From c810acd7b85434953f1e884479d2ac2c3936e672 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 3 Jun 2025 03:32:11 +0000 Subject: [PATCH] Publish Advisories GHSA-5c32-vrpq-fgr5 GHSA-65w2-546p-7mvg GHSA-9qhh-c53m-4q69 GHSA-rfh5-gx7w-h7v7 GHSA-jpf5-526x-c5hw GHSA-4cg2-c6h6-v749 GHSA-54fr-xq3m-cp2f GHSA-55pf-868x-9jw7 GHSA-5xmm-mgwx-ww9j GHSA-cgv7-8cq3-8938 GHSA-rcj3-h239-hjc8 GHSA-x828-wp24-7h9m --- .../GHSA-5c32-vrpq-fgr5.json | 6 ++- .../GHSA-65w2-546p-7mvg.json | 2 +- .../GHSA-9qhh-c53m-4q69.json | 3 +- .../GHSA-rfh5-gx7w-h7v7.json | 6 ++- .../GHSA-jpf5-526x-c5hw.json | 6 ++- .../GHSA-4cg2-c6h6-v749.json | 48 +++++++++++++++++++ .../GHSA-54fr-xq3m-cp2f.json | 40 ++++++++++++++++ .../GHSA-55pf-868x-9jw7.json | 15 ++++-- .../GHSA-5xmm-mgwx-ww9j.json | 11 +++-- .../GHSA-cgv7-8cq3-8938.json | 44 +++++++++++++++++ .../GHSA-rcj3-h239-hjc8.json | 15 ++++-- .../GHSA-x828-wp24-7h9m.json | 15 ++++-- 12 files changed, 191 insertions(+), 20 deletions(-) create mode 100644 advisories/unreviewed/2025/06/GHSA-4cg2-c6h6-v749/GHSA-4cg2-c6h6-v749.json create mode 100644 advisories/unreviewed/2025/06/GHSA-54fr-xq3m-cp2f/GHSA-54fr-xq3m-cp2f.json create mode 100644 advisories/unreviewed/2025/06/GHSA-cgv7-8cq3-8938/GHSA-cgv7-8cq3-8938.json diff --git a/advisories/unreviewed/2023/08/GHSA-5c32-vrpq-fgr5/GHSA-5c32-vrpq-fgr5.json b/advisories/unreviewed/2023/08/GHSA-5c32-vrpq-fgr5/GHSA-5c32-vrpq-fgr5.json index c21ca9573d4..24198facf98 100644 --- a/advisories/unreviewed/2023/08/GHSA-5c32-vrpq-fgr5/GHSA-5c32-vrpq-fgr5.json +++ b/advisories/unreviewed/2023/08/GHSA-5c32-vrpq-fgr5/GHSA-5c32-vrpq-fgr5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5c32-vrpq-fgr5", - "modified": "2024-12-15T21:34:15Z", + "modified": "2025-06-03T03:30:31Z", "published": "2023-08-16T21:31:04Z", "aliases": [ "CVE-2023-4387" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://github.com/torvalds/linux/commit/9e7fef9521e73ca8afd7da9e58c14654b02dfad8" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2022:7683" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2022:8267" diff --git a/advisories/unreviewed/2023/12/GHSA-65w2-546p-7mvg/GHSA-65w2-546p-7mvg.json b/advisories/unreviewed/2023/12/GHSA-65w2-546p-7mvg/GHSA-65w2-546p-7mvg.json index 9ded2e3ccd9..d5a3c2431fd 100644 --- a/advisories/unreviewed/2023/12/GHSA-65w2-546p-7mvg/GHSA-65w2-546p-7mvg.json +++ b/advisories/unreviewed/2023/12/GHSA-65w2-546p-7mvg/GHSA-65w2-546p-7mvg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-65w2-546p-7mvg", - "modified": "2023-12-07T21:31:10Z", + "modified": "2025-06-03T03:30:31Z", "published": "2023-12-04T15:31:55Z", "aliases": [ "CVE-2023-48863" diff --git a/advisories/unreviewed/2023/12/GHSA-9qhh-c53m-4q69/GHSA-9qhh-c53m-4q69.json b/advisories/unreviewed/2023/12/GHSA-9qhh-c53m-4q69/GHSA-9qhh-c53m-4q69.json index 42cedeee805..b707eeb9c2d 100644 --- a/advisories/unreviewed/2023/12/GHSA-9qhh-c53m-4q69/GHSA-9qhh-c53m-4q69.json +++ b/advisories/unreviewed/2023/12/GHSA-9qhh-c53m-4q69/GHSA-9qhh-c53m-4q69.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-rfh5-gx7w-h7v7/GHSA-rfh5-gx7w-h7v7.json b/advisories/unreviewed/2025/04/GHSA-rfh5-gx7w-h7v7/GHSA-rfh5-gx7w-h7v7.json index 3c7839f1c1f..4ef752fbfe6 100644 --- a/advisories/unreviewed/2025/04/GHSA-rfh5-gx7w-h7v7/GHSA-rfh5-gx7w-h7v7.json +++ b/advisories/unreviewed/2025/04/GHSA-rfh5-gx7w-h7v7/GHSA-rfh5-gx7w-h7v7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rfh5-gx7w-h7v7", - "modified": "2025-05-30T18:31:01Z", + "modified": "2025-06-03T03:30:32Z", "published": "2025-04-15T06:30:34Z", "aliases": [ "CVE-2025-3576" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3576" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:8411" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-3576" diff --git a/advisories/unreviewed/2025/05/GHSA-jpf5-526x-c5hw/GHSA-jpf5-526x-c5hw.json b/advisories/unreviewed/2025/05/GHSA-jpf5-526x-c5hw/GHSA-jpf5-526x-c5hw.json index b4e2c0fc76d..9f0c65ee04c 100644 --- a/advisories/unreviewed/2025/05/GHSA-jpf5-526x-c5hw/GHSA-jpf5-526x-c5hw.json +++ b/advisories/unreviewed/2025/05/GHSA-jpf5-526x-c5hw/GHSA-jpf5-526x-c5hw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jpf5-526x-c5hw", - "modified": "2025-06-02T21:30:24Z", + "modified": "2025-06-03T03:30:31Z", "published": "2025-05-30T15:30:30Z", "aliases": [ "CVE-2025-40909" @@ -66,6 +66,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/06/02/6" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/06/02/7" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/06/GHSA-4cg2-c6h6-v749/GHSA-4cg2-c6h6-v749.json b/advisories/unreviewed/2025/06/GHSA-4cg2-c6h6-v749/GHSA-4cg2-c6h6-v749.json new file mode 100644 index 00000000000..047f5cd6712 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4cg2-c6h6-v749/GHSA-4cg2-c6h6-v749.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cg2-c6h6-v749", + "modified": "2025-06-03T03:30:32Z", + "published": "2025-06-03T03:30:32Z", + "aliases": [ + "CVE-2025-2939" + ], + "details": "The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter . This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute arbitrary functions, though it does not allow user supplied parameters only single functions can be called so the impact is limited.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2939" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ninja-tables/tags/5.0.18/vendor/wpfluent/framework/src/WPFluent/Http/Client.php#L399" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ninja-tables/tags/5.0.19/vendor/wpfluent/framework/src/WPFluent/Http/Client.php#L399" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ninja-tables/trunk/vendor/wpfluent/framework/src/WPFluent/Http/Client.php#L399" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8e38553d-5dba-4c84-95f7-43420245c770?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T03:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-54fr-xq3m-cp2f/GHSA-54fr-xq3m-cp2f.json b/advisories/unreviewed/2025/06/GHSA-54fr-xq3m-cp2f/GHSA-54fr-xq3m-cp2f.json new file mode 100644 index 00000000000..ff1abcb509a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-54fr-xq3m-cp2f/GHSA-54fr-xq3m-cp2f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54fr-xq3m-cp2f", + "modified": "2025-06-03T03:30:32Z", + "published": "2025-06-03T03:30:32Z", + "aliases": [ + "CVE-2025-4224" + ], + "details": "The wpForo + wpForo Advanced Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upload names in all versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4224" + }, + { + "type": "WEB", + "url": "https://gvectors.com/product/wpforo-advanced-attachments/#tab-changelog" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e634dafc-8eb0-406f-93b1-ee1d2b44171d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T03:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-55pf-868x-9jw7/GHSA-55pf-868x-9jw7.json b/advisories/unreviewed/2025/06/GHSA-55pf-868x-9jw7/GHSA-55pf-868x-9jw7.json index ee22964e7d4..3ef21dca491 100644 --- a/advisories/unreviewed/2025/06/GHSA-55pf-868x-9jw7/GHSA-55pf-868x-9jw7.json +++ b/advisories/unreviewed/2025/06/GHSA-55pf-868x-9jw7/GHSA-55pf-868x-9jw7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-55pf-868x-9jw7", - "modified": "2025-06-02T21:30:25Z", + "modified": "2025-06-03T03:30:31Z", "published": "2025-06-02T21:30:25Z", "aliases": [ "CVE-2025-23099" ], "details": "An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-02T19:15:26Z" diff --git a/advisories/unreviewed/2025/06/GHSA-5xmm-mgwx-ww9j/GHSA-5xmm-mgwx-ww9j.json b/advisories/unreviewed/2025/06/GHSA-5xmm-mgwx-ww9j/GHSA-5xmm-mgwx-ww9j.json index 0eb65e07a7e..45ea18d364c 100644 --- a/advisories/unreviewed/2025/06/GHSA-5xmm-mgwx-ww9j/GHSA-5xmm-mgwx-ww9j.json +++ b/advisories/unreviewed/2025/06/GHSA-5xmm-mgwx-ww9j/GHSA-5xmm-mgwx-ww9j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5xmm-mgwx-ww9j", - "modified": "2025-06-03T00:31:03Z", + "modified": "2025-06-03T03:30:31Z", "published": "2025-06-03T00:31:02Z", "aliases": [ "CVE-2025-5068" ], "details": "Use after free in Blink in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-03T00:15:20Z" diff --git a/advisories/unreviewed/2025/06/GHSA-cgv7-8cq3-8938/GHSA-cgv7-8cq3-8938.json b/advisories/unreviewed/2025/06/GHSA-cgv7-8cq3-8938/GHSA-cgv7-8cq3-8938.json new file mode 100644 index 00000000000..2420d436933 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-cgv7-8cq3-8938/GHSA-cgv7-8cq3-8938.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgv7-8cq3-8938", + "modified": "2025-06-03T03:30:32Z", + "published": "2025-06-03T03:30:32Z", + "aliases": [ + "CVE-2025-4047" + ], + "details": "The Broken Link Checker plugin for WordPress is vulnerable to unauthorized data access due to a missing capability check on the ajax_full_status and ajax_dashboard_status functions in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view the plugin's status.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4047" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/broken-link-checker/tags/2.4.2/legacy/core/core.php#L3272" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3294992" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/33ac910c-9531-45ea-84cf-1d379233f7d3?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-03T03:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rcj3-h239-hjc8/GHSA-rcj3-h239-hjc8.json b/advisories/unreviewed/2025/06/GHSA-rcj3-h239-hjc8/GHSA-rcj3-h239-hjc8.json index 16e205bbbf9..eab6d2fcb9f 100644 --- a/advisories/unreviewed/2025/06/GHSA-rcj3-h239-hjc8/GHSA-rcj3-h239-hjc8.json +++ b/advisories/unreviewed/2025/06/GHSA-rcj3-h239-hjc8/GHSA-rcj3-h239-hjc8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rcj3-h239-hjc8", - "modified": "2025-06-02T21:30:25Z", + "modified": "2025-06-03T03:30:31Z", "published": "2025-06-02T21:30:25Z", "aliases": [ "CVE-2025-23105" ], "details": "An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processor leads to privilege escalation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-02T19:15:26Z" diff --git a/advisories/unreviewed/2025/06/GHSA-x828-wp24-7h9m/GHSA-x828-wp24-7h9m.json b/advisories/unreviewed/2025/06/GHSA-x828-wp24-7h9m/GHSA-x828-wp24-7h9m.json index fdae92f4cc4..6b58adbed3d 100644 --- a/advisories/unreviewed/2025/06/GHSA-x828-wp24-7h9m/GHSA-x828-wp24-7h9m.json +++ b/advisories/unreviewed/2025/06/GHSA-x828-wp24-7h9m/GHSA-x828-wp24-7h9m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x828-wp24-7h9m", - "modified": "2025-06-03T00:31:03Z", + "modified": "2025-06-03T03:30:32Z", "published": "2025-06-03T00:31:02Z", "aliases": [ "CVE-2025-5419" ], "details": "Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-06-03T00:15:21Z"