diff --git a/advisories/unreviewed/2022/05/GHSA-mmm5-f82c-58j8/GHSA-mmm5-f82c-58j8.json b/advisories/unreviewed/2022/05/GHSA-mmm5-f82c-58j8/GHSA-mmm5-f82c-58j8.json index 9e9f59b8450..611e2985555 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmm5-f82c-58j8/GHSA-mmm5-f82c-58j8.json +++ b/advisories/unreviewed/2022/05/GHSA-mmm5-f82c-58j8/GHSA-mmm5-f82c-58j8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mmm5-f82c-58j8", - "modified": "2022-05-24T19:01:29Z", + "modified": "2025-01-24T18:31:04Z", "published": "2022-05-24T19:01:29Z", "aliases": [ "CVE-2021-32030" ], "details": "The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handle_request in router/httpd/httpd.c and auth_check in web_hook.o. An attacker-supplied value of '\\0' matches the device's default value of '\\0' in some situations.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,6 +26,10 @@ { "type": "WEB", "url": "https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/ASUS-Gaming-Routers/RT-AC2900/HelpDesk_BIOS" + }, + { + "type": "WEB", + "url": "https://www.atredis.com/blog/2021/4/30/asus-authentication-bypass" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/05/GHSA-3q6h-q44p-xw88/GHSA-3q6h-q44p-xw88.json b/advisories/unreviewed/2023/05/GHSA-3q6h-q44p-xw88/GHSA-3q6h-q44p-xw88.json index 964c6c308f9..050f78c03cd 100644 --- a/advisories/unreviewed/2023/05/GHSA-3q6h-q44p-xw88/GHSA-3q6h-q44p-xw88.json +++ b/advisories/unreviewed/2023/05/GHSA-3q6h-q44p-xw88/GHSA-3q6h-q44p-xw88.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-66wf-rqpr-jpx7/GHSA-66wf-rqpr-jpx7.json b/advisories/unreviewed/2023/05/GHSA-66wf-rqpr-jpx7/GHSA-66wf-rqpr-jpx7.json index a4befb33053..68a74201468 100644 --- a/advisories/unreviewed/2023/05/GHSA-66wf-rqpr-jpx7/GHSA-66wf-rqpr-jpx7.json +++ b/advisories/unreviewed/2023/05/GHSA-66wf-rqpr-jpx7/GHSA-66wf-rqpr-jpx7.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-7p8r-xg5m-xgx8/GHSA-7p8r-xg5m-xgx8.json b/advisories/unreviewed/2023/05/GHSA-7p8r-xg5m-xgx8/GHSA-7p8r-xg5m-xgx8.json index 38c127d063a..e77105e6f0a 100644 --- a/advisories/unreviewed/2023/05/GHSA-7p8r-xg5m-xgx8/GHSA-7p8r-xg5m-xgx8.json +++ b/advisories/unreviewed/2023/05/GHSA-7p8r-xg5m-xgx8/GHSA-7p8r-xg5m-xgx8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-209" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-7qhm-5mxq-x7vp/GHSA-7qhm-5mxq-x7vp.json b/advisories/unreviewed/2023/05/GHSA-7qhm-5mxq-x7vp/GHSA-7qhm-5mxq-x7vp.json index 17e4faa0c00..2d9a7774d2c 100644 --- a/advisories/unreviewed/2023/05/GHSA-7qhm-5mxq-x7vp/GHSA-7qhm-5mxq-x7vp.json +++ b/advisories/unreviewed/2023/05/GHSA-7qhm-5mxq-x7vp/GHSA-7qhm-5mxq-x7vp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7qhm-5mxq-x7vp", - "modified": "2024-04-04T04:02:39Z", + "modified": "2025-01-24T18:31:05Z", "published": "2023-05-11T18:30:17Z", "aliases": [ "CVE-2023-24540" @@ -34,11 +34,16 @@ { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2023-1752" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241115-0008" } ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-77" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-c9hr-fvm9-7c49/GHSA-c9hr-fvm9-7c49.json b/advisories/unreviewed/2023/05/GHSA-c9hr-fvm9-7c49/GHSA-c9hr-fvm9-7c49.json index f5c3d77adbb..5147681c4e1 100644 --- a/advisories/unreviewed/2023/05/GHSA-c9hr-fvm9-7c49/GHSA-c9hr-fvm9-7c49.json +++ b/advisories/unreviewed/2023/05/GHSA-c9hr-fvm9-7c49/GHSA-c9hr-fvm9-7c49.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-f7h3-xrj3-8hhr/GHSA-f7h3-xrj3-8hhr.json b/advisories/unreviewed/2023/05/GHSA-f7h3-xrj3-8hhr/GHSA-f7h3-xrj3-8hhr.json index d590565728e..336f3d26c3d 100644 --- a/advisories/unreviewed/2023/05/GHSA-f7h3-xrj3-8hhr/GHSA-f7h3-xrj3-8hhr.json +++ b/advisories/unreviewed/2023/05/GHSA-f7h3-xrj3-8hhr/GHSA-f7h3-xrj3-8hhr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-h5cm-gwjx-3qq9/GHSA-h5cm-gwjx-3qq9.json b/advisories/unreviewed/2023/05/GHSA-h5cm-gwjx-3qq9/GHSA-h5cm-gwjx-3qq9.json index 32427f24fdf..ffc23c8884b 100644 --- a/advisories/unreviewed/2023/05/GHSA-h5cm-gwjx-3qq9/GHSA-h5cm-gwjx-3qq9.json +++ b/advisories/unreviewed/2023/05/GHSA-h5cm-gwjx-3qq9/GHSA-h5cm-gwjx-3qq9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-754" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-hf25-hwqc-v6g2/GHSA-hf25-hwqc-v6g2.json b/advisories/unreviewed/2023/05/GHSA-hf25-hwqc-v6g2/GHSA-hf25-hwqc-v6g2.json index 3ec6af31aad..fd5be727e4e 100644 --- a/advisories/unreviewed/2023/05/GHSA-hf25-hwqc-v6g2/GHSA-hf25-hwqc-v6g2.json +++ b/advisories/unreviewed/2023/05/GHSA-hf25-hwqc-v6g2/GHSA-hf25-hwqc-v6g2.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-hvp3-qrpc-r6hh/GHSA-hvp3-qrpc-r6hh.json b/advisories/unreviewed/2023/05/GHSA-hvp3-qrpc-r6hh/GHSA-hvp3-qrpc-r6hh.json index 27f45cea066..5bc69b966b8 100644 --- a/advisories/unreviewed/2023/05/GHSA-hvp3-qrpc-r6hh/GHSA-hvp3-qrpc-r6hh.json +++ b/advisories/unreviewed/2023/05/GHSA-hvp3-qrpc-r6hh/GHSA-hvp3-qrpc-r6hh.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-jv3c-wr43-xgx8/GHSA-jv3c-wr43-xgx8.json b/advisories/unreviewed/2023/05/GHSA-jv3c-wr43-xgx8/GHSA-jv3c-wr43-xgx8.json index 8175301b99d..80c8bcda04f 100644 --- a/advisories/unreviewed/2023/05/GHSA-jv3c-wr43-xgx8/GHSA-jv3c-wr43-xgx8.json +++ b/advisories/unreviewed/2023/05/GHSA-jv3c-wr43-xgx8/GHSA-jv3c-wr43-xgx8.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-m67g-36f9-cxh6/GHSA-m67g-36f9-cxh6.json b/advisories/unreviewed/2023/05/GHSA-m67g-36f9-cxh6/GHSA-m67g-36f9-cxh6.json index 02327057b57..217b01ca362 100644 --- a/advisories/unreviewed/2023/05/GHSA-m67g-36f9-cxh6/GHSA-m67g-36f9-cxh6.json +++ b/advisories/unreviewed/2023/05/GHSA-m67g-36f9-cxh6/GHSA-m67g-36f9-cxh6.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-203" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-mxfc-hgc2-6wxg/GHSA-mxfc-hgc2-6wxg.json b/advisories/unreviewed/2023/05/GHSA-mxfc-hgc2-6wxg/GHSA-mxfc-hgc2-6wxg.json index 1a621a05d98..c3c28f1488e 100644 --- a/advisories/unreviewed/2023/05/GHSA-mxfc-hgc2-6wxg/GHSA-mxfc-hgc2-6wxg.json +++ b/advisories/unreviewed/2023/05/GHSA-mxfc-hgc2-6wxg/GHSA-mxfc-hgc2-6wxg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-326" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-p3p9-g3mr-hhrx/GHSA-p3p9-g3mr-hhrx.json b/advisories/unreviewed/2023/05/GHSA-p3p9-g3mr-hhrx/GHSA-p3p9-g3mr-hhrx.json index 31663b8f954..6cb978ecf16 100644 --- a/advisories/unreviewed/2023/05/GHSA-p3p9-g3mr-hhrx/GHSA-p3p9-g3mr-hhrx.json +++ b/advisories/unreviewed/2023/05/GHSA-p3p9-g3mr-hhrx/GHSA-p3p9-g3mr-hhrx.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/05/GHSA-pm6r-6p9q-w5rf/GHSA-pm6r-6p9q-w5rf.json b/advisories/unreviewed/2023/05/GHSA-pm6r-6p9q-w5rf/GHSA-pm6r-6p9q-w5rf.json index 35c0cf5d924..e271094050c 100644 --- a/advisories/unreviewed/2023/05/GHSA-pm6r-6p9q-w5rf/GHSA-pm6r-6p9q-w5rf.json +++ b/advisories/unreviewed/2023/05/GHSA-pm6r-6p9q-w5rf/GHSA-pm6r-6p9q-w5rf.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-89" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/05/GHSA-qfvr-c3w2-x3h7/GHSA-qfvr-c3w2-x3h7.json b/advisories/unreviewed/2023/05/GHSA-qfvr-c3w2-x3h7/GHSA-qfvr-c3w2-x3h7.json index 969f9b89c22..49b4f2c8579 100644 --- a/advisories/unreviewed/2023/05/GHSA-qfvr-c3w2-x3h7/GHSA-qfvr-c3w2-x3h7.json +++ b/advisories/unreviewed/2023/05/GHSA-qfvr-c3w2-x3h7/GHSA-qfvr-c3w2-x3h7.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-vxf8-wwpw-phxg/GHSA-vxf8-wwpw-phxg.json b/advisories/unreviewed/2023/05/GHSA-vxf8-wwpw-phxg/GHSA-vxf8-wwpw-phxg.json index 62e7756a706..e5a077e4138 100644 --- a/advisories/unreviewed/2023/05/GHSA-vxf8-wwpw-phxg/GHSA-vxf8-wwpw-phxg.json +++ b/advisories/unreviewed/2023/05/GHSA-vxf8-wwpw-phxg/GHSA-vxf8-wwpw-phxg.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-552", "CWE-668" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/07/GHSA-8wrw-hcvf-r5f8/GHSA-8wrw-hcvf-r5f8.json b/advisories/unreviewed/2023/07/GHSA-8wrw-hcvf-r5f8/GHSA-8wrw-hcvf-r5f8.json index ebf8ad60199..cda4edf327e 100644 --- a/advisories/unreviewed/2023/07/GHSA-8wrw-hcvf-r5f8/GHSA-8wrw-hcvf-r5f8.json +++ b/advisories/unreviewed/2023/07/GHSA-8wrw-hcvf-r5f8/GHSA-8wrw-hcvf-r5f8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8wrw-hcvf-r5f8", - "modified": "2024-04-04T05:42:36Z", + "modified": "2025-01-24T18:31:05Z", "published": "2023-07-06T21:14:56Z", "aliases": [ "CVE-2023-2663" diff --git a/advisories/unreviewed/2024/02/GHSA-cpp3-849q-7wmj/GHSA-cpp3-849q-7wmj.json b/advisories/unreviewed/2024/02/GHSA-cpp3-849q-7wmj/GHSA-cpp3-849q-7wmj.json index 574308dbb7f..f92641eacbb 100644 --- a/advisories/unreviewed/2024/02/GHSA-cpp3-849q-7wmj/GHSA-cpp3-849q-7wmj.json +++ b/advisories/unreviewed/2024/02/GHSA-cpp3-849q-7wmj/GHSA-cpp3-849q-7wmj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cpp3-849q-7wmj", - "modified": "2024-02-14T18:30:26Z", + "modified": "2025-01-24T18:31:07Z", "published": "2024-02-14T18:30:25Z", "aliases": [ "CVE-2024-23607" diff --git a/advisories/unreviewed/2024/02/GHSA-fgh6-x5w4-82cg/GHSA-fgh6-x5w4-82cg.json b/advisories/unreviewed/2024/02/GHSA-fgh6-x5w4-82cg/GHSA-fgh6-x5w4-82cg.json index 3fbd92cdc5b..c598fe7d8db 100644 --- a/advisories/unreviewed/2024/02/GHSA-fgh6-x5w4-82cg/GHSA-fgh6-x5w4-82cg.json +++ b/advisories/unreviewed/2024/02/GHSA-fgh6-x5w4-82cg/GHSA-fgh6-x5w4-82cg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fgh6-x5w4-82cg", - "modified": "2024-02-14T18:30:26Z", + "modified": "2025-01-24T18:31:07Z", "published": "2024-02-14T18:30:26Z", "aliases": [ "CVE-2024-24966" diff --git a/advisories/unreviewed/2024/03/GHSA-2vwx-x49m-q6hr/GHSA-2vwx-x49m-q6hr.json b/advisories/unreviewed/2024/03/GHSA-2vwx-x49m-q6hr/GHSA-2vwx-x49m-q6hr.json index b42f70ba981..a80b88dc04b 100644 --- a/advisories/unreviewed/2024/03/GHSA-2vwx-x49m-q6hr/GHSA-2vwx-x49m-q6hr.json +++ b/advisories/unreviewed/2024/03/GHSA-2vwx-x49m-q6hr/GHSA-2vwx-x49m-q6hr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2vwx-x49m-q6hr", - "modified": "2024-03-21T15:31:54Z", + "modified": "2025-01-24T18:31:08Z", "published": "2024-03-21T15:31:54Z", "aliases": [ "CVE-2024-29878" diff --git a/advisories/unreviewed/2024/03/GHSA-6qxg-84xw-6m8w/GHSA-6qxg-84xw-6m8w.json b/advisories/unreviewed/2024/03/GHSA-6qxg-84xw-6m8w/GHSA-6qxg-84xw-6m8w.json index 10b25247081..61cb5fcdb78 100644 --- a/advisories/unreviewed/2024/03/GHSA-6qxg-84xw-6m8w/GHSA-6qxg-84xw-6m8w.json +++ b/advisories/unreviewed/2024/03/GHSA-6qxg-84xw-6m8w/GHSA-6qxg-84xw-6m8w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6qxg-84xw-6m8w", - "modified": "2024-03-21T15:31:54Z", + "modified": "2025-01-24T18:31:08Z", "published": "2024-03-21T15:31:54Z", "aliases": [ "CVE-2024-29879" diff --git a/advisories/unreviewed/2024/03/GHSA-f64p-xgr6-r5f4/GHSA-f64p-xgr6-r5f4.json b/advisories/unreviewed/2024/03/GHSA-f64p-xgr6-r5f4/GHSA-f64p-xgr6-r5f4.json index 45b5b02f587..1853e8bc19b 100644 --- a/advisories/unreviewed/2024/03/GHSA-f64p-xgr6-r5f4/GHSA-f64p-xgr6-r5f4.json +++ b/advisories/unreviewed/2024/03/GHSA-f64p-xgr6-r5f4/GHSA-f64p-xgr6-r5f4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f64p-xgr6-r5f4", - "modified": "2024-03-21T15:31:53Z", + "modified": "2025-01-24T18:31:08Z", "published": "2024-03-21T15:31:53Z", "aliases": [ "CVE-2024-29877" diff --git a/advisories/unreviewed/2024/04/GHSA-7g8v-p8gp-3mff/GHSA-7g8v-p8gp-3mff.json b/advisories/unreviewed/2024/04/GHSA-7g8v-p8gp-3mff/GHSA-7g8v-p8gp-3mff.json index ec16f3c8b12..31e7101f07f 100644 --- a/advisories/unreviewed/2024/04/GHSA-7g8v-p8gp-3mff/GHSA-7g8v-p8gp-3mff.json +++ b/advisories/unreviewed/2024/04/GHSA-7g8v-p8gp-3mff/GHSA-7g8v-p8gp-3mff.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-285" + "CWE-285", + "CWE-639" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-8x2m-vwxp-r65j/GHSA-8x2m-vwxp-r65j.json b/advisories/unreviewed/2024/04/GHSA-8x2m-vwxp-r65j/GHSA-8x2m-vwxp-r65j.json index 524d9358c2f..669f81939cc 100644 --- a/advisories/unreviewed/2024/04/GHSA-8x2m-vwxp-r65j/GHSA-8x2m-vwxp-r65j.json +++ b/advisories/unreviewed/2024/04/GHSA-8x2m-vwxp-r65j/GHSA-8x2m-vwxp-r65j.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-476" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-w59w-35q3-vcg7/GHSA-w59w-35q3-vcg7.json b/advisories/unreviewed/2024/04/GHSA-w59w-35q3-vcg7/GHSA-w59w-35q3-vcg7.json index a8fc19f506d..32343dd3543 100644 --- a/advisories/unreviewed/2024/04/GHSA-w59w-35q3-vcg7/GHSA-w59w-35q3-vcg7.json +++ b/advisories/unreviewed/2024/04/GHSA-w59w-35q3-vcg7/GHSA-w59w-35q3-vcg7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w59w-35q3-vcg7", - "modified": "2024-04-04T09:30:34Z", + "modified": "2025-01-24T18:31:08Z", "published": "2024-04-04T09:30:34Z", "aliases": [ "CVE-2024-29006" ], "details": "By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead to authentication bypass and other operational problems should an attacker decide to spoof their IP address this way. Users are recommended to upgrade to CloudStack version 4.18.1.1 or 4.19.0.1, which fixes this issue.\n\n", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-290" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T08:15:06Z" diff --git a/advisories/unreviewed/2024/05/GHSA-4xr9-57fm-rwq6/GHSA-4xr9-57fm-rwq6.json b/advisories/unreviewed/2024/05/GHSA-4xr9-57fm-rwq6/GHSA-4xr9-57fm-rwq6.json index b1e8b3e7238..bf16387a0eb 100644 --- a/advisories/unreviewed/2024/05/GHSA-4xr9-57fm-rwq6/GHSA-4xr9-57fm-rwq6.json +++ b/advisories/unreviewed/2024/05/GHSA-4xr9-57fm-rwq6/GHSA-4xr9-57fm-rwq6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4xr9-57fm-rwq6", - "modified": "2024-05-16T06:30:51Z", + "modified": "2025-01-24T18:31:09Z", "published": "2024-05-16T06:30:51Z", "aliases": [ "CVE-2024-4318" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8823-566r-4pqv/GHSA-8823-566r-4pqv.json b/advisories/unreviewed/2024/05/GHSA-8823-566r-4pqv/GHSA-8823-566r-4pqv.json index 741b12a8afc..0da5eefaed2 100644 --- a/advisories/unreviewed/2024/05/GHSA-8823-566r-4pqv/GHSA-8823-566r-4pqv.json +++ b/advisories/unreviewed/2024/05/GHSA-8823-566r-4pqv/GHSA-8823-566r-4pqv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8823-566r-4pqv", - "modified": "2024-05-16T06:30:51Z", + "modified": "2025-01-24T18:31:09Z", "published": "2024-05-16T06:30:51Z", "aliases": [ "CVE-2024-4279" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-639" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-vg6j-98mp-hc22/GHSA-vg6j-98mp-hc22.json b/advisories/unreviewed/2024/05/GHSA-vg6j-98mp-hc22/GHSA-vg6j-98mp-hc22.json index 9222534eb68..1bcedbbb543 100644 --- a/advisories/unreviewed/2024/05/GHSA-vg6j-98mp-hc22/GHSA-vg6j-98mp-hc22.json +++ b/advisories/unreviewed/2024/05/GHSA-vg6j-98mp-hc22/GHSA-vg6j-98mp-hc22.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-x4wq-f6wg-7mvp/GHSA-x4wq-f6wg-7mvp.json b/advisories/unreviewed/2024/05/GHSA-x4wq-f6wg-7mvp/GHSA-x4wq-f6wg-7mvp.json index 73132c30c74..158be205a86 100644 --- a/advisories/unreviewed/2024/05/GHSA-x4wq-f6wg-7mvp/GHSA-x4wq-f6wg-7mvp.json +++ b/advisories/unreviewed/2024/05/GHSA-x4wq-f6wg-7mvp/GHSA-x4wq-f6wg-7mvp.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xmv2-92jh-84fp/GHSA-xmv2-92jh-84fp.json b/advisories/unreviewed/2024/05/GHSA-xmv2-92jh-84fp/GHSA-xmv2-92jh-84fp.json index 46b3f610fc2..64c3b76effb 100644 --- a/advisories/unreviewed/2024/05/GHSA-xmv2-92jh-84fp/GHSA-xmv2-92jh-84fp.json +++ b/advisories/unreviewed/2024/05/GHSA-xmv2-92jh-84fp/GHSA-xmv2-92jh-84fp.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-2j54-3gcc-fxxg/GHSA-2j54-3gcc-fxxg.json b/advisories/unreviewed/2024/11/GHSA-2j54-3gcc-fxxg/GHSA-2j54-3gcc-fxxg.json index 341a37ee1df..274cd3a0439 100644 --- a/advisories/unreviewed/2024/11/GHSA-2j54-3gcc-fxxg/GHSA-2j54-3gcc-fxxg.json +++ b/advisories/unreviewed/2024/11/GHSA-2j54-3gcc-fxxg/GHSA-2j54-3gcc-fxxg.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2j54-3gcc-fxxg", - "modified": "2024-11-14T12:31:01Z", + "modified": "2025-01-24T18:31:12Z", "published": "2024-11-14T12:31:01Z", "aliases": [ "CVE-2024-5917" ], "details": "A server-side request forgery in PAN-OS software enables an unauthenticated attacker to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Amber" diff --git a/advisories/unreviewed/2024/11/GHSA-77jf-qvrc-2mmc/GHSA-77jf-qvrc-2mmc.json b/advisories/unreviewed/2024/11/GHSA-77jf-qvrc-2mmc/GHSA-77jf-qvrc-2mmc.json index 5b4b8da926f..704610adc82 100644 --- a/advisories/unreviewed/2024/11/GHSA-77jf-qvrc-2mmc/GHSA-77jf-qvrc-2mmc.json +++ b/advisories/unreviewed/2024/11/GHSA-77jf-qvrc-2mmc/GHSA-77jf-qvrc-2mmc.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-77jf-qvrc-2mmc", - "modified": "2024-11-14T12:31:00Z", + "modified": "2025-01-24T18:31:12Z", "published": "2024-11-14T12:31:00Z", "aliases": [ "CVE-2024-2552" ], "details": "A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions in the management plane and delete files on the firewall.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" diff --git a/advisories/unreviewed/2024/11/GHSA-7h98-97f3-2x3x/GHSA-7h98-97f3-2x3x.json b/advisories/unreviewed/2024/11/GHSA-7h98-97f3-2x3x/GHSA-7h98-97f3-2x3x.json index 8654c1dd591..c53e8cbf569 100644 --- a/advisories/unreviewed/2024/11/GHSA-7h98-97f3-2x3x/GHSA-7h98-97f3-2x3x.json +++ b/advisories/unreviewed/2024/11/GHSA-7h98-97f3-2x3x/GHSA-7h98-97f3-2x3x.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7h98-97f3-2x3x", - "modified": "2024-11-14T12:31:00Z", + "modified": "2025-01-24T18:31:12Z", "published": "2024-11-14T12:31:00Z", "aliases": [ "CVE-2024-2551" ], "details": "A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by sending a crafted packet through the data plane that causes a denial of service (DoS) condition. Repeated attempts to trigger this condition result in the firewall entering maintenance mode.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" diff --git a/advisories/unreviewed/2024/11/GHSA-m359-59cc-2426/GHSA-m359-59cc-2426.json b/advisories/unreviewed/2024/11/GHSA-m359-59cc-2426/GHSA-m359-59cc-2426.json index 74b72c9743f..d9d86bf3f70 100644 --- a/advisories/unreviewed/2024/11/GHSA-m359-59cc-2426/GHSA-m359-59cc-2426.json +++ b/advisories/unreviewed/2024/11/GHSA-m359-59cc-2426/GHSA-m359-59cc-2426.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m359-59cc-2426", - "modified": "2024-11-14T12:31:01Z", + "modified": "2025-01-24T18:31:12Z", "published": "2024-11-14T12:31:01Z", "aliases": [ "CVE-2024-5919" ], "details": "A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the firewall management interface.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:C/RE:M/U:Amber" diff --git a/advisories/unreviewed/2024/11/GHSA-q527-gcw3-86jr/GHSA-q527-gcw3-86jr.json b/advisories/unreviewed/2024/11/GHSA-q527-gcw3-86jr/GHSA-q527-gcw3-86jr.json index a4a22a4cf8a..260e438f176 100644 --- a/advisories/unreviewed/2024/11/GHSA-q527-gcw3-86jr/GHSA-q527-gcw3-86jr.json +++ b/advisories/unreviewed/2024/11/GHSA-q527-gcw3-86jr/GHSA-q527-gcw3-86jr.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q527-gcw3-86jr", - "modified": "2024-11-14T12:31:00Z", + "modified": "2025-01-24T18:31:12Z", "published": "2024-11-14T12:31:00Z", "aliases": [ "CVE-2024-2550" ], "details": "A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop the GlobalProtect service on the firewall by sending a specially crafted packet that causes a denial of service (DoS) condition. Repeated attempts to trigger this condition result in the firewall entering maintenance mode.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" diff --git a/advisories/unreviewed/2024/11/GHSA-xx8r-3wgj-j632/GHSA-xx8r-3wgj-j632.json b/advisories/unreviewed/2024/11/GHSA-xx8r-3wgj-j632/GHSA-xx8r-3wgj-j632.json index f951faf34f3..d71e28800a8 100644 --- a/advisories/unreviewed/2024/11/GHSA-xx8r-3wgj-j632/GHSA-xx8r-3wgj-j632.json +++ b/advisories/unreviewed/2024/11/GHSA-xx8r-3wgj-j632/GHSA-xx8r-3wgj-j632.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xx8r-3wgj-j632", - "modified": "2024-11-14T12:31:01Z", + "modified": "2025-01-24T18:31:12Z", "published": "2024-11-14T12:31:01Z", "aliases": [ "CVE-2024-5920" ], "details": "A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administrator who can perform restricted actions on the PAN-OS node after the execution of JavaScript in the legitimate PAN-OS administrator's browser.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" diff --git a/advisories/unreviewed/2025/01/GHSA-23r3-hw65-m2x7/GHSA-23r3-hw65-m2x7.json b/advisories/unreviewed/2025/01/GHSA-23r3-hw65-m2x7/GHSA-23r3-hw65-m2x7.json new file mode 100644 index 00000000000..9f988ee980e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-23r3-hw65-m2x7/GHSA-23r3-hw65-m2x7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23r3-hw65-m2x7", + "modified": "2025-01-24T18:31:13Z", + "published": "2025-01-24T18:31:13Z", + "aliases": [ + "CVE-2025-24542" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icegram Icegram allows Stored XSS. This issue affects Icegram: from n/a through 3.1.31.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24542" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/icegram/vulnerability/wordpress-icegram-engage-plugin-3-1-31-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-258w-34pg-5724/GHSA-258w-34pg-5724.json b/advisories/unreviewed/2025/01/GHSA-258w-34pg-5724/GHSA-258w-34pg-5724.json new file mode 100644 index 00000000000..11041314826 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-258w-34pg-5724/GHSA-258w-34pg-5724.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-258w-34pg-5724", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24678" + ], + "details": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Listamester Listamester allows Stored XSS. This issue affects Listamester: from n/a through 2.3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24678" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/listamester/vulnerability/wordpress-listamester-plugin-2-3-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-25fx-9jj6-385f/GHSA-25fx-9jj6-385f.json b/advisories/unreviewed/2025/01/GHSA-25fx-9jj6-385f/GHSA-25fx-9jj6-385f.json new file mode 100644 index 00000000000..47c6e931798 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-25fx-9jj6-385f/GHSA-25fx-9jj6-385f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25fx-9jj6-385f", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24681" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWax Product Carousel Slider & Grid Ultimate for WooCommerce allows Stored XSS. This issue affects Product Carousel Slider & Grid Ultimate for WooCommerce: from n/a through 1.10.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24681" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-product-carousel-slider-and-grid-ultimate/vulnerability/wordpress-product-carousel-slider-grid-ultimate-for-woocommerce-plugin-1-10-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-286p-j2mm-3mx9/GHSA-286p-j2mm-3mx9.json b/advisories/unreviewed/2025/01/GHSA-286p-j2mm-3mx9/GHSA-286p-j2mm-3mx9.json new file mode 100644 index 00000000000..20f298cd46a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-286p-j2mm-3mx9/GHSA-286p-j2mm-3mx9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-286p-j2mm-3mx9", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24595" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins All Embed – Elementor Addons allows Stored XSS. This issue affects All Embed – Elementor Addons: from n/a through 1.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24595" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/all-embed-addons-for-elementor/vulnerability/wordpress-all-embed-elementor-addons-plugin-1-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2cfp-2pmr-56x9/GHSA-2cfp-2pmr-56x9.json b/advisories/unreviewed/2025/01/GHSA-2cfp-2pmr-56x9/GHSA-2cfp-2pmr-56x9.json new file mode 100644 index 00000000000..f9e9605ce0f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2cfp-2pmr-56x9/GHSA-2cfp-2pmr-56x9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cfp-2pmr-56x9", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24682" + ], + "details": "Missing Authorization vulnerability in mikemmx Super Block Slider allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Super Block Slider: from n/a through 2.7.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24682" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/super-block-slider/vulnerability/wordpress-super-block-slider-plugin-2-7-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2cgh-57h5-g49r/GHSA-2cgh-57h5-g49r.json b/advisories/unreviewed/2025/01/GHSA-2cgh-57h5-g49r/GHSA-2cgh-57h5-g49r.json new file mode 100644 index 00000000000..0d4e24bb619 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2cgh-57h5-g49r/GHSA-2cgh-57h5-g49r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cgh-57h5-g49r", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24674" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Teplitsa. Technologies for Social Good ShMapper by Teplitsa allows Stored XSS. This issue affects ShMapper by Teplitsa: from n/a through 1.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24674" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/shmapper-by-teplitsa/vulnerability/wordpress-shmapper-by-teplitsa-plugin-1-5-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2jrx-fmqr-7h3v/GHSA-2jrx-fmqr-7h3v.json b/advisories/unreviewed/2025/01/GHSA-2jrx-fmqr-7h3v/GHSA-2jrx-fmqr-7h3v.json new file mode 100644 index 00000000000..6f708c11b2f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2jrx-fmqr-7h3v/GHSA-2jrx-fmqr-7h3v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jrx-fmqr-7h3v", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24571" + ], + "details": "Missing Authorization vulnerability in Epsiloncool WP Fast Total Search allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Fast Total Search: from n/a through 1.78.258.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24571" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fulltext-search/vulnerability/wordpress-wp-fast-total-search-plugin-1-78-258-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2m3f-r6c7-4j2x/GHSA-2m3f-r6c7-4j2x.json b/advisories/unreviewed/2025/01/GHSA-2m3f-r6c7-4j2x/GHSA-2m3f-r6c7-4j2x.json new file mode 100644 index 00000000000..a9959827f53 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2m3f-r6c7-4j2x/GHSA-2m3f-r6c7-4j2x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2m3f-r6c7-4j2x", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24657" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee Wishlist for WooCommerce allows Stored XSS. This issue affects Wishlist for WooCommerce: from n/a through 2.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24657" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wt-woocommerce-wishlist/vulnerability/wordpress-wishlist-for-woocommerce-plugin-2-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2mhx-6p2w-94qg/GHSA-2mhx-6p2w-94qg.json b/advisories/unreviewed/2025/01/GHSA-2mhx-6p2w-94qg/GHSA-2mhx-6p2w-94qg.json new file mode 100644 index 00000000000..d344eaaa181 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2mhx-6p2w-94qg/GHSA-2mhx-6p2w-94qg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mhx-6p2w-94qg", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24675" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osamaesh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 7.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24675" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-stats-manager/vulnerability/wordpress-wp-visitor-statistics-real-time-traffic-plugin-7-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2wjg-4xfw-c8xm/GHSA-2wjg-4xfw-c8xm.json b/advisories/unreviewed/2025/01/GHSA-2wjg-4xfw-c8xm/GHSA-2wjg-4xfw-c8xm.json new file mode 100644 index 00000000000..d47d33f9e44 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2wjg-4xfw-c8xm/GHSA-2wjg-4xfw-c8xm.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wjg-4xfw-c8xm", + "modified": "2025-01-24T18:31:13Z", + "published": "2025-01-24T18:31:13Z", + "aliases": [ + "CVE-2025-0701" + ], + "details": "A vulnerability classified as critical has been found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. This affects an unknown part of the file /admin/sys/user/list. The manipulation of the argument sort leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0701" + }, + { + "type": "WEB", + "url": "https://github.com/JoeyBling/bootplus/issues/23" + }, + { + "type": "WEB", + "url": "https://github.com/JoeyBling/bootplus/issues/23#issue-2786909921" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.293229" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.293229" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.480839" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-36g3-jf2j-m2rj/GHSA-36g3-jf2j-m2rj.json b/advisories/unreviewed/2025/01/GHSA-36g3-jf2j-m2rj/GHSA-36g3-jf2j-m2rj.json new file mode 100644 index 00000000000..67ea5da9020 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-36g3-jf2j-m2rj/GHSA-36g3-jf2j-m2rj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36g3-jf2j-m2rj", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24730" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rextheme WP VR allows DOM-Based XSS. This issue affects WP VR: from n/a through 8.5.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24730" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpvr/vulnerability/wordpress-wp-vr-plugin-8-5-14-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-38fw-44gr-hrfp/GHSA-38fw-44gr-hrfp.json b/advisories/unreviewed/2025/01/GHSA-38fw-44gr-hrfp/GHSA-38fw-44gr-hrfp.json new file mode 100644 index 00000000000..80135f701d8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-38fw-44gr-hrfp/GHSA-38fw-44gr-hrfp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38fw-44gr-hrfp", + "modified": "2025-01-24T18:31:12Z", + "published": "2025-01-24T18:31:12Z", + "aliases": [ + "CVE-2024-40693" + ], + "details": "IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim for performing further attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40693" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7168387" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-38q5-35h2-4xpw/GHSA-38q5-35h2-4xpw.json b/advisories/unreviewed/2025/01/GHSA-38q5-35h2-4xpw/GHSA-38q5-35h2-4xpw.json new file mode 100644 index 00000000000..365df2a5126 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-38q5-35h2-4xpw/GHSA-38q5-35h2-4xpw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38q5-35h2-4xpw", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24568" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates allows Cross Site Request Forgery. This issue affects Starter Templates: from n/a through 4.4.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24568" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/astra-sites/vulnerability/wordpress-starter-templates-plugin-4-4-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3p9q-2c9q-vq29/GHSA-3p9q-2c9q-vq29.json b/advisories/unreviewed/2025/01/GHSA-3p9q-2c9q-vq29/GHSA-3p9q-2c9q-vq29.json new file mode 100644 index 00000000000..f86070dc54b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3p9q-2c9q-vq29/GHSA-3p9q-2c9q-vq29.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p9q-2c9q-vq29", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24714" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Bubble Menu – circle floating menu allows Cross Site Request Forgery. This issue affects Bubble Menu – circle floating menu: from n/a through 4.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24714" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bubble-menu/vulnerability/wordpress-bubble-menu-plugin-4-0-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3v34-886r-p598/GHSA-3v34-886r-p598.json b/advisories/unreviewed/2025/01/GHSA-3v34-886r-p598/GHSA-3v34-886r-p598.json new file mode 100644 index 00000000000..d4d3bfbe140 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3v34-886r-p598/GHSA-3v34-886r-p598.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3v34-886r-p598", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24588" + ], + "details": "Missing Authorization vulnerability in Patreon Patreon WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Patreon WordPress: from n/a through 1.9.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24588" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/patreon-connect/vulnerability/wordpress-patreon-wordpress-plugin-1-9-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3wh6-j4g5-pq88/GHSA-3wh6-j4g5-pq88.json b/advisories/unreviewed/2025/01/GHSA-3wh6-j4g5-pq88/GHSA-3wh6-j4g5-pq88.json new file mode 100644 index 00000000000..d84a3eed656 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3wh6-j4g5-pq88/GHSA-3wh6-j4g5-pq88.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wh6-j4g5-pq88", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24582" + ], + "details": "Insertion of Sensitive Information Into Sent Data vulnerability in Code for Recovery 12 Step Meeting List allows Retrieve Embedded Sensitive Data. This issue affects 12 Step Meeting List: from n/a through 3.16.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24582" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/12-step-meeting-list/vulnerability/wordpress-12-step-meeting-list-plugin-3-16-5-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4384-wg24-m29h/GHSA-4384-wg24-m29h.json b/advisories/unreviewed/2025/01/GHSA-4384-wg24-m29h/GHSA-4384-wg24-m29h.json new file mode 100644 index 00000000000..c066b31edf7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4384-wg24-m29h/GHSA-4384-wg24-m29h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4384-wg24-m29h", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24715" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Counter Box allows Cross Site Request Forgery. This issue affects Counter Box: from n/a through 2.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24715" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/counter-box/vulnerability/wordpress-counter-box-plugin-2-0-5-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4gqv-wrwc-ppcm/GHSA-4gqv-wrwc-ppcm.json b/advisories/unreviewed/2025/01/GHSA-4gqv-wrwc-ppcm/GHSA-4gqv-wrwc-ppcm.json new file mode 100644 index 00000000000..23be0a822fd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4gqv-wrwc-ppcm/GHSA-4gqv-wrwc-ppcm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gqv-wrwc-ppcm", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24687" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lars Wallenborn Show/Hide Shortcode allows Stored XSS. This issue affects Show/Hide Shortcode: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24687" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/showhide-shortcode/vulnerability/wordpress-show-hide-shortcode-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4hp8-c3wm-fwh9/GHSA-4hp8-c3wm-fwh9.json b/advisories/unreviewed/2025/01/GHSA-4hp8-c3wm-fwh9/GHSA-4hp8-c3wm-fwh9.json new file mode 100644 index 00000000000..fbe254c68fd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4hp8-c3wm-fwh9/GHSA-4hp8-c3wm-fwh9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hp8-c3wm-fwh9", + "modified": "2025-01-24T18:31:13Z", + "published": "2025-01-24T18:31:13Z", + "aliases": [ + "CVE-2025-24546" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in RSTheme Ultimate Coming Soon & Maintenance allows Cross Site Request Forgery. This issue affects Ultimate Coming Soon & Maintenance: from n/a through 1.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24546" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-coming-soon/vulnerability/wordpress-ultimate-coming-soon-maintenance-plugin-1-0-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4j45-j8xj-879v/GHSA-4j45-j8xj-879v.json b/advisories/unreviewed/2025/01/GHSA-4j45-j8xj-879v/GHSA-4j45-j8xj-879v.json new file mode 100644 index 00000000000..2dd8a1a0eb9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4j45-j8xj-879v/GHSA-4j45-j8xj-879v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4j45-j8xj-879v", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24572" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search allows Cross Site Request Forgery. This issue affects WP Fast Total Search: from n/a through 1.78.258.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24572" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fulltext-search/vulnerability/wordpress-wp-fast-total-search-plugin-1-78-258-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-53r5-cc2m-mv3x/GHSA-53r5-cc2m-mv3x.json b/advisories/unreviewed/2025/01/GHSA-53r5-cc2m-mv3x/GHSA-53r5-cc2m-mv3x.json new file mode 100644 index 00000000000..dcadaab941e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-53r5-cc2m-mv3x/GHSA-53r5-cc2m-mv3x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53r5-cc2m-mv3x", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24663" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tips and Tricks HQ, Ruhul Amin, Josh Lobe Simple Download Monitor allows Blind SQL Injection. This issue affects Simple Download Monitor: from n/a through 3.9.25.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24663" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-download-monitor/vulnerability/wordpress-simple-download-monitor-plugin-3-9-25-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5735-g7pj-r929/GHSA-5735-g7pj-r929.json b/advisories/unreviewed/2025/01/GHSA-5735-g7pj-r929/GHSA-5735-g7pj-r929.json new file mode 100644 index 00000000000..02520bbbd2d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5735-g7pj-r929/GHSA-5735-g7pj-r929.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5735-g7pj-r929", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24596" + ], + "details": "Missing Authorization vulnerability in WC Product Table WooCommerce Product Table Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WooCommerce Product Table Lite: from n/a through 3.8.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24596" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wc-product-table-lite/vulnerability/wordpress-woocommerce-product-table-lite-plugin-3-8-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-577q-qfgj-fmwf/GHSA-577q-qfgj-fmwf.json b/advisories/unreviewed/2025/01/GHSA-577q-qfgj-fmwf/GHSA-577q-qfgj-fmwf.json new file mode 100644 index 00000000000..3d4a9bf3827 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-577q-qfgj-fmwf/GHSA-577q-qfgj-fmwf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-577q-qfgj-fmwf", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24755" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org PDF Invoices for WooCommerce + Drag and Drop Template Builder allows Stored XSS. This issue affects PDF Invoices for WooCommerce + Drag and Drop Template Builder: from n/a through 4.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24755" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pdf-for-woocommerce/vulnerability/wordpress-pdf-invoices-for-woocommerce-plugin-4-6-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-583m-24fh-9gfq/GHSA-583m-24fh-9gfq.json b/advisories/unreviewed/2025/01/GHSA-583m-24fh-9gfq/GHSA-583m-24fh-9gfq.json new file mode 100644 index 00000000000..2be004a8c1b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-583m-24fh-9gfq/GHSA-583m-24fh-9gfq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-583m-24fh-9gfq", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24751" + ], + "details": "Missing Authorization vulnerability in GoDaddy CoBlocks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CoBlocks: from n/a through 3.1.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24751" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/coblocks/vulnerability/wordpress-coblocks-plugin-3-1-13-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5r7q-7ch8-hr6q/GHSA-5r7q-7ch8-hr6q.json b/advisories/unreviewed/2025/01/GHSA-5r7q-7ch8-hr6q/GHSA-5r7q-7ch8-hr6q.json new file mode 100644 index 00000000000..0b521ada5e4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5r7q-7ch8-hr6q/GHSA-5r7q-7ch8-hr6q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r7q-7ch8-hr6q", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24652" + ], + "details": "Missing Authorization vulnerability in Revmakx WP Duplicate – WordPress Migration Plugin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Duplicate – WordPress Migration Plugin: from n/a through 1.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24652" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/local-sync/vulnerability/wordpress-wp-duplicate-plugin-1-1-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-63hg-gf2w-9gf3/GHSA-63hg-gf2w-9gf3.json b/advisories/unreviewed/2025/01/GHSA-63hg-gf2w-9gf3/GHSA-63hg-gf2w-9gf3.json new file mode 100644 index 00000000000..d39e060fa76 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-63hg-gf2w-9gf3/GHSA-63hg-gf2w-9gf3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63hg-gf2w-9gf3", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24717" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Modal Window allows Cross Site Request Forgery. This issue affects Modal Window: from n/a through 6.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24717" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/modal-window/vulnerability/wordpress-modal-window-plugin-6-1-4-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-646p-6wgh-wfh8/GHSA-646p-6wgh-wfh8.json b/advisories/unreviewed/2025/01/GHSA-646p-6wgh-wfh8/GHSA-646p-6wgh-wfh8.json new file mode 100644 index 00000000000..b4bbe21ffd8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-646p-6wgh-wfh8/GHSA-646p-6wgh-wfh8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-646p-6wgh-wfh8", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24736" + ], + "details": "Missing Authorization vulnerability in Metaphor Creations Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post Duplicator: from n/a through 2.35.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24736" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/post-duplicator/vulnerability/wordpress-post-duplicator-plugin-2-35-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-66g8-r87v-92fx/GHSA-66g8-r87v-92fx.json b/advisories/unreviewed/2025/01/GHSA-66g8-r87v-92fx/GHSA-66g8-r87v-92fx.json new file mode 100644 index 00000000000..8e8e06c9f00 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-66g8-r87v-92fx/GHSA-66g8-r87v-92fx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66g8-r87v-92fx", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24579" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Phillips Nested Pages allows Stored XSS. This issue affects Nested Pages: from n/a through 3.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24579" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-nested-pages/vulnerability/wordpress-nested-pages-plugin-3-2-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-68jj-2qvq-4jh5/GHSA-68jj-2qvq-4jh5.json b/advisories/unreviewed/2025/01/GHSA-68jj-2qvq-4jh5/GHSA-68jj-2qvq-4jh5.json new file mode 100644 index 00000000000..75f47569d0c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-68jj-2qvq-4jh5/GHSA-68jj-2qvq-4jh5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68jj-2qvq-4jh5", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24724" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Side Menu Lite allows Cross Site Request Forgery. This issue affects Side Menu Lite: from n/a through 5.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24724" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/side-menu-lite/vulnerability/wordpress-side-menu-lite-plugin-5-3-1-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-69wv-gf67-c3m8/GHSA-69wv-gf67-c3m8.json b/advisories/unreviewed/2025/01/GHSA-69wv-gf67-c3m8/GHSA-69wv-gf67-c3m8.json new file mode 100644 index 00000000000..2b3adefdcef --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-69wv-gf67-c3m8/GHSA-69wv-gf67-c3m8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69wv-gf67-c3m8", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24712" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Radius Blocks allows Cross Site Request Forgery. This issue affects Radius Blocks: from n/a through 2.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24712" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/radius-blocks/vulnerability/wordpress-radius-blocks-wordpress-gutenberg-blocks-plugin-2-1-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6p72-9rwx-x4v5/GHSA-6p72-9rwx-x4v5.json b/advisories/unreviewed/2025/01/GHSA-6p72-9rwx-x4v5/GHSA-6p72-9rwx-x4v5.json new file mode 100644 index 00000000000..eecc231a46a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6p72-9rwx-x4v5/GHSA-6p72-9rwx-x4v5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p72-9rwx-x4v5", + "modified": "2025-01-24T18:31:12Z", + "published": "2025-01-24T18:31:12Z", + "aliases": [ + "CVE-2024-13698" + ], + "details": "The Jobify - Job Board WordPress Theme for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'download_image_via_ai' and 'generate_image_via_ai' functions in all versions up to, and including, 4.2.7. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application to upload files in an image format, and to generate AI images using the site's OpenAI key.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13698" + }, + { + "type": "WEB", + "url": "https://themeforest.net/item/jobify-wordpress-job-board-theme/5247604" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/393811e4-71dd-4359-80fa-5a3d146439bb?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6xg4-555m-qm52/GHSA-6xg4-555m-qm52.json b/advisories/unreviewed/2025/01/GHSA-6xg4-555m-qm52/GHSA-6xg4-555m-qm52.json new file mode 100644 index 00000000000..8dfb2617ea4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6xg4-555m-qm52/GHSA-6xg4-555m-qm52.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xg4-555m-qm52", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24562" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Optimal Access Inc. KBucket allows Stored XSS. This issue affects KBucket: from n/a through 4.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24562" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/kbucket/vulnerability/wordpress-kbucket-plugin-4-1-6-csrf-to-stored-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6xwx-qgg8-v5m5/GHSA-6xwx-qgg8-v5m5.json b/advisories/unreviewed/2025/01/GHSA-6xwx-qgg8-v5m5/GHSA-6xwx-qgg8-v5m5.json new file mode 100644 index 00000000000..1efd021028d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6xwx-qgg8-v5m5/GHSA-6xwx-qgg8-v5m5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xwx-qgg8-v5m5", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24644" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Stored XSS. This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24644" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/print-invoices-packing-slip-labels-for-woocommerce/vulnerability/wordpress-woocommerce-pdf-invoices-plugin-4-7-1-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-73x8-ccpr-jw52/GHSA-73x8-ccpr-jw52.json b/advisories/unreviewed/2025/01/GHSA-73x8-ccpr-jw52/GHSA-73x8-ccpr-jw52.json new file mode 100644 index 00000000000..4c5090298d1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-73x8-ccpr-jw52/GHSA-73x8-ccpr-jw52.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73x8-ccpr-jw52", + "modified": "2025-01-24T18:31:12Z", + "published": "2025-01-24T18:31:12Z", + "aliases": [ + "CVE-2024-41757" + ], + "details": "IBM Concert Software 1.0.0 and 1.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41757" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7173596" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-311" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7mc7-7hrx-6fcv/GHSA-7mc7-7hrx-6fcv.json b/advisories/unreviewed/2025/01/GHSA-7mc7-7hrx-6fcv/GHSA-7mc7-7hrx-6fcv.json new file mode 100644 index 00000000000..1e9cfc2e4b1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7mc7-7hrx-6fcv/GHSA-7mc7-7hrx-6fcv.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mc7-7hrx-6fcv", + "modified": "2025-01-24T18:31:13Z", + "published": "2025-01-24T18:31:13Z", + "aliases": [ + "CVE-2025-0702" + ], + "details": "A vulnerability classified as critical was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. This vulnerability affects unknown code of the file src/main/java/io/github/controller/SysFileController.java. The manipulation of the argument portraitFile leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0702" + }, + { + "type": "WEB", + "url": "https://github.com/JoeyBling/bootplus/issues/24" + }, + { + "type": "WEB", + "url": "https://github.com/JoeyBling/bootplus/issues/24#issue-2786919432" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.293230" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.293230" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.480841" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7qcj-rrpq-j8w7/GHSA-7qcj-rrpq-j8w7.json b/advisories/unreviewed/2025/01/GHSA-7qcj-rrpq-j8w7/GHSA-7qcj-rrpq-j8w7.json new file mode 100644 index 00000000000..18d3c0ec6f7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7qcj-rrpq-j8w7/GHSA-7qcj-rrpq-j8w7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qcj-rrpq-j8w7", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24691" + ], + "details": "Missing Authorization vulnerability in Gagan Sandhu , Enej Bajgoric , CTLT DEV, UBC People Lists allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects People Lists: from n/a through 1.3.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24691" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/people-lists/vulnerability/wordpress-people-lists-plugin-1-3-10-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7w8r-57xm-qr69/GHSA-7w8r-57xm-qr69.json b/advisories/unreviewed/2025/01/GHSA-7w8r-57xm-qr69/GHSA-7w8r-57xm-qr69.json new file mode 100644 index 00000000000..07d166fab62 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7w8r-57xm-qr69/GHSA-7w8r-57xm-qr69.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7w8r-57xm-qr69", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24746" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Popup Maker Popup Maker allows Stored XSS. This issue affects Popup Maker: from n/a through 1.20.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24746" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/popup-maker/vulnerability/wordpress-popup-maker-plugin-1-20-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-826h-7wh2-gj4q/GHSA-826h-7wh2-gj4q.json b/advisories/unreviewed/2025/01/GHSA-826h-7wh2-gj4q/GHSA-826h-7wh2-gj4q.json new file mode 100644 index 00000000000..008e7b79d90 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-826h-7wh2-gj4q/GHSA-826h-7wh2-gj4q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-826h-7wh2-gj4q", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24695" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in HasThemes Extensions For CF7 allows Server Side Request Forgery. This issue affects Extensions For CF7: from n/a through 3.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24695" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/extensions-for-cf7/vulnerability/wordpress-extensions-for-cf7-plugin-3-2-0-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8crw-9p7v-xfx8/GHSA-8crw-9p7v-xfx8.json b/advisories/unreviewed/2025/01/GHSA-8crw-9p7v-xfx8/GHSA-8crw-9p7v-xfx8.json new file mode 100644 index 00000000000..40471c564b4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8crw-9p7v-xfx8/GHSA-8crw-9p7v-xfx8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8crw-9p7v-xfx8", + "modified": "2025-01-24T18:31:12Z", + "published": "2025-01-24T18:31:12Z", + "aliases": [ + "CVE-2024-25034" + ], + "details": "IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the type of file in the File Manager T1 process. Attackers can make use of this weakness and upload malicious executable files into the system that can be sent to victims for performing further attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25034" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7168387" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T16:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8f27-8fr7-2363/GHSA-8f27-8fr7-2363.json b/advisories/unreviewed/2025/01/GHSA-8f27-8fr7-2363/GHSA-8f27-8fr7-2363.json new file mode 100644 index 00000000000..d8d4a1cbd54 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8f27-8fr7-2363/GHSA-8f27-8fr7-2363.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8f27-8fr7-2363", + "modified": "2025-01-24T18:31:13Z", + "published": "2025-01-24T18:31:13Z", + "aliases": [ + "CVE-2025-23222" + ], + "details": "An issue was discovered in Deepin dde-api-proxy through 1.0.19 in which unprivileged users can access D-Bus services as root. Specifically, dde-api-proxy runs as root and forwards messages from arbitrary local users to legacy D-Bus methods in the actual D-Bus services, and the actual D-Bus services don't know about the proxy situation (they believe that root is asking them to do things). Consequently several proxied methods, that shouldn't be accessible to non-root users, are accessible to non-root users. In situations where Polkit is involved, the caller would be treated as admin, resulting in a similar escalation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23222" + }, + { + "type": "WEB", + "url": "https://bugzilla.suse.com/show_bug.cgi?id=1229918" + }, + { + "type": "WEB", + "url": "https://security.opensuse.org/2025/01/24/dde-api-proxy-privilege-escalation.html" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2025/01/24/3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-940" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8rh7-vrhr-qjgr/GHSA-8rh7-vrhr-qjgr.json b/advisories/unreviewed/2025/01/GHSA-8rh7-vrhr-qjgr/GHSA-8rh7-vrhr-qjgr.json new file mode 100644 index 00000000000..a3b0ca73316 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8rh7-vrhr-qjgr/GHSA-8rh7-vrhr-qjgr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rh7-vrhr-qjgr", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24668" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle PPOM for WooCommerce allows Stored XSS. This issue affects PPOM for WooCommerce: from n/a through 33.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24668" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-product-addon/vulnerability/wordpress-ppom-for-woocommerce-plugin-33-0-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8v3g-2772-j73f/GHSA-8v3g-2772-j73f.json b/advisories/unreviewed/2025/01/GHSA-8v3g-2772-j73f/GHSA-8v3g-2772-j73f.json new file mode 100644 index 00000000000..21672a48c86 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8v3g-2772-j73f/GHSA-8v3g-2772-j73f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8v3g-2772-j73f", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24713" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder allows Cross Site Request Forgery. This issue affects Button Generator – easily Button Builder: from n/a through 3.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24713" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/button-generation/vulnerability/wordpress-button-generator-easily-button-builder-plugin-3-1-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8x66-w66p-wqj8/GHSA-8x66-w66p-wqj8.json b/advisories/unreviewed/2025/01/GHSA-8x66-w66p-wqj8/GHSA-8x66-w66p-wqj8.json new file mode 100644 index 00000000000..1e17f6e57c5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8x66-w66p-wqj8/GHSA-8x66-w66p-wqj8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x66-w66p-wqj8", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24587" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in I Thirteen Web Solution Email Subscription Popup allows Blind SQL Injection. This issue affects Email Subscription Popup: from n/a through 1.2.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24587" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/email-subscribe/vulnerability/wordpress-email-subscription-popup-plugin-1-2-23-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9m28-gm8r-8h2p/GHSA-9m28-gm8r-8h2p.json b/advisories/unreviewed/2025/01/GHSA-9m28-gm8r-8h2p/GHSA-9m28-gm8r-8h2p.json new file mode 100644 index 00000000000..54e67bdc7ca --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9m28-gm8r-8h2p/GHSA-9m28-gm8r-8h2p.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m28-gm8r-8h2p", + "modified": "2025-01-24T18:31:13Z", + "published": "2025-01-24T18:31:12Z", + "aliases": [ + "CVE-2025-0698" + ], + "details": "A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. It has been classified as critical. Affected is an unknown function of the file /admin/sys/menu/list. The manipulation of the argument sort/order leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0698" + }, + { + "type": "WEB", + "url": "https://github.com/JoeyBling/bootplus/issues/19" + }, + { + "type": "WEB", + "url": "https://github.com/JoeyBling/bootplus/issues/19#issue-2786879797" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.293226" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.293226" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.480827" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c63w-gjxf-c2hv/GHSA-c63w-gjxf-c2hv.json b/advisories/unreviewed/2025/01/GHSA-c63w-gjxf-c2hv/GHSA-c63w-gjxf-c2hv.json new file mode 100644 index 00000000000..0f9283b82ac --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c63w-gjxf-c2hv/GHSA-c63w-gjxf-c2hv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c63w-gjxf-c2hv", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24683" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill RSVP and Event Management Plugin allows SQL Injection. This issue affects RSVP and Event Management Plugin: from n/a through 2.7.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24683" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rsvp/vulnerability/wordpress-rsvp-and-event-management-plugin-2-7-14-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c72w-jmcc-c82g/GHSA-c72w-jmcc-c82g.json b/advisories/unreviewed/2025/01/GHSA-c72w-jmcc-c82g/GHSA-c72w-jmcc-c82g.json new file mode 100644 index 00000000000..9744bc47863 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c72w-jmcc-c82g/GHSA-c72w-jmcc-c82g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c72w-jmcc-c82g", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24573" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pagelayer Team PageLayer allows DOM-Based XSS. This issue affects PageLayer: from n/a through 1.9.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24573" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pagelayer/vulnerability/wordpress-pagelayer-plugin-1-9-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cgvj-5xxj-mf5j/GHSA-cgvj-5xxj-mf5j.json b/advisories/unreviewed/2025/01/GHSA-cgvj-5xxj-mf5j/GHSA-cgvj-5xxj-mf5j.json new file mode 100644 index 00000000000..34a8b984a96 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cgvj-5xxj-mf5j/GHSA-cgvj-5xxj-mf5j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgvj-5xxj-mf5j", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24703" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in DLX Plugins Comment Edit Core – Simple Comment Editing allows Server Side Request Forgery. This issue affects Comment Edit Core – Simple Comment Editing: from n/a through 3.0.33.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24703" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-comment-editing/vulnerability/wordpress-comment-edit-core-simple-comment-editing-plugin-3-0-33-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cjjv-jx93-m7h6/GHSA-cjjv-jx93-m7h6.json b/advisories/unreviewed/2025/01/GHSA-cjjv-jx93-m7h6/GHSA-cjjv-jx93-m7h6.json new file mode 100644 index 00000000000..c35307dae65 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cjjv-jx93-m7h6/GHSA-cjjv-jx93-m7h6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjjv-jx93-m7h6", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24725" + ], + "details": "Missing Authorization vulnerability in ThimPress Thim Elementor Kit allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Thim Elementor Kit: from n/a through 1.2.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24725" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/thim-elementor-kit/vulnerability/wordpress-thim-elementor-kit-plugin-1-2-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cm82-4m3m-m8hf/GHSA-cm82-4m3m-m8hf.json b/advisories/unreviewed/2025/01/GHSA-cm82-4m3m-m8hf/GHSA-cm82-4m3m-m8hf.json new file mode 100644 index 00000000000..26dee84f724 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cm82-4m3m-m8hf/GHSA-cm82-4m3m-m8hf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cm82-4m3m-m8hf", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24622" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in PickPlugins Job Board Manager allows Cross Site Request Forgery. This issue affects Job Board Manager: from n/a through 2.1.59.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24622" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/job-board-manager/vulnerability/wordpress-job-board-manager-plugin-2-1-59-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cmx2-533j-hg92/GHSA-cmx2-533j-hg92.json b/advisories/unreviewed/2025/01/GHSA-cmx2-533j-hg92/GHSA-cmx2-533j-hg92.json new file mode 100644 index 00000000000..99693d3363c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cmx2-533j-hg92/GHSA-cmx2-533j-hg92.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmx2-533j-hg92", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24575" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HelloAsso HelloAsso allows Stored XSS. This issue affects HelloAsso: from n/a through 1.1.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24575" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/helloasso/vulnerability/wordpress-helloasso-plugin-1-1-11-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cqhr-j8pc-vj2g/GHSA-cqhr-j8pc-vj2g.json b/advisories/unreviewed/2025/01/GHSA-cqhr-j8pc-vj2g/GHSA-cqhr-j8pc-vj2g.json new file mode 100644 index 00000000000..987b8893d54 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cqhr-j8pc-vj2g/GHSA-cqhr-j8pc-vj2g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqhr-j8pc-vj2g", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24679" + ], + "details": "Missing Authorization vulnerability in webraketen Internal Links Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Internal Links Manager: from n/a through 2.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24679" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/seo-automated-link-building/vulnerability/wordpress-internal-links-manager-plugin-2-5-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cxv9-hf3m-2mjw/GHSA-cxv9-hf3m-2mjw.json b/advisories/unreviewed/2025/01/GHSA-cxv9-hf3m-2mjw/GHSA-cxv9-hf3m-2mjw.json new file mode 100644 index 00000000000..5a73046fd57 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cxv9-hf3m-2mjw/GHSA-cxv9-hf3m-2mjw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxv9-hf3m-2mjw", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24638" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pete Dring Create with Code allows DOM-Based XSS. This issue affects Create with Code: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24638" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/create-with-code/vulnerability/wordpress-create-with-code-plugin-1-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f377-mvfh-526m/GHSA-f377-mvfh-526m.json b/advisories/unreviewed/2025/01/GHSA-f377-mvfh-526m/GHSA-f377-mvfh-526m.json new file mode 100644 index 00000000000..2da8180812b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f377-mvfh-526m/GHSA-f377-mvfh-526m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f377-mvfh-526m", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24610" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Christian Leuenberg, L.net Web Solutions Restrict Anonymous Access allows Stored XSS. This issue affects Restrict Anonymous Access: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24610" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/restrict-anonymous-access/vulnerability/wordpress-restrict-anonymous-access-plugin-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f3f2-368q-3f38/GHSA-f3f2-368q-3f38.json b/advisories/unreviewed/2025/01/GHSA-f3f2-368q-3f38/GHSA-f3f2-368q-3f38.json new file mode 100644 index 00000000000..7762c88ec92 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f3f2-368q-3f38/GHSA-f3f2-368q-3f38.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3f2-368q-3f38", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24634" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Svetoslav Marinov (Slavi) Orbisius Simple Notice allows Stored XSS. This issue affects Orbisius Simple Notice: from n/a through 1.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24634" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/orbisius-simple-notice/vulnerability/wordpress-orbisius-simple-notice-plugin-1-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f4wf-g9jr-v23g/GHSA-f4wf-g9jr-v23g.json b/advisories/unreviewed/2025/01/GHSA-f4wf-g9jr-v23g/GHSA-f4wf-g9jr-v23g.json new file mode 100644 index 00000000000..9dbd7648109 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f4wf-g9jr-v23g/GHSA-f4wf-g9jr-v23g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4wf-g9jr-v23g", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24722" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in F.A.Q Builder Team FAQ Builder AYS allows Stored XSS. This issue affects FAQ Builder AYS: from n/a through 1.7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24722" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/faq-builder-ays/vulnerability/wordpress-faq-builder-ays-plugin-1-7-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f9xx-p2j6-3m6j/GHSA-f9xx-p2j6-3m6j.json b/advisories/unreviewed/2025/01/GHSA-f9xx-p2j6-3m6j/GHSA-f9xx-p2j6-3m6j.json new file mode 100644 index 00000000000..373e222feb1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f9xx-p2j6-3m6j/GHSA-f9xx-p2j6-3m6j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9xx-p2j6-3m6j", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24555" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in SubscriptionDNA.com Subscription DNA allows Stored XSS. This issue affects Subscription DNA: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24555" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/subscriptiondna/vulnerability/wordpress-subscription-dna-plugin-2-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fc33-g257-p9q6/GHSA-fc33-g257-p9q6.json b/advisories/unreviewed/2025/01/GHSA-fc33-g257-p9q6/GHSA-fc33-g257-p9q6.json index 9033ff3441a..f4018bbcbc1 100644 --- a/advisories/unreviewed/2025/01/GHSA-fc33-g257-p9q6/GHSA-fc33-g257-p9q6.json +++ b/advisories/unreviewed/2025/01/GHSA-fc33-g257-p9q6/GHSA-fc33-g257-p9q6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fc33-g257-p9q6", - "modified": "2025-01-22T06:30:46Z", + "modified": "2025-01-24T18:31:12Z", "published": "2025-01-22T06:30:46Z", "aliases": [ "CVE-2024-13584" diff --git a/advisories/unreviewed/2025/01/GHSA-fg8c-xgcm-8446/GHSA-fg8c-xgcm-8446.json b/advisories/unreviewed/2025/01/GHSA-fg8c-xgcm-8446/GHSA-fg8c-xgcm-8446.json new file mode 100644 index 00000000000..fa3a75b02b7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fg8c-xgcm-8446/GHSA-fg8c-xgcm-8446.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg8c-xgcm-8446", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24658" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Hawes Auction Nudge – Your eBay on Your Site allows Stored XSS. This issue affects Auction Nudge – Your eBay on Your Site: from n/a through 7.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24658" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/auction-nudge/vulnerability/wordpress-auction-nudge-your-ebay-on-your-site-plugin-7-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fhgg-6h6w-vm63/GHSA-fhgg-6h6w-vm63.json b/advisories/unreviewed/2025/01/GHSA-fhgg-6h6w-vm63/GHSA-fhgg-6h6w-vm63.json new file mode 100644 index 00000000000..e8c9627b7d7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fhgg-6h6w-vm63/GHSA-fhgg-6h6w-vm63.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhgg-6h6w-vm63", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24721" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aleksandar Urošević Easy YouTube Gallery allows Stored XSS. This issue affects Easy YouTube Gallery: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24721" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-youtube-gallery/vulnerability/wordpress-easy-youtube-gallery-plugin-1-0-4-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fmfj-r33w-wf97/GHSA-fmfj-r33w-wf97.json b/advisories/unreviewed/2025/01/GHSA-fmfj-r33w-wf97/GHSA-fmfj-r33w-wf97.json new file mode 100644 index 00000000000..d3086267716 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fmfj-r33w-wf97/GHSA-fmfj-r33w-wf97.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmfj-r33w-wf97", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24719" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Widget Countdown allows Stored XSS. This issue affects Widget Countdown: from n/a through 2.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24719" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/widget-countdown/vulnerability/wordpress-widget-countdown-plugin-2-7-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fmq3-crhc-vf6v/GHSA-fmq3-crhc-vf6v.json b/advisories/unreviewed/2025/01/GHSA-fmq3-crhc-vf6v/GHSA-fmq3-crhc-vf6v.json new file mode 100644 index 00000000000..c55ac8b8da1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fmq3-crhc-vf6v/GHSA-fmq3-crhc-vf6v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmq3-crhc-vf6v", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24594" + ], + "details": "Missing Authorization vulnerability in Speedcomp Linet ERP-Woocommerce Integration allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Linet ERP-Woocommerce Integration: from n/a through 3.5.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24594" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/linet-erp-woocommerce-integration/vulnerability/wordpress-linet-erp-woocommerce-integration-plugin-3-5-7-csrf-to-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fq4m-wxv9-xm4c/GHSA-fq4m-wxv9-xm4c.json b/advisories/unreviewed/2025/01/GHSA-fq4m-wxv9-xm4c/GHSA-fq4m-wxv9-xm4c.json new file mode 100644 index 00000000000..6c65d606e75 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fq4m-wxv9-xm4c/GHSA-fq4m-wxv9-xm4c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq4m-wxv9-xm4c", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24589" + ], + "details": "Missing Authorization vulnerability in JS Morisset JSM Show Post Metadata allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JSM Show Post Metadata: from n/a through 4.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24589" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jsm-show-post-meta/vulnerability/wordpress-jsm-show-post-metadata-plugin-4-6-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g339-vh54-3m75/GHSA-g339-vh54-3m75.json b/advisories/unreviewed/2025/01/GHSA-g339-vh54-3m75/GHSA-g339-vh54-3m75.json new file mode 100644 index 00000000000..2f518a05331 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g339-vh54-3m75/GHSA-g339-vh54-3m75.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g339-vh54-3m75", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24698" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in G5Theme Essential Real Estate allows Cross Site Request Forgery. This issue affects Essential Real Estate: from n/a through 5.1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24698" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/essential-real-estate/vulnerability/wordpress-essential-real-estate-plugin-5-1-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g4rw-2g4w-2cmr/GHSA-g4rw-2g4w-2cmr.json b/advisories/unreviewed/2025/01/GHSA-g4rw-2g4w-2cmr/GHSA-g4rw-2g4w-2cmr.json new file mode 100644 index 00000000000..c5264ff159b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g4rw-2g4w-2cmr/GHSA-g4rw-2g4w-2cmr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4rw-2g4w-2cmr", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24728" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yannick Lefebvre Bug Library allows Blind SQL Injection. This issue affects Bug Library: from n/a through 2.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24728" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bug-library/vulnerability/wordpress-bug-library-plugin-2-1-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g5jx-rvpr-cwqr/GHSA-g5jx-rvpr-cwqr.json b/advisories/unreviewed/2025/01/GHSA-g5jx-rvpr-cwqr/GHSA-g5jx-rvpr-cwqr.json new file mode 100644 index 00000000000..cd5e6bc1958 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g5jx-rvpr-cwqr/GHSA-g5jx-rvpr-cwqr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5jx-rvpr-cwqr", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24753" + ], + "details": "Missing Authorization vulnerability in Kadence WP Gutenberg Blocks by Kadence Blocks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through 3.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24753" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/kadence-blocks/vulnerability/wordpress-kadence-blocks-plugin-3-3-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g7mw-xh95-cg69/GHSA-g7mw-xh95-cg69.json b/advisories/unreviewed/2025/01/GHSA-g7mw-xh95-cg69/GHSA-g7mw-xh95-cg69.json new file mode 100644 index 00000000000..e0744e1afbf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g7mw-xh95-cg69/GHSA-g7mw-xh95-cg69.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7mw-xh95-cg69", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24756" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in mgplugin Roi Calculator allows Stored XSS. This issue affects Roi Calculator: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24756" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/roi-calculator/vulnerability/wordpress-roi-calculator-plugin-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gc7r-v5w8-p7mh/GHSA-gc7r-v5w8-p7mh.json b/advisories/unreviewed/2025/01/GHSA-gc7r-v5w8-p7mh/GHSA-gc7r-v5w8-p7mh.json new file mode 100644 index 00000000000..07b3c09598d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gc7r-v5w8-p7mh/GHSA-gc7r-v5w8-p7mh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc7r-v5w8-p7mh", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24706" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MultiVendorX WC Marketplace allows Stored XSS. This issue affects WC Marketplace: from n/a through 4.2.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24706" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dc-woocommerce-multi-vendor/vulnerability/wordpress-multivendorx-plugin-4-2-13-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-ggj6-66q9-rcw5/GHSA-ggj6-66q9-rcw5.json b/advisories/unreviewed/2025/01/GHSA-ggj6-66q9-rcw5/GHSA-ggj6-66q9-rcw5.json new file mode 100644 index 00000000000..4de28ad6c75 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-ggj6-66q9-rcw5/GHSA-ggj6-66q9-rcw5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggj6-66q9-rcw5", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24733" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AddonMaster Post Grid Master allows PHP Local File Inclusion. This issue affects Post Grid Master: from n/a through 3.4.12.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24733" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ajax-filter-posts/vulnerability/wordpress-post-grid-master-plugin-3-4-12-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gpm9-2hwg-767x/GHSA-gpm9-2hwg-767x.json b/advisories/unreviewed/2025/01/GHSA-gpm9-2hwg-767x/GHSA-gpm9-2hwg-767x.json new file mode 100644 index 00000000000..b4d1205729c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gpm9-2hwg-767x/GHSA-gpm9-2hwg-767x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpm9-2hwg-767x", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24585" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N.O.U.S. Open Useful and Simple Event post allows Stored XSS. This issue affects Event post: from n/a through 5.9.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24585" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/event-post/vulnerability/wordpress-event-post-plugin-5-9-7-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h57h-c2xr-7qm5/GHSA-h57h-c2xr-7qm5.json b/advisories/unreviewed/2025/01/GHSA-h57h-c2xr-7qm5/GHSA-h57h-c2xr-7qm5.json new file mode 100644 index 00000000000..1cfc054c1d6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h57h-c2xr-7qm5/GHSA-h57h-c2xr-7qm5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h57h-c2xr-7qm5", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24696" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP Attire Attire Blocks allows Cross Site Request Forgery. This issue affects Attire Blocks: from n/a through 1.9.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24696" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/attire-blocks/vulnerability/wordpress-gutenberg-blocks-and-page-layouts-plugin-1-9-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h926-63hm-5vc6/GHSA-h926-63hm-5vc6.json b/advisories/unreviewed/2025/01/GHSA-h926-63hm-5vc6/GHSA-h926-63hm-5vc6.json new file mode 100644 index 00000000000..3e1d5b4d3b3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h926-63hm-5vc6/GHSA-h926-63hm-5vc6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h926-63hm-5vc6", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24580" + ], + "details": "Missing Authorization vulnerability in Code for Recovery 12 Step Meeting List allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects 12 Step Meeting List: from n/a through 3.16.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24580" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/12-step-meeting-list/vulnerability/wordpress-12-step-meeting-list-plugin-3-16-5-arbitrary-content-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j3jv-7rhv-xvrw/GHSA-j3jv-7rhv-xvrw.json b/advisories/unreviewed/2025/01/GHSA-j3jv-7rhv-xvrw/GHSA-j3jv-7rhv-xvrw.json new file mode 100644 index 00000000000..528bc7c4ec5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j3jv-7rhv-xvrw/GHSA-j3jv-7rhv-xvrw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3jv-7rhv-xvrw", + "modified": "2025-01-24T18:31:13Z", + "published": "2025-01-24T18:31:13Z", + "aliases": [ + "CVE-2025-24552" + ], + "details": "Generation of Error Message Containing Sensitive Information vulnerability in David de Boer Paytium allows Retrieve Embedded Sensitive Data. This issue affects Paytium: from n/a through 4.4.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24552" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/paytium/vulnerability/wordpress-paytium-plugin-4-4-11-full-path-disclosure-fpd-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j44m-7853-52q2/GHSA-j44m-7853-52q2.json b/advisories/unreviewed/2025/01/GHSA-j44m-7853-52q2/GHSA-j44m-7853-52q2.json new file mode 100644 index 00000000000..7a98f683ce8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j44m-7853-52q2/GHSA-j44m-7853-52q2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j44m-7853-52q2", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24727" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodePeople Contact Form Email allows Stored XSS. This issue affects Contact Form Email: from n/a through 1.3.52.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24727" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/contact-form-to-email/vulnerability/wordpress-contact-form-to-email-plugin-1-3-52-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j4c9-86rf-q9fc/GHSA-j4c9-86rf-q9fc.json b/advisories/unreviewed/2025/01/GHSA-j4c9-86rf-q9fc/GHSA-j4c9-86rf-q9fc.json new file mode 100644 index 00000000000..7e5d37d39ed --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j4c9-86rf-q9fc/GHSA-j4c9-86rf-q9fc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4c9-86rf-q9fc", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24659" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WordPress Download Manager Premium Packages allows Blind SQL Injection. This issue affects Premium Packages: from n/a through 5.9.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24659" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpdm-premium-packages/vulnerability/wordpress-premium-packages-sell-digital-products-securely-plugin-5-9-6-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j73w-mhfq-5m8p/GHSA-j73w-mhfq-5m8p.json b/advisories/unreviewed/2025/01/GHSA-j73w-mhfq-5m8p/GHSA-j73w-mhfq-5m8p.json new file mode 100644 index 00000000000..68f3402f052 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j73w-mhfq-5m8p/GHSA-j73w-mhfq-5m8p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j73w-mhfq-5m8p", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24613" + ], + "details": "Missing Authorization vulnerability in Foliovision FV Thoughtful Comments allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FV Thoughtful Comments: from n/a through 0.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24613" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/thoughtful-comments/vulnerability/wordpress-fv-thoughtful-comments-plugin-0-3-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jfgp-w7cm-f72g/GHSA-jfgp-w7cm-f72g.json b/advisories/unreviewed/2025/01/GHSA-jfgp-w7cm-f72g/GHSA-jfgp-w7cm-f72g.json new file mode 100644 index 00000000000..0cad4ea8c5c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jfgp-w7cm-f72g/GHSA-jfgp-w7cm-f72g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfgp-w7cm-f72g", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24720" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Sticky Buttons allows Cross Site Request Forgery. This issue affects Sticky Buttons: from n/a through 4.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24720" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sticky-buttons/vulnerability/wordpress-sticky-buttons-plugin-4-1-1-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jfm3-jh2m-2h53/GHSA-jfm3-jh2m-2h53.json b/advisories/unreviewed/2025/01/GHSA-jfm3-jh2m-2h53/GHSA-jfm3-jh2m-2h53.json new file mode 100644 index 00000000000..d46bbcbac7d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jfm3-jh2m-2h53/GHSA-jfm3-jh2m-2h53.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfm3-jh2m-2h53", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24701" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Kiboko Labs Chained Quiz allows Server Side Request Forgery. This issue affects Chained Quiz: from n/a through 1.3.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24701" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/chained-quiz/vulnerability/wordpress-chained-quiz-plugin-1-3-2-9-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jh7p-hgv5-5cq4/GHSA-jh7p-hgv5-5cq4.json b/advisories/unreviewed/2025/01/GHSA-jh7p-hgv5-5cq4/GHSA-jh7p-hgv5-5cq4.json new file mode 100644 index 00000000000..3dea883890c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jh7p-hgv5-5cq4/GHSA-jh7p-hgv5-5cq4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jh7p-hgv5-5cq4", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24633" + ], + "details": "Missing Authorization vulnerability in silverplugins217 Build Private Store For Woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Build Private Store For Woocommerce: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24633" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/build-private-store-for-woocommerce/vulnerability/wordpress-build-private-store-for-woocommerce-plugin-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jjg7-9c8p-q57r/GHSA-jjg7-9c8p-q57r.json b/advisories/unreviewed/2025/01/GHSA-jjg7-9c8p-q57r/GHSA-jjg7-9c8p-q57r.json new file mode 100644 index 00000000000..f2be8e891ff --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jjg7-9c8p-q57r/GHSA-jjg7-9c8p-q57r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjg7-9c8p-q57r", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24673" + ], + "details": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in AyeCode Ltd Ketchup Shortcodes allows Stored XSS. This issue affects Ketchup Shortcodes: from n/a through 0.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24673" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ketchup-shortcodes-pack/vulnerability/wordpress-ketchup-shortcodes-plugin-0-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jqj4-ghqx-v4jp/GHSA-jqj4-ghqx-v4jp.json b/advisories/unreviewed/2025/01/GHSA-jqj4-ghqx-v4jp/GHSA-jqj4-ghqx-v4jp.json new file mode 100644 index 00000000000..87286267c19 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jqj4-ghqx-v4jp/GHSA-jqj4-ghqx-v4jp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqj4-ghqx-v4jp", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24729" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ElementInvader ElementInvader Addons for Elementor allows Stored XSS. This issue affects ElementInvader Addons for Elementor: from n/a through 1.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24729" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/elementinvader-addons-for-elementor/vulnerability/wordpress-elementinvader-addons-for-elementor-plugin-1-3-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jxg6-2hxp-8xg9/GHSA-jxg6-2hxp-8xg9.json b/advisories/unreviewed/2025/01/GHSA-jxg6-2hxp-8xg9/GHSA-jxg6-2hxp-8xg9.json new file mode 100644 index 00000000000..483e4bbdc96 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jxg6-2hxp-8xg9/GHSA-jxg6-2hxp-8xg9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxg6-2hxp-8xg9", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24649" + ], + "details": "Missing Authorization vulnerability in wpase.com Admin and Site Enhancements (ASE) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Admin and Site Enhancements (ASE): from n/a through 7.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24649" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/admin-site-enhancements/vulnerability/wordpress-admin-and-site-enhancements-ase-plugin-7-6-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jxqj-8qmq-4r2x/GHSA-jxqj-8qmq-4r2x.json b/advisories/unreviewed/2025/01/GHSA-jxqj-8qmq-4r2x/GHSA-jxqj-8qmq-4r2x.json new file mode 100644 index 00000000000..492c84d5c18 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jxqj-8qmq-4r2x/GHSA-jxqj-8qmq-4r2x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxqj-8qmq-4r2x", + "modified": "2025-01-24T18:31:12Z", + "published": "2025-01-24T18:31:12Z", + "aliases": [ + "CVE-2024-40706" + ], + "details": "IBM InfoSphere Information Server 11.7 could allow a remote user to obtain sensitive version information that could aid in further attacks against the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40706" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7169826" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m2wm-46c6-h3mf/GHSA-m2wm-46c6-h3mf.json b/advisories/unreviewed/2025/01/GHSA-m2wm-46c6-h3mf/GHSA-m2wm-46c6-h3mf.json new file mode 100644 index 00000000000..a41dbe6820a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m2wm-46c6-h3mf/GHSA-m2wm-46c6-h3mf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2wm-46c6-h3mf", + "modified": "2025-01-24T18:31:13Z", + "published": "2025-01-24T18:31:13Z", + "aliases": [ + "CVE-2025-24547" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matthias Wagner - FALKEmedia Caching Compatible Cookie Opt-In and JavaScript allows Stored XSS. This issue affects Caching Compatible Cookie Opt-In and JavaScript: from n/a through 0.0.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24547" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/caching-compatible-cookie-optin-and-javascript/vulnerability/wordpress-caching-compatible-cookie-opt-in-plugin-0-0-10-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m7rj-x62g-9rjj/GHSA-m7rj-x62g-9rjj.json b/advisories/unreviewed/2025/01/GHSA-m7rj-x62g-9rjj/GHSA-m7rj-x62g-9rjj.json new file mode 100644 index 00000000000..f6e007c9715 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m7rj-x62g-9rjj/GHSA-m7rj-x62g-9rjj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7rj-x62g-9rjj", + "modified": "2025-01-24T18:31:12Z", + "published": "2025-01-24T18:31:12Z", + "aliases": [ + "CVE-2024-45077" + ], + "details": "IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload which allows authenticated low privileged user to upload restricted file types with a simple method of adding a dot to the end of the file name if Maximo is installed on Windows operating system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45077" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7174819" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m7x4-vmph-gfvr/GHSA-m7x4-vmph-gfvr.json b/advisories/unreviewed/2025/01/GHSA-m7x4-vmph-gfvr/GHSA-m7x4-vmph-gfvr.json new file mode 100644 index 00000000000..baaaf124f37 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m7x4-vmph-gfvr/GHSA-m7x4-vmph-gfvr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7x4-vmph-gfvr", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24647" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in datafeedr.com WooCommerce Cloak Affiliate Links allows Cross Site Request Forgery. This issue affects WooCommerce Cloak Affiliate Links: from n/a through 1.0.35.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24647" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-cloak-affiliate-links/vulnerability/wordpress-woocommerce-cloak-affiliate-links-plugin-1-0-35-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mcj2-mqj3-5r2j/GHSA-mcj2-mqj3-5r2j.json b/advisories/unreviewed/2025/01/GHSA-mcj2-mqj3-5r2j/GHSA-mcj2-mqj3-5r2j.json new file mode 100644 index 00000000000..0504bec1d55 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mcj2-mqj3-5r2j/GHSA-mcj2-mqj3-5r2j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcj2-mqj3-5r2j", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24591" + ], + "details": "Missing Authorization vulnerability in NinjaTeam GDPR CCPA Compliance Support allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GDPR CCPA Compliance Support: from n/a through 2.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24591" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ninja-gdpr-compliance/vulnerability/wordpress-gdpr-ccpa-compliance-cookie-consent-banner-plugin-2-7-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mj89-3fcv-c7jq/GHSA-mj89-3fcv-c7jq.json b/advisories/unreviewed/2025/01/GHSA-mj89-3fcv-c7jq/GHSA-mj89-3fcv-c7jq.json new file mode 100644 index 00000000000..c0d60e6231a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mj89-3fcv-c7jq/GHSA-mj89-3fcv-c7jq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mj89-3fcv-c7jq", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24738" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in NowButtons.com Call Now Button allows Cross Site Request Forgery. This issue affects Call Now Button: from n/a through 1.4.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24738" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/call-now-button/vulnerability/wordpress-call-now-button-plugin-1-4-13-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mv5m-5jxg-q38h/GHSA-mv5m-5jxg-q38h.json b/advisories/unreviewed/2025/01/GHSA-mv5m-5jxg-q38h/GHSA-mv5m-5jxg-q38h.json new file mode 100644 index 00000000000..45c6aabf323 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mv5m-5jxg-q38h/GHSA-mv5m-5jxg-q38h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv5m-5jxg-q38h", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24709" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plethora Plugins Plethora Plugins Tabs + Accordions allows Stored XSS. This issue affects Plethora Plugins Tabs + Accordions: from n/a through 1.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24709" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/plethora-tabs-accordions/vulnerability/wordpress-plethora-plugins-tabs-accordions-plugin-1-1-5-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p43r-vvqq-vqcj/GHSA-p43r-vvqq-vqcj.json b/advisories/unreviewed/2025/01/GHSA-p43r-vvqq-vqcj/GHSA-p43r-vvqq-vqcj.json new file mode 100644 index 00000000000..a58cba81b4e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p43r-vvqq-vqcj/GHSA-p43r-vvqq-vqcj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p43r-vvqq-vqcj", + "modified": "2025-01-24T18:31:13Z", + "published": "2025-01-24T18:31:13Z", + "aliases": [ + "CVE-2024-35122" + ], + "details": "IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to a file level local denial of service caused by an insufficient authority requirement. A local non-privileged user can configure a referential constraint with the privileges of a user socially engineered to access the target file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35122" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7178317" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p93h-x2hj-qcf8/GHSA-p93h-x2hj-qcf8.json b/advisories/unreviewed/2025/01/GHSA-p93h-x2hj-qcf8/GHSA-p93h-x2hj-qcf8.json new file mode 100644 index 00000000000..fb365291eec --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p93h-x2hj-qcf8/GHSA-p93h-x2hj-qcf8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p93h-x2hj-qcf8", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24650" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic allows Upload a Web Shell to a Web Server. This issue affects Tourfic: from n/a through 2.15.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24650" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tourfic/vulnerability/wordpress-tourfic-plugin-2-15-3-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pf3h-gh3r-gj26/GHSA-pf3h-gh3r-gj26.json b/advisories/unreviewed/2025/01/GHSA-pf3h-gh3r-gj26/GHSA-pf3h-gh3r-gj26.json new file mode 100644 index 00000000000..3e1c6461e0b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pf3h-gh3r-gj26/GHSA-pf3h-gh3r-gj26.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf3h-gh3r-gj26", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24731" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IP2Location Download IP2Location Country Blocker allows Stored XSS. This issue affects Download IP2Location Country Blocker: from n/a through 2.38.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24731" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ip2location-country-blocker/vulnerability/wordpress-ip2location-country-blocker-plugin-2-38-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pw24-xh85-3q7g/GHSA-pw24-xh85-3q7g.json b/advisories/unreviewed/2025/01/GHSA-pw24-xh85-3q7g/GHSA-pw24-xh85-3q7g.json new file mode 100644 index 00000000000..f1a9363c52f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pw24-xh85-3q7g/GHSA-pw24-xh85-3q7g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw24-xh85-3q7g", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24704" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sebastian Zaha Magic the Gathering Card Tooltips allows Stored XSS. This issue affects Magic the Gathering Card Tooltips: from n/a through 3.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24704" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/magic-the-gathering-card-tooltips/vulnerability/wordpress-magic-the-gathering-card-tooltips-plugin-3-4-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-px9r-jcp7-fvj6/GHSA-px9r-jcp7-fvj6.json b/advisories/unreviewed/2025/01/GHSA-px9r-jcp7-fvj6/GHSA-px9r-jcp7-fvj6.json new file mode 100644 index 00000000000..d12e46d02f6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-px9r-jcp7-fvj6/GHSA-px9r-jcp7-fvj6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px9r-jcp7-fvj6", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24604" + ], + "details": "Missing Authorization vulnerability in Vikas Ratudi VForm allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects VForm: from n/a through 3.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24604" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/v-form/vulnerability/wordpress-lifetime-free-drag-drop-contact-form-builder-for-wordpress-vform-plugin-3-0-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q5g5-8h98-5fq6/GHSA-q5g5-8h98-5fq6.json b/advisories/unreviewed/2025/01/GHSA-q5g5-8h98-5fq6/GHSA-q5g5-8h98-5fq6.json new file mode 100644 index 00000000000..1c268f1e113 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q5g5-8h98-5fq6/GHSA-q5g5-8h98-5fq6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5g5-8h98-5fq6", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24618" + ], + "details": "Missing Authorization vulnerability in ElementInvader ElementInvader Addons for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementInvader Addons for Elementor: from n/a through 1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24618" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/elementinvader-addons-for-elementor/vulnerability/wordpress-elementinvader-addons-for-elementor-plugin-1-3-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q9j3-xwrw-7cx6/GHSA-q9j3-xwrw-7cx6.json b/advisories/unreviewed/2025/01/GHSA-q9j3-xwrw-7cx6/GHSA-q9j3-xwrw-7cx6.json new file mode 100644 index 00000000000..e1e9e771423 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q9j3-xwrw-7cx6/GHSA-q9j3-xwrw-7cx6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9j3-xwrw-7cx6", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24627" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Linnea Huxford, LinSoftware Blur Text allows Stored XSS. This issue affects Blur Text: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24627" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/blur-text/vulnerability/wordpress-blur-text-plugin-1-0-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qm87-37gc-qg37/GHSA-qm87-37gc-qg37.json b/advisories/unreviewed/2025/01/GHSA-qm87-37gc-qg37/GHSA-qm87-37gc-qg37.json new file mode 100644 index 00000000000..39ce99c2223 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qm87-37gc-qg37/GHSA-qm87-37gc-qg37.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm87-37gc-qg37", + "modified": "2025-01-24T18:31:13Z", + "published": "2025-01-24T18:31:13Z", + "aliases": [ + "CVE-2025-0700" + ], + "details": "A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/sys/log/list. The manipulation of the argument logId leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0700" + }, + { + "type": "WEB", + "url": "https://github.com/JoeyBling/bootplus/issues/22" + }, + { + "type": "WEB", + "url": "https://github.com/JoeyBling/bootplus/issues/22#issue-2786899884" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.293228" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.293228" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.480838" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r3m6-9xgf-3f9v/GHSA-r3m6-9xgf-3f9v.json b/advisories/unreviewed/2025/01/GHSA-r3m6-9xgf-3f9v/GHSA-r3m6-9xgf-3f9v.json new file mode 100644 index 00000000000..f2928be48dd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r3m6-9xgf-3f9v/GHSA-r3m6-9xgf-3f9v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3m6-9xgf-3f9v", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24711" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Popup Box allows Cross Site Request Forgery. This issue affects Popup Box: from n/a through 3.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24711" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/popup-box/vulnerability/wordpress-popup-box-plugin-3-2-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r4wv-hr59-ggm2/GHSA-r4wv-hr59-ggm2.json b/advisories/unreviewed/2025/01/GHSA-r4wv-hr59-ggm2/GHSA-r4wv-hr59-ggm2.json new file mode 100644 index 00000000000..87a22744d62 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r4wv-hr59-ggm2/GHSA-r4wv-hr59-ggm2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4wv-hr59-ggm2", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24732" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Booking & Appointment - Repute Infosystems BookingPress allows DOM-Based XSS. This issue affects BookingPress: from n/a through 1.1.25.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24732" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bookingpress-appointment-booking/vulnerability/wordpress-bookingpress-plugin-1-1-25-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r634-5v75-69xx/GHSA-r634-5v75-69xx.json b/advisories/unreviewed/2025/01/GHSA-r634-5v75-69xx/GHSA-r634-5v75-69xx.json new file mode 100644 index 00000000000..07a8dd7b5f9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r634-5v75-69xx/GHSA-r634-5v75-69xx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r634-5v75-69xx", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24702" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xagio Xagio SEO allows Stored XSS. This issue affects Xagio SEO: from n/a through 7.0.0.20.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24702" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/xagio-seo/vulnerability/wordpress-xagio-seo-plugin-7-0-0-20-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r7jj-xx6g-89w3/GHSA-r7jj-xx6g-89w3.json b/advisories/unreviewed/2025/01/GHSA-r7jj-xx6g-89w3/GHSA-r7jj-xx6g-89w3.json new file mode 100644 index 00000000000..4e10268d5b3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r7jj-xx6g-89w3/GHSA-r7jj-xx6g-89w3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7jj-xx6g-89w3", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24672" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodePeople Form Builder CP allows SQL Injection. This issue affects Form Builder CP: from n/a through 1.2.41.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24672" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cp-easy-form-builder/vulnerability/wordpress-form-builder-cp-plugin-1-2-41-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r7xj-pwvr-9j47/GHSA-r7xj-pwvr-9j47.json b/advisories/unreviewed/2025/01/GHSA-r7xj-pwvr-9j47/GHSA-r7xj-pwvr-9j47.json new file mode 100644 index 00000000000..5673971395b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r7xj-pwvr-9j47/GHSA-r7xj-pwvr-9j47.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7xj-pwvr-9j47", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24623" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Security Really Simple SSL allows Cross Site Request Forgery. This issue affects Really Simple SSL: from n/a through 9.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24623" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/really-simple-ssl/vulnerability/wordpress-really-simple-security-plugin-9-1-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rhg7-3675-h757/GHSA-rhg7-3675-h757.json b/advisories/unreviewed/2025/01/GHSA-rhg7-3675-h757/GHSA-rhg7-3675-h757.json new file mode 100644 index 00000000000..9f3080b6fd6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rhg7-3675-h757/GHSA-rhg7-3675-h757.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhg7-3675-h757", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24716" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Herd Effects allows Cross Site Request Forgery. This issue affects Herd Effects: from n/a through 6.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24716" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mwp-herd-effect/vulnerability/wordpress-herd-effects-plugin-6-2-1-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rhmc-gg97-3jw8/GHSA-rhmc-gg97-3jw8.json b/advisories/unreviewed/2025/01/GHSA-rhmc-gg97-3jw8/GHSA-rhmc-gg97-3jw8.json new file mode 100644 index 00000000000..485d405693b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rhmc-gg97-3jw8/GHSA-rhmc-gg97-3jw8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhmc-gg97-3jw8", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24726" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Conctact Form 7 allows Stored XSS. This issue affects HT Conctact Form 7: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24726" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ht-contactform/vulnerability/wordpress-contact-form-7-widget-plugin-1-2-1-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rx9w-c6jv-2grg/GHSA-rx9w-c6jv-2grg.json b/advisories/unreviewed/2025/01/GHSA-rx9w-c6jv-2grg/GHSA-rx9w-c6jv-2grg.json new file mode 100644 index 00000000000..6e4bb13fce6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rx9w-c6jv-2grg/GHSA-rx9w-c6jv-2grg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx9w-c6jv-2grg", + "modified": "2025-01-24T18:31:13Z", + "published": "2025-01-24T18:31:13Z", + "aliases": [ + "CVE-2019-15690" + ], + "details": "LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-15690" + }, + { + "type": "WEB", + "url": "https://ics-cert.kaspersky.com/vulnerabilities/klcert-20-009-remote-code-execution-on-libvnc-version-prior-to-0-9-12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v33p-6qfg-8qqq/GHSA-v33p-6qfg-8qqq.json b/advisories/unreviewed/2025/01/GHSA-v33p-6qfg-8qqq/GHSA-v33p-6qfg-8qqq.json new file mode 100644 index 00000000000..78c0b7868a5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v33p-6qfg-8qqq/GHSA-v33p-6qfg-8qqq.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v33p-6qfg-8qqq", + "modified": "2025-01-24T18:31:13Z", + "published": "2025-01-24T18:31:12Z", + "aliases": [ + "CVE-2025-0699" + ], + "details": "A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/sys/role/list. The manipulation of the argument sort leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0699" + }, + { + "type": "WEB", + "url": "https://github.com/JoeyBling/bootplus/issues/21" + }, + { + "type": "WEB", + "url": "https://github.com/JoeyBling/bootplus/issues/21#issue-2786893665" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.293227" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.293227" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.480836" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T16:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v64q-g9rj-xx9j/GHSA-v64q-g9rj-xx9j.json b/advisories/unreviewed/2025/01/GHSA-v64q-g9rj-xx9j/GHSA-v64q-g9rj-xx9j.json new file mode 100644 index 00000000000..e871e131197 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v64q-g9rj-xx9j/GHSA-v64q-g9rj-xx9j.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v64q-g9rj-xx9j", + "modified": "2025-01-24T18:31:13Z", + "published": "2025-01-24T18:31:13Z", + "aliases": [ + "CVE-2024-56404" + ], + "details": "In One Identity Identity Manager 9.x before 9.3, an insecure direct object reference (IDOR) vulnerability allows privilege escalation. Only On-Premise installations are affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56404" + }, + { + "type": "WEB", + "url": "https://support.oneidentity.com/product-notification/noti-00001678" + }, + { + "type": "WEB", + "url": "https://support.oneidentity.com/technical-documents/identity-manager/9.3/release-notes" + }, + { + "type": "WEB", + "url": "https://www.oneidentity.com/community/identity-manager" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-302" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vgvg-jgvw-9xgg/GHSA-vgvg-jgvw-9xgg.json b/advisories/unreviewed/2025/01/GHSA-vgvg-jgvw-9xgg/GHSA-vgvg-jgvw-9xgg.json new file mode 100644 index 00000000000..c3f5b994725 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vgvg-jgvw-9xgg/GHSA-vgvg-jgvw-9xgg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgvg-jgvw-9xgg", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24705" + ], + "details": "Missing Authorization vulnerability in Arshid WooCommerce Quick View allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WooCommerce Quick View: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24705" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-quick-view/vulnerability/wordpress-woocommerce-quick-view-plugin-1-1-1-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vv36-mwqg-q796/GHSA-vv36-mwqg-q796.json b/advisories/unreviewed/2025/01/GHSA-vv36-mwqg-q796/GHSA-vv36-mwqg-q796.json new file mode 100644 index 00000000000..2f17e2d6da4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vv36-mwqg-q796/GHSA-vv36-mwqg-q796.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv36-mwqg-q796", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24561" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ReviewsTap ReviewsTap allows Stored XSS. This issue affects ReviewsTap: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24561" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/reviewstap/vulnerability/wordpress-reviewstap-plugin-1-1-2-csrf-to-stored-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vv54-2hxr-6q8g/GHSA-vv54-2hxr-6q8g.json b/advisories/unreviewed/2025/01/GHSA-vv54-2hxr-6q8g/GHSA-vv54-2hxr-6q8g.json new file mode 100644 index 00000000000..65e9d209c89 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vv54-2hxr-6q8g/GHSA-vv54-2hxr-6q8g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv54-2hxr-6q8g", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24578" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ElementInvader ElementInvader Addons for Elementor allows DOM-Based XSS. This issue affects ElementInvader Addons for Elementor: from n/a through 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24578" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/elementinvader-addons-for-elementor/vulnerability/wordpress-elementinvader-addons-for-elementor-plugin-1-3-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vv78-q2h7-6xc8/GHSA-vv78-q2h7-6xc8.json b/advisories/unreviewed/2025/01/GHSA-vv78-q2h7-6xc8/GHSA-vv78-q2h7-6xc8.json new file mode 100644 index 00000000000..c906ecdd801 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vv78-q2h7-6xc8/GHSA-vv78-q2h7-6xc8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv78-q2h7-6xc8", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24570" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atarim Atarim allows Stored XSS. This issue affects Atarim: from n/a through 4.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24570" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/atarim-visual-collaboration/vulnerability/wordpress-atarim-plugin-4-0-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vvqf-9323-5hxg/GHSA-vvqf-9323-5hxg.json b/advisories/unreviewed/2025/01/GHSA-vvqf-9323-5hxg/GHSA-vvqf-9323-5hxg.json new file mode 100644 index 00000000000..9ace20a0864 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vvqf-9323-5hxg/GHSA-vvqf-9323-5hxg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvqf-9323-5hxg", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24636" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Laymance Technologies LLC MachForm Shortcode allows Stored XSS. This issue affects MachForm Shortcode: from n/a through 1.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24636" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/machform-shortcode/vulnerability/wordpress-machform-shortcode-plugin-1-4-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w6fj-qr27-8g23/GHSA-w6fj-qr27-8g23.json b/advisories/unreviewed/2025/01/GHSA-w6fj-qr27-8g23/GHSA-w6fj-qr27-8g23.json new file mode 100644 index 00000000000..96fd27688b4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w6fj-qr27-8g23/GHSA-w6fj-qr27-8g23.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6fj-qr27-8g23", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24723" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodePeople Booking Calendar Contact Form allows Stored XSS. This issue affects Booking Calendar Contact Form: from n/a through 1.2.55.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24723" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/booking-calendar-contact-form/vulnerability/wordpress-booking-calendar-contact-form-plugin-1-2-55-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w6q5-wwh8-6fjf/GHSA-w6q5-wwh8-6fjf.json b/advisories/unreviewed/2025/01/GHSA-w6q5-wwh8-6fjf/GHSA-w6q5-wwh8-6fjf.json new file mode 100644 index 00000000000..928bcf1bf6b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w6q5-wwh8-6fjf/GHSA-w6q5-wwh8-6fjf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6q5-wwh8-6fjf", + "modified": "2025-01-24T18:31:13Z", + "published": "2025-01-24T18:31:13Z", + "aliases": [ + "CVE-2025-23991" + ], + "details": "Missing Authorization vulnerability in theDotstore Product Size Charts Plugin for WooCommerce.This issue affects Product Size Charts Plugin for WooCommerce: from n/a through 2.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23991" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-advanced-product-size-chart/vulnerability/wordpress-product-size-charts-plugin-for-woocommerce-plugin-2-4-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wggx-64pj-vx67/GHSA-wggx-64pj-vx67.json b/advisories/unreviewed/2025/01/GHSA-wggx-64pj-vx67/GHSA-wggx-64pj-vx67.json new file mode 100644 index 00000000000..3501f90783e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wggx-64pj-vx67/GHSA-wggx-64pj-vx67.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wggx-64pj-vx67", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24750" + ], + "details": "Missing Authorization vulnerability in ExactMetrics ExactMetrics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ExactMetrics: from n/a through 8.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24750" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/google-analytics-dashboard-for-wp/vulnerability/wordpress-exactmetrics-plugin-8-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wh29-96gw-42p6/GHSA-wh29-96gw-42p6.json b/advisories/unreviewed/2025/01/GHSA-wh29-96gw-42p6/GHSA-wh29-96gw-42p6.json new file mode 100644 index 00000000000..0d760441972 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wh29-96gw-42p6/GHSA-wh29-96gw-42p6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh29-96gw-42p6", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24611" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Smackcoders WP Ultimate Exporter allows Absolute Path Traversal. This issue affects WP Ultimate Exporter: from n/a through 2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24611" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-ultimate-exporter/vulnerability/wordpress-export-all-posts-products-orders-refunds-users-plugin-2-9-arbitrary-file-read-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x28g-5xx3-xcpg/GHSA-x28g-5xx3-xcpg.json b/advisories/unreviewed/2025/01/GHSA-x28g-5xx3-xcpg/GHSA-x28g-5xx3-xcpg.json new file mode 100644 index 00000000000..ffbf57c25bd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x28g-5xx3-xcpg/GHSA-x28g-5xx3-xcpg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x28g-5xx3-xcpg", + "modified": "2025-01-24T18:31:14Z", + "published": "2025-01-24T18:31:14Z", + "aliases": [ + "CVE-2025-24625" + ], + "details": "Missing Authorization vulnerability in Marco Almeida | Webdados Taxonomy/Term and Role based Discounts for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Taxonomy/Term and Role based Discounts for WooCommerce: from n/a through 5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24625" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/taxonomy-discounts-woocommerce/vulnerability/wordpress-taxonomy-term-and-role-based-discounts-for-woocommerce-plugin-5-1-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x44f-5mqw-wm87/GHSA-x44f-5mqw-wm87.json b/advisories/unreviewed/2025/01/GHSA-x44f-5mqw-wm87/GHSA-x44f-5mqw-wm87.json new file mode 100644 index 00000000000..251ae20d4ae --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x44f-5mqw-wm87/GHSA-x44f-5mqw-wm87.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x44f-5mqw-wm87", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24666" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeIsle AI Chatbot for WordPress – Hyve Lite allows Stored XSS. This issue affects AI Chatbot for WordPress – Hyve Lite: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24666" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hyve-lite/vulnerability/wordpress-hyve-lite-plugin-1-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x896-jjgf-wjp7/GHSA-x896-jjgf-wjp7.json b/advisories/unreviewed/2025/01/GHSA-x896-jjgf-wjp7/GHSA-x896-jjgf-wjp7.json new file mode 100644 index 00000000000..44804d8d9a3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x896-jjgf-wjp7/GHSA-x896-jjgf-wjp7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x896-jjgf-wjp7", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24669" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SERPed SERPed.net allows SQL Injection. This issue affects SERPed.net: from n/a through 4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24669" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/serped-net/vulnerability/wordpress-serped-net-plugin-4-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x9p2-255h-fh6r/GHSA-x9p2-255h-fh6r.json b/advisories/unreviewed/2025/01/GHSA-x9p2-255h-fh6r/GHSA-x9p2-255h-fh6r.json new file mode 100644 index 00000000000..f42668b4135 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x9p2-255h-fh6r/GHSA-x9p2-255h-fh6r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9p2-255h-fh6r", + "modified": "2025-01-24T18:31:13Z", + "published": "2025-01-24T18:31:13Z", + "aliases": [ + "CVE-2025-24543" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in RSTheme Ultimate Coming Soon & Maintenance allows Cross Site Request Forgery. This issue affects Ultimate Coming Soon & Maintenance: from n/a through 1.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24543" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-coming-soon/vulnerability/wordpress-ultimate-coming-soon-maintenance-plugin-1-0-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xc38-wv63-jhgw/GHSA-xc38-wv63-jhgw.json b/advisories/unreviewed/2025/01/GHSA-xc38-wv63-jhgw/GHSA-xc38-wv63-jhgw.json new file mode 100644 index 00000000000..99435039f87 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xc38-wv63-jhgw/GHSA-xc38-wv63-jhgw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xc38-wv63-jhgw", + "modified": "2025-01-24T18:31:15Z", + "published": "2025-01-24T18:31:15Z", + "aliases": [ + "CVE-2025-24693" + ], + "details": "Missing Authorization vulnerability in Yehi Advanced Notifications allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Advanced Notifications: from n/a through 1.2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24693" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-notifications/vulnerability/wordpress-advanced-notifications-plugin-1-2-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xv3x-4h27-q4j5/GHSA-xv3x-4h27-q4j5.json b/advisories/unreviewed/2025/01/GHSA-xv3x-4h27-q4j5/GHSA-xv3x-4h27-q4j5.json new file mode 100644 index 00000000000..8207b5a9ae4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xv3x-4h27-q4j5/GHSA-xv3x-4h27-q4j5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv3x-4h27-q4j5", + "modified": "2025-01-24T18:31:16Z", + "published": "2025-01-24T18:31:16Z", + "aliases": [ + "CVE-2025-24739" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in FluentSMTP & WPManageNinja Team FluentSMTP allows Cross Site Request Forgery. This issue affects FluentSMTP: from n/a through 2.2.80.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24739" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fluent-smtp/vulnerability/wordpress-fluentsmtp-plugin-2-2-80-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T18:15:48Z" + } +} \ No newline at end of file