From d91a29078ea4bdb92030c001ffdc6709f2873270 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 9 Apr 2025 18:32:33 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-47xh-88vf-mqw7.json | 2 +- .../GHSA-5c9w-vq5m-266h.json | 3 +- .../GHSA-g5qg-593p-j5gq.json | 6 ++-- .../GHSA-gg38-fph6-54g7.json | 4 ++- .../GHSA-hr2h-gpm8-8hqc.json | 3 +- .../GHSA-jc4j-5j4g-r9cv.json | 6 ++-- .../GHSA-m5jj-959w-4x33.json | 4 ++- .../GHSA-vfm9-f37f-c9j3.json | 6 ++-- .../GHSA-3w7c-xcfc-fcwc.json | 6 ++-- .../GHSA-4q5q-v9v4-9c33.json | 4 +-- .../GHSA-59hg-3x57-2mwj.json | 4 +-- .../GHSA-9qr6-r6j4-qfxh.json | 4 +-- .../GHSA-r26g-5xh6-pgwp.json | 6 ++-- .../GHSA-xph7-pm58-q56v.json | 4 +-- .../GHSA-j8x5-54p6-cqvm.json | 6 +++- .../GHSA-24q3-2w85-x8p7.json | 36 +++++++++++++++++++ .../GHSA-24xg-93rh-whf7.json | 36 +++++++++++++++++++ .../GHSA-299q-fv2g-6cv8.json | 36 +++++++++++++++++++ .../GHSA-29pc-4j9r-26vc.json | 36 +++++++++++++++++++ .../GHSA-2cgp-x82p-v5h2.json | 36 +++++++++++++++++++ .../GHSA-2gx7-rx3r-f497.json | 36 +++++++++++++++++++ .../GHSA-2jm5-gphf-c739.json | 36 +++++++++++++++++++ .../GHSA-2mf6-qwmh-746g.json | 36 +++++++++++++++++++ .../GHSA-2qxx-8p5c-f68v.json | 36 +++++++++++++++++++ .../GHSA-33rx-6fc2-f369.json | 36 +++++++++++++++++++ .../GHSA-33xp-9q65-cm27.json | 36 +++++++++++++++++++ .../GHSA-35pc-r523-37pv.json | 36 +++++++++++++++++++ .../GHSA-3854-mvcm-fg9r.json | 36 +++++++++++++++++++ .../GHSA-3j2q-q8wr-v983.json | 36 +++++++++++++++++++ .../GHSA-3rm8-xf73-cj38.json | 36 +++++++++++++++++++ .../GHSA-426w-795m-hg3h.json | 36 +++++++++++++++++++ .../GHSA-43gx-3jr2-gx6w.json | 36 +++++++++++++++++++ .../GHSA-44f3-pxxm-4qwj.json | 36 +++++++++++++++++++ .../GHSA-4gxx-54gw-qwch.json | 34 ++++++++++++++++++ .../GHSA-5633-fxcw-h329.json | 36 +++++++++++++++++++ .../GHSA-5cx9-wv4f-39x3.json | 36 +++++++++++++++++++ .../GHSA-5hpp-r359-82qx.json | 36 +++++++++++++++++++ .../GHSA-5m5x-m4w3-hv65.json | 36 +++++++++++++++++++ .../GHSA-5w3p-36f6-83mh.json | 36 +++++++++++++++++++ .../GHSA-5xf3-rcpj-qcrg.json | 36 +++++++++++++++++++ .../GHSA-6257-v6vg-94g2.json | 36 +++++++++++++++++++ .../GHSA-65gx-jp3x-238j.json | 31 ++++++++++++++++ .../GHSA-65hf-6f49-4xh5.json | 36 +++++++++++++++++++ .../GHSA-6c3x-fhmr-wc2g.json | 36 +++++++++++++++++++ .../GHSA-6jvm-qqmx-p365.json | 36 +++++++++++++++++++ .../GHSA-6xc5-hvpf-5vpf.json | 36 +++++++++++++++++++ .../GHSA-6xgq-mgmp-386h.json | 36 +++++++++++++++++++ .../GHSA-737j-v765-x69q.json | 36 +++++++++++++++++++ .../GHSA-772g-g522-9m9m.json | 36 +++++++++++++++++++ .../GHSA-79hr-83rq-v4gf.json | 36 +++++++++++++++++++ .../GHSA-7f8r-wrhj-9gh8.json | 36 +++++++++++++++++++ .../GHSA-7hrr-g3xx-3xvg.json | 33 +++++++++++++++++ .../GHSA-7pp9-494f-jgr4.json | 36 +++++++++++++++++++ .../GHSA-7q79-r2jw-xmf3.json | 36 +++++++++++++++++++ .../GHSA-7rq5-qrmh-5348.json | 36 +++++++++++++++++++ .../GHSA-7xpj-h3mq-wxqm.json | 36 +++++++++++++++++++ .../GHSA-82wh-q6v3-5fv7.json | 36 +++++++++++++++++++ .../GHSA-843j-35q9-6f9x.json | 36 +++++++++++++++++++ .../GHSA-856w-4h2q-c3vm.json | 36 +++++++++++++++++++ .../GHSA-85r9-5wfq-frxc.json | 36 +++++++++++++++++++ .../GHSA-898w-4rv7-h42q.json | 36 +++++++++++++++++++ .../GHSA-8p4q-mjrr-xrcg.json | 36 +++++++++++++++++++ .../GHSA-8rm9-3g88-c2rp.json | 36 +++++++++++++++++++ .../GHSA-9262-x7f9-6hfc.json | 33 +++++++++++++++++ .../GHSA-93wv-g9pq-74g3.json | 36 +++++++++++++++++++ .../GHSA-9gjh-5rhx-x686.json | 36 +++++++++++++++++++ .../GHSA-c44j-83ph-xfxg.json | 36 +++++++++++++++++++ .../GHSA-c4x2-9r8f-8pxc.json | 36 +++++++++++++++++++ .../GHSA-c59x-jvxg-r9vx.json | 36 +++++++++++++++++++ .../GHSA-c6c6-925f-94rf.json | 33 +++++++++++++++++ .../GHSA-cfrf-53p9-8wmj.json | 36 +++++++++++++++++++ .../GHSA-ch43-9gp9-2hvw.json | 36 +++++++++++++++++++ .../GHSA-cxgr-6fph-qpw7.json | 36 +++++++++++++++++++ .../GHSA-cxx3-36xh-96f7.json | 36 +++++++++++++++++++ .../GHSA-f77f-c7pq-c4g7.json | 36 +++++++++++++++++++ .../GHSA-f9qc-474c-5mh2.json | 36 +++++++++++++++++++ .../GHSA-ffmm-98mj-4mgx.json | 36 +++++++++++++++++++ .../GHSA-fgg8-rprm-rg7v.json | 31 ++++++++++++++++ .../GHSA-fv2f-79j5-jgrv.json | 36 +++++++++++++++++++ .../GHSA-ggmq-45q5-gq4m.json | 36 +++++++++++++++++++ .../GHSA-gr2v-pvqm-gwwc.json | 36 +++++++++++++++++++ .../GHSA-h6cv-hw2x-5cwp.json | 36 +++++++++++++++++++ .../GHSA-h78m-4g6h-334g.json | 4 ++- .../GHSA-hc4m-pjg9-5c8f.json | 36 +++++++++++++++++++ .../GHSA-hfpr-xhrf-jgv3.json | 36 +++++++++++++++++++ .../GHSA-hg33-c74g-5r58.json | 36 +++++++++++++++++++ .../GHSA-hhhr-875p-xj5g.json | 36 +++++++++++++++++++ .../GHSA-hp4v-q7qc-45wr.json | 6 +++- .../GHSA-hp8v-m2mf-6ffv.json | 36 +++++++++++++++++++ .../GHSA-hv83-7234-xwv7.json | 36 +++++++++++++++++++ .../GHSA-hwj3-v9vw-g5g2.json | 36 +++++++++++++++++++ .../GHSA-hx3q-gx9q-hxmw.json | 36 +++++++++++++++++++ .../GHSA-j2q2-q6cc-jr5h.json | 36 +++++++++++++++++++ .../GHSA-j7hv-f7pc-9m6h.json | 36 +++++++++++++++++++ .../GHSA-j7wg-vqfq-fh3f.json | 4 ++- .../GHSA-j8mc-xcxh-9rm2.json | 36 +++++++++++++++++++ .../GHSA-j95m-vcjc-hm79.json | 31 ++++++++++++++++ .../GHSA-jq4c-g2mv-39mq.json | 36 +++++++++++++++++++ .../GHSA-jqxw-j9cr-8v8p.json | 36 +++++++++++++++++++ .../GHSA-jwq2-c69m-7qxf.json | 36 +++++++++++++++++++ .../GHSA-jxcg-5m5x-c4g8.json | 36 +++++++++++++++++++ .../GHSA-m6f3-8qqf-55g7.json | 36 +++++++++++++++++++ .../GHSA-mj8j-8p89-3rvg.json | 36 +++++++++++++++++++ .../GHSA-mjrr-qgcx-q669.json | 36 +++++++++++++++++++ .../GHSA-mp9m-wpqx-25wj.json | 36 +++++++++++++++++++ .../GHSA-mv3c-mc8v-rj5r.json | 36 +++++++++++++++++++ .../GHSA-p2h8-p639-829m.json | 36 +++++++++++++++++++ .../GHSA-pffp-xj6v-7cgc.json | 36 +++++++++++++++++++ .../GHSA-pg6j-c3fc-2fvj.json | 36 +++++++++++++++++++ .../GHSA-pjfr-c8m4-mrf9.json | 36 +++++++++++++++++++ .../GHSA-pm4j-p7pm-fpvx.json | 6 +++- .../GHSA-pmfj-rg5g-cfpx.json | 36 +++++++++++++++++++ .../GHSA-pwxr-fc25-6gwf.json | 36 +++++++++++++++++++ .../GHSA-px4w-362r-5vgp.json | 36 +++++++++++++++++++ .../GHSA-px88-f2h5-pcx3.json | 36 +++++++++++++++++++ .../GHSA-pxh9-975p-9rpv.json | 36 +++++++++++++++++++ .../GHSA-q7p5-2w2c-9c56.json | 4 ++- .../GHSA-qcjq-v94f-pfgp.json | 36 +++++++++++++++++++ .../GHSA-qj6q-34pj-64w4.json | 36 +++++++++++++++++++ .../GHSA-qp4q-3vv6-j3rc.json | 36 +++++++++++++++++++ .../GHSA-qqr7-vq9w-hmc2.json | 36 +++++++++++++++++++ .../GHSA-qr78-9ggp-8w57.json | 36 +++++++++++++++++++ .../GHSA-qwp5-gwx9-5v2m.json | 36 +++++++++++++++++++ .../GHSA-r4xq-444j-73wr.json | 36 +++++++++++++++++++ .../GHSA-rcqj-3fmp-5cqx.json | 6 +++- .../GHSA-rhcv-f9x8-59x3.json | 36 +++++++++++++++++++ .../GHSA-v6v7-m3w9-36g8.json | 34 ++++++++++++++++++ .../GHSA-v9rj-9v4c-4gv6.json | 36 +++++++++++++++++++ .../GHSA-vf6g-8jqq-qrj6.json | 36 +++++++++++++++++++ .../GHSA-vg3w-gqwr-gvv2.json | 36 +++++++++++++++++++ .../GHSA-vrxx-q897-j52j.json | 36 +++++++++++++++++++ .../GHSA-vvj6-5p3w-2v9q.json | 36 +++++++++++++++++++ .../GHSA-w8w8-9687-2q2q.json | 36 +++++++++++++++++++ .../GHSA-wg2x-g88m-2886.json | 36 +++++++++++++++++++ .../GHSA-whrw-3m5j-pg8w.json | 36 +++++++++++++++++++ .../GHSA-wjcr-pcrw-p99x.json | 36 +++++++++++++++++++ .../GHSA-wwf3-h2pc-prc7.json | 36 +++++++++++++++++++ .../GHSA-wx7v-p49w-vwx3.json | 36 +++++++++++++++++++ .../GHSA-x44w-4pwf-wpx2.json | 36 +++++++++++++++++++ .../GHSA-xfpw-388w-fh3f.json | 3 +- .../GHSA-xjh4-42q7-h5mj.json | 36 +++++++++++++++++++ 141 files changed, 4326 insertions(+), 31 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-24q3-2w85-x8p7/GHSA-24q3-2w85-x8p7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-24xg-93rh-whf7/GHSA-24xg-93rh-whf7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-299q-fv2g-6cv8/GHSA-299q-fv2g-6cv8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-29pc-4j9r-26vc/GHSA-29pc-4j9r-26vc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2cgp-x82p-v5h2/GHSA-2cgp-x82p-v5h2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2gx7-rx3r-f497/GHSA-2gx7-rx3r-f497.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2jm5-gphf-c739/GHSA-2jm5-gphf-c739.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2mf6-qwmh-746g/GHSA-2mf6-qwmh-746g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2qxx-8p5c-f68v/GHSA-2qxx-8p5c-f68v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-33rx-6fc2-f369/GHSA-33rx-6fc2-f369.json create mode 100644 advisories/unreviewed/2025/04/GHSA-33xp-9q65-cm27/GHSA-33xp-9q65-cm27.json create mode 100644 advisories/unreviewed/2025/04/GHSA-35pc-r523-37pv/GHSA-35pc-r523-37pv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3854-mvcm-fg9r/GHSA-3854-mvcm-fg9r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3j2q-q8wr-v983/GHSA-3j2q-q8wr-v983.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3rm8-xf73-cj38/GHSA-3rm8-xf73-cj38.json create mode 100644 advisories/unreviewed/2025/04/GHSA-426w-795m-hg3h/GHSA-426w-795m-hg3h.json create mode 100644 advisories/unreviewed/2025/04/GHSA-43gx-3jr2-gx6w/GHSA-43gx-3jr2-gx6w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-44f3-pxxm-4qwj/GHSA-44f3-pxxm-4qwj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4gxx-54gw-qwch/GHSA-4gxx-54gw-qwch.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5633-fxcw-h329/GHSA-5633-fxcw-h329.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5cx9-wv4f-39x3/GHSA-5cx9-wv4f-39x3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5hpp-r359-82qx/GHSA-5hpp-r359-82qx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5m5x-m4w3-hv65/GHSA-5m5x-m4w3-hv65.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5w3p-36f6-83mh/GHSA-5w3p-36f6-83mh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5xf3-rcpj-qcrg/GHSA-5xf3-rcpj-qcrg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6257-v6vg-94g2/GHSA-6257-v6vg-94g2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-65gx-jp3x-238j/GHSA-65gx-jp3x-238j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-65hf-6f49-4xh5/GHSA-65hf-6f49-4xh5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6c3x-fhmr-wc2g/GHSA-6c3x-fhmr-wc2g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6jvm-qqmx-p365/GHSA-6jvm-qqmx-p365.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6xc5-hvpf-5vpf/GHSA-6xc5-hvpf-5vpf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6xgq-mgmp-386h/GHSA-6xgq-mgmp-386h.json create mode 100644 advisories/unreviewed/2025/04/GHSA-737j-v765-x69q/GHSA-737j-v765-x69q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-772g-g522-9m9m/GHSA-772g-g522-9m9m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-79hr-83rq-v4gf/GHSA-79hr-83rq-v4gf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7f8r-wrhj-9gh8/GHSA-7f8r-wrhj-9gh8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7hrr-g3xx-3xvg/GHSA-7hrr-g3xx-3xvg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7pp9-494f-jgr4/GHSA-7pp9-494f-jgr4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7q79-r2jw-xmf3/GHSA-7q79-r2jw-xmf3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7rq5-qrmh-5348/GHSA-7rq5-qrmh-5348.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7xpj-h3mq-wxqm/GHSA-7xpj-h3mq-wxqm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-82wh-q6v3-5fv7/GHSA-82wh-q6v3-5fv7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-843j-35q9-6f9x/GHSA-843j-35q9-6f9x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-856w-4h2q-c3vm/GHSA-856w-4h2q-c3vm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-85r9-5wfq-frxc/GHSA-85r9-5wfq-frxc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-898w-4rv7-h42q/GHSA-898w-4rv7-h42q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8p4q-mjrr-xrcg/GHSA-8p4q-mjrr-xrcg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8rm9-3g88-c2rp/GHSA-8rm9-3g88-c2rp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9262-x7f9-6hfc/GHSA-9262-x7f9-6hfc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-93wv-g9pq-74g3/GHSA-93wv-g9pq-74g3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9gjh-5rhx-x686/GHSA-9gjh-5rhx-x686.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c44j-83ph-xfxg/GHSA-c44j-83ph-xfxg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c4x2-9r8f-8pxc/GHSA-c4x2-9r8f-8pxc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c59x-jvxg-r9vx/GHSA-c59x-jvxg-r9vx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c6c6-925f-94rf/GHSA-c6c6-925f-94rf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cfrf-53p9-8wmj/GHSA-cfrf-53p9-8wmj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ch43-9gp9-2hvw/GHSA-ch43-9gp9-2hvw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cxgr-6fph-qpw7/GHSA-cxgr-6fph-qpw7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cxx3-36xh-96f7/GHSA-cxx3-36xh-96f7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f77f-c7pq-c4g7/GHSA-f77f-c7pq-c4g7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f9qc-474c-5mh2/GHSA-f9qc-474c-5mh2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ffmm-98mj-4mgx/GHSA-ffmm-98mj-4mgx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fgg8-rprm-rg7v/GHSA-fgg8-rprm-rg7v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fv2f-79j5-jgrv/GHSA-fv2f-79j5-jgrv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ggmq-45q5-gq4m/GHSA-ggmq-45q5-gq4m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gr2v-pvqm-gwwc/GHSA-gr2v-pvqm-gwwc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h6cv-hw2x-5cwp/GHSA-h6cv-hw2x-5cwp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hc4m-pjg9-5c8f/GHSA-hc4m-pjg9-5c8f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hfpr-xhrf-jgv3/GHSA-hfpr-xhrf-jgv3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hg33-c74g-5r58/GHSA-hg33-c74g-5r58.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hhhr-875p-xj5g/GHSA-hhhr-875p-xj5g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hp8v-m2mf-6ffv/GHSA-hp8v-m2mf-6ffv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hv83-7234-xwv7/GHSA-hv83-7234-xwv7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hwj3-v9vw-g5g2/GHSA-hwj3-v9vw-g5g2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hx3q-gx9q-hxmw/GHSA-hx3q-gx9q-hxmw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j2q2-q6cc-jr5h/GHSA-j2q2-q6cc-jr5h.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j7hv-f7pc-9m6h/GHSA-j7hv-f7pc-9m6h.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j8mc-xcxh-9rm2/GHSA-j8mc-xcxh-9rm2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j95m-vcjc-hm79/GHSA-j95m-vcjc-hm79.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jq4c-g2mv-39mq/GHSA-jq4c-g2mv-39mq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jqxw-j9cr-8v8p/GHSA-jqxw-j9cr-8v8p.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jwq2-c69m-7qxf/GHSA-jwq2-c69m-7qxf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jxcg-5m5x-c4g8/GHSA-jxcg-5m5x-c4g8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m6f3-8qqf-55g7/GHSA-m6f3-8qqf-55g7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mj8j-8p89-3rvg/GHSA-mj8j-8p89-3rvg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mjrr-qgcx-q669/GHSA-mjrr-qgcx-q669.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mp9m-wpqx-25wj/GHSA-mp9m-wpqx-25wj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mv3c-mc8v-rj5r/GHSA-mv3c-mc8v-rj5r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p2h8-p639-829m/GHSA-p2h8-p639-829m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pffp-xj6v-7cgc/GHSA-pffp-xj6v-7cgc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pg6j-c3fc-2fvj/GHSA-pg6j-c3fc-2fvj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pjfr-c8m4-mrf9/GHSA-pjfr-c8m4-mrf9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pmfj-rg5g-cfpx/GHSA-pmfj-rg5g-cfpx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pwxr-fc25-6gwf/GHSA-pwxr-fc25-6gwf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-px4w-362r-5vgp/GHSA-px4w-362r-5vgp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-px88-f2h5-pcx3/GHSA-px88-f2h5-pcx3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pxh9-975p-9rpv/GHSA-pxh9-975p-9rpv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qcjq-v94f-pfgp/GHSA-qcjq-v94f-pfgp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qj6q-34pj-64w4/GHSA-qj6q-34pj-64w4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qp4q-3vv6-j3rc/GHSA-qp4q-3vv6-j3rc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qqr7-vq9w-hmc2/GHSA-qqr7-vq9w-hmc2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qr78-9ggp-8w57/GHSA-qr78-9ggp-8w57.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qwp5-gwx9-5v2m/GHSA-qwp5-gwx9-5v2m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r4xq-444j-73wr/GHSA-r4xq-444j-73wr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rhcv-f9x8-59x3/GHSA-rhcv-f9x8-59x3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v6v7-m3w9-36g8/GHSA-v6v7-m3w9-36g8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v9rj-9v4c-4gv6/GHSA-v9rj-9v4c-4gv6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vf6g-8jqq-qrj6/GHSA-vf6g-8jqq-qrj6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vg3w-gqwr-gvv2/GHSA-vg3w-gqwr-gvv2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vrxx-q897-j52j/GHSA-vrxx-q897-j52j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vvj6-5p3w-2v9q/GHSA-vvj6-5p3w-2v9q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-w8w8-9687-2q2q/GHSA-w8w8-9687-2q2q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wg2x-g88m-2886/GHSA-wg2x-g88m-2886.json create mode 100644 advisories/unreviewed/2025/04/GHSA-whrw-3m5j-pg8w/GHSA-whrw-3m5j-pg8w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wjcr-pcrw-p99x/GHSA-wjcr-pcrw-p99x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wwf3-h2pc-prc7/GHSA-wwf3-h2pc-prc7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wx7v-p49w-vwx3/GHSA-wx7v-p49w-vwx3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x44w-4pwf-wpx2/GHSA-x44w-4pwf-wpx2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xjh4-42q7-h5mj/GHSA-xjh4-42q7-h5mj.json diff --git a/advisories/unreviewed/2023/01/GHSA-47xh-88vf-mqw7/GHSA-47xh-88vf-mqw7.json b/advisories/unreviewed/2023/01/GHSA-47xh-88vf-mqw7/GHSA-47xh-88vf-mqw7.json index c9616ea5258..cacfaee8686 100644 --- a/advisories/unreviewed/2023/01/GHSA-47xh-88vf-mqw7/GHSA-47xh-88vf-mqw7.json +++ b/advisories/unreviewed/2023/01/GHSA-47xh-88vf-mqw7/GHSA-47xh-88vf-mqw7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-47xh-88vf-mqw7", - "modified": "2023-01-18T15:30:30Z", + "modified": "2025-04-09T18:30:38Z", "published": "2023-01-10T21:30:26Z", "aliases": [ "CVE-2022-45165" diff --git a/advisories/unreviewed/2023/01/GHSA-5c9w-vq5m-266h/GHSA-5c9w-vq5m-266h.json b/advisories/unreviewed/2023/01/GHSA-5c9w-vq5m-266h/GHSA-5c9w-vq5m-266h.json index aef84fbc580..33c029f55d9 100644 --- a/advisories/unreviewed/2023/01/GHSA-5c9w-vq5m-266h/GHSA-5c9w-vq5m-266h.json +++ b/advisories/unreviewed/2023/01/GHSA-5c9w-vq5m-266h/GHSA-5c9w-vq5m-266h.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-g5qg-593p-j5gq/GHSA-g5qg-593p-j5gq.json b/advisories/unreviewed/2023/01/GHSA-g5qg-593p-j5gq/GHSA-g5qg-593p-j5gq.json index 25bfa18c38b..d2aeef22d0a 100644 --- a/advisories/unreviewed/2023/01/GHSA-g5qg-593p-j5gq/GHSA-g5qg-593p-j5gq.json +++ b/advisories/unreviewed/2023/01/GHSA-g5qg-593p-j5gq/GHSA-g5qg-593p-j5gq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g5qg-593p-j5gq", - "modified": "2023-01-14T06:30:29Z", + "modified": "2025-04-09T18:30:38Z", "published": "2023-01-10T21:30:26Z", "aliases": [ "CVE-2022-45167" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-gg38-fph6-54g7/GHSA-gg38-fph6-54g7.json b/advisories/unreviewed/2023/01/GHSA-gg38-fph6-54g7/GHSA-gg38-fph6-54g7.json index 20a043585d4..7dda4840b8b 100644 --- a/advisories/unreviewed/2023/01/GHSA-gg38-fph6-54g7/GHSA-gg38-fph6-54g7.json +++ b/advisories/unreviewed/2023/01/GHSA-gg38-fph6-54g7/GHSA-gg38-fph6-54g7.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-hr2h-gpm8-8hqc/GHSA-hr2h-gpm8-8hqc.json b/advisories/unreviewed/2023/01/GHSA-hr2h-gpm8-8hqc/GHSA-hr2h-gpm8-8hqc.json index 18489479ab8..76da3ba0e99 100644 --- a/advisories/unreviewed/2023/01/GHSA-hr2h-gpm8-8hqc/GHSA-hr2h-gpm8-8hqc.json +++ b/advisories/unreviewed/2023/01/GHSA-hr2h-gpm8-8hqc/GHSA-hr2h-gpm8-8hqc.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-20" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-jc4j-5j4g-r9cv/GHSA-jc4j-5j4g-r9cv.json b/advisories/unreviewed/2023/01/GHSA-jc4j-5j4g-r9cv/GHSA-jc4j-5j4g-r9cv.json index 654f66a9426..f742fcf0c88 100644 --- a/advisories/unreviewed/2023/01/GHSA-jc4j-5j4g-r9cv/GHSA-jc4j-5j4g-r9cv.json +++ b/advisories/unreviewed/2023/01/GHSA-jc4j-5j4g-r9cv/GHSA-jc4j-5j4g-r9cv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jc4j-5j4g-r9cv", - "modified": "2023-01-14T06:30:29Z", + "modified": "2025-04-09T18:30:38Z", "published": "2023-01-10T21:30:26Z", "aliases": [ "CVE-2022-45164" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-m5jj-959w-4x33/GHSA-m5jj-959w-4x33.json b/advisories/unreviewed/2023/01/GHSA-m5jj-959w-4x33/GHSA-m5jj-959w-4x33.json index e7a66b38ac2..aabc3e8f578 100644 --- a/advisories/unreviewed/2023/01/GHSA-m5jj-959w-4x33/GHSA-m5jj-959w-4x33.json +++ b/advisories/unreviewed/2023/01/GHSA-m5jj-959w-4x33/GHSA-m5jj-959w-4x33.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-vfm9-f37f-c9j3/GHSA-vfm9-f37f-c9j3.json b/advisories/unreviewed/2023/01/GHSA-vfm9-f37f-c9j3/GHSA-vfm9-f37f-c9j3.json index 5adbee87cee..7b4225bba68 100644 --- a/advisories/unreviewed/2023/01/GHSA-vfm9-f37f-c9j3/GHSA-vfm9-f37f-c9j3.json +++ b/advisories/unreviewed/2023/01/GHSA-vfm9-f37f-c9j3/GHSA-vfm9-f37f-c9j3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vfm9-f37f-c9j3", - "modified": "2023-01-14T06:30:29Z", + "modified": "2025-04-09T18:30:38Z", "published": "2023-01-10T21:30:26Z", "aliases": [ "CVE-2022-45166" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-3w7c-xcfc-fcwc/GHSA-3w7c-xcfc-fcwc.json b/advisories/unreviewed/2024/03/GHSA-3w7c-xcfc-fcwc/GHSA-3w7c-xcfc-fcwc.json index 6e27e0a554b..62ec3d7735a 100644 --- a/advisories/unreviewed/2024/03/GHSA-3w7c-xcfc-fcwc/GHSA-3w7c-xcfc-fcwc.json +++ b/advisories/unreviewed/2024/03/GHSA-3w7c-xcfc-fcwc/GHSA-3w7c-xcfc-fcwc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3w7c-xcfc-fcwc", - "modified": "2024-03-20T15:32:48Z", + "modified": "2025-04-09T18:30:39Z", "published": "2024-03-20T15:32:48Z", "aliases": [ "CVE-2024-1325" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-4q5q-v9v4-9c33/GHSA-4q5q-v9v4-9c33.json b/advisories/unreviewed/2024/03/GHSA-4q5q-v9v4-9c33/GHSA-4q5q-v9v4-9c33.json index 272aa95beec..8b4daf91adf 100644 --- a/advisories/unreviewed/2024/03/GHSA-4q5q-v9v4-9c33/GHSA-4q5q-v9v4-9c33.json +++ b/advisories/unreviewed/2024/03/GHSA-4q5q-v9v4-9c33/GHSA-4q5q-v9v4-9c33.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-4q5q-v9v4-9c33", - "modified": "2024-03-28T15:30:33Z", + "modified": "2025-04-09T18:30:40Z", "published": "2024-03-28T15:30:33Z", "aliases": [ "CVE-2024-0259" ], - "details": "Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is restarted, the replaced binary runs with local system privileges, allowing a low-privileged user to gain elevated privileges.\n\n", + "details": "Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is restarted, the replaced binary runs with local system privileges, allowing a low-privileged user to gain elevated privileges.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-59hg-3x57-2mwj/GHSA-59hg-3x57-2mwj.json b/advisories/unreviewed/2024/03/GHSA-59hg-3x57-2mwj/GHSA-59hg-3x57-2mwj.json index 084e0301c18..16d46e70a86 100644 --- a/advisories/unreviewed/2024/03/GHSA-59hg-3x57-2mwj/GHSA-59hg-3x57-2mwj.json +++ b/advisories/unreviewed/2024/03/GHSA-59hg-3x57-2mwj/GHSA-59hg-3x57-2mwj.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-59hg-3x57-2mwj", - "modified": "2024-03-29T15:30:28Z", + "modified": "2025-04-09T18:30:40Z", "published": "2024-03-29T15:30:28Z", "aliases": [ "CVE-2024-30458" ], - "details": "Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS – WooCommerce Currency Switcher.This issue affects WOOCS – WooCommerce Currency Switcher: from n/a through 1.4.1.7.\n\n", + "details": "Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS – WooCommerce Currency Switcher.This issue affects WOOCS – WooCommerce Currency Switcher: from n/a through 1.4.1.7.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-9qr6-r6j4-qfxh/GHSA-9qr6-r6j4-qfxh.json b/advisories/unreviewed/2024/03/GHSA-9qr6-r6j4-qfxh/GHSA-9qr6-r6j4-qfxh.json index 1cc21449854..fbc20419e71 100644 --- a/advisories/unreviewed/2024/03/GHSA-9qr6-r6j4-qfxh/GHSA-9qr6-r6j4-qfxh.json +++ b/advisories/unreviewed/2024/03/GHSA-9qr6-r6j4-qfxh/GHSA-9qr6-r6j4-qfxh.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-9qr6-r6j4-qfxh", - "modified": "2024-03-29T15:30:28Z", + "modified": "2025-04-09T18:30:40Z", "published": "2024-03-29T15:30:28Z", "aliases": [ "CVE-2024-30456" ], - "details": "Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WPCS.This issue affects WPCS: from n/a through 1.2.0.1.\n\n", + "details": "Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WPCS.This issue affects WPCS: from n/a through 1.2.0.1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-r26g-5xh6-pgwp/GHSA-r26g-5xh6-pgwp.json b/advisories/unreviewed/2024/03/GHSA-r26g-5xh6-pgwp/GHSA-r26g-5xh6-pgwp.json index 8536bd2b6b1..1a6569725d1 100644 --- a/advisories/unreviewed/2024/03/GHSA-r26g-5xh6-pgwp/GHSA-r26g-5xh6-pgwp.json +++ b/advisories/unreviewed/2024/03/GHSA-r26g-5xh6-pgwp/GHSA-r26g-5xh6-pgwp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r26g-5xh6-pgwp", - "modified": "2024-03-20T15:32:48Z", + "modified": "2025-04-09T18:30:39Z", "published": "2024-03-20T15:32:48Z", "aliases": [ "CVE-2024-1205" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-434" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-xph7-pm58-q56v/GHSA-xph7-pm58-q56v.json b/advisories/unreviewed/2024/03/GHSA-xph7-pm58-q56v/GHSA-xph7-pm58-q56v.json index d90daf1acc0..9e865ea6d64 100644 --- a/advisories/unreviewed/2024/03/GHSA-xph7-pm58-q56v/GHSA-xph7-pm58-q56v.json +++ b/advisories/unreviewed/2024/03/GHSA-xph7-pm58-q56v/GHSA-xph7-pm58-q56v.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-xph7-pm58-q56v", - "modified": "2024-03-21T18:32:03Z", + "modified": "2025-04-09T18:30:39Z", "published": "2024-03-21T18:32:03Z", "aliases": [ "CVE-2024-2578" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPCoder WP Coder allows Stored XSS.This issue affects WP Coder: from n/a through 3.5.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPCoder WP Coder allows Stored XSS.This issue affects WP Coder: from n/a through 3.5.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2025/02/GHSA-j8x5-54p6-cqvm/GHSA-j8x5-54p6-cqvm.json b/advisories/unreviewed/2025/02/GHSA-j8x5-54p6-cqvm/GHSA-j8x5-54p6-cqvm.json index ef222a4c448..316840fcb2a 100644 --- a/advisories/unreviewed/2025/02/GHSA-j8x5-54p6-cqvm/GHSA-j8x5-54p6-cqvm.json +++ b/advisories/unreviewed/2025/02/GHSA-j8x5-54p6-cqvm/GHSA-j8x5-54p6-cqvm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j8x5-54p6-cqvm", - "modified": "2025-02-12T21:31:54Z", + "modified": "2025-04-09T18:30:47Z", "published": "2025-02-12T21:31:54Z", "aliases": [ "CVE-2025-0113" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://security.paloaltonetworks.com/CVE-2024-0113" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2025-0113" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-24q3-2w85-x8p7/GHSA-24q3-2w85-x8p7.json b/advisories/unreviewed/2025/04/GHSA-24q3-2w85-x8p7/GHSA-24q3-2w85-x8p7.json new file mode 100644 index 00000000000..4ed4246c9d1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-24q3-2w85-x8p7/GHSA-24q3-2w85-x8p7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24q3-2w85-x8p7", + "modified": "2025-04-09T18:30:52Z", + "published": "2025-04-09T18:30:51Z", + "aliases": [ + "CVE-2025-31382" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in theode Language Field allows Stored XSS. This issue affects Language Field: from n/a through 0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31382" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/language-field/vulnerability/wordpress-language-field-plugin-0-9-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-24xg-93rh-whf7/GHSA-24xg-93rh-whf7.json b/advisories/unreviewed/2025/04/GHSA-24xg-93rh-whf7/GHSA-24xg-93rh-whf7.json new file mode 100644 index 00000000000..c1d181ebd38 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-24xg-93rh-whf7/GHSA-24xg-93rh-whf7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24xg-93rh-whf7", + "modified": "2025-04-09T18:30:52Z", + "published": "2025-04-09T18:30:52Z", + "aliases": [ + "CVE-2025-31400" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in icyleaf WS Audio Player allows Stored XSS. This issue affects WS Audio Player: from n/a through 1.1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31400" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ws-audio-player/vulnerability/wordpress-ws-audio-player-plugin-1-1-8-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-299q-fv2g-6cv8/GHSA-299q-fv2g-6cv8.json b/advisories/unreviewed/2025/04/GHSA-299q-fv2g-6cv8/GHSA-299q-fv2g-6cv8.json new file mode 100644 index 00000000000..0fc8faa7791 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-299q-fv2g-6cv8/GHSA-299q-fv2g-6cv8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-299q-fv2g-6cv8", + "modified": "2025-04-09T18:30:52Z", + "published": "2025-04-09T18:30:52Z", + "aliases": [ + "CVE-2025-31385" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Site Table of Contents allows Stored XSS. This issue affects Site Table of Contents: from n/a through 0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31385" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/site-table-of-contents/vulnerability/wordpress-site-table-of-contents-plugin-0-3-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-29pc-4j9r-26vc/GHSA-29pc-4j9r-26vc.json b/advisories/unreviewed/2025/04/GHSA-29pc-4j9r-26vc/GHSA-29pc-4j9r-26vc.json new file mode 100644 index 00000000000..0d18821cd5f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-29pc-4j9r-26vc/GHSA-29pc-4j9r-26vc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29pc-4j9r-26vc", + "modified": "2025-04-09T18:30:51Z", + "published": "2025-04-09T18:30:51Z", + "aliases": [ + "CVE-2025-31036" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WPSolr free WPSolr allows Privilege Escalation. This issue affects WPSolr: from n/a through 24.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31036" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpsolr-free/vulnerability/wordpress-wpsolr-plugin-24-0-csrf-to-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2cgp-x82p-v5h2/GHSA-2cgp-x82p-v5h2.json b/advisories/unreviewed/2025/04/GHSA-2cgp-x82p-v5h2/GHSA-2cgp-x82p-v5h2.json new file mode 100644 index 00000000000..5baaa9f480a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2cgp-x82p-v5h2/GHSA-2cgp-x82p-v5h2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cgp-x82p-v5h2", + "modified": "2025-04-09T18:30:53Z", + "published": "2025-04-09T18:30:53Z", + "aliases": [ + "CVE-2025-32481" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ninotheme Nino Social Connect allows Stored XSS. This issue affects Nino Social Connect: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32481" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nino-social-connect/vulnerability/wordpress-nino-social-connect-plugin-2-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2gx7-rx3r-f497/GHSA-2gx7-rx3r-f497.json b/advisories/unreviewed/2025/04/GHSA-2gx7-rx3r-f497/GHSA-2gx7-rx3r-f497.json new file mode 100644 index 00000000000..9c5520d1197 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2gx7-rx3r-f497/GHSA-2gx7-rx3r-f497.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gx7-rx3r-f497", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:56Z", + "aliases": [ + "CVE-2025-32679" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ZealousWeb User Registration Using Contact Form 7 allows Cross Site Request Forgery. This issue affects User Registration Using Contact Form 7: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32679" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/user-registration-using-contact-form-7/vulnerability/wordpress-user-registration-using-contact-form-7-plugin-2-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2jm5-gphf-c739/GHSA-2jm5-gphf-c739.json b/advisories/unreviewed/2025/04/GHSA-2jm5-gphf-c739/GHSA-2jm5-gphf-c739.json new file mode 100644 index 00000000000..c962ea8f537 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2jm5-gphf-c739/GHSA-2jm5-gphf-c739.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jm5-gphf-c739", + "modified": "2025-04-09T18:30:52Z", + "published": "2025-04-09T18:30:52Z", + "aliases": [ + "CVE-2025-31383" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in FrescoChat Live Chat allows Stored XSS. This issue affects FrescoChat Live Chat: from n/a through 3.2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31383" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/flexytalk-widget/vulnerability/wordpress-frescochat-live-chat-plugin-3-2-6-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2mf6-qwmh-746g/GHSA-2mf6-qwmh-746g.json b/advisories/unreviewed/2025/04/GHSA-2mf6-qwmh-746g/GHSA-2mf6-qwmh-746g.json new file mode 100644 index 00000000000..65353ede2c9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2mf6-qwmh-746g/GHSA-2mf6-qwmh-746g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mf6-qwmh-746g", + "modified": "2025-04-09T18:30:51Z", + "published": "2025-04-09T18:30:51Z", + "aliases": [ + "CVE-2025-31038" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Essential Marketer Essential Breadcrumbs allows Privilege Escalation. This issue affects Essential Breadcrumbs: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31038" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/essential-breadcrumbs/vulnerability/wordpress-essential-breadcrumbs-plugin-1-1-1-csrf-to-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2qxx-8p5c-f68v/GHSA-2qxx-8p5c-f68v.json b/advisories/unreviewed/2025/04/GHSA-2qxx-8p5c-f68v/GHSA-2qxx-8p5c-f68v.json new file mode 100644 index 00000000000..6181af40b95 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2qxx-8p5c-f68v/GHSA-2qxx-8p5c-f68v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qxx-8p5c-f68v", + "modified": "2025-04-09T18:30:54Z", + "published": "2025-04-09T18:30:54Z", + "aliases": [ + "CVE-2025-32543" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hivedigital Canonical Attachments allows Reflected XSS. This issue affects Canonical Attachments: from n/a through 1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32543" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/canonical-attachments/vulnerability/wordpress-canonical-attachments-plugin-1-7-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-33rx-6fc2-f369/GHSA-33rx-6fc2-f369.json b/advisories/unreviewed/2025/04/GHSA-33rx-6fc2-f369/GHSA-33rx-6fc2-f369.json new file mode 100644 index 00000000000..2c895c7f4f2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-33rx-6fc2-f369/GHSA-33rx-6fc2-f369.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33rx-6fc2-f369", + "modified": "2025-04-09T18:30:54Z", + "published": "2025-04-09T18:30:54Z", + "aliases": [ + "CVE-2025-32518" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in hossainawlad ALD Login Page allows Stored XSS. This issue affects ALD Login Page: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32518" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ald-login-page/vulnerability/wordpress-ald-login-page-plugin-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-33xp-9q65-cm27/GHSA-33xp-9q65-cm27.json b/advisories/unreviewed/2025/04/GHSA-33xp-9q65-cm27/GHSA-33xp-9q65-cm27.json new file mode 100644 index 00000000000..a090162d486 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-33xp-9q65-cm27/GHSA-33xp-9q65-cm27.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33xp-9q65-cm27", + "modified": "2025-04-09T18:30:53Z", + "published": "2025-04-09T18:30:53Z", + "aliases": [ + "CVE-2025-32498" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in oleglark VKontakte Cross-Post allows Stored XSS. This issue affects VKontakte Cross-Post: from n/a through 0.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32498" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/vkontakte-cross-post/vulnerability/wordpress-vkontakte-cross-post-plugin-0-3-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-35pc-r523-37pv/GHSA-35pc-r523-37pv.json b/advisories/unreviewed/2025/04/GHSA-35pc-r523-37pv/GHSA-35pc-r523-37pv.json new file mode 100644 index 00000000000..cf093794437 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-35pc-r523-37pv/GHSA-35pc-r523-37pv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35pc-r523-37pv", + "modified": "2025-04-09T18:30:52Z", + "published": "2025-04-09T18:30:52Z", + "aliases": [ + "CVE-2025-31395" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in a.ankit Easy Custom CSS allows Stored XSS. This issue affects Easy Custom CSS: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31395" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easy-custom-css/vulnerability/wordpress-easy-custom-css-plugin-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3854-mvcm-fg9r/GHSA-3854-mvcm-fg9r.json b/advisories/unreviewed/2025/04/GHSA-3854-mvcm-fg9r/GHSA-3854-mvcm-fg9r.json new file mode 100644 index 00000000000..ef7e888393b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3854-mvcm-fg9r/GHSA-3854-mvcm-fg9r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3854-mvcm-fg9r", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:56Z", + "aliases": [ + "CVE-2025-32677" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in solwininfotech WP Social Stream Designer allows Blind SQL Injection. This issue affects WP Social Stream Designer: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32677" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/social-stream-design/vulnerability/wordpress-wp-social-stream-designer-plugin-1-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3j2q-q8wr-v983/GHSA-3j2q-q8wr-v983.json b/advisories/unreviewed/2025/04/GHSA-3j2q-q8wr-v983/GHSA-3j2q-q8wr-v983.json new file mode 100644 index 00000000000..f2f5a6e253d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3j2q-q8wr-v983/GHSA-3j2q-q8wr-v983.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j2q-q8wr-v983", + "modified": "2025-04-09T18:30:51Z", + "published": "2025-04-09T18:30:51Z", + "aliases": [ + "CVE-2025-31035" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Chris WP Editor.md – The Perfect WordPress Markdown Editor allows Stored XSS. This issue affects WP Editor.md – The Perfect WordPress Markdown Editor: from n/a through 10.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31035" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-editormd/vulnerability/wordpress-wp-editor-md-the-perfect-wordpress-markdown-editor-10-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3rm8-xf73-cj38/GHSA-3rm8-xf73-cj38.json b/advisories/unreviewed/2025/04/GHSA-3rm8-xf73-cj38/GHSA-3rm8-xf73-cj38.json new file mode 100644 index 00000000000..fe695aff570 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3rm8-xf73-cj38/GHSA-3rm8-xf73-cj38.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rm8-xf73-cj38", + "modified": "2025-04-09T18:30:50Z", + "published": "2025-04-09T18:30:50Z", + "aliases": [ + "CVE-2025-31002" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze allows Using Malicious Files. This issue affects Squeeze: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31002" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/squeeze/vulnerability/wordpress-squeeze-plugin-1-6-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-426w-795m-hg3h/GHSA-426w-795m-hg3h.json b/advisories/unreviewed/2025/04/GHSA-426w-795m-hg3h/GHSA-426w-795m-hg3h.json new file mode 100644 index 00000000000..13d773fe71e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-426w-795m-hg3h/GHSA-426w-795m-hg3h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-426w-795m-hg3h", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:56Z", + "aliases": [ + "CVE-2025-32678" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ashish Ajani WP Show Stats allows Cross Site Request Forgery. This issue affects WP Show Stats: from n/a through 1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32678" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-show-stats/vulnerability/wordpress-wp-show-stats-plugin-1-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-43gx-3jr2-gx6w/GHSA-43gx-3jr2-gx6w.json b/advisories/unreviewed/2025/04/GHSA-43gx-3jr2-gx6w/GHSA-43gx-3jr2-gx6w.json new file mode 100644 index 00000000000..d8711e25c88 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-43gx-3jr2-gx6w/GHSA-43gx-3jr2-gx6w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43gx-3jr2-gx6w", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:56Z", + "aliases": [ + "CVE-2025-32667" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in fromdoppler Doppler Forms allows Stored XSS. This issue affects Doppler Forms: from n/a through 2.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32667" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/doppler-form/vulnerability/wordpress-doppler-forms-plugin-2-4-5-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-44f3-pxxm-4qwj/GHSA-44f3-pxxm-4qwj.json b/advisories/unreviewed/2025/04/GHSA-44f3-pxxm-4qwj/GHSA-44f3-pxxm-4qwj.json new file mode 100644 index 00000000000..4f78a6924a9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-44f3-pxxm-4qwj/GHSA-44f3-pxxm-4qwj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44f3-pxxm-4qwj", + "modified": "2025-04-09T18:30:54Z", + "published": "2025-04-09T18:30:54Z", + "aliases": [ + "CVE-2025-32502" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in lemmentwickler ePaper Lister for Yumpu allows Stored XSS. This issue affects ePaper Lister for Yumpu: from n/a through 1.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32502" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/magazine-lister-for-yumpu/vulnerability/wordpress-epaper-lister-for-yumpu-plugin-1-4-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4gxx-54gw-qwch/GHSA-4gxx-54gw-qwch.json b/advisories/unreviewed/2025/04/GHSA-4gxx-54gw-qwch/GHSA-4gxx-54gw-qwch.json new file mode 100644 index 00000000000..68e337adb85 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4gxx-54gw-qwch/GHSA-4gxx-54gw-qwch.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gxx-54gw-qwch", + "modified": "2025-04-09T18:30:57Z", + "published": "2025-04-09T18:30:57Z", + "aliases": [ + "CVE-2025-3115" + ], + "details": "Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions.\nAdditionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3115" + }, + { + "type": "WEB", + "url": "https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-april-08-2025-spotfire-cve-2025-3114-r3484" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5633-fxcw-h329/GHSA-5633-fxcw-h329.json b/advisories/unreviewed/2025/04/GHSA-5633-fxcw-h329/GHSA-5633-fxcw-h329.json new file mode 100644 index 00000000000..7273337c35b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5633-fxcw-h329/GHSA-5633-fxcw-h329.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5633-fxcw-h329", + "modified": "2025-04-09T18:30:54Z", + "published": "2025-04-09T18:30:54Z", + "aliases": [ + "CVE-2025-32610" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Foliovision: Making the web work for you Foliopress WYSIWYG allows Cross Site Request Forgery. This issue affects Foliopress WYSIWYG: from n/a through 2.6.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32610" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/foliopress-wysiwyg/vulnerability/wordpress-foliopress-wysiwyg-plugin-2-6-18-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5cx9-wv4f-39x3/GHSA-5cx9-wv4f-39x3.json b/advisories/unreviewed/2025/04/GHSA-5cx9-wv4f-39x3/GHSA-5cx9-wv4f-39x3.json new file mode 100644 index 00000000000..de79ba2d4cb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5cx9-wv4f-39x3/GHSA-5cx9-wv4f-39x3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cx9-wv4f-39x3", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:55Z", + "aliases": [ + "CVE-2025-32664" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ashokbasnet Nepali Date Utilities allows Stored XSS. This issue affects Nepali Date Utilities: from n/a through 1.0.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32664" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nepali-date-utilities/vulnerability/wordpress-nepali-date-utilities-plugin-1-0-13-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5hpp-r359-82qx/GHSA-5hpp-r359-82qx.json b/advisories/unreviewed/2025/04/GHSA-5hpp-r359-82qx/GHSA-5hpp-r359-82qx.json new file mode 100644 index 00000000000..00bff16dd2e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5hpp-r359-82qx/GHSA-5hpp-r359-82qx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hpp-r359-82qx", + "modified": "2025-04-09T18:30:53Z", + "published": "2025-04-09T18:30:53Z", + "aliases": [ + "CVE-2025-32487" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Joe Waymark allows Server Side Request Forgery. This issue affects Waymark: from n/a through 1.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32487" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/waymark/vulnerability/wordpress-waymark-1-5-2-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5m5x-m4w3-hv65/GHSA-5m5x-m4w3-hv65.json b/advisories/unreviewed/2025/04/GHSA-5m5x-m4w3-hv65/GHSA-5m5x-m4w3-hv65.json new file mode 100644 index 00000000000..e25e69ea20e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5m5x-m4w3-hv65/GHSA-5m5x-m4w3-hv65.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5m5x-m4w3-hv65", + "modified": "2025-04-09T18:30:54Z", + "published": "2025-04-09T18:30:54Z", + "aliases": [ + "CVE-2025-32580" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in debounce DeBounce Email Validator allows Stored XSS. This issue affects DeBounce Email Validator: from n/a through 5.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32580" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/debounce-io-email-validator/vulnerability/wordpress-debounce-email-validator-plugin-5-7-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5w3p-36f6-83mh/GHSA-5w3p-36f6-83mh.json b/advisories/unreviewed/2025/04/GHSA-5w3p-36f6-83mh/GHSA-5w3p-36f6-83mh.json new file mode 100644 index 00000000000..9e222d5bcf3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5w3p-36f6-83mh/GHSA-5w3p-36f6-83mh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w3p-36f6-83mh", + "modified": "2025-04-09T18:30:52Z", + "published": "2025-04-09T18:30:52Z", + "aliases": [ + "CVE-2025-31393" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in vfvalent Social Bookmarking RELOADED allows Stored XSS. This issue affects Social Bookmarking RELOADED: from n/a through 3.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31393" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/social-bookmarking-reloaded/vulnerability/wordpress-social-bookmarking-reloaded-plugin-3-18-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5xf3-rcpj-qcrg/GHSA-5xf3-rcpj-qcrg.json b/advisories/unreviewed/2025/04/GHSA-5xf3-rcpj-qcrg/GHSA-5xf3-rcpj-qcrg.json new file mode 100644 index 00000000000..0c3538026fe --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5xf3-rcpj-qcrg/GHSA-5xf3-rcpj-qcrg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xf3-rcpj-qcrg", + "modified": "2025-04-09T18:30:52Z", + "published": "2025-04-09T18:30:52Z", + "aliases": [ + "CVE-2025-32478" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Mario Aguiar WP SexyLightBox allows Stored XSS. This issue affects WP SexyLightBox: from n/a through 0.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32478" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-sexylightbox/vulnerability/wordpress-wp-sexylightbox-plugin-0-5-3-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6257-v6vg-94g2/GHSA-6257-v6vg-94g2.json b/advisories/unreviewed/2025/04/GHSA-6257-v6vg-94g2/GHSA-6257-v6vg-94g2.json new file mode 100644 index 00000000000..2c73863c7f3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6257-v6vg-94g2/GHSA-6257-v6vg-94g2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6257-v6vg-94g2", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:56Z", + "aliases": [ + "CVE-2025-32669" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in MERGADO Mergado Pack allows Stored XSS. This issue affects Mergado Pack: from n/a through 4.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32669" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mergado-marketing-pack/vulnerability/wordpress-mergado-pack-plugin-4-0-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-65gx-jp3x-238j/GHSA-65gx-jp3x-238j.json b/advisories/unreviewed/2025/04/GHSA-65gx-jp3x-238j/GHSA-65gx-jp3x-238j.json new file mode 100644 index 00000000000..6564b078d4e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-65gx-jp3x-238j/GHSA-65gx-jp3x-238j.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65gx-jp3x-238j", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:56Z", + "aliases": [ + "CVE-2025-3475" + ], + "details": "Allocation of Resources Without Limits or Throttling, Incorrect Authorization vulnerability in Drupal WEB-T allows Excessive Allocation, Content Spoofing.This issue affects WEB-T: from 0.0.0 before 1.1.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3475" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-030" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-65hf-6f49-4xh5/GHSA-65hf-6f49-4xh5.json b/advisories/unreviewed/2025/04/GHSA-65hf-6f49-4xh5/GHSA-65hf-6f49-4xh5.json new file mode 100644 index 00000000000..cab136cf6ec --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-65hf-6f49-4xh5/GHSA-65hf-6f49-4xh5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65hf-6f49-4xh5", + "modified": "2025-04-09T18:30:53Z", + "published": "2025-04-09T18:30:53Z", + "aliases": [ + "CVE-2025-32497" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in squiter Spoiler Block allows Stored XSS. This issue affects Spoiler Block: from n/a through 1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32497" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/spoiler-block/vulnerability/wordpress-spoiler-block-plugin-1-7-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6c3x-fhmr-wc2g/GHSA-6c3x-fhmr-wc2g.json b/advisories/unreviewed/2025/04/GHSA-6c3x-fhmr-wc2g/GHSA-6c3x-fhmr-wc2g.json new file mode 100644 index 00000000000..7f0a8f25e8a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6c3x-fhmr-wc2g/GHSA-6c3x-fhmr-wc2g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c3x-fhmr-wc2g", + "modified": "2025-04-09T18:30:51Z", + "published": "2025-04-09T18:30:51Z", + "aliases": [ + "CVE-2025-31005" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Uzair Easyfonts allows Cross Site Request Forgery. This issue affects Easyfonts: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31005" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/easyfonts/vulnerability/wordpress-easyfonts-plugin-1-1-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6jvm-qqmx-p365/GHSA-6jvm-qqmx-p365.json b/advisories/unreviewed/2025/04/GHSA-6jvm-qqmx-p365/GHSA-6jvm-qqmx-p365.json new file mode 100644 index 00000000000..4ae71a0b281 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6jvm-qqmx-p365/GHSA-6jvm-qqmx-p365.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jvm-qqmx-p365", + "modified": "2025-04-09T18:30:51Z", + "published": "2025-04-09T18:30:51Z", + "aliases": [ + "CVE-2025-31023" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Purab Seo Meta Tags allows Cross Site Request Forgery. This issue affects Seo Meta Tags: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31023" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/seo-meta-tags/vulnerability/wordpress-seo-meta-tags-plugin-1-4-csrf-to-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6xc5-hvpf-5vpf/GHSA-6xc5-hvpf-5vpf.json b/advisories/unreviewed/2025/04/GHSA-6xc5-hvpf-5vpf/GHSA-6xc5-hvpf-5vpf.json new file mode 100644 index 00000000000..713c4740719 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6xc5-hvpf-5vpf/GHSA-6xc5-hvpf-5vpf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xc5-hvpf-5vpf", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:56Z", + "aliases": [ + "CVE-2025-32694" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Rustaurius Ultimate WP Mail allows Phishing. This issue affects Ultimate WP Mail: from n/a through 1.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32694" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-wp-mail/vulnerability/wordpress-ultimate-wp-mail-1-3-2-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6xgq-mgmp-386h/GHSA-6xgq-mgmp-386h.json b/advisories/unreviewed/2025/04/GHSA-6xgq-mgmp-386h/GHSA-6xgq-mgmp-386h.json new file mode 100644 index 00000000000..d5a286996e6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6xgq-mgmp-386h/GHSA-6xgq-mgmp-386h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xgq-mgmp-386h", + "modified": "2025-04-09T18:30:54Z", + "published": "2025-04-09T18:30:54Z", + "aliases": [ + "CVE-2025-32555" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Edamam SEO, Nutrition and Print for Recipes by Edamam allows Stored XSS. This issue affects SEO, Nutrition and Print for Recipes by Edamam: from n/a through 3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32555" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/seo-nutrition-and-print-for-recipes-by-edamam/vulnerability/wordpress-seo-nutrition-and-print-for-recipes-by-edamam-plugin-3-3-csrf-to-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-737j-v765-x69q/GHSA-737j-v765-x69q.json b/advisories/unreviewed/2025/04/GHSA-737j-v765-x69q/GHSA-737j-v765-x69q.json new file mode 100644 index 00000000000..e45f0a49583 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-737j-v765-x69q/GHSA-737j-v765-x69q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-737j-v765-x69q", + "modified": "2025-04-09T18:30:53Z", + "published": "2025-04-09T18:30:53Z", + "aliases": [ + "CVE-2025-32495" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Waymark allows Stored XSS. This issue affects Waymark: from n/a through 1.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32495" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/waymark/vulnerability/wordpress-waymark-1-5-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-772g-g522-9m9m/GHSA-772g-g522-9m9m.json b/advisories/unreviewed/2025/04/GHSA-772g-g522-9m9m/GHSA-772g-g522-9m9m.json new file mode 100644 index 00000000000..918033faab0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-772g-g522-9m9m/GHSA-772g-g522-9m9m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-772g-g522-9m9m", + "modified": "2025-04-09T18:30:53Z", + "published": "2025-04-09T18:30:53Z", + "aliases": [ + "CVE-2025-32485" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Bjoern WP Performance Pack allows Cross Site Request Forgery. This issue affects WP Performance Pack: from n/a through 2.5.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32485" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-performance-pack/vulnerability/wordpress-wp-performance-pack-2-5-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-79hr-83rq-v4gf/GHSA-79hr-83rq-v4gf.json b/advisories/unreviewed/2025/04/GHSA-79hr-83rq-v4gf/GHSA-79hr-83rq-v4gf.json new file mode 100644 index 00000000000..4673b67a019 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-79hr-83rq-v4gf/GHSA-79hr-83rq-v4gf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79hr-83rq-v4gf", + "modified": "2025-04-09T18:30:52Z", + "published": "2025-04-09T18:30:52Z", + "aliases": [ + "CVE-2025-31399" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Chandan Garg CG Scroll To Top allows Stored XSS. This issue affects CG Scroll To Top: from n/a through 3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31399" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cg-scroll-to-top/vulnerability/wordpress-cg-scroll-to-top-plugin-3-5-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7f8r-wrhj-9gh8/GHSA-7f8r-wrhj-9gh8.json b/advisories/unreviewed/2025/04/GHSA-7f8r-wrhj-9gh8/GHSA-7f8r-wrhj-9gh8.json new file mode 100644 index 00000000000..5a533103d2c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7f8r-wrhj-9gh8/GHSA-7f8r-wrhj-9gh8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f8r-wrhj-9gh8", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:56Z", + "aliases": [ + "CVE-2025-32693" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WPWebinarSystem WebinarPress allows Phishing. This issue affects WebinarPress: from n/a through 1.33.27.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32693" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-webinarsystem/vulnerability/wordpress-webinarpress-1-33-27-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7hrr-g3xx-3xvg/GHSA-7hrr-g3xx-3xvg.json b/advisories/unreviewed/2025/04/GHSA-7hrr-g3xx-3xvg/GHSA-7hrr-g3xx-3xvg.json new file mode 100644 index 00000000000..b7596bbf08b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7hrr-g3xx-3xvg/GHSA-7hrr-g3xx-3xvg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hrr-g3xx-3xvg", + "modified": "2025-04-09T18:30:50Z", + "published": "2025-04-09T18:30:50Z", + "aliases": [ + "CVE-2025-29390" + ], + "details": "jerryhanjj ERP 1.0 is vulnerable to SQL Injection in the set_password function in application/controllers/home.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29390" + }, + { + "type": "WEB", + "url": "https://github.com/jerryhanjj/ERP/issues/7" + }, + { + "type": "WEB", + "url": "https://gist.github.com/jaylan545/dbe989f09c73e311ccbfe5336435638c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7pp9-494f-jgr4/GHSA-7pp9-494f-jgr4.json b/advisories/unreviewed/2025/04/GHSA-7pp9-494f-jgr4/GHSA-7pp9-494f-jgr4.json new file mode 100644 index 00000000000..674e29858cc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7pp9-494f-jgr4/GHSA-7pp9-494f-jgr4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pp9-494f-jgr4", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:56Z", + "aliases": [ + "CVE-2025-32683" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RomanCode MapSVG Lite allows DOM-Based XSS. This issue affects MapSVG Lite: from n/a through 8.5.32.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32683" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mapsvg-lite-interactive-vector-maps/vulnerability/wordpress-mapsvg-lite-plugin-8-5-32-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7q79-r2jw-xmf3/GHSA-7q79-r2jw-xmf3.json b/advisories/unreviewed/2025/04/GHSA-7q79-r2jw-xmf3/GHSA-7q79-r2jw-xmf3.json new file mode 100644 index 00000000000..9ef7628f509 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7q79-r2jw-xmf3/GHSA-7q79-r2jw-xmf3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q79-r2jw-xmf3", + "modified": "2025-04-09T18:30:53Z", + "published": "2025-04-09T18:30:53Z", + "aliases": [ + "CVE-2025-32482" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in quanganhdo Custom Smilies allows Stored XSS. This issue affects Custom Smilies: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32482" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/custom-smilies/vulnerability/wordpress-custom-smilies-plugin-1-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7rq5-qrmh-5348/GHSA-7rq5-qrmh-5348.json b/advisories/unreviewed/2025/04/GHSA-7rq5-qrmh-5348/GHSA-7rq5-qrmh-5348.json new file mode 100644 index 00000000000..d32bad8d561 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7rq5-qrmh-5348/GHSA-7rq5-qrmh-5348.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rq5-qrmh-5348", + "modified": "2025-04-09T18:30:51Z", + "published": "2025-04-09T18:30:51Z", + "aliases": [ + "CVE-2025-31020" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webliberty Simple Spoiler allows Stored XSS. This issue affects Simple Spoiler: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31020" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-spoiler/vulnerability/wordpress-simple-spoiler-1-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7xpj-h3mq-wxqm/GHSA-7xpj-h3mq-wxqm.json b/advisories/unreviewed/2025/04/GHSA-7xpj-h3mq-wxqm/GHSA-7xpj-h3mq-wxqm.json new file mode 100644 index 00000000000..402761517d5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7xpj-h3mq-wxqm/GHSA-7xpj-h3mq-wxqm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xpj-h3mq-wxqm", + "modified": "2025-04-09T18:30:55Z", + "published": "2025-04-09T18:30:55Z", + "aliases": [ + "CVE-2025-32624" + ], + "details": "Missing Authorization vulnerability in czater Czater.pl – live chat i telefon allows Cross Site Request Forgery. This issue affects Czater.pl – live chat i telefon: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32624" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/czater/vulnerability/wordpress-czater-pl-live-chat-i-telefon-plugin-1-0-5-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-82wh-q6v3-5fv7/GHSA-82wh-q6v3-5fv7.json b/advisories/unreviewed/2025/04/GHSA-82wh-q6v3-5fv7/GHSA-82wh-q6v3-5fv7.json new file mode 100644 index 00000000000..cbfaa41fb4e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-82wh-q6v3-5fv7/GHSA-82wh-q6v3-5fv7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82wh-q6v3-5fv7", + "modified": "2025-04-09T18:30:54Z", + "published": "2025-04-09T18:30:54Z", + "aliases": [ + "CVE-2025-32556" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Sandor Kovacs Simple Post Meta Manager allows Reflected XSS. This issue affects Simple Post Meta Manager: from n/a through 1.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32556" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-post-meta-manager/vulnerability/wordpress-simple-post-meta-manager-plugin-1-0-9-csrf-to-reflected-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-843j-35q9-6f9x/GHSA-843j-35q9-6f9x.json b/advisories/unreviewed/2025/04/GHSA-843j-35q9-6f9x/GHSA-843j-35q9-6f9x.json new file mode 100644 index 00000000000..d464919801c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-843j-35q9-6f9x/GHSA-843j-35q9-6f9x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-843j-35q9-6f9x", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:56Z", + "aliases": [ + "CVE-2025-32675" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in QuantumCloud SEO Help allows Server Side Request Forgery. This issue affects SEO Help: from n/a through 6.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32675" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/seo-help/vulnerability/wordpress-seo-help-plugin-6-6-0-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-856w-4h2q-c3vm/GHSA-856w-4h2q-c3vm.json b/advisories/unreviewed/2025/04/GHSA-856w-4h2q-c3vm/GHSA-856w-4h2q-c3vm.json new file mode 100644 index 00000000000..31952d85cd6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-856w-4h2q-c3vm/GHSA-856w-4h2q-c3vm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-856w-4h2q-c3vm", + "modified": "2025-04-09T18:30:54Z", + "published": "2025-04-09T18:30:54Z", + "aliases": [ + "CVE-2025-32501" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in dimafreund RentSyst allows Stored XSS. This issue affects RentSyst: from n/a through 2.0.72.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32501" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rentsyst/vulnerability/wordpress-rentsyst-plugin-2-0-72-cross-site-request-forgery-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-85r9-5wfq-frxc/GHSA-85r9-5wfq-frxc.json b/advisories/unreviewed/2025/04/GHSA-85r9-5wfq-frxc/GHSA-85r9-5wfq-frxc.json new file mode 100644 index 00000000000..ac0e29411d3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-85r9-5wfq-frxc/GHSA-85r9-5wfq-frxc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85r9-5wfq-frxc", + "modified": "2025-04-09T18:30:54Z", + "published": "2025-04-09T18:30:54Z", + "aliases": [ + "CVE-2025-32505" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in SCAND MultiMailer allows Stored XSS. This issue affects MultiMailer: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32505" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/scand-multi-mailer/vulnerability/wordpress-multimailer-plugin-1-0-3-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-898w-4rv7-h42q/GHSA-898w-4rv7-h42q.json b/advisories/unreviewed/2025/04/GHSA-898w-4rv7-h42q/GHSA-898w-4rv7-h42q.json new file mode 100644 index 00000000000..61c95aa5e7e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-898w-4rv7-h42q/GHSA-898w-4rv7-h42q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-898w-4rv7-h42q", + "modified": "2025-04-09T18:30:54Z", + "published": "2025-04-09T18:30:54Z", + "aliases": [ + "CVE-2025-32575" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in axew3 WP w3all phpBB allows Reflected XSS. This issue affects WP w3all phpBB: from n/a through 2.9.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32575" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-w3all-phpbb-integration/vulnerability/wordpress-wp-w3all-phpbb-plugin-2-9-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8p4q-mjrr-xrcg/GHSA-8p4q-mjrr-xrcg.json b/advisories/unreviewed/2025/04/GHSA-8p4q-mjrr-xrcg/GHSA-8p4q-mjrr-xrcg.json new file mode 100644 index 00000000000..0daad2c25ba --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8p4q-mjrr-xrcg/GHSA-8p4q-mjrr-xrcg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p4q-mjrr-xrcg", + "modified": "2025-04-09T18:30:55Z", + "published": "2025-04-09T18:30:54Z", + "aliases": [ + "CVE-2025-32584" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Chat2 Chat2 allows Cross Site Request Forgery. This issue affects Chat2: from n/a through 3.6.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32584" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/chat2/vulnerability/wordpress-chat2-plugin-3-6-3-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8rm9-3g88-c2rp/GHSA-8rm9-3g88-c2rp.json b/advisories/unreviewed/2025/04/GHSA-8rm9-3g88-c2rp/GHSA-8rm9-3g88-c2rp.json new file mode 100644 index 00000000000..c4a3301f3c8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8rm9-3g88-c2rp/GHSA-8rm9-3g88-c2rp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rm9-3g88-c2rp", + "modified": "2025-04-09T18:30:52Z", + "published": "2025-04-09T18:30:52Z", + "aliases": [ + "CVE-2025-32479" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ab-tools Flags Widget allows Stored XSS. This issue affects Flags Widget: from n/a through 1.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32479" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/flags-widget/vulnerability/wordpress-flags-widget-plugin-1-0-7-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9262-x7f9-6hfc/GHSA-9262-x7f9-6hfc.json b/advisories/unreviewed/2025/04/GHSA-9262-x7f9-6hfc/GHSA-9262-x7f9-6hfc.json new file mode 100644 index 00000000000..7134ad25a0c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9262-x7f9-6hfc/GHSA-9262-x7f9-6hfc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9262-x7f9-6hfc", + "modified": "2025-04-09T18:30:50Z", + "published": "2025-04-09T18:30:50Z", + "aliases": [ + "CVE-2025-29394" + ], + "details": "An insecure permissions vulnerability in verydows v2.0 allows a remote attacker to execute arbitrary code by uploading a file type.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29394" + }, + { + "type": "WEB", + "url": "https://github.com/Verytops/verydows/issues/24" + }, + { + "type": "WEB", + "url": "https://gist.github.com/jaylan545/01e9653c0139638152927fe6f00cd82e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-93wv-g9pq-74g3/GHSA-93wv-g9pq-74g3.json b/advisories/unreviewed/2025/04/GHSA-93wv-g9pq-74g3/GHSA-93wv-g9pq-74g3.json new file mode 100644 index 00000000000..6e80935327f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-93wv-g9pq-74g3/GHSA-93wv-g9pq-74g3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93wv-g9pq-74g3", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:56Z", + "aliases": [ + "CVE-2025-32690" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Angelo Mandato PowerPress Podcasting allows DOM-Based XSS. This issue affects PowerPress Podcasting: from n/a through 11.12.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32690" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/powerpress/vulnerability/wordpress-powerpress-podcasting-11-12-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9gjh-5rhx-x686/GHSA-9gjh-5rhx-x686.json b/advisories/unreviewed/2025/04/GHSA-9gjh-5rhx-x686/GHSA-9gjh-5rhx-x686.json new file mode 100644 index 00000000000..8d15bc086ef --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9gjh-5rhx-x686/GHSA-9gjh-5rhx-x686.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gjh-5rhx-x686", + "modified": "2025-04-09T18:30:51Z", + "published": "2025-04-09T18:30:51Z", + "aliases": [ + "CVE-2025-31034" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in AboZain Albanna Customize Login Page allows Cross Site Request Forgery. This issue affects Customize Login Page: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31034" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/customize-login-page/vulnerability/wordpress-customize-login-page-plugin-1-1-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c44j-83ph-xfxg/GHSA-c44j-83ph-xfxg.json b/advisories/unreviewed/2025/04/GHSA-c44j-83ph-xfxg/GHSA-c44j-83ph-xfxg.json new file mode 100644 index 00000000000..3e752ecc42a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c44j-83ph-xfxg/GHSA-c44j-83ph-xfxg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c44j-83ph-xfxg", + "modified": "2025-04-09T18:30:52Z", + "published": "2025-04-09T18:30:52Z", + "aliases": [ + "CVE-2025-31401" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in mmetrodw MMX – Make Me Christmas allows Stored XSS. This issue affects MMX – Make Me Christmas: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31401" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mmx-make-me-christmas/vulnerability/wordpress-mmx-make-me-christmas-plugin-1-0-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c4x2-9r8f-8pxc/GHSA-c4x2-9r8f-8pxc.json b/advisories/unreviewed/2025/04/GHSA-c4x2-9r8f-8pxc/GHSA-c4x2-9r8f-8pxc.json new file mode 100644 index 00000000000..72fb1e2921c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c4x2-9r8f-8pxc/GHSA-c4x2-9r8f-8pxc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4x2-9r8f-8pxc", + "modified": "2025-04-09T18:30:53Z", + "published": "2025-04-09T18:30:53Z", + "aliases": [ + "CVE-2025-32492" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eliot Akira Admin Menu Post List allows Stored XSS. This issue affects Admin Menu Post List: from n/a through 2.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32492" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/admin-menu-post-list/vulnerability/wordpress-admin-menu-post-list-2-0-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c59x-jvxg-r9vx/GHSA-c59x-jvxg-r9vx.json b/advisories/unreviewed/2025/04/GHSA-c59x-jvxg-r9vx/GHSA-c59x-jvxg-r9vx.json new file mode 100644 index 00000000000..98aee197b9a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c59x-jvxg-r9vx/GHSA-c59x-jvxg-r9vx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c59x-jvxg-r9vx", + "modified": "2025-04-09T18:30:54Z", + "published": "2025-04-09T18:30:54Z", + "aliases": [ + "CVE-2025-32547" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in gtlwpdev All push notification for WP allows Blind SQL Injection. This issue affects All push notification for WP: from n/a through 1.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32547" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/all-push-notification/vulnerability/wordpress-all-push-notification-for-wp-plugin-1-5-3-csrf-to-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c6c6-925f-94rf/GHSA-c6c6-925f-94rf.json b/advisories/unreviewed/2025/04/GHSA-c6c6-925f-94rf/GHSA-c6c6-925f-94rf.json new file mode 100644 index 00000000000..ac565e5f54f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c6c6-925f-94rf/GHSA-c6c6-925f-94rf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6c6-925f-94rf", + "modified": "2025-04-09T18:30:50Z", + "published": "2025-04-09T18:30:50Z", + "aliases": [ + "CVE-2025-29391" + ], + "details": "horvey Library-Manager v1.0 is vulnerable to SQL Injection in Admin/Controller/BookController.class.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29391" + }, + { + "type": "WEB", + "url": "https://github.com/horvey/Library-Manager/issues/9" + }, + { + "type": "WEB", + "url": "https://gist.github.com/jaylan545/73dee34609ac492b9009625fb985cde4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cfrf-53p9-8wmj/GHSA-cfrf-53p9-8wmj.json b/advisories/unreviewed/2025/04/GHSA-cfrf-53p9-8wmj/GHSA-cfrf-53p9-8wmj.json new file mode 100644 index 00000000000..e0fa9f11b3f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cfrf-53p9-8wmj/GHSA-cfrf-53p9-8wmj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfrf-53p9-8wmj", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:55Z", + "aliases": [ + "CVE-2025-32661" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive US Map allows Stored XSS. This issue affects Interactive US Map: from n/a through 2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32661" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/interactive-us-map/vulnerability/wordpress-interactive-us-map-plugin-2-7-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ch43-9gp9-2hvw/GHSA-ch43-9gp9-2hvw.json b/advisories/unreviewed/2025/04/GHSA-ch43-9gp9-2hvw/GHSA-ch43-9gp9-2hvw.json new file mode 100644 index 00000000000..dc30415cc58 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ch43-9gp9-2hvw/GHSA-ch43-9gp9-2hvw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch43-9gp9-2hvw", + "modified": "2025-04-09T18:30:55Z", + "published": "2025-04-09T18:30:55Z", + "aliases": [ + "CVE-2025-32645" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Hiren Patel Custom Posts Order allows Stored XSS. This issue affects Custom Posts Order: from n/a through 4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32645" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/custom-posts-order/vulnerability/wordpress-custom-posts-order-plugin-4-4-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cxgr-6fph-qpw7/GHSA-cxgr-6fph-qpw7.json b/advisories/unreviewed/2025/04/GHSA-cxgr-6fph-qpw7/GHSA-cxgr-6fph-qpw7.json new file mode 100644 index 00000000000..6beb173914a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cxgr-6fph-qpw7/GHSA-cxgr-6fph-qpw7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxgr-6fph-qpw7", + "modified": "2025-04-09T18:30:52Z", + "published": "2025-04-09T18:30:52Z", + "aliases": [ + "CVE-2025-31402" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in NewsBoard Plugin NewsBoard Post and RSS Scroller allows Stored XSS. This issue affects NewsBoard Post and RSS Scroller: from n/a through 1.2.12.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31402" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/newsboard/vulnerability/wordpress-newsboard-post-and-rss-scroller-plugin-1-2-12-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cxx3-36xh-96f7/GHSA-cxx3-36xh-96f7.json b/advisories/unreviewed/2025/04/GHSA-cxx3-36xh-96f7/GHSA-cxx3-36xh-96f7.json new file mode 100644 index 00000000000..e227e7c6ed1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cxx3-36xh-96f7/GHSA-cxx3-36xh-96f7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxx3-36xh-96f7", + "modified": "2025-04-09T18:30:54Z", + "published": "2025-04-09T18:30:54Z", + "aliases": [ + "CVE-2025-32612" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in rafasashi User Session Synchronizer allows Stored XSS. This issue affects User Session Synchronizer: from n/a through 1.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32612" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/user-session-synchronizer/vulnerability/wordpress-user-session-synchronizer-plugin-1-4-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f77f-c7pq-c4g7/GHSA-f77f-c7pq-c4g7.json b/advisories/unreviewed/2025/04/GHSA-f77f-c7pq-c4g7/GHSA-f77f-c7pq-c4g7.json new file mode 100644 index 00000000000..af168a57815 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f77f-c7pq-c4g7/GHSA-f77f-c7pq-c4g7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f77f-c7pq-c4g7", + "modified": "2025-04-09T18:30:53Z", + "published": "2025-04-09T18:30:53Z", + "aliases": [ + "CVE-2025-32500" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Sudavar Codescar Radio Widget allows Stored XSS. This issue affects Codescar Radio Widget: from n/a through 0.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32500" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/codescar-radio-widget/vulnerability/wordpress-codescar-radio-widget-plugin-0-4-2-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f9qc-474c-5mh2/GHSA-f9qc-474c-5mh2.json b/advisories/unreviewed/2025/04/GHSA-f9qc-474c-5mh2/GHSA-f9qc-474c-5mh2.json new file mode 100644 index 00000000000..d3b6a978da5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f9qc-474c-5mh2/GHSA-f9qc-474c-5mh2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9qc-474c-5mh2", + "modified": "2025-04-09T18:30:52Z", + "published": "2025-04-09T18:30:52Z", + "aliases": [ + "CVE-2025-32476" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in blueinstyle Advanced Tag Lists allows Stored XSS. This issue affects Advanced Tag Lists: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32476" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-tag-list/vulnerability/wordpress-advanced-tag-lists-plugin-1-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ffmm-98mj-4mgx/GHSA-ffmm-98mj-4mgx.json b/advisories/unreviewed/2025/04/GHSA-ffmm-98mj-4mgx/GHSA-ffmm-98mj-4mgx.json new file mode 100644 index 00000000000..3728282c7f6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ffmm-98mj-4mgx/GHSA-ffmm-98mj-4mgx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffmm-98mj-4mgx", + "modified": "2025-04-09T18:30:53Z", + "published": "2025-04-09T18:30:52Z", + "aliases": [ + "CVE-2025-32477" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Jordi Salord WP-Easy Menu allows Stored XSS. This issue affects WP-Easy Menu: from n/a through 0.41.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32477" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-easy-menu/vulnerability/wordpress-wp-easy-menu-plugin-0-41-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fgg8-rprm-rg7v/GHSA-fgg8-rprm-rg7v.json b/advisories/unreviewed/2025/04/GHSA-fgg8-rprm-rg7v/GHSA-fgg8-rprm-rg7v.json new file mode 100644 index 00000000000..97c70d831b1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fgg8-rprm-rg7v/GHSA-fgg8-rprm-rg7v.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgg8-rprm-rg7v", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:56Z", + "aliases": [ + "CVE-2025-3131" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal ECA: Event - Condition - Action allows Cross Site Request Forgery.This issue affects ECA: Event - Condition - Action: from 0.0.0 before 1.1.12, from 2.0.0 before 2.0.16, from 2.1.0 before 2.1.7, from 0.0.0 before 1.2.*.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3131" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-031" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fv2f-79j5-jgrv/GHSA-fv2f-79j5-jgrv.json b/advisories/unreviewed/2025/04/GHSA-fv2f-79j5-jgrv/GHSA-fv2f-79j5-jgrv.json new file mode 100644 index 00000000000..605e23b37c2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fv2f-79j5-jgrv/GHSA-fv2f-79j5-jgrv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv2f-79j5-jgrv", + "modified": "2025-04-09T18:30:55Z", + "published": "2025-04-09T18:30:55Z", + "aliases": [ + "CVE-2025-32621" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Vsourz Digital WP Map Route Planner allows Cross Site Request Forgery. This issue affects WP Map Route Planner: from n/a through 1.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32621" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-map-route-planner/vulnerability/wordpress-wp-map-route-planner-plugin-1-0-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ggmq-45q5-gq4m/GHSA-ggmq-45q5-gq4m.json b/advisories/unreviewed/2025/04/GHSA-ggmq-45q5-gq4m/GHSA-ggmq-45q5-gq4m.json new file mode 100644 index 00000000000..e8c43d453d0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ggmq-45q5-gq4m/GHSA-ggmq-45q5-gq4m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggmq-45q5-gq4m", + "modified": "2025-04-09T18:30:51Z", + "published": "2025-04-09T18:30:51Z", + "aliases": [ + "CVE-2025-31026" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Austin Comment Validation Reloaded allows Stored XSS. This issue affects Comment Validation Reloaded: from n/a through 0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31026" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/comment-validation-reloaded/vulnerability/wordpress-comment-validation-reloaded-plugin-0-5-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gr2v-pvqm-gwwc/GHSA-gr2v-pvqm-gwwc.json b/advisories/unreviewed/2025/04/GHSA-gr2v-pvqm-gwwc/GHSA-gr2v-pvqm-gwwc.json new file mode 100644 index 00000000000..2b53f617b2f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gr2v-pvqm-gwwc/GHSA-gr2v-pvqm-gwwc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr2v-pvqm-gwwc", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:56Z", + "aliases": [ + "CVE-2025-32673" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in epeken Epeken All Kurir allows Stored XSS. This issue affects Epeken All Kurir: from n/a through 1.4.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32673" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/epeken-all-kurir/vulnerability/wordpress-epeken-all-kurir-plugin-1-4-6-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h6cv-hw2x-5cwp/GHSA-h6cv-hw2x-5cwp.json b/advisories/unreviewed/2025/04/GHSA-h6cv-hw2x-5cwp/GHSA-h6cv-hw2x-5cwp.json new file mode 100644 index 00000000000..9e54feb6201 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h6cv-hw2x-5cwp/GHSA-h6cv-hw2x-5cwp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6cv-hw2x-5cwp", + "modified": "2025-04-09T18:30:55Z", + "published": "2025-04-09T18:30:55Z", + "aliases": [ + "CVE-2025-32642" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in appsbd Vite Coupon allows Remote Code Inclusion. This issue affects Vite Coupon: from n/a through 1.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32642" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/vite-coupon/vulnerability/wordpress-vite-coupon-plugin-1-0-7-csrf-to-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h78m-4g6h-334g/GHSA-h78m-4g6h-334g.json b/advisories/unreviewed/2025/04/GHSA-h78m-4g6h-334g/GHSA-h78m-4g6h-334g.json index 41eeabdd40f..2618e6b078e 100644 --- a/advisories/unreviewed/2025/04/GHSA-h78m-4g6h-334g/GHSA-h78m-4g6h-334g.json +++ b/advisories/unreviewed/2025/04/GHSA-h78m-4g6h-334g/GHSA-h78m-4g6h-334g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-77" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-hc4m-pjg9-5c8f/GHSA-hc4m-pjg9-5c8f.json b/advisories/unreviewed/2025/04/GHSA-hc4m-pjg9-5c8f/GHSA-hc4m-pjg9-5c8f.json new file mode 100644 index 00000000000..19d29930ebe --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hc4m-pjg9-5c8f/GHSA-hc4m-pjg9-5c8f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc4m-pjg9-5c8f", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:56Z", + "aliases": [ + "CVE-2025-32691" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Angelo Mandato PowerPress Podcasting allows Server Side Request Forgery. This issue affects PowerPress Podcasting: from n/a through 11.12.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32691" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/powerpress/vulnerability/wordpress-powerpress-podcasting-11-12-4-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hfpr-xhrf-jgv3/GHSA-hfpr-xhrf-jgv3.json b/advisories/unreviewed/2025/04/GHSA-hfpr-xhrf-jgv3/GHSA-hfpr-xhrf-jgv3.json new file mode 100644 index 00000000000..bf3a9ddef1a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hfpr-xhrf-jgv3/GHSA-hfpr-xhrf-jgv3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfpr-xhrf-jgv3", + "modified": "2025-04-09T18:30:53Z", + "published": "2025-04-09T18:30:53Z", + "aliases": [ + "CVE-2025-32494" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in bozdoz reCAPTCHA Jetpack allows Cross Site Request Forgery. This issue affects reCAPTCHA Jetpack: from n/a through 0.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32494" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/recaptcha-jetpack/vulnerability/wordpress-recaptcha-jetpack-0-2-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hg33-c74g-5r58/GHSA-hg33-c74g-5r58.json b/advisories/unreviewed/2025/04/GHSA-hg33-c74g-5r58/GHSA-hg33-c74g-5r58.json new file mode 100644 index 00000000000..391e894058f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hg33-c74g-5r58/GHSA-hg33-c74g-5r58.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hg33-c74g-5r58", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:56Z", + "aliases": [ + "CVE-2025-32684" + ], + "details": "Missing Authorization vulnerability in RomanCode MapSVG Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MapSVG Lite: from n/a through 8.5.32.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32684" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mapsvg-lite-interactive-vector-maps/vulnerability/wordpress-mapsvg-lite-plugin-8-5-32-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hhhr-875p-xj5g/GHSA-hhhr-875p-xj5g.json b/advisories/unreviewed/2025/04/GHSA-hhhr-875p-xj5g/GHSA-hhhr-875p-xj5g.json new file mode 100644 index 00000000000..28960ac403c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hhhr-875p-xj5g/GHSA-hhhr-875p-xj5g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhhr-875p-xj5g", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:56Z", + "aliases": [ + "CVE-2025-32695" + ], + "details": "Incorrect Privilege Assignment vulnerability in Mestres do WP Checkout Mestres WP allows Privilege Escalation. This issue affects Checkout Mestres WP: from n/a through 8.7.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32695" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/checkout-mestres-wp/vulnerability/wordpress-checkout-mestres-wp-8-7-5-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hp4v-q7qc-45wr/GHSA-hp4v-q7qc-45wr.json b/advisories/unreviewed/2025/04/GHSA-hp4v-q7qc-45wr/GHSA-hp4v-q7qc-45wr.json index c2e4edfd561..db1b60ed74e 100644 --- a/advisories/unreviewed/2025/04/GHSA-hp4v-q7qc-45wr/GHSA-hp4v-q7qc-45wr.json +++ b/advisories/unreviewed/2025/04/GHSA-hp4v-q7qc-45wr/GHSA-hp4v-q7qc-45wr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hp4v-q7qc-45wr", - "modified": "2025-04-07T21:32:06Z", + "modified": "2025-04-09T18:30:49Z", "published": "2025-04-07T15:31:10Z", "aliases": [ "CVE-2025-30401" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://www.facebook.com/security/advisories/cve-2025-30401" + }, + { + "type": "WEB", + "url": "https://www.whatsapp.com/security/advisories/2025" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-hp8v-m2mf-6ffv/GHSA-hp8v-m2mf-6ffv.json b/advisories/unreviewed/2025/04/GHSA-hp8v-m2mf-6ffv/GHSA-hp8v-m2mf-6ffv.json new file mode 100644 index 00000000000..ab02640140b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hp8v-m2mf-6ffv/GHSA-hp8v-m2mf-6ffv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp8v-m2mf-6ffv", + "modified": "2025-04-09T18:30:51Z", + "published": "2025-04-09T18:30:51Z", + "aliases": [ + "CVE-2025-31042" + ], + "details": "Missing Authorization vulnerability in rtakao Sandwich Adsense allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sandwich Adsense: from n/a through 4.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31042" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/firsth3tagadsense/vulnerability/wordpress-sandwich-adsense-4-0-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hv83-7234-xwv7/GHSA-hv83-7234-xwv7.json b/advisories/unreviewed/2025/04/GHSA-hv83-7234-xwv7/GHSA-hv83-7234-xwv7.json new file mode 100644 index 00000000000..0d9f1af010b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hv83-7234-xwv7/GHSA-hv83-7234-xwv7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hv83-7234-xwv7", + "modified": "2025-04-09T18:30:55Z", + "published": "2025-04-09T18:30:55Z", + "aliases": [ + "CVE-2025-32617" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Ydesignservices Multiple Location Google Map allows Stored XSS. This issue affects Multiple Location Google Map: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32617" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/multiple-location-google-map/vulnerability/wordpress-multiple-location-google-map-plugin-1-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hwj3-v9vw-g5g2/GHSA-hwj3-v9vw-g5g2.json b/advisories/unreviewed/2025/04/GHSA-hwj3-v9vw-g5g2/GHSA-hwj3-v9vw-g5g2.json new file mode 100644 index 00000000000..1af808f9f6b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hwj3-v9vw-g5g2/GHSA-hwj3-v9vw-g5g2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwj3-v9vw-g5g2", + "modified": "2025-04-09T18:30:52Z", + "published": "2025-04-09T18:30:52Z", + "aliases": [ + "CVE-2025-31404" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Wladyslaw Madejczyk AF Tell a Friend allows Stored XSS. This issue affects AF Tell a Friend: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31404" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/af-tell-a-friend/vulnerability/wordpress-af-tell-a-friend-plugin-1-4-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hx3q-gx9q-hxmw/GHSA-hx3q-gx9q-hxmw.json b/advisories/unreviewed/2025/04/GHSA-hx3q-gx9q-hxmw/GHSA-hx3q-gx9q-hxmw.json new file mode 100644 index 00000000000..576e24cdfbb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hx3q-gx9q-hxmw/GHSA-hx3q-gx9q-hxmw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx3q-gx9q-hxmw", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:55Z", + "aliases": [ + "CVE-2025-32676" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Picture-Planet GmbH Verowa Connect allows Blind SQL Injection. This issue affects Verowa Connect: from n/a through 3.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32676" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/verowa-connect/vulnerability/wordpress-verowa-connect-plugin-3-0-5-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j2q2-q6cc-jr5h/GHSA-j2q2-q6cc-jr5h.json b/advisories/unreviewed/2025/04/GHSA-j2q2-q6cc-jr5h/GHSA-j2q2-q6cc-jr5h.json new file mode 100644 index 00000000000..ea2dcc96f75 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j2q2-q6cc-jr5h/GHSA-j2q2-q6cc-jr5h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2q2-q6cc-jr5h", + "modified": "2025-04-09T18:30:51Z", + "published": "2025-04-09T18:30:51Z", + "aliases": [ + "CVE-2025-31008" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YouTube Embed Plugin Support YouTube Embed allows Stored XSS. This issue affects YouTube Embed: from n/a through 5.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31008" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/youtube-embed/vulnerability/wordpress-youtube-embed-5-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j7hv-f7pc-9m6h/GHSA-j7hv-f7pc-9m6h.json b/advisories/unreviewed/2025/04/GHSA-j7hv-f7pc-9m6h/GHSA-j7hv-f7pc-9m6h.json new file mode 100644 index 00000000000..d456002c403 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j7hv-f7pc-9m6h/GHSA-j7hv-f7pc-9m6h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7hv-f7pc-9m6h", + "modified": "2025-04-09T18:30:51Z", + "published": "2025-04-09T18:30:51Z", + "aliases": [ + "CVE-2025-31017" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robert Noakes Nav Menu Manager allows Stored XSS. This issue affects Nav Menu Manager: from n/a through 3.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31017" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/noakes-menu-manager/vulnerability/wordpress-nav-menu-manager-3-2-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j7wg-vqfq-fh3f/GHSA-j7wg-vqfq-fh3f.json b/advisories/unreviewed/2025/04/GHSA-j7wg-vqfq-fh3f/GHSA-j7wg-vqfq-fh3f.json index e9c4a04867f..be28aa7f0e5 100644 --- a/advisories/unreviewed/2025/04/GHSA-j7wg-vqfq-fh3f/GHSA-j7wg-vqfq-fh3f.json +++ b/advisories/unreviewed/2025/04/GHSA-j7wg-vqfq-fh3f/GHSA-j7wg-vqfq-fh3f.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-j8mc-xcxh-9rm2/GHSA-j8mc-xcxh-9rm2.json b/advisories/unreviewed/2025/04/GHSA-j8mc-xcxh-9rm2/GHSA-j8mc-xcxh-9rm2.json new file mode 100644 index 00000000000..629ca52f0df --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j8mc-xcxh-9rm2/GHSA-j8mc-xcxh-9rm2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8mc-xcxh-9rm2", + "modified": "2025-04-09T18:30:54Z", + "published": "2025-04-09T18:30:54Z", + "aliases": [ + "CVE-2025-32570" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ChillPay ChillPay WooCommerce allows Stored XSS. This issue affects ChillPay WooCommerce: from n/a through 2.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32570" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/chillpay-payment-gateway/vulnerability/wordpress-chillpay-woocommerce-plugin-2-5-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j95m-vcjc-hm79/GHSA-j95m-vcjc-hm79.json b/advisories/unreviewed/2025/04/GHSA-j95m-vcjc-hm79/GHSA-j95m-vcjc-hm79.json new file mode 100644 index 00000000000..5c2f6fa3eb1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j95m-vcjc-hm79/GHSA-j95m-vcjc-hm79.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j95m-vcjc-hm79", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:56Z", + "aliases": [ + "CVE-2025-3474" + ], + "details": "Missing Authentication for Critical Function vulnerability in Drupal Panels allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Panels: from 0.0.0 before 4.9.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3474" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-033" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jq4c-g2mv-39mq/GHSA-jq4c-g2mv-39mq.json b/advisories/unreviewed/2025/04/GHSA-jq4c-g2mv-39mq/GHSA-jq4c-g2mv-39mq.json new file mode 100644 index 00000000000..90b66b33925 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jq4c-g2mv-39mq/GHSA-jq4c-g2mv-39mq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq4c-g2mv-39mq", + "modified": "2025-04-09T18:30:55Z", + "published": "2025-04-09T18:30:55Z", + "aliases": [ + "CVE-2025-32659" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in fraudlabspro FraudLabs Pro for WooCommerce allows Stored XSS. This issue affects FraudLabs Pro for WooCommerce: from n/a through 2.22.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32659" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fraudlabs-pro-for-woocommerce/vulnerability/wordpress-fraudlabs-pro-for-woocommerce-plugin-2-22-7-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jqxw-j9cr-8v8p/GHSA-jqxw-j9cr-8v8p.json b/advisories/unreviewed/2025/04/GHSA-jqxw-j9cr-8v8p/GHSA-jqxw-j9cr-8v8p.json new file mode 100644 index 00000000000..68a003493c7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jqxw-j9cr-8v8p/GHSA-jqxw-j9cr-8v8p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqxw-j9cr-8v8p", + "modified": "2025-04-09T18:30:51Z", + "published": "2025-04-09T18:30:51Z", + "aliases": [ + "CVE-2025-31033" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Adam Nowak Buddypress Humanity allows Cross Site Request Forgery. This issue affects Buddypress Humanity: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31033" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/buddypress-humanity/vulnerability/wordpress-buddypress-humanity-plugin-1-2-csrf-to-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jwq2-c69m-7qxf/GHSA-jwq2-c69m-7qxf.json b/advisories/unreviewed/2025/04/GHSA-jwq2-c69m-7qxf/GHSA-jwq2-c69m-7qxf.json new file mode 100644 index 00000000000..0aa0beab148 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jwq2-c69m-7qxf/GHSA-jwq2-c69m-7qxf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwq2-c69m-7qxf", + "modified": "2025-04-09T18:30:54Z", + "published": "2025-04-09T18:30:54Z", + "aliases": [ + "CVE-2025-32563" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in dangrossman WP Calais Auto Tagger allows Cross Site Request Forgery. This issue affects WP Calais Auto Tagger: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32563" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/calais-auto-tagger/vulnerability/wordpress-wp-calais-auto-tagger-plugin-2-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jxcg-5m5x-c4g8/GHSA-jxcg-5m5x-c4g8.json b/advisories/unreviewed/2025/04/GHSA-jxcg-5m5x-c4g8/GHSA-jxcg-5m5x-c4g8.json new file mode 100644 index 00000000000..7e158fcf5cc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jxcg-5m5x-c4g8/GHSA-jxcg-5m5x-c4g8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxcg-5m5x-c4g8", + "modified": "2025-04-09T18:30:53Z", + "published": "2025-04-09T18:30:53Z", + "aliases": [ + "CVE-2025-32488" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in آریا وردپرس Aria Font allows Stored XSS. This issue affects Aria Font: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32488" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/aria-font/vulnerability/wordpress-aria-font-1-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m6f3-8qqf-55g7/GHSA-m6f3-8qqf-55g7.json b/advisories/unreviewed/2025/04/GHSA-m6f3-8qqf-55g7/GHSA-m6f3-8qqf-55g7.json new file mode 100644 index 00000000000..c4727e29ec2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m6f3-8qqf-55g7/GHSA-m6f3-8qqf-55g7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6f3-8qqf-55g7", + "modified": "2025-04-09T18:30:53Z", + "published": "2025-04-09T18:30:53Z", + "aliases": [ + "CVE-2025-32493" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VibeThemes BP Social Connect allows Stored XSS. This issue affects BP Social Connect: from n/a through 1.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32493" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bp-social-connect/vulnerability/wordpress-bp-social-connect-1-6-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mj8j-8p89-3rvg/GHSA-mj8j-8p89-3rvg.json b/advisories/unreviewed/2025/04/GHSA-mj8j-8p89-3rvg/GHSA-mj8j-8p89-3rvg.json new file mode 100644 index 00000000000..7059cff39b0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mj8j-8p89-3rvg/GHSA-mj8j-8p89-3rvg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mj8j-8p89-3rvg", + "modified": "2025-04-09T18:30:53Z", + "published": "2025-04-09T18:30:53Z", + "aliases": [ + "CVE-2025-32503" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Conti Link Shield allows Stored XSS. This issue affects Link Shield: from n/a through 0.5.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32503" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/link-shield/vulnerability/wordpress-link-shield-plugin-0-5-4-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mjrr-qgcx-q669/GHSA-mjrr-qgcx-q669.json b/advisories/unreviewed/2025/04/GHSA-mjrr-qgcx-q669/GHSA-mjrr-qgcx-q669.json new file mode 100644 index 00000000000..06dafaf3a1f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mjrr-qgcx-q669/GHSA-mjrr-qgcx-q669.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjrr-qgcx-q669", + "modified": "2025-04-09T18:30:54Z", + "published": "2025-04-09T18:30:54Z", + "aliases": [ + "CVE-2025-32559" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in REVE Chat REVE Chat allows Stored XSS. This issue affects REVE Chat: from n/a through 6.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32559" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/revechat/vulnerability/wordpress-reve-chat-plugin-6-2-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mp9m-wpqx-25wj/GHSA-mp9m-wpqx-25wj.json b/advisories/unreviewed/2025/04/GHSA-mp9m-wpqx-25wj/GHSA-mp9m-wpqx-25wj.json new file mode 100644 index 00000000000..c82447915a8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mp9m-wpqx-25wj/GHSA-mp9m-wpqx-25wj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp9m-wpqx-25wj", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:56Z", + "aliases": [ + "CVE-2025-32685" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aristo Rinjuang WP Inquiries allows SQL Injection. This issue affects WP Inquiries: from n/a through 0.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32685" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-inquiries/vulnerability/wordpress-wp-inquiries-0-2-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mv3c-mc8v-rj5r/GHSA-mv3c-mc8v-rj5r.json b/advisories/unreviewed/2025/04/GHSA-mv3c-mc8v-rj5r/GHSA-mv3c-mc8v-rj5r.json new file mode 100644 index 00000000000..dad9d091349 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mv3c-mc8v-rj5r/GHSA-mv3c-mc8v-rj5r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv3c-mc8v-rj5r", + "modified": "2025-04-09T18:30:53Z", + "published": "2025-04-09T18:30:53Z", + "aliases": [ + "CVE-2025-32499" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpWax Logo Showcase Ultimate allows PHP Local File Inclusion. This issue affects Logo Showcase Ultimate: from n/a through 1.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32499" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/logo-showcase-ultimate/vulnerability/wordpress-logo-showcase-ultimate-plugin-1-4-4-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p2h8-p639-829m/GHSA-p2h8-p639-829m.json b/advisories/unreviewed/2025/04/GHSA-p2h8-p639-829m/GHSA-p2h8-p639-829m.json new file mode 100644 index 00000000000..5ae5b088a7b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p2h8-p639-829m/GHSA-p2h8-p639-829m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2h8-p639-829m", + "modified": "2025-04-09T18:30:51Z", + "published": "2025-04-09T18:30:51Z", + "aliases": [ + "CVE-2025-31032" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Pagopar - Grupo M S.A. Pagopar – WooCommerce Gateway allows Stored XSS. This issue affects Pagopar – WooCommerce Gateway: from n/a through 2.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31032" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pagopar-woocommerce-gateway/vulnerability/wordpress-pagopar-woocommerce-gateway-plugin-2-7-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pffp-xj6v-7cgc/GHSA-pffp-xj6v-7cgc.json b/advisories/unreviewed/2025/04/GHSA-pffp-xj6v-7cgc/GHSA-pffp-xj6v-7cgc.json new file mode 100644 index 00000000000..d449bae5355 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pffp-xj6v-7cgc/GHSA-pffp-xj6v-7cgc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pffp-xj6v-7cgc", + "modified": "2025-04-09T18:30:53Z", + "published": "2025-04-09T18:30:53Z", + "aliases": [ + "CVE-2025-32489" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Wetterwarner allows Stored XSS. This issue affects Wetterwarner: from n/a through 2.7.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32489" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wetterwarner/vulnerability/wordpress-wetterwarner-2-7-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pg6j-c3fc-2fvj/GHSA-pg6j-c3fc-2fvj.json b/advisories/unreviewed/2025/04/GHSA-pg6j-c3fc-2fvj/GHSA-pg6j-c3fc-2fvj.json new file mode 100644 index 00000000000..a14aa17cd83 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pg6j-c3fc-2fvj/GHSA-pg6j-c3fc-2fvj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg6j-c3fc-2fvj", + "modified": "2025-04-09T18:30:54Z", + "published": "2025-04-09T18:30:54Z", + "aliases": [ + "CVE-2025-32597" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in George Sexton WordPress Events Calendar Plugin – connectDaily allows Cross-Site Scripting (XSS). This issue affects WordPress Events Calendar Plugin – connectDaily: from n/a through 1.4.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32597" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/connect-daily-web-calendar/vulnerability/wordpress-wordpress-events-calendar-plugin-connectdaily-plugin-1-4-8-csrf-to-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pjfr-c8m4-mrf9/GHSA-pjfr-c8m4-mrf9.json b/advisories/unreviewed/2025/04/GHSA-pjfr-c8m4-mrf9/GHSA-pjfr-c8m4-mrf9.json new file mode 100644 index 00000000000..6c2c99fe5fe --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pjfr-c8m4-mrf9/GHSA-pjfr-c8m4-mrf9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjfr-c8m4-mrf9", + "modified": "2025-04-09T18:30:54Z", + "published": "2025-04-09T18:30:54Z", + "aliases": [ + "CVE-2025-32576" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Agence web Eoxia - Montpellier WP shop allows Upload a Web Shell to a Web Server. This issue affects WP shop: from n/a through 2.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32576" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpshop/vulnerability/wordpress-wp-shop-plugin-2-6-0-csrf-to-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pm4j-p7pm-fpvx/GHSA-pm4j-p7pm-fpvx.json b/advisories/unreviewed/2025/04/GHSA-pm4j-p7pm-fpvx/GHSA-pm4j-p7pm-fpvx.json index d05e4e1d6fc..4ad8547b579 100644 --- a/advisories/unreviewed/2025/04/GHSA-pm4j-p7pm-fpvx/GHSA-pm4j-p7pm-fpvx.json +++ b/advisories/unreviewed/2025/04/GHSA-pm4j-p7pm-fpvx/GHSA-pm4j-p7pm-fpvx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pm4j-p7pm-fpvx", - "modified": "2025-04-09T15:32:23Z", + "modified": "2025-04-09T18:30:50Z", "published": "2025-04-09T15:32:23Z", "aliases": [ "CVE-2025-27391" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/25p96cvzl1mkt29lwm2d8knklkoqolps" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/09/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-pmfj-rg5g-cfpx/GHSA-pmfj-rg5g-cfpx.json b/advisories/unreviewed/2025/04/GHSA-pmfj-rg5g-cfpx/GHSA-pmfj-rg5g-cfpx.json new file mode 100644 index 00000000000..238c85cd8bd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pmfj-rg5g-cfpx/GHSA-pmfj-rg5g-cfpx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmfj-rg5g-cfpx", + "modified": "2025-04-09T18:30:54Z", + "published": "2025-04-09T18:30:54Z", + "aliases": [ + "CVE-2025-32616" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in nimbata Nimbata Call Tracking allows Stored XSS. This issue affects Nimbata Call Tracking: from n/a through 1.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32616" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nimbata-call-tracking/vulnerability/wordpress-nimbata-call-tracking-plugin-1-7-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pwxr-fc25-6gwf/GHSA-pwxr-fc25-6gwf.json b/advisories/unreviewed/2025/04/GHSA-pwxr-fc25-6gwf/GHSA-pwxr-fc25-6gwf.json new file mode 100644 index 00000000000..ae2bfa2da28 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pwxr-fc25-6gwf/GHSA-pwxr-fc25-6gwf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwxr-fc25-6gwf", + "modified": "2025-04-09T18:30:51Z", + "published": "2025-04-09T18:30:51Z", + "aliases": [ + "CVE-2025-31004" + ], + "details": "Missing Authorization vulnerability in Croover.inc Rich Table of Contents allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Rich Table of Contents: from n/a through 1.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31004" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rich-table-of-content/vulnerability/wordpress-rich-table-of-contents-plugin-1-4-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-px4w-362r-5vgp/GHSA-px4w-362r-5vgp.json b/advisories/unreviewed/2025/04/GHSA-px4w-362r-5vgp/GHSA-px4w-362r-5vgp.json new file mode 100644 index 00000000000..c2758deadc5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-px4w-362r-5vgp/GHSA-px4w-362r-5vgp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px4w-362r-5vgp", + "modified": "2025-04-09T18:30:54Z", + "published": "2025-04-09T18:30:54Z", + "aliases": [ + "CVE-2025-32550" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Click & Pledge Connect Plugin allows SQL Injection. This issue affects Click & Pledge Connect Plugin: from 2.24080000 through WP6.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32550" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/click-pledge-connect/vulnerability/wordpress-click-pledge-connect-plugin-plugin-2-24080000-wp6-6-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-px88-f2h5-pcx3/GHSA-px88-f2h5-pcx3.json b/advisories/unreviewed/2025/04/GHSA-px88-f2h5-pcx3/GHSA-px88-f2h5-pcx3.json new file mode 100644 index 00000000000..aafc68cd5e7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-px88-f2h5-pcx3/GHSA-px88-f2h5-pcx3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px88-f2h5-pcx3", + "modified": "2025-04-09T18:30:50Z", + "published": "2025-04-09T18:30:50Z", + "aliases": [ + "CVE-2025-31003" + ], + "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bogdan Bendziukov Squeeze allows Retrieve Embedded Sensitive Data. This issue affects Squeeze: from n/a through 1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31003" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/squeeze/vulnerability/wordpress-squeeze-plugin-1-6-full-path-disclosure-fpd-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pxh9-975p-9rpv/GHSA-pxh9-975p-9rpv.json b/advisories/unreviewed/2025/04/GHSA-pxh9-975p-9rpv/GHSA-pxh9-975p-9rpv.json new file mode 100644 index 00000000000..3e86af583c9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pxh9-975p-9rpv/GHSA-pxh9-975p-9rpv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxh9-975p-9rpv", + "modified": "2025-04-09T18:30:52Z", + "published": "2025-04-09T18:30:52Z", + "aliases": [ + "CVE-2025-31391" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in regen Script Compressor allows Stored XSS. This issue affects Script Compressor: from n/a through 1.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31391" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/script-compressor/vulnerability/wordpress-script-compressor-plugin-1-7-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q7p5-2w2c-9c56/GHSA-q7p5-2w2c-9c56.json b/advisories/unreviewed/2025/04/GHSA-q7p5-2w2c-9c56/GHSA-q7p5-2w2c-9c56.json index 56f903a999b..68908da4984 100644 --- a/advisories/unreviewed/2025/04/GHSA-q7p5-2w2c-9c56/GHSA-q7p5-2w2c-9c56.json +++ b/advisories/unreviewed/2025/04/GHSA-q7p5-2w2c-9c56/GHSA-q7p5-2w2c-9c56.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-qcjq-v94f-pfgp/GHSA-qcjq-v94f-pfgp.json b/advisories/unreviewed/2025/04/GHSA-qcjq-v94f-pfgp/GHSA-qcjq-v94f-pfgp.json new file mode 100644 index 00000000000..077e5425cce --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qcjq-v94f-pfgp/GHSA-qcjq-v94f-pfgp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcjq-v94f-pfgp", + "modified": "2025-04-09T18:30:51Z", + "published": "2025-04-09T18:30:51Z", + "aliases": [ + "CVE-2025-31009" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Jan Boddez IndieBlocks allows Server Side Request Forgery. This issue affects IndieBlocks: from n/a through 0.13.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31009" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/indieblocks/vulnerability/wordpress-indieblocks-0-13-1-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qj6q-34pj-64w4/GHSA-qj6q-34pj-64w4.json b/advisories/unreviewed/2025/04/GHSA-qj6q-34pj-64w4/GHSA-qj6q-34pj-64w4.json new file mode 100644 index 00000000000..d10750eddd2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qj6q-34pj-64w4/GHSA-qj6q-34pj-64w4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qj6q-34pj-64w4", + "modified": "2025-04-09T18:30:55Z", + "published": "2025-04-09T18:30:55Z", + "aliases": [ + "CVE-2025-32623" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in plainware PlainInventory allows Stored XSS. This issue affects PlainInventory: from n/a through 3.1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32623" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/z-inventory-manager/vulnerability/wordpress-plaininventory-plugin-3-1-9-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qp4q-3vv6-j3rc/GHSA-qp4q-3vv6-j3rc.json b/advisories/unreviewed/2025/04/GHSA-qp4q-3vv6-j3rc/GHSA-qp4q-3vv6-j3rc.json new file mode 100644 index 00000000000..2647a9d1a1e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qp4q-3vv6-j3rc/GHSA-qp4q-3vv6-j3rc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp4q-3vv6-j3rc", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:56Z", + "aliases": [ + "CVE-2025-32680" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Grade Us, Inc. Review Stream allows Stored XSS. This issue affects Review Stream: from n/a through 1.6.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32680" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/review-stream/vulnerability/wordpress-review-stream-plugin-1-6-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qqr7-vq9w-hmc2/GHSA-qqr7-vq9w-hmc2.json b/advisories/unreviewed/2025/04/GHSA-qqr7-vq9w-hmc2/GHSA-qqr7-vq9w-hmc2.json new file mode 100644 index 00000000000..11cd71f8236 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qqr7-vq9w-hmc2/GHSA-qqr7-vq9w-hmc2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqr7-vq9w-hmc2", + "modified": "2025-04-09T18:30:53Z", + "published": "2025-04-09T18:30:53Z", + "aliases": [ + "CVE-2025-32483" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Salisbury Request Call Back allows Stored XSS. This issue affects Request Call Back: from n/a through 1.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32483" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/request-call-back/vulnerability/wordpress-request-call-back-1-4-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qr78-9ggp-8w57/GHSA-qr78-9ggp-8w57.json b/advisories/unreviewed/2025/04/GHSA-qr78-9ggp-8w57/GHSA-qr78-9ggp-8w57.json new file mode 100644 index 00000000000..16a00f15217 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qr78-9ggp-8w57/GHSA-qr78-9ggp-8w57.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr78-9ggp-8w57", + "modified": "2025-04-09T18:30:52Z", + "published": "2025-04-09T18:30:52Z", + "aliases": [ + "CVE-2025-31388" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in doa The World allows Stored XSS. This issue affects The World: from n/a through 0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31388" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/the-world/vulnerability/wordpress-the-world-plugin-0-4-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qwp5-gwx9-5v2m/GHSA-qwp5-gwx9-5v2m.json b/advisories/unreviewed/2025/04/GHSA-qwp5-gwx9-5v2m/GHSA-qwp5-gwx9-5v2m.json new file mode 100644 index 00000000000..108d9e641f5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qwp5-gwx9-5v2m/GHSA-qwp5-gwx9-5v2m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwp5-gwx9-5v2m", + "modified": "2025-04-09T18:30:51Z", + "published": "2025-04-09T18:30:51Z", + "aliases": [ + "CVE-2025-31375" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in bhoogterp Scheduled allows Stored XSS. This issue affects Scheduled: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31375" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/scheduled/vulnerability/wordpress-scheduled-plugin-1-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r4xq-444j-73wr/GHSA-r4xq-444j-73wr.json b/advisories/unreviewed/2025/04/GHSA-r4xq-444j-73wr/GHSA-r4xq-444j-73wr.json new file mode 100644 index 00000000000..97b3707edce --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r4xq-444j-73wr/GHSA-r4xq-444j-73wr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4xq-444j-73wr", + "modified": "2025-04-09T18:30:55Z", + "published": "2025-04-09T18:30:55Z", + "aliases": [ + "CVE-2025-32591" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Kevon Adonis WP Abstracts allows Cross Site Request Forgery. This issue affects WP Abstracts: from n/a through 2.7.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32591" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-abstracts-manuscripts-manager/vulnerability/wordpress-wp-abstracts-plugin-2-7-2-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rcqj-3fmp-5cqx/GHSA-rcqj-3fmp-5cqx.json b/advisories/unreviewed/2025/04/GHSA-rcqj-3fmp-5cqx/GHSA-rcqj-3fmp-5cqx.json index 7a07f9f3533..2a3d5bc55f3 100644 --- a/advisories/unreviewed/2025/04/GHSA-rcqj-3fmp-5cqx/GHSA-rcqj-3fmp-5cqx.json +++ b/advisories/unreviewed/2025/04/GHSA-rcqj-3fmp-5cqx/GHSA-rcqj-3fmp-5cqx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rcqj-3fmp-5cqx", - "modified": "2025-04-09T12:30:24Z", + "modified": "2025-04-09T18:30:50Z", "published": "2025-04-09T12:30:24Z", "aliases": [ "CVE-2025-30677" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://pulsar.apache.org/security" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/09/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-rhcv-f9x8-59x3/GHSA-rhcv-f9x8-59x3.json b/advisories/unreviewed/2025/04/GHSA-rhcv-f9x8-59x3/GHSA-rhcv-f9x8-59x3.json new file mode 100644 index 00000000000..4f7a9b3ac00 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rhcv-f9x8-59x3/GHSA-rhcv-f9x8-59x3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhcv-f9x8-59x3", + "modified": "2025-04-09T18:30:55Z", + "published": "2025-04-09T18:30:54Z", + "aliases": [ + "CVE-2025-32581" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ankit Singla WordPress Spam Blocker allows Stored XSS. This issue affects WordPress Spam Blocker: from n/a through 2.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32581" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cf7-manual-spam-blocker/vulnerability/wordpress-wordpress-spam-blocker-plugin-2-0-4-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v6v7-m3w9-36g8/GHSA-v6v7-m3w9-36g8.json b/advisories/unreviewed/2025/04/GHSA-v6v7-m3w9-36g8/GHSA-v6v7-m3w9-36g8.json new file mode 100644 index 00000000000..4314efb2b6b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v6v7-m3w9-36g8/GHSA-v6v7-m3w9-36g8.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6v7-m3w9-36g8", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:56Z", + "aliases": [ + "CVE-2025-3114" + ], + "details": "Code Execution via Malicious Files: Attackers can create specially crafted files with embedded code that may execute without adequate security validation, potentially leading to system compromise.\n\nSandbox Bypass Vulnerability: A flaw in the TERR security mechanism allows attackers to bypass sandbox restrictions, enabling the execution of untrusted code without appropriate controls.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3114" + }, + { + "type": "WEB", + "url": "https://community.spotfire.com/articles/spotfire/spotfire-security-advisory-april-08-2025-spotfire-cve-2025-3114-r3484" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v9rj-9v4c-4gv6/GHSA-v9rj-9v4c-4gv6.json b/advisories/unreviewed/2025/04/GHSA-v9rj-9v4c-4gv6/GHSA-v9rj-9v4c-4gv6.json new file mode 100644 index 00000000000..4318db046ab --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v9rj-9v4c-4gv6/GHSA-v9rj-9v4c-4gv6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9rj-9v4c-4gv6", + "modified": "2025-04-09T18:30:53Z", + "published": "2025-04-09T18:30:53Z", + "aliases": [ + "CVE-2025-32484" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Mathieu Chartier WP-Planification allows Stored XSS. This issue affects WP-Planification: from n/a through 2.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32484" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-planification/vulnerability/wordpress-wp-planification-wp-planning-plugin-2-3-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vf6g-8jqq-qrj6/GHSA-vf6g-8jqq-qrj6.json b/advisories/unreviewed/2025/04/GHSA-vf6g-8jqq-qrj6/GHSA-vf6g-8jqq-qrj6.json new file mode 100644 index 00000000000..c4f65d4f8ce --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vf6g-8jqq-qrj6/GHSA-vf6g-8jqq-qrj6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vf6g-8jqq-qrj6", + "modified": "2025-04-09T18:30:55Z", + "published": "2025-04-09T18:30:55Z", + "aliases": [ + "CVE-2025-32619" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in KeyCAPTCHA KeyCAPTCHA allows Stored XSS. This issue affects KeyCAPTCHA: from n/a through 2.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32619" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/keycaptcha/vulnerability/wordpress-keycaptcha-plugin-2-5-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vg3w-gqwr-gvv2/GHSA-vg3w-gqwr-gvv2.json b/advisories/unreviewed/2025/04/GHSA-vg3w-gqwr-gvv2/GHSA-vg3w-gqwr-gvv2.json new file mode 100644 index 00000000000..c887cb6e001 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vg3w-gqwr-gvv2/GHSA-vg3w-gqwr-gvv2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg3w-gqwr-gvv2", + "modified": "2025-04-09T18:30:51Z", + "published": "2025-04-09T18:30:51Z", + "aliases": [ + "CVE-2025-31377" + ], + "details": "Missing Authorization vulnerability in Asaquzzaman mishu Woo Product Feed For Marketing Channels allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woo Product Feed For Marketing Channels: from n/a through 1.9.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31377" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-to-google-merchant-center/vulnerability/wordpress-woo-product-feed-for-marketing-channels-1-9-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vrxx-q897-j52j/GHSA-vrxx-q897-j52j.json b/advisories/unreviewed/2025/04/GHSA-vrxx-q897-j52j/GHSA-vrxx-q897-j52j.json new file mode 100644 index 00000000000..e03a0817597 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vrxx-q897-j52j/GHSA-vrxx-q897-j52j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrxx-q897-j52j", + "modified": "2025-04-09T18:30:55Z", + "published": "2025-04-09T18:30:55Z", + "aliases": [ + "CVE-2025-32644" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ip2location IP2Location World Clock allows Stored XSS. This issue affects IP2Location World Clock: from n/a through 1.1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32644" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ip2location-world-clock/vulnerability/wordpress-ip2location-world-clock-plugin-1-1-9-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vvj6-5p3w-2v9q/GHSA-vvj6-5p3w-2v9q.json b/advisories/unreviewed/2025/04/GHSA-vvj6-5p3w-2v9q/GHSA-vvj6-5p3w-2v9q.json new file mode 100644 index 00000000000..d776f03c36c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vvj6-5p3w-2v9q/GHSA-vvj6-5p3w-2v9q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvj6-5p3w-2v9q", + "modified": "2025-04-09T18:30:52Z", + "published": "2025-04-09T18:30:52Z", + "aliases": [ + "CVE-2025-31390" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in bdoga Social Crowd allows Stored XSS. This issue affects Social Crowd: from n/a through 0.9.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31390" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/social-crowd/vulnerability/wordpress-social-crowd-plugin-0-9-6-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w8w8-9687-2q2q/GHSA-w8w8-9687-2q2q.json b/advisories/unreviewed/2025/04/GHSA-w8w8-9687-2q2q/GHSA-w8w8-9687-2q2q.json new file mode 100644 index 00000000000..e4f25b724f5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w8w8-9687-2q2q/GHSA-w8w8-9687-2q2q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8w8-9687-2q2q", + "modified": "2025-04-09T18:30:52Z", + "published": "2025-04-09T18:30:52Z", + "aliases": [ + "CVE-2025-31392" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Shameem Reza Smart Product Gallery Slider allows Cross Site Request Forgery. This issue affects Smart Product Gallery Slider: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31392" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/smart-product-gallery-slider/vulnerability/wordpress-smart-product-gallery-slider-plugin-1-0-4-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wg2x-g88m-2886/GHSA-wg2x-g88m-2886.json b/advisories/unreviewed/2025/04/GHSA-wg2x-g88m-2886/GHSA-wg2x-g88m-2886.json new file mode 100644 index 00000000000..27c5170d701 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wg2x-g88m-2886/GHSA-wg2x-g88m-2886.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg2x-g88m-2886", + "modified": "2025-04-09T18:30:52Z", + "published": "2025-04-09T18:30:52Z", + "aliases": [ + "CVE-2025-31394" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kailey (trepmal) More Mime Type Filters allows Stored XSS. This issue affects More Mime Type Filters: from n/a through 0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31394" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/more-mime-type-filters/vulnerability/wordpress-more-mime-type-filters-plugin-0-3-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-whrw-3m5j-pg8w/GHSA-whrw-3m5j-pg8w.json b/advisories/unreviewed/2025/04/GHSA-whrw-3m5j-pg8w/GHSA-whrw-3m5j-pg8w.json new file mode 100644 index 00000000000..8deaf8c0f2d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-whrw-3m5j-pg8w/GHSA-whrw-3m5j-pg8w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whrw-3m5j-pg8w", + "modified": "2025-04-09T18:30:55Z", + "published": "2025-04-09T18:30:55Z", + "aliases": [ + "CVE-2025-32640" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor One Click Accessibility allows Stored XSS. This issue affects One Click Accessibility: from n/a through 3.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32640" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pojo-accessibility/vulnerability/wordpress-one-click-accessibility-plugin-3-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wjcr-pcrw-p99x/GHSA-wjcr-pcrw-p99x.json b/advisories/unreviewed/2025/04/GHSA-wjcr-pcrw-p99x/GHSA-wjcr-pcrw-p99x.json new file mode 100644 index 00000000000..87f6d69b3f3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wjcr-pcrw-p99x/GHSA-wjcr-pcrw-p99x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjcr-pcrw-p99x", + "modified": "2025-04-09T18:30:51Z", + "published": "2025-04-09T18:30:51Z", + "aliases": [ + "CVE-2025-31012" + ], + "details": "Missing Authorization vulnerability in Phil Age Gate allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Age Gate: from n/a through 3.5.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31012" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/age-gate/vulnerability/wordpress-age-gate-3-5-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wwf3-h2pc-prc7/GHSA-wwf3-h2pc-prc7.json b/advisories/unreviewed/2025/04/GHSA-wwf3-h2pc-prc7/GHSA-wwf3-h2pc-prc7.json new file mode 100644 index 00000000000..04485f5e176 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wwf3-h2pc-prc7/GHSA-wwf3-h2pc-prc7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwf3-h2pc-prc7", + "modified": "2025-04-09T18:30:55Z", + "published": "2025-04-09T18:30:55Z", + "aliases": [ + "CVE-2025-32641" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in anantaddons Anant Addons for Elementor allows Cross Site Request Forgery. This issue affects Anant Addons for Elementor: from n/a through 1.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32641" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/anant-addons-for-elementor/vulnerability/wordpress-anant-addons-for-elementor-plugin-1-1-5-csrf-to-arbitrary-plugin-installation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wx7v-p49w-vwx3/GHSA-wx7v-p49w-vwx3.json b/advisories/unreviewed/2025/04/GHSA-wx7v-p49w-vwx3/GHSA-wx7v-p49w-vwx3.json new file mode 100644 index 00000000000..96fd7110df1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wx7v-p49w-vwx3/GHSA-wx7v-p49w-vwx3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx7v-p49w-vwx3", + "modified": "2025-04-09T18:30:52Z", + "published": "2025-04-09T18:30:52Z", + "aliases": [ + "CVE-2025-32480" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in dalziel Windows Live Writer allows Stored XSS. This issue affects Windows Live Writer: from n/a through 0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32480" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/windows-live-writer/vulnerability/wordpress-windows-live-writer-plugin-0-1-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x44w-4pwf-wpx2/GHSA-x44w-4pwf-wpx2.json b/advisories/unreviewed/2025/04/GHSA-x44w-4pwf-wpx2/GHSA-x44w-4pwf-wpx2.json new file mode 100644 index 00000000000..9814cc499a4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x44w-4pwf-wpx2/GHSA-x44w-4pwf-wpx2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x44w-4pwf-wpx2", + "modified": "2025-04-09T18:30:53Z", + "published": "2025-04-09T18:30:53Z", + "aliases": [ + "CVE-2025-32496" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Uncodethemes Ultra Demo Importer allows Upload a Web Shell to a Web Server. This issue affects Ultra Demo Importer: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32496" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ut-demo-importer/vulnerability/wordpress-ultra-demo-importer-plugin-1-0-5-csrf-to-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xfpw-388w-fh3f/GHSA-xfpw-388w-fh3f.json b/advisories/unreviewed/2025/04/GHSA-xfpw-388w-fh3f/GHSA-xfpw-388w-fh3f.json index 92e90c1bc71..0b8759b37e7 100644 --- a/advisories/unreviewed/2025/04/GHSA-xfpw-388w-fh3f/GHSA-xfpw-388w-fh3f.json +++ b/advisories/unreviewed/2025/04/GHSA-xfpw-388w-fh3f/GHSA-xfpw-388w-fh3f.json @@ -54,7 +54,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-xjh4-42q7-h5mj/GHSA-xjh4-42q7-h5mj.json b/advisories/unreviewed/2025/04/GHSA-xjh4-42q7-h5mj/GHSA-xjh4-42q7-h5mj.json new file mode 100644 index 00000000000..9fc7e360b1e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xjh4-42q7-h5mj/GHSA-xjh4-42q7-h5mj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjh4-42q7-h5mj", + "modified": "2025-04-09T18:30:56Z", + "published": "2025-04-09T18:30:56Z", + "aliases": [ + "CVE-2025-32692" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle WP Subscription Forms allows PHP Local File Inclusion. This issue affects WP Subscription Forms: from n/a through 1.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32692" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-subscription-forms/vulnerability/wordpress-wp-subscription-forms-1-2-4-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T17:15:53Z" + } +} \ No newline at end of file