diff --git a/advisories/github-reviewed/2024/03/GHSA-xjp4-hw94-mvp5/GHSA-xjp4-hw94-mvp5.json b/advisories/github-reviewed/2024/03/GHSA-xjp4-hw94-mvp5/GHSA-xjp4-hw94-mvp5.json index bf20fc55fbf..9c3b6d4fd15 100644 --- a/advisories/github-reviewed/2024/03/GHSA-xjp4-hw94-mvp5/GHSA-xjp4-hw94-mvp5.json +++ b/advisories/github-reviewed/2024/03/GHSA-xjp4-hw94-mvp5/GHSA-xjp4-hw94-mvp5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xjp4-hw94-mvp5", - "modified": "2024-05-02T18:47:14Z", + "modified": "2024-12-13T15:30:38Z", "published": "2024-03-21T09:31:14Z", "aliases": [ "CVE-2024-29131" @@ -64,6 +64,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YD4AFTIIQW662LUAQRMWS6BBKYSZG3YS" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241213-0001" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/03/20/4" diff --git a/advisories/github-reviewed/2024/09/GHSA-735f-pc8j-v9w8/GHSA-735f-pc8j-v9w8.json b/advisories/github-reviewed/2024/09/GHSA-735f-pc8j-v9w8/GHSA-735f-pc8j-v9w8.json index 7e84ca750b2..9a98bba5a64 100644 --- a/advisories/github-reviewed/2024/09/GHSA-735f-pc8j-v9w8/GHSA-735f-pc8j-v9w8.json +++ b/advisories/github-reviewed/2024/09/GHSA-735f-pc8j-v9w8/GHSA-735f-pc8j-v9w8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-735f-pc8j-v9w8", - "modified": "2024-09-23T20:07:08Z", + "modified": "2024-12-13T15:30:39Z", "published": "2024-09-19T16:06:03Z", "aliases": [ "CVE-2024-7254" @@ -345,6 +345,10 @@ { "type": "WEB", "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/google-protobuf/CVE-2024-7254.yml" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241213-0010" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-6mxm-8w9r-4997/GHSA-6mxm-8w9r-4997.json b/advisories/unreviewed/2022/05/GHSA-6mxm-8w9r-4997/GHSA-6mxm-8w9r-4997.json index c4af71cabc1..0c178d9a97a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6mxm-8w9r-4997/GHSA-6mxm-8w9r-4997.json +++ b/advisories/unreviewed/2022/05/GHSA-6mxm-8w9r-4997/GHSA-6mxm-8w9r-4997.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6mxm-8w9r-4997", - "modified": "2022-05-13T01:27:49Z", + "modified": "2024-12-13T15:30:38Z", "published": "2022-05-13T01:27:49Z", "aliases": [ "CVE-2018-12122" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://security.gentoo.org/glsa/202003-48" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241213-0009" + }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/106043" diff --git a/advisories/unreviewed/2022/05/GHSA-f6m9-hpfw-xjw4/GHSA-f6m9-hpfw-xjw4.json b/advisories/unreviewed/2022/05/GHSA-f6m9-hpfw-xjw4/GHSA-f6m9-hpfw-xjw4.json index 3b3377779b3..b315a433011 100644 --- a/advisories/unreviewed/2022/05/GHSA-f6m9-hpfw-xjw4/GHSA-f6m9-hpfw-xjw4.json +++ b/advisories/unreviewed/2022/05/GHSA-f6m9-hpfw-xjw4/GHSA-f6m9-hpfw-xjw4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f6m9-hpfw-xjw4", - "modified": "2022-05-13T01:27:48Z", + "modified": "2024-12-13T15:30:38Z", "published": "2022-05-13T01:27:48Z", "aliases": [ "CVE-2018-12123" @@ -30,10 +30,15 @@ { "type": "WEB", "url": "https://security.gentoo.org/glsa/202003-48" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241213-0008" } ], "database_specific": { "cwe_ids": [ + "CWE-115", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-jh5x-7c5f-4c44/GHSA-jh5x-7c5f-4c44.json b/advisories/unreviewed/2022/05/GHSA-jh5x-7c5f-4c44/GHSA-jh5x-7c5f-4c44.json index c57939d4105..59bfea3f9c4 100644 --- a/advisories/unreviewed/2022/05/GHSA-jh5x-7c5f-4c44/GHSA-jh5x-7c5f-4c44.json +++ b/advisories/unreviewed/2022/05/GHSA-jh5x-7c5f-4c44/GHSA-jh5x-7c5f-4c44.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jh5x-7c5f-4c44", - "modified": "2022-05-13T01:16:06Z", + "modified": "2024-12-13T15:30:38Z", "published": "2022-05-13T01:16:06Z", "aliases": [ "CVE-2018-7738" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://bugs.debian.org/892179" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241213-0002" + }, { "type": "WEB", "url": "https://usn.ubuntu.com/4512-1" diff --git a/advisories/unreviewed/2022/05/GHSA-pv82-vf69-rqqm/GHSA-pv82-vf69-rqqm.json b/advisories/unreviewed/2022/05/GHSA-pv82-vf69-rqqm/GHSA-pv82-vf69-rqqm.json index a52d22c11c2..86287803da9 100644 --- a/advisories/unreviewed/2022/05/GHSA-pv82-vf69-rqqm/GHSA-pv82-vf69-rqqm.json +++ b/advisories/unreviewed/2022/05/GHSA-pv82-vf69-rqqm/GHSA-pv82-vf69-rqqm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pv82-vf69-rqqm", - "modified": "2022-05-13T01:04:11Z", + "modified": "2024-12-13T15:30:38Z", "published": "2022-05-13T01:04:11Z", "aliases": [ "CVE-2017-9217" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://launchpad.net/bugs/1621396" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241213-0003" + }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/98677" diff --git a/advisories/unreviewed/2023/05/GHSA-c9hr-fvm9-7c49/GHSA-c9hr-fvm9-7c49.json b/advisories/unreviewed/2023/05/GHSA-c9hr-fvm9-7c49/GHSA-c9hr-fvm9-7c49.json index 6dd2466b8b8..f5c3d77adbb 100644 --- a/advisories/unreviewed/2023/05/GHSA-c9hr-fvm9-7c49/GHSA-c9hr-fvm9-7c49.json +++ b/advisories/unreviewed/2023/05/GHSA-c9hr-fvm9-7c49/GHSA-c9hr-fvm9-7c49.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c9hr-fvm9-7c49", - "modified": "2024-04-04T04:02:38Z", + "modified": "2024-12-13T15:30:38Z", "published": "2023-05-11T18:30:17Z", "aliases": [ "CVE-2023-29400" @@ -34,6 +34,10 @@ { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2023-1753" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241213-0005" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-f2cj-5636-4j38/GHSA-f2cj-5636-4j38.json b/advisories/unreviewed/2023/06/GHSA-f2cj-5636-4j38/GHSA-f2cj-5636-4j38.json index 4a482f555d9..4e93d1b7513 100644 --- a/advisories/unreviewed/2023/06/GHSA-f2cj-5636-4j38/GHSA-f2cj-5636-4j38.json +++ b/advisories/unreviewed/2023/06/GHSA-f2cj-5636-4j38/GHSA-f2cj-5636-4j38.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f2cj-5636-4j38", - "modified": "2023-11-25T12:30:22Z", + "modified": "2024-12-13T15:30:38Z", "published": "2023-06-08T21:30:27Z", "aliases": [ "CVE-2023-29402" @@ -46,6 +46,10 @@ { "type": "WEB", "url": "https://security.gentoo.org/glsa/202311-09" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241213-0004" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-53mx-8hhc-gmp3/GHSA-53mx-8hhc-gmp3.json b/advisories/unreviewed/2024/11/GHSA-53mx-8hhc-gmp3/GHSA-53mx-8hhc-gmp3.json index 58f1d3038cc..fc1c547cc77 100644 --- a/advisories/unreviewed/2024/11/GHSA-53mx-8hhc-gmp3/GHSA-53mx-8hhc-gmp3.json +++ b/advisories/unreviewed/2024/11/GHSA-53mx-8hhc-gmp3/GHSA-53mx-8hhc-gmp3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-53mx-8hhc-gmp3", - "modified": "2024-11-27T18:34:03Z", + "modified": "2024-12-13T15:30:38Z", "published": "2024-11-26T15:31:01Z", "aliases": [ "CVE-2024-11691" @@ -46,6 +46,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-68" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-70" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-g337-g667-mjvw/GHSA-g337-g667-mjvw.json b/advisories/unreviewed/2024/11/GHSA-g337-g667-mjvw/GHSA-g337-g667-mjvw.json index 082b6f90d10..de3c0de97ce 100644 --- a/advisories/unreviewed/2024/11/GHSA-g337-g667-mjvw/GHSA-g337-g667-mjvw.json +++ b/advisories/unreviewed/2024/11/GHSA-g337-g667-mjvw/GHSA-g337-g667-mjvw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g337-g667-mjvw", - "modified": "2024-11-25T21:30:48Z", + "modified": "2024-12-13T15:30:38Z", "published": "2024-11-06T09:31:21Z", "aliases": [ "CVE-2024-9681" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://curl.se/docs/CVE-2024-9681.json" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241213-0006" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/11/06/2" diff --git a/advisories/unreviewed/2024/11/GHSA-mjcw-r3mg-3848/GHSA-mjcw-r3mg-3848.json b/advisories/unreviewed/2024/11/GHSA-mjcw-r3mg-3848/GHSA-mjcw-r3mg-3848.json index b7c92030946..3959c8f435e 100644 --- a/advisories/unreviewed/2024/11/GHSA-mjcw-r3mg-3848/GHSA-mjcw-r3mg-3848.json +++ b/advisories/unreviewed/2024/11/GHSA-mjcw-r3mg-3848/GHSA-mjcw-r3mg-3848.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mjcw-r3mg-3848", - "modified": "2024-11-27T18:34:03Z", + "modified": "2024-12-13T15:30:38Z", "published": "2024-11-26T15:31:02Z", "aliases": [ "CVE-2024-11694" @@ -42,6 +42,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-68" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-70" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-23hv-h2r7-ggj5/GHSA-23hv-h2r7-ggj5.json b/advisories/unreviewed/2024/12/GHSA-23hv-h2r7-ggj5/GHSA-23hv-h2r7-ggj5.json new file mode 100644 index 00000000000..a06447c8299 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-23hv-h2r7-ggj5/GHSA-23hv-h2r7-ggj5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23hv-h2r7-ggj5", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54266" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ImageRecycle ImageRecycle pdf & image compression allows Reflected XSS.This issue affects ImageRecycle pdf & image compression: from n/a through 3.1.16.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54266" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/imagerecycle-pdf-image-compression/vulnerability/wordpress-imagerecycle-pdf-image-compression-plugin-3-1-16-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-26vh-hjq5-fv9v/GHSA-26vh-hjq5-fv9v.json b/advisories/unreviewed/2024/12/GHSA-26vh-hjq5-fv9v/GHSA-26vh-hjq5-fv9v.json new file mode 100644 index 00000000000..ab4f5f818fc --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-26vh-hjq5-fv9v/GHSA-26vh-hjq5-fv9v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26vh-hjq5-fv9v", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-33324" + ], + "details": "Missing Authorization vulnerability in wppal Easy Captcha allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Captcha: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33324" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-captcha/vulnerability/wordpress-easy-captcha-plugin-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-294c-hx25-mgvq/GHSA-294c-hx25-mgvq.json b/advisories/unreviewed/2024/12/GHSA-294c-hx25-mgvq/GHSA-294c-hx25-mgvq.json new file mode 100644 index 00000000000..906bccfc41c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-294c-hx25-mgvq/GHSA-294c-hx25-mgvq.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-294c-hx25-mgvq", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2024-48007" + ], + "details": "Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability. A Remote unauthenticated attacker could potentially exploit this vulnerability by gaining access to the source code, easily retrieving these secrets and reusing them to access the system leading to gaining access to unauthorized data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48007" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000259765/dsa-2024-429-security-update-for-dell-recoverpoint-for-virtual-machines-multiple-third-party-component-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2fh3-rm73-hjxf/GHSA-2fh3-rm73-hjxf.json b/advisories/unreviewed/2024/12/GHSA-2fh3-rm73-hjxf/GHSA-2fh3-rm73-hjxf.json new file mode 100644 index 00000000000..907e99e8089 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2fh3-rm73-hjxf/GHSA-2fh3-rm73-hjxf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fh3-rm73-hjxf", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54314" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NicheAddons Primary Addon for Elementor allows Stored XSS.This issue affects Primary Addon for Elementor: from n/a through 1.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54314" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/primary-addon-for-elementor/vulnerability/wordpress-primary-addon-for-elementor-plugin-1-6-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2hf9-h2hv-2f9c/GHSA-2hf9-h2hv-2f9c.json b/advisories/unreviewed/2024/12/GHSA-2hf9-h2hv-2f9c/GHSA-2hf9-h2hv-2f9c.json new file mode 100644 index 00000000000..f2a0d0e0c95 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2hf9-h2hv-2f9c/GHSA-2hf9-h2hv-2f9c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hf9-h2hv-2f9c", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2022-46795" + ], + "details": "Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.7.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46795" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-delivery-notes/vulnerability/wordpress-print-invoice-delivery-notes-for-woocommerce-plugin-4-7-2-csrf-plugin-settings-reset-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2jpx-8fpp-54rx/GHSA-2jpx-8fpp-54rx.json b/advisories/unreviewed/2024/12/GHSA-2jpx-8fpp-54rx/GHSA-2jpx-8fpp-54rx.json new file mode 100644 index 00000000000..fe9888d4da1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2jpx-8fpp-54rx/GHSA-2jpx-8fpp-54rx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jpx-8fpp-54rx", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41849" + ], + "details": "Missing Authorization vulnerability in WP Happy Coders Posts Like Dislike allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Posts Like Dislike: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41849" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/posts-like-dislike/vulnerability/wordpress-posts-like-dislike-plugin-1-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2q85-m42h-7pqh/GHSA-2q85-m42h-7pqh.json b/advisories/unreviewed/2024/12/GHSA-2q85-m42h-7pqh/GHSA-2q85-m42h-7pqh.json new file mode 100644 index 00000000000..05103b5dbb9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2q85-m42h-7pqh/GHSA-2q85-m42h-7pqh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2q85-m42h-7pqh", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54278" + ], + "details": "Missing Authorization vulnerability in Plugin Devs News Ticker for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects News Ticker for Elementor: from n/a through 2.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54278" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/news-ticker-for-elementor/vulnerability/wordpress-news-ticker-for-elementor-plugin-2-1-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2v26-7fm5-rmj8/GHSA-2v26-7fm5-rmj8.json b/advisories/unreviewed/2024/12/GHSA-2v26-7fm5-rmj8/GHSA-2v26-7fm5-rmj8.json new file mode 100644 index 00000000000..8577e638c0f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2v26-7fm5-rmj8/GHSA-2v26-7fm5-rmj8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v26-7fm5-rmj8", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41848" + ], + "details": "Missing Authorization vulnerability in Majeed Raza Carousel Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Carousel Slider: from n/a through 2.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41848" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/carousel-slider/vulnerability/wordpress-carousel-slider-plugin-2-2-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-33wx-gh7x-xv44/GHSA-33wx-gh7x-xv44.json b/advisories/unreviewed/2024/12/GHSA-33wx-gh7x-xv44/GHSA-33wx-gh7x-xv44.json new file mode 100644 index 00000000000..51eb7d2aa08 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-33wx-gh7x-xv44/GHSA-33wx-gh7x-xv44.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33wx-gh7x-xv44", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41870" + ], + "details": "Missing Authorization vulnerability in Themeum WP Crowdfunding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Crowdfunding: from n/a through 2.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41870" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-crowdfunding/vulnerability/wordpress-wp-crowdfunding-plugin-2-1-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-363c-mcgp-pjjx/GHSA-363c-mcgp-pjjx.json b/advisories/unreviewed/2024/12/GHSA-363c-mcgp-pjjx/GHSA-363c-mcgp-pjjx.json new file mode 100644 index 00000000000..9161b15c013 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-363c-mcgp-pjjx/GHSA-363c-mcgp-pjjx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-363c-mcgp-pjjx", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-33998" + ], + "details": "Missing Authorization vulnerability in cybernetikz Easy Social Icons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Social Icons: from n/a through 3.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33998" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-social-icons/vulnerability/wordpress-easy-social-icons-plugin-3-2-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-36p9-3c3r-22pp/GHSA-36p9-3c3r-22pp.json b/advisories/unreviewed/2024/12/GHSA-36p9-3c3r-22pp/GHSA-36p9-3c3r-22pp.json new file mode 100644 index 00000000000..f98c9a6dd42 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-36p9-3c3r-22pp/GHSA-36p9-3c3r-22pp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36p9-3c3r-22pp", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-34381" + ], + "details": "Missing Authorization vulnerability in Gesundheit Bewegt GmbH Zippy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zippy: from n/a through 1.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34381" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/zippy/vulnerability/wordpress-zippy-plugin-1-6-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-36xf-458c-932h/GHSA-36xf-458c-932h.json b/advisories/unreviewed/2024/12/GHSA-36xf-458c-932h/GHSA-36xf-458c-932h.json new file mode 100644 index 00000000000..acdc4499723 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-36xf-458c-932h/GHSA-36xf-458c-932h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36xf-458c-932h", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2022-45840" + ], + "details": "Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Affiliate Links: from n/a through 6.2.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45840" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-auto-affiliate-links/vulnerability/wordpress-auto-affiliate-links-plugin-6-2-1-5-unauth-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-37gx-37xg-963j/GHSA-37gx-37xg-963j.json b/advisories/unreviewed/2024/12/GHSA-37gx-37xg-963j/GHSA-37gx-37xg-963j.json new file mode 100644 index 00000000000..01136d0ea73 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-37gx-37xg-963j/GHSA-37gx-37xg-963j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37gx-37xg-963j", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54261" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HK Digital Agency LLC TAX SERVICE Electronic HDM allows SQL Injection.This issue affects TAX SERVICE Electronic HDM: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54261" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/virtual-hdm-for-taxservice-am/vulnerability/wordpress-tax-service-electronic-hdm-plugin-1-1-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-38q4-6g9v-f3wc/GHSA-38q4-6g9v-f3wc.json b/advisories/unreviewed/2024/12/GHSA-38q4-6g9v-f3wc/GHSA-38q4-6g9v-f3wc.json new file mode 100644 index 00000000000..2661725e43d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-38q4-6g9v-f3wc/GHSA-38q4-6g9v-f3wc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38q4-6g9v-f3wc", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54239" + ], + "details": "Missing Authorization vulnerability in dugudlabs Eyewear prescription form allows Privilege Escalation.This issue affects Eyewear prescription form: from n/a through 4.0.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54239" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/eyewear-prescription-form/vulnerability/wordpress-eyewear-prescription-form-plugin-4-0-18-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3crp-m98r-rm3q/GHSA-3crp-m98r-rm3q.json b/advisories/unreviewed/2024/12/GHSA-3crp-m98r-rm3q/GHSA-3crp-m98r-rm3q.json new file mode 100644 index 00000000000..dc0d3bb7d27 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3crp-m98r-rm3q/GHSA-3crp-m98r-rm3q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3crp-m98r-rm3q", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-35777" + ], + "details": "Missing Authorization vulnerability in The Events Calendar The Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through 6.1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35777" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/the-events-calendar/vulnerability/wordpress-the-events-calendar-plugin-6-1-2-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3hqm-9m87-w2r2/GHSA-3hqm-9m87-w2r2.json b/advisories/unreviewed/2024/12/GHSA-3hqm-9m87-w2r2/GHSA-3hqm-9m87-w2r2.json new file mode 100644 index 00000000000..e896d4a8a9b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3hqm-9m87-w2r2/GHSA-3hqm-9m87-w2r2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hqm-9m87-w2r2", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-44147" + ], + "details": "Missing Authorization vulnerability in Apasionados Comment Blacklist Updater allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comment Blacklist Updater: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44147" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/comment-blacklist-updater/vulnerability/wordpress-comment-blacklist-updater-plugin-1-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3m8w-2mvj-9q7j/GHSA-3m8w-2mvj-9q7j.json b/advisories/unreviewed/2024/12/GHSA-3m8w-2mvj-9q7j/GHSA-3m8w-2mvj-9q7j.json new file mode 100644 index 00000000000..906a4676744 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3m8w-2mvj-9q7j/GHSA-3m8w-2mvj-9q7j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3m8w-2mvj-9q7j", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-32519" + ], + "details": "Missing Authorization vulnerability in Webcodin WCP Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCP Contact Form: from n/a through 3.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32519" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wcp-contact-form/vulnerability/wordpress-wcp-contact-form-plugin-3-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3mp2-rhvg-j63c/GHSA-3mp2-rhvg-j63c.json b/advisories/unreviewed/2024/12/GHSA-3mp2-rhvg-j63c/GHSA-3mp2-rhvg-j63c.json new file mode 100644 index 00000000000..0f42e9cadec --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3mp2-rhvg-j63c/GHSA-3mp2-rhvg-j63c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mp2-rhvg-j63c", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2024-48008" + ], + "details": "Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability. An Low privileged remote attacker could potentially exploit this vulnerability leading to information disclosure ,allowing of unintended actions like reading files that may contain sensitive information", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48008" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000259765/dsa-2024-429-security-update-for-dell-recoverpoint-for-virtual-machines-multiple-third-party-component-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-11" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3p5p-c5mc-jqg3/GHSA-3p5p-c5mc-jqg3.json b/advisories/unreviewed/2024/12/GHSA-3p5p-c5mc-jqg3/GHSA-3p5p-c5mc-jqg3.json new file mode 100644 index 00000000000..6727db999d4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3p5p-c5mc-jqg3/GHSA-3p5p-c5mc-jqg3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p5p-c5mc-jqg3", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2022-46807" + ], + "details": "Missing Authorization vulnerability in Lauri Karisola / WP Trio Stock Sync for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Sync for WooCommerce: from n/a through 2.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46807" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/stock-sync-for-woocommerce/vulnerability/wordpress-stock-sync-for-woocommerce-plugin-2-3-2-broken-access-control-csrf?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3v7v-w4cq-gmpp/GHSA-3v7v-w4cq-gmpp.json b/advisories/unreviewed/2024/12/GHSA-3v7v-w4cq-gmpp/GHSA-3v7v-w4cq-gmpp.json new file mode 100644 index 00000000000..d2cb5110695 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3v7v-w4cq-gmpp/GHSA-3v7v-w4cq-gmpp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3v7v-w4cq-gmpp", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-22697" + ], + "details": "Missing Authorization vulnerability in Survey Maker team Survey Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Survey Maker: from n/a through 3.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22697" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/survey-maker/vulnerability/wordpress-survey-maker-plugin-3-2-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3w2v-f8x7-qc92/GHSA-3w2v-f8x7-qc92.json b/advisories/unreviewed/2024/12/GHSA-3w2v-f8x7-qc92/GHSA-3w2v-f8x7-qc92.json new file mode 100644 index 00000000000..0031cb75668 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3w2v-f8x7-qc92/GHSA-3w2v-f8x7-qc92.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w2v-f8x7-qc92", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41951" + ], + "details": "Missing Authorization vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through 4.6.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41951" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/buddypress-media/vulnerability/wordpress-rtmedia-for-wordpress-buddypress-and-bbpress-plugin-4-6-14-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3w53-58xm-8pwx/GHSA-3w53-58xm-8pwx.json b/advisories/unreviewed/2024/12/GHSA-3w53-58xm-8pwx/GHSA-3w53-58xm-8pwx.json new file mode 100644 index 00000000000..3026e4500e0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3w53-58xm-8pwx/GHSA-3w53-58xm-8pwx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w53-58xm-8pwx", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2022-44578" + ], + "details": "Missing Authorization vulnerability in Pierre JEHAN Owl Carousel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Owl Carousel: from n/a through 0.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44578" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/owl-carousel/vulnerability/wordpress-owl-carousel-plugin-0-5-3-broken-access-control-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3xc8-796c-9xf5/GHSA-3xc8-796c-9xf5.json b/advisories/unreviewed/2024/12/GHSA-3xc8-796c-9xf5/GHSA-3xc8-796c-9xf5.json new file mode 100644 index 00000000000..3aacf0d07d6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3xc8-796c-9xf5/GHSA-3xc8-796c-9xf5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xc8-796c-9xf5", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2022-47176" + ], + "details": "Missing Authorization vulnerability in Depicter Slider and Popup by Averta Depicter Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Depicter Slider: from n/a through 1.9.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47176" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/depicter/vulnerability/wordpress-depicter-slider-plugin-1-7-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-455h-7777-fx44/GHSA-455h-7777-fx44.json b/advisories/unreviewed/2024/12/GHSA-455h-7777-fx44/GHSA-455h-7777-fx44.json new file mode 100644 index 00000000000..7820fd9b7bd --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-455h-7777-fx44/GHSA-455h-7777-fx44.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-455h-7777-fx44", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-36526" + ], + "details": "Missing Authorization vulnerability in Inqsys Technology Duplicate Post Page Menu & Custom Post Type allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Duplicate Post Page Menu & Custom Post Type: from n/a through 2.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36526" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/duplicate-post-page-menu-custom-post-type/vulnerability/wordpress-duplicate-post-page-menu-custom-post-type-plugin-2-3-1-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-476h-737f-mc4w/GHSA-476h-737f-mc4w.json b/advisories/unreviewed/2024/12/GHSA-476h-737f-mc4w/GHSA-476h-737f-mc4w.json new file mode 100644 index 00000000000..0db2bd59a30 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-476h-737f-mc4w/GHSA-476h-737f-mc4w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-476h-737f-mc4w", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-40203" + ], + "details": "Missing Authorization vulnerability in MailMunch MailChimp Forms by MailMunch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MailChimp Forms by MailMunch: from n/a through 3.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40203" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mailchimp-forms-by-mailmunch/vulnerability/wordpress-mailchimp-forms-by-mailmunch-plugin-3-1-4-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-47v4-7vc9-jjhx/GHSA-47v4-7vc9-jjhx.json b/advisories/unreviewed/2024/12/GHSA-47v4-7vc9-jjhx/GHSA-47v4-7vc9-jjhx.json new file mode 100644 index 00000000000..c1d062b66ca --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-47v4-7vc9-jjhx/GHSA-47v4-7vc9-jjhx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47v4-7vc9-jjhx", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54303" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ido Kobelkowsky / yalla ya! Simple Payment allows Reflected XSS.This issue affects Simple Payment: from n/a through 2.3.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54303" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-payment/vulnerability/wordpress-simple-payment-plugin-2-3-7-refleceted-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-485q-m5hh-2rqx/GHSA-485q-m5hh-2rqx.json b/advisories/unreviewed/2024/12/GHSA-485q-m5hh-2rqx/GHSA-485q-m5hh-2rqx.json new file mode 100644 index 00000000000..5c79497d0cf --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-485q-m5hh-2rqx/GHSA-485q-m5hh-2rqx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-485q-m5hh-2rqx", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-40005" + ], + "details": "Missing Authorization vulnerability in Easy Digital Downloads Easy Digital Downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through 3.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40005" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-digital-downloads/vulnerability/wordpress-easy-digital-downloads-plugin-3-1-5-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4863-57r9-m6xc/GHSA-4863-57r9-m6xc.json b/advisories/unreviewed/2024/12/GHSA-4863-57r9-m6xc/GHSA-4863-57r9-m6xc.json new file mode 100644 index 00000000000..dc943058c84 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4863-57r9-m6xc/GHSA-4863-57r9-m6xc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4863-57r9-m6xc", + "modified": "2024-12-13T15:30:45Z", + "published": "2024-12-13T15:30:45Z", + "aliases": [ + "CVE-2024-54343" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Howard Ehrenberg Connect Contact Form 7 to Constant Contact allows Reflected XSS.This issue affects Connect Contact Form 7 to Constant Contact: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54343" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/connect-contact-form-7-to-constant-contact-v3/vulnerability/wordpress-connect-contact-form-7-to-constant-contact-plugin-1-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4ffq-5gpq-hvrg/GHSA-4ffq-5gpq-hvrg.json b/advisories/unreviewed/2024/12/GHSA-4ffq-5gpq-hvrg/GHSA-4ffq-5gpq-hvrg.json new file mode 100644 index 00000000000..4f82c973561 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4ffq-5gpq-hvrg/GHSA-4ffq-5gpq-hvrg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4ffq-5gpq-hvrg", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54295" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in InspireUI ListApp Mobile Manager allows Authentication Bypass.This issue affects ListApp Mobile Manager: from n/a through 1.7.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54295" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/listapp-mobile-manager/vulnerability/wordpress-listapp-mobile-manager-plugin-1-7-7-account-takeover-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4g8h-jqj8-hf34/GHSA-4g8h-jqj8-hf34.json b/advisories/unreviewed/2024/12/GHSA-4g8h-jqj8-hf34/GHSA-4g8h-jqj8-hf34.json new file mode 100644 index 00000000000..f8502ed3967 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4g8h-jqj8-hf34/GHSA-4g8h-jqj8-hf34.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g8h-jqj8-hf34", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2024-38488" + ], + "details": "Dell RecoverPoint for Virtual Machines 6.0.x contains a vulnerability. An improper Restriction of Excessive Authentication vulnerability where a Network attacker could potentially exploit this vulnerability, leading to a brute force attack or a dictionary attack against the RecoverPoint login form and a complete system compromise.\nThis allows attackers to brute-force the password of valid users in an automated manner.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38488" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000259765/dsa-2024-429-security-update-for-dell-recoverpoint-for-virtual-machines-multiple-third-party-component-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4m49-wchq-72x6/GHSA-4m49-wchq-72x6.json b/advisories/unreviewed/2024/12/GHSA-4m49-wchq-72x6/GHSA-4m49-wchq-72x6.json new file mode 100644 index 00000000000..a7d78d21c53 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4m49-wchq-72x6/GHSA-4m49-wchq-72x6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m49-wchq-72x6", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54250" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prodigy Commerce Prodigy Commerce allows DOM-Based XSS.This issue affects Prodigy Commerce: from n/a through 3.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54250" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/prodigy-commerce/vulnerability/wordpress-prodigy-commerce-plugin-3-0-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4qg3-w6pq-6h3p/GHSA-4qg3-w6pq-6h3p.json b/advisories/unreviewed/2024/12/GHSA-4qg3-w6pq-6h3p/GHSA-4qg3-w6pq-6h3p.json new file mode 100644 index 00000000000..a4a67e439d3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4qg3-w6pq-6h3p/GHSA-4qg3-w6pq-6h3p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qg3-w6pq-6h3p", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-35051" + ], + "details": "Missing Authorization vulnerability in Cimatti Consulting Contact Forms by Cimatti allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Forms by Cimatti: from n/a through 1.5.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35051" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/contact-forms/vulnerability/wordpress-contact-forms-by-cimatti-plugin-1-5-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4qw4-2fxp-97xp/GHSA-4qw4-2fxp-97xp.json b/advisories/unreviewed/2024/12/GHSA-4qw4-2fxp-97xp/GHSA-4qw4-2fxp-97xp.json new file mode 100644 index 00000000000..370baa702ea --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4qw4-2fxp-97xp/GHSA-4qw4-2fxp-97xp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qw4-2fxp-97xp", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54320" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ICDSoft Hosting ICDSoft Reseller Store allows Reflected XSS.This issue affects ICDSoft Reseller Store: from n/a through 2.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54320" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/icdsoft-reseller-store/vulnerability/wordpress-icdsoft-reseller-store-plugin-2-4-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-556m-mw5q-xwrr/GHSA-556m-mw5q-xwrr.json b/advisories/unreviewed/2024/12/GHSA-556m-mw5q-xwrr/GHSA-556m-mw5q-xwrr.json new file mode 100644 index 00000000000..6a5efc6e4ec --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-556m-mw5q-xwrr/GHSA-556m-mw5q-xwrr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-556m-mw5q-xwrr", + "modified": "2024-12-13T15:30:45Z", + "published": "2024-12-13T15:30:45Z", + "aliases": [ + "CVE-2024-54340" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sylvia van Os Simple Presenter allows Reflected XSS.This issue affects Simple Presenter: from n/a through 1.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54340" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-presenter/vulnerability/wordpress-simple-presenter-plugin-1-5-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-579m-qp7f-jr3r/GHSA-579m-qp7f-jr3r.json b/advisories/unreviewed/2024/12/GHSA-579m-qp7f-jr3r/GHSA-579m-qp7f-jr3r.json new file mode 100644 index 00000000000..99e6d1239e7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-579m-qp7f-jr3r/GHSA-579m-qp7f-jr3r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-579m-qp7f-jr3r", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-37971" + ], + "details": "Missing Authorization vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Product Stock Alert: from n/a through 2.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37971" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-product-stock-alert/vulnerability/wordpress-woocommerce-product-stock-alert-plugin-2-0-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-57jf-hj8w-7hr5/GHSA-57jf-hj8w-7hr5.json b/advisories/unreviewed/2024/12/GHSA-57jf-hj8w-7hr5/GHSA-57jf-hj8w-7hr5.json new file mode 100644 index 00000000000..4d07b6e3406 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-57jf-hj8w-7hr5/GHSA-57jf-hj8w-7hr5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57jf-hj8w-7hr5", + "modified": "2024-12-13T15:30:45Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54328" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Nacional Invoice Payment for WooCommerce allows Reflected XSS.This issue affects Invoice Payment for WooCommerce: from n/a through 1.7.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54328" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/invoice-payment-for-woocommerce/vulnerability/wordpress-invoice-payment-for-woocommerce-plugin-1-7-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-58mm-jjg7-f87h/GHSA-58mm-jjg7-f87h.json b/advisories/unreviewed/2024/12/GHSA-58mm-jjg7-f87h/GHSA-58mm-jjg7-f87h.json new file mode 100644 index 00000000000..48b1f314638 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-58mm-jjg7-f87h/GHSA-58mm-jjg7-f87h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58mm-jjg7-f87h", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-36528" + ], + "details": "Missing Authorization vulnerability in FeedbackWP kk Star Ratings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects kk Star Ratings: from n/a through 5.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36528" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/kk-star-ratings/vulnerability/wordpress-kk-star-ratings-plugin-5-4-3-rate-manipulation-due-to-ip-spoofing-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-594m-pfh4-vc82/GHSA-594m-pfh4-vc82.json b/advisories/unreviewed/2024/12/GHSA-594m-pfh4-vc82/GHSA-594m-pfh4-vc82.json new file mode 100644 index 00000000000..a6503bb3170 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-594m-pfh4-vc82/GHSA-594m-pfh4-vc82.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-594m-pfh4-vc82", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54240" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blaze Online Blaze Online eParcel for WooCommerce allows Reflected XSS.This issue affects Blaze Online eParcel for WooCommerce: from n/a through 1.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54240" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/blaze-online-eparcel-for-woocommerce/vulnerability/wordpress-blaze-online-eparcel-for-woocommerce-plugin-1-3-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-59j7-m658-8wh4/GHSA-59j7-m658-8wh4.json b/advisories/unreviewed/2024/12/GHSA-59j7-m658-8wh4/GHSA-59j7-m658-8wh4.json new file mode 100644 index 00000000000..01afd4a3c7b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-59j7-m658-8wh4/GHSA-59j7-m658-8wh4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59j7-m658-8wh4", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54244" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 Easy Replace allows Stored XSS.This issue affects Easy Replace: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54244" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-replace/vulnerability/wordpress-easy-replace-plugin-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5cpj-xvxp-wvgm/GHSA-5cpj-xvxp-wvgm.json b/advisories/unreviewed/2024/12/GHSA-5cpj-xvxp-wvgm/GHSA-5cpj-xvxp-wvgm.json new file mode 100644 index 00000000000..2fd92d45d5a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5cpj-xvxp-wvgm/GHSA-5cpj-xvxp-wvgm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cpj-xvxp-wvgm", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2022-45841" + ], + "details": "Missing Authorization vulnerability in RoboSoft Robo Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Robo Gallery: from n/a through 3.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45841" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/robo-gallery/vulnerability/wordpress-robo-gallery-plugin-3-2-9-auth-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5g3w-xq8v-pfw5/GHSA-5g3w-xq8v-pfw5.json b/advisories/unreviewed/2024/12/GHSA-5g3w-xq8v-pfw5/GHSA-5g3w-xq8v-pfw5.json new file mode 100644 index 00000000000..9ecbe603cb9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5g3w-xq8v-pfw5/GHSA-5g3w-xq8v-pfw5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g3w-xq8v-pfw5", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54321" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Hive Support Hive Support – WordPress Help Desk allows Cross Site Request Forgery.This issue affects Hive Support – WordPress Help Desk: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54321" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hive-support/vulnerability/wordpress-hive-support-plugin-1-1-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5g4q-5r23-wrrp/GHSA-5g4q-5r23-wrrp.json b/advisories/unreviewed/2024/12/GHSA-5g4q-5r23-wrrp/GHSA-5g4q-5r23-wrrp.json new file mode 100644 index 00000000000..757fc34d928 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5g4q-5r23-wrrp/GHSA-5g4q-5r23-wrrp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g4q-5r23-wrrp", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-32520" + ], + "details": "Missing Authorization vulnerability in Webcodin WCP Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCP Contact Form: from n/a through 3.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32520" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wcp-contact-form/vulnerability/wordpress-wcp-contact-form-plugin-3-1-0-broken-access-control-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5gv9-5mf3-9rpm/GHSA-5gv9-5mf3-9rpm.json b/advisories/unreviewed/2024/12/GHSA-5gv9-5mf3-9rpm/GHSA-5gv9-5mf3-9rpm.json new file mode 100644 index 00000000000..b764a128fb1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5gv9-5mf3-9rpm/GHSA-5gv9-5mf3-9rpm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gv9-5mf3-9rpm", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54246" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 FAQs allows Stored XSS.This issue affects FAQs: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54246" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/faqs/vulnerability/wordpress-faqs-plugin-1-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5hgq-g4w5-rwmf/GHSA-5hgq-g4w5-rwmf.json b/advisories/unreviewed/2024/12/GHSA-5hgq-g4w5-rwmf/GHSA-5hgq-g4w5-rwmf.json new file mode 100644 index 00000000000..ec258b83903 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5hgq-g4w5-rwmf/GHSA-5hgq-g4w5-rwmf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hgq-g4w5-rwmf", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-39920" + ], + "details": "Missing Authorization vulnerability in Themeisle Redirection for Contact Form 7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Redirection for Contact Form 7: from n/a through 2.9.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39920" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpcf7-redirect/vulnerability/wordpress-redirection-for-contact-form-7-plugin-2-9-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5px8-j6f2-cwm9/GHSA-5px8-j6f2-cwm9.json b/advisories/unreviewed/2024/12/GHSA-5px8-j6f2-cwm9/GHSA-5px8-j6f2-cwm9.json new file mode 100644 index 00000000000..2ba4604f535 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5px8-j6f2-cwm9/GHSA-5px8-j6f2-cwm9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5px8-j6f2-cwm9", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41873" + ], + "details": "Missing Authorization vulnerability in miniOrange SAML SP Single Sign On allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SAML SP Single Sign On: from n/a through 5.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41873" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/miniorange-saml-20-single-sign-on/vulnerability/wordpress-saml-single-sign-on-sso-login-plugin-5-0-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5x2h-v2cr-43q8/GHSA-5x2h-v2cr-43q8.json b/advisories/unreviewed/2024/12/GHSA-5x2h-v2cr-43q8/GHSA-5x2h-v2cr-43q8.json new file mode 100644 index 00000000000..43037290db4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5x2h-v2cr-43q8/GHSA-5x2h-v2cr-43q8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5x2h-v2cr-43q8", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41857" + ], + "details": "Missing Authorization vulnerability in ClickToTweet.com Click To Tweet allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Click To Tweet: from n/a through 2.0.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41857" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/click-to-tweet/vulnerability/wordpress-click-to-tweet-plugin-2-0-14-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-64w3-pw9g-6jc3/GHSA-64w3-pw9g-6jc3.json b/advisories/unreviewed/2024/12/GHSA-64w3-pw9g-6jc3/GHSA-64w3-pw9g-6jc3.json new file mode 100644 index 00000000000..fc8e5fb3803 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-64w3-pw9g-6jc3/GHSA-64w3-pw9g-6jc3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64w3-pw9g-6jc3", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41802" + ], + "details": "Missing Authorization vulnerability in Team Heateor Super Socializer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Socializer: from n/a through 7.13.54.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41802" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/super-socializer/vulnerability/wordpress-super-socializer-plugin-7-13-54-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-678p-f9v3-rq46/GHSA-678p-f9v3-rq46.json b/advisories/unreviewed/2024/12/GHSA-678p-f9v3-rq46/GHSA-678p-f9v3-rq46.json new file mode 100644 index 00000000000..c8ffabdc695 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-678p-f9v3-rq46/GHSA-678p-f9v3-rq46.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-678p-f9v3-rq46", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54299" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Revi Revi.io allows Reflected XSS.This issue affects Revi.io: from n/a through 5.7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54299" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/revi-io-customer-and-product-reviews/vulnerability/wordpress-revi-io-plugin-5-7-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-67g4-5m8x-cjpr/GHSA-67g4-5m8x-cjpr.json b/advisories/unreviewed/2024/12/GHSA-67g4-5m8x-cjpr/GHSA-67g4-5m8x-cjpr.json new file mode 100644 index 00000000000..241b1278554 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-67g4-5m8x-cjpr/GHSA-67g4-5m8x-cjpr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67g4-5m8x-cjpr", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54287" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Best Wp Developer Advanced Blog Post Block allows Stored XSS.This issue affects Advanced Blog Post Block: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54287" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-blog-post-block/vulnerability/wordpress-advanced-blog-post-block-plugin-1-0-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-67wr-qmv5-xmr6/GHSA-67wr-qmv5-xmr6.json b/advisories/unreviewed/2024/12/GHSA-67wr-qmv5-xmr6/GHSA-67wr-qmv5-xmr6.json new file mode 100644 index 00000000000..2bcf1e7d993 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-67wr-qmv5-xmr6/GHSA-67wr-qmv5-xmr6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67wr-qmv5-xmr6", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-33995" + ], + "details": "Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo Gallery by 10Web: from n/a through 1.8.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33995" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/photo-gallery/vulnerability/wordpress-photo-gallery-by-10web-plugin-1-8-15-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-685g-7w4h-726p/GHSA-685g-7w4h-726p.json b/advisories/unreviewed/2024/12/GHSA-685g-7w4h-726p/GHSA-685g-7w4h-726p.json new file mode 100644 index 00000000000..77180d2948b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-685g-7w4h-726p/GHSA-685g-7w4h-726p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-685g-7w4h-726p", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41130" + ], + "details": "Missing Authorization vulnerability in Premmerce Premmerce User Roles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Premmerce User Roles: from n/a through 1.0.12.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41130" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/premmerce-user-roles/vulnerability/wordpress-premmerce-user-roles-plugin-1-0-12-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-689c-7x7v-4xm7/GHSA-689c-7x7v-4xm7.json b/advisories/unreviewed/2024/12/GHSA-689c-7x7v-4xm7/GHSA-689c-7x7v-4xm7.json new file mode 100644 index 00000000000..d91f6d11ce2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-689c-7x7v-4xm7/GHSA-689c-7x7v-4xm7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-689c-7x7v-4xm7", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41875" + ], + "details": "Missing Authorization vulnerability in wpdirectorykit.com WP Directory Kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Directory Kit: from n/a through 1.2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41875" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpdirectorykit/vulnerability/wordpress-wp-directory-kit-plugin-1-2-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-69r7-7qx9-rhm7/GHSA-69r7-7qx9-rhm7.json b/advisories/unreviewed/2024/12/GHSA-69r7-7qx9-rhm7/GHSA-69r7-7qx9-rhm7.json new file mode 100644 index 00000000000..4c6a12e1336 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-69r7-7qx9-rhm7/GHSA-69r7-7qx9-rhm7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69r7-7qx9-rhm7", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41862" + ], + "details": "Weak Authentication vulnerability in Guido VS Contact Form allows Authentication Abuse.This issue affects VS Contact Form: from n/a through 14.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41862" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/very-simple-contact-form/vulnerability/wordpress-vs-contact-form-plugin-13-9-sum-captcha-bypass-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1390" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6cmq-jm4v-8r35/GHSA-6cmq-jm4v-8r35.json b/advisories/unreviewed/2024/12/GHSA-6cmq-jm4v-8r35/GHSA-6cmq-jm4v-8r35.json index 535913b6a90..4cd095e77f7 100644 --- a/advisories/unreviewed/2024/12/GHSA-6cmq-jm4v-8r35/GHSA-6cmq-jm4v-8r35.json +++ b/advisories/unreviewed/2024/12/GHSA-6cmq-jm4v-8r35/GHSA-6cmq-jm4v-8r35.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6cmq-jm4v-8r35", - "modified": "2024-12-03T18:31:03Z", + "modified": "2024-12-13T15:30:38Z", "published": "2024-12-03T18:31:03Z", "aliases": [ "CVE-2024-29404" ], "details": "An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary code via the export parameter of the Chroma Effects function in the Profiles component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-03T17:15:10Z" diff --git a/advisories/unreviewed/2024/12/GHSA-6g2r-jrch-rf7x/GHSA-6g2r-jrch-rf7x.json b/advisories/unreviewed/2024/12/GHSA-6g2r-jrch-rf7x/GHSA-6g2r-jrch-rf7x.json new file mode 100644 index 00000000000..7b36e865c2b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6g2r-jrch-rf7x/GHSA-6g2r-jrch-rf7x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6g2r-jrch-rf7x", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54242" + ], + "details": "Missing Authorization vulnerability in Appsbd Simple Notification allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Notification: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54242" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-notification/vulnerability/wordpress-simple-notification-plugin-1-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6h66-rxfg-jpg5/GHSA-6h66-rxfg-jpg5.json b/advisories/unreviewed/2024/12/GHSA-6h66-rxfg-jpg5/GHSA-6h66-rxfg-jpg5.json new file mode 100644 index 00000000000..dcf65827706 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6h66-rxfg-jpg5/GHSA-6h66-rxfg-jpg5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6h66-rxfg-jpg5", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-36680" + ], + "details": "Missing Authorization vulnerability in Iulia Cazan Image Regenerate & Select Crop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Regenerate & Select Crop: from n/a through 7.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36680" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/image-regenerate-select-crop/vulnerability/wordpress-image-regenerate-select-crop-plugin-7-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6h8p-5x85-6w38/GHSA-6h8p-5x85-6w38.json b/advisories/unreviewed/2024/12/GHSA-6h8p-5x85-6w38/GHSA-6h8p-5x85-6w38.json new file mode 100644 index 00000000000..fa5baa66961 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6h8p-5x85-6w38/GHSA-6h8p-5x85-6w38.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6h8p-5x85-6w38", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2022-45819" + ], + "details": "Missing Authorization vulnerability in Popup Maker Popup Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Maker: from n/a through 1.17.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45819" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/popup-maker/vulnerability/wordpress-popup-maker-plugin-1-17-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6j5j-2637-v7cg/GHSA-6j5j-2637-v7cg.json b/advisories/unreviewed/2024/12/GHSA-6j5j-2637-v7cg/GHSA-6j5j-2637-v7cg.json new file mode 100644 index 00000000000..70eb8ee51c9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6j5j-2637-v7cg/GHSA-6j5j-2637-v7cg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j5j-2637-v7cg", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-24902" + ], + "details": "Dell RecoverPoint for Virtual Machines 6.0.x contains an Improper access control vulnerability. A low privileged local attacker could potentially exploit this vulnerability leading to gaining access to unauthorized data for a limited time.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24902" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000259765/dsa-2024-429-security-update-for-dell-recoverpoint-for-virtual-machines-multiple-third-party-component-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6mfj-55gm-gqv7/GHSA-6mfj-55gm-gqv7.json b/advisories/unreviewed/2024/12/GHSA-6mfj-55gm-gqv7/GHSA-6mfj-55gm-gqv7.json new file mode 100644 index 00000000000..d7db9484d1f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6mfj-55gm-gqv7/GHSA-6mfj-55gm-gqv7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mfj-55gm-gqv7", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54315" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NicheAddons Events Addon for Elementor allows DOM-Based XSS.This issue affects Events Addon for Elementor: from n/a through 2.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54315" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/events-addon-for-elementor/vulnerability/wordpress-events-addon-for-elementor-plugin-2-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6pwh-fj58-f6hj/GHSA-6pwh-fj58-f6hj.json b/advisories/unreviewed/2024/12/GHSA-6pwh-fj58-f6hj/GHSA-6pwh-fj58-f6hj.json new file mode 100644 index 00000000000..8a954882ef7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6pwh-fj58-f6hj/GHSA-6pwh-fj58-f6hj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pwh-fj58-f6hj", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54264" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in César Morillas Shortcodes Blocks Creator Ultimate allows Reflected XSS.This issue affects Shortcodes Blocks Creator Ultimate: from n/a through 2.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54264" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-shortcodes-creator/vulnerability/wordpress-shortcodes-blocks-creator-ultimate-plugin-2-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6rjq-282f-p3mr/GHSA-6rjq-282f-p3mr.json b/advisories/unreviewed/2024/12/GHSA-6rjq-282f-p3mr/GHSA-6rjq-282f-p3mr.json new file mode 100644 index 00000000000..22869a7ee26 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6rjq-282f-p3mr/GHSA-6rjq-282f-p3mr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rjq-282f-p3mr", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-35037" + ], + "details": "Missing Authorization vulnerability in Surfer Surfer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Surfer: from n/a through 1.3.2.357.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35037" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/surferseo/vulnerability/wordpress-surfer-plugin-1-1-2-298-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-6v4c-8jrj-xwqj/GHSA-6v4c-8jrj-xwqj.json b/advisories/unreviewed/2024/12/GHSA-6v4c-8jrj-xwqj/GHSA-6v4c-8jrj-xwqj.json new file mode 100644 index 00000000000..7caf11ef168 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6v4c-8jrj-xwqj/GHSA-6v4c-8jrj-xwqj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v4c-8jrj-xwqj", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-36681" + ], + "details": "Missing Authorization vulnerability in Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Widgets – Price Ticker & Coins List: from n/a through 2.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36681" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cryptocurrency-price-ticker-widget/vulnerability/wordpress-cryptocurrency-widgets-price-ticker-coins-list-plugin-2-6-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-756v-rcmm-vwxh/GHSA-756v-rcmm-vwxh.json b/advisories/unreviewed/2024/12/GHSA-756v-rcmm-vwxh/GHSA-756v-rcmm-vwxh.json new file mode 100644 index 00000000000..f8b430d45eb --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-756v-rcmm-vwxh/GHSA-756v-rcmm-vwxh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-756v-rcmm-vwxh", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-38385" + ], + "details": "Missing Authorization vulnerability in Artbees JupiterX Core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JupiterX Core: from 3.0.0 through 3.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38385" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jupiterx-core/vulnerability/wordpress-jupiter-x-core-plugin-3-0-0-3-3-0-multiple-contributor-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-75c8-99jx-256c/GHSA-75c8-99jx-256c.json b/advisories/unreviewed/2024/12/GHSA-75c8-99jx-256c/GHSA-75c8-99jx-256c.json new file mode 100644 index 00000000000..1444cfea2c7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-75c8-99jx-256c/GHSA-75c8-99jx-256c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75c8-99jx-256c", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54252" + ], + "details": "Missing Authorization vulnerability in PINPOINT.WORLD Pinpoint Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pinpoint Booking System: from n/a through 2.9.9.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54252" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/booking-system/vulnerability/wordpress-pinpoint-booking-system-plugin-2-9-9-5-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7cxh-6qmq-5722/GHSA-7cxh-6qmq-5722.json b/advisories/unreviewed/2024/12/GHSA-7cxh-6qmq-5722/GHSA-7cxh-6qmq-5722.json new file mode 100644 index 00000000000..8bd01b99105 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7cxh-6qmq-5722/GHSA-7cxh-6qmq-5722.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cxh-6qmq-5722", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54319" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MultiNet Interactive AB Kundgenerator allows Reflected XSS.This issue affects Kundgenerator: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54319" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/kundgenerator/vulnerability/wordpress-kundgenerator-plugin-1-0-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7f3j-54j2-wrv7/GHSA-7f3j-54j2-wrv7.json b/advisories/unreviewed/2024/12/GHSA-7f3j-54j2-wrv7/GHSA-7f3j-54j2-wrv7.json new file mode 100644 index 00000000000..74f5852e0f0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7f3j-54j2-wrv7/GHSA-7f3j-54j2-wrv7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f3j-54j2-wrv7", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-38477" + ], + "details": "Missing Authorization vulnerability in Stanislav Kuznetsov QR code MeCard/vCard generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects QR code MeCard/vCard generator: from n/a through 1.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38477" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-qrcode-me-v-card/vulnerability/wordpress-qr-code-mecard-vcard-generator-plugin-1-5-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7hgq-c3gv-933p/GHSA-7hgq-c3gv-933p.json b/advisories/unreviewed/2024/12/GHSA-7hgq-c3gv-933p/GHSA-7hgq-c3gv-933p.json new file mode 100644 index 00000000000..95a62bb2cd0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7hgq-c3gv-933p/GHSA-7hgq-c3gv-933p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hgq-c3gv-933p", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2024-11986" + ], + "details": "Improper input handling in the 'Host Header' allows an unauthenticated attacker to store a payload in web application logs. When an Administrator views the logs using the application's standard functionality, it enables the execution of the payload, resulting in Stored XSS or 'Cross-Site Scripting'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11986" + }, + { + "type": "WEB", + "url": "https://crushftp.com/crush11wiki/Wiki.jsp?page=Update" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7hhc-h873-cfwj/GHSA-7hhc-h873-cfwj.json b/advisories/unreviewed/2024/12/GHSA-7hhc-h873-cfwj/GHSA-7hhc-h873-cfwj.json new file mode 100644 index 00000000000..1ded727b87e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7hhc-h873-cfwj/GHSA-7hhc-h873-cfwj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hhc-h873-cfwj", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54235" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shiptimize Shiptimize for WooCommerce allows Reflected XSS.This issue affects Shiptimize for WooCommerce: from n/a through 3.1.86.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54235" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/shiptimize-for-woocommerce/vulnerability/wordpress-shiptimize-for-woocommerce-plugin-3-1-86-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7pvp-q2m7-p3xg/GHSA-7pvp-q2m7-p3xg.json b/advisories/unreviewed/2024/12/GHSA-7pvp-q2m7-p3xg/GHSA-7pvp-q2m7-p3xg.json new file mode 100644 index 00000000000..449939990dd --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7pvp-q2m7-p3xg/GHSA-7pvp-q2m7-p3xg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pvp-q2m7-p3xg", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-38475" + ], + "details": "Missing Authorization vulnerability in RedNao Donations Made Easy – Smart Donations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38475" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/smart-donations/vulnerability/wordpress-donations-made-easy-smart-donations-plugin-4-0-12-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7qf4-vp3h-jh9x/GHSA-7qf4-vp3h-jh9x.json b/advisories/unreviewed/2024/12/GHSA-7qf4-vp3h-jh9x/GHSA-7qf4-vp3h-jh9x.json new file mode 100644 index 00000000000..cda2721d1b3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7qf4-vp3h-jh9x/GHSA-7qf4-vp3h-jh9x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qf4-vp3h-jh9x", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54237" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in anzia Ni CRM Lead allows Reflected XSS.This issue affects Ni CRM Lead: from n/a through 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54237" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ni-crm-lead/vulnerability/wordpress-ni-crm-lead-plugin-1-3-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7qj2-9cvc-wr5g/GHSA-7qj2-9cvc-wr5g.json b/advisories/unreviewed/2024/12/GHSA-7qj2-9cvc-wr5g/GHSA-7qj2-9cvc-wr5g.json new file mode 100644 index 00000000000..bcceac6735b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7qj2-9cvc-wr5g/GHSA-7qj2-9cvc-wr5g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qj2-9cvc-wr5g", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54300" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Neuralabz LTD. AutoWP allows Cross Site Request Forgery.This issue affects AutoWP: from n/a through 2.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54300" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/autowp-ai-content-writer-rewriter/vulnerability/wordpress-autowp-plugin-2-0-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7v6h-292g-jmmf/GHSA-7v6h-292g-jmmf.json b/advisories/unreviewed/2024/12/GHSA-7v6h-292g-jmmf/GHSA-7v6h-292g-jmmf.json new file mode 100644 index 00000000000..b8fa097bf3b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7v6h-292g-jmmf/GHSA-7v6h-292g-jmmf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v6h-292g-jmmf", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-38483" + ], + "details": "Missing Authorization vulnerability in Dylan Blokhuis Instant CSS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Instant CSS: from n/a through 1.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38483" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/instant-css/vulnerability/wordpress-instant-css-plugin-1-1-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8265-386p-5v6c/GHSA-8265-386p-5v6c.json b/advisories/unreviewed/2024/12/GHSA-8265-386p-5v6c/GHSA-8265-386p-5v6c.json new file mode 100644 index 00000000000..d0779ba4272 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8265-386p-5v6c/GHSA-8265-386p-5v6c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8265-386p-5v6c", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41683" + ], + "details": "Missing Authorization vulnerability in Pechenki TelSender allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TelSender: from n/a through 1.14.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41683" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/telsender/vulnerability/wordpress-telsender-plugin-1-14-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-82f5-xjqp-xw48/GHSA-82f5-xjqp-xw48.json b/advisories/unreviewed/2024/12/GHSA-82f5-xjqp-xw48/GHSA-82f5-xjqp-xw48.json new file mode 100644 index 00000000000..48c3c856f59 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-82f5-xjqp-xw48/GHSA-82f5-xjqp-xw48.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82f5-xjqp-xw48", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41649" + ], + "details": "Missing Authorization vulnerability in Ovic Team Ovic Product Bundle allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ovic Product Bundle: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41649" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ovic-product-bundle/vulnerability/wordpress-ovic-product-bundle-plugin-1-1-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-845p-72jm-3p9q/GHSA-845p-72jm-3p9q.json b/advisories/unreviewed/2024/12/GHSA-845p-72jm-3p9q/GHSA-845p-72jm-3p9q.json new file mode 100644 index 00000000000..fe94550d415 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-845p-72jm-3p9q/GHSA-845p-72jm-3p9q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-845p-72jm-3p9q", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54307" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in AIpost AIcomments allows Cross Site Request Forgery.This issue affects AIcomments: from n/a through 1.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54307" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/aicomments/vulnerability/wordpress-aicomments-plugin-1-4-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-89p6-5p4m-h2pv/GHSA-89p6-5p4m-h2pv.json b/advisories/unreviewed/2024/12/GHSA-89p6-5p4m-h2pv/GHSA-89p6-5p4m-h2pv.json new file mode 100644 index 00000000000..1be1ced197e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-89p6-5p4m-h2pv/GHSA-89p6-5p4m-h2pv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89p6-5p4m-h2pv", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-40331" + ], + "details": "Missing Authorization vulnerability in bqworks Accordion Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion Slider: from n/a through 1.9.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40331" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/accordion-slider/vulnerability/wordpress-accordion-slider-plugin-1-9-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-89r2-hwx6-33p8/GHSA-89r2-hwx6-33p8.json b/advisories/unreviewed/2024/12/GHSA-89r2-hwx6-33p8/GHSA-89r2-hwx6-33p8.json new file mode 100644 index 00000000000..1ce583e8313 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-89r2-hwx6-33p8/GHSA-89r2-hwx6-33p8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89r2-hwx6-33p8", + "modified": "2024-12-13T15:30:45Z", + "published": "2024-12-13T15:30:45Z", + "aliases": [ + "CVE-2024-54337" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in DevriX DX Dark Site allows Stored XSS.This issue affects DX Dark Site: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54337" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/devrix-dark-site/vulnerability/wordpress-dx-dark-site-plugin-1-0-1-csrf-to-stored-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8f38-9x5m-gx9w/GHSA-8f38-9x5m-gx9w.json b/advisories/unreviewed/2024/12/GHSA-8f38-9x5m-gx9w/GHSA-8f38-9x5m-gx9w.json new file mode 100644 index 00000000000..02006f20e0d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8f38-9x5m-gx9w/GHSA-8f38-9x5m-gx9w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8f38-9x5m-gx9w", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-36510" + ], + "details": "Missing Authorization vulnerability in Reservation Diary ReDi Restaurant Reservation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReDi Restaurant Reservation: from n/a through 23.0211.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36510" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/redi-restaurant-reservation/vulnerability/wordpress-redi-restaurant-reservation-plugin-23-0211-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8f7g-f5q3-fc3x/GHSA-8f7g-f5q3-fc3x.json b/advisories/unreviewed/2024/12/GHSA-8f7g-f5q3-fc3x/GHSA-8f7g-f5q3-fc3x.json new file mode 100644 index 00000000000..e41ac0afeaf --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8f7g-f5q3-fc3x/GHSA-8f7g-f5q3-fc3x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8f7g-f5q3-fc3x", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-34019" + ], + "details": "Missing Authorization vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Toolkit for LearnDash: from n/a through 3.6.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34019" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/uncanny-learndash-toolkit/vulnerability/wordpress-uncanny-toolkit-for-learndash-plugin-3-6-4-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8f9w-g33v-vmxc/GHSA-8f9w-g33v-vmxc.json b/advisories/unreviewed/2024/12/GHSA-8f9w-g33v-vmxc/GHSA-8f9w-g33v-vmxc.json new file mode 100644 index 00000000000..1637354bdd5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8f9w-g33v-vmxc/GHSA-8f9w-g33v-vmxc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8f9w-g33v-vmxc", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-38480" + ], + "details": "Missing Authorization vulnerability in Certain Dev Booster Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booster Elementor Addons: from n/a through 1.4.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38480" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/booster-for-elementor/vulnerability/wordpress-booster-elementor-addons-plugin-1-4-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8fg5-f59f-ph4f/GHSA-8fg5-f59f-ph4f.json b/advisories/unreviewed/2024/12/GHSA-8fg5-f59f-ph4f/GHSA-8fg5-f59f-ph4f.json new file mode 100644 index 00000000000..7bde3529e4e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8fg5-f59f-ph4f/GHSA-8fg5-f59f-ph4f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fg5-f59f-ph4f", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-37967" + ], + "details": "Missing Authorization vulnerability in Designinvento DirectoryPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DirectoryPress: from n/a through 3.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37967" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/directorypress/vulnerability/wordpress-directorypress-plugin-3-6-2-unauthenticated-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8hq9-vrmh-437m/GHSA-8hq9-vrmh-437m.json b/advisories/unreviewed/2024/12/GHSA-8hq9-vrmh-437m/GHSA-8hq9-vrmh-437m.json new file mode 100644 index 00000000000..6b8e419caa0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8hq9-vrmh-437m/GHSA-8hq9-vrmh-437m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hq9-vrmh-437m", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54323" + ], + "details": "Missing Authorization vulnerability in WPExpertsio New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects New User Approve: from n/a through 2.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54323" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/new-user-approve/vulnerability/wordpress-new-user-approve-plugin-2-6-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8j4x-2cxg-566c/GHSA-8j4x-2cxg-566c.json b/advisories/unreviewed/2024/12/GHSA-8j4x-2cxg-566c/GHSA-8j4x-2cxg-566c.json new file mode 100644 index 00000000000..de195d5bb67 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8j4x-2cxg-566c/GHSA-8j4x-2cxg-566c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j4x-2cxg-566c", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54301" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FormFacade FormFacade allows Reflected XSS.This issue affects FormFacade: from n/a through 1.3.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54301" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/formfacade/vulnerability/wordpress-formfacade-plugin-1-3-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8jq7-jpg9-m3h2/GHSA-8jq7-jpg9-m3h2.json b/advisories/unreviewed/2024/12/GHSA-8jq7-jpg9-m3h2/GHSA-8jq7-jpg9-m3h2.json new file mode 100644 index 00000000000..8bd0499f6a7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8jq7-jpg9-m3h2/GHSA-8jq7-jpg9-m3h2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jq7-jpg9-m3h2", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54292" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Appsplate Appsplate allows SQL Injection.This issue affects Appsplate: from n/a through 2.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54292" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/appsplate/vulnerability/wordpress-appsplate-plugin-2-1-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8mxc-hgx3-p9f3/GHSA-8mxc-hgx3-p9f3.json b/advisories/unreviewed/2024/12/GHSA-8mxc-hgx3-p9f3/GHSA-8mxc-hgx3-p9f3.json new file mode 100644 index 00000000000..55853f82798 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8mxc-hgx3-p9f3/GHSA-8mxc-hgx3-p9f3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mxc-hgx3-p9f3", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54324" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cloud Inn SMSify allows Reflected XSS.This issue affects SMSify: from n/a through 6.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54324" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/smsify/vulnerability/wordpress-smsify-plugin-6-0-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8v3m-977j-9xcw/GHSA-8v3m-977j-9xcw.json b/advisories/unreviewed/2024/12/GHSA-8v3m-977j-9xcw/GHSA-8v3m-977j-9xcw.json new file mode 100644 index 00000000000..0afeffa2eb0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8v3m-977j-9xcw/GHSA-8v3m-977j-9xcw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8v3m-977j-9xcw", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-44142" + ], + "details": "Missing Authorization vulnerability in Inactive Logout Inactive Logout allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Inactive Logout: from n/a through 3.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44142" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/inactive-logout/vulnerability/wordpress-inactive-logout-plugin-3-2-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8w4w-f5fh-qf9q/GHSA-8w4w-f5fh-qf9q.json b/advisories/unreviewed/2024/12/GHSA-8w4w-f5fh-qf9q/GHSA-8w4w-f5fh-qf9q.json new file mode 100644 index 00000000000..e3a9e2864c8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8w4w-f5fh-qf9q/GHSA-8w4w-f5fh-qf9q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w4w-f5fh-qf9q", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54304" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hive Support Hive Support – WordPress Help Desk allows SQL Injection.This issue affects Hive Support – WordPress Help Desk: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54304" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hive-support/vulnerability/wordpress-hive-support-plugin-1-1-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8x97-xf27-8q82/GHSA-8x97-xf27-8q82.json b/advisories/unreviewed/2024/12/GHSA-8x97-xf27-8q82/GHSA-8x97-xf27-8q82.json new file mode 100644 index 00000000000..86500310e2b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8x97-xf27-8q82/GHSA-8x97-xf27-8q82.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x97-xf27-8q82", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54276" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Felix Moira Poll Builder allows Stored XSS.This issue affects Poll Builder: from n/a through 1.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54276" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/poll-builder/vulnerability/wordpress-poll-builder-plugin-1-3-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8xrc-g7qp-jr24/GHSA-8xrc-g7qp-jr24.json b/advisories/unreviewed/2024/12/GHSA-8xrc-g7qp-jr24/GHSA-8xrc-g7qp-jr24.json new file mode 100644 index 00000000000..79793a03c81 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8xrc-g7qp-jr24/GHSA-8xrc-g7qp-jr24.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xrc-g7qp-jr24", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54290" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Fletcher Role Includer allows Reflected XSS.This issue affects Role Includer: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54290" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/role-includer/vulnerability/wordpress-role-includer-plugin-1-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-93x5-8qq9-j6pm/GHSA-93x5-8qq9-j6pm.json b/advisories/unreviewed/2024/12/GHSA-93x5-8qq9-j6pm/GHSA-93x5-8qq9-j6pm.json new file mode 100644 index 00000000000..23e91cfa4dd --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-93x5-8qq9-j6pm/GHSA-93x5-8qq9-j6pm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93x5-8qq9-j6pm", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-32585" + ], + "details": "Missing Authorization vulnerability in Total-Soft Portfolio Gallery – Responsive Image Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Portfolio Gallery – Responsive Image Gallery: from n/a through 1.4.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32585" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gallery-portfolio/vulnerability/wordpress-portfolio-gallery-responsive-image-gallery-plugin-1-4-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-97g5-8v5w-2cf2/GHSA-97g5-8v5w-2cf2.json b/advisories/unreviewed/2024/12/GHSA-97g5-8v5w-2cf2/GHSA-97g5-8v5w-2cf2.json new file mode 100644 index 00000000000..151f4e1d1aa --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-97g5-8v5w-2cf2/GHSA-97g5-8v5w-2cf2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97g5-8v5w-2cf2", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41664" + ], + "details": "Missing Authorization vulnerability in AlphaBPO Easy Newsletter Signups allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Newsletter Signups: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41664" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-newsletter-signups/vulnerability/wordpress-easy-newsletter-signups-plugin-1-0-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-98cx-x9cv-hfmj/GHSA-98cx-x9cv-hfmj.json b/advisories/unreviewed/2024/12/GHSA-98cx-x9cv-hfmj/GHSA-98cx-x9cv-hfmj.json new file mode 100644 index 00000000000..47e20853fe9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-98cx-x9cv-hfmj/GHSA-98cx-x9cv-hfmj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98cx-x9cv-hfmj", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54296" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in Codexpert, Inc CoSchool LMS allows Authentication Bypass.This issue affects CoSchool LMS: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54296" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/coschool/vulnerability/wordpress-coschool-lms-plugin-1-2-account-takeover-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9f66-j572-p954/GHSA-9f66-j572-p954.json b/advisories/unreviewed/2024/12/GHSA-9f66-j572-p954/GHSA-9f66-j572-p954.json new file mode 100644 index 00000000000..6f81057ddaf --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9f66-j572-p954/GHSA-9f66-j572-p954.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f66-j572-p954", + "modified": "2024-12-13T15:30:45Z", + "published": "2024-12-13T15:30:45Z", + "aliases": [ + "CVE-2024-54344" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood WP Quick Shop allows Reflected XSS.This issue affects WP Quick Shop: from n/a through 1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54344" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-quick-shop/vulnerability/wordpress-wp-quick-shop-plugin-1-3-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9vp7-2w9w-9982/GHSA-9vp7-2w9w-9982.json b/advisories/unreviewed/2024/12/GHSA-9vp7-2w9w-9982/GHSA-9vp7-2w9w-9982.json new file mode 100644 index 00000000000..c5d0d276c7a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9vp7-2w9w-9982/GHSA-9vp7-2w9w-9982.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vp7-2w9w-9982", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54312" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ووکامرس فارسی Persian Woocommerce SMS allows Reflected XSS.This issue affects Persian Woocommerce SMS: from n/a through 7.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54312" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/persian-woocommerce-sms/vulnerability/wordpress-fzonh-m-oo-mrs-persian-woocommerce-sms-plugin-7-0-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c2m9-hpp2-j675/GHSA-c2m9-hpp2-j675.json b/advisories/unreviewed/2024/12/GHSA-c2m9-hpp2-j675/GHSA-c2m9-hpp2-j675.json new file mode 100644 index 00000000000..e4d08dc9271 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c2m9-hpp2-j675/GHSA-c2m9-hpp2-j675.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2m9-hpp2-j675", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41690" + ], + "details": "Missing Authorization vulnerability in Wiser Notify WiserNotify Social Proof allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WiserNotify Social Proof: from n/a through 2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41690" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wiser-notify/vulnerability/wordpress-wisernotify-social-proof-plugin-2-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c2xg-f2c9-gvpr/GHSA-c2xg-f2c9-gvpr.json b/advisories/unreviewed/2024/12/GHSA-c2xg-f2c9-gvpr/GHSA-c2xg-f2c9-gvpr.json new file mode 100644 index 00000000000..f393bd96935 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c2xg-f2c9-gvpr/GHSA-c2xg-f2c9-gvpr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2xg-f2c9-gvpr", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54271" + ], + "details": "Missing Authorization vulnerability in WPTaskForce WPCargo Track & Trace allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCargo Track & Trace: from n/a through 7.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54271" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpcargo/vulnerability/wordpress-wpcargo-track-trace-plugin-7-0-6-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c37r-7mg5-gpf7/GHSA-c37r-7mg5-gpf7.json b/advisories/unreviewed/2024/12/GHSA-c37r-7mg5-gpf7/GHSA-c37r-7mg5-gpf7.json new file mode 100644 index 00000000000..8c4f2145bf8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c37r-7mg5-gpf7/GHSA-c37r-7mg5-gpf7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c37r-7mg5-gpf7", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41695" + ], + "details": "Missing Authorization vulnerability in Analytify Analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through 5.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41695" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-analytify/vulnerability/wordpress-analytify-google-analytics-dashboard-for-wordpress-plugin-5-1-0-broken-access-control-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c429-2q48-3x6w/GHSA-c429-2q48-3x6w.json b/advisories/unreviewed/2024/12/GHSA-c429-2q48-3x6w/GHSA-c429-2q48-3x6w.json new file mode 100644 index 00000000000..b38b9d861da --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c429-2q48-3x6w/GHSA-c429-2q48-3x6w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c429-2q48-3x6w", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54248" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Michael DUMONTET eewee admin custom allows Privilege Escalation.This issue affects eewee admin custom: from n/a through 1.8.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54248" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/eewee-admincustom/vulnerability/wordpress-eewee-admin-custom-plugin-1-8-2-4-csrf-to-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c42x-7v9q-fg7m/GHSA-c42x-7v9q-fg7m.json b/advisories/unreviewed/2024/12/GHSA-c42x-7v9q-fg7m/GHSA-c42x-7v9q-fg7m.json new file mode 100644 index 00000000000..60472918c5f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c42x-7v9q-fg7m/GHSA-c42x-7v9q-fg7m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c42x-7v9q-fg7m", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54245" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 Clients allows Stored XSS.This issue affects Clients: from n/a through 1.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54245" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/clients/vulnerability/wordpress-clients-plugin-1-1-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c4pr-cjx5-2mh2/GHSA-c4pr-cjx5-2mh2.json b/advisories/unreviewed/2024/12/GHSA-c4pr-cjx5-2mh2/GHSA-c4pr-cjx5-2mh2.json new file mode 100644 index 00000000000..406e6f348f8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c4pr-cjx5-2mh2/GHSA-c4pr-cjx5-2mh2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4pr-cjx5-2mh2", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54258" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in anzia Ni CRM Lead allows SQL Injection.This issue affects Ni CRM Lead: from n/a through 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54258" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ni-crm-lead/vulnerability/wordpress-ni-crm-lead-plugin-1-3-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-c4vc-qwpj-cgw6/GHSA-c4vc-qwpj-cgw6.json b/advisories/unreviewed/2024/12/GHSA-c4vc-qwpj-cgw6/GHSA-c4vc-qwpj-cgw6.json new file mode 100644 index 00000000000..d39d5ab5feb --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-c4vc-qwpj-cgw6/GHSA-c4vc-qwpj-cgw6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4vc-qwpj-cgw6", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-39996" + ], + "details": "Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Accordion and Accordion Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion and Accordion Slider: from n/a through 1.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39996" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/accordion-and-accordion-slider/vulnerability/wordpress-accordion-and-accordion-slider-plugin-1-2-4-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cccw-63fq-w4wv/GHSA-cccw-63fq-w4wv.json b/advisories/unreviewed/2024/12/GHSA-cccw-63fq-w4wv/GHSA-cccw-63fq-w4wv.json new file mode 100644 index 00000000000..7614e821a0a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cccw-63fq-w4wv/GHSA-cccw-63fq-w4wv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cccw-63fq-w4wv", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54311" + ], + "details": "Missing Authorization vulnerability in i.lychkov Mark New Posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mark New Posts: from n/a through 7.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54311" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mark-new-posts/vulnerability/wordpress-mark-new-posts-plugin-7-5-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-ch4p-crcc-3w42/GHSA-ch4p-crcc-3w42.json b/advisories/unreviewed/2024/12/GHSA-ch4p-crcc-3w42/GHSA-ch4p-crcc-3w42.json new file mode 100644 index 00000000000..416d9e7c5c4 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-ch4p-crcc-3w42/GHSA-ch4p-crcc-3w42.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch4p-crcc-3w42", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41688" + ], + "details": "Missing Authorization vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through 1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41688" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bulk-noindex-nofollow-toolkit-by-mad-fish/vulnerability/wordpress-bulk-noindex-nofollow-toolkit-plugin-1-42-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cprp-w79q-f798/GHSA-cprp-w79q-f798.json b/advisories/unreviewed/2024/12/GHSA-cprp-w79q-f798/GHSA-cprp-w79q-f798.json new file mode 100644 index 00000000000..14c68d18a8c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cprp-w79q-f798/GHSA-cprp-w79q-f798.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cprp-w79q-f798", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-32593" + ], + "details": "Missing Authorization vulnerability in GS Plugins GS Pins for Pinterest allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GS Pins for Pinterest: from n/a through 1.6.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32593" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gs-pinterest-portfolio/vulnerability/wordpress-gs-pins-for-pinterest-plugin-1-6-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cw4w-742w-5qj9/GHSA-cw4w-742w-5qj9.json b/advisories/unreviewed/2024/12/GHSA-cw4w-742w-5qj9/GHSA-cw4w-742w-5qj9.json new file mode 100644 index 00000000000..0d843f91011 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cw4w-742w-5qj9/GHSA-cw4w-742w-5qj9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cw4w-742w-5qj9", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-27456" + ], + "details": "Missing Authorization vulnerability in HashThemes Total allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Total: from n/a through 2.1.19.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27456" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/total/vulnerability/wordpress-total-theme-2-1-19-authenticated-arbitrary-plugin-activation?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cxc7-f9xp-4jgg/GHSA-cxc7-f9xp-4jgg.json b/advisories/unreviewed/2024/12/GHSA-cxc7-f9xp-4jgg/GHSA-cxc7-f9xp-4jgg.json new file mode 100644 index 00000000000..439af27c37e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cxc7-f9xp-4jgg/GHSA-cxc7-f9xp-4jgg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxc7-f9xp-4jgg", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54302" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VForm allows Reflected XSS.This issue affects VForm: from n/a through 3.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54302" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/v-form/vulnerability/wordpress-vform-plugin-3-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cxqp-pqvv-h89v/GHSA-cxqp-pqvv-h89v.json b/advisories/unreviewed/2024/12/GHSA-cxqp-pqvv-h89v/GHSA-cxqp-pqvv-h89v.json new file mode 100644 index 00000000000..798a5a0d3c2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cxqp-pqvv-h89v/GHSA-cxqp-pqvv-h89v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxqp-pqvv-h89v", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-33928" + ], + "details": "Missing Authorization vulnerability in WebToffee WordPress Backup & Migration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Backup & Migration: from n/a through 1.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33928" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-migration-duplicator/vulnerability/wordpress-wordpress-backup-migration-plugin-1-4-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-f22v-ffw2-qx8g/GHSA-f22v-ffw2-qx8g.json b/advisories/unreviewed/2024/12/GHSA-f22v-ffw2-qx8g/GHSA-f22v-ffw2-qx8g.json new file mode 100644 index 00000000000..76877cbc99b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f22v-ffw2-qx8g/GHSA-f22v-ffw2-qx8g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f22v-ffw2-qx8g", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54236" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in anzia Ni WooCommerce Bulk Product Editor allows Reflected XSS.This issue affects Ni WooCommerce Bulk Product Editor: from n/a through 1.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54236" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ni-woocommerce-product-editor/vulnerability/wordpress-ni-woocommerce-bulk-product-editor-plugin-1-4-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-f3hq-gxw2-6xpg/GHSA-f3hq-gxw2-6xpg.json b/advisories/unreviewed/2024/12/GHSA-f3hq-gxw2-6xpg/GHSA-f3hq-gxw2-6xpg.json new file mode 100644 index 00000000000..0be2db4d035 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f3hq-gxw2-6xpg/GHSA-f3hq-gxw2-6xpg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3hq-gxw2-6xpg", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54306" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in KCT AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot allows Cross Site Request Forgery.This issue affects AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot: from n/a through 1.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54306" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ai-seo-translator/vulnerability/wordpress-aikct-engine-chatbot-chatgpt-gemini-gpt-4o-best-ai-chatbot-plugin-1-6-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-f4jg-3gfx-44mj/GHSA-f4jg-3gfx-44mj.json b/advisories/unreviewed/2024/12/GHSA-f4jg-3gfx-44mj/GHSA-f4jg-3gfx-44mj.json new file mode 100644 index 00000000000..6168f06d466 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-f4jg-3gfx-44mj/GHSA-f4jg-3gfx-44mj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4jg-3gfx-44mj", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54277" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alireza aliniya Nias course allows DOM-Based XSS.This issue affects Nias course: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54277" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nias-course/vulnerability/wordpress-nias-course-plugin-1-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fg26-cqw6-r8pw/GHSA-fg26-cqw6-r8pw.json b/advisories/unreviewed/2024/12/GHSA-fg26-cqw6-r8pw/GHSA-fg26-cqw6-r8pw.json new file mode 100644 index 00000000000..a79682dc53e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fg26-cqw6-r8pw/GHSA-fg26-cqw6-r8pw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg26-cqw6-r8pw", + "modified": "2024-12-13T15:30:45Z", + "published": "2024-12-13T15:30:45Z", + "aliases": [ + "CVE-2024-54345" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SKT Themes Bicycleshop allows DOM-Based XSS.This issue affects Bicycleshop: from n/a through 1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54345" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/bicycleshop/vulnerability/wordpress-bicycleshop-theme-1-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fh8x-pp45-h2fp/GHSA-fh8x-pp45-h2fp.json b/advisories/unreviewed/2024/12/GHSA-fh8x-pp45-h2fp/GHSA-fh8x-pp45-h2fp.json new file mode 100644 index 00000000000..0e14c64da5d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fh8x-pp45-h2fp/GHSA-fh8x-pp45-h2fp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh8x-pp45-h2fp", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-33215" + ], + "details": "Missing Authorization vulnerability in Tagbox Taggbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Taggbox: from n/a through 3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33215" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/taggbox-widget/vulnerability/wordpress-taggbox-ugc-galleries-social-media-widgets-user-reviews-analytics-plugin-2-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fp55-ccw2-mpc3/GHSA-fp55-ccw2-mpc3.json b/advisories/unreviewed/2024/12/GHSA-fp55-ccw2-mpc3/GHSA-fp55-ccw2-mpc3.json new file mode 100644 index 00000000000..733e0fd294b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fp55-ccw2-mpc3/GHSA-fp55-ccw2-mpc3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp55-ccw2-mpc3", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41952" + ], + "details": "Missing Authorization vulnerability in Contact Form - WPManageNinja LLC FluentForm allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentForm: from n/a through 5.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41952" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fluentform/vulnerability/wordpress-fluent-forms-plugin-5-0-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fp89-mh8w-pvx6/GHSA-fp89-mh8w-pvx6.json b/advisories/unreviewed/2024/12/GHSA-fp89-mh8w-pvx6/GHSA-fp89-mh8w-pvx6.json new file mode 100644 index 00000000000..30a285926ae --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fp89-mh8w-pvx6/GHSA-fp89-mh8w-pvx6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp89-mh8w-pvx6", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54274" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Octrace Studio WordPress HelpDesk & Support Ticket System Plugin – Octrace Support allows Reflected XSS.This issue affects WordPress HelpDesk & Support Ticket System Plugin – Octrace Support: from n/a through 1.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54274" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/octrace-support/vulnerability/wordpress-octrace-support-plugin-1-2-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fw47-976j-mgxw/GHSA-fw47-976j-mgxw.json b/advisories/unreviewed/2024/12/GHSA-fw47-976j-mgxw/GHSA-fw47-976j-mgxw.json new file mode 100644 index 00000000000..b0155c4e047 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fw47-976j-mgxw/GHSA-fw47-976j-mgxw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw47-976j-mgxw", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54305" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woocs J&T Express Malaysia allows Reflected XSS.This issue affects J&T Express Malaysia: from n/a through 2.0.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54305" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jt-express/vulnerability/wordpress-j-t-express-malaysia-plugin-2-0-13-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fx7w-r2qg-gq45/GHSA-fx7w-r2qg-gq45.json b/advisories/unreviewed/2024/12/GHSA-fx7w-r2qg-gq45/GHSA-fx7w-r2qg-gq45.json new file mode 100644 index 00000000000..abc97ca4d37 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fx7w-r2qg-gq45/GHSA-fx7w-r2qg-gq45.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fx7w-r2qg-gq45", + "modified": "2024-12-13T15:30:45Z", + "published": "2024-12-13T15:30:45Z", + "aliases": [ + "CVE-2024-54334" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zeshan B Quran Phrases About Most People Shortcodes allows DOM-Based XSS.This issue affects Quran Phrases About Most People Shortcodes: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54334" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quran-phrases-about-most-people-shortcodes/vulnerability/wordpress-quran-phrases-about-most-people-shortcodes-plugin-1-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g2hj-pq3h-fqxr/GHSA-g2hj-pq3h-fqxr.json b/advisories/unreviewed/2024/12/GHSA-g2hj-pq3h-fqxr/GHSA-g2hj-pq3h-fqxr.json new file mode 100644 index 00000000000..0318147d587 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g2hj-pq3h-fqxr/GHSA-g2hj-pq3h-fqxr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2hj-pq3h-fqxr", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-34376" + ], + "details": "Missing Authorization vulnerability in Rextheme Change WooCommerce Add To Cart Button Text allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Change WooCommerce Add To Cart Button Text: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34376" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/change-woocommerce-add-to-cart-button-text/vulnerability/wordpress-change-woocommerce-add-to-cart-button-text-plugin-1-3-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g484-4fg8-w2qw/GHSA-g484-4fg8-w2qw.json b/advisories/unreviewed/2024/12/GHSA-g484-4fg8-w2qw/GHSA-g484-4fg8-w2qw.json new file mode 100644 index 00000000000..033d97eef0d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g484-4fg8-w2qw/GHSA-g484-4fg8-w2qw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g484-4fg8-w2qw", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54265" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Reflected XSS.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.6.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54265" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/vulnerability/wordpress-barcode-scanner-and-inventory-manager-plugin-1-6-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g7vj-553h-hjwx/GHSA-g7vj-553h-hjwx.json b/advisories/unreviewed/2024/12/GHSA-g7vj-553h-hjwx/GHSA-g7vj-553h-hjwx.json new file mode 100644 index 00000000000..82947e5e201 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g7vj-553h-hjwx/GHSA-g7vj-553h-hjwx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7vj-553h-hjwx", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-34387" + ], + "details": "Missing Authorization vulnerability in Constant Contact Constant Contact Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Constant Contact Forms: from n/a through 2.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34387" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/constant-contact-forms/vulnerability/wordpress-constant-contact-forms-plugin-1-14-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g8w8-65mq-pgmc/GHSA-g8w8-65mq-pgmc.json b/advisories/unreviewed/2024/12/GHSA-g8w8-65mq-pgmc/GHSA-g8w8-65mq-pgmc.json new file mode 100644 index 00000000000..9c7ec286c57 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g8w8-65mq-pgmc/GHSA-g8w8-65mq-pgmc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8w8-65mq-pgmc", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54231" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in anzia Ni WooCommerce Order Export allows Reflected XSS.This issue affects Ni WooCommerce Order Export: from n/a through 3.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54231" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ni-woocommerce-order-export/vulnerability/wordpress-ni-woocommerce-order-export-plugin-3-1-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g9hc-4xr6-9wr4/GHSA-g9hc-4xr6-9wr4.json b/advisories/unreviewed/2024/12/GHSA-g9hc-4xr6-9wr4/GHSA-g9hc-4xr6-9wr4.json new file mode 100644 index 00000000000..84736341840 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g9hc-4xr6-9wr4/GHSA-g9hc-4xr6-9wr4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9hc-4xr6-9wr4", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2022-43472" + ], + "details": "Missing Authorization vulnerability in StylemixThemes eRoom – Zoom Meetings & Webinar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eRoom – Zoom Meetings & Webinar: from n/a through 1.4.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43472" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/eroom-zoom-meetings-webinar/vulnerability/wordpress-eroom-plugin-1-4-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-ggcf-5rrx-7333/GHSA-ggcf-5rrx-7333.json b/advisories/unreviewed/2024/12/GHSA-ggcf-5rrx-7333/GHSA-ggcf-5rrx-7333.json new file mode 100644 index 00000000000..7bd7eb4d3b8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-ggcf-5rrx-7333/GHSA-ggcf-5rrx-7333.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggcf-5rrx-7333", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54273" + ], + "details": "Deserialization of Untrusted Data vulnerability in PickPlugins Mail Picker allows Object Injection.This issue affects Mail Picker: from n/a through 1.0.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54273" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mail-picker/vulnerability/wordpress-mail-picker-plugin-1-0-14-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gpwq-qppr-7c5w/GHSA-gpwq-qppr-7c5w.json b/advisories/unreviewed/2024/12/GHSA-gpwq-qppr-7c5w/GHSA-gpwq-qppr-7c5w.json new file mode 100644 index 00000000000..d8602a67f39 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gpwq-qppr-7c5w/GHSA-gpwq-qppr-7c5w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpwq-qppr-7c5w", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-32599" + ], + "details": "Missing Authorization vulnerability in Bill Minozzi reCAPTCHA for all allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects reCAPTCHA for all: from n/a through 1.22.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32599" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/recaptcha-for-all/vulnerability/wordpress-recaptcha-for-all-plugin-1-22-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gq4m-hx6p-2rp5/GHSA-gq4m-hx6p-2rp5.json b/advisories/unreviewed/2024/12/GHSA-gq4m-hx6p-2rp5/GHSA-gq4m-hx6p-2rp5.json new file mode 100644 index 00000000000..1c47cd2a8c2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gq4m-hx6p-2rp5/GHSA-gq4m-hx6p-2rp5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq4m-hx6p-2rp5", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-36519" + ], + "details": "Missing Authorization vulnerability in wpthemego SW Product Bundles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SW Product Bundles: from n/a through 2.0.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36519" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sw-product-bundles/vulnerability/wordpress-sw-product-bundles-plugin-2-0-15-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gr6x-wfgx-r7fm/GHSA-gr6x-wfgx-r7fm.json b/advisories/unreviewed/2024/12/GHSA-gr6x-wfgx-r7fm/GHSA-gr6x-wfgx-r7fm.json new file mode 100644 index 00000000000..c3395f8d772 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gr6x-wfgx-r7fm/GHSA-gr6x-wfgx-r7fm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr6x-wfgx-r7fm", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54282" + ], + "details": "Deserialization of Untrusted Data vulnerability in Themeum WP Mega Menu allows Object Injection.This issue affects WP Mega Menu: from n/a through 1.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54282" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-megamenu/vulnerability/wordpress-wp-mega-menu-plugin-1-4-2-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gv5w-pqg2-3w8x/GHSA-gv5w-pqg2-3w8x.json b/advisories/unreviewed/2024/12/GHSA-gv5w-pqg2-3w8x/GHSA-gv5w-pqg2-3w8x.json new file mode 100644 index 00000000000..ab6d8f4b80b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gv5w-pqg2-3w8x/GHSA-gv5w-pqg2-3w8x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv5w-pqg2-3w8x", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54256" + ], + "details": "Missing Authorization vulnerability in Seerox Easy Blocks pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Easy Blocks pro: from n/a through 1.0.21.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54256" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-blocks-pro/vulnerability/wordpress-easy-blocks-pro-plugin-1-0-21-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gvpq-4fvc-8q2q/GHSA-gvpq-4fvc-8q2q.json b/advisories/unreviewed/2024/12/GHSA-gvpq-4fvc-8q2q/GHSA-gvpq-4fvc-8q2q.json new file mode 100644 index 00000000000..b2308f2113f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gvpq-4fvc-8q2q/GHSA-gvpq-4fvc-8q2q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvpq-4fvc-8q2q", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-37989" + ], + "details": "Missing Authorization vulnerability in Easyship Easyship WooCommerce Shipping Rates allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easyship WooCommerce Shipping Rates: from n/a through 0.9.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37989" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easyship-woocommerce-shipping-rates/vulnerability/wordpress-easyship-woocommerce-shipping-rates-plugin-0-8-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gwqg-29r6-j2pq/GHSA-gwqg-29r6-j2pq.json b/advisories/unreviewed/2024/12/GHSA-gwqg-29r6-j2pq/GHSA-gwqg-29r6-j2pq.json new file mode 100644 index 00000000000..9be29dbf00f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gwqg-29r6-j2pq/GHSA-gwqg-29r6-j2pq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwqg-29r6-j2pq", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54293" + ], + "details": "Incorrect Privilege Assignment vulnerability in CE21 CE21 Suite allows Privilege Escalation.This issue affects CE21 Suite: from n/a through 2.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54293" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ce21-suite/vulnerability/wordpress-ce21-suite-plugin-2-2-0-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h46f-q7jf-wgr6/GHSA-h46f-q7jf-wgr6.json b/advisories/unreviewed/2024/12/GHSA-h46f-q7jf-wgr6/GHSA-h46f-q7jf-wgr6.json new file mode 100644 index 00000000000..956ca454428 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h46f-q7jf-wgr6/GHSA-h46f-q7jf-wgr6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h46f-q7jf-wgr6", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2022-46846" + ], + "details": "Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Trending/Popular Post Slider and Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trending/Popular Post Slider and Widget: from n/a through 1.5.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46846" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-trending-post-slider-and-widget/vulnerability/wordpress-trending-popular-post-slider-and-widget-plugin-1-5-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h9xx-632f-3wf6/GHSA-h9xx-632f-3wf6.json b/advisories/unreviewed/2024/12/GHSA-h9xx-632f-3wf6/GHSA-h9xx-632f-3wf6.json new file mode 100644 index 00000000000..3517e36c191 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h9xx-632f-3wf6/GHSA-h9xx-632f-3wf6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9xx-632f-3wf6", + "modified": "2024-12-13T15:30:45Z", + "published": "2024-12-13T15:30:45Z", + "aliases": [ + "CVE-2024-54336" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in Projectopia Projectopia allows Authentication Bypass.This issue affects Projectopia: from n/a through 5.1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54336" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/projectopia-core/vulnerability/wordpress-projectopia-plugin-5-1-7-account-takeover-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hmmg-44qj-gxjj/GHSA-hmmg-44qj-gxjj.json b/advisories/unreviewed/2024/12/GHSA-hmmg-44qj-gxjj/GHSA-hmmg-44qj-gxjj.json new file mode 100644 index 00000000000..53514c27378 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hmmg-44qj-gxjj/GHSA-hmmg-44qj-gxjj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmmg-44qj-gxjj", + "modified": "2024-12-13T15:30:45Z", + "published": "2024-12-13T15:30:45Z", + "aliases": [ + "CVE-2024-54346" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SKT Themes Barter allows DOM-Based XSS.This issue affects Barter: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54346" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/barter/vulnerability/wordpress-barter-theme-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hqrx-gcpg-fwj7/GHSA-hqrx-gcpg-fwj7.json b/advisories/unreviewed/2024/12/GHSA-hqrx-gcpg-fwj7/GHSA-hqrx-gcpg-fwj7.json new file mode 100644 index 00000000000..c6df5b5ffcb --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hqrx-gcpg-fwj7/GHSA-hqrx-gcpg-fwj7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqrx-gcpg-fwj7", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2022-47594" + ], + "details": "Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through 3.8.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47594" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/essential-blocks/vulnerability/wordpress-essential-blocks-for-gutenberg-plugin-3-8-5-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hw7q-5gxp-c6j5/GHSA-hw7q-5gxp-c6j5.json b/advisories/unreviewed/2024/12/GHSA-hw7q-5gxp-c6j5/GHSA-hw7q-5gxp-c6j5.json new file mode 100644 index 00000000000..304ed84f606 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hw7q-5gxp-c6j5/GHSA-hw7q-5gxp-c6j5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hw7q-5gxp-c6j5", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-30490" + ], + "details": "Missing Authorization vulnerability in Matthew Ruddy Easing Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easing Slider : from n/a through 3.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30490" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easing-slider/vulnerability/wordpress-easing-slider-plugin-3-0-8-plugin-settings-reset-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hwgp-fj53-vmfq/GHSA-hwgp-fj53-vmfq.json b/advisories/unreviewed/2024/12/GHSA-hwgp-fj53-vmfq/GHSA-hwgp-fj53-vmfq.json new file mode 100644 index 00000000000..a192770b9ce --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hwgp-fj53-vmfq/GHSA-hwgp-fj53-vmfq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwgp-fj53-vmfq", + "modified": "2024-12-13T15:30:45Z", + "published": "2024-12-13T15:30:45Z", + "aliases": [ + "CVE-2024-54341" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LabelGrid LabelGrid Tools allows Reflected XSS.This issue affects LabelGrid Tools: from n/a through 1.3.58.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54341" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/label-grid-tools/vulnerability/wordpress-labelgrid-tools-plugin-1-3-58-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hx8r-9859-p3wh/GHSA-hx8r-9859-p3wh.json b/advisories/unreviewed/2024/12/GHSA-hx8r-9859-p3wh/GHSA-hx8r-9859-p3wh.json new file mode 100644 index 00000000000..02ac31a0e98 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hx8r-9859-p3wh/GHSA-hx8r-9859-p3wh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx8r-9859-p3wh", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54243" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 Echoza allows Stored XSS.This issue affects Echoza: from n/a through 0.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54243" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/echoza/vulnerability/wordpress-echoza-plugin-0-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hxg3-qgfc-88mw/GHSA-hxg3-qgfc-88mw.json b/advisories/unreviewed/2024/12/GHSA-hxg3-qgfc-88mw/GHSA-hxg3-qgfc-88mw.json new file mode 100644 index 00000000000..93c7d82880a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hxg3-qgfc-88mw/GHSA-hxg3-qgfc-88mw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxg3-qgfc-88mw", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-36506" + ], + "details": "Missing Authorization vulnerability in YITH YITH WooCommerce Waiting List allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YITH WooCommerce Waiting List: from n/a through 2.13.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36506" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/yith-woocommerce-waiting-list/vulnerability/wordpress-yith-woocommerce-waitlist-plugin-2-6-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j26j-8pq8-x582/GHSA-j26j-8pq8-x582.json b/advisories/unreviewed/2024/12/GHSA-j26j-8pq8-x582/GHSA-j26j-8pq8-x582.json new file mode 100644 index 00000000000..9f851ccae1b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j26j-8pq8-x582/GHSA-j26j-8pq8-x582.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j26j-8pq8-x582", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41869" + ], + "details": "Missing Authorization vulnerability in Alex Volkov WP Accessibility Helper (WAH) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Accessibility Helper (WAH): from n/a through 0.6.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41869" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-accessibility-helper/vulnerability/wordpress-wp-accessibility-helper-wah-plugin-0-6-2-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j274-pg4w-6cj6/GHSA-j274-pg4w-6cj6.json b/advisories/unreviewed/2024/12/GHSA-j274-pg4w-6cj6/GHSA-j274-pg4w-6cj6.json new file mode 100644 index 00000000000..d2facc3e30b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j274-pg4w-6cj6/GHSA-j274-pg4w-6cj6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j274-pg4w-6cj6", + "modified": "2024-12-13T15:30:45Z", + "published": "2024-12-13T15:30:45Z", + "aliases": [ + "CVE-2024-54335" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZebraSoft Monaco ImmoToolBox Connect allows Reflected XSS.This issue affects ImmoToolBox Connect: from n/a through 1.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54335" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/immotoolbox-connect/vulnerability/wordpress-immotoolbox-connect-plugin-1-3-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j3qr-gw2j-fj2r/GHSA-j3qr-gw2j-fj2r.json b/advisories/unreviewed/2024/12/GHSA-j3qr-gw2j-fj2r/GHSA-j3qr-gw2j-fj2r.json new file mode 100644 index 00000000000..8e05e17e0b6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j3qr-gw2j-fj2r/GHSA-j3qr-gw2j-fj2r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3qr-gw2j-fj2r", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-38479" + ], + "details": "Missing Authorization vulnerability in Codents Simple Googlebot Visit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Googlebot Visit: from n/a through 1.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38479" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-googlebot-visit/vulnerability/wordpress-simple-googlebot-visit-plugin-1-2-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j523-c39q-h78r/GHSA-j523-c39q-h78r.json b/advisories/unreviewed/2024/12/GHSA-j523-c39q-h78r/GHSA-j523-c39q-h78r.json new file mode 100644 index 00000000000..71825c0eac8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j523-c39q-h78r/GHSA-j523-c39q-h78r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j523-c39q-h78r", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54326" + ], + "details": "Missing Authorization vulnerability in Eyal Fitoussi GEO my WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GEO my WordPress: from n/a through 4.5.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54326" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/geo-my-wp/vulnerability/wordpress-geo-my-wp-plugin-4-5-0-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j572-7jg9-f4xg/GHSA-j572-7jg9-f4xg.json b/advisories/unreviewed/2024/12/GHSA-j572-7jg9-f4xg/GHSA-j572-7jg9-f4xg.json new file mode 100644 index 00000000000..78ad2e4b59b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j572-7jg9-f4xg/GHSA-j572-7jg9-f4xg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j572-7jg9-f4xg", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54318" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicejob NiceJob allows Stored XSS.This issue affects NiceJob: from n/a through 3.6.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54318" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nicejob/vulnerability/wordpress-nicejob-plugin-3-6-5-cross-site-scripting-xss-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j5q5-3xrg-g36w/GHSA-j5q5-3xrg-g36w.json b/advisories/unreviewed/2024/12/GHSA-j5q5-3xrg-g36w/GHSA-j5q5-3xrg-g36w.json new file mode 100644 index 00000000000..fd83b8ddd47 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j5q5-3xrg-g36w/GHSA-j5q5-3xrg-g36w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5q5-3xrg-g36w", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2022-47429" + ], + "details": "Missing Authorization vulnerability in 8Degree Themes Coming Soon Landing Page and Maintenance Mode WordPress Plugin allows Retrieve Embedded Sensitive Data.This issue affects Coming Soon Landing Page and Maintenance Mode WordPress Plugin: from n/a through 2.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47429" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/8-degree-coming-soon-page/vulnerability/wordpress-coming-soon-landing-page-and-maintenance-mode-wordpress-plugin-plugin-2-2-0-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j5q9-7xqm-r9fg/GHSA-j5q9-7xqm-r9fg.json b/advisories/unreviewed/2024/12/GHSA-j5q9-7xqm-r9fg/GHSA-j5q9-7xqm-r9fg.json new file mode 100644 index 00000000000..235b29450d3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j5q9-7xqm-r9fg/GHSA-j5q9-7xqm-r9fg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5q9-7xqm-r9fg", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-37969" + ], + "details": "Missing Authorization vulnerability in The African Boss Checkout with Zelle on Woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Checkout with Zelle on Woocommerce: from n/a through 3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37969" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wc-zelle/vulnerability/wordpress-checkout-with-zelle-on-woocommerce-plugin-3-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j683-9f8m-7px6/GHSA-j683-9f8m-7px6.json b/advisories/unreviewed/2024/12/GHSA-j683-9f8m-7px6/GHSA-j683-9f8m-7px6.json new file mode 100644 index 00000000000..2a21f6f757a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j683-9f8m-7px6/GHSA-j683-9f8m-7px6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j683-9f8m-7px6", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54308" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CurrencyRate.today Cryptocurrency Price Widget allows Stored XSS.This issue affects Cryptocurrency Price Widget: from n/a through 1.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54308" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cryptocurrency-price-widget/vulnerability/wordpress-cryptocurrency-price-widget-plugin-1-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j6f4-g5vh-36v8/GHSA-j6f4-g5vh-36v8.json b/advisories/unreviewed/2024/12/GHSA-j6f4-g5vh-36v8/GHSA-j6f4-g5vh-36v8.json new file mode 100644 index 00000000000..2dccc23a180 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j6f4-g5vh-36v8/GHSA-j6f4-g5vh-36v8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6f4-g5vh-36v8", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-39997" + ], + "details": "Missing Authorization vulnerability in supsystic.com Popup by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup by Supsystic: from n/a through 1.10.19.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39997" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/popup-by-supsystic/vulnerability/wordpress-popup-by-supsystic-plugin-1-10-19-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j77w-w4mp-8h58/GHSA-j77w-w4mp-8h58.json b/advisories/unreviewed/2024/12/GHSA-j77w-w4mp-8h58/GHSA-j77w-w4mp-8h58.json new file mode 100644 index 00000000000..2fe278878ed --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j77w-w4mp-8h58/GHSA-j77w-w4mp-8h58.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j77w-w4mp-8h58", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-35046" + ], + "details": "Missing Authorization vulnerability in Dynamic.ooo Dynamic Visibility for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dynamic Visibility for Elementor: from n/a through 5.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35046" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dynamic-visibility-for-elementor/vulnerability/wordpress-dynamic-visibility-for-elementor-plugin-5-0-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j7hx-8fjx-qhrv/GHSA-j7hx-8fjx-qhrv.json b/advisories/unreviewed/2024/12/GHSA-j7hx-8fjx-qhrv/GHSA-j7hx-8fjx-qhrv.json new file mode 100644 index 00000000000..09e2ff5e013 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j7hx-8fjx-qhrv/GHSA-j7hx-8fjx-qhrv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7hx-8fjx-qhrv", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54297" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in www.vbsso.com vBSSO-lite allows Authentication Bypass.This issue affects vBSSO-lite: from n/a through 1.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54297" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/vbsso-lite/vulnerability/wordpress-vbsso-lite-plugin-1-4-3-account-takeover-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j869-crw9-vrvh/GHSA-j869-crw9-vrvh.json b/advisories/unreviewed/2024/12/GHSA-j869-crw9-vrvh/GHSA-j869-crw9-vrvh.json new file mode 100644 index 00000000000..6da8cd56fc8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j869-crw9-vrvh/GHSA-j869-crw9-vrvh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j869-crw9-vrvh", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-33994" + ], + "details": "Missing Authorization vulnerability in Jason Crouse, VeronaLabs Slimstat Analytics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slimstat Analytics: from n/a through 5.0.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33994" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-slimstat/vulnerability/wordpress-slimstat-analytics-plugin-5-0-5-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j8m7-chf8-r8x3/GHSA-j8m7-chf8-r8x3.json b/advisories/unreviewed/2024/12/GHSA-j8m7-chf8-r8x3/GHSA-j8m7-chf8-r8x3.json new file mode 100644 index 00000000000..da92094ec1f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j8m7-chf8-r8x3/GHSA-j8m7-chf8-r8x3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8m7-chf8-r8x3", + "modified": "2024-12-13T15:30:45Z", + "published": "2024-12-13T15:30:45Z", + "aliases": [ + "CVE-2024-54351" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Tom Landis Fancy Roller Scroller allows Stored XSS.This issue affects Fancy Roller Scroller: from n/a through 1.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54351" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fancy-roller-scroller/vulnerability/wordpress-fancy-roller-scroller-plugin-1-4-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jcm8-w5wv-cxc6/GHSA-jcm8-w5wv-cxc6.json b/advisories/unreviewed/2024/12/GHSA-jcm8-w5wv-cxc6/GHSA-jcm8-w5wv-cxc6.json new file mode 100644 index 00000000000..6b759c46838 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jcm8-w5wv-cxc6/GHSA-jcm8-w5wv-cxc6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcm8-w5wv-cxc6", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2022-46840" + ], + "details": "Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46840" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/js-support-ticket/vulnerability/wordpress-js-help-desk-plugin-2-7-1-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jf99-j3rv-qp5p/GHSA-jf99-j3rv-qp5p.json b/advisories/unreviewed/2024/12/GHSA-jf99-j3rv-qp5p/GHSA-jf99-j3rv-qp5p.json new file mode 100644 index 00000000000..bc07d050f5a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jf99-j3rv-qp5p/GHSA-jf99-j3rv-qp5p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jf99-j3rv-qp5p", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-36518" + ], + "details": "Missing Authorization vulnerability in Hugh Lashbrooke Post Hit Counter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Hit Counter: from n/a through 1.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36518" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/post-hit-counter/vulnerability/wordpress-post-hit-counter-plugin-1-3-2-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jfr2-m965-cp8h/GHSA-jfr2-m965-cp8h.json b/advisories/unreviewed/2024/12/GHSA-jfr2-m965-cp8h/GHSA-jfr2-m965-cp8h.json new file mode 100644 index 00000000000..cdc8a9ecd8c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jfr2-m965-cp8h/GHSA-jfr2-m965-cp8h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfr2-m965-cp8h", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41686" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ilGhera Woocommerce Support System allows Cross Site Request Forgery.This issue affects Woocommerce Support System: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41686" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wc-support-system/vulnerability/wordpress-woocommerce-support-system-plugin-1-2-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jmq8-p4r6-9r2c/GHSA-jmq8-p4r6-9r2c.json b/advisories/unreviewed/2024/12/GHSA-jmq8-p4r6-9r2c/GHSA-jmq8-p4r6-9r2c.json new file mode 100644 index 00000000000..adf6843e82d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jmq8-p4r6-9r2c/GHSA-jmq8-p4r6-9r2c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmq8-p4r6-9r2c", + "modified": "2024-12-13T15:30:45Z", + "published": "2024-12-13T15:30:45Z", + "aliases": [ + "CVE-2024-54333" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in silverplugins217 Check Pincode For Woocommerce allows Reflected XSS.This issue affects Check Pincode For Woocommerce: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54333" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/check-pincode-for-woocommerce/vulnerability/wordpress-check-pincode-for-woocommerce-plugin-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jqwg-pp3j-9wvj/GHSA-jqwg-pp3j-9wvj.json b/advisories/unreviewed/2024/12/GHSA-jqwg-pp3j-9wvj/GHSA-jqwg-pp3j-9wvj.json new file mode 100644 index 00000000000..7ef3c8fd134 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jqwg-pp3j-9wvj/GHSA-jqwg-pp3j-9wvj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqwg-pp3j-9wvj", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-28980" + ], + "details": "Dell RecoverPoint for VMs, version(s) 6.0.x contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the SSH. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28980" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000259765/dsa-2024-429-security-update-for-dell-recoverpoint-for-virtual-machines-multiple-third-party-component-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jv99-wf4f-255j/GHSA-jv99-wf4f-255j.json b/advisories/unreviewed/2024/12/GHSA-jv99-wf4f-255j/GHSA-jv99-wf4f-255j.json new file mode 100644 index 00000000000..64659352cb0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jv99-wf4f-255j/GHSA-jv99-wf4f-255j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv99-wf4f-255j", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-44149" + ], + "details": "Missing Authorization vulnerability in BeRocket Brands for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brands for WooCommerce: from n/a through 3.8.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44149" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/brands-for-woocommerce/vulnerability/wordpress-brands-for-woocommerce-plugin-3-8-2-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jvv6-2x5h-x4xc/GHSA-jvv6-2x5h-x4xc.json b/advisories/unreviewed/2024/12/GHSA-jvv6-2x5h-x4xc/GHSA-jvv6-2x5h-x4xc.json new file mode 100644 index 00000000000..08254d08a68 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jvv6-2x5h-x4xc/GHSA-jvv6-2x5h-x4xc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvv6-2x5h-x4xc", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-34009" + ], + "details": "Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Media & Share Icons: from n/a through 2.8.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34009" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-social-media-icons/vulnerability/wordpress-social-media-share-buttons-social-sharing-icons-plugin-2-8-1-broken-access-control-csrf?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-jxpm-23vm-58g5/GHSA-jxpm-23vm-58g5.json b/advisories/unreviewed/2024/12/GHSA-jxpm-23vm-58g5/GHSA-jxpm-23vm-58g5.json new file mode 100644 index 00000000000..74a404388a9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-jxpm-23vm-58g5/GHSA-jxpm-23vm-58g5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxpm-23vm-58g5", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2022-45806" + ], + "details": "Missing Authorization vulnerability in Strategy11 Form Builder Team Formidable Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Formidable Forms: from n/a through 5.5.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45806" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/formidable/vulnerability/wordpress-formidable-forms-plugin-5-5-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m2x6-82qg-2f4p/GHSA-m2x6-82qg-2f4p.json b/advisories/unreviewed/2024/12/GHSA-m2x6-82qg-2f4p/GHSA-m2x6-82qg-2f4p.json new file mode 100644 index 00000000000..558ae5fe426 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m2x6-82qg-2f4p/GHSA-m2x6-82qg-2f4p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2x6-82qg-2f4p", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54316" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NicheAddons Restaurant & Cafe Addon for Elementor allows DOM-Based XSS.This issue affects Restaurant & Cafe Addon for Elementor: from n/a through 1.5.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54316" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/restaurant-cafe-addon-for-elementor/vulnerability/wordpress-restaurant-cafe-addon-for-elementor-plugin-1-5-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m3vm-c2qr-hmgv/GHSA-m3vm-c2qr-hmgv.json b/advisories/unreviewed/2024/12/GHSA-m3vm-c2qr-hmgv/GHSA-m3vm-c2qr-hmgv.json new file mode 100644 index 00000000000..f5076c62ae2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m3vm-c2qr-hmgv/GHSA-m3vm-c2qr-hmgv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3vm-c2qr-hmgv", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54259" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DELUCKS GmbH DELUCKS SEO allows Path Traversal.This issue affects DELUCKS SEO: from n/a through 2.5.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54259" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/delucks-seo/vulnerability/wordpress-delucks-seo-plugin-2-5-5-arbitrary-file-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m566-3ffq-743v/GHSA-m566-3ffq-743v.json b/advisories/unreviewed/2024/12/GHSA-m566-3ffq-743v/GHSA-m566-3ffq-743v.json new file mode 100644 index 00000000000..e7268ead30b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m566-3ffq-743v/GHSA-m566-3ffq-743v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m566-3ffq-743v", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-35052" + ], + "details": "Missing Authorization vulnerability in wpWax - WP Business Directory Plugin and Classified Listings Directory Directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through 7.5.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35052" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/directorist/vulnerability/wordpress-directorist-plugin-7-5-4-arbitrary-content-deletion?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m97w-3mvr-4h42/GHSA-m97w-3mvr-4h42.json b/advisories/unreviewed/2024/12/GHSA-m97w-3mvr-4h42/GHSA-m97w-3mvr-4h42.json new file mode 100644 index 00000000000..4789904be67 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m97w-3mvr-4h42/GHSA-m97w-3mvr-4h42.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m97w-3mvr-4h42", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54325" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DealerTrend CarDealerPress allows Reflected XSS.This issue affects CarDealerPress: from n/a through 6.6.2410.02.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54325" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cardealerpress/vulnerability/wordpress-cardealerpress-plugin-6-6-2410-02-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m9cr-g8p8-8x4r/GHSA-m9cr-g8p8-8x4r.json b/advisories/unreviewed/2024/12/GHSA-m9cr-g8p8-8x4r/GHSA-m9cr-g8p8-8x4r.json new file mode 100644 index 00000000000..21fec22dfff --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m9cr-g8p8-8x4r/GHSA-m9cr-g8p8-8x4r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9cr-g8p8-8x4r", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-40003" + ], + "details": "Missing Authorization vulnerability in weDevs WP Project Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Project Manager: from n/a through 2.6.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40003" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wedevs-project-manager/vulnerability/wordpress-wp-project-manager-plugin-2-6-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m9q2-px3p-j8fg/GHSA-m9q2-px3p-j8fg.json b/advisories/unreviewed/2024/12/GHSA-m9q2-px3p-j8fg/GHSA-m9q2-px3p-j8fg.json new file mode 100644 index 00000000000..4e091294c9d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m9q2-px3p-j8fg/GHSA-m9q2-px3p-j8fg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9q2-px3p-j8fg", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54286" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sendsmaily LLC Smaily for WP allows Stored XSS.This issue affects Smaily for WP: from n/a through 3.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54286" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/smaily-for-wp/vulnerability/wordpress-smaily-for-wp-plugin-3-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mcjp-gvrf-fpxw/GHSA-mcjp-gvrf-fpxw.json b/advisories/unreviewed/2024/12/GHSA-mcjp-gvrf-fpxw/GHSA-mcjp-gvrf-fpxw.json new file mode 100644 index 00000000000..d508e15571f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mcjp-gvrf-fpxw/GHSA-mcjp-gvrf-fpxw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcjp-gvrf-fpxw", + "modified": "2024-12-13T15:30:45Z", + "published": "2024-12-13T15:30:45Z", + "aliases": [ + "CVE-2024-54347" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BAKKBONE Australia FloristPress allows Reflected XSS.This issue affects FloristPress: from n/a through 7.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54347" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bakkbone-florist-companion/vulnerability/wordpress-floristpress-plugin-7-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mcx7-xrrv-484m/GHSA-mcx7-xrrv-484m.json b/advisories/unreviewed/2024/12/GHSA-mcx7-xrrv-484m/GHSA-mcx7-xrrv-484m.json new file mode 100644 index 00000000000..1788ab59bd0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mcx7-xrrv-484m/GHSA-mcx7-xrrv-484m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcx7-xrrv-484m", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54238" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Colin Tomele Board Document Manager from CHUHPL allows Reflected XSS.This issue affects Board Document Manager from CHUHPL: from n/a through 1.9.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54238" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/board-document-manager-from-chuhpl/vulnerability/wordpress-board-document-manager-from-chuhpl-plugin-1-9-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mgc8-86f4-wh2w/GHSA-mgc8-86f4-wh2w.json b/advisories/unreviewed/2024/12/GHSA-mgc8-86f4-wh2w/GHSA-mgc8-86f4-wh2w.json new file mode 100644 index 00000000000..df4d3e60a61 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mgc8-86f4-wh2w/GHSA-mgc8-86f4-wh2w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgc8-86f4-wh2w", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54233" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Enea Overclokk Advanced Control Manager for WordPress by ItalyStrap allows Reflected XSS.This issue affects Advanced Control Manager for WordPress by ItalyStrap: from n/a through 2.16.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54233" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-control-manager/vulnerability/wordpress-advanced-control-manager-plugin-2-16-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mhcc-425r-jwgv/GHSA-mhcc-425r-jwgv.json b/advisories/unreviewed/2024/12/GHSA-mhcc-425r-jwgv/GHSA-mhcc-425r-jwgv.json new file mode 100644 index 00000000000..cfd5879c0b5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mhcc-425r-jwgv/GHSA-mhcc-425r-jwgv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhcc-425r-jwgv", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-32798" + ], + "details": "Missing Authorization vulnerability in 10up Simple Page Ordering allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Page Ordering: from n/a through 2.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32798" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-page-ordering/vulnerability/wordpress-simple-page-ordering-plugin-2-5-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mpfv-c66g-p7m7/GHSA-mpfv-c66g-p7m7.json b/advisories/unreviewed/2024/12/GHSA-mpfv-c66g-p7m7/GHSA-mpfv-c66g-p7m7.json new file mode 100644 index 00000000000..a96e23f3b2b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mpfv-c66g-p7m7/GHSA-mpfv-c66g-p7m7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpfv-c66g-p7m7", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2022-46811" + ], + "details": "Missing Authorization vulnerability in VillaTheme(villatheme.com) ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce: from n/a through 1.0.21.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46811" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-alidropship/vulnerability/wordpress-ald-dropshipping-and-fulfillment-for-aliexpress-and-woocommerce-plugin-1-0-21-broken-access-control-csrf?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mv8m-8gw4-6jh3/GHSA-mv8m-8gw4-6jh3.json b/advisories/unreviewed/2024/12/GHSA-mv8m-8gw4-6jh3/GHSA-mv8m-8gw4-6jh3.json new file mode 100644 index 00000000000..1525524bfd0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mv8m-8gw4-6jh3/GHSA-mv8m-8gw4-6jh3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv8m-8gw4-6jh3", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-40001" + ], + "details": "Missing Authorization vulnerability in SolidWP iThemes Sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iThemes Sync: from n/a through 2.1.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40001" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ithemes-sync/vulnerability/wordpress-ithemes-sync-plugin-2-1-13-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mvpw-6hhp-gcq9/GHSA-mvpw-6hhp-gcq9.json b/advisories/unreviewed/2024/12/GHSA-mvpw-6hhp-gcq9/GHSA-mvpw-6hhp-gcq9.json new file mode 100644 index 00000000000..361380d097f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mvpw-6hhp-gcq9/GHSA-mvpw-6hhp-gcq9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvpw-6hhp-gcq9", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54310" + ], + "details": "Missing Authorization vulnerability in Aslam Khan Gouran Gou Manage My Account Menu allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Gou Manage My Account Menu: from n/a through 1.0.1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54310" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gou-wc-account-tabs/vulnerability/wordpress-gou-manage-my-account-menu-plugin-1-0-1-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mvr3-fvpv-v5pf/GHSA-mvr3-fvpv-v5pf.json b/advisories/unreviewed/2024/12/GHSA-mvr3-fvpv-v5pf/GHSA-mvr3-fvpv-v5pf.json new file mode 100644 index 00000000000..6781fb10672 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mvr3-fvpv-v5pf/GHSA-mvr3-fvpv-v5pf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvr3-fvpv-v5pf", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-39995" + ], + "details": "Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Portfolio and Projects allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Portfolio and Projects: from n/a through 1.3.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39995" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/portfolio-and-projects/vulnerability/wordpress-portfolio-and-projects-plugin-1-3-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p2rq-8crm-mpff/GHSA-p2rq-8crm-mpff.json b/advisories/unreviewed/2024/12/GHSA-p2rq-8crm-mpff/GHSA-p2rq-8crm-mpff.json new file mode 100644 index 00000000000..ff35f37db07 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p2rq-8crm-mpff/GHSA-p2rq-8crm-mpff.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2rq-8crm-mpff", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54262" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Siddharth Nagar Import Export For WooCommerce allows Upload a Web Shell to a Web Server.This issue affects Import Export For WooCommerce: from n/a through 1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54262" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/import-export-for-woocommerce/vulnerability/wordpress-import-export-for-woocommerce-plugin-1-5-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p3vc-9w4j-j66m/GHSA-p3vc-9w4j-j66m.json b/advisories/unreviewed/2024/12/GHSA-p3vc-9w4j-j66m/GHSA-p3vc-9w4j-j66m.json new file mode 100644 index 00000000000..7cee9195da7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p3vc-9w4j-j66m/GHSA-p3vc-9w4j-j66m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3vc-9w4j-j66m", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-32581" + ], + "details": "Missing Authorization vulnerability in MobileMonkey WP-Chatbot for Messenger allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-Chatbot for Messenger: from n/a through 4.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32581" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-chatbot/vulnerability/wordpress-wp-chatbot-for-messenger-plugin-4-7-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p77r-v683-34m4/GHSA-p77r-v683-34m4.json b/advisories/unreviewed/2024/12/GHSA-p77r-v683-34m4/GHSA-p77r-v683-34m4.json new file mode 100644 index 00000000000..a45ce420095 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p77r-v683-34m4/GHSA-p77r-v683-34m4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p77r-v683-34m4", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-38514" + ], + "details": "Missing Authorization vulnerability in social share pro Social Share Icons & Social Share Buttons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Share Icons & Social Share Buttons: from n/a through 3.5.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38514" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-social-media-plus/vulnerability/wordpress-social-share-icons-social-share-buttons-plugin-3-5-7-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p83f-5g8v-2prf/GHSA-p83f-5g8v-2prf.json b/advisories/unreviewed/2024/12/GHSA-p83f-5g8v-2prf/GHSA-p83f-5g8v-2prf.json new file mode 100644 index 00000000000..0b9a2818319 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p83f-5g8v-2prf/GHSA-p83f-5g8v-2prf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p83f-5g8v-2prf", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54241" + ], + "details": "Missing Authorization vulnerability in Appsbd Elite Notification – Sales Popup, Social Proof, FOMO & WooCommerce Notification allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elite Notification – Sales Popup, Social Proof, FOMO & WooCommerce Notification: from 1.5 through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54241" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/elite-notification/vulnerability/wordpress-elite-notification-plugin-1-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pfw8-vjxx-7qhh/GHSA-pfw8-vjxx-7qhh.json b/advisories/unreviewed/2024/12/GHSA-pfw8-vjxx-7qhh/GHSA-pfw8-vjxx-7qhh.json new file mode 100644 index 00000000000..9ab698ab311 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pfw8-vjxx-7qhh/GHSA-pfw8-vjxx-7qhh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfw8-vjxx-7qhh", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-40011" + ], + "details": "Missing Authorization vulnerability in StylemixThemes Cost Calculator Builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cost Calculator Builder: from n/a through 3.1.42.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40011" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cost-calculator-builder/vulnerability/wordpress-cost-calculator-builder-plugin-3-1-42-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pg94-fqwx-cjcv/GHSA-pg94-fqwx-cjcv.json b/advisories/unreviewed/2024/12/GHSA-pg94-fqwx-cjcv/GHSA-pg94-fqwx-cjcv.json new file mode 100644 index 00000000000..1571d77bdf0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pg94-fqwx-cjcv/GHSA-pg94-fqwx-cjcv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg94-fqwx-cjcv", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2024-22461" + ], + "details": "Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote attacker could potentially exploit this vulnerability by running any command as root, leading to gaining of root-level access and compromise of complete system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22461" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000259765/dsa-2024-429-security-update-for-dell-recoverpoint-for-virtual-machines-multiple-third-party-component-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-phf4-w5j6-499q/GHSA-phf4-w5j6-499q.json b/advisories/unreviewed/2024/12/GHSA-phf4-w5j6-499q/GHSA-phf4-w5j6-499q.json new file mode 100644 index 00000000000..f18208f6940 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-phf4-w5j6-499q/GHSA-phf4-w5j6-499q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phf4-w5j6-499q", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41133" + ], + "details": "Authentication Bypass by Spoofing vulnerability in Michal Novák Secure Admin IP allows Functionality Bypass.This issue affects Secure Admin IP: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41133" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/secure-admin-ip/vulnerability/wordpress-secure-admin-ip-plugin-2-0-ip-spoofing-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-phf6-xcgg-v6v5/GHSA-phf6-xcgg-v6v5.json b/advisories/unreviewed/2024/12/GHSA-phf6-xcgg-v6v5/GHSA-phf6-xcgg-v6v5.json new file mode 100644 index 00000000000..68c97d87e86 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-phf6-xcgg-v6v5/GHSA-phf6-xcgg-v6v5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phf6-xcgg-v6v5", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54272" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RadiusTheme Radius Blocks – WordPress Gutenberg Blocks allows Stored XSS.This issue affects Radius Blocks – WordPress Gutenberg Blocks: from n/a through 2.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54272" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/radius-blocks/vulnerability/wordpress-radius-blocks-plugin-2-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pm7j-cf5m-mq99/GHSA-pm7j-cf5m-mq99.json b/advisories/unreviewed/2024/12/GHSA-pm7j-cf5m-mq99/GHSA-pm7j-cf5m-mq99.json new file mode 100644 index 00000000000..f05aa6c3fe9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pm7j-cf5m-mq99/GHSA-pm7j-cf5m-mq99.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pm7j-cf5m-mq99", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2022-45826" + ], + "details": "Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through 2.9.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45826" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sunshine-photo-cart/vulnerability/wordpress-sunshine-photo-cart-plugin-2-9-13-auth-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pw24-hpqw-cm69/GHSA-pw24-hpqw-cm69.json b/advisories/unreviewed/2024/12/GHSA-pw24-hpqw-cm69/GHSA-pw24-hpqw-cm69.json new file mode 100644 index 00000000000..b803f28f835 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pw24-hpqw-cm69/GHSA-pw24-hpqw-cm69.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw24-hpqw-cm69", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54309" + ], + "details": "Insertion of Sensitive Information Into Sent Data vulnerability in wpdebuglog PostBox allows Retrieve Embedded Sensitive Data.This issue affects PostBox: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54309" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/postbox-email-logs/vulnerability/wordpress-postbox-plugin-1-0-4-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q24w-35fr-jmr7/GHSA-q24w-35fr-jmr7.json b/advisories/unreviewed/2024/12/GHSA-q24w-35fr-jmr7/GHSA-q24w-35fr-jmr7.json new file mode 100644 index 00000000000..7f20fe74890 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q24w-35fr-jmr7/GHSA-q24w-35fr-jmr7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q24w-35fr-jmr7", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54234" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wp-buy Limit Login Attempts allows SQL Injection.This issue affects Limit Login Attempts: from n/a through 5.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54234" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-limit-failed-login-attempts/vulnerability/wordpress-limit-login-attempts-plugin-5-5-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q4j5-q57w-hgq7/GHSA-q4j5-q57w-hgq7.json b/advisories/unreviewed/2024/12/GHSA-q4j5-q57w-hgq7/GHSA-q4j5-q57w-hgq7.json new file mode 100644 index 00000000000..8184886feb9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q4j5-q57w-hgq7/GHSA-q4j5-q57w-hgq7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4j5-q57w-hgq7", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54322" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ederson Peka Media Downloader allows Reflected XSS.This issue affects Media Downloader: from n/a through 0.4.7.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54322" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/media-downloader/vulnerability/wordpress-media-downloader-plugin-0-4-7-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q6jx-59mp-vr6g/GHSA-q6jx-59mp-vr6g.json b/advisories/unreviewed/2024/12/GHSA-q6jx-59mp-vr6g/GHSA-q6jx-59mp-vr6g.json new file mode 100644 index 00000000000..3e92d0e1db9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q6jx-59mp-vr6g/GHSA-q6jx-59mp-vr6g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6jx-59mp-vr6g", + "modified": "2024-12-13T15:30:45Z", + "published": "2024-12-13T15:30:45Z", + "aliases": [ + "CVE-2024-54339" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jbd7 geoFlickr allows Reflected XSS.This issue affects geoFlickr: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54339" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/geoflickr/vulnerability/wordpress-geoflickr-plugin-1-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q6wm-pmrv-qcfw/GHSA-q6wm-pmrv-qcfw.json b/advisories/unreviewed/2024/12/GHSA-q6wm-pmrv-qcfw/GHSA-q6wm-pmrv-qcfw.json new file mode 100644 index 00000000000..3765c70745e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q6wm-pmrv-qcfw/GHSA-q6wm-pmrv-qcfw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6wm-pmrv-qcfw", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-32601" + ], + "details": "Missing Authorization vulnerability in Booking Ultra Pro Booking Ultra Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking Ultra Pro: from n/a through 1.1.12.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32601" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/booking-ultra-pro/vulnerability/wordpress-booking-ultra-pro-appointments-booking-calendar-plugin-plugin-1-1-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q7h3-ggj4-423p/GHSA-q7h3-ggj4-423p.json b/advisories/unreviewed/2024/12/GHSA-q7h3-ggj4-423p/GHSA-q7h3-ggj4-423p.json new file mode 100644 index 00000000000..0297496666d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q7h3-ggj4-423p/GHSA-q7h3-ggj4-423p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7h3-ggj4-423p", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54298" + ], + "details": "Missing Authorization vulnerability in Bill Minozzi Car Dealer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Dealer: from n/a through 4.46.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54298" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cardealer/vulnerability/wordpress-car-dealer-plugin-4-46-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-q966-x4v8-whfm/GHSA-q966-x4v8-whfm.json b/advisories/unreviewed/2024/12/GHSA-q966-x4v8-whfm/GHSA-q966-x4v8-whfm.json new file mode 100644 index 00000000000..8ccf192f735 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-q966-x4v8-whfm/GHSA-q966-x4v8-whfm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q966-x4v8-whfm", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-40213" + ], + "details": "Missing Authorization vulnerability in Mateusz Czardybon Justified Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Justified Gallery: from n/a through 1.7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40213" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/justified-gallery/vulnerability/wordpress-justified-gallery-plugin-1-7-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qp8v-3468-8fwp/GHSA-qp8v-3468-8fwp.json b/advisories/unreviewed/2024/12/GHSA-qp8v-3468-8fwp/GHSA-qp8v-3468-8fwp.json new file mode 100644 index 00000000000..a61b1efd6b6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qp8v-3468-8fwp/GHSA-qp8v-3468-8fwp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp8v-3468-8fwp", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54275" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wibergs Web CSV to html allows Reflected XSS.This issue affects CSV to html: from n/a through 3.04.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54275" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/csv-to-html/vulnerability/wordpress-csv-to-html-plugin-3-04-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qq4x-p2f8-c2j8/GHSA-qq4x-p2f8-c2j8.json b/advisories/unreviewed/2024/12/GHSA-qq4x-p2f8-c2j8/GHSA-qq4x-p2f8-c2j8.json new file mode 100644 index 00000000000..fd3447e2e2e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qq4x-p2f8-c2j8/GHSA-qq4x-p2f8-c2j8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq4x-p2f8-c2j8", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2022-47182" + ], + "details": "Missing Authorization vulnerability in Wpexpertsio APIExperts Square for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects APIExperts Square for WooCommerce: from n/a through 4.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47182" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woosquare/vulnerability/wordpress-apiexperts-square-for-woocommerce-plugin-4-2-5-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qv2x-7mqw-c4mf/GHSA-qv2x-7mqw-c4mf.json b/advisories/unreviewed/2024/12/GHSA-qv2x-7mqw-c4mf/GHSA-qv2x-7mqw-c4mf.json new file mode 100644 index 00000000000..5449baa1b71 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qv2x-7mqw-c4mf/GHSA-qv2x-7mqw-c4mf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv2x-7mqw-c4mf", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-36531" + ], + "details": "Missing Authorization vulnerability in LiquidPoll LiquidPoll – Advanced Polls for Creators and Brands allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LiquidPoll – Advanced Polls for Creators and Brands: from n/a through 3.3.68.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36531" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-poll/vulnerability/wordpress-liquidpoll-advanced-polls-for-creators-and-brands-plugin-3-3-68-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-r235-444x-j59r/GHSA-r235-444x-j59r.json b/advisories/unreviewed/2024/12/GHSA-r235-444x-j59r/GHSA-r235-444x-j59r.json new file mode 100644 index 00000000000..68c1d2f4de9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-r235-444x-j59r/GHSA-r235-444x-j59r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r235-444x-j59r", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-37887" + ], + "details": "Missing Authorization vulnerability in WPSchoolPress Team WPSchoolPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPSchoolPress: from n/a through 2.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37887" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpschoolpress/vulnerability/wordpress-wpschoolpress-plugin-2-2-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-r689-h98v-j38j/GHSA-r689-h98v-j38j.json b/advisories/unreviewed/2024/12/GHSA-r689-h98v-j38j/GHSA-r689-h98v-j38j.json new file mode 100644 index 00000000000..4d13e119134 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-r689-h98v-j38j/GHSA-r689-h98v-j38j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r689-h98v-j38j", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54288" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LDD Web Design LDD Directory Lite allows Reflected XSS.This issue affects LDD Directory Lite: from n/a through 3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54288" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ldd-directory-lite/vulnerability/wordpress-ldd-directory-lite-plugin-3-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rfr4-95g9-6vf3/GHSA-rfr4-95g9-6vf3.json b/advisories/unreviewed/2024/12/GHSA-rfr4-95g9-6vf3/GHSA-rfr4-95g9-6vf3.json index 96a8873d4f3..b70d5de5b03 100644 --- a/advisories/unreviewed/2024/12/GHSA-rfr4-95g9-6vf3/GHSA-rfr4-95g9-6vf3.json +++ b/advisories/unreviewed/2024/12/GHSA-rfr4-95g9-6vf3/GHSA-rfr4-95g9-6vf3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rfr4-95g9-6vf3", - "modified": "2024-12-07T09:30:23Z", + "modified": "2024-12-13T15:30:38Z", "published": "2024-12-07T09:30:23Z", "aliases": [ "CVE-2024-53143" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfsnotify: Fix ordering of iput() and watched_objects decrement\n\nEnsure the superblock is kept alive until we're done with iput().\nHolding a reference to an inode is not allowed unless we ensure the\nsuperblock stays alive, which fsnotify does by keeping the\nwatched_objects count elevated, so iput() must happen before the\nwatched_objects decrement.\nThis can lead to a UAF of something like sb->s_fs_info in tmpfs, but the\nUAF is hard to hit because race orderings that oops are more likely, thanks\nto the CHECK_DATA_CORRUPTION() block in generic_shutdown_super().\n\nAlso, ensure that fsnotify_put_sb_watched_objects() doesn't call\nfsnotify_sb_watched_objects() on a superblock that may have already been\nfreed, which would cause a UAF read of sb->s_fsnotify_info.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-07T07:15:03Z" diff --git a/advisories/unreviewed/2024/12/GHSA-rfx3-q6g4-f3qc/GHSA-rfx3-q6g4-f3qc.json b/advisories/unreviewed/2024/12/GHSA-rfx3-q6g4-f3qc/GHSA-rfx3-q6g4-f3qc.json new file mode 100644 index 00000000000..dd88286406a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rfx3-q6g4-f3qc/GHSA-rfx3-q6g4-f3qc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfx3-q6g4-f3qc", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54289" + ], + "details": "Missing Authorization vulnerability in Awesome Support Team Awesome Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through 6.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54289" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/awesome-support/vulnerability/wordpress-awesome-support-plugin-6-3-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-rrj2-pjjj-cxf2/GHSA-rrj2-pjjj-cxf2.json b/advisories/unreviewed/2024/12/GHSA-rrj2-pjjj-cxf2/GHSA-rrj2-pjjj-cxf2.json new file mode 100644 index 00000000000..abbe0f5a95b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-rrj2-pjjj-cxf2/GHSA-rrj2-pjjj-cxf2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrj2-pjjj-cxf2", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-28990" + ], + "details": "Missing Authorization vulnerability in HashThemes Viral Mag allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Viral Mag: from n/a through 1.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28990" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/viral-mag/vulnerability/wordpress-viral-mag-theme-1-0-9-authenticated-arbitrary-plugin-activation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v2q3-j5hx-299f/GHSA-v2q3-j5hx-299f.json b/advisories/unreviewed/2024/12/GHSA-v2q3-j5hx-299f/GHSA-v2q3-j5hx-299f.json new file mode 100644 index 00000000000..e264c3ce4fe --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v2q3-j5hx-299f/GHSA-v2q3-j5hx-299f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2q3-j5hx-299f", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2022-46838" + ], + "details": "Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46838" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/js-support-ticket/vulnerability/wordpress-js-help-desk-plugin-2-7-1-unauthenticated-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v3h6-g82x-p5vm/GHSA-v3h6-g82x-p5vm.json b/advisories/unreviewed/2024/12/GHSA-v3h6-g82x-p5vm/GHSA-v3h6-g82x-p5vm.json new file mode 100644 index 00000000000..5f8d7d00be3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v3h6-g82x-p5vm/GHSA-v3h6-g82x-p5vm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3h6-g82x-p5vm", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-47984" + ], + "details": "Dell RecoverPoint for Virtual Machines 6.0.x contains Denial of Service vulnerability. A User with Remote access could potentially exploit this vulnerability, leading to the disruption of most functionalities of the RPA persistent after reboot, resulting in need of technical support intervention in getting system back to stable state.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47984" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000259765/dsa-2024-429-security-update-for-dell-recoverpoint-for-virtual-machines-multiple-third-party-component-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-790" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v7m3-w6pr-q332/GHSA-v7m3-w6pr-q332.json b/advisories/unreviewed/2024/12/GHSA-v7m3-w6pr-q332/GHSA-v7m3-w6pr-q332.json new file mode 100644 index 00000000000..e0dcc945c01 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v7m3-w6pr-q332/GHSA-v7m3-w6pr-q332.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7m3-w6pr-q332", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-40334" + ], + "details": "Missing Authorization vulnerability in realmag777 HUSKY allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HUSKY: from n/a through 1.3.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40334" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-products-filter/vulnerability/wordpress-husky-products-filter-for-woocommerce-professional-plugin-1-3-4-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-v9v6-vggf-mfmf/GHSA-v9v6-vggf-mfmf.json b/advisories/unreviewed/2024/12/GHSA-v9v6-vggf-mfmf/GHSA-v9v6-vggf-mfmf.json new file mode 100644 index 00000000000..fb44e7fead1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-v9v6-vggf-mfmf/GHSA-v9v6-vggf-mfmf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9v6-vggf-mfmf", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41866" + ], + "details": "Missing Authorization vulnerability in Team Plugins360 Automatic YouTube Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automatic YouTube Gallery: from n/a through 2.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41866" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/automatic-youtube-gallery/vulnerability/wordpress-automatic-youtube-gallery-plugin-2-3-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vf63-29qv-79ch/GHSA-vf63-29qv-79ch.json b/advisories/unreviewed/2024/12/GHSA-vf63-29qv-79ch/GHSA-vf63-29qv-79ch.json new file mode 100644 index 00000000000..3bfeaf91416 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vf63-29qv-79ch/GHSA-vf63-29qv-79ch.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vf63-29qv-79ch", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41132" + ], + "details": "Missing Authorization vulnerability in ShapedPlugin LLC Category Slider for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Category Slider for WooCommerce: from n/a through 1.4.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41132" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-category-slider-grid/vulnerability/wordpress-category-slider-for-woocommerce-plugin-1-4-15-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vgwh-f2ch-gh4f/GHSA-vgwh-f2ch-gh4f.json b/advisories/unreviewed/2024/12/GHSA-vgwh-f2ch-gh4f/GHSA-vgwh-f2ch-gh4f.json new file mode 100644 index 00000000000..4b218542fdf --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vgwh-f2ch-gh4f/GHSA-vgwh-f2ch-gh4f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgwh-f2ch-gh4f", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-32574" + ], + "details": "Missing Authorization vulnerability in Fahad Mahmood Injection Guard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Injection Guard: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32574" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/injection-guard/vulnerability/wordpress-injection-guard-plugin-1-2-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vpgj-6w52-7hjj/GHSA-vpgj-6w52-7hjj.json b/advisories/unreviewed/2024/12/GHSA-vpgj-6w52-7hjj/GHSA-vpgj-6w52-7hjj.json new file mode 100644 index 00000000000..1f375653b50 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vpgj-6w52-7hjj/GHSA-vpgj-6w52-7hjj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpgj-6w52-7hjj", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2022-47168" + ], + "details": "Missing Authorization vulnerability in Printful Printful Integration for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Printful Integration for WooCommerce: from n/a through 2.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47168" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/printful-shipping-for-woocommerce/vulnerability/wordpress-printful-integration-for-woocommerce-plugin-2-2-2-cross-site-request-forgery-csrf?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vpxj-44mq-4f7v/GHSA-vpxj-44mq-4f7v.json b/advisories/unreviewed/2024/12/GHSA-vpxj-44mq-4f7v/GHSA-vpxj-44mq-4f7v.json new file mode 100644 index 00000000000..9d0f5a1ee18 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vpxj-44mq-4f7v/GHSA-vpxj-44mq-4f7v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpxj-44mq-4f7v", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-32586" + ], + "details": "Missing Authorization vulnerability in Thomas Michalak Soundcloud Is Gold allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Soundcloud Is Gold: from n/a through 2.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32586" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/soundcloud-is-gold/vulnerability/wordpress-soundcloud-is-gold-plugin-2-5-1-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vqr4-g336-pjh8/GHSA-vqr4-g336-pjh8.json b/advisories/unreviewed/2024/12/GHSA-vqr4-g336-pjh8/GHSA-vqr4-g336-pjh8.json new file mode 100644 index 00000000000..7c29df52474 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vqr4-g336-pjh8/GHSA-vqr4-g336-pjh8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqr4-g336-pjh8", + "modified": "2024-12-13T15:30:45Z", + "published": "2024-12-13T15:30:45Z", + "aliases": [ + "CVE-2024-54338" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Christer Fernstrom Hello Event Widgets For Elementor allows DOM-Based XSS.This issue affects Hello Event Widgets For Elementor: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54338" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hello-event-widgets-for-elementor/vulnerability/wordpress-hello-event-widgets-for-elementor-plugin-1-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vvjx-vqg4-qv57/GHSA-vvjx-vqg4-qv57.json b/advisories/unreviewed/2024/12/GHSA-vvjx-vqg4-qv57/GHSA-vvjx-vqg4-qv57.json new file mode 100644 index 00000000000..abcddd1d74f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vvjx-vqg4-qv57/GHSA-vvjx-vqg4-qv57.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvjx-vqg4-qv57", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-40670" + ], + "details": "Missing Authorization vulnerability in ReviewX Team ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.17.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40670" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/reviewx/vulnerability/wordpress-reviewx-plugin-1-6-17-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vwj4-qq98-x49w/GHSA-vwj4-qq98-x49w.json b/advisories/unreviewed/2024/12/GHSA-vwj4-qq98-x49w/GHSA-vwj4-qq98-x49w.json new file mode 100644 index 00000000000..1b37b7b258b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vwj4-qq98-x49w/GHSA-vwj4-qq98-x49w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwj4-qq98-x49w", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-32506" + ], + "details": "Missing Authorization vulnerability in Link Whisper Link Whisper Free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Link Whisper Free: from n/a through 0.6.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32506" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/link-whisper/vulnerability/wordpress-link-whisper-free-plugin-0-6-3-unauthenticated-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vx4r-9ggh-9499/GHSA-vx4r-9ggh-9499.json b/advisories/unreviewed/2024/12/GHSA-vx4r-9ggh-9499/GHSA-vx4r-9ggh-9499.json new file mode 100644 index 00000000000..53113f73659 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vx4r-9ggh-9499/GHSA-vx4r-9ggh-9499.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx4r-9ggh-9499", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41671" + ], + "details": "Missing Authorization vulnerability in Tyche Softwares Abandoned Cart Lite for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Abandoned Cart Lite for WooCommerce: from n/a through 5.16.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41671" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-abandoned-cart/vulnerability/wordpress-abandoned-cart-lite-for-woocommerce-plugin-5-16-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w2c6-mxqg-rgx9/GHSA-w2c6-mxqg-rgx9.json b/advisories/unreviewed/2024/12/GHSA-w2c6-mxqg-rgx9/GHSA-w2c6-mxqg-rgx9.json new file mode 100644 index 00000000000..c7fcb07a648 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w2c6-mxqg-rgx9/GHSA-w2c6-mxqg-rgx9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2c6-mxqg-rgx9", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54267" + ], + "details": "Missing Authorization vulnerability in CreativeMindsSolutions CM Answers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CM Answers: from n/a through 3.2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54267" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cm-answers/vulnerability/wordpress-cm-answers-plugin-3-2-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w3f7-gqrp-cccw/GHSA-w3f7-gqrp-cccw.json b/advisories/unreviewed/2024/12/GHSA-w3f7-gqrp-cccw/GHSA-w3f7-gqrp-cccw.json new file mode 100644 index 00000000000..5346532dfec --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w3f7-gqrp-cccw/GHSA-w3f7-gqrp-cccw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3f7-gqrp-cccw", + "modified": "2024-12-13T15:30:43Z", + "published": "2024-12-13T15:30:43Z", + "aliases": [ + "CVE-2024-54268" + ], + "details": "Missing Authorization vulnerability in SiteOrigin SiteOrigin Widgets Bundle allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SiteOrigin Widgets Bundle: from n/a through 1.64.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54268" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/so-widgets-bundle/vulnerability/wordpress-siteorigin-widgets-bundle-plugin-1-64-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w3p6-hxv6-48rg/GHSA-w3p6-hxv6-48rg.json b/advisories/unreviewed/2024/12/GHSA-w3p6-hxv6-48rg/GHSA-w3p6-hxv6-48rg.json new file mode 100644 index 00000000000..9de3716352f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w3p6-hxv6-48rg/GHSA-w3p6-hxv6-48rg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3p6-hxv6-48rg", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-32507" + ], + "details": "Missing Authorization vulnerability in wp3sixty Woo Custom Emails allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woo Custom Emails: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32507" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-custom-emails/vulnerability/wordpress-woo-custom-emails-plugin-2-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w43h-737f-6x4q/GHSA-w43h-737f-6x4q.json b/advisories/unreviewed/2024/12/GHSA-w43h-737f-6x4q/GHSA-w43h-737f-6x4q.json new file mode 100644 index 00000000000..80d5cdf3b7d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w43h-737f-6x4q/GHSA-w43h-737f-6x4q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w43h-737f-6x4q", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-37987" + ], + "details": "Missing Authorization vulnerability in miniOrange YourMembership Single Sign On allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YourMembership Single Sign On: from n/a through 1.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37987" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/login-with-yourmembership/vulnerability/wordpress-yourmembership-single-sign-on-plugin-1-1-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w46h-pcjm-w7gc/GHSA-w46h-pcjm-w7gc.json b/advisories/unreviewed/2024/12/GHSA-w46h-pcjm-w7gc/GHSA-w46h-pcjm-w7gc.json new file mode 100644 index 00000000000..f08269240af --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w46h-pcjm-w7gc/GHSA-w46h-pcjm-w7gc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w46h-pcjm-w7gc", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41865" + ], + "details": "Missing Authorization vulnerability in bqworks Slider Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slider Pro: from n/a through 4.8.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41865" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sliderpro/vulnerability/wordpress-slider-pro-plugin-4-8-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w4r8-222j-w435/GHSA-w4r8-222j-w435.json b/advisories/unreviewed/2024/12/GHSA-w4r8-222j-w435/GHSA-w4r8-222j-w435.json new file mode 100644 index 00000000000..aa0086b5b00 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w4r8-222j-w435/GHSA-w4r8-222j-w435.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4r8-222j-w435", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-39305" + ], + "details": "Missing Authorization vulnerability in YetAnotherStarsRating.com Yet Another Stars Rating allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Yet Another Stars Rating: from n/a through 3.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39305" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/yet-another-stars-rating/vulnerability/wordpress-yet-another-stars-rating-plugin-3-4-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w8q9-2fwm-j44j/GHSA-w8q9-2fwm-j44j.json b/advisories/unreviewed/2024/12/GHSA-w8q9-2fwm-j44j/GHSA-w8q9-2fwm-j44j.json new file mode 100644 index 00000000000..caa6cc23836 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w8q9-2fwm-j44j/GHSA-w8q9-2fwm-j44j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8q9-2fwm-j44j", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41803" + ], + "details": "Missing Authorization vulnerability in BitPay BitPay Checkout for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BitPay Checkout for WooCommerce: from n/a through 4.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41803" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bitpay-checkout-for-woocommerce/vulnerability/wordpress-bitpay-checkout-for-woocommerce-plugin-4-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w9vc-q9hh-6g37/GHSA-w9vc-q9hh-6g37.json b/advisories/unreviewed/2024/12/GHSA-w9vc-q9hh-6g37/GHSA-w9vc-q9hh-6g37.json new file mode 100644 index 00000000000..7a6744b46a7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w9vc-q9hh-6g37/GHSA-w9vc-q9hh-6g37.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9vc-q9hh-6g37", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-37984" + ], + "details": "Missing Authorization vulnerability in ExpressTech Quiz And Survey Master allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through 8.1.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37984" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quiz-master-next/vulnerability/wordpress-quiz-and-survey-master-plugin-8-1-10-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wf5h-h44v-7hcj/GHSA-wf5h-h44v-7hcj.json b/advisories/unreviewed/2024/12/GHSA-wf5h-h44v-7hcj/GHSA-wf5h-h44v-7hcj.json new file mode 100644 index 00000000000..f11011430fb --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wf5h-h44v-7hcj/GHSA-wf5h-h44v-7hcj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wf5h-h44v-7hcj", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-40678" + ], + "details": "Missing Authorization vulnerability in Lasso Simple URLs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple URLs: from n/a through 117.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40678" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-urls/vulnerability/wordpress-simple-urls-plugin-117-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wgqm-vc4g-q5f9/GHSA-wgqm-vc4g-q5f9.json b/advisories/unreviewed/2024/12/GHSA-wgqm-vc4g-q5f9/GHSA-wgqm-vc4g-q5f9.json new file mode 100644 index 00000000000..d77bff0e1ac --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wgqm-vc4g-q5f9/GHSA-wgqm-vc4g-q5f9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgqm-vc4g-q5f9", + "modified": "2024-12-13T15:30:42Z", + "published": "2024-12-13T15:30:42Z", + "aliases": [ + "CVE-2023-41689" + ], + "details": "Missing Authorization vulnerability in Koen Reus Post to Google My Business (Google Business Profile) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post to Google My Business (Google Business Profile): from n/a through 3.1.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41689" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/post-to-google-my-business/vulnerability/wordpress-post-to-google-my-business-google-business-profile-plugin-3-1-14-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wm3h-3hjp-64v8/GHSA-wm3h-3hjp-64v8.json b/advisories/unreviewed/2024/12/GHSA-wm3h-3hjp-64v8/GHSA-wm3h-3hjp-64v8.json new file mode 100644 index 00000000000..0e3baabe5ea --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wm3h-3hjp-64v8/GHSA-wm3h-3hjp-64v8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm3h-3hjp-64v8", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-36509" + ], + "details": "Missing Authorization vulnerability in Suresh Chand CHP Ads Block Detector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CHP Ads Block Detector: from n/a through 3.9.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36509" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/chp-ads-block-detector/vulnerability/wordpress-chp-ads-block-detector-plugin-3-9-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wmmf-jh7w-h9g8/GHSA-wmmf-jh7w-h9g8.json b/advisories/unreviewed/2024/12/GHSA-wmmf-jh7w-h9g8/GHSA-wmmf-jh7w-h9g8.json new file mode 100644 index 00000000000..91fbf29ebc8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wmmf-jh7w-h9g8/GHSA-wmmf-jh7w-h9g8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmmf-jh7w-h9g8", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-32963" + ], + "details": "Missing Authorization vulnerability in a3rev Software WooCommerce Predictive Search allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Predictive Search: from n/a through 5.8.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32963" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-predictive-search/vulnerability/wordpress-predictive-search-for-woocommerce-plugin-5-8-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wqxm-mxc5-6f58/GHSA-wqxm-mxc5-6f58.json b/advisories/unreviewed/2024/12/GHSA-wqxm-mxc5-6f58/GHSA-wqxm-mxc5-6f58.json new file mode 100644 index 00000000000..2cd27ccb3dc --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wqxm-mxc5-6f58/GHSA-wqxm-mxc5-6f58.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqxm-mxc5-6f58", + "modified": "2024-12-13T15:30:39Z", + "published": "2024-12-13T15:30:39Z", + "aliases": [ + "CVE-2022-46796" + ], + "details": "Missing Authorization vulnerability in VillaTheme CURCY allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CURCY: from n/a through 2.1.25.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46796" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-multi-currency/vulnerability/wordpress-curcy-plugin-2-1-25-unauthenticated-plugin-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x6c9-29w5-8r88/GHSA-x6c9-29w5-8r88.json b/advisories/unreviewed/2024/12/GHSA-x6c9-29w5-8r88/GHSA-x6c9-29w5-8r88.json new file mode 100644 index 00000000000..25ef8c36600 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x6c9-29w5-8r88/GHSA-x6c9-29w5-8r88.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6c9-29w5-8r88", + "modified": "2024-12-13T15:30:45Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54329" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metup s.r.l. CleverNode Related Content allows Reflected XSS.This issue affects CleverNode Related Content: from n/a through 1.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54329" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/clevernode-related-content/vulnerability/wordpress-clevernode-related-content-plugin-1-1-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x764-r7rr-qvx4/GHSA-x764-r7rr-qvx4.json b/advisories/unreviewed/2024/12/GHSA-x764-r7rr-qvx4/GHSA-x764-r7rr-qvx4.json new file mode 100644 index 00000000000..1485114fb3e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x764-r7rr-qvx4/GHSA-x764-r7rr-qvx4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x764-r7rr-qvx4", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-35875" + ], + "details": "Missing Authorization vulnerability in Jegstudio Gutenverse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse: from n/a through 1.8.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35875" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gutenverse/vulnerability/wordpress-gutenverse-gutenberg-blocks-page-builder-for-site-editor-plugin-1-8-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x9w4-cxmc-832m/GHSA-x9w4-cxmc-832m.json b/advisories/unreviewed/2024/12/GHSA-x9w4-cxmc-832m/GHSA-x9w4-cxmc-832m.json new file mode 100644 index 00000000000..e33f7ae9ce9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x9w4-cxmc-832m/GHSA-x9w4-cxmc-832m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9w4-cxmc-832m", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54313" + ], + "details": "Path Traversal vulnerability in FULL. FULL Customer allows Path Traversal.This issue affects FULL Customer: from n/a through 3.1.25.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54313" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/full-customer/vulnerability/wordpress-full-cliente-plugin-3-1-25-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xf3c-5p5c-grm3/GHSA-xf3c-5p5c-grm3.json b/advisories/unreviewed/2024/12/GHSA-xf3c-5p5c-grm3/GHSA-xf3c-5p5c-grm3.json new file mode 100644 index 00000000000..4510e909207 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xf3c-5p5c-grm3/GHSA-xf3c-5p5c-grm3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xf3c-5p5c-grm3", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-25988" + ], + "details": "Missing Authorization vulnerability in Video Gallery by Total-Soft Video Gallery – YouTube Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Video Gallery – YouTube Gallery: from n/a through 1.7.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25988" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gallery-videos/vulnerability/wordpress-video-gallery-youtube-gallery-plugin-1-7-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xgc5-wm9v-rqr3/GHSA-xgc5-wm9v-rqr3.json b/advisories/unreviewed/2024/12/GHSA-xgc5-wm9v-rqr3/GHSA-xgc5-wm9v-rqr3.json new file mode 100644 index 00000000000..6bb526e7334 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xgc5-wm9v-rqr3/GHSA-xgc5-wm9v-rqr3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgc5-wm9v-rqr3", + "modified": "2024-12-13T15:30:45Z", + "published": "2024-12-13T15:30:45Z", + "aliases": [ + "CVE-2024-54330" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Hep Hep Hurra (HHH) Hurrakify allows Server Side Request Forgery.This issue affects Hurrakify: from n/a through 2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54330" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hurrakify/vulnerability/wordpress-hurrakify-plugin-2-4-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xjg4-367c-227h/GHSA-xjg4-367c-227h.json b/advisories/unreviewed/2024/12/GHSA-xjg4-367c-227h/GHSA-xjg4-367c-227h.json new file mode 100644 index 00000000000..6def2cf6c09 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xjg4-367c-227h/GHSA-xjg4-367c-227h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjg4-367c-227h", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54294" + ], + "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in appgenixinfotech Firebase OTP Authentication allows Authentication Bypass.This issue affects Firebase OTP Authentication: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54294" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/authentication-via-otp-using-firebase/vulnerability/wordpress-firebase-otp-authentication-plugin-1-0-1-account-takeover-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xqrr-554w-8mch/GHSA-xqrr-554w-8mch.json b/advisories/unreviewed/2024/12/GHSA-xqrr-554w-8mch/GHSA-xqrr-554w-8mch.json new file mode 100644 index 00000000000..c111d1ad76a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xqrr-554w-8mch/GHSA-xqrr-554w-8mch.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqrr-554w-8mch", + "modified": "2024-12-13T15:30:45Z", + "published": "2024-12-13T15:30:45Z", + "aliases": [ + "CVE-2024-54342" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in STAGGS Staggs Product Configurator for WooCommerce allows Reflected XSS.This issue affects Staggs Product Configurator for WooCommerce: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54342" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/staggs/vulnerability/wordpress-staggs-plugin-2-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xrx7-h3p9-h3r6/GHSA-xrx7-h3p9-h3r6.json b/advisories/unreviewed/2024/12/GHSA-xrx7-h3p9-h3r6/GHSA-xrx7-h3p9-h3r6.json new file mode 100644 index 00000000000..64f8b2137ee --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xrx7-h3p9-h3r6/GHSA-xrx7-h3p9-h3r6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrx7-h3p9-h3r6", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-33996" + ], + "details": "Missing Authorization vulnerability in СleanTalk - Anti-Spam Protection Spam protection, AntiSpam, FireWall by CleanTalk allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spam protection, AntiSpam, FireWall by CleanTalk: from n/a through 6.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33996" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cleantalk-spam-protect/vulnerability/wordpress-spam-protection-antispam-firewall-by-cleantalk-plugin-6-10-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xv6r-vqm4-6f6r/GHSA-xv6r-vqm4-6f6r.json b/advisories/unreviewed/2024/12/GHSA-xv6r-vqm4-6f6r/GHSA-xv6r-vqm4-6f6r.json new file mode 100644 index 00000000000..5bc7e9a0c66 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xv6r-vqm4-6f6r/GHSA-xv6r-vqm4-6f6r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv6r-vqm4-6f6r", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54317" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Google Web Stories allows Stored XSS.This issue affects Web Stories: from n/a through 1.37.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54317" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/web-stories/vulnerability/wordpress-web-stories-plugin-1-37-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xvwj-v9pv-cwjj/GHSA-xvwj-v9pv-cwjj.json b/advisories/unreviewed/2024/12/GHSA-xvwj-v9pv-cwjj/GHSA-xvwj-v9pv-cwjj.json new file mode 100644 index 00000000000..802c4ad6417 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xvwj-v9pv-cwjj/GHSA-xvwj-v9pv-cwjj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvwj-v9pv-cwjj", + "modified": "2024-12-13T15:30:45Z", + "published": "2024-12-13T15:30:45Z", + "aliases": [ + "CVE-2024-54349" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mashiurz.com Plain Post allows Stored XSS.This issue affects Plain Post: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54349" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/plain-post/vulnerability/wordpress-plain-post-plugin-1-0-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xw29-mcqh-6v78/GHSA-xw29-mcqh-6v78.json b/advisories/unreviewed/2024/12/GHSA-xw29-mcqh-6v78/GHSA-xw29-mcqh-6v78.json new file mode 100644 index 00000000000..e14419df9e6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xw29-mcqh-6v78/GHSA-xw29-mcqh-6v78.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw29-mcqh-6v78", + "modified": "2024-12-13T15:30:40Z", + "published": "2024-12-13T15:30:40Z", + "aliases": [ + "CVE-2023-34014" + ], + "details": "Missing Authorization vulnerability in G5Theme Grid Plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grid Plus: from n/a through 1.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34014" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/grid-plus/vulnerability/wordpress-grid-plus-plugin-1-3-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xx6h-c2fx-v78f/GHSA-xx6h-c2fx-v78f.json b/advisories/unreviewed/2024/12/GHSA-xx6h-c2fx-v78f/GHSA-xx6h-c2fx-v78f.json new file mode 100644 index 00000000000..59ad3179240 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xx6h-c2fx-v78f/GHSA-xx6h-c2fx-v78f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xx6h-c2fx-v78f", + "modified": "2024-12-13T15:30:41Z", + "published": "2024-12-13T15:30:41Z", + "aliases": [ + "CVE-2023-38383" + ], + "details": "Missing Authorization vulnerability in OnTheGoSystems Language allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Language: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38383" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wordpress-language/vulnerability/wordpress-wordpress-language-plugin-1-2-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xxcf-46fg-r5q4/GHSA-xxcf-46fg-r5q4.json b/advisories/unreviewed/2024/12/GHSA-xxcf-46fg-r5q4/GHSA-xxcf-46fg-r5q4.json new file mode 100644 index 00000000000..71ac7ccdc7a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xxcf-46fg-r5q4/GHSA-xxcf-46fg-r5q4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxcf-46fg-r5q4", + "modified": "2024-12-13T15:30:44Z", + "published": "2024-12-13T15:30:44Z", + "aliases": [ + "CVE-2024-54327" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in universam UNIVERSAM allows Reflected XSS.This issue affects UNIVERSAM: from n/a through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54327" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/universam-demo/vulnerability/wordpress-universam-plugin-8-59-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-13T15:15:39Z" + } +} \ No newline at end of file