From dec022248da010d3cc6315e2247eaf8429d9f841 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 13 Jan 2025 15:32:32 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2wjg-2258-j35v.json | 4 +- .../GHSA-4452-v8jv-h496.json | 4 +- .../GHSA-gqv6-f424-3g7h.json | 1 + .../GHSA-xmmg-4cv8-23px.json | 3 +- .../GHSA-48mq-mj2m-9cjq.json | 2 +- .../GHSA-3vv9-8w9f-p9ff.json | 11 +++-- .../GHSA-4796-5527-wm9m.json | 40 +++++++++++++++++++ .../GHSA-4vrr-rw92-55r5.json | 36 +++++++++++++++++ .../GHSA-67mc-4p8x-7m7c.json | 36 +++++++++++++++++ .../GHSA-6qmq-j47c-v4fj.json | 11 +++-- .../GHSA-7jhp-8mw7-9mrw.json | 31 ++++++++++++++ .../GHSA-7mwr-cp39-gfrr.json | 36 +++++++++++++++++ .../GHSA-7wr4-3xj4-r25x.json | 36 +++++++++++++++++ .../GHSA-89c7-pc4g-j258.json | 40 +++++++++++++++++++ .../GHSA-8wq5-f766-wx2w.json | 36 +++++++++++++++++ .../GHSA-9hh8-pv8q-9qj8.json | 36 +++++++++++++++++ .../GHSA-cm3g-7qfv-7cxg.json | 36 +++++++++++++++++ .../GHSA-cw8x-p7hf-968r.json | 11 +++-- .../GHSA-fvwm-q99j-g85v.json | 36 +++++++++++++++++ .../GHSA-grjf-8q2x-rwg3.json | 36 +++++++++++++++++ .../GHSA-h6pf-2cgw-xppm.json | 36 +++++++++++++++++ .../GHSA-hj67-jpc7-m6mm.json | 36 +++++++++++++++++ .../GHSA-hp45-vh86-p77g.json | 36 +++++++++++++++++ .../GHSA-hpcp-qr34-rj6h.json | 11 +++-- .../GHSA-j5m8-gxw9-4wjf.json | 36 +++++++++++++++++ .../GHSA-mr89-55m9-528m.json | 36 +++++++++++++++++ .../GHSA-pqrv-f5cf-p9gq.json | 36 +++++++++++++++++ .../GHSA-pw9j-qgmc-g62h.json | 11 +++-- .../GHSA-r7m8-pv7c-r2ph.json | 11 +++-- .../GHSA-rmhw-74f4-6h32.json | 36 +++++++++++++++++ .../GHSA-vpm9-4h47-6p73.json | 36 +++++++++++++++++ .../GHSA-vvfx-pqjc-f597.json | 36 +++++++++++++++++ .../GHSA-x46g-g77r-3g5c.json | 36 +++++++++++++++++ 33 files changed, 853 insertions(+), 22 deletions(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-4796-5527-wm9m/GHSA-4796-5527-wm9m.json create mode 100644 advisories/unreviewed/2025/01/GHSA-4vrr-rw92-55r5/GHSA-4vrr-rw92-55r5.json create mode 100644 advisories/unreviewed/2025/01/GHSA-67mc-4p8x-7m7c/GHSA-67mc-4p8x-7m7c.json create mode 100644 advisories/unreviewed/2025/01/GHSA-7jhp-8mw7-9mrw/GHSA-7jhp-8mw7-9mrw.json create mode 100644 advisories/unreviewed/2025/01/GHSA-7mwr-cp39-gfrr/GHSA-7mwr-cp39-gfrr.json create mode 100644 advisories/unreviewed/2025/01/GHSA-7wr4-3xj4-r25x/GHSA-7wr4-3xj4-r25x.json create mode 100644 advisories/unreviewed/2025/01/GHSA-89c7-pc4g-j258/GHSA-89c7-pc4g-j258.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8wq5-f766-wx2w/GHSA-8wq5-f766-wx2w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9hh8-pv8q-9qj8/GHSA-9hh8-pv8q-9qj8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-cm3g-7qfv-7cxg/GHSA-cm3g-7qfv-7cxg.json create mode 100644 advisories/unreviewed/2025/01/GHSA-fvwm-q99j-g85v/GHSA-fvwm-q99j-g85v.json create mode 100644 advisories/unreviewed/2025/01/GHSA-grjf-8q2x-rwg3/GHSA-grjf-8q2x-rwg3.json create mode 100644 advisories/unreviewed/2025/01/GHSA-h6pf-2cgw-xppm/GHSA-h6pf-2cgw-xppm.json create mode 100644 advisories/unreviewed/2025/01/GHSA-hj67-jpc7-m6mm/GHSA-hj67-jpc7-m6mm.json create mode 100644 advisories/unreviewed/2025/01/GHSA-hp45-vh86-p77g/GHSA-hp45-vh86-p77g.json create mode 100644 advisories/unreviewed/2025/01/GHSA-j5m8-gxw9-4wjf/GHSA-j5m8-gxw9-4wjf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-mr89-55m9-528m/GHSA-mr89-55m9-528m.json create mode 100644 advisories/unreviewed/2025/01/GHSA-pqrv-f5cf-p9gq/GHSA-pqrv-f5cf-p9gq.json create mode 100644 advisories/unreviewed/2025/01/GHSA-rmhw-74f4-6h32/GHSA-rmhw-74f4-6h32.json create mode 100644 advisories/unreviewed/2025/01/GHSA-vpm9-4h47-6p73/GHSA-vpm9-4h47-6p73.json create mode 100644 advisories/unreviewed/2025/01/GHSA-vvfx-pqjc-f597/GHSA-vvfx-pqjc-f597.json create mode 100644 advisories/unreviewed/2025/01/GHSA-x46g-g77r-3g5c/GHSA-x46g-g77r-3g5c.json diff --git a/advisories/unreviewed/2024/02/GHSA-2wjg-2258-j35v/GHSA-2wjg-2258-j35v.json b/advisories/unreviewed/2024/02/GHSA-2wjg-2258-j35v/GHSA-2wjg-2258-j35v.json index a6fd7a2e774..48d7810f76f 100644 --- a/advisories/unreviewed/2024/02/GHSA-2wjg-2258-j35v/GHSA-2wjg-2258-j35v.json +++ b/advisories/unreviewed/2024/02/GHSA-2wjg-2258-j35v/GHSA-2wjg-2258-j35v.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-434" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-4452-v8jv-h496/GHSA-4452-v8jv-h496.json b/advisories/unreviewed/2024/02/GHSA-4452-v8jv-h496/GHSA-4452-v8jv-h496.json index 13ad53085a0..fea0ec943aa 100644 --- a/advisories/unreviewed/2024/02/GHSA-4452-v8jv-h496/GHSA-4452-v8jv-h496.json +++ b/advisories/unreviewed/2024/02/GHSA-4452-v8jv-h496/GHSA-4452-v8jv-h496.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-91" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-gqv6-f424-3g7h/GHSA-gqv6-f424-3g7h.json b/advisories/unreviewed/2024/02/GHSA-gqv6-f424-3g7h/GHSA-gqv6-f424-3g7h.json index fef3854bf30..f7d34eb3347 100644 --- a/advisories/unreviewed/2024/02/GHSA-gqv6-f424-3g7h/GHSA-gqv6-f424-3g7h.json +++ b/advisories/unreviewed/2024/02/GHSA-gqv6-f424-3g7h/GHSA-gqv6-f424-3g7h.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1333", "CWE-20" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/02/GHSA-xmmg-4cv8-23px/GHSA-xmmg-4cv8-23px.json b/advisories/unreviewed/2024/02/GHSA-xmmg-4cv8-23px/GHSA-xmmg-4cv8-23px.json index 808f3ebf642..0737e536863 100644 --- a/advisories/unreviewed/2024/02/GHSA-xmmg-4cv8-23px/GHSA-xmmg-4cv8-23px.json +++ b/advisories/unreviewed/2024/02/GHSA-xmmg-4cv8-23px/GHSA-xmmg-4cv8-23px.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-601" + "CWE-601", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-48mq-mj2m-9cjq/GHSA-48mq-mj2m-9cjq.json b/advisories/unreviewed/2024/07/GHSA-48mq-mj2m-9cjq/GHSA-48mq-mj2m-9cjq.json index 898158ce610..ead8e450a5d 100644 --- a/advisories/unreviewed/2024/07/GHSA-48mq-mj2m-9cjq/GHSA-48mq-mj2m-9cjq.json +++ b/advisories/unreviewed/2024/07/GHSA-48mq-mj2m-9cjq/GHSA-48mq-mj2m-9cjq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-48mq-mj2m-9cjq", - "modified": "2024-07-16T18:31:42Z", + "modified": "2025-01-13T15:30:48Z", "published": "2024-07-16T15:30:50Z", "aliases": [ "CVE-2024-32861" diff --git a/advisories/unreviewed/2025/01/GHSA-3vv9-8w9f-p9ff/GHSA-3vv9-8w9f-p9ff.json b/advisories/unreviewed/2025/01/GHSA-3vv9-8w9f-p9ff/GHSA-3vv9-8w9f-p9ff.json index de1efbb6578..35d55194578 100644 --- a/advisories/unreviewed/2025/01/GHSA-3vv9-8w9f-p9ff/GHSA-3vv9-8w9f-p9ff.json +++ b/advisories/unreviewed/2025/01/GHSA-3vv9-8w9f-p9ff/GHSA-3vv9-8w9f-p9ff.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3vv9-8w9f-p9ff", - "modified": "2025-01-13T12:31:59Z", + "modified": "2025-01-13T15:30:49Z", "published": "2025-01-13T12:31:59Z", "aliases": [ "CVE-2024-52938" ], "details": "Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to subvert reconstruction activities to trigger a write of data outside the Guest's virtualised GPU memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-823" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-13T12:15:06Z" diff --git a/advisories/unreviewed/2025/01/GHSA-4796-5527-wm9m/GHSA-4796-5527-wm9m.json b/advisories/unreviewed/2025/01/GHSA-4796-5527-wm9m/GHSA-4796-5527-wm9m.json new file mode 100644 index 00000000000..1d334f1d0a9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4796-5527-wm9m/GHSA-4796-5527-wm9m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4796-5527-wm9m", + "modified": "2025-01-13T15:30:50Z", + "published": "2025-01-13T15:30:50Z", + "aliases": [ + "CVE-2024-47796" + ], + "details": "An improper array index validation vulnerability exists in the nowindow functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47796" + }, + { + "type": "WEB", + "url": "https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=89a6e399f1e17d08a8bc8cdaa05b2ac9a50cd4f6" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2122" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4vrr-rw92-55r5/GHSA-4vrr-rw92-55r5.json b/advisories/unreviewed/2025/01/GHSA-4vrr-rw92-55r5/GHSA-4vrr-rw92-55r5.json new file mode 100644 index 00000000000..53f9eaec16d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4vrr-rw92-55r5/GHSA-4vrr-rw92-55r5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vrr-rw92-55r5", + "modified": "2025-01-13T15:30:50Z", + "published": "2025-01-13T15:30:50Z", + "aliases": [ + "CVE-2025-22800" + ], + "details": "Missing Authorization vulnerability in Post SMTP Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post SMTP: from n/a through 2.9.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22800" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/post-smtp/vulnerability/wordpress-post-smtp-plugin-2-9-11-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-67mc-4p8x-7m7c/GHSA-67mc-4p8x-7m7c.json b/advisories/unreviewed/2025/01/GHSA-67mc-4p8x-7m7c/GHSA-67mc-4p8x-7m7c.json new file mode 100644 index 00000000000..61503e6b357 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-67mc-4p8x-7m7c/GHSA-67mc-4p8x-7m7c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67mc-4p8x-7m7c", + "modified": "2025-01-13T15:30:50Z", + "published": "2025-01-13T15:30:50Z", + "aliases": [ + "CVE-2025-22567" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in trustist TRUSTist REVIEWer allows Reflected XSS.This issue affects TRUSTist REVIEWer: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22567" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/trustist-reviewer/vulnerability/wordpress-trustist-reviewer-plugin-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6qmq-j47c-v4fj/GHSA-6qmq-j47c-v4fj.json b/advisories/unreviewed/2025/01/GHSA-6qmq-j47c-v4fj/GHSA-6qmq-j47c-v4fj.json index 4a93fc44372..18f367025be 100644 --- a/advisories/unreviewed/2025/01/GHSA-6qmq-j47c-v4fj/GHSA-6qmq-j47c-v4fj.json +++ b/advisories/unreviewed/2025/01/GHSA-6qmq-j47c-v4fj/GHSA-6qmq-j47c-v4fj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6qmq-j47c-v4fj", - "modified": "2025-01-13T06:30:25Z", + "modified": "2025-01-13T15:30:49Z", "published": "2025-01-13T06:30:25Z", "aliases": [ "CVE-2024-12568" ], "details": "The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Workflow settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-13T06:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7jhp-8mw7-9mrw/GHSA-7jhp-8mw7-9mrw.json b/advisories/unreviewed/2025/01/GHSA-7jhp-8mw7-9mrw/GHSA-7jhp-8mw7-9mrw.json new file mode 100644 index 00000000000..de295609e09 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7jhp-8mw7-9mrw/GHSA-7jhp-8mw7-9mrw.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jhp-8mw7-9mrw", + "modified": "2025-01-13T15:30:49Z", + "published": "2025-01-13T15:30:49Z", + "aliases": [ + "CVE-2025-22828" + ], + "details": "CloudStack users can add and read comments (annotations) on resources they are authorised to access. \n\nDue to an access validation issue that affects Apache CloudStack versions from 4.16.0, users who have access, prior access or knowledge of resource UUIDs can list and add comments (annotations) to such resources. \n\nAn attacker with a user-account and access or prior knowledge of resource UUIDs may exploit this issue to read contents of the comments (annotations) or add malicious comments (annotations) to such resources. \n\nThis may cause potential loss of confidentiality of CloudStack environments and resources if the comments (annotations) contain any privileged information. However, guessing or brute-forcing resource UUIDs are generally hard to impossible and access to listing or adding comments isn't same as access to CloudStack resources, making this issue of very low severity and general low impact.\n\n\nCloudStack admins may also disallow listAnnotations and addAnnotation API access to non-admin roles in their environment as an interim measure.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22828" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/bbsm9fdwrgfyostzojh6ghpocgdmx8rs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T13:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7mwr-cp39-gfrr/GHSA-7mwr-cp39-gfrr.json b/advisories/unreviewed/2025/01/GHSA-7mwr-cp39-gfrr/GHSA-7mwr-cp39-gfrr.json new file mode 100644 index 00000000000..a1421fab2de --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7mwr-cp39-gfrr/GHSA-7mwr-cp39-gfrr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mwr-cp39-gfrr", + "modified": "2025-01-13T15:30:50Z", + "published": "2025-01-13T15:30:50Z", + "aliases": [ + "CVE-2025-22576" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Downing Site PIN allows Reflected XSS.This issue affects Site PIN: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22576" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/site-pin/vulnerability/wordpress-site-pin-plugin-1-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7wr4-3xj4-r25x/GHSA-7wr4-3xj4-r25x.json b/advisories/unreviewed/2025/01/GHSA-7wr4-3xj4-r25x/GHSA-7wr4-3xj4-r25x.json new file mode 100644 index 00000000000..c16286fb41e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7wr4-3xj4-r25x/GHSA-7wr4-3xj4-r25x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wr4-3xj4-r25x", + "modified": "2025-01-13T15:30:50Z", + "published": "2025-01-13T15:30:50Z", + "aliases": [ + "CVE-2025-22586" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Detlef Stöver WPEX Replace DB Urls allows Reflected XSS.This issue affects WPEX Replace DB Urls: from n/a through 0.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22586" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpex-replace/vulnerability/wordpress-wpex-replace-db-urls-plugin-0-4-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-89c7-pc4g-j258/GHSA-89c7-pc4g-j258.json b/advisories/unreviewed/2025/01/GHSA-89c7-pc4g-j258/GHSA-89c7-pc4g-j258.json new file mode 100644 index 00000000000..d4739e45dd0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-89c7-pc4g-j258/GHSA-89c7-pc4g-j258.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89c7-pc4g-j258", + "modified": "2025-01-13T15:30:50Z", + "published": "2025-01-13T15:30:50Z", + "aliases": [ + "CVE-2024-52333" + ], + "details": "An improper array index validation vulnerability exists in the determineMinMax functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52333" + }, + { + "type": "WEB", + "url": "https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=03e851b0586d05057c3268988e180ffb426b2e03" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-2121" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8wq5-f766-wx2w/GHSA-8wq5-f766-wx2w.json b/advisories/unreviewed/2025/01/GHSA-8wq5-f766-wx2w/GHSA-8wq5-f766-wx2w.json new file mode 100644 index 00000000000..7ade87ae017 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8wq5-f766-wx2w/GHSA-8wq5-f766-wx2w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wq5-f766-wx2w", + "modified": "2025-01-13T15:30:49Z", + "published": "2025-01-13T15:30:49Z", + "aliases": [ + "CVE-2025-22337" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infosoft Consultant Order Audit Log for WooCommerce allows Reflected XSS.This issue affects Order Audit Log for WooCommerce: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22337" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/order-audit-log-for-woocommerce/vulnerability/wordpress-order-audit-log-for-woocommerce-plugin-2-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9hh8-pv8q-9qj8/GHSA-9hh8-pv8q-9qj8.json b/advisories/unreviewed/2025/01/GHSA-9hh8-pv8q-9qj8/GHSA-9hh8-pv8q-9qj8.json new file mode 100644 index 00000000000..4610ccbc311 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9hh8-pv8q-9qj8/GHSA-9hh8-pv8q-9qj8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hh8-pv8q-9qj8", + "modified": "2025-01-13T15:30:49Z", + "published": "2025-01-13T15:30:49Z", + "aliases": [ + "CVE-2025-22498" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in New Normal LLC LucidLMS allows Reflected XSS.This issue affects LucidLMS: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22498" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/lucidlms/vulnerability/wordpress-lucidlms-plugin-1-0-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cm3g-7qfv-7cxg/GHSA-cm3g-7qfv-7cxg.json b/advisories/unreviewed/2025/01/GHSA-cm3g-7qfv-7cxg/GHSA-cm3g-7qfv-7cxg.json new file mode 100644 index 00000000000..43129b116df --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cm3g-7qfv-7cxg/GHSA-cm3g-7qfv-7cxg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cm3g-7qfv-7cxg", + "modified": "2025-01-13T15:30:50Z", + "published": "2025-01-13T15:30:50Z", + "aliases": [ + "CVE-2025-22569" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in grandslambert Featured Page Widget allows Reflected XSS.This issue affects Featured Page Widget: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22569" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/featured-page-widget/vulnerability/wordpress-featured-page-widget-plugin-2-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cw8x-p7hf-968r/GHSA-cw8x-p7hf-968r.json b/advisories/unreviewed/2025/01/GHSA-cw8x-p7hf-968r/GHSA-cw8x-p7hf-968r.json index 18c58b8789e..de365a85b5b 100644 --- a/advisories/unreviewed/2025/01/GHSA-cw8x-p7hf-968r/GHSA-cw8x-p7hf-968r.json +++ b/advisories/unreviewed/2025/01/GHSA-cw8x-p7hf-968r/GHSA-cw8x-p7hf-968r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cw8x-p7hf-968r", - "modified": "2025-01-13T06:30:25Z", + "modified": "2025-01-13T15:30:49Z", "published": "2025-01-13T06:30:25Z", "aliases": [ "CVE-2024-12566" ], "details": "The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-13T06:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-fvwm-q99j-g85v/GHSA-fvwm-q99j-g85v.json b/advisories/unreviewed/2025/01/GHSA-fvwm-q99j-g85v/GHSA-fvwm-q99j-g85v.json new file mode 100644 index 00000000000..8bd30b4c782 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fvwm-q99j-g85v/GHSA-fvwm-q99j-g85v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvwm-q99j-g85v", + "modified": "2025-01-13T15:30:50Z", + "published": "2025-01-13T15:30:50Z", + "aliases": [ + "CVE-2025-22506" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SmartAgenda Smart Agenda allows Stored XSS.This issue affects Smart Agenda: from n/a through 4.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22506" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/smart-agenda-prise-de-rendez-vous-en-ligne/vulnerability/wordpress-smart-agenda-plugin-4-7-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-grjf-8q2x-rwg3/GHSA-grjf-8q2x-rwg3.json b/advisories/unreviewed/2025/01/GHSA-grjf-8q2x-rwg3/GHSA-grjf-8q2x-rwg3.json new file mode 100644 index 00000000000..61db65aff09 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-grjf-8q2x-rwg3/GHSA-grjf-8q2x-rwg3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grjf-8q2x-rwg3", + "modified": "2025-01-13T15:30:50Z", + "published": "2025-01-13T15:30:50Z", + "aliases": [ + "CVE-2025-22499" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FAKTOR VIER F4 Post Tree allows Reflected XSS.This issue affects F4 Post Tree: from n/a through 1.1.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22499" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/f4-tree/vulnerability/wordpress-f4-post-tree-plugin-1-1-18-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h6pf-2cgw-xppm/GHSA-h6pf-2cgw-xppm.json b/advisories/unreviewed/2025/01/GHSA-h6pf-2cgw-xppm/GHSA-h6pf-2cgw-xppm.json new file mode 100644 index 00000000000..d0b9f6289e4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h6pf-2cgw-xppm/GHSA-h6pf-2cgw-xppm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6pf-2cgw-xppm", + "modified": "2025-01-13T15:30:50Z", + "published": "2025-01-13T15:30:50Z", + "aliases": [ + "CVE-2025-22777" + ], + "details": "Deserialization of Untrusted Data vulnerability in GiveWP GiveWP allows Object Injection.This issue affects GiveWP: from n/a through 3.19.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22777" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-givewp-plugin-3-19-3-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hj67-jpc7-m6mm/GHSA-hj67-jpc7-m6mm.json b/advisories/unreviewed/2025/01/GHSA-hj67-jpc7-m6mm/GHSA-hj67-jpc7-m6mm.json new file mode 100644 index 00000000000..2819745df78 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hj67-jpc7-m6mm/GHSA-hj67-jpc7-m6mm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj67-jpc7-m6mm", + "modified": "2025-01-13T15:30:49Z", + "published": "2025-01-13T15:30:49Z", + "aliases": [ + "CVE-2025-22344" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Convoy Media Category Library allows Reflected XSS.This issue affects Media Category Library: from n/a through 2.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22344" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/media-category-library/vulnerability/wordpress-media-category-library-plugin-2-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hp45-vh86-p77g/GHSA-hp45-vh86-p77g.json b/advisories/unreviewed/2025/01/GHSA-hp45-vh86-p77g/GHSA-hp45-vh86-p77g.json new file mode 100644 index 00000000000..a8ef57f45e7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hp45-vh86-p77g/GHSA-hp45-vh86-p77g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp45-vh86-p77g", + "modified": "2025-01-13T15:30:50Z", + "published": "2025-01-13T15:30:50Z", + "aliases": [ + "CVE-2025-22570" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Miloš Đekić Inline Tweets allows Stored XSS.This issue affects Inline Tweets: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22570" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/inline-tweets/vulnerability/wordpress-inline-tweets-plugin-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hpcp-qr34-rj6h/GHSA-hpcp-qr34-rj6h.json b/advisories/unreviewed/2025/01/GHSA-hpcp-qr34-rj6h/GHSA-hpcp-qr34-rj6h.json index dc95dedcabe..35855d511d9 100644 --- a/advisories/unreviewed/2025/01/GHSA-hpcp-qr34-rj6h/GHSA-hpcp-qr34-rj6h.json +++ b/advisories/unreviewed/2025/01/GHSA-hpcp-qr34-rj6h/GHSA-hpcp-qr34-rj6h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hpcp-qr34-rj6h", - "modified": "2025-01-13T06:30:25Z", + "modified": "2025-01-13T15:30:49Z", "published": "2025-01-13T06:30:25Z", "aliases": [ "CVE-2024-11636" ], "details": "The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Text Block options, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-13T06:15:08Z" diff --git a/advisories/unreviewed/2025/01/GHSA-j5m8-gxw9-4wjf/GHSA-j5m8-gxw9-4wjf.json b/advisories/unreviewed/2025/01/GHSA-j5m8-gxw9-4wjf/GHSA-j5m8-gxw9-4wjf.json new file mode 100644 index 00000000000..9cfb111f42e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j5m8-gxw9-4wjf/GHSA-j5m8-gxw9-4wjf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5m8-gxw9-4wjf", + "modified": "2025-01-13T15:30:50Z", + "published": "2025-01-13T15:30:50Z", + "aliases": [ + "CVE-2025-22588" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scanventory.net Scanventory allows Reflected XSS.This issue affects Scanventory: from n/a through 1.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22588" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-inventory-management/vulnerability/wordpress-scanventory-plugin-1-1-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mr89-55m9-528m/GHSA-mr89-55m9-528m.json b/advisories/unreviewed/2025/01/GHSA-mr89-55m9-528m/GHSA-mr89-55m9-528m.json new file mode 100644 index 00000000000..5fa64c342f6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mr89-55m9-528m/GHSA-mr89-55m9-528m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr89-55m9-528m", + "modified": "2025-01-13T15:30:50Z", + "published": "2025-01-13T15:30:50Z", + "aliases": [ + "CVE-2025-22583" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anshul Sojatia Scan External Links allows Reflected XSS.This issue affects Scan External Links: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22583" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/scan-external-links/vulnerability/wordpress-scan-external-links-plugin-1-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pqrv-f5cf-p9gq/GHSA-pqrv-f5cf-p9gq.json b/advisories/unreviewed/2025/01/GHSA-pqrv-f5cf-p9gq/GHSA-pqrv-f5cf-p9gq.json new file mode 100644 index 00000000000..172f265972e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pqrv-f5cf-p9gq/GHSA-pqrv-f5cf-p9gq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqrv-f5cf-p9gq", + "modified": "2025-01-13T15:30:50Z", + "published": "2025-01-13T15:30:50Z", + "aliases": [ + "CVE-2025-22568" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paramveer Singh for Arete IT Private Limited Post And Page Reactions allows Reflected XSS.This issue affects Post And Page Reactions: from n/a through 1.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22568" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/post-and-page-reactions/vulnerability/wordpress-post-and-page-reactions-plugin-1-0-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T14:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pw9j-qgmc-g62h/GHSA-pw9j-qgmc-g62h.json b/advisories/unreviewed/2025/01/GHSA-pw9j-qgmc-g62h/GHSA-pw9j-qgmc-g62h.json index 00420cfbe4a..ab71dde9bec 100644 --- a/advisories/unreviewed/2025/01/GHSA-pw9j-qgmc-g62h/GHSA-pw9j-qgmc-g62h.json +++ b/advisories/unreviewed/2025/01/GHSA-pw9j-qgmc-g62h/GHSA-pw9j-qgmc-g62h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pw9j-qgmc-g62h", - "modified": "2025-01-13T06:30:25Z", + "modified": "2025-01-13T15:30:49Z", "published": "2025-01-13T06:30:25Z", "aliases": [ "CVE-2024-12274" ], "details": "The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.1.23 export settings functionality exports data to a public folder, with an easily guessable file name, allowing unauthenticated attackers to access the exported files (if they exist).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-13T06:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-r7m8-pv7c-r2ph/GHSA-r7m8-pv7c-r2ph.json b/advisories/unreviewed/2025/01/GHSA-r7m8-pv7c-r2ph/GHSA-r7m8-pv7c-r2ph.json index c9add686ab6..c4462eec41a 100644 --- a/advisories/unreviewed/2025/01/GHSA-r7m8-pv7c-r2ph/GHSA-r7m8-pv7c-r2ph.json +++ b/advisories/unreviewed/2025/01/GHSA-r7m8-pv7c-r2ph/GHSA-r7m8-pv7c-r2ph.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r7m8-pv7c-r2ph", - "modified": "2025-01-13T06:30:25Z", + "modified": "2025-01-13T15:30:49Z", "published": "2025-01-13T06:30:25Z", "aliases": [ "CVE-2024-12567" ], "details": "The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-13T06:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-rmhw-74f4-6h32/GHSA-rmhw-74f4-6h32.json b/advisories/unreviewed/2025/01/GHSA-rmhw-74f4-6h32/GHSA-rmhw-74f4-6h32.json new file mode 100644 index 00000000000..055242af529 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rmhw-74f4-6h32/GHSA-rmhw-74f4-6h32.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmhw-74f4-6h32", + "modified": "2025-01-13T15:30:49Z", + "published": "2025-01-13T15:30:49Z", + "aliases": [ + "CVE-2024-56065" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder.biz Team WP2LEADS allows Reflected XSS.This issue affects WP2LEADS: from n/a through 3.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56065" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp2leads/vulnerability/wordpress-wp2leads-plugin-3-4-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vpm9-4h47-6p73/GHSA-vpm9-4h47-6p73.json b/advisories/unreviewed/2025/01/GHSA-vpm9-4h47-6p73/GHSA-vpm9-4h47-6p73.json new file mode 100644 index 00000000000..ee4440d544b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vpm9-4h47-6p73/GHSA-vpm9-4h47-6p73.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpm9-4h47-6p73", + "modified": "2025-01-13T15:30:49Z", + "published": "2025-01-13T15:30:49Z", + "aliases": [ + "CVE-2025-22314" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Scripts Food Store – Online Food Delivery & Pickup allows Reflected XSS.This issue affects Food Store – Online Food Delivery & Pickup: from n/a through 1.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22314" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/food-store/vulnerability/wordpress-food-store-plugin-1-5-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T14:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vvfx-pqjc-f597/GHSA-vvfx-pqjc-f597.json b/advisories/unreviewed/2025/01/GHSA-vvfx-pqjc-f597/GHSA-vvfx-pqjc-f597.json new file mode 100644 index 00000000000..830bfd8ad09 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vvfx-pqjc-f597/GHSA-vvfx-pqjc-f597.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvfx-pqjc-f597", + "modified": "2025-01-13T15:30:49Z", + "published": "2025-01-13T15:30:49Z", + "aliases": [ + "CVE-2024-56301" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eniture Technology Distance Based Shipping Calculator allows Reflected XSS.This issue affects Distance Based Shipping Calculator: from n/a through 2.0.21.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56301" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/distance-based-shipping-calculator/vulnerability/wordpress-distance-based-shipping-calculator-plugin-2-0-21-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x46g-g77r-3g5c/GHSA-x46g-g77r-3g5c.json b/advisories/unreviewed/2025/01/GHSA-x46g-g77r-3g5c/GHSA-x46g-g77r-3g5c.json new file mode 100644 index 00000000000..8365e1aa24f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x46g-g77r-3g5c/GHSA-x46g-g77r-3g5c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x46g-g77r-3g5c", + "modified": "2025-01-13T15:30:50Z", + "published": "2025-01-13T15:30:50Z", + "aliases": [ + "CVE-2025-22514" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yamna Tatheer KNR Author List Widget allows Reflected XSS.This issue affects KNR Author List Widget: from n/a through 3.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22514" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/knr-author-list-widget/vulnerability/wordpress-axact-author-list-widget-plugin-3-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-13T14:15:11Z" + } +} \ No newline at end of file