file mode 100644 index 00000000000..ad67916a588 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-43fx-2cfr-rfxj/GHSA-43fx-2cfr-rfxj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43fx-2cfr-rfxj", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-54433" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Simple Booking Simple Booking Widget allows Stored XSS.This issue affects Simple Booking Widget: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54433" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-booking-widget/vulnerability/wordpress-simple-booking-widget-plugin-1-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4fg5-v4j6-7jhj/GHSA-4fg5-v4j6-7jhj.json b/advisories/unreviewed/2024/12/GHSA-4fg5-v4j6-7jhj/GHSA-4fg5-v4j6-7jhj.json new file mode 100644 index 00000000000..69d306b2bbd --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4fg5-v4j6-7jhj/GHSA-4fg5-v4j6-7jhj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fg5-v4j6-7jhj", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-56005" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Posti Posti Shipping allows Cross Site Request Forgery.This issue affects Posti Shipping: from n/a through 3.10.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56005" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/posti-shipping/vulnerability/wordpress-posti-shipping-plugin-3-10-3-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4mm3-32x8-9pg9/GHSA-4mm3-32x8-9pg9.json b/advisories/unreviewed/2024/12/GHSA-4mm3-32x8-9pg9/GHSA-4mm3-32x8-9pg9.json new file mode 100644 index 00000000000..f4d6858fbee --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4mm3-32x8-9pg9/GHSA-4mm3-32x8-9pg9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mm3-32x8-9pg9", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-55973" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ryan Nystrom TSB Occasion Editor allows SQL Injection.This issue affects TSB Occasion Editor: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55973" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tsb-occasion-editor/vulnerability/wordpress-tsb-occasion-editor-plugin-1-2-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4r28-24qr-fj7r/GHSA-4r28-24qr-fj7r.json b/advisories/unreviewed/2024/12/GHSA-4r28-24qr-fj7r/GHSA-4r28-24qr-fj7r.json new file mode 100644 index 00000000000..65d71200734 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4r28-24qr-fj7r/GHSA-4r28-24qr-fj7r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r28-24qr-fj7r", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-54428" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in onigetoc Add image to Post allows Stored XSS.This issue affects Add image to Post: from n/a through 0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54428" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/add-image-to-post/vulnerability/wordpress-add-image-to-post-plugin-0-6-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4xrm-6vq2-f7mq/GHSA-4xrm-6vq2-f7mq.json b/advisories/unreviewed/2024/12/GHSA-4xrm-6vq2-f7mq/GHSA-4xrm-6vq2-f7mq.json new file mode 100644 index 00000000000..9ee4eb0c008 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4xrm-6vq2-f7mq/GHSA-4xrm-6vq2-f7mq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xrm-6vq2-f7mq", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54359" + ], + "details": "Missing Authorization vulnerability in Saul Morales Pacheco Banner System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Banner System: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54359" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/banner-system/vulnerability/wordpress-banner-system-plugin-1-0-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-537w-3mmj-9pr3/GHSA-537w-3mmj-9pr3.json b/advisories/unreviewed/2024/12/GHSA-537w-3mmj-9pr3/GHSA-537w-3mmj-9pr3.json new file mode 100644 index 00000000000..e48ce6ff5cf --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-537w-3mmj-9pr3/GHSA-537w-3mmj-9pr3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-537w-3mmj-9pr3", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-55989" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kyle M. Brown WP Simple Pay Lite Manager allows SQL Injection.This issue affects WP Simple Pay Lite Manager: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55989" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/stripe-manager/vulnerability/wordpress-wp-simple-pay-lite-manager-plugin-1-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-556w-mh92-76gh/GHSA-556w-mh92-76gh.json b/advisories/unreviewed/2024/12/GHSA-556w-mh92-76gh/GHSA-556w-mh92-76gh.json new file mode 100644 index 00000000000..554f358c272 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-556w-mh92-76gh/GHSA-556w-mh92-76gh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-556w-mh92-76gh", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54380" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Filippo Bodei WP Cookies Enabler allows PHP Local File Inclusion.This issue affects WP Cookies Enabler: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54380" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-cookies-enabler/vulnerability/wordpress-wp-cookies-enabler-plugin-1-0-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-595w-xcwx-w23j/GHSA-595w-xcwx-w23j.json b/advisories/unreviewed/2024/12/GHSA-595w-xcwx-w23j/GHSA-595w-xcwx-w23j.json new file mode 100644 index 00000000000..f745fb75def --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-595w-xcwx-w23j/GHSA-595w-xcwx-w23j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-595w-xcwx-w23j", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54409" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in fzmaster @ XPD XPD Reduce Image Filesize allows Stored XSS.This issue affects XPD Reduce Image Filesize: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54409" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/xpd-reduce-image-filesize/vulnerability/wordpress-xpd-reduce-image-filesize-plugin-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5f3c-j6m9-3fqv/GHSA-5f3c-j6m9-3fqv.json b/advisories/unreviewed/2024/12/GHSA-5f3c-j6m9-3fqv/GHSA-5f3c-j6m9-3fqv.json new file mode 100644 index 00000000000..565e936d03a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5f3c-j6m9-3fqv/GHSA-5f3c-j6m9-3fqv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f3c-j6m9-3fqv", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-54432" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Shambhu Prasad Patnaik WP Flipkart Importer allows Stored XSS.This issue affects WP Flipkart Importer: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54432" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-flipkart-importer/vulnerability/wordpress-wp-flipkart-importer-plugin-1-4-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5fcg-g7jg-hx9p/GHSA-5fcg-g7jg-hx9p.json b/advisories/unreviewed/2024/12/GHSA-5fcg-g7jg-hx9p/GHSA-5fcg-g7jg-hx9p.json new file mode 100644 index 00000000000..88e61becae3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5fcg-g7jg-hx9p/GHSA-5fcg-g7jg-hx9p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fcg-g7jg-hx9p", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54411" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in hosting.io, campaigns.io WP Controller allows Stored XSS.This issue affects WP Controller: from n/a through 3.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54411" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-management-controller/vulnerability/wordpress-wp-controller-plugin-3-2-0-csrf-to-stored-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5h2x-fwcw-rwv2/GHSA-5h2x-fwcw-rwv2.json b/advisories/unreviewed/2024/12/GHSA-5h2x-fwcw-rwv2/GHSA-5h2x-fwcw-rwv2.json new file mode 100644 index 00000000000..bbb6f7a1c67 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5h2x-fwcw-rwv2/GHSA-5h2x-fwcw-rwv2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h2x-fwcw-rwv2", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-55979" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webriderz Wr Age Verification allows SQL Injection.This issue affects Wr Age Verification: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55979" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wr-age-verification/vulnerability/wordpress-wr-age-verification-plugin-2-0-0-sql-injection-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5xmv-h4m3-4vx5/GHSA-5xmv-h4m3-4vx5.json b/advisories/unreviewed/2024/12/GHSA-5xmv-h4m3-4vx5/GHSA-5xmv-h4m3-4vx5.json new file mode 100644 index 00000000000..df4e2cdaa29 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5xmv-h4m3-4vx5/GHSA-5xmv-h4m3-4vx5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xmv-h4m3-4vx5", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54390" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bouzid Nazim Zitouni TagGator allows Reflected XSS.This issue affects TagGator: from n/a through 1.54.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54390" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/taggator/vulnerability/wordpress-taggator-plugin-1-54-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6fp6-p23m-84hh/GHSA-6fp6-p23m-84hh.json b/advisories/unreviewed/2024/12/GHSA-6fp6-p23m-84hh/GHSA-6fp6-p23m-84hh.json new file mode 100644 index 00000000000..58e388f35c5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6fp6-p23m-84hh/GHSA-6fp6-p23m-84hh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fp6-p23m-84hh", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-54441" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Meini Utech World Time allows Stored XSS.This issue affects Utech World Time: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54441" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/utech-world-time-for-wp/vulnerability/wordpress-utech-world-time-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6m5p-x936-73hr/GHSA-6m5p-x936-73hr.json b/advisories/unreviewed/2024/12/GHSA-6m5p-x936-73hr/GHSA-6m5p-x936-73hr.json new file mode 100644 index 00000000000..6b73bc16488 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6m5p-x936-73hr/GHSA-6m5p-x936-73hr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m5p-x936-73hr", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54374" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sabri Taieb Sogrid allows PHP Local File Inclusion.This issue affects Sogrid: from n/a through 1.5.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54374" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sogrid/vulnerability/wordpress-sogrid-plugin-1-5-6-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6q8m-vq2h-r3j2/GHSA-6q8m-vq2h-r3j2.json b/advisories/unreviewed/2024/12/GHSA-6q8m-vq2h-r3j2/GHSA-6q8m-vq2h-r3j2.json new file mode 100644 index 00000000000..b7e4eb9e528 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6q8m-vq2h-r3j2/GHSA-6q8m-vq2h-r3j2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q8m-vq2h-r3j2", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-54435" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Thomas Hoefter Onlywire Multi Autosubmitter allows Stored XSS.This issue affects Onlywire Multi Autosubmitter: from n/a through 1.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54435" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/onlywire-multi-autosubmitter/vulnerability/wordpress-onlywire-multi-autosubmitter-plugin-1-2-4-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-765j-hqm9-rj5c/GHSA-765j-hqm9-rj5c.json b/advisories/unreviewed/2024/12/GHSA-765j-hqm9-rj5c/GHSA-765j-hqm9-rj5c.json new file mode 100644 index 00000000000..2441b0fa7d5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-765j-hqm9-rj5c/GHSA-765j-hqm9-rj5c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-765j-hqm9-rj5c", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54394" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Web solution soft Mandrill WP allows Stored XSS.This issue affects Mandrill WP: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54394" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/email-form-under-post/vulnerability/wordpress-mandrill-wp-plugin-1-0-5-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-772g-rc25-jfc4/GHSA-772g-rc25-jfc4.json b/advisories/unreviewed/2024/12/GHSA-772g-rc25-jfc4/GHSA-772g-rc25-jfc4.json new file mode 100644 index 00000000000..bb38391b3f5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-772g-rc25-jfc4/GHSA-772g-rc25-jfc4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-772g-rc25-jfc4", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54373" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chris Gårdenberg, MultiNet Interactive AB EduAdmin Booking allows PHP Local File Inclusion.This issue affects EduAdmin Booking: from n/a through 5.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54373" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/eduadmin-booking/vulnerability/wordpress-eduadmin-booking-plugin-5-2-0-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7788-cmgc-rw4w/GHSA-7788-cmgc-rw4w.json b/advisories/unreviewed/2024/12/GHSA-7788-cmgc-rw4w/GHSA-7788-cmgc-rw4w.json new file mode 100644 index 00000000000..a173f07a489 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7788-cmgc-rw4w/GHSA-7788-cmgc-rw4w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7788-cmgc-rw4w", + "modified": "2024-12-16T15:31:34Z", + "published": "2024-12-16T15:31:34Z", + "aliases": [ + "CVE-2024-12090" + ], + "details": "A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12090" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-77ch-rvc7-4fjv/GHSA-77ch-rvc7-4fjv.json b/advisories/unreviewed/2024/12/GHSA-77ch-rvc7-4fjv/GHSA-77ch-rvc7-4fjv.json new file mode 100644 index 00000000000..fd7a8c25332 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-77ch-rvc7-4fjv/GHSA-77ch-rvc7-4fjv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77ch-rvc7-4fjv", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54365" + ], + "details": "Incorrect Privilege Assignment vulnerability in Halim KH Easy User Settings allows Privilege Escalation.This issue affects KH Easy User Settings: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54365" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/kh-easy-user-settings/vulnerability/wordpress-kh-easy-user-settings-plugin-1-0-0-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7q86-pv7h-63qc/GHSA-7q86-pv7h-63qc.json b/advisories/unreviewed/2024/12/GHSA-7q86-pv7h-63qc/GHSA-7q86-pv7h-63qc.json new file mode 100644 index 00000000000..60c45d074b9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7q86-pv7h-63qc/GHSA-7q86-pv7h-63qc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q86-pv7h-63qc", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54369" + ], + "details": "Missing Authorization vulnerability in ThemeHunk Zita Site Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Zita Site Builder: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54369" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ai-site-builder/vulnerability/wordpress-zita-site-builder-plugin-1-0-2-arbitrary-plugin-installation-and-activation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7qpr-85r9-qfcc/GHSA-7qpr-85r9-qfcc.json b/advisories/unreviewed/2024/12/GHSA-7qpr-85r9-qfcc/GHSA-7qpr-85r9-qfcc.json new file mode 100644 index 00000000000..9860c542335 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7qpr-85r9-qfcc/GHSA-7qpr-85r9-qfcc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qpr-85r9-qfcc", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54418" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Diversified Technology Corp., WPYog, and Gagan Deep Singh DTC Documents allows Cross Site Request Forgery.This issue affects DTC Documents: from n/a through 1.1.05.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54418" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dtc-documents/vulnerability/wordpress-dtc-documents-plugin-1-1-05-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7v7x-8p54-6fgp/GHSA-7v7x-8p54-6fgp.json b/advisories/unreviewed/2024/12/GHSA-7v7x-8p54-6fgp/GHSA-7v7x-8p54-6fgp.json new file mode 100644 index 00000000000..b6380c5a523 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7v7x-8p54-6fgp/GHSA-7v7x-8p54-6fgp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v7x-8p54-6fgp", + "modified": "2024-12-16T15:31:38Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-56015" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in John Godley Tidy Up allows Reflected XSS.This issue affects Tidy Up: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56015" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tidy-up/vulnerability/wordpress-tidy-up-plugin-1-3-csrf-to-reflected-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-86wm-x842-r6gc/GHSA-86wm-x842-r6gc.json b/advisories/unreviewed/2024/12/GHSA-86wm-x842-r6gc/GHSA-86wm-x842-r6gc.json new file mode 100644 index 00000000000..d347b9f7a1d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-86wm-x842-r6gc/GHSA-86wm-x842-r6gc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86wm-x842-r6gc", + "modified": "2024-12-16T15:31:34Z", + "published": "2024-12-16T15:31:34Z", + "aliases": [ + "CVE-2024-54331" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Micha I Plant A Tree allows Stored XSS.This issue affects I Plant A Tree: from n/a through 1.7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54331" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/i-plant-a-tree/vulnerability/wordpress-i-plant-a-tree-plugin-1-7-3-csrf-to-stored-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8725-gx62-5qhc/GHSA-8725-gx62-5qhc.json b/advisories/unreviewed/2024/12/GHSA-8725-gx62-5qhc/GHSA-8725-gx62-5qhc.json new file mode 100644 index 00000000000..46337a9088f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8725-gx62-5qhc/GHSA-8725-gx62-5qhc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8725-gx62-5qhc", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54401" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Turcu Ciprian Advanced Fancybox allows Stored XSS.This issue affects Advanced Fancybox: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54401" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-fancybox/vulnerability/wordpress-advanced-fancybox-plugin-1-1-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8c5x-9gh7-8vm2/GHSA-8c5x-9gh7-8vm2.json b/advisories/unreviewed/2024/12/GHSA-8c5x-9gh7-8vm2/GHSA-8c5x-9gh7-8vm2.json new file mode 100644 index 00000000000..e27eea549ea --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8c5x-9gh7-8vm2/GHSA-8c5x-9gh7-8vm2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8c5x-9gh7-8vm2", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-54434" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Phoetry phZoom allows Stored XSS.This issue affects phZoom: from n/a through 1.2.92.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54434" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/phzoom/vulnerability/wordpress-phzoom-plugin-1-2-92-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8ph5-4j2w-wmhg/GHSA-8ph5-4j2w-wmhg.json b/advisories/unreviewed/2024/12/GHSA-8ph5-4j2w-wmhg/GHSA-8ph5-4j2w-wmhg.json new file mode 100644 index 00000000000..b98f7b01da6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8ph5-4j2w-wmhg/GHSA-8ph5-4j2w-wmhg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8ph5-4j2w-wmhg", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-54440" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in blueskyy WP-Ban-User allows Stored XSS.This issue affects WP-Ban-User: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54440" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-ban-user/vulnerability/wordpress-wp-ban-user-plugin-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8q92-x23f-rvxh/GHSA-8q92-x23f-rvxh.json b/advisories/unreviewed/2024/12/GHSA-8q92-x23f-rvxh/GHSA-8q92-x23f-rvxh.json new file mode 100644 index 00000000000..98921f8222c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8q92-x23f-rvxh/GHSA-8q92-x23f-rvxh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q92-x23f-rvxh", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-55993" + ], + "details": "Missing Authorization vulnerability in PickPlugins Job Board Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Job Board Manager: from n/a through 2.1.60.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55993" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/job-board-manager/vulnerability/wordpress-job-board-manager-plugin-2-1-60-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8rhv-37fw-8hc2/GHSA-8rhv-37fw-8hc2.json b/advisories/unreviewed/2024/12/GHSA-8rhv-37fw-8hc2/GHSA-8rhv-37fw-8hc2.json new file mode 100644 index 00000000000..82f89186599 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8rhv-37fw-8hc2/GHSA-8rhv-37fw-8hc2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rhv-37fw-8hc2", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-55972" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Chris Carvache eTemplates allows SQL Injection.This issue affects eTemplates: from n/a through 0.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55972" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/etemplates/vulnerability/wordpress-etemplates-plugin-0-2-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8rmx-gfxw-r4q8/GHSA-8rmx-gfxw-r4q8.json b/advisories/unreviewed/2024/12/GHSA-8rmx-gfxw-r4q8/GHSA-8rmx-gfxw-r4q8.json new file mode 100644 index 00000000000..5bc3d3c2867 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8rmx-gfxw-r4q8/GHSA-8rmx-gfxw-r4q8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rmx-gfxw-r4q8", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54405" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Andy Chapman ECT Social Share allows Stored XSS.This issue affects ECT Social Share: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54405" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ect-social-share/vulnerability/wordpress-ect-social-share-plugin-1-3-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8vjg-gr7v-8hv3/GHSA-8vjg-gr7v-8hv3.json b/advisories/unreviewed/2024/12/GHSA-8vjg-gr7v-8hv3/GHSA-8vjg-gr7v-8hv3.json new file mode 100644 index 00000000000..71ecebdc274 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8vjg-gr7v-8hv3/GHSA-8vjg-gr7v-8hv3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vjg-gr7v-8hv3", + "modified": "2024-12-16T15:31:34Z", + "published": "2024-12-16T15:31:34Z", + "aliases": [ + "CVE-2024-54332" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WPFactory WP Currency Exchange Rates allows Stored XSS.This issue affects WP Currency Exchange Rates: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54332" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-currency-exchange-rates/vulnerability/wordpress-wp-currency-exchange-rates-plugin-1-2-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9256-qm87-9345/GHSA-9256-qm87-9345.json b/advisories/unreviewed/2024/12/GHSA-9256-qm87-9345/GHSA-9256-qm87-9345.json new file mode 100644 index 00000000000..47605253a6f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9256-qm87-9345/GHSA-9256-qm87-9345.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9256-qm87-9345", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54402" + ], + "details": "Missing Authorization vulnerability in Jozoor Arabic Webfonts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Arabic Webfonts: from n/a through 1.4.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54402" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/arabic-webfonts/vulnerability/wordpress-arabic-webfonts-plugin-1-4-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-92pc-gccf-whq7/GHSA-92pc-gccf-whq7.json b/advisories/unreviewed/2024/12/GHSA-92pc-gccf-whq7/GHSA-92pc-gccf-whq7.json new file mode 100644 index 00000000000..07ae6eac4ac --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-92pc-gccf-whq7/GHSA-92pc-gccf-whq7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92pc-gccf-whq7", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54398" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Project Caruso Flaming Forms allows Stored XSS.This issue affects Flaming Forms: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54398" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/flaming-forms/vulnerability/wordpress-flaming-forms-plugin-1-0-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9656-v933-mxp7/GHSA-9656-v933-mxp7.json b/advisories/unreviewed/2024/12/GHSA-9656-v933-mxp7/GHSA-9656-v933-mxp7.json new file mode 100644 index 00000000000..c1d06b095f6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9656-v933-mxp7/GHSA-9656-v933-mxp7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9656-v933-mxp7", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54403" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Scott Visual Recent Posts allows Reflected XSS.This issue affects Visual Recent Posts: from n/a through 1.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54403" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/visual-recent-posts/vulnerability/wordpress-visual-recent-posts-plugin-1-2-3-reflected-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-97hv-pw4c-xf38/GHSA-97hv-pw4c-xf38.json b/advisories/unreviewed/2024/12/GHSA-97hv-pw4c-xf38/GHSA-97hv-pw4c-xf38.json new file mode 100644 index 00000000000..7f94ffc00cd --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-97hv-pw4c-xf38/GHSA-97hv-pw4c-xf38.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97hv-pw4c-xf38", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54392" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Midoks WP微信机器人 allows Stored XSS.This issue affects WP微信机器人: from n/a through 5.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54392" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-weixin-robot/vulnerability/wordpress-wp-plugin-5-3-5-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9fcv-79vj-hrf3/GHSA-9fcv-79vj-hrf3.json b/advisories/unreviewed/2024/12/GHSA-9fcv-79vj-hrf3/GHSA-9fcv-79vj-hrf3.json new file mode 100644 index 00000000000..23afc5afd69 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9fcv-79vj-hrf3/GHSA-9fcv-79vj-hrf3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fcv-79vj-hrf3", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54368" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ruben Garza, Jr. GitSync allows Code Injection.This issue affects GitSync: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54368" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/git-sync/vulnerability/wordpress-gitsync-plugin-1-1-0-csrf-to-remote-code-execution-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9pc9-px3j-hxmw/GHSA-9pc9-px3j-hxmw.json b/advisories/unreviewed/2024/12/GHSA-9pc9-px3j-hxmw/GHSA-9pc9-px3j-hxmw.json new file mode 100644 index 00000000000..797c6e12868 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9pc9-px3j-hxmw/GHSA-9pc9-px3j-hxmw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pc9-px3j-hxmw", + "modified": "2024-12-16T15:31:34Z", + "published": "2024-12-16T15:31:34Z", + "aliases": [ + "CVE-2024-12668" + ], + "details": "Velocidex WinPmem versions below 4.1 suffer from an Out of Bounds Write vulnerability whereby an attacker can subvert code-signing facilities leading to the ability to write the value zero anywhere in memory with the driver – without using the\\nPMEM_WRITE_ENABLED compilation flag. This issue is remediated in version 4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12668" + }, + { + "type": "WEB", + "url": "https://github.com/Velocidex/WinPmem/releases/tag/v4.1.dev1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9pgc-34gm-jwr2/GHSA-9pgc-34gm-jwr2.json b/advisories/unreviewed/2024/12/GHSA-9pgc-34gm-jwr2/GHSA-9pgc-34gm-jwr2.json new file mode 100644 index 00000000000..76762abb767 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9pgc-34gm-jwr2/GHSA-9pgc-34gm-jwr2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pgc-34gm-jwr2", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54412" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ecommerce Templates ECT Product Carousel allows Stored XSS.This issue affects ECT Product Carousel: from n/a through 1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54412" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ect-product-carousel/vulnerability/wordpress-ect-product-carousel-plugin-1-9-csrf-to-stored-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9qpp-96vr-f3r8/GHSA-9qpp-96vr-f3r8.json b/advisories/unreviewed/2024/12/GHSA-9qpp-96vr-f3r8/GHSA-9qpp-96vr-f3r8.json new file mode 100644 index 00000000000..efd242dab9d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9qpp-96vr-f3r8/GHSA-9qpp-96vr-f3r8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qpp-96vr-f3r8", + "modified": "2024-12-16T15:31:38Z", + "published": "2024-12-16T15:31:38Z", + "aliases": [ + "CVE-2024-56013" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in Wovax, LLC. Wovax IDX allows Authentication Bypass.This issue affects Wovax IDX: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56013" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wovax-idx/vulnerability/wordpress-wovax-idx-plugin-1-2-2-account-takeover-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9xj8-533q-hxq7/GHSA-9xj8-533q-hxq7.json b/advisories/unreviewed/2024/12/GHSA-9xj8-533q-hxq7/GHSA-9xj8-533q-hxq7.json new file mode 100644 index 00000000000..848f387be66 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9xj8-533q-hxq7/GHSA-9xj8-533q-hxq7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xj8-533q-hxq7", + "modified": "2024-12-16T15:31:34Z", + "published": "2024-12-16T15:31:34Z", + "aliases": [ + "CVE-2024-54352" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Sabri Taieb Sogrid allows Privilege Escalation.This issue affects Sogrid: from n/a through 1.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54352" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sogrid/vulnerability/wordpress-sogrid-plugin-1-5-2-csrf-to-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c36x-7qg6-qwjj/GHSA-c36x-7qg6-qwjj.json b/advisories/unreviewed/2024/12/GHSA-c36x-7qg6-qwjj/GHSA-c36x-7qg6-qwjj.json new file mode 100644 index 00000000000..c348794dddb --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c36x-7qg6-qwjj/GHSA-c36x-7qg6-qwjj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c36x-7qg6-qwjj", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-55992" + ], + "details": "Missing Authorization vulnerability in Open Tools WooCommerce Basic Ordernumbers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Basic Ordernumbers: from n/a through 1.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55992" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-basic-ordernumbers/vulnerability/wordpress-woocommerce-basic-ordernumbers-plugin-1-4-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c3hf-hhg3-xg3m/GHSA-c3hf-hhg3-xg3m.json b/advisories/unreviewed/2024/12/GHSA-c3hf-hhg3-xg3m/GHSA-c3hf-hhg3-xg3m.json new file mode 100644 index 00000000000..55dbb8fc103 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c3hf-hhg3-xg3m/GHSA-c3hf-hhg3-xg3m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3hf-hhg3-xg3m", + "modified": "2024-12-16T15:31:34Z", + "published": "2024-12-16T15:31:34Z", + "aliases": [ + "CVE-2024-54356" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in vCita.com Online Booking & Scheduling Calendar for WordPress by vcita allows Cross Site Request Forgery.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54356" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/meeting-scheduler-by-vcita/vulnerability/wordpress-online-booking-scheduling-calendar-for-wordpress-by-vcita-plugin-4-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c68r-r29p-9xpp/GHSA-c68r-r29p-9xpp.json b/advisories/unreviewed/2024/12/GHSA-c68r-r29p-9xpp/GHSA-c68r-r29p-9xpp.json new file mode 100644 index 00000000000..7cfa382d9a3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c68r-r29p-9xpp/GHSA-c68r-r29p-9xpp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c68r-r29p-9xpp", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54417" + ], + "details": "Missing Authorization vulnerability in Pixelgrade PixProof allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects PixProof: from n/a through 2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54417" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pixproof/vulnerability/wordpress-pixproof-plugin-2-0-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c6pw-qh93-r927/GHSA-c6pw-qh93-r927.json b/advisories/unreviewed/2024/12/GHSA-c6pw-qh93-r927/GHSA-c6pw-qh93-r927.json new file mode 100644 index 00000000000..7427e712001 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c6pw-qh93-r927/GHSA-c6pw-qh93-r927.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6pw-qh93-r927", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54427" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Linda MacPhee-Cobb Category of Posts allows Stored XSS.This issue affects Category of Posts: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54427" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/list-one-category-of-posts/vulnerability/wordpress-category-of-posts-plugin-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c827-f4c9-92x2/GHSA-c827-f4c9-92x2.json b/advisories/unreviewed/2024/12/GHSA-c827-f4c9-92x2/GHSA-c827-f4c9-92x2.json new file mode 100644 index 00000000000..a3a503fe341 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c827-f4c9-92x2/GHSA-c827-f4c9-92x2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c827-f4c9-92x2", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-55977" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in launch-page-importer LaunchPage.app Importer allows SQL Injection.This issue affects LaunchPage.app Importer: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55977" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/launchpage-app-importer/vulnerability/wordpress-launchpage-app-importer-plugin-1-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c82h-4vv7-76g8/GHSA-c82h-4vv7-76g8.json b/advisories/unreviewed/2024/12/GHSA-c82h-4vv7-76g8/GHSA-c82h-4vv7-76g8.json new file mode 100644 index 00000000000..828271a2ea1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c82h-4vv7-76g8/GHSA-c82h-4vv7-76g8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c82h-4vv7-76g8", + "modified": "2024-12-16T15:31:34Z", + "published": "2024-12-16T15:31:34Z", + "aliases": [ + "CVE-2024-12091" + ], + "details": "A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12091" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cp2j-jp3f-vjpj/GHSA-cp2j-jp3f-vjpj.json b/advisories/unreviewed/2024/12/GHSA-cp2j-jp3f-vjpj/GHSA-cp2j-jp3f-vjpj.json new file mode 100644 index 00000000000..82933104fb8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cp2j-jp3f-vjpj/GHSA-cp2j-jp3f-vjpj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp2j-jp3f-vjpj", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54431" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Mohamed Riyaz Admin Customization allows Stored XSS.This issue affects Admin Customization: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54431" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpp-customization/vulnerability/wordpress-admin-customization-plugin-2-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cv8q-wprf-95p9/GHSA-cv8q-wprf-95p9.json b/advisories/unreviewed/2024/12/GHSA-cv8q-wprf-95p9/GHSA-cv8q-wprf-95p9.json new file mode 100644 index 00000000000..cded136ce40 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cv8q-wprf-95p9/GHSA-cv8q-wprf-95p9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv8q-wprf-95p9", + "modified": "2024-12-16T15:31:34Z", + "published": "2024-12-16T15:31:34Z", + "aliases": [ + "CVE-2024-12092" + ], + "details": "A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12092" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fgg3-pvqg-v5pf/GHSA-fgg3-pvqg-v5pf.json b/advisories/unreviewed/2024/12/GHSA-fgg3-pvqg-v5pf/GHSA-fgg3-pvqg-v5pf.json new file mode 100644 index 00000000000..4bd14abab4f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fgg3-pvqg-v5pf/GHSA-fgg3-pvqg-v5pf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgg3-pvqg-v5pf", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54421" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Sanjay Singh Negi Floating Video Player allows Stored XSS.This issue affects Floating Video Player: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54421" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/floating-player/vulnerability/wordpress-floating-video-player-plugin-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fq38-2fgf-27mv/GHSA-fq38-2fgf-27mv.json b/advisories/unreviewed/2024/12/GHSA-fq38-2fgf-27mv/GHSA-fq38-2fgf-27mv.json new file mode 100644 index 00000000000..4aa59bc98e5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fq38-2fgf-27mv/GHSA-fq38-2fgf-27mv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq38-2fgf-27mv", + "modified": "2024-12-16T15:31:38Z", + "published": "2024-12-16T15:31:38Z", + "aliases": [ + "CVE-2024-56009" + ], + "details": "Missing Authorization vulnerability in spreadr Spreadr Woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Spreadr Woocommerce: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56009" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/spreadr-for-woocomerce/vulnerability/wordpress-spreadr-woocommerce-plugin-1-0-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-frcj-vgwr-3f9p/GHSA-frcj-vgwr-3f9p.json b/advisories/unreviewed/2024/12/GHSA-frcj-vgwr-3f9p/GHSA-frcj-vgwr-3f9p.json new file mode 100644 index 00000000000..b0700c9dd7d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-frcj-vgwr-3f9p/GHSA-frcj-vgwr-3f9p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frcj-vgwr-3f9p", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-54442" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lluís Cortès Better WP Login Page allows Stored XSS.This issue affects Better WP Login Page: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54442" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/better-wp-login-page/vulnerability/wordpress-better-wp-login-page-plugin-better-wp-login-page-1-1-2-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fv85-82q3-9pf8/GHSA-fv85-82q3-9pf8.json b/advisories/unreviewed/2024/12/GHSA-fv85-82q3-9pf8/GHSA-fv85-82q3-9pf8.json new file mode 100644 index 00000000000..9e8ba16c5d0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fv85-82q3-9pf8/GHSA-fv85-82q3-9pf8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv85-82q3-9pf8", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54395" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Becky Sanders Increase Sociability allows Reflected XSS.This issue affects Increase Sociability: from n/a through 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54395" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/increase-sociability/vulnerability/wordpress-increase-sociability-plugin-1-3-0-reflected-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fvf3-w678-5823/GHSA-fvf3-w678-5823.json b/advisories/unreviewed/2024/12/GHSA-fvf3-w678-5823/GHSA-fvf3-w678-5823.json new file mode 100644 index 00000000000..ab5c2a75b65 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fvf3-w678-5823/GHSA-fvf3-w678-5823.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvf3-w678-5823", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54391" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Matt Walters WordPress Filter allows Stored XSS.This issue affects WordPress Filter: from n/a through 1.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54391" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wordpress-filter/vulnerability/wordpress-wordpress-filter-plugin-1-4-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gcvm-mm2c-wrfh/GHSA-gcvm-mm2c-wrfh.json b/advisories/unreviewed/2024/12/GHSA-gcvm-mm2c-wrfh/GHSA-gcvm-mm2c-wrfh.json new file mode 100644 index 00000000000..38a11ab8fae --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gcvm-mm2c-wrfh/GHSA-gcvm-mm2c-wrfh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcvm-mm2c-wrfh", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54430" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Bastien Ho EELV Newsletter allows Cross Site Request Forgery.This issue affects EELV Newsletter: from n/a through 4.8.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54430" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/eelv-newsletter/vulnerability/wordpress-eelv-newsletter-plugin-4-8-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gq6w-rgrp-976h/GHSA-gq6w-rgrp-976h.json b/advisories/unreviewed/2024/12/GHSA-gq6w-rgrp-976h/GHSA-gq6w-rgrp-976h.json new file mode 100644 index 00000000000..7201859b8e8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gq6w-rgrp-976h/GHSA-gq6w-rgrp-976h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq6w-rgrp-976h", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54407" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in 随意的风 CK and SyntaxHighlighter allows Stored XSS.This issue affects CK and SyntaxHighlighter: from n/a through 3.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54407" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ck-and-syntaxhighlighter/vulnerability/wordpress-ck-and-syntaxhighlighter-plugin-3-4-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gx52-wqq6-r834/GHSA-gx52-wqq6-r834.json b/advisories/unreviewed/2024/12/GHSA-gx52-wqq6-r834/GHSA-gx52-wqq6-r834.json new file mode 100644 index 00000000000..dbbec00593a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gx52-wqq6-r834/GHSA-gx52-wqq6-r834.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx52-wqq6-r834", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54426" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Andy Fradelakis LeaderBoard Plugin allows Stored XSS.This issue affects LeaderBoard Plugin: from n/a through 1.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54426" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/leaderboard-lite/vulnerability/wordpress-leaderboard-plugin-plugin-1-2-4-csrf-to-stored-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h32q-4pph-8pgm/GHSA-h32q-4pph-8pgm.json b/advisories/unreviewed/2024/12/GHSA-h32q-4pph-8pgm/GHSA-h32q-4pph-8pgm.json index fda461a7b36..ba3796d215f 100644 --- a/advisories/unreviewed/2024/12/GHSA-h32q-4pph-8pgm/GHSA-h32q-4pph-8pgm.json +++ b/advisories/unreviewed/2024/12/GHSA-h32q-4pph-8pgm/GHSA-h32q-4pph-8pgm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h32q-4pph-8pgm", - "modified": "2024-12-11T00:31:24Z", + "modified": "2024-12-16T15:31:34Z", "published": "2024-12-10T15:32:31Z", "aliases": [ "CVE-2024-5660" diff --git a/advisories/unreviewed/2024/12/GHSA-h3fr-83x2-rwvv/GHSA-h3fr-83x2-rwvv.json b/advisories/unreviewed/2024/12/GHSA-h3fr-83x2-rwvv/GHSA-h3fr-83x2-rwvv.json new file mode 100644 index 00000000000..7421aa0c188 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h3fr-83x2-rwvv/GHSA-h3fr-83x2-rwvv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3fr-83x2-rwvv", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54419" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Mansur Ahamed Ui Slider Filter By Price allows Cross Site Request Forgery.This issue affects Ui Slider Filter By Price: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54419" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ui-slider-filter-by-price/vulnerability/wordpress-ui-slider-filter-by-price-plugin-1-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h7r9-3wpm-8jg6/GHSA-h7r9-3wpm-8jg6.json b/advisories/unreviewed/2024/12/GHSA-h7r9-3wpm-8jg6/GHSA-h7r9-3wpm-8jg6.json new file mode 100644 index 00000000000..89b4f93b202 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h7r9-3wpm-8jg6/GHSA-h7r9-3wpm-8jg6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7r9-3wpm-8jg6", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54372" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Sourov Amin Insertify allows Code Injection.This issue affects Insertify: from n/a through 1.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54372" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/insertify/vulnerability/wordpress-insertify-plugin-1-1-4-csrf-to-remote-code-execution-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hj8f-99rq-2qg5/GHSA-hj8f-99rq-2qg5.json b/advisories/unreviewed/2024/12/GHSA-hj8f-99rq-2qg5/GHSA-hj8f-99rq-2qg5.json new file mode 100644 index 00000000000..3d2b3c15dd6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hj8f-99rq-2qg5/GHSA-hj8f-99rq-2qg5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj8f-99rq-2qg5", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54393" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Sheikh Heera WP Fiddle allows Stored XSS.This issue affects WP Fiddle: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54393" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-fiddle/vulnerability/wordpress-wp-fiddle-plugin-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hjxc-5vcp-9rmf/GHSA-hjxc-5vcp-9rmf.json b/advisories/unreviewed/2024/12/GHSA-hjxc-5vcp-9rmf/GHSA-hjxc-5vcp-9rmf.json new file mode 100644 index 00000000000..c28a3c86fc7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hjxc-5vcp-9rmf/GHSA-hjxc-5vcp-9rmf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjxc-5vcp-9rmf", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54397" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Antonio Gocaj Go Animate allows Stored XSS.This issue affects Go Animate: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54397" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/goanimate/vulnerability/wordpress-go-animate-plugin-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hpr8-g3rf-4f89/GHSA-hpr8-g3rf-4f89.json b/advisories/unreviewed/2024/12/GHSA-hpr8-g3rf-4f89/GHSA-hpr8-g3rf-4f89.json new file mode 100644 index 00000000000..0645394245e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hpr8-g3rf-4f89/GHSA-hpr8-g3rf-4f89.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpr8-g3rf-4f89", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54389" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Eduardo Chiaro addWeather allows Cross Site Request Forgery.This issue affects addWeather: from n/a through 2.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54389" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/myweather/vulnerability/wordpress-addweather-plugin-2-5-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hpwc-g7x9-qgm8/GHSA-hpwc-g7x9-qgm8.json b/advisories/unreviewed/2024/12/GHSA-hpwc-g7x9-qgm8/GHSA-hpwc-g7x9-qgm8.json new file mode 100644 index 00000000000..a82803e7456 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hpwc-g7x9-qgm8/GHSA-hpwc-g7x9-qgm8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpwc-g7x9-qgm8", + "modified": "2024-12-16T15:31:34Z", + "published": "2024-12-16T15:31:34Z", + "aliases": [ + "CVE-2024-54354" + ], + "details": "Missing Authorization vulnerability in Beat Kueffer Termin-Kalender allows Stored XSS.This issue affects Termin-Kalender: from n/a through 0.99.47.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54354" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/termin-kalender/vulnerability/wordpress-termin-kalender-plugin-0-99-47-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hqgq-wgpj-wxwf/GHSA-hqgq-wgpj-wxwf.json b/advisories/unreviewed/2024/12/GHSA-hqgq-wgpj-wxwf/GHSA-hqgq-wgpj-wxwf.json new file mode 100644 index 00000000000..1a8b58ef38e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hqgq-wgpj-wxwf/GHSA-hqgq-wgpj-wxwf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqgq-wgpj-wxwf", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-54443" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluginscafe Advanced Data Table For Elementor allows Stored XSS.This issue affects Advanced Data Table For Elementor: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54443" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-data-table-for-elementor/vulnerability/wordpress-advanced-data-table-for-elementor-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hv8q-qqrh-ccgj/GHSA-hv8q-qqrh-ccgj.json b/advisories/unreviewed/2024/12/GHSA-hv8q-qqrh-ccgj/GHSA-hv8q-qqrh-ccgj.json new file mode 100644 index 00000000000..e85a7c237b2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hv8q-qqrh-ccgj/GHSA-hv8q-qqrh-ccgj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hv8q-qqrh-ccgj", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54364" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spartac Feedpress Generator allows Reflected XSS.This issue affects Feedpress Generator: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54364" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/feedpress-generator/vulnerability/wordpress-feedpress-generator-plugin-1-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hwq4-qw38-h933/GHSA-hwq4-qw38-h933.json b/advisories/unreviewed/2024/12/GHSA-hwq4-qw38-h933/GHSA-hwq4-qw38-h933.json new file mode 100644 index 00000000000..670f7f116db --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hwq4-qw38-h933/GHSA-hwq4-qw38-h933.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwq4-qw38-h933", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54423" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Jesse Overright Social Media Sharing allows Stored XSS.This issue affects Social Media Sharing: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54423" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/social-media-sharing/vulnerability/wordpress-social-media-sharing-plugin-1-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j2f8-56pc-7gmr/GHSA-j2f8-56pc-7gmr.json b/advisories/unreviewed/2024/12/GHSA-j2f8-56pc-7gmr/GHSA-j2f8-56pc-7gmr.json new file mode 100644 index 00000000000..d4d995e4cbd --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j2f8-56pc-7gmr/GHSA-j2f8-56pc-7gmr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2f8-56pc-7gmr", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-55986" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in serviceonline Service allows Blind SQL Injection.This issue affects Service: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55986" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/service/vulnerability/wordpress-service-plugin-1-0-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jq38-2x24-q99r/GHSA-jq38-2x24-q99r.json b/advisories/unreviewed/2024/12/GHSA-jq38-2x24-q99r/GHSA-jq38-2x24-q99r.json new file mode 100644 index 00000000000..ee19cafbeaf --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jq38-2x24-q99r/GHSA-jq38-2x24-q99r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq38-2x24-q99r", + "modified": "2024-12-16T15:31:34Z", + "published": "2024-12-16T15:31:34Z", + "aliases": [ + "CVE-2024-37251" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WPENGINE, INC. Advanced Custom Fields PRO.This issue affects Advanced Custom Fields PRO: from n/a before 6.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37251" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-custom-fields-pro/vulnerability/wordpress-advanced-custom-fields-pro-plugin-6-3-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jr93-xph2-hggc/GHSA-jr93-xph2-hggc.json b/advisories/unreviewed/2024/12/GHSA-jr93-xph2-hggc/GHSA-jr93-xph2-hggc.json new file mode 100644 index 00000000000..cdf526ac9d6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jr93-xph2-hggc/GHSA-jr93-xph2-hggc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr93-xph2-hggc", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54387" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jaytesh Barange Posts Date Ranges allows Reflected XSS.This issue affects Posts Date Ranges: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54387" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/posts-date-ranges/vulnerability/wordpress-posts-date-ranges-plugin-2-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m5qp-25mc-53xj/GHSA-m5qp-25mc-53xj.json b/advisories/unreviewed/2024/12/GHSA-m5qp-25mc-53xj/GHSA-m5qp-25mc-53xj.json new file mode 100644 index 00000000000..5f558244a68 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m5qp-25mc-53xj/GHSA-m5qp-25mc-53xj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5qp-25mc-53xj", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54386" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Get Push Monkey LLC Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart allows Cross Site Request Forgery.This issue affects Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart: from n/a through 3.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54386" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/push-monkey-desktop-push-notifications/vulnerability/wordpress-push-monkey-pro-plugin-3-9-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mcw9-h88f-7f3f/GHSA-mcw9-h88f-7f3f.json b/advisories/unreviewed/2024/12/GHSA-mcw9-h88f-7f3f/GHSA-mcw9-h88f-7f3f.json new file mode 100644 index 00000000000..42c788fbb90 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mcw9-h88f-7f3f/GHSA-mcw9-h88f-7f3f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcw9-h88f-7f3f", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54425" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in LionScripts.com LionScripts: Site Maintenance & Noindex Nofollow Plugin allows Stored XSS.This issue affects LionScripts: Site Maintenance & Noindex Nofollow Plugin: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54425" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/maintenance-and-noindex-nofollow/vulnerability/wordpress-lionscripts-site-maintenance-plugin-2-1-csrf-to-stored-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mrfc-m82j-82wf/GHSA-mrfc-m82j-82wf.json b/advisories/unreviewed/2024/12/GHSA-mrfc-m82j-82wf/GHSA-mrfc-m82j-82wf.json new file mode 100644 index 00000000000..572e4f4ae9e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mrfc-m82j-82wf/GHSA-mrfc-m82j-82wf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrfc-m82j-82wf", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54367" + ], + "details": "Deserialization of Untrusted Data vulnerability in ForumWP ForumWP allows Object Injection.This issue affects ForumWP: from n/a through 2.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54367" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/forumwp/vulnerability/wordpress-forumwp-plugin-2-1-0-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mv4h-62h2-5hwv/GHSA-mv4h-62h2-5hwv.json b/advisories/unreviewed/2024/12/GHSA-mv4h-62h2-5hwv/GHSA-mv4h-62h2-5hwv.json new file mode 100644 index 00000000000..cb255974320 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mv4h-62h2-5hwv/GHSA-mv4h-62h2-5hwv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv4h-62h2-5hwv", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-54437" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Merrill M. Mayer jCarousel allows Stored XSS.This issue affects jCarousel: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54437" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jcarousel-for-wordpress/vulnerability/wordpress-jcarousel-for-wordpress-plugin-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mwqf-g5pc-qrr8/GHSA-mwqf-g5pc-qrr8.json b/advisories/unreviewed/2024/12/GHSA-mwqf-g5pc-qrr8/GHSA-mwqf-g5pc-qrr8.json new file mode 100644 index 00000000000..bd2f0c8045e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mwqf-g5pc-qrr8/GHSA-mwqf-g5pc-qrr8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwqf-g5pc-qrr8", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54361" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in outstrip Instant Appointment allows SQL Injection.This issue affects Instant Appointment: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54361" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/instant-appointment/vulnerability/wordpress-instant-appointment-plugin-1-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mx9w-v2pf-gr86/GHSA-mx9w-v2pf-gr86.json b/advisories/unreviewed/2024/12/GHSA-mx9w-v2pf-gr86/GHSA-mx9w-v2pf-gr86.json new file mode 100644 index 00000000000..64894c3c508 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mx9w-v2pf-gr86/GHSA-mx9w-v2pf-gr86.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx9w-v2pf-gr86", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54415" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Cyle Conoly WP-HideThat allows Stored XSS.This issue affects WP-HideThat: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54415" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-hide-that/vulnerability/wordpress-wp-hidethat-plugin-1-2-csrf-to-stored-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p49r-xxpc-j8fj/GHSA-p49r-xxpc-j8fj.json b/advisories/unreviewed/2024/12/GHSA-p49r-xxpc-j8fj/GHSA-p49r-xxpc-j8fj.json new file mode 100644 index 00000000000..545c70a128d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p49r-xxpc-j8fj/GHSA-p49r-xxpc-j8fj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p49r-xxpc-j8fj", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-55994" + ], + "details": "Missing Authorization vulnerability in 搜狐畅言 畅言评论系统 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 畅言评论系统: from n/a through 2.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55994" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/changyan/vulnerability/wordpress-plugin-2-0-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p6m5-m496-hfm6/GHSA-p6m5-m496-hfm6.json b/advisories/unreviewed/2024/12/GHSA-p6m5-m496-hfm6/GHSA-p6m5-m496-hfm6.json new file mode 100644 index 00000000000..e0dfd552367 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p6m5-m496-hfm6/GHSA-p6m5-m496-hfm6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6m5-m496-hfm6", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-54439" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Alok Tiwari Amazon Product Price allows Stored XSS.This issue affects Amazon Product Price: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54439" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/amazon-product-price/vulnerability/wordpress-amazon-product-price-plugin-1-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p7qh-jh34-85qr/GHSA-p7qh-jh34-85qr.json b/advisories/unreviewed/2024/12/GHSA-p7qh-jh34-85qr/GHSA-p7qh-jh34-85qr.json new file mode 100644 index 00000000000..d2ea6739b80 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p7qh-jh34-85qr/GHSA-p7qh-jh34-85qr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7qh-jh34-85qr", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-56001" + ], + "details": "Missing Authorization vulnerability in Ksher Ksher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ksher: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56001" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ksher-payment/vulnerability/wordpress-ksher-plugin-1-1-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p8cc-27cr-294h/GHSA-p8cc-27cr-294h.json b/advisories/unreviewed/2024/12/GHSA-p8cc-27cr-294h/GHSA-p8cc-27cr-294h.json new file mode 100644 index 00000000000..42866c38ba6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p8cc-27cr-294h/GHSA-p8cc-27cr-294h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8cc-27cr-294h", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-55974" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AMS Nexe Iberica Mimoos allows SQL Injection.This issue affects Mimoos: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55974" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/devoluciones-packback/vulnerability/wordpress-mimoos-plugin-1-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pcgf-8qxw-vjpc/GHSA-pcgf-8qxw-vjpc.json b/advisories/unreviewed/2024/12/GHSA-pcgf-8qxw-vjpc/GHSA-pcgf-8qxw-vjpc.json new file mode 100644 index 00000000000..a0697b4c830 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pcgf-8qxw-vjpc/GHSA-pcgf-8qxw-vjpc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcgf-8qxw-vjpc", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54413" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Stefan Brandt Display Future Posts allows Stored XSS.This issue affects Display Future Posts: from n/a through 0.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54413" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/display-future-posts/vulnerability/wordpress-display-future-posts-plugin-0-2-3-csrf-to-stored-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pqhv-cv76-m4hc/GHSA-pqhv-cv76-m4hc.json b/advisories/unreviewed/2024/12/GHSA-pqhv-cv76-m4hc/GHSA-pqhv-cv76-m4hc.json new file mode 100644 index 00000000000..f0530029571 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pqhv-cv76-m4hc/GHSA-pqhv-cv76-m4hc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqhv-cv76-m4hc", + "modified": "2024-12-16T15:31:34Z", + "published": "2024-12-16T15:31:34Z", + "aliases": [ + "CVE-2024-12089" + ], + "details": "A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12089" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pvqx-h7hh-wp79/GHSA-pvqx-h7hh-wp79.json b/advisories/unreviewed/2024/12/GHSA-pvqx-h7hh-wp79/GHSA-pvqx-h7hh-wp79.json new file mode 100644 index 00000000000..9e9adfb5187 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pvqx-h7hh-wp79/GHSA-pvqx-h7hh-wp79.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvqx-h7hh-wp79", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-55981" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nabajit Roy Nabz Image Gallery allows SQL Injection.This issue affects Nabz Image Gallery: from n/a through v1.00.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55981" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nabz-image-gallery/vulnerability/wordpress-nabz-image-gallery-plugin-v1-00-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q5vw-gwwh-j8r7/GHSA-q5vw-gwwh-j8r7.json b/advisories/unreviewed/2024/12/GHSA-q5vw-gwwh-j8r7/GHSA-q5vw-gwwh-j8r7.json new file mode 100644 index 00000000000..06f0fe36681 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q5vw-gwwh-j8r7/GHSA-q5vw-gwwh-j8r7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5vw-gwwh-j8r7", + "modified": "2024-12-16T15:31:34Z", + "published": "2024-12-16T15:31:34Z", + "aliases": [ + "CVE-2024-10972" + ], + "details": "Velocidex WinPmem versions below 4.1 suffer from an Improper Input Validation vulnerability whereby an attacker can directly communicate with the driver by accessing the \\\"\\\\\\\\.\\\\pmem\\\" device. From that point, it is possible to communicate with the driver via regular device operations, starting with a system of IOCTLs. To send specific orders to the driver, one can use IRP_MJ_DEVICE_CONTROL control code. This issue is remediated in version 4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10972" + }, + { + "type": "WEB", + "url": "https://github.com/Velocidex/WinPmem/releases/tag/v4.1.dev1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q97w-jc54-cmqr/GHSA-q97w-jc54-cmqr.json b/advisories/unreviewed/2024/12/GHSA-q97w-jc54-cmqr/GHSA-q97w-jc54-cmqr.json new file mode 100644 index 00000000000..9ea95cd8063 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q97w-jc54-cmqr/GHSA-q97w-jc54-cmqr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q97w-jc54-cmqr", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54429" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ivan Ovsyannikov Aphorismus allows Stored XSS.This issue affects Aphorismus: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54429" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/aphorismus/vulnerability/wordpress-aphorismus-plugin-1-2-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qc35-5wrm-x6wx/GHSA-qc35-5wrm-x6wx.json b/advisories/unreviewed/2024/12/GHSA-qc35-5wrm-x6wx/GHSA-qc35-5wrm-x6wx.json new file mode 100644 index 00000000000..f1b70edf6f4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qc35-5wrm-x6wx/GHSA-qc35-5wrm-x6wx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc35-5wrm-x6wx", + "modified": "2024-12-16T15:31:34Z", + "published": "2024-12-16T15:31:34Z", + "aliases": [ + "CVE-2024-49775" + ], + "details": "A vulnerability has been identified in Opcenter Execution Foundation (All versions), Opcenter Intelligence (All versions), Opcenter Quality (All versions), Opcenter RDL (All versions), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SINEC NMS (All versions if operated in conjunction with UMC < V2.15), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions). Affected products contain a heap-based buffer overflow vulnerability in the integrated UMC component.\nThis could allow an unauthenticated remote attacker to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49775" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-928984.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qhgg-j635-qfw9/GHSA-qhgg-j635-qfw9.json b/advisories/unreviewed/2024/12/GHSA-qhgg-j635-qfw9/GHSA-qhgg-j635-qfw9.json new file mode 100644 index 00000000000..260b70cafc0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qhgg-j635-qfw9/GHSA-qhgg-j635-qfw9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhgg-j635-qfw9", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-55987" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ritesh Sanap Advanced What should we write next about allows SQL Injection.This issue affects Advanced What should we write next about: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55987" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-what-should-we-write-about-next/vulnerability/wordpress-advanced-what-should-we-write-next-about-plugin-1-0-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qp25-vh5m-jhp5/GHSA-qp25-vh5m-jhp5.json b/advisories/unreviewed/2024/12/GHSA-qp25-vh5m-jhp5/GHSA-qp25-vh5m-jhp5.json new file mode 100644 index 00000000000..9bf170a8fd7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qp25-vh5m-jhp5/GHSA-qp25-vh5m-jhp5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp25-vh5m-jhp5", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54406" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Reza Moallemi Comments On Feed allows Reflected XSS.This issue affects Comments On Feed: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54406" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/comments-on-feed/vulnerability/wordpress-comments-on-feed-plugin-1-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qrwq-c8cf-p4wv/GHSA-qrwq-c8cf-p4wv.json b/advisories/unreviewed/2024/12/GHSA-qrwq-c8cf-p4wv/GHSA-qrwq-c8cf-p4wv.json new file mode 100644 index 00000000000..f77de5e6afc --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qrwq-c8cf-p4wv/GHSA-qrwq-c8cf-p4wv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrwq-c8cf-p4wv", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54399" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in CRUDLab CRUDLab Google Plus Button allows Stored XSS.This issue affects CRUDLab Google Plus Button: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54399" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/crudlab-google-plus/vulnerability/wordpress-crudlab-google-plus-button-plugin-1-0-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-r65p-7pcp-4hmm/GHSA-r65p-7pcp-4hmm.json b/advisories/unreviewed/2024/12/GHSA-r65p-7pcp-4hmm/GHSA-r65p-7pcp-4hmm.json new file mode 100644 index 00000000000..40b4fbbbac6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-r65p-7pcp-4hmm/GHSA-r65p-7pcp-4hmm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r65p-7pcp-4hmm", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-55988" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Amol Nirmala Waman Navayan CSV Export allows Blind SQL Injection.This issue affects Navayan CSV Export: from n/a through 1.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55988" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/navayan-csv-export/vulnerability/wordpress-navayan-csv-export-plugin-1-0-9-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rc8c-8v29-wf9h/GHSA-rc8c-8v29-wf9h.json b/advisories/unreviewed/2024/12/GHSA-rc8c-8v29-wf9h/GHSA-rc8c-8v29-wf9h.json new file mode 100644 index 00000000000..94dbe5cb9f3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rc8c-8v29-wf9h/GHSA-rc8c-8v29-wf9h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rc8c-8v29-wf9h", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-55982" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in richteam Share Buttons – Social Media allows Blind SQL Injection.This issue affects Share Buttons – Social Media: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55982" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rich-web-share-button/vulnerability/wordpress-share-buttons-social-media-plugin-1-0-2-sql-injection-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rhhv-6w3f-j654/GHSA-rhhv-6w3f-j654.json b/advisories/unreviewed/2024/12/GHSA-rhhv-6w3f-j654/GHSA-rhhv-6w3f-j654.json new file mode 100644 index 00000000000..b713b50c225 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rhhv-6w3f-j654/GHSA-rhhv-6w3f-j654.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhhv-6w3f-j654", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54366" + ], + "details": "Generation of Error Message Containing Sensitive Information vulnerability in Dave Kiss Vimeography allows Retrieve Embedded Sensitive Data.This issue affects Vimeography: from n/a through 2.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54366" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/vimeography/vulnerability/wordpress-vimeography-plugin-2-4-4-full-path-disclosure-fpd-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v267-h3hm-27xj/GHSA-v267-h3hm-27xj.json b/advisories/unreviewed/2024/12/GHSA-v267-h3hm-27xj/GHSA-v267-h3hm-27xj.json new file mode 100644 index 00000000000..e6056c8c062 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v267-h3hm-27xj/GHSA-v267-h3hm-27xj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v267-h3hm-27xj", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-54420" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Aleksander Novikov Metrika allows Cross Site Request Forgery.This issue affects Metrika: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54420" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/metrika/vulnerability/wordpress-metrika-plugin-1-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v3jg-qf5j-54wh/GHSA-v3jg-qf5j-54wh.json b/advisories/unreviewed/2024/12/GHSA-v3jg-qf5j-54wh/GHSA-v3jg-qf5j-54wh.json new file mode 100644 index 00000000000..bdc49cc1660 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v3jg-qf5j-54wh/GHSA-v3jg-qf5j-54wh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3jg-qf5j-54wh", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54370" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member allows Upload a Web Shell to a Web Server.This issue affects Video & Photo Gallery for Ultimate Member: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54370" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gallery-for-ultimate-member/vulnerability/wordpress-video-photo-gallery-for-ultimate-member-plugin-1-1-0-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v3qf-fgcw-33vg/GHSA-v3qf-fgcw-33vg.json b/advisories/unreviewed/2024/12/GHSA-v3qf-fgcw-33vg/GHSA-v3qf-fgcw-33vg.json new file mode 100644 index 00000000000..ffae533467c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v3qf-fgcw-33vg/GHSA-v3qf-fgcw-33vg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3qf-fgcw-33vg", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54385" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in SoftLab Radio Player allows Server Side Request Forgery.This issue affects Radio Player: from n/a through 2.0.82.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54385" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/radio-player/vulnerability/wordpress-radio-player-plugin-2-0-82-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v5wp-6cxh-7g56/GHSA-v5wp-6cxh-7g56.json b/advisories/unreviewed/2024/12/GHSA-v5wp-6cxh-7g56/GHSA-v5wp-6cxh-7g56.json new file mode 100644 index 00000000000..d91708d321b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v5wp-6cxh-7g56/GHSA-v5wp-6cxh-7g56.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5wp-6cxh-7g56", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54384" + ], + "details": "Missing Authorization vulnerability in eLightUp Falcon – WordPress Optimizations & Tweaks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Falcon – WordPress Optimizations & Tweaks: from n/a through 2.8.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54384" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/falcon/vulnerability/wordpress-falcon-wordpress-optimizations-tweaks-plugin-2-8-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v846-wcv6-j9fr/GHSA-v846-wcv6-j9fr.json b/advisories/unreviewed/2024/12/GHSA-v846-wcv6-j9fr/GHSA-v846-wcv6-j9fr.json new file mode 100644 index 00000000000..f38808ff87e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v846-wcv6-j9fr/GHSA-v846-wcv6-j9fr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v846-wcv6-j9fr", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-55980" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webriderz Wr Age Verification allows SQL Injection.This issue affects Wr Age Verification: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55980" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wr-age-verification/vulnerability/wordpress-wr-age-verification-plugin-2-0-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vcjh-jjp4-2cxf/GHSA-vcjh-jjp4-2cxf.json b/advisories/unreviewed/2024/12/GHSA-vcjh-jjp4-2cxf/GHSA-vcjh-jjp4-2cxf.json new file mode 100644 index 00000000000..cdcb76d8632 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vcjh-jjp4-2cxf/GHSA-vcjh-jjp4-2cxf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcjh-jjp4-2cxf", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54414" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in geoWP Geoportail Shortcode allows Stored XSS.This issue affects Geoportail Shortcode: from n/a through 2.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54414" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/geoportail-shortcode/vulnerability/wordpress-geoportail-shortcode-plugin-2-4-4-csrf-to-stored-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vcp9-mrmm-2gh8/GHSA-vcp9-mrmm-2gh8.json b/advisories/unreviewed/2024/12/GHSA-vcp9-mrmm-2gh8/GHSA-vcp9-mrmm-2gh8.json new file mode 100644 index 00000000000..fca19091478 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vcp9-mrmm-2gh8/GHSA-vcp9-mrmm-2gh8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcp9-mrmm-2gh8", + "modified": "2024-12-16T15:31:34Z", + "published": "2024-12-16T15:31:34Z", + "aliases": [ + "CVE-2024-54355" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in brandtoss WP Mailster allows Cross Site Request Forgery.This issue affects WP Mailster: from n/a through 1.8.17.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54355" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-mailster/vulnerability/wordpress-wp-mailster-plugin-1-8-17-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vfcc-4q8x-f299/GHSA-vfcc-4q8x-f299.json b/advisories/unreviewed/2024/12/GHSA-vfcc-4q8x-f299/GHSA-vfcc-4q8x-f299.json new file mode 100644 index 00000000000..98f7dbabee6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vfcc-4q8x-f299/GHSA-vfcc-4q8x-f299.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfcc-4q8x-f299", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54410" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Toby Cox SOPA Blackout allows Stored XSS.This issue affects SOPA Blackout: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54410" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sopa-blackout/vulnerability/wordpress-sopa-blackout-plugin-1-4-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vg3c-gxqw-hr85/GHSA-vg3c-gxqw-hr85.json b/advisories/unreviewed/2024/12/GHSA-vg3c-gxqw-hr85/GHSA-vg3c-gxqw-hr85.json new file mode 100644 index 00000000000..a0e8ac3c8aa --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vg3c-gxqw-hr85/GHSA-vg3c-gxqw-hr85.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg3c-gxqw-hr85", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54404" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Nazmul Ahsan MDC Comment Toolbar allows Stored XSS.This issue affects MDC Comment Toolbar: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54404" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mdc-comment-toolbar/vulnerability/wordpress-mdc-comment-toolbar-plugin-1-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vhww-mm25-q8mv/GHSA-vhww-mm25-q8mv.json b/advisories/unreviewed/2024/12/GHSA-vhww-mm25-q8mv/GHSA-vhww-mm25-q8mv.json new file mode 100644 index 00000000000..74a3d530231 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vhww-mm25-q8mv/GHSA-vhww-mm25-q8mv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhww-mm25-q8mv", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54424" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ilya Chekalskiy Like in Vk.com allows Stored XSS.This issue affects Like in Vk.com: from n/a through 0.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54424" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/like-on-vkontakte/vulnerability/wordpress-like-in-vk-com-plugin-0-5-2-csrf-to-stored-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vjr5-7gc7-rrhq/GHSA-vjr5-7gc7-rrhq.json b/advisories/unreviewed/2024/12/GHSA-vjr5-7gc7-rrhq/GHSA-vjr5-7gc7-rrhq.json new file mode 100644 index 00000000000..2f326be4c3e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vjr5-7gc7-rrhq/GHSA-vjr5-7gc7-rrhq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjr5-7gc7-rrhq", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54379" + ], + "details": "Missing Authorization vulnerability in Blokhaus Minterpress allows Privilege Escalation.This issue affects Minterpress: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54379" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/minterpress/vulnerability/wordpress-minterpress-plugin-1-0-5-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vpp4-4mqw-4hw7/GHSA-vpp4-4mqw-4hw7.json b/advisories/unreviewed/2024/12/GHSA-vpp4-4mqw-4hw7/GHSA-vpp4-4mqw-4hw7.json new file mode 100644 index 00000000000..a7b33c66465 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vpp4-4mqw-4hw7/GHSA-vpp4-4mqw-4hw7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpp4-4mqw-4hw7", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-55978" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WalletStation.com Code Generator Pro allows SQL Injection.This issue affects Code Generator Pro: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55978" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/code-generator-pro/vulnerability/wordpress-code-generator-pro-plugin-1-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w3r7-6c65-fr45/GHSA-w3r7-6c65-fr45.json b/advisories/unreviewed/2024/12/GHSA-w3r7-6c65-fr45/GHSA-w3r7-6c65-fr45.json new file mode 100644 index 00000000000..4033b6c75ef --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w3r7-6c65-fr45/GHSA-w3r7-6c65-fr45.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3r7-6c65-fr45", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-55990" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ewald Harmsen Mollie for Contact Form 7 allows Blind SQL Injection.This issue affects Mollie for Contact Form 7: from n/a through 5.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55990" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cf7-mollie/vulnerability/wordpress-mollie-for-contact-form-7-plugin-5-0-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w4w2-7q2f-mxm4/GHSA-w4w2-7q2f-mxm4.json b/advisories/unreviewed/2024/12/GHSA-w4w2-7q2f-mxm4/GHSA-w4w2-7q2f-mxm4.json new file mode 100644 index 00000000000..1ebf5a6c087 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w4w2-7q2f-mxm4/GHSA-w4w2-7q2f-mxm4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4w2-7q2f-mxm4", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54422" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gaowei Tang Evernote Sync allows Reflected XSS.This issue affects Evernote Sync: from n/a through 3.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54422" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/evernote-sync/vulnerability/wordpress-evernote-sync-plugin-3-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w926-rj83-69p8/GHSA-w926-rj83-69p8.json b/advisories/unreviewed/2024/12/GHSA-w926-rj83-69p8/GHSA-w926-rj83-69p8.json new file mode 100644 index 00000000000..54a0fe752bb --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w926-rj83-69p8/GHSA-w926-rj83-69p8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w926-rj83-69p8", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54382" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldThemes Bold Page Builder allows Path Traversal.This issue affects Bold Page Builder: from n/a through 5.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54382" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bold-page-builder/vulnerability/wordpress-bold-page-builder-plugin-5-1-5-path-traversal-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w97j-3h9r-h9rm/GHSA-w97j-3h9r-h9rm.json b/advisories/unreviewed/2024/12/GHSA-w97j-3h9r-h9rm/GHSA-w97j-3h9r-h9rm.json new file mode 100644 index 00000000000..df4fad9f20f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w97j-3h9r-h9rm/GHSA-w97j-3h9r-h9rm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w97j-3h9r-h9rm", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54388" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Phuc Pham Multiple Admin Emails allows Cross Site Request Forgery.This issue affects Multiple Admin Emails: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54388" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/multiple-admin-emails/vulnerability/wordpress-multiple-admin-emails-plugin-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wgjj-vjmp-269h/GHSA-wgjj-vjmp-269h.json b/advisories/unreviewed/2024/12/GHSA-wgjj-vjmp-269h/GHSA-wgjj-vjmp-269h.json new file mode 100644 index 00000000000..9c39894dece --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wgjj-vjmp-269h/GHSA-wgjj-vjmp-269h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgjj-vjmp-269h", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54360" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in premila Gutensee allows DOM-Based XSS.This issue affects Gutensee: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54360" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gutensee/vulnerability/wordpress-gutensee-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wgq9-xh75-7fxc/GHSA-wgq9-xh75-7fxc.json b/advisories/unreviewed/2024/12/GHSA-wgq9-xh75-7fxc/GHSA-wgq9-xh75-7fxc.json new file mode 100644 index 00000000000..7cc679c8d6f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wgq9-xh75-7fxc/GHSA-wgq9-xh75-7fxc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgq9-xh75-7fxc", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54416" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Navdeep Kumar Wp Login with Ajax allows Stored XSS.This issue affects Wp Login with Ajax: from n/a through 0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54416" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-login-with-ajax/vulnerability/wordpress-wp-login-with-ajax-plugin-0-6-csrf-to-stored-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wwm7-p227-pcgv/GHSA-wwm7-p227-pcgv.json b/advisories/unreviewed/2024/12/GHSA-wwm7-p227-pcgv/GHSA-wwm7-p227-pcgv.json new file mode 100644 index 00000000000..9b82fd6781a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wwm7-p227-pcgv/GHSA-wwm7-p227-pcgv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwm7-p227-pcgv", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54400" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in MELONIQ.NET AppMaps allows Stored XSS.This issue affects AppMaps: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54400" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/appmaps/vulnerability/wordpress-appmaps-plugin-1-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wx4q-8vh8-7998/GHSA-wx4q-8vh8-7998.json b/advisories/unreviewed/2024/12/GHSA-wx4q-8vh8-7998/GHSA-wx4q-8vh8-7998.json new file mode 100644 index 00000000000..e53d1e5498e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wx4q-8vh8-7998/GHSA-wx4q-8vh8-7998.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx4q-8vh8-7998", + "modified": "2024-12-16T15:31:35Z", + "published": "2024-12-16T15:31:35Z", + "aliases": [ + "CVE-2024-54363" + ], + "details": "Incorrect Privilege Assignment vulnerability in nssTheme Wp NssUser Register allows Privilege Escalation.This issue affects Wp NssUser Register: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54363" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-nssuser-register/vulnerability/wordpress-wp-nssuser-register-plugin-1-0-0-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x45w-x6jp-jg2w/GHSA-x45w-x6jp-jg2w.json b/advisories/unreviewed/2024/12/GHSA-x45w-x6jp-jg2w/GHSA-x45w-x6jp-jg2w.json new file mode 100644 index 00000000000..bb0db8ceefb --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x45w-x6jp-jg2w/GHSA-x45w-x6jp-jg2w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x45w-x6jp-jg2w", + "modified": "2024-12-16T15:31:34Z", + "published": "2024-12-16T15:31:34Z", + "aliases": [ + "CVE-2024-54358" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Avatar 3D Creator 3D Avatar User Profile allows Reflected XSS.This issue affects 3D Avatar User Profile: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54358" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/3d-avatar-user-profile/vulnerability/wordpress-3d-avatar-user-profile-plugin-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x5hw-h4f2-565p/GHSA-x5hw-h4f2-565p.json b/advisories/unreviewed/2024/12/GHSA-x5hw-h4f2-565p/GHSA-x5hw-h4f2-565p.json new file mode 100644 index 00000000000..8cdaf94a710 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x5hw-h4f2-565p/GHSA-x5hw-h4f2-565p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5hw-h4f2-565p", + "modified": "2024-12-16T15:31:34Z", + "published": "2024-12-16T15:31:34Z", + "aliases": [ + "CVE-2024-54353" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WPGear Hack-Info allows Stored XSS.This issue affects Hack-Info: from n/a through 3.17.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54353" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hack-info/vulnerability/wordpress-hack-info-plugin-3-17-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x942-9rvg-798r/GHSA-x942-9rvg-798r.json b/advisories/unreviewed/2024/12/GHSA-x942-9rvg-798r/GHSA-x942-9rvg-798r.json new file mode 100644 index 00000000000..732c4245ee5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x942-9rvg-798r/GHSA-x942-9rvg-798r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x942-9rvg-798r", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-55976" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mike Leembruggen Critical Site Intel allows SQL Injection.This issue affects Critical Site Intel: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55976" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/critical-site-intel-stats/vulnerability/wordpress-critical-site-intel-plugin-1-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xf96-h6wr-6499/GHSA-xf96-h6wr-6499.json b/advisories/unreviewed/2024/12/GHSA-xf96-h6wr-6499/GHSA-xf96-h6wr-6499.json new file mode 100644 index 00000000000..b2876273fbc --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xf96-h6wr-6499/GHSA-xf96-h6wr-6499.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xf96-h6wr-6499", + "modified": "2024-12-16T15:31:37Z", + "published": "2024-12-16T15:31:37Z", + "aliases": [ + "CVE-2024-56004" + ], + "details": "Missing Authorization vulnerability in Alex W Fowler Easy Site Importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Site Importer: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56004" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-site-importer/vulnerability/wordpress-easy-site-importer-plugin-1-0-1-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xfv4-rqpc-qx97/GHSA-xfv4-rqpc-qx97.json b/advisories/unreviewed/2024/12/GHSA-xfv4-rqpc-qx97/GHSA-xfv4-rqpc-qx97.json new file mode 100644 index 00000000000..04a0a1d6f88 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xfv4-rqpc-qx97/GHSA-xfv4-rqpc-qx97.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xfv4-rqpc-qx97", + "modified": "2024-12-16T15:31:36Z", + "published": "2024-12-16T15:31:36Z", + "aliases": [ + "CVE-2024-54408" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Jake H. Youtube Video Grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youtube Video Grid: from n/a through 1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54408" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/youmax-channel-embeds-for-youtube-businesses/vulnerability/wordpress-youtube-video-grid-plugin-1-9-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-16T15:15:17Z" + } +} \ No newline at end of file