diff --git a/advisories/unreviewed/2024/07/GHSA-6gjh-c4qj-794j/GHSA-6gjh-c4qj-794j.json b/advisories/unreviewed/2024/07/GHSA-6gjh-c4qj-794j/GHSA-6gjh-c4qj-794j.json new file mode 100644 index 00000000000..ecaab379cfd --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-6gjh-c4qj-794j/GHSA-6gjh-c4qj-794j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gjh-c4qj-794j", + "modified": "2024-07-22T00:30:36Z", + "published": "2024-07-22T00:30:36Z", + "aliases": [ + "CVE-2024-37457" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ultimate Blocks Ultimate Blocks – Gutenberg Blocks Plugin allows Stored XSS.This issue affects Ultimate Blocks – Gutenberg Blocks Plugin: from n/a through 3.1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37457" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ultimate-blocks/wordpress-ultimate-blocks-wordpress-blocks-plugin-plugin-3-1-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-21T23:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8976-mgrg-7rqg/GHSA-8976-mgrg-7rqg.json b/advisories/unreviewed/2024/07/GHSA-8976-mgrg-7rqg/GHSA-8976-mgrg-7rqg.json new file mode 100644 index 00000000000..dc63eddb937 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8976-mgrg-7rqg/GHSA-8976-mgrg-7rqg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8976-mgrg-7rqg", + "modified": "2024-07-22T00:30:35Z", + "published": "2024-07-22T00:30:35Z", + "aliases": [ + "CVE-2024-37446" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kiboko Labs Chained Quiz allows Stored XSS.This issue affects Chained Quiz: from n/a through 1.3.2.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37446" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/chained-quiz/wordpress-chained-quiz-plugin-1-3-2-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-21T23:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8j5c-mmh8-684w/GHSA-8j5c-mmh8-684w.json b/advisories/unreviewed/2024/07/GHSA-8j5c-mmh8-684w/GHSA-8j5c-mmh8-684w.json new file mode 100644 index 00000000000..0d2ee94414b --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8j5c-mmh8-684w/GHSA-8j5c-mmh8-684w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j5c-mmh8-684w", + "modified": "2024-07-22T00:30:35Z", + "published": "2024-07-22T00:30:35Z", + "aliases": [ + "CVE-2024-37465" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Senol Sahin GPT3 AI Content Writer allows Stored XSS.This issue affects GPT3 AI Content Writer: from n/a through 1.8.66.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37465" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/gpt3-ai-content-generator/wordpress-ai-power-complete-ai-pack-powered-by-gpt-4-plugin-1-8-66-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-21T22:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-h22g-mg95-g397/GHSA-h22g-mg95-g397.json b/advisories/unreviewed/2024/07/GHSA-h22g-mg95-g397/GHSA-h22g-mg95-g397.json new file mode 100644 index 00000000000..eb9d635332d --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-h22g-mg95-g397/GHSA-h22g-mg95-g397.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h22g-mg95-g397", + "modified": "2024-07-22T00:30:36Z", + "published": "2024-07-22T00:30:36Z", + "aliases": [ + "CVE-2024-6962" + ], + "details": "A vulnerability classified as critical was found in Tenda O3 1.0.0.10. This vulnerability affects the function formQosSet. The manipulation of the argument remark/ipRange/upSpeed/downSpeed/enable leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272116. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6962" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/O3V2.0/formQosSet.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.272116" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.272116" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.374583" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T00:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-j32g-hr5c-pwm2/GHSA-j32g-hr5c-pwm2.json b/advisories/unreviewed/2024/07/GHSA-j32g-hr5c-pwm2/GHSA-j32g-hr5c-pwm2.json new file mode 100644 index 00000000000..15b9e69b55f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-j32g-hr5c-pwm2/GHSA-j32g-hr5c-pwm2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j32g-hr5c-pwm2", + "modified": "2024-07-22T00:30:35Z", + "published": "2024-07-22T00:30:35Z", + "aliases": [ + "CVE-2024-38781" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ArtistScope CopySafe Web Protection allows Reflected XSS.This issue affects CopySafe Web Protection: from n/a through 3.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38781" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-copysafe-web/wordpress-copysafe-web-protection-plugin-3-15-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-21T22:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-j7jv-2w23-w786/GHSA-j7jv-2w23-w786.json b/advisories/unreviewed/2024/07/GHSA-j7jv-2w23-w786/GHSA-j7jv-2w23-w786.json new file mode 100644 index 00000000000..d4ae9f12ea9 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-j7jv-2w23-w786/GHSA-j7jv-2w23-w786.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7jv-2w23-w786", + "modified": "2024-07-22T00:30:36Z", + "published": "2024-07-22T00:30:36Z", + "aliases": [ + "CVE-2024-6963" + ], + "details": "A vulnerability, which was classified as critical, has been found in Tenda O3 1.0.0.10. This issue affects the function formexeCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272117 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6963" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/O3V2.0/formexeCommand.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.272117" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.272117" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.374584" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-22T00:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-mf8x-j428-fg35/GHSA-mf8x-j428-fg35.json b/advisories/unreviewed/2024/07/GHSA-mf8x-j428-fg35/GHSA-mf8x-j428-fg35.json new file mode 100644 index 00000000000..deefcaba43f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-mf8x-j428-fg35/GHSA-mf8x-j428-fg35.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf8x-j428-fg35", + "modified": "2024-07-22T00:30:35Z", + "published": "2024-07-22T00:30:35Z", + "aliases": [ + "CVE-2024-37459" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PayPlus LTD PayPlus Payment Gateway allows Reflected XSS.This issue affects PayPlus Payment Gateway: from n/a through 6.6.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37459" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/payplus-payment-gateway/wordpress-payplus-payment-gateway-plugin-6-6-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-21T22:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-phcc-x3ph-xcr3/GHSA-phcc-x3ph-xcr3.json b/advisories/unreviewed/2024/07/GHSA-phcc-x3ph-xcr3/GHSA-phcc-x3ph-xcr3.json new file mode 100644 index 00000000000..9e4f8ff74b4 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-phcc-x3ph-xcr3/GHSA-phcc-x3ph-xcr3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phcc-x3ph-xcr3", + "modified": "2024-07-22T00:30:35Z", + "published": "2024-07-22T00:30:35Z", + "aliases": [ + "CVE-2024-37480" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Apollo13Themes Apollo13 Framework Extensions apollo13-framework-extensions allows Stored XSS.This issue affects Apollo13 Framework Extensions: from n/a through 1.9.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37480" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/apollo13-framework-extensions/wordpress-apollo13-framework-extensions-plugin-1-9-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-21T22:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-q3x3-7729-46hc/GHSA-q3x3-7729-46hc.json b/advisories/unreviewed/2024/07/GHSA-q3x3-7729-46hc/GHSA-q3x3-7729-46hc.json new file mode 100644 index 00000000000..eadd13fa36b --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-q3x3-7729-46hc/GHSA-q3x3-7729-46hc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3x3-7729-46hc", + "modified": "2024-07-22T00:30:36Z", + "published": "2024-07-22T00:30:36Z", + "aliases": [ + "CVE-2024-37449" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.7.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37449" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/revslider/wordpress-slider-revolution-plugin-6-7-13-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-21T23:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-rrwg-x3vw-47jq/GHSA-rrwg-x3vw-47jq.json b/advisories/unreviewed/2024/07/GHSA-rrwg-x3vw-47jq/GHSA-rrwg-x3vw-47jq.json new file mode 100644 index 00000000000..4d5d33a3a29 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-rrwg-x3vw-47jq/GHSA-rrwg-x3vw-47jq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrwg-x3vw-47jq", + "modified": "2024-07-22T00:30:35Z", + "published": "2024-07-22T00:30:35Z", + "aliases": [ + "CVE-2024-37466" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kraftplugins Mega Elements.This issue affects Mega Elements: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37466" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mega-elements-addons-for-elementor/wordpress-mega-elements-plugin-1-2-2-contributor-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-21T22:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-rxm4-rcrf-9vfm/GHSA-rxm4-rcrf-9vfm.json b/advisories/unreviewed/2024/07/GHSA-rxm4-rcrf-9vfm/GHSA-rxm4-rcrf-9vfm.json new file mode 100644 index 00000000000..2b8b660dcc9 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-rxm4-rcrf-9vfm/GHSA-rxm4-rcrf-9vfm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxm4-rcrf-9vfm", + "modified": "2024-07-22T00:30:35Z", + "published": "2024-07-22T00:30:35Z", + "aliases": [ + "CVE-2024-37461" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibson IdeaPush allows Stored XSS.This issue affects IdeaPush: from n/a through 8.65.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37461" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ideapush/wordpress-ideapush-plugin-8-65-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-21T22:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-v732-x3hh-884c/GHSA-v732-x3hh-884c.json b/advisories/unreviewed/2024/07/GHSA-v732-x3hh-884c/GHSA-v732-x3hh-884c.json new file mode 100644 index 00000000000..25db0ff6430 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-v732-x3hh-884c/GHSA-v732-x3hh-884c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v732-x3hh-884c", + "modified": "2024-07-22T00:30:36Z", + "published": "2024-07-22T00:30:36Z", + "aliases": [ + "CVE-2024-37447" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PixelYourSite PixelYourSite – Your smart PIXEL (TAG) Manager allows Stored XSS.This issue affects PixelYourSite – Your smart PIXEL (TAG) Manager: from n/a through 9.6.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37447" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pixelyoursite/wordpress-pixelyoursite-your-smart-pixel-tag-api-manager-plugin-9-6-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-21T23:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-v927-q8h9-6wx3/GHSA-v927-q8h9-6wx3.json b/advisories/unreviewed/2024/07/GHSA-v927-q8h9-6wx3/GHSA-v927-q8h9-6wx3.json new file mode 100644 index 00000000000..8f77fd7bacd --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-v927-q8h9-6wx3/GHSA-v927-q8h9-6wx3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v927-q8h9-6wx3", + "modified": "2024-07-22T00:30:35Z", + "published": "2024-07-22T00:30:35Z", + "aliases": [ + "CVE-2024-37485" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vinny Alves (UseStrict Consulting) bbPress Notify allows Reflected XSS.This issue affects bbPress Notify: from n/a through 2.18.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37485" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bbpress-notify-nospam/wordpress-bbpress-notify-no-spam-plugin-2-18-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-21T22:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-wmqh-rxr8-9mrc/GHSA-wmqh-rxr8-9mrc.json b/advisories/unreviewed/2024/07/GHSA-wmqh-rxr8-9mrc/GHSA-wmqh-rxr8-9mrc.json new file mode 100644 index 00000000000..2c31948541a --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-wmqh-rxr8-9mrc/GHSA-wmqh-rxr8-9mrc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmqh-rxr8-9mrc", + "modified": "2024-07-22T00:30:35Z", + "published": "2024-07-22T00:30:35Z", + "aliases": [ + "CVE-2024-37460" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SuperSaaS SuperSaaS – online appointment scheduling allows Stored XSS.This issue affects SuperSaaS – online appointment scheduling: from n/a through 2.1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37460" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/supersaas-appointment-scheduling/wordpress-supersaas-online-appointment-scheduling-plugin-2-1-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-21T22:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-x36h-623h-3qgf/GHSA-x36h-623h-3qgf.json b/advisories/unreviewed/2024/07/GHSA-x36h-623h-3qgf/GHSA-x36h-623h-3qgf.json new file mode 100644 index 00000000000..73a3632cae5 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-x36h-623h-3qgf/GHSA-x36h-623h-3qgf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x36h-623h-3qgf", + "modified": "2024-07-22T00:30:35Z", + "published": "2024-07-22T00:30:35Z", + "aliases": [ + "CVE-2024-38782" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MapsMarker.Com e.U. Leaflet Maps Marker allows Stored XSS.This issue affects Leaflet Maps Marker: from n/a through 3.12.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38782" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/leaflet-maps-marker/wordpress-leaflet-maps-marker-plugin-3-12-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-21T22:15:04Z" + } +} \ No newline at end of file