diff --git a/advisories/unreviewed/2022/09/GHSA-7qqr-wwjq-98v6/GHSA-7qqr-wwjq-98v6.json b/advisories/unreviewed/2022/09/GHSA-7qqr-wwjq-98v6/GHSA-7qqr-wwjq-98v6.json index 51aa0e6ded8..080dd5f429c 100644 --- a/advisories/unreviewed/2022/09/GHSA-7qqr-wwjq-98v6/GHSA-7qqr-wwjq-98v6.json +++ b/advisories/unreviewed/2022/09/GHSA-7qqr-wwjq-98v6/GHSA-7qqr-wwjq-98v6.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-256", "CWE-552" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/09/GHSA-ww6v-6x26-hgfc/GHSA-ww6v-6x26-hgfc.json b/advisories/unreviewed/2022/09/GHSA-ww6v-6x26-hgfc/GHSA-ww6v-6x26-hgfc.json index 9c3e6a81083..b0912b65747 100644 --- a/advisories/unreviewed/2022/09/GHSA-ww6v-6x26-hgfc/GHSA-ww6v-6x26-hgfc.json +++ b/advisories/unreviewed/2022/09/GHSA-ww6v-6x26-hgfc/GHSA-ww6v-6x26-hgfc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ww6v-6x26-hgfc", - "modified": "2022-10-04T00:00:19Z", + "modified": "2025-05-20T21:30:26Z", "published": "2022-09-30T00:00:47Z", "aliases": [ "CVE-2022-39173" @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/10/GHSA-7p78-28rx-wm6c/GHSA-7p78-28rx-wm6c.json b/advisories/unreviewed/2022/10/GHSA-7p78-28rx-wm6c/GHSA-7p78-28rx-wm6c.json index b0fc8e29edd..139b1035086 100644 --- a/advisories/unreviewed/2022/10/GHSA-7p78-28rx-wm6c/GHSA-7p78-28rx-wm6c.json +++ b/advisories/unreviewed/2022/10/GHSA-7p78-28rx-wm6c/GHSA-7p78-28rx-wm6c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7p78-28rx-wm6c", - "modified": "2022-10-05T00:00:39Z", + "modified": "2025-05-20T21:30:27Z", "published": "2022-10-01T00:00:21Z", "aliases": [ "CVE-2022-37461" diff --git a/advisories/unreviewed/2022/10/GHSA-h43g-m94v-wfpv/GHSA-h43g-m94v-wfpv.json b/advisories/unreviewed/2022/10/GHSA-h43g-m94v-wfpv/GHSA-h43g-m94v-wfpv.json index c70912f2912..4d88b2f2fb3 100644 --- a/advisories/unreviewed/2022/10/GHSA-h43g-m94v-wfpv/GHSA-h43g-m94v-wfpv.json +++ b/advisories/unreviewed/2022/10/GHSA-h43g-m94v-wfpv/GHSA-h43g-m94v-wfpv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h43g-m94v-wfpv", - "modified": "2022-10-05T00:00:39Z", + "modified": "2025-05-20T21:30:27Z", "published": "2022-10-01T00:00:25Z", "aliases": [ "CVE-2022-41848" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/log/drivers/char/pcmcia/synclink_cs.c" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/lkml/20220919040251.GA302541%40ubuntu/T/#rc85e751f467b3e6f9ccef92cfa7fb8a6cc50c270" + }, { "type": "WEB", "url": "https://lore.kernel.org/lkml/20220919040251.GA302541@ubuntu/T/#rc85e751f467b3e6f9ccef92cfa7fb8a6cc50c270" diff --git a/advisories/unreviewed/2022/10/GHSA-hvjm-8776-hw2q/GHSA-hvjm-8776-hw2q.json b/advisories/unreviewed/2022/10/GHSA-hvjm-8776-hw2q/GHSA-hvjm-8776-hw2q.json index b50db407ddb..ac80287089f 100644 --- a/advisories/unreviewed/2022/10/GHSA-hvjm-8776-hw2q/GHSA-hvjm-8776-hw2q.json +++ b/advisories/unreviewed/2022/10/GHSA-hvjm-8776-hw2q/GHSA-hvjm-8776-hw2q.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/10/GHSA-jg3v-79gc-572m/GHSA-jg3v-79gc-572m.json b/advisories/unreviewed/2022/10/GHSA-jg3v-79gc-572m/GHSA-jg3v-79gc-572m.json index f7b2ff9a719..f7e3f17009a 100644 --- a/advisories/unreviewed/2022/10/GHSA-jg3v-79gc-572m/GHSA-jg3v-79gc-572m.json +++ b/advisories/unreviewed/2022/10/GHSA-jg3v-79gc-572m/GHSA-jg3v-79gc-572m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jg3v-79gc-572m", - "modified": "2022-10-05T00:00:37Z", + "modified": "2025-05-20T21:30:28Z", "published": "2022-10-01T00:00:20Z", "aliases": [ "CVE-2022-1959" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-vpc9-mjhw-r32h/GHSA-vpc9-mjhw-r32h.json b/advisories/unreviewed/2022/10/GHSA-vpc9-mjhw-r32h/GHSA-vpc9-mjhw-r32h.json index 567a3470741..d20368d3ee4 100644 --- a/advisories/unreviewed/2022/10/GHSA-vpc9-mjhw-r32h/GHSA-vpc9-mjhw-r32h.json +++ b/advisories/unreviewed/2022/10/GHSA-vpc9-mjhw-r32h/GHSA-vpc9-mjhw-r32h.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/10/GHSA-wpjq-v255-668c/GHSA-wpjq-v255-668c.json b/advisories/unreviewed/2022/10/GHSA-wpjq-v255-668c/GHSA-wpjq-v255-668c.json index 4cf711fd49b..f4a2d531b63 100644 --- a/advisories/unreviewed/2022/10/GHSA-wpjq-v255-668c/GHSA-wpjq-v255-668c.json +++ b/advisories/unreviewed/2022/10/GHSA-wpjq-v255-668c/GHSA-wpjq-v255-668c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wpjq-v255-668c", - "modified": "2022-10-05T00:00:38Z", + "modified": "2025-05-20T21:30:28Z", "published": "2022-10-01T00:00:20Z", "aliases": [ "CVE-2022-40274" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/10/GHSA-xh2c-fh83-6hgx/GHSA-xh2c-fh83-6hgx.json b/advisories/unreviewed/2022/10/GHSA-xh2c-fh83-6hgx/GHSA-xh2c-fh83-6hgx.json index 60a2a6f75f6..12da4f53951 100644 --- a/advisories/unreviewed/2022/10/GHSA-xh2c-fh83-6hgx/GHSA-xh2c-fh83-6hgx.json +++ b/advisories/unreviewed/2022/10/GHSA-xh2c-fh83-6hgx/GHSA-xh2c-fh83-6hgx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xh2c-fh83-6hgx", - "modified": "2022-10-05T00:00:38Z", + "modified": "2025-05-20T21:30:26Z", "published": "2022-10-01T00:00:25Z", "aliases": [ "CVE-2022-2778" diff --git a/advisories/unreviewed/2023/01/GHSA-j754-rjhq-mj6j/GHSA-j754-rjhq-mj6j.json b/advisories/unreviewed/2023/01/GHSA-j754-rjhq-mj6j/GHSA-j754-rjhq-mj6j.json index 9c08297ac24..99b179ebede 100644 --- a/advisories/unreviewed/2023/01/GHSA-j754-rjhq-mj6j/GHSA-j754-rjhq-mj6j.json +++ b/advisories/unreviewed/2023/01/GHSA-j754-rjhq-mj6j/GHSA-j754-rjhq-mj6j.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-321", "CWE-798" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/01/GHSA-xcff-26c4-66wg/GHSA-xcff-26c4-66wg.json b/advisories/unreviewed/2023/01/GHSA-xcff-26c4-66wg/GHSA-xcff-26c4-66wg.json index 839272e9816..191e94022ab 100644 --- a/advisories/unreviewed/2023/01/GHSA-xcff-26c4-66wg/GHSA-xcff-26c4-66wg.json +++ b/advisories/unreviewed/2023/01/GHSA-xcff-26c4-66wg/GHSA-xcff-26c4-66wg.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-321", "CWE-798" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/01/GHSA-xjj6-f689-gwr9/GHSA-xjj6-f689-gwr9.json b/advisories/unreviewed/2023/01/GHSA-xjj6-f689-gwr9/GHSA-xjj6-f689-gwr9.json index a5efa88a553..0b6055bd236 100644 --- a/advisories/unreviewed/2023/01/GHSA-xjj6-f689-gwr9/GHSA-xjj6-f689-gwr9.json +++ b/advisories/unreviewed/2023/01/GHSA-xjj6-f689-gwr9/GHSA-xjj6-f689-gwr9.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-321", "CWE-798" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/01/GHSA-xwch-5xjc-3j47/GHSA-xwch-5xjc-3j47.json b/advisories/unreviewed/2023/01/GHSA-xwch-5xjc-3j47/GHSA-xwch-5xjc-3j47.json index 7f9627d0e77..95bcdc32a56 100644 --- a/advisories/unreviewed/2023/01/GHSA-xwch-5xjc-3j47/GHSA-xwch-5xjc-3j47.json +++ b/advisories/unreviewed/2023/01/GHSA-xwch-5xjc-3j47/GHSA-xwch-5xjc-3j47.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-321", "CWE-798" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2025/02/GHSA-4q44-89v6-r47v/GHSA-4q44-89v6-r47v.json b/advisories/unreviewed/2025/02/GHSA-4q44-89v6-r47v/GHSA-4q44-89v6-r47v.json index bb8582f1e66..3c90bfa36f7 100644 --- a/advisories/unreviewed/2025/02/GHSA-4q44-89v6-r47v/GHSA-4q44-89v6-r47v.json +++ b/advisories/unreviewed/2025/02/GHSA-4q44-89v6-r47v/GHSA-4q44-89v6-r47v.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-mrrm-jfxh-4cwj/GHSA-mrrm-jfxh-4cwj.json b/advisories/unreviewed/2025/02/GHSA-mrrm-jfxh-4cwj/GHSA-mrrm-jfxh-4cwj.json index f7afab5b78a..d9f0d69d601 100644 --- a/advisories/unreviewed/2025/02/GHSA-mrrm-jfxh-4cwj/GHSA-mrrm-jfxh-4cwj.json +++ b/advisories/unreviewed/2025/02/GHSA-mrrm-jfxh-4cwj/GHSA-mrrm-jfxh-4cwj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-2377-3h83-ch9w/GHSA-2377-3h83-ch9w.json b/advisories/unreviewed/2025/05/GHSA-2377-3h83-ch9w/GHSA-2377-3h83-ch9w.json index 374b361ff61..7fbe508dec5 100644 --- a/advisories/unreviewed/2025/05/GHSA-2377-3h83-ch9w/GHSA-2377-3h83-ch9w.json +++ b/advisories/unreviewed/2025/05/GHSA-2377-3h83-ch9w/GHSA-2377-3h83-ch9w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2377-3h83-ch9w", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:36Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-12874" ], "details": "The Top Comments WordPress plugin through 1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:37Z" diff --git a/advisories/unreviewed/2025/05/GHSA-244m-98g9-4pg8/GHSA-244m-98g9-4pg8.json b/advisories/unreviewed/2025/05/GHSA-244m-98g9-4pg8/GHSA-244m-98g9-4pg8.json index 855afc14c40..f0485b0c99d 100644 --- a/advisories/unreviewed/2025/05/GHSA-244m-98g9-4pg8/GHSA-244m-98g9-4pg8.json +++ b/advisories/unreviewed/2025/05/GHSA-244m-98g9-4pg8/GHSA-244m-98g9-4pg8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-244m-98g9-4pg8", - "modified": "2025-05-15T21:31:34Z", + "modified": "2025-05-20T21:30:42Z", "published": "2025-05-15T21:31:34Z", "aliases": [ "CVE-2025-1288" ], "details": "The WOOEXIM WordPress plugin through 5.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make an unauthenticated user vulnerable to reflected XSS via a CSRF attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:16:02Z" diff --git a/advisories/unreviewed/2025/05/GHSA-28c7-hwc8-phgm/GHSA-28c7-hwc8-phgm.json b/advisories/unreviewed/2025/05/GHSA-28c7-hwc8-phgm/GHSA-28c7-hwc8-phgm.json index 41fbc8ad71b..acd3d232cd8 100644 --- a/advisories/unreviewed/2025/05/GHSA-28c7-hwc8-phgm/GHSA-28c7-hwc8-phgm.json +++ b/advisories/unreviewed/2025/05/GHSA-28c7-hwc8-phgm/GHSA-28c7-hwc8-phgm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-28c7-hwc8-phgm", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:35Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-12735" ], "details": "The Advance Post Prefix WordPress plugin through 1.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins and above to perform SQL injection attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:36Z" diff --git a/advisories/unreviewed/2025/05/GHSA-28fx-qww6-g655/GHSA-28fx-qww6-g655.json b/advisories/unreviewed/2025/05/GHSA-28fx-qww6-g655/GHSA-28fx-qww6-g655.json index c2b74d0bf39..f1b99e41139 100644 --- a/advisories/unreviewed/2025/05/GHSA-28fx-qww6-g655/GHSA-28fx-qww6-g655.json +++ b/advisories/unreviewed/2025/05/GHSA-28fx-qww6-g655/GHSA-28fx-qww6-g655.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-28fx-qww6-g655", - "modified": "2025-05-15T21:31:28Z", + "modified": "2025-05-20T21:30:32Z", "published": "2025-05-15T21:31:28Z", "aliases": [ "CVE-2024-10362" ], "details": "The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.9.1 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:33Z" diff --git a/advisories/unreviewed/2025/05/GHSA-2cw7-7rj8-j2x7/GHSA-2cw7-7rj8-j2x7.json b/advisories/unreviewed/2025/05/GHSA-2cw7-7rj8-j2x7/GHSA-2cw7-7rj8-j2x7.json index 0871e38776d..d5b9ece241d 100644 --- a/advisories/unreviewed/2025/05/GHSA-2cw7-7rj8-j2x7/GHSA-2cw7-7rj8-j2x7.json +++ b/advisories/unreviewed/2025/05/GHSA-2cw7-7rj8-j2x7/GHSA-2cw7-7rj8-j2x7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2cw7-7rj8-j2x7", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-20T21:30:40Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-8082" ], "details": "The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:57Z" diff --git a/advisories/unreviewed/2025/05/GHSA-2g6g-hhqw-63q5/GHSA-2g6g-hhqw-63q5.json b/advisories/unreviewed/2025/05/GHSA-2g6g-hhqw-63q5/GHSA-2g6g-hhqw-63q5.json index 3abda7160b0..6e980566cbb 100644 --- a/advisories/unreviewed/2025/05/GHSA-2g6g-hhqw-63q5/GHSA-2g6g-hhqw-63q5.json +++ b/advisories/unreviewed/2025/05/GHSA-2g6g-hhqw-63q5/GHSA-2g6g-hhqw-63q5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2g6g-hhqw-63q5", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:33Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-12282" ], "details": "The WordPress连接微博 WordPress plugin through 2.5.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:35Z" diff --git a/advisories/unreviewed/2025/05/GHSA-2w83-9v42-r6h5/GHSA-2w83-9v42-r6h5.json b/advisories/unreviewed/2025/05/GHSA-2w83-9v42-r6h5/GHSA-2w83-9v42-r6h5.json index 4337c98191a..c5d840117ae 100644 --- a/advisories/unreviewed/2025/05/GHSA-2w83-9v42-r6h5/GHSA-2w83-9v42-r6h5.json +++ b/advisories/unreviewed/2025/05/GHSA-2w83-9v42-r6h5/GHSA-2w83-9v42-r6h5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2w83-9v42-r6h5", - "modified": "2025-05-15T21:31:28Z", + "modified": "2025-05-20T21:30:32Z", "published": "2025-05-15T21:31:28Z", "aliases": [ "CVE-2024-10818" ], "details": "The JSFiddle Shortcode WordPress plugin before 1.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:33Z" diff --git a/advisories/unreviewed/2025/05/GHSA-3262-4hm9-mq8q/GHSA-3262-4hm9-mq8q.json b/advisories/unreviewed/2025/05/GHSA-3262-4hm9-mq8q/GHSA-3262-4hm9-mq8q.json index b3f7038d78e..d3b9e340391 100644 --- a/advisories/unreviewed/2025/05/GHSA-3262-4hm9-mq8q/GHSA-3262-4hm9-mq8q.json +++ b/advisories/unreviewed/2025/05/GHSA-3262-4hm9-mq8q/GHSA-3262-4hm9-mq8q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3262-4hm9-mq8q", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T21:30:36Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-13127" ], "details": "The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:38Z" diff --git a/advisories/unreviewed/2025/05/GHSA-32jx-cx53-vp3r/GHSA-32jx-cx53-vp3r.json b/advisories/unreviewed/2025/05/GHSA-32jx-cx53-vp3r/GHSA-32jx-cx53-vp3r.json index 90f16e05e4b..a4ee98a8412 100644 --- a/advisories/unreviewed/2025/05/GHSA-32jx-cx53-vp3r/GHSA-32jx-cx53-vp3r.json +++ b/advisories/unreviewed/2025/05/GHSA-32jx-cx53-vp3r/GHSA-32jx-cx53-vp3r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-32jx-cx53-vp3r", - "modified": "2025-05-15T21:31:28Z", + "modified": "2025-05-20T21:30:33Z", "published": "2025-05-15T21:31:28Z", "aliases": [ "CVE-2024-11373" ], "details": "The Connexion Logs WordPress plugin through 3.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:35Z" diff --git a/advisories/unreviewed/2025/05/GHSA-34x7-vxc3-qvr6/GHSA-34x7-vxc3-qvr6.json b/advisories/unreviewed/2025/05/GHSA-34x7-vxc3-qvr6/GHSA-34x7-vxc3-qvr6.json new file mode 100644 index 00000000000..c9ec1365df5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-34x7-vxc3-qvr6/GHSA-34x7-vxc3-qvr6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34x7-vxc3-qvr6", + "modified": "2025-05-20T21:30:43Z", + "published": "2025-05-20T21:30:43Z", + "aliases": [ + "CVE-2025-44891" + ], + "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_add_post function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44891" + }, + { + "type": "WEB", + "url": "https://lafdrew.github.io/2025/04/20/web-snmp-v3host-add-post-host-ip" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-352j-376q-2pmc/GHSA-352j-376q-2pmc.json b/advisories/unreviewed/2025/05/GHSA-352j-376q-2pmc/GHSA-352j-376q-2pmc.json index 0bd3a529592..1abed3f900f 100644 --- a/advisories/unreviewed/2025/05/GHSA-352j-376q-2pmc/GHSA-352j-376q-2pmc.json +++ b/advisories/unreviewed/2025/05/GHSA-352j-376q-2pmc/GHSA-352j-376q-2pmc.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-353c-hm8f-g46h/GHSA-353c-hm8f-g46h.json b/advisories/unreviewed/2025/05/GHSA-353c-hm8f-g46h/GHSA-353c-hm8f-g46h.json index 718d453a964..84ada8d5e31 100644 --- a/advisories/unreviewed/2025/05/GHSA-353c-hm8f-g46h/GHSA-353c-hm8f-g46h.json +++ b/advisories/unreviewed/2025/05/GHSA-353c-hm8f-g46h/GHSA-353c-hm8f-g46h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-353c-hm8f-g46h", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:34Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-12722" ], "details": "The Twitter Bootstrap Collapse aka Accordian Shortcode WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:36Z" diff --git a/advisories/unreviewed/2025/05/GHSA-3vx5-jr5m-gpmq/GHSA-3vx5-jr5m-gpmq.json b/advisories/unreviewed/2025/05/GHSA-3vx5-jr5m-gpmq/GHSA-3vx5-jr5m-gpmq.json index 9781bdfdf4a..c60480d4d37 100644 --- a/advisories/unreviewed/2025/05/GHSA-3vx5-jr5m-gpmq/GHSA-3vx5-jr5m-gpmq.json +++ b/advisories/unreviewed/2025/05/GHSA-3vx5-jr5m-gpmq/GHSA-3vx5-jr5m-gpmq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3vx5-jr5m-gpmq", - "modified": "2025-05-15T21:31:28Z", + "modified": "2025-05-20T21:30:33Z", "published": "2025-05-15T21:31:28Z", "aliases": [ "CVE-2024-11719" ], "details": "The tarteaucitron-wp WordPress plugin before 0.3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:35Z" diff --git a/advisories/unreviewed/2025/05/GHSA-42p9-p46j-wc9w/GHSA-42p9-p46j-wc9w.json b/advisories/unreviewed/2025/05/GHSA-42p9-p46j-wc9w/GHSA-42p9-p46j-wc9w.json index 4c43315aa04..de50eca3476 100644 --- a/advisories/unreviewed/2025/05/GHSA-42p9-p46j-wc9w/GHSA-42p9-p46j-wc9w.json +++ b/advisories/unreviewed/2025/05/GHSA-42p9-p46j-wc9w/GHSA-42p9-p46j-wc9w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-42p9-p46j-wc9w", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T21:30:37Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-13823" ], "details": "The 360 Product Rotation WordPress plugin through 1.5.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:40Z" diff --git a/advisories/unreviewed/2025/05/GHSA-448c-v79p-pvxc/GHSA-448c-v79p-pvxc.json b/advisories/unreviewed/2025/05/GHSA-448c-v79p-pvxc/GHSA-448c-v79p-pvxc.json new file mode 100644 index 00000000000..50cce63a39d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-448c-v79p-pvxc/GHSA-448c-v79p-pvxc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-448c-v79p-pvxc", + "modified": "2025-05-20T21:30:43Z", + "published": "2025-05-20T21:30:43Z", + "aliases": [ + "CVE-2025-44885" + ], + "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the remote_ip parameter in the web_snmpv3_remote_engineId_add_post function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44885" + }, + { + "type": "WEB", + "url": "https://lafdrew.github.io/2025/04/20/web-snmpv3-remote-engineId-add-post-remote-ip" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T20:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4g4f-j7gv-ph46/GHSA-4g4f-j7gv-ph46.json b/advisories/unreviewed/2025/05/GHSA-4g4f-j7gv-ph46/GHSA-4g4f-j7gv-ph46.json index 7b020024f4a..46e5a328662 100644 --- a/advisories/unreviewed/2025/05/GHSA-4g4f-j7gv-ph46/GHSA-4g4f-j7gv-ph46.json +++ b/advisories/unreviewed/2025/05/GHSA-4g4f-j7gv-ph46/GHSA-4g4f-j7gv-ph46.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4g4f-j7gv-ph46", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:35Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-12733" ], "details": "The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:36Z" diff --git a/advisories/unreviewed/2025/05/GHSA-4gr5-vxg2-5c62/GHSA-4gr5-vxg2-5c62.json b/advisories/unreviewed/2025/05/GHSA-4gr5-vxg2-5c62/GHSA-4gr5-vxg2-5c62.json index f2817df0036..c94e6e24ea9 100644 --- a/advisories/unreviewed/2025/05/GHSA-4gr5-vxg2-5c62/GHSA-4gr5-vxg2-5c62.json +++ b/advisories/unreviewed/2025/05/GHSA-4gr5-vxg2-5c62/GHSA-4gr5-vxg2-5c62.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4gr5-vxg2-5c62", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:34Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-12716" ], "details": "The Simple Basic Contact Form WordPress plugin before 20250114 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:36Z" diff --git a/advisories/unreviewed/2025/05/GHSA-4rxh-wp98-c3j4/GHSA-4rxh-wp98-c3j4.json b/advisories/unreviewed/2025/05/GHSA-4rxh-wp98-c3j4/GHSA-4rxh-wp98-c3j4.json new file mode 100644 index 00000000000..16d149d0438 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4rxh-wp98-c3j4/GHSA-4rxh-wp98-c3j4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rxh-wp98-c3j4", + "modified": "2025-05-20T21:30:31Z", + "published": "2025-05-20T21:30:31Z", + "aliases": [ + "CVE-2024-13629" + ], + "details": "The pushBIZ WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13629" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/5ffb548c-14f1-499d-8bbf-6ecc632cbb8c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4v78-7jx6-mhrg/GHSA-4v78-7jx6-mhrg.json b/advisories/unreviewed/2025/05/GHSA-4v78-7jx6-mhrg/GHSA-4v78-7jx6-mhrg.json index 5a9a8a1d199..ddf0a5e8a9d 100644 --- a/advisories/unreviewed/2025/05/GHSA-4v78-7jx6-mhrg/GHSA-4v78-7jx6-mhrg.json +++ b/advisories/unreviewed/2025/05/GHSA-4v78-7jx6-mhrg/GHSA-4v78-7jx6-mhrg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4v78-7jx6-mhrg", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:32Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-11267" ], "details": "The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with Contributor to perform SQL injection attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:34Z" diff --git a/advisories/unreviewed/2025/05/GHSA-4wqv-9447-79rg/GHSA-4wqv-9447-79rg.json b/advisories/unreviewed/2025/05/GHSA-4wqv-9447-79rg/GHSA-4wqv-9447-79rg.json new file mode 100644 index 00000000000..a69e147ffaf --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4wqv-9447-79rg/GHSA-4wqv-9447-79rg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wqv-9447-79rg", + "modified": "2025-05-20T21:30:43Z", + "published": "2025-05-20T21:30:43Z", + "aliases": [ + "CVE-2025-44882" + ], + "details": "A command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44882" + }, + { + "type": "WEB", + "url": "https://lafdrew.github.io/2025/03/31/Remote-Command-Execution-in-firewall-cgi-of-wavlink-WL-WN579A3-Device" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4x2h-w98x-4p25/GHSA-4x2h-w98x-4p25.json b/advisories/unreviewed/2025/05/GHSA-4x2h-w98x-4p25/GHSA-4x2h-w98x-4p25.json index 6a0993f1d02..d55d37891f2 100644 --- a/advisories/unreviewed/2025/05/GHSA-4x2h-w98x-4p25/GHSA-4x2h-w98x-4p25.json +++ b/advisories/unreviewed/2025/05/GHSA-4x2h-w98x-4p25/GHSA-4x2h-w98x-4p25.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4x2h-w98x-4p25", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:36Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-12873" ], "details": "The Custom Field Manager WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:37Z" diff --git a/advisories/unreviewed/2025/05/GHSA-559f-7rvx-wm9p/GHSA-559f-7rvx-wm9p.json b/advisories/unreviewed/2025/05/GHSA-559f-7rvx-wm9p/GHSA-559f-7rvx-wm9p.json index 4d8be00bf8f..c09bc27c6f6 100644 --- a/advisories/unreviewed/2025/05/GHSA-559f-7rvx-wm9p/GHSA-559f-7rvx-wm9p.json +++ b/advisories/unreviewed/2025/05/GHSA-559f-7rvx-wm9p/GHSA-559f-7rvx-wm9p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-559f-7rvx-wm9p", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-20T21:30:38Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-5440" ], "details": "The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:54Z" diff --git a/advisories/unreviewed/2025/05/GHSA-5hhg-f58g-x5j3/GHSA-5hhg-f58g-x5j3.json b/advisories/unreviewed/2025/05/GHSA-5hhg-f58g-x5j3/GHSA-5hhg-f58g-x5j3.json new file mode 100644 index 00000000000..b783c263113 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5hhg-f58g-x5j3/GHSA-5hhg-f58g-x5j3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hhg-f58g-x5j3", + "modified": "2025-05-20T21:30:43Z", + "published": "2025-05-20T21:30:43Z", + "aliases": [ + "CVE-2025-44894" + ], + "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radDftParamKey parameter in the web_radiusSrv_dftParam_post function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44894" + }, + { + "type": "WEB", + "url": "https://lafdrew.github.io/2025/04/20/web-radiusSrv-dftParam-post-radDftParamKey" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5qff-4269-vc22/GHSA-5qff-4269-vc22.json b/advisories/unreviewed/2025/05/GHSA-5qff-4269-vc22/GHSA-5qff-4269-vc22.json index 77cd4cc3583..c7f5ba62e76 100644 --- a/advisories/unreviewed/2025/05/GHSA-5qff-4269-vc22/GHSA-5qff-4269-vc22.json +++ b/advisories/unreviewed/2025/05/GHSA-5qff-4269-vc22/GHSA-5qff-4269-vc22.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5qff-4269-vc22", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:35Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-12770" ], "details": "The WP ULike WordPress plugin before 4.7.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:37Z" diff --git a/advisories/unreviewed/2025/05/GHSA-62xj-j866-fwp8/GHSA-62xj-j866-fwp8.json b/advisories/unreviewed/2025/05/GHSA-62xj-j866-fwp8/GHSA-62xj-j866-fwp8.json index 4fe8018f90f..9c4ff4139b5 100644 --- a/advisories/unreviewed/2025/05/GHSA-62xj-j866-fwp8/GHSA-62xj-j866-fwp8.json +++ b/advisories/unreviewed/2025/05/GHSA-62xj-j866-fwp8/GHSA-62xj-j866-fwp8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-62xj-j866-fwp8", - "modified": "2025-05-15T21:31:28Z", + "modified": "2025-05-20T21:30:33Z", "published": "2025-05-15T21:31:28Z", "aliases": [ "CVE-2024-11843" ], "details": "The Panorama WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:35Z" diff --git a/advisories/unreviewed/2025/05/GHSA-63hr-jqx6-r6hw/GHSA-63hr-jqx6-r6hw.json b/advisories/unreviewed/2025/05/GHSA-63hr-jqx6-r6hw/GHSA-63hr-jqx6-r6hw.json index 5ac7a484727..88e40c676af 100644 --- a/advisories/unreviewed/2025/05/GHSA-63hr-jqx6-r6hw/GHSA-63hr-jqx6-r6hw.json +++ b/advisories/unreviewed/2025/05/GHSA-63hr-jqx6-r6hw/GHSA-63hr-jqx6-r6hw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-63hr-jqx6-r6hw", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T21:30:37Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-13729" ], "details": "The Podlove Podcast Publisher WordPress plugin before 4.1.24 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:39Z" diff --git a/advisories/unreviewed/2025/05/GHSA-6545-29c2-j2r5/GHSA-6545-29c2-j2r5.json b/advisories/unreviewed/2025/05/GHSA-6545-29c2-j2r5/GHSA-6545-29c2-j2r5.json index e8a013c7bc3..57b5b0afcc0 100644 --- a/advisories/unreviewed/2025/05/GHSA-6545-29c2-j2r5/GHSA-6545-29c2-j2r5.json +++ b/advisories/unreviewed/2025/05/GHSA-6545-29c2-j2r5/GHSA-6545-29c2-j2r5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6545-29c2-j2r5", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:36Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-13313" ], "details": "The AWeber WordPress plugin through 7.3.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:38Z" diff --git a/advisories/unreviewed/2025/05/GHSA-69xj-9qh4-v9hv/GHSA-69xj-9qh4-v9hv.json b/advisories/unreviewed/2025/05/GHSA-69xj-9qh4-v9hv/GHSA-69xj-9qh4-v9hv.json index 0744b12d432..dbc42caa27e 100644 --- a/advisories/unreviewed/2025/05/GHSA-69xj-9qh4-v9hv/GHSA-69xj-9qh4-v9hv.json +++ b/advisories/unreviewed/2025/05/GHSA-69xj-9qh4-v9hv/GHSA-69xj-9qh4-v9hv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-69xj-9qh4-v9hv", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:34Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-12725" ], "details": "The Clasify Classified Listing WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:36Z" diff --git a/advisories/unreviewed/2025/05/GHSA-6vhr-vrr2-gfrx/GHSA-6vhr-vrr2-gfrx.json b/advisories/unreviewed/2025/05/GHSA-6vhr-vrr2-gfrx/GHSA-6vhr-vrr2-gfrx.json index 01708068ac7..0014a2693d3 100644 --- a/advisories/unreviewed/2025/05/GHSA-6vhr-vrr2-gfrx/GHSA-6vhr-vrr2-gfrx.json +++ b/advisories/unreviewed/2025/05/GHSA-6vhr-vrr2-gfrx/GHSA-6vhr-vrr2-gfrx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6vhr-vrr2-gfrx", - "modified": "2025-05-15T21:31:33Z", + "modified": "2025-05-20T21:30:41Z", "published": "2025-05-15T21:31:33Z", "aliases": [ "CVE-2024-8620" ], "details": "The MapPress Maps for WordPress plugin before 2.93 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:59Z" diff --git a/advisories/unreviewed/2025/05/GHSA-74mm-f42c-v226/GHSA-74mm-f42c-v226.json b/advisories/unreviewed/2025/05/GHSA-74mm-f42c-v226/GHSA-74mm-f42c-v226.json new file mode 100644 index 00000000000..c04587cb48f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-74mm-f42c-v226/GHSA-74mm-f42c-v226.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74mm-f42c-v226", + "modified": "2025-05-20T21:30:31Z", + "published": "2025-05-20T21:30:31Z", + "aliases": [ + "CVE-2024-13630" + ], + "details": "The NewsTicker WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13630" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/15eed487-01ac-4c1e-88f8-26cfa036fb54" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-75jq-cq85-m7jx/GHSA-75jq-cq85-m7jx.json b/advisories/unreviewed/2025/05/GHSA-75jq-cq85-m7jx/GHSA-75jq-cq85-m7jx.json index 450c12ec36b..3ae7570f9eb 100644 --- a/advisories/unreviewed/2025/05/GHSA-75jq-cq85-m7jx/GHSA-75jq-cq85-m7jx.json +++ b/advisories/unreviewed/2025/05/GHSA-75jq-cq85-m7jx/GHSA-75jq-cq85-m7jx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-75jq-cq85-m7jx", - "modified": "2025-05-15T21:31:28Z", + "modified": "2025-05-20T21:30:32Z", "published": "2025-05-15T21:31:28Z", "aliases": [ "CVE-2024-11221" ], "details": "The Full Screen (Page) Background Image Slideshow WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:34Z" diff --git a/advisories/unreviewed/2025/05/GHSA-79vg-2g4j-h2vr/GHSA-79vg-2g4j-h2vr.json b/advisories/unreviewed/2025/05/GHSA-79vg-2g4j-h2vr/GHSA-79vg-2g4j-h2vr.json index b991a9114f4..e7b7a21905e 100644 --- a/advisories/unreviewed/2025/05/GHSA-79vg-2g4j-h2vr/GHSA-79vg-2g4j-h2vr.json +++ b/advisories/unreviewed/2025/05/GHSA-79vg-2g4j-h2vr/GHSA-79vg-2g4j-h2vr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-79vg-2g4j-h2vr", - "modified": "2025-05-15T21:31:33Z", + "modified": "2025-05-20T21:30:41Z", "published": "2025-05-15T21:31:33Z", "aliases": [ "CVE-2024-8619" ], "details": "The Ajax Search Lite WordPress plugin before 4.12.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:59Z" diff --git a/advisories/unreviewed/2025/05/GHSA-7fvh-65xr-g9fx/GHSA-7fvh-65xr-g9fx.json b/advisories/unreviewed/2025/05/GHSA-7fvh-65xr-g9fx/GHSA-7fvh-65xr-g9fx.json index d7280bf8f89..516c66776ae 100644 --- a/advisories/unreviewed/2025/05/GHSA-7fvh-65xr-g9fx/GHSA-7fvh-65xr-g9fx.json +++ b/advisories/unreviewed/2025/05/GHSA-7fvh-65xr-g9fx/GHSA-7fvh-65xr-g9fx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7fvh-65xr-g9fx", - "modified": "2025-05-15T21:31:34Z", + "modified": "2025-05-20T21:30:42Z", "published": "2025-05-15T21:31:34Z", "aliases": [ "CVE-2025-0687" ], "details": "The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:16:01Z" diff --git a/advisories/unreviewed/2025/05/GHSA-7ggj-vx66-73fv/GHSA-7ggj-vx66-73fv.json b/advisories/unreviewed/2025/05/GHSA-7ggj-vx66-73fv/GHSA-7ggj-vx66-73fv.json new file mode 100644 index 00000000000..2c8b60c65b2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7ggj-vx66-73fv/GHSA-7ggj-vx66-73fv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7ggj-vx66-73fv", + "modified": "2025-05-20T21:30:30Z", + "published": "2025-05-20T21:30:30Z", + "aliases": [ + "CVE-2024-12737" + ], + "details": "The WP BASE Booking of Appointments, Services and Events WordPress plugin before 5.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12737" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/997eb9f6-80e1-4bc5-be72-bd6a6f52379c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7gvw-8492-45cx/GHSA-7gvw-8492-45cx.json b/advisories/unreviewed/2025/05/GHSA-7gvw-8492-45cx/GHSA-7gvw-8492-45cx.json index d981c28de8a..05910539c17 100644 --- a/advisories/unreviewed/2025/05/GHSA-7gvw-8492-45cx/GHSA-7gvw-8492-45cx.json +++ b/advisories/unreviewed/2025/05/GHSA-7gvw-8492-45cx/GHSA-7gvw-8492-45cx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7gvw-8492-45cx", - "modified": "2025-05-15T21:31:28Z", + "modified": "2025-05-20T21:30:32Z", "published": "2025-05-15T21:31:28Z", "aliases": [ "CVE-2024-11189" ], "details": "The Social Share And Social Locker WordPress plugin before 1.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:34Z" diff --git a/advisories/unreviewed/2025/05/GHSA-7h9p-m872-c67m/GHSA-7h9p-m872-c67m.json b/advisories/unreviewed/2025/05/GHSA-7h9p-m872-c67m/GHSA-7h9p-m872-c67m.json index 9620ff23bf6..e49b2865fca 100644 --- a/advisories/unreviewed/2025/05/GHSA-7h9p-m872-c67m/GHSA-7h9p-m872-c67m.json +++ b/advisories/unreviewed/2025/05/GHSA-7h9p-m872-c67m/GHSA-7h9p-m872-c67m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7h9p-m872-c67m", - "modified": "2025-05-15T21:31:28Z", + "modified": "2025-05-20T21:30:32Z", "published": "2025-05-15T21:31:28Z", "aliases": [ "CVE-2024-11269" ], "details": "The AHAthat Plugin WordPress plugin through 1.6 does not sanitize and escape a parameter before using it in a SQL statement, allowing Admin to perform SQL injection attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:34Z" diff --git a/advisories/unreviewed/2025/05/GHSA-7wxh-2hv2-977q/GHSA-7wxh-2hv2-977q.json b/advisories/unreviewed/2025/05/GHSA-7wxh-2hv2-977q/GHSA-7wxh-2hv2-977q.json index 2654e685704..4a1ad0bda5e 100644 --- a/advisories/unreviewed/2025/05/GHSA-7wxh-2hv2-977q/GHSA-7wxh-2hv2-977q.json +++ b/advisories/unreviewed/2025/05/GHSA-7wxh-2hv2-977q/GHSA-7wxh-2hv2-977q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7wxh-2hv2-977q", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T21:30:37Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-13616" ], "details": "The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:39Z" diff --git a/advisories/unreviewed/2025/05/GHSA-7x4v-3vr9-6h78/GHSA-7x4v-3vr9-6h78.json b/advisories/unreviewed/2025/05/GHSA-7x4v-3vr9-6h78/GHSA-7x4v-3vr9-6h78.json index 98577beeee3..1b415a90724 100644 --- a/advisories/unreviewed/2025/05/GHSA-7x4v-3vr9-6h78/GHSA-7x4v-3vr9-6h78.json +++ b/advisories/unreviewed/2025/05/GHSA-7x4v-3vr9-6h78/GHSA-7x4v-3vr9-6h78.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7x4v-3vr9-6h78", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:35Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-12739" ], "details": "The Mobile Contact Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:36Z" diff --git a/advisories/unreviewed/2025/05/GHSA-844h-f426-fxwj/GHSA-844h-f426-fxwj.json b/advisories/unreviewed/2025/05/GHSA-844h-f426-fxwj/GHSA-844h-f426-fxwj.json new file mode 100644 index 00000000000..cf495be3ecd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-844h-f426-fxwj/GHSA-844h-f426-fxwj.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-844h-f426-fxwj", + "modified": "2025-05-20T21:30:43Z", + "published": "2025-05-20T21:30:43Z", + "aliases": [ + "CVE-2025-4997" + ], + "details": "A vulnerability, which was classified as problematic, was found in H3C R2+ProG up to 200R004. Affected is the function UpdateWanParams/AddMacList/EditMacList/AddWlanMacList/EditWlanMacList/Edit_BasicSSID/Edit_GuestSSIDFor2P4G/Edit_BasicSSID_5G/SetAPInfoById of the file /goform/aspForm of the component HTTP POST Request Handler. The manipulation of the argument param leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4997" + }, + { + "type": "WEB", + "url": "https://github.com/CH13hh/tmp_store_cc/blob/main/H3C%20R2%2BProG/1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309648" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309648" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.563551" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T20:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-874p-6rxv-4ppg/GHSA-874p-6rxv-4ppg.json b/advisories/unreviewed/2025/05/GHSA-874p-6rxv-4ppg/GHSA-874p-6rxv-4ppg.json index 1a285adb05e..d83564e3b51 100644 --- a/advisories/unreviewed/2025/05/GHSA-874p-6rxv-4ppg/GHSA-874p-6rxv-4ppg.json +++ b/advisories/unreviewed/2025/05/GHSA-874p-6rxv-4ppg/GHSA-874p-6rxv-4ppg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-874p-6rxv-4ppg", - "modified": "2025-05-15T21:31:28Z", + "modified": "2025-05-20T21:30:32Z", "published": "2025-05-15T21:31:28Z", "aliases": [ "CVE-2024-11141" ], "details": "The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings and is missing CSRF protection which could allow subscribers to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:34Z" diff --git a/advisories/unreviewed/2025/05/GHSA-89wf-mr2w-22xh/GHSA-89wf-mr2w-22xh.json b/advisories/unreviewed/2025/05/GHSA-89wf-mr2w-22xh/GHSA-89wf-mr2w-22xh.json index 95475a2cde6..4a111ad0797 100644 --- a/advisories/unreviewed/2025/05/GHSA-89wf-mr2w-22xh/GHSA-89wf-mr2w-22xh.json +++ b/advisories/unreviewed/2025/05/GHSA-89wf-mr2w-22xh/GHSA-89wf-mr2w-22xh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-89wf-mr2w-22xh", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T21:30:37Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-13486" ], "details": "The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:39Z" diff --git a/advisories/unreviewed/2025/05/GHSA-8jcq-cgc3-57jm/GHSA-8jcq-cgc3-57jm.json b/advisories/unreviewed/2025/05/GHSA-8jcq-cgc3-57jm/GHSA-8jcq-cgc3-57jm.json index 32174c5644e..0fbbe0fbb7e 100644 --- a/advisories/unreviewed/2025/05/GHSA-8jcq-cgc3-57jm/GHSA-8jcq-cgc3-57jm.json +++ b/advisories/unreviewed/2025/05/GHSA-8jcq-cgc3-57jm/GHSA-8jcq-cgc3-57jm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8jcq-cgc3-57jm", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:34Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-12734" ], "details": "The Advance Post Prefix WordPress plugin through 1.1.1, Advance Post Prefix WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:36Z" diff --git a/advisories/unreviewed/2025/05/GHSA-8rhc-9wf9-c4f6/GHSA-8rhc-9wf9-c4f6.json b/advisories/unreviewed/2025/05/GHSA-8rhc-9wf9-c4f6/GHSA-8rhc-9wf9-c4f6.json index 83736dc034e..4bef8f0520d 100644 --- a/advisories/unreviewed/2025/05/GHSA-8rhc-9wf9-c4f6/GHSA-8rhc-9wf9-c4f6.json +++ b/advisories/unreviewed/2025/05/GHSA-8rhc-9wf9-c4f6/GHSA-8rhc-9wf9-c4f6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8rhc-9wf9-c4f6", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-20T21:30:39Z", "published": "2025-05-15T21:31:31Z", "aliases": [ "CVE-2024-6718" ], "details": "The PVN Auth Popup WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:56Z" diff --git a/advisories/unreviewed/2025/05/GHSA-9495-7c48-4348/GHSA-9495-7c48-4348.json b/advisories/unreviewed/2025/05/GHSA-9495-7c48-4348/GHSA-9495-7c48-4348.json index 3326f701c44..8ff306dc701 100644 --- a/advisories/unreviewed/2025/05/GHSA-9495-7c48-4348/GHSA-9495-7c48-4348.json +++ b/advisories/unreviewed/2025/05/GHSA-9495-7c48-4348/GHSA-9495-7c48-4348.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9495-7c48-4348", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:34Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-12732" ], "details": "The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:36Z" diff --git a/advisories/unreviewed/2025/05/GHSA-94c7-f7jq-xgj6/GHSA-94c7-f7jq-xgj6.json b/advisories/unreviewed/2025/05/GHSA-94c7-f7jq-xgj6/GHSA-94c7-f7jq-xgj6.json index 77b14c76eec..f352838a5c9 100644 --- a/advisories/unreviewed/2025/05/GHSA-94c7-f7jq-xgj6/GHSA-94c7-f7jq-xgj6.json +++ b/advisories/unreviewed/2025/05/GHSA-94c7-f7jq-xgj6/GHSA-94c7-f7jq-xgj6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-94c7-f7jq-xgj6", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:36Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-13128" ], "details": "The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:38Z" diff --git a/advisories/unreviewed/2025/05/GHSA-95c2-647q-689h/GHSA-95c2-647q-689h.json b/advisories/unreviewed/2025/05/GHSA-95c2-647q-689h/GHSA-95c2-647q-689h.json new file mode 100644 index 00000000000..d5b76e81d84 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-95c2-647q-689h/GHSA-95c2-647q-689h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95c2-647q-689h", + "modified": "2025-05-20T21:30:43Z", + "published": "2025-05-20T21:30:43Z", + "aliases": [ + "CVE-2025-44896" + ], + "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bindEditMACName parameter in the web_acl_bindEdit_post function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44896" + }, + { + "type": "WEB", + "url": "https://lafdrew.github.io/2025/04/18/web-acl-bindEdit-post-bindEditMACName-StackOverflow" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-96h4-8m29-phmf/GHSA-96h4-8m29-phmf.json b/advisories/unreviewed/2025/05/GHSA-96h4-8m29-phmf/GHSA-96h4-8m29-phmf.json index 2fdf398f658..8e4425b3409 100644 --- a/advisories/unreviewed/2025/05/GHSA-96h4-8m29-phmf/GHSA-96h4-8m29-phmf.json +++ b/advisories/unreviewed/2025/05/GHSA-96h4-8m29-phmf/GHSA-96h4-8m29-phmf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-96h4-8m29-phmf", - "modified": "2025-05-15T21:31:28Z", + "modified": "2025-05-20T21:30:32Z", "published": "2025-05-15T21:31:28Z", "aliases": [ "CVE-2024-11266" ], "details": "The Geocache Stat Bar Widget WordPress plugin through 0.911 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:34Z" diff --git a/advisories/unreviewed/2025/05/GHSA-98qf-h3c2-3wwr/GHSA-98qf-h3c2-3wwr.json b/advisories/unreviewed/2025/05/GHSA-98qf-h3c2-3wwr/GHSA-98qf-h3c2-3wwr.json index 8746d5c3408..9ef827f03c7 100644 --- a/advisories/unreviewed/2025/05/GHSA-98qf-h3c2-3wwr/GHSA-98qf-h3c2-3wwr.json +++ b/advisories/unreviewed/2025/05/GHSA-98qf-h3c2-3wwr/GHSA-98qf-h3c2-3wwr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-98qf-h3c2-3wwr", - "modified": "2025-05-15T21:31:34Z", + "modified": "2025-05-20T21:30:41Z", "published": "2025-05-15T21:31:34Z", "aliases": [ "CVE-2025-0329" ], "details": "The AI ChatBot for WordPress WordPress plugin before 6.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:16:01Z" diff --git a/advisories/unreviewed/2025/05/GHSA-9fcp-xcwr-cjm9/GHSA-9fcp-xcwr-cjm9.json b/advisories/unreviewed/2025/05/GHSA-9fcp-xcwr-cjm9/GHSA-9fcp-xcwr-cjm9.json index f1153a5c8c9..1aca37fd44e 100644 --- a/advisories/unreviewed/2025/05/GHSA-9fcp-xcwr-cjm9/GHSA-9fcp-xcwr-cjm9.json +++ b/advisories/unreviewed/2025/05/GHSA-9fcp-xcwr-cjm9/GHSA-9fcp-xcwr-cjm9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9fcp-xcwr-cjm9", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:35Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-12743" ], "details": "The MailPoet WordPress plugin before 5.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:37Z" diff --git a/advisories/unreviewed/2025/05/GHSA-9g8q-q3hj-343m/GHSA-9g8q-q3hj-343m.json b/advisories/unreviewed/2025/05/GHSA-9g8q-q3hj-343m/GHSA-9g8q-q3hj-343m.json index 9f9e5727c74..5df717d1031 100644 --- a/advisories/unreviewed/2025/05/GHSA-9g8q-q3hj-343m/GHSA-9g8q-q3hj-343m.json +++ b/advisories/unreviewed/2025/05/GHSA-9g8q-q3hj-343m/GHSA-9g8q-q3hj-343m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9g8q-q3hj-343m", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-20T21:30:38Z", "published": "2025-05-15T21:31:31Z", "aliases": [ "CVE-2024-6462" ], "details": "The DL Yandex Metrika WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:55Z" diff --git a/advisories/unreviewed/2025/05/GHSA-9vf8-3h22-8c7j/GHSA-9vf8-3h22-8c7j.json b/advisories/unreviewed/2025/05/GHSA-9vf8-3h22-8c7j/GHSA-9vf8-3h22-8c7j.json new file mode 100644 index 00000000000..2d40edfa91c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9vf8-3h22-8c7j/GHSA-9vf8-3h22-8c7j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vf8-3h22-8c7j", + "modified": "2025-05-20T21:30:43Z", + "published": "2025-05-20T21:30:43Z", + "aliases": [ + "CVE-2025-44890" + ], + "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_notifyv3_add_post function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44890" + }, + { + "type": "WEB", + "url": "https://lafdrew.github.io/2025/04/20/web-snmp-notifyv3-add-post-host-ip" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T20:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c3j4-92qv-mh62/GHSA-c3j4-92qv-mh62.json b/advisories/unreviewed/2025/05/GHSA-c3j4-92qv-mh62/GHSA-c3j4-92qv-mh62.json new file mode 100644 index 00000000000..29b3ea15b55 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c3j4-92qv-mh62/GHSA-c3j4-92qv-mh62.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3j4-92qv-mh62", + "modified": "2025-05-20T21:30:43Z", + "published": "2025-05-20T21:30:43Z", + "aliases": [ + "CVE-2025-44880" + ], + "details": "A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44880" + }, + { + "type": "WEB", + "url": "https://lafdrew.github.io/2025/03/27/Remote-Command-Execution-in-adm-cgi-of-wavlink-WL-WN579A3-Device" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c4c6-xhvm-jcxg/GHSA-c4c6-xhvm-jcxg.json b/advisories/unreviewed/2025/05/GHSA-c4c6-xhvm-jcxg/GHSA-c4c6-xhvm-jcxg.json new file mode 100644 index 00000000000..a70f89de041 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c4c6-xhvm-jcxg/GHSA-c4c6-xhvm-jcxg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4c6-xhvm-jcxg", + "modified": "2025-05-20T21:30:42Z", + "published": "2025-05-20T21:30:42Z", + "aliases": [ + "CVE-2025-44884" + ], + "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44884" + }, + { + "type": "WEB", + "url": "https://lafdrew.github.io/2025/04/20/web-sys-infoContact-post-contact" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T20:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-chqc-5pg2-gc95/GHSA-chqc-5pg2-gc95.json b/advisories/unreviewed/2025/05/GHSA-chqc-5pg2-gc95/GHSA-chqc-5pg2-gc95.json index e832123f3f7..9639c503963 100644 --- a/advisories/unreviewed/2025/05/GHSA-chqc-5pg2-gc95/GHSA-chqc-5pg2-gc95.json +++ b/advisories/unreviewed/2025/05/GHSA-chqc-5pg2-gc95/GHSA-chqc-5pg2-gc95.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-chqc-5pg2-gc95", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-20T21:30:39Z", "published": "2025-05-15T21:31:31Z", "aliases": [ "CVE-2024-6712" ], "details": "The MapFig Studio WordPress plugin through 0.2.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:56Z" diff --git a/advisories/unreviewed/2025/05/GHSA-cqqm-8g3r-4grm/GHSA-cqqm-8g3r-4grm.json b/advisories/unreviewed/2025/05/GHSA-cqqm-8g3r-4grm/GHSA-cqqm-8g3r-4grm.json index 79e87cccea2..2dcacf57a4f 100644 --- a/advisories/unreviewed/2025/05/GHSA-cqqm-8g3r-4grm/GHSA-cqqm-8g3r-4grm.json +++ b/advisories/unreviewed/2025/05/GHSA-cqqm-8g3r-4grm/GHSA-cqqm-8g3r-4grm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cqqm-8g3r-4grm", - "modified": "2025-05-15T21:31:28Z", + "modified": "2025-05-20T21:30:32Z", "published": "2025-05-15T21:31:28Z", "aliases": [ "CVE-2024-10634" ], "details": "The Nokaut Offers Box WordPress plugin through 1.4.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin reset the Nokaut Offers Box WordPress plugin through 1.4.0 via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:33Z" diff --git a/advisories/unreviewed/2025/05/GHSA-cqw5-7mc9-48hp/GHSA-cqw5-7mc9-48hp.json b/advisories/unreviewed/2025/05/GHSA-cqw5-7mc9-48hp/GHSA-cqw5-7mc9-48hp.json index 676db9fee1c..5b26bdfd239 100644 --- a/advisories/unreviewed/2025/05/GHSA-cqw5-7mc9-48hp/GHSA-cqw5-7mc9-48hp.json +++ b/advisories/unreviewed/2025/05/GHSA-cqw5-7mc9-48hp/GHSA-cqw5-7mc9-48hp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cqw5-7mc9-48hp", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T21:30:36Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-13384" ], "details": "The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.24 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:39Z" diff --git a/advisories/unreviewed/2025/05/GHSA-f4x9-c974-c97m/GHSA-f4x9-c974-c97m.json b/advisories/unreviewed/2025/05/GHSA-f4x9-c974-c97m/GHSA-f4x9-c974-c97m.json new file mode 100644 index 00000000000..06b53d8f7f5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f4x9-c974-c97m/GHSA-f4x9-c974-c97m.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4x9-c974-c97m", + "modified": "2025-05-20T21:30:43Z", + "published": "2025-05-20T21:30:43Z", + "aliases": [ + "CVE-2025-44883" + ], + "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_serverEdit_post function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44883" + }, + { + "type": "WEB", + "url": "https://lafdrew.github.io/2025/04/20/web-tacplus-serverEdit-post-tacIp" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f5ww-x9w7-q9v2/GHSA-f5ww-x9w7-q9v2.json b/advisories/unreviewed/2025/05/GHSA-f5ww-x9w7-q9v2/GHSA-f5ww-x9w7-q9v2.json index 40e905bd75f..a378cda0967 100644 --- a/advisories/unreviewed/2025/05/GHSA-f5ww-x9w7-q9v2/GHSA-f5ww-x9w7-q9v2.json +++ b/advisories/unreviewed/2025/05/GHSA-f5ww-x9w7-q9v2/GHSA-f5ww-x9w7-q9v2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f5ww-x9w7-q9v2", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T21:30:38Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-5026" ], "details": "The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:54Z" diff --git a/advisories/unreviewed/2025/05/GHSA-f87f-4wg8-gxhp/GHSA-f87f-4wg8-gxhp.json b/advisories/unreviewed/2025/05/GHSA-f87f-4wg8-gxhp/GHSA-f87f-4wg8-gxhp.json index 4f0bdaed9f2..d1998b2ea8d 100644 --- a/advisories/unreviewed/2025/05/GHSA-f87f-4wg8-gxhp/GHSA-f87f-4wg8-gxhp.json +++ b/advisories/unreviewed/2025/05/GHSA-f87f-4wg8-gxhp/GHSA-f87f-4wg8-gxhp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f87f-4wg8-gxhp", - "modified": "2025-05-15T21:31:34Z", + "modified": "2025-05-20T21:30:42Z", "published": "2025-05-15T21:31:34Z", "aliases": [ "CVE-2025-1289" ], "details": "The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:16:02Z" diff --git a/advisories/unreviewed/2025/05/GHSA-fq7q-wgm6-7rqj/GHSA-fq7q-wgm6-7rqj.json b/advisories/unreviewed/2025/05/GHSA-fq7q-wgm6-7rqj/GHSA-fq7q-wgm6-7rqj.json index eb120bc661b..9a2392162df 100644 --- a/advisories/unreviewed/2025/05/GHSA-fq7q-wgm6-7rqj/GHSA-fq7q-wgm6-7rqj.json +++ b/advisories/unreviewed/2025/05/GHSA-fq7q-wgm6-7rqj/GHSA-fq7q-wgm6-7rqj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fq7q-wgm6-7rqj", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T21:30:35Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-12808" ], "details": "The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:37Z" diff --git a/advisories/unreviewed/2025/05/GHSA-g453-c6fq-7fg3/GHSA-g453-c6fq-7fg3.json b/advisories/unreviewed/2025/05/GHSA-g453-c6fq-7fg3/GHSA-g453-c6fq-7fg3.json index b9d2b489fab..e5871a74ba4 100644 --- a/advisories/unreviewed/2025/05/GHSA-g453-c6fq-7fg3/GHSA-g453-c6fq-7fg3.json +++ b/advisories/unreviewed/2025/05/GHSA-g453-c6fq-7fg3/GHSA-g453-c6fq-7fg3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g453-c6fq-7fg3", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:34Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-12726" ], "details": "The ClipArt WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:36Z" diff --git a/advisories/unreviewed/2025/05/GHSA-gprh-m7xv-mqpj/GHSA-gprh-m7xv-mqpj.json b/advisories/unreviewed/2025/05/GHSA-gprh-m7xv-mqpj/GHSA-gprh-m7xv-mqpj.json index 509905709b4..28743ac8f91 100644 --- a/advisories/unreviewed/2025/05/GHSA-gprh-m7xv-mqpj/GHSA-gprh-m7xv-mqpj.json +++ b/advisories/unreviewed/2025/05/GHSA-gprh-m7xv-mqpj/GHSA-gprh-m7xv-mqpj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gprh-m7xv-mqpj", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T21:30:37Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-13621" ], "details": "The GDPR Framework By Data443 WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:39Z" diff --git a/advisories/unreviewed/2025/05/GHSA-h2f3-9263-mhpx/GHSA-h2f3-9263-mhpx.json b/advisories/unreviewed/2025/05/GHSA-h2f3-9263-mhpx/GHSA-h2f3-9263-mhpx.json index 7e52c3a8613..8eddfba45a4 100644 --- a/advisories/unreviewed/2025/05/GHSA-h2f3-9263-mhpx/GHSA-h2f3-9263-mhpx.json +++ b/advisories/unreviewed/2025/05/GHSA-h2f3-9263-mhpx/GHSA-h2f3-9263-mhpx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h2f3-9263-mhpx", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T21:30:37Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-13730" ], "details": "The Podlove Podcast Publisher WordPress plugin before 4.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:40Z" diff --git a/advisories/unreviewed/2025/05/GHSA-h393-525x-w74q/GHSA-h393-525x-w74q.json b/advisories/unreviewed/2025/05/GHSA-h393-525x-w74q/GHSA-h393-525x-w74q.json new file mode 100644 index 00000000000..7288d9fc4be --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h393-525x-w74q/GHSA-h393-525x-w74q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h393-525x-w74q", + "modified": "2025-05-20T21:30:31Z", + "published": "2025-05-20T21:30:31Z", + "aliases": [ + "CVE-2024-13633" + ], + "details": "The Simple catalogue WordPress plugin through 1.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13633" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/4291d5eb-c006-42b0-accf-90f09f26b6a0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h9vp-frfm-hwvq/GHSA-h9vp-frfm-hwvq.json b/advisories/unreviewed/2025/05/GHSA-h9vp-frfm-hwvq/GHSA-h9vp-frfm-hwvq.json index 741fdb78709..b3635d97520 100644 --- a/advisories/unreviewed/2025/05/GHSA-h9vp-frfm-hwvq/GHSA-h9vp-frfm-hwvq.json +++ b/advisories/unreviewed/2025/05/GHSA-h9vp-frfm-hwvq/GHSA-h9vp-frfm-hwvq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h9vp-frfm-hwvq", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:35Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-12750" ], "details": "The Competition Form WordPress plugin through 2.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:37Z" diff --git a/advisories/unreviewed/2025/05/GHSA-hc6j-5h8v-c5cg/GHSA-hc6j-5h8v-c5cg.json b/advisories/unreviewed/2025/05/GHSA-hc6j-5h8v-c5cg/GHSA-hc6j-5h8v-c5cg.json index 8f3e6a554ca..cf79d9d38cf 100644 --- a/advisories/unreviewed/2025/05/GHSA-hc6j-5h8v-c5cg/GHSA-hc6j-5h8v-c5cg.json +++ b/advisories/unreviewed/2025/05/GHSA-hc6j-5h8v-c5cg/GHSA-hc6j-5h8v-c5cg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hc6j-5h8v-c5cg", - "modified": "2025-05-15T21:31:28Z", + "modified": "2025-05-20T21:30:32Z", "published": "2025-05-15T21:31:28Z", "aliases": [ "CVE-2024-10639" ], "details": "The Auto Prune Posts WordPress plugin before 3.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:33Z" diff --git a/advisories/unreviewed/2025/05/GHSA-hjxc-cj85-6rvh/GHSA-hjxc-cj85-6rvh.json b/advisories/unreviewed/2025/05/GHSA-hjxc-cj85-6rvh/GHSA-hjxc-cj85-6rvh.json index ffa35d40907..c1092aad2ef 100644 --- a/advisories/unreviewed/2025/05/GHSA-hjxc-cj85-6rvh/GHSA-hjxc-cj85-6rvh.json +++ b/advisories/unreviewed/2025/05/GHSA-hjxc-cj85-6rvh/GHSA-hjxc-cj85-6rvh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hjxc-cj85-6rvh", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-20T21:30:39Z", "published": "2025-05-15T21:31:31Z", "aliases": [ "CVE-2024-6719" ], "details": "The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users to update them via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:56Z" diff --git a/advisories/unreviewed/2025/05/GHSA-j2p9-f4vx-cp2g/GHSA-j2p9-f4vx-cp2g.json b/advisories/unreviewed/2025/05/GHSA-j2p9-f4vx-cp2g/GHSA-j2p9-f4vx-cp2g.json index 8cf1c0cfc20..b268531cea1 100644 --- a/advisories/unreviewed/2025/05/GHSA-j2p9-f4vx-cp2g/GHSA-j2p9-f4vx-cp2g.json +++ b/advisories/unreviewed/2025/05/GHSA-j2p9-f4vx-cp2g/GHSA-j2p9-f4vx-cp2g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j2p9-f4vx-cp2g", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-20T21:30:38Z", "published": "2025-05-15T21:31:31Z", "aliases": [ "CVE-2024-6486" ], "details": "The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injection via the \"cli_path\" parameter. This allows authenticated attackers, with administrator-level permission to execute arbitrary OS commands on the server leading to remote code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:55Z" diff --git a/advisories/unreviewed/2025/05/GHSA-j4jp-4rjc-6479/GHSA-j4jp-4rjc-6479.json b/advisories/unreviewed/2025/05/GHSA-j4jp-4rjc-6479/GHSA-j4jp-4rjc-6479.json index fe1e6adefa3..fc417b7d5be 100644 --- a/advisories/unreviewed/2025/05/GHSA-j4jp-4rjc-6479/GHSA-j4jp-4rjc-6479.json +++ b/advisories/unreviewed/2025/05/GHSA-j4jp-4rjc-6479/GHSA-j4jp-4rjc-6479.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j4jp-4rjc-6479", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-20T21:30:38Z", "published": "2025-05-15T21:31:31Z", "aliases": [ "CVE-2024-6668" ], "details": "The ProfilePro WordPress plugin through 1.3 does not sanitise and escape some parameters and lacks proper access controls, which could allow users with a role as low as subscriber to perform Cross-Site Scripting attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:55Z" diff --git a/advisories/unreviewed/2025/05/GHSA-j78m-3c5f-wq4g/GHSA-j78m-3c5f-wq4g.json b/advisories/unreviewed/2025/05/GHSA-j78m-3c5f-wq4g/GHSA-j78m-3c5f-wq4g.json new file mode 100644 index 00000000000..3359afbce26 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j78m-3c5f-wq4g/GHSA-j78m-3c5f-wq4g.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j78m-3c5f-wq4g", + "modified": "2025-05-20T21:30:43Z", + "published": "2025-05-20T21:30:43Z", + "aliases": [ + "CVE-2025-44898" + ], + "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the theauthName parameter in the web_aaa_loginAuthlistEdit function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44898" + }, + { + "type": "WEB", + "url": "https://lafdrew.github.io/2025/04/18/web-aaa-loginAuthlistEdit-get-authName-StackOverflow" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j7cm-jxq2-h8q5/GHSA-j7cm-jxq2-h8q5.json b/advisories/unreviewed/2025/05/GHSA-j7cm-jxq2-h8q5/GHSA-j7cm-jxq2-h8q5.json index 626d734f633..c69b2835658 100644 --- a/advisories/unreviewed/2025/05/GHSA-j7cm-jxq2-h8q5/GHSA-j7cm-jxq2-h8q5.json +++ b/advisories/unreviewed/2025/05/GHSA-j7cm-jxq2-h8q5/GHSA-j7cm-jxq2-h8q5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j7cm-jxq2-h8q5", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-20T21:30:39Z", "published": "2025-05-15T21:31:31Z", "aliases": [ "CVE-2024-6713" ], "details": "The PVN Auth Popup WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:56Z" diff --git a/advisories/unreviewed/2025/05/GHSA-j95r-8c72-m59j/GHSA-j95r-8c72-m59j.json b/advisories/unreviewed/2025/05/GHSA-j95r-8c72-m59j/GHSA-j95r-8c72-m59j.json index d8b88aa945d..14b77fa17ac 100644 --- a/advisories/unreviewed/2025/05/GHSA-j95r-8c72-m59j/GHSA-j95r-8c72-m59j.json +++ b/advisories/unreviewed/2025/05/GHSA-j95r-8c72-m59j/GHSA-j95r-8c72-m59j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j95r-8c72-m59j", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:33Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-12680" ], "details": "The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:36Z" diff --git a/advisories/unreviewed/2025/05/GHSA-jcm8-5j7x-8gjh/GHSA-jcm8-5j7x-8gjh.json b/advisories/unreviewed/2025/05/GHSA-jcm8-5j7x-8gjh/GHSA-jcm8-5j7x-8gjh.json new file mode 100644 index 00000000000..2a57baa570a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jcm8-5j7x-8gjh/GHSA-jcm8-5j7x-8gjh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcm8-5j7x-8gjh", + "modified": "2025-05-20T21:30:32Z", + "published": "2025-05-20T21:30:32Z", + "aliases": [ + "CVE-2024-13634" + ], + "details": "The Post Sync WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13634" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/0e60bf74-19fb-441c-85a8-005def36af9a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jr3v-9vjg-r9jw/GHSA-jr3v-9vjg-r9jw.json b/advisories/unreviewed/2025/05/GHSA-jr3v-9vjg-r9jw/GHSA-jr3v-9vjg-r9jw.json index 391e7c9af7c..f9714d7dbd6 100644 --- a/advisories/unreviewed/2025/05/GHSA-jr3v-9vjg-r9jw/GHSA-jr3v-9vjg-r9jw.json +++ b/advisories/unreviewed/2025/05/GHSA-jr3v-9vjg-r9jw/GHSA-jr3v-9vjg-r9jw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jr3v-9vjg-r9jw", - "modified": "2025-05-15T21:31:28Z", + "modified": "2025-05-20T21:30:32Z", "published": "2025-05-15T21:31:28Z", "aliases": [ "CVE-2024-10632" ], "details": "The Nokaut Offers Box WordPress plugin through 1.4.0 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:33Z" diff --git a/advisories/unreviewed/2025/05/GHSA-m252-h4rm-hqfr/GHSA-m252-h4rm-hqfr.json b/advisories/unreviewed/2025/05/GHSA-m252-h4rm-hqfr/GHSA-m252-h4rm-hqfr.json new file mode 100644 index 00000000000..4b9b0957943 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m252-h4rm-hqfr/GHSA-m252-h4rm-hqfr.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m252-h4rm-hqfr", + "modified": "2025-05-20T21:30:44Z", + "published": "2025-05-20T21:30:44Z", + "aliases": [ + "CVE-2025-4999" + ], + "details": "A vulnerability was found in Linksys FGW3000-AH and FGW3000-HK up to 1.0.17.000000 and classified as critical. Affected by this issue is the function sub_4153FC of the file /cgi-bin/sysconf.cgi of the component HTTP POST Request Handler. The manipulation of the argument supplicant_rnd_id_en leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4999" + }, + { + "type": "WEB", + "url": "https://github.com/CH13hh/tmp_store_cc/blob/main/FGW3000/1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309650" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309650" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.565909" + }, + { + "type": "WEB", + "url": "https://www.linksys.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T21:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m33j-944f-82fq/GHSA-m33j-944f-82fq.json b/advisories/unreviewed/2025/05/GHSA-m33j-944f-82fq/GHSA-m33j-944f-82fq.json index 7d7cb1eab15..754abda1ab0 100644 --- a/advisories/unreviewed/2025/05/GHSA-m33j-944f-82fq/GHSA-m33j-944f-82fq.json +++ b/advisories/unreviewed/2025/05/GHSA-m33j-944f-82fq/GHSA-m33j-944f-82fq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m33j-944f-82fq", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-20T21:30:39Z", "published": "2025-05-15T21:31:31Z", "aliases": [ "CVE-2024-6708" ], "details": "The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting its content on the admin area, which allows Admin+ users to perform Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:55Z" diff --git a/advisories/unreviewed/2025/05/GHSA-m7hp-64f5-g5fr/GHSA-m7hp-64f5-g5fr.json b/advisories/unreviewed/2025/05/GHSA-m7hp-64f5-g5fr/GHSA-m7hp-64f5-g5fr.json index 5baa3749ec9..311712793a2 100644 --- a/advisories/unreviewed/2025/05/GHSA-m7hp-64f5-g5fr/GHSA-m7hp-64f5-g5fr.json +++ b/advisories/unreviewed/2025/05/GHSA-m7hp-64f5-g5fr/GHSA-m7hp-64f5-g5fr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m7hp-64f5-g5fr", - "modified": "2025-05-15T21:31:33Z", + "modified": "2025-05-20T21:30:41Z", "published": "2025-05-15T21:31:33Z", "aliases": [ "CVE-2024-8701" ], "details": "The events-calendar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:59Z" diff --git a/advisories/unreviewed/2025/05/GHSA-m7mh-68hv-jwrj/GHSA-m7mh-68hv-jwrj.json b/advisories/unreviewed/2025/05/GHSA-m7mh-68hv-jwrj/GHSA-m7mh-68hv-jwrj.json index a6f45236f0d..742ec170b32 100644 --- a/advisories/unreviewed/2025/05/GHSA-m7mh-68hv-jwrj/GHSA-m7mh-68hv-jwrj.json +++ b/advisories/unreviewed/2025/05/GHSA-m7mh-68hv-jwrj/GHSA-m7mh-68hv-jwrj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m7mh-68hv-jwrj", - "modified": "2025-05-15T21:31:33Z", + "modified": "2025-05-20T21:30:41Z", "published": "2025-05-15T21:31:33Z", "aliases": [ "CVE-2024-8699" ], "details": "The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:59Z" diff --git a/advisories/unreviewed/2025/05/GHSA-m87q-2m67-hxxh/GHSA-m87q-2m67-hxxh.json b/advisories/unreviewed/2025/05/GHSA-m87q-2m67-hxxh/GHSA-m87q-2m67-hxxh.json index 9172148c96c..de43ceff63d 100644 --- a/advisories/unreviewed/2025/05/GHSA-m87q-2m67-hxxh/GHSA-m87q-2m67-hxxh.json +++ b/advisories/unreviewed/2025/05/GHSA-m87q-2m67-hxxh/GHSA-m87q-2m67-hxxh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m87q-2m67-hxxh", - "modified": "2025-05-15T21:31:33Z", + "modified": "2025-05-20T21:30:41Z", "published": "2025-05-15T21:31:33Z", "aliases": [ "CVE-2024-8673" ], "details": "The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:59Z" diff --git a/advisories/unreviewed/2025/05/GHSA-m8jc-qh4f-52fp/GHSA-m8jc-qh4f-52fp.json b/advisories/unreviewed/2025/05/GHSA-m8jc-qh4f-52fp/GHSA-m8jc-qh4f-52fp.json index 01b10015c9b..499e5a7c2c8 100644 --- a/advisories/unreviewed/2025/05/GHSA-m8jc-qh4f-52fp/GHSA-m8jc-qh4f-52fp.json +++ b/advisories/unreviewed/2025/05/GHSA-m8jc-qh4f-52fp/GHSA-m8jc-qh4f-52fp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m8jc-qh4f-52fp", - "modified": "2025-05-15T21:31:28Z", + "modified": "2025-05-20T21:30:32Z", "published": "2025-05-15T21:31:28Z", "aliases": [ "CVE-2024-10475" ], "details": "The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin before 1.9.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:33Z" diff --git a/advisories/unreviewed/2025/05/GHSA-p629-9pvp-h6f9/GHSA-p629-9pvp-h6f9.json b/advisories/unreviewed/2025/05/GHSA-p629-9pvp-h6f9/GHSA-p629-9pvp-h6f9.json index 63faf781ece..2a18b25e4bc 100644 --- a/advisories/unreviewed/2025/05/GHSA-p629-9pvp-h6f9/GHSA-p629-9pvp-h6f9.json +++ b/advisories/unreviewed/2025/05/GHSA-p629-9pvp-h6f9/GHSA-p629-9pvp-h6f9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p629-9pvp-h6f9", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:32Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-11372" ], "details": "The Connexion Logs WordPress plugin through 3.0.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:35Z" diff --git a/advisories/unreviewed/2025/05/GHSA-pqg5-24w7-qhj2/GHSA-pqg5-24w7-qhj2.json b/advisories/unreviewed/2025/05/GHSA-pqg5-24w7-qhj2/GHSA-pqg5-24w7-qhj2.json new file mode 100644 index 00000000000..51f34ecbde2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pqg5-24w7-qhj2/GHSA-pqg5-24w7-qhj2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqg5-24w7-qhj2", + "modified": "2025-05-20T21:30:32Z", + "published": "2025-05-20T21:30:32Z", + "aliases": [ + "CVE-2024-13669" + ], + "details": "The CalendApp WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13669" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/71e69cf2-7d41-479c-9721-662b57571c90" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pr6c-x44x-mpwc/GHSA-pr6c-x44x-mpwc.json b/advisories/unreviewed/2025/05/GHSA-pr6c-x44x-mpwc/GHSA-pr6c-x44x-mpwc.json index 2063f6db102..80b062da9bf 100644 --- a/advisories/unreviewed/2025/05/GHSA-pr6c-x44x-mpwc/GHSA-pr6c-x44x-mpwc.json +++ b/advisories/unreviewed/2025/05/GHSA-pr6c-x44x-mpwc/GHSA-pr6c-x44x-mpwc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pr6c-x44x-mpwc", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T21:30:36Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-13482" ], "details": "The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:39Z" diff --git a/advisories/unreviewed/2025/05/GHSA-prgf-xxfj-c6gv/GHSA-prgf-xxfj-c6gv.json b/advisories/unreviewed/2025/05/GHSA-prgf-xxfj-c6gv/GHSA-prgf-xxfj-c6gv.json index 979e812825b..6f04a1afcb3 100644 --- a/advisories/unreviewed/2025/05/GHSA-prgf-xxfj-c6gv/GHSA-prgf-xxfj-c6gv.json +++ b/advisories/unreviewed/2025/05/GHSA-prgf-xxfj-c6gv/GHSA-prgf-xxfj-c6gv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-prgf-xxfj-c6gv", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-20T21:30:40Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-8090" ], "details": "The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:57Z" diff --git a/advisories/unreviewed/2025/05/GHSA-pvrm-g69c-c84r/GHSA-pvrm-g69c-c84r.json b/advisories/unreviewed/2025/05/GHSA-pvrm-g69c-c84r/GHSA-pvrm-g69c-c84r.json index fd74aa34d60..cfea318b2ad 100644 --- a/advisories/unreviewed/2025/05/GHSA-pvrm-g69c-c84r/GHSA-pvrm-g69c-c84r.json +++ b/advisories/unreviewed/2025/05/GHSA-pvrm-g69c-c84r/GHSA-pvrm-g69c-c84r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pvrm-g69c-c84r", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-20T21:30:40Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-8095" ], "details": "The BabelZ WordPress plugin through 1.1.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:57Z" diff --git a/advisories/unreviewed/2025/05/GHSA-pvvp-x3x5-w98p/GHSA-pvvp-x3x5-w98p.json b/advisories/unreviewed/2025/05/GHSA-pvvp-x3x5-w98p/GHSA-pvvp-x3x5-w98p.json index 8387dd6802a..bda0081219b 100644 --- a/advisories/unreviewed/2025/05/GHSA-pvvp-x3x5-w98p/GHSA-pvvp-x3x5-w98p.json +++ b/advisories/unreviewed/2025/05/GHSA-pvvp-x3x5-w98p/GHSA-pvvp-x3x5-w98p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pvvp-x3x5-w98p", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T21:30:36Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-13357" ], "details": "The Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high privilege users such as author to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:39Z" diff --git a/advisories/unreviewed/2025/05/GHSA-q3cq-6xv8-j4p3/GHSA-q3cq-6xv8-j4p3.json b/advisories/unreviewed/2025/05/GHSA-q3cq-6xv8-j4p3/GHSA-q3cq-6xv8-j4p3.json index 8cb9a8a4b30..bbc9e21d9c1 100644 --- a/advisories/unreviewed/2025/05/GHSA-q3cq-6xv8-j4p3/GHSA-q3cq-6xv8-j4p3.json +++ b/advisories/unreviewed/2025/05/GHSA-q3cq-6xv8-j4p3/GHSA-q3cq-6xv8-j4p3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q3cq-6xv8-j4p3", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T21:30:36Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-13382" ], "details": "The Calculated Fields Form WordPress plugin before 5.2.64 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:39Z" diff --git a/advisories/unreviewed/2025/05/GHSA-q4w4-f94p-rpp4/GHSA-q4w4-f94p-rpp4.json b/advisories/unreviewed/2025/05/GHSA-q4w4-f94p-rpp4/GHSA-q4w4-f94p-rpp4.json new file mode 100644 index 00000000000..0a036cd494b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q4w4-f94p-rpp4/GHSA-q4w4-f94p-rpp4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4w4-f94p-rpp4", + "modified": "2025-05-20T21:30:31Z", + "published": "2025-05-20T21:30:30Z", + "aliases": [ + "CVE-2024-10563" + ], + "details": "The WooCommerce Cart Count Shortcode WordPress plugin before 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10563" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/08ed69f6-9c9b-4548-9dbb-05b602530ef7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q4w4-v939-f8rm/GHSA-q4w4-v939-f8rm.json b/advisories/unreviewed/2025/05/GHSA-q4w4-v939-f8rm/GHSA-q4w4-v939-f8rm.json index 7913cfbabe4..29aabe57e99 100644 --- a/advisories/unreviewed/2025/05/GHSA-q4w4-v939-f8rm/GHSA-q4w4-v939-f8rm.json +++ b/advisories/unreviewed/2025/05/GHSA-q4w4-v939-f8rm/GHSA-q4w4-v939-f8rm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q4w4-v939-f8rm", - "modified": "2025-05-15T21:31:34Z", + "modified": "2025-05-20T21:30:42Z", "published": "2025-05-15T21:31:34Z", "aliases": [ "CVE-2025-0688" ], "details": "The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:16:01Z" diff --git a/advisories/unreviewed/2025/05/GHSA-q79f-fxqg-m9px/GHSA-q79f-fxqg-m9px.json b/advisories/unreviewed/2025/05/GHSA-q79f-fxqg-m9px/GHSA-q79f-fxqg-m9px.json index fddc9563a50..bc8fbfe704c 100644 --- a/advisories/unreviewed/2025/05/GHSA-q79f-fxqg-m9px/GHSA-q79f-fxqg-m9px.json +++ b/advisories/unreviewed/2025/05/GHSA-q79f-fxqg-m9px/GHSA-q79f-fxqg-m9px.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q79f-fxqg-m9px", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-20T21:30:40Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-8094" ], "details": "The Ntz Antispam WordPress plugin through 2.0e does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:57Z" diff --git a/advisories/unreviewed/2025/05/GHSA-q8vg-jpq8-qfm6/GHSA-q8vg-jpq8-qfm6.json b/advisories/unreviewed/2025/05/GHSA-q8vg-jpq8-qfm6/GHSA-q8vg-jpq8-qfm6.json index c1943e510ff..4d56335d92a 100644 --- a/advisories/unreviewed/2025/05/GHSA-q8vg-jpq8-qfm6/GHSA-q8vg-jpq8-qfm6.json +++ b/advisories/unreviewed/2025/05/GHSA-q8vg-jpq8-qfm6/GHSA-q8vg-jpq8-qfm6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q8vg-jpq8-qfm6", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-20T21:30:40Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-8187" ], "details": "The Smart Post Show WordPress plugin before 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:58Z" diff --git a/advisories/unreviewed/2025/05/GHSA-qgvm-vj48-358p/GHSA-qgvm-vj48-358p.json b/advisories/unreviewed/2025/05/GHSA-qgvm-vj48-358p/GHSA-qgvm-vj48-358p.json index aa302dcf7e6..a40442ea82c 100644 --- a/advisories/unreviewed/2025/05/GHSA-qgvm-vj48-358p/GHSA-qgvm-vj48-358p.json +++ b/advisories/unreviewed/2025/05/GHSA-qgvm-vj48-358p/GHSA-qgvm-vj48-358p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qgvm-vj48-358p", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-20T21:30:38Z", "published": "2025-05-15T21:31:31Z", "aliases": [ "CVE-2024-6690" ], "details": "The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:55Z" diff --git a/advisories/unreviewed/2025/05/GHSA-qp64-fxm9-hxp3/GHSA-qp64-fxm9-hxp3.json b/advisories/unreviewed/2025/05/GHSA-qp64-fxm9-hxp3/GHSA-qp64-fxm9-hxp3.json new file mode 100644 index 00000000000..8163d46a53c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qp64-fxm9-hxp3/GHSA-qp64-fxm9-hxp3.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp64-fxm9-hxp3", + "modified": "2025-05-20T21:30:44Z", + "published": "2025-05-20T21:30:44Z", + "aliases": [ + "CVE-2025-5000" + ], + "details": "A vulnerability was found in Linksys FGW3000-AH and FGW3000-HK up to 1.0.17.000000. It has been classified as critical. This affects the function control_panel_sw of the file /cgi-bin/sysconf.cgi of the component HTTP POST Request Handler. The manipulation of the argument filename leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5000" + }, + { + "type": "WEB", + "url": "https://github.com/CH13hh/tmp_store_cc/blob/main/FGW3000/2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309651" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309651" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.565992" + }, + { + "type": "WEB", + "url": "https://www.linksys.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T21:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qp9v-5v7f-q6f8/GHSA-qp9v-5v7f-q6f8.json b/advisories/unreviewed/2025/05/GHSA-qp9v-5v7f-q6f8/GHSA-qp9v-5v7f-q6f8.json index fe05d285ed2..88f092574b2 100644 --- a/advisories/unreviewed/2025/05/GHSA-qp9v-5v7f-q6f8/GHSA-qp9v-5v7f-q6f8.json +++ b/advisories/unreviewed/2025/05/GHSA-qp9v-5v7f-q6f8/GHSA-qp9v-5v7f-q6f8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qp9v-5v7f-q6f8", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T21:30:37Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-13727" ], "details": "The MemberSpace WordPress plugin before 2.1.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:39Z" diff --git a/advisories/unreviewed/2025/05/GHSA-qr28-f5f9-2wjf/GHSA-qr28-f5f9-2wjf.json b/advisories/unreviewed/2025/05/GHSA-qr28-f5f9-2wjf/GHSA-qr28-f5f9-2wjf.json index ba1dbe17e6f..7f4f3599472 100644 --- a/advisories/unreviewed/2025/05/GHSA-qr28-f5f9-2wjf/GHSA-qr28-f5f9-2wjf.json +++ b/advisories/unreviewed/2025/05/GHSA-qr28-f5f9-2wjf/GHSA-qr28-f5f9-2wjf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qr28-f5f9-2wjf", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T21:30:37Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-13865" ], "details": "The S3Player WordPress plugin through 4.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:40Z" diff --git a/advisories/unreviewed/2025/05/GHSA-qv2q-53c8-mm8v/GHSA-qv2q-53c8-mm8v.json b/advisories/unreviewed/2025/05/GHSA-qv2q-53c8-mm8v/GHSA-qv2q-53c8-mm8v.json new file mode 100644 index 00000000000..f1cacef7ece --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qv2q-53c8-mm8v/GHSA-qv2q-53c8-mm8v.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv2q-53c8-mm8v", + "modified": "2025-05-20T21:30:43Z", + "published": "2025-05-20T21:30:43Z", + "aliases": [ + "CVE-2025-4996" + ], + "details": "A vulnerability, which was classified as problematic, has been found in Intelbras RF 301K 1.1.5. This issue affects some unknown processing of the component Add Static IP. The manipulation of the argument Description leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4996" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309647" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309647" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.501900" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qvqw-6658-7p9p/GHSA-qvqw-6658-7p9p.json b/advisories/unreviewed/2025/05/GHSA-qvqw-6658-7p9p/GHSA-qvqw-6658-7p9p.json index 2fe3e0297b1..0079701f06b 100644 --- a/advisories/unreviewed/2025/05/GHSA-qvqw-6658-7p9p/GHSA-qvqw-6658-7p9p.json +++ b/advisories/unreviewed/2025/05/GHSA-qvqw-6658-7p9p/GHSA-qvqw-6658-7p9p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qvqw-6658-7p9p", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-20T21:30:39Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-6797" ], "details": "The DL Robots.txt WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:56Z" diff --git a/advisories/unreviewed/2025/05/GHSA-r5wg-fxw7-6v36/GHSA-r5wg-fxw7-6v36.json b/advisories/unreviewed/2025/05/GHSA-r5wg-fxw7-6v36/GHSA-r5wg-fxw7-6v36.json index 780b7f0696c..0bd2edd44fb 100644 --- a/advisories/unreviewed/2025/05/GHSA-r5wg-fxw7-6v36/GHSA-r5wg-fxw7-6v36.json +++ b/advisories/unreviewed/2025/05/GHSA-r5wg-fxw7-6v36/GHSA-r5wg-fxw7-6v36.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r5wg-fxw7-6v36", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T21:30:36Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-13383" ], "details": "The HD Quiz WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:39Z" diff --git a/advisories/unreviewed/2025/05/GHSA-r77g-4w8g-2vqq/GHSA-r77g-4w8g-2vqq.json b/advisories/unreviewed/2025/05/GHSA-r77g-4w8g-2vqq/GHSA-r77g-4w8g-2vqq.json index 7e5ff9521f5..26aba4d97a8 100644 --- a/advisories/unreviewed/2025/05/GHSA-r77g-4w8g-2vqq/GHSA-r77g-4w8g-2vqq.json +++ b/advisories/unreviewed/2025/05/GHSA-r77g-4w8g-2vqq/GHSA-r77g-4w8g-2vqq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r77g-4w8g-2vqq", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T21:30:36Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-12812" ], "details": "The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 has an issue where employees can manipulate parameters to access the data of terminated employees.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:37Z" diff --git a/advisories/unreviewed/2025/05/GHSA-rp4r-xcg3-254c/GHSA-rp4r-xcg3-254c.json b/advisories/unreviewed/2025/05/GHSA-rp4r-xcg3-254c/GHSA-rp4r-xcg3-254c.json new file mode 100644 index 00000000000..5d6e54b03af --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rp4r-xcg3-254c/GHSA-rp4r-xcg3-254c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rp4r-xcg3-254c", + "modified": "2025-05-20T21:30:32Z", + "published": "2025-05-20T21:30:32Z", + "aliases": [ + "CVE-2024-13678" + ], + "details": "The R3W InstaFeed WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13678" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/ba759796-a152-4f13-a474-f0368b4bc1f6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rrc7-p8g9-c7vg/GHSA-rrc7-p8g9-c7vg.json b/advisories/unreviewed/2025/05/GHSA-rrc7-p8g9-c7vg/GHSA-rrc7-p8g9-c7vg.json index 1125d4ddd06..cdce1a319f1 100644 --- a/advisories/unreviewed/2025/05/GHSA-rrc7-p8g9-c7vg/GHSA-rrc7-p8g9-c7vg.json +++ b/advisories/unreviewed/2025/05/GHSA-rrc7-p8g9-c7vg/GHSA-rrc7-p8g9-c7vg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rrc7-p8g9-c7vg", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:36Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-13053" ], "details": "The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:38Z" diff --git a/advisories/unreviewed/2025/05/GHSA-v364-qrc6-2qj4/GHSA-v364-qrc6-2qj4.json b/advisories/unreviewed/2025/05/GHSA-v364-qrc6-2qj4/GHSA-v364-qrc6-2qj4.json index dfe8bee4fb8..ba6ca12d488 100644 --- a/advisories/unreviewed/2025/05/GHSA-v364-qrc6-2qj4/GHSA-v364-qrc6-2qj4.json +++ b/advisories/unreviewed/2025/05/GHSA-v364-qrc6-2qj4/GHSA-v364-qrc6-2qj4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v364-qrc6-2qj4", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:33Z", "published": "2025-05-15T21:31:28Z", "aliases": [ "CVE-2024-12301" ], "details": "The JSP Store Locator WordPress plugin through 1.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:35Z" diff --git a/advisories/unreviewed/2025/05/GHSA-v3q8-hfj4-rq9j/GHSA-v3q8-hfj4-rq9j.json b/advisories/unreviewed/2025/05/GHSA-v3q8-hfj4-rq9j/GHSA-v3q8-hfj4-rq9j.json new file mode 100644 index 00000000000..b9ac8b826bd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v3q8-hfj4-rq9j/GHSA-v3q8-hfj4-rq9j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3q8-hfj4-rq9j", + "modified": "2025-05-20T21:30:43Z", + "published": "2025-05-20T21:30:43Z", + "aliases": [ + "CVE-2025-44881" + ], + "details": "A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44881" + }, + { + "type": "WEB", + "url": "https://lafdrew.github.io/2025/03/31/Remote-Command-Execution-in-qos-cgi-of-wavlink-WL-WN579A3-Device" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T20:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v4h8-jvp4-3vjm/GHSA-v4h8-jvp4-3vjm.json b/advisories/unreviewed/2025/05/GHSA-v4h8-jvp4-3vjm/GHSA-v4h8-jvp4-3vjm.json index 990484711ed..9869f5e4ca4 100644 --- a/advisories/unreviewed/2025/05/GHSA-v4h8-jvp4-3vjm/GHSA-v4h8-jvp4-3vjm.json +++ b/advisories/unreviewed/2025/05/GHSA-v4h8-jvp4-3vjm/GHSA-v4h8-jvp4-3vjm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v4h8-jvp4-3vjm", - "modified": "2025-05-15T21:31:28Z", + "modified": "2025-05-20T21:30:32Z", "published": "2025-05-15T21:31:28Z", "aliases": [ "CVE-2024-11190" ], "details": "The jwp-a11y WordPress plugin through 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:34Z" diff --git a/advisories/unreviewed/2025/05/GHSA-v6jx-8472-465v/GHSA-v6jx-8472-465v.json b/advisories/unreviewed/2025/05/GHSA-v6jx-8472-465v/GHSA-v6jx-8472-465v.json index 96191dfe6c4..38ff369d1e9 100644 --- a/advisories/unreviewed/2025/05/GHSA-v6jx-8472-465v/GHSA-v6jx-8472-465v.json +++ b/advisories/unreviewed/2025/05/GHSA-v6jx-8472-465v/GHSA-v6jx-8472-465v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v6jx-8472-465v", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T21:30:37Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-13619" ], "details": "The LifterLMS WordPress plugin before 8.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:39Z" diff --git a/advisories/unreviewed/2025/05/GHSA-v82c-v3v8-qq2x/GHSA-v82c-v3v8-qq2x.json b/advisories/unreviewed/2025/05/GHSA-v82c-v3v8-qq2x/GHSA-v82c-v3v8-qq2x.json index f1f5cab513f..da3b6854333 100644 --- a/advisories/unreviewed/2025/05/GHSA-v82c-v3v8-qq2x/GHSA-v82c-v3v8-qq2x.json +++ b/advisories/unreviewed/2025/05/GHSA-v82c-v3v8-qq2x/GHSA-v82c-v3v8-qq2x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v82c-v3v8-qq2x", - "modified": "2025-05-15T21:31:33Z", + "modified": "2025-05-20T21:30:41Z", "published": "2025-05-15T21:31:33Z", "aliases": [ "CVE-2024-8618" ], "details": "The Page Builder: Pagelayer WordPress plugin before 1.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:59Z" diff --git a/advisories/unreviewed/2025/05/GHSA-v884-m573-754j/GHSA-v884-m573-754j.json b/advisories/unreviewed/2025/05/GHSA-v884-m573-754j/GHSA-v884-m573-754j.json index e6ee52de93e..5dc8ac5f721 100644 --- a/advisories/unreviewed/2025/05/GHSA-v884-m573-754j/GHSA-v884-m573-754j.json +++ b/advisories/unreviewed/2025/05/GHSA-v884-m573-754j/GHSA-v884-m573-754j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v884-m573-754j", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-20T21:30:40Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-8050" ], "details": "The Custom Author Base WordPress plugin through 1.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:57Z" diff --git a/advisories/unreviewed/2025/05/GHSA-vcr6-vwcj-r3r3/GHSA-vcr6-vwcj-r3r3.json b/advisories/unreviewed/2025/05/GHSA-vcr6-vwcj-r3r3/GHSA-vcr6-vwcj-r3r3.json index e247d117365..60ae9fcb775 100644 --- a/advisories/unreviewed/2025/05/GHSA-vcr6-vwcj-r3r3/GHSA-vcr6-vwcj-r3r3.json +++ b/advisories/unreviewed/2025/05/GHSA-vcr6-vwcj-r3r3/GHSA-vcr6-vwcj-r3r3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vcr6-vwcj-r3r3", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-20T21:30:38Z", "published": "2025-05-15T21:31:31Z", "aliases": [ "CVE-2024-6335" ], "details": "The Tracking Code Manager WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:54Z" diff --git a/advisories/unreviewed/2025/05/GHSA-vf8r-rhw4-6q8g/GHSA-vf8r-rhw4-6q8g.json b/advisories/unreviewed/2025/05/GHSA-vf8r-rhw4-6q8g/GHSA-vf8r-rhw4-6q8g.json index cdfa0b25554..c55ca540f3e 100644 --- a/advisories/unreviewed/2025/05/GHSA-vf8r-rhw4-6q8g/GHSA-vf8r-rhw4-6q8g.json +++ b/advisories/unreviewed/2025/05/GHSA-vf8r-rhw4-6q8g/GHSA-vf8r-rhw4-6q8g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vf8r-rhw4-6q8g", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-20T21:30:38Z", "published": "2025-05-15T21:31:31Z", "aliases": [ "CVE-2024-6478" ], "details": "The CTT Expresso para WooCommerce WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:55Z" diff --git a/advisories/unreviewed/2025/05/GHSA-vg38-3h8m-863x/GHSA-vg38-3h8m-863x.json b/advisories/unreviewed/2025/05/GHSA-vg38-3h8m-863x/GHSA-vg38-3h8m-863x.json index da73d2669ea..6b652e54155 100644 --- a/advisories/unreviewed/2025/05/GHSA-vg38-3h8m-863x/GHSA-vg38-3h8m-863x.json +++ b/advisories/unreviewed/2025/05/GHSA-vg38-3h8m-863x/GHSA-vg38-3h8m-863x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vg38-3h8m-863x", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:33Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-12679" ], "details": "The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:35Z" diff --git a/advisories/unreviewed/2025/05/GHSA-vj3r-c4pc-hrp4/GHSA-vj3r-c4pc-hrp4.json b/advisories/unreviewed/2025/05/GHSA-vj3r-c4pc-hrp4/GHSA-vj3r-c4pc-hrp4.json new file mode 100644 index 00000000000..95311291f59 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vj3r-c4pc-hrp4/GHSA-vj3r-c4pc-hrp4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vj3r-c4pc-hrp4", + "modified": "2025-05-20T21:30:43Z", + "published": "2025-05-20T21:30:43Z", + "aliases": [ + "CVE-2025-44888" + ], + "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the stp_conf_name parameter in the web_stp_globalSetting_post function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44888" + }, + { + "type": "WEB", + "url": "https://lafdrew.github.io/2025/04/20/web-stp-globalSetting-post-stp-conf-name" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T20:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vqmr-vxc7-5wc4/GHSA-vqmr-vxc7-5wc4.json b/advisories/unreviewed/2025/05/GHSA-vqmr-vxc7-5wc4/GHSA-vqmr-vxc7-5wc4.json new file mode 100644 index 00000000000..f1b207e9f3b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vqmr-vxc7-5wc4/GHSA-vqmr-vxc7-5wc4.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqmr-vxc7-5wc4", + "modified": "2025-05-20T21:30:43Z", + "published": "2025-05-20T21:30:43Z", + "aliases": [ + "CVE-2025-4998" + ], + "details": "A vulnerability has been found in H3C Magic R200G up to 100R002 and classified as problematic. Affected by this vulnerability is the function Edit_BasicSSID/Edit_BasicSSID_5G/SetAPWifiorLedInfoById/SetMobileAPInfoById/Asp_SetTimingtimeWifiAndLed/AddMacList/EditMacList/AddWlanMacList/EditWlanMacList of the file /goform/aspForm of the component HTTP POST Request Handler. The manipulation of the argument param leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4998" + }, + { + "type": "WEB", + "url": "https://github.com/CH13hh/tmp_store_cc/blob/main/H3C%20Magic%20R200G/1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309649" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309649" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.563583" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w4q6-qj6g-h25w/GHSA-w4q6-qj6g-h25w.json b/advisories/unreviewed/2025/05/GHSA-w4q6-qj6g-h25w/GHSA-w4q6-qj6g-h25w.json new file mode 100644 index 00000000000..c3c9b43bdc6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w4q6-qj6g-h25w/GHSA-w4q6-qj6g-h25w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4q6-qj6g-h25w", + "modified": "2025-05-20T21:30:43Z", + "published": "2025-05-20T21:30:43Z", + "aliases": [ + "CVE-2025-44897" + ], + "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bytftp_srvip parameter in the web_tool_upgradeManager_post function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44897" + }, + { + "type": "WEB", + "url": "https://lafdrew.github.io/2025/04/20/web-tool-upgradeManager-post-tftp-srvip" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w589-4j7g-6889/GHSA-w589-4j7g-6889.json b/advisories/unreviewed/2025/05/GHSA-w589-4j7g-6889/GHSA-w589-4j7g-6889.json index 46e08ed5b20..2944ffbb09c 100644 --- a/advisories/unreviewed/2025/05/GHSA-w589-4j7g-6889/GHSA-w589-4j7g-6889.json +++ b/advisories/unreviewed/2025/05/GHSA-w589-4j7g-6889/GHSA-w589-4j7g-6889.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w589-4j7g-6889", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-20T21:30:38Z", "published": "2025-05-15T21:31:31Z", "aliases": [ "CVE-2024-6159" ], "details": "The Push Notification for Post and BuddyPress WordPress plugin before 1.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:54Z" diff --git a/advisories/unreviewed/2025/05/GHSA-w7g4-p5vp-3m77/GHSA-w7g4-p5vp-3m77.json b/advisories/unreviewed/2025/05/GHSA-w7g4-p5vp-3m77/GHSA-w7g4-p5vp-3m77.json index 8ee14e26683..201a642364f 100644 --- a/advisories/unreviewed/2025/05/GHSA-w7g4-p5vp-3m77/GHSA-w7g4-p5vp-3m77.json +++ b/advisories/unreviewed/2025/05/GHSA-w7g4-p5vp-3m77/GHSA-w7g4-p5vp-3m77.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w7g4-p5vp-3m77", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-20T21:30:40Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-8032" ], "details": "The Smooth Gallery Replacement WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:57Z" diff --git a/advisories/unreviewed/2025/05/GHSA-w7g5-m4q3-r22v/GHSA-w7g5-m4q3-r22v.json b/advisories/unreviewed/2025/05/GHSA-w7g5-m4q3-r22v/GHSA-w7g5-m4q3-r22v.json index a17fd6dc8f1..f323dde42f9 100644 --- a/advisories/unreviewed/2025/05/GHSA-w7g5-m4q3-r22v/GHSA-w7g5-m4q3-r22v.json +++ b/advisories/unreviewed/2025/05/GHSA-w7g5-m4q3-r22v/GHSA-w7g5-m4q3-r22v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w7g5-m4q3-r22v", - "modified": "2025-05-15T21:31:34Z", + "modified": "2025-05-20T21:30:42Z", "published": "2025-05-15T21:31:34Z", "aliases": [ "CVE-2025-1033" ], "details": "The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:16:02Z" diff --git a/advisories/unreviewed/2025/05/GHSA-w97m-g6h7-95c2/GHSA-w97m-g6h7-95c2.json b/advisories/unreviewed/2025/05/GHSA-w97m-g6h7-95c2/GHSA-w97m-g6h7-95c2.json index 7e9fc64e7f5..f72c165ce6b 100644 --- a/advisories/unreviewed/2025/05/GHSA-w97m-g6h7-95c2/GHSA-w97m-g6h7-95c2.json +++ b/advisories/unreviewed/2025/05/GHSA-w97m-g6h7-95c2/GHSA-w97m-g6h7-95c2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w97m-g6h7-95c2", - "modified": "2025-05-15T21:31:32Z", + "modified": "2025-05-20T21:30:40Z", "published": "2025-05-15T21:31:32Z", "aliases": [ "CVE-2024-8085" ], "details": "The PeoplePond WordPress plugin through 1.1.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:57Z" diff --git a/advisories/unreviewed/2025/05/GHSA-wjgg-2chr-56vm/GHSA-wjgg-2chr-56vm.json b/advisories/unreviewed/2025/05/GHSA-wjgg-2chr-56vm/GHSA-wjgg-2chr-56vm.json index 0a5a6b42cd9..0b614514e5b 100644 --- a/advisories/unreviewed/2025/05/GHSA-wjgg-2chr-56vm/GHSA-wjgg-2chr-56vm.json +++ b/advisories/unreviewed/2025/05/GHSA-wjgg-2chr-56vm/GHSA-wjgg-2chr-56vm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wjgg-2chr-56vm", - "modified": "2025-05-15T21:31:28Z", + "modified": "2025-05-20T21:30:32Z", "published": "2025-05-15T21:31:28Z", "aliases": [ "CVE-2024-10677" ], "details": "The BTEV WordPress plugin through 2.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:33Z" diff --git a/advisories/unreviewed/2025/05/GHSA-x468-pj97-v469/GHSA-x468-pj97-v469.json b/advisories/unreviewed/2025/05/GHSA-x468-pj97-v469/GHSA-x468-pj97-v469.json index f21727122fb..d66201e8cfa 100644 --- a/advisories/unreviewed/2025/05/GHSA-x468-pj97-v469/GHSA-x468-pj97-v469.json +++ b/advisories/unreviewed/2025/05/GHSA-x468-pj97-v469/GHSA-x468-pj97-v469.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x468-pj97-v469", - "modified": "2025-05-15T21:31:33Z", + "modified": "2025-05-20T21:30:41Z", "published": "2025-05-15T21:31:33Z", "aliases": [ "CVE-2024-8700" ], "details": "The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:59Z" diff --git a/advisories/unreviewed/2025/05/GHSA-x5f2-w3c3-pvvg/GHSA-x5f2-w3c3-pvvg.json b/advisories/unreviewed/2025/05/GHSA-x5f2-w3c3-pvvg/GHSA-x5f2-w3c3-pvvg.json index 68aee48a1cc..a2ebc7266e4 100644 --- a/advisories/unreviewed/2025/05/GHSA-x5f2-w3c3-pvvg/GHSA-x5f2-w3c3-pvvg.json +++ b/advisories/unreviewed/2025/05/GHSA-x5f2-w3c3-pvvg/GHSA-x5f2-w3c3-pvvg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x5f2-w3c3-pvvg", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T21:30:35Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-12800" ], "details": "The IP Based Login WordPress plugin before 2.4.1 does not sanitise values when importing, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:37Z" diff --git a/advisories/unreviewed/2025/05/GHSA-x7pf-mv6r-v5x9/GHSA-x7pf-mv6r-v5x9.json b/advisories/unreviewed/2025/05/GHSA-x7pf-mv6r-v5x9/GHSA-x7pf-mv6r-v5x9.json index 26f32c30bf8..5964f0fdb49 100644 --- a/advisories/unreviewed/2025/05/GHSA-x7pf-mv6r-v5x9/GHSA-x7pf-mv6r-v5x9.json +++ b/advisories/unreviewed/2025/05/GHSA-x7pf-mv6r-v5x9/GHSA-x7pf-mv6r-v5x9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x7pf-mv6r-v5x9", - "modified": "2025-05-15T21:31:33Z", + "modified": "2025-05-20T21:30:41Z", "published": "2025-05-15T21:31:33Z", "aliases": [ "CVE-2024-8670" ], "details": "The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:59Z" diff --git a/advisories/unreviewed/2025/05/GHSA-x8qc-qf2g-j5w3/GHSA-x8qc-qf2g-j5w3.json b/advisories/unreviewed/2025/05/GHSA-x8qc-qf2g-j5w3/GHSA-x8qc-qf2g-j5w3.json index c7d3d1a7bc6..fb367f5a04d 100644 --- a/advisories/unreviewed/2025/05/GHSA-x8qc-qf2g-j5w3/GHSA-x8qc-qf2g-j5w3.json +++ b/advisories/unreviewed/2025/05/GHSA-x8qc-qf2g-j5w3/GHSA-x8qc-qf2g-j5w3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x8qc-qf2g-j5w3", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:32Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-11502" ], "details": "The Planning Center Online Giving WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:35Z" diff --git a/advisories/unreviewed/2025/05/GHSA-x8r2-wrm6-4v97/GHSA-x8r2-wrm6-4v97.json b/advisories/unreviewed/2025/05/GHSA-x8r2-wrm6-4v97/GHSA-x8r2-wrm6-4v97.json index 0fddf88c076..5a7b403c8f0 100644 --- a/advisories/unreviewed/2025/05/GHSA-x8r2-wrm6-4v97/GHSA-x8r2-wrm6-4v97.json +++ b/advisories/unreviewed/2025/05/GHSA-x8r2-wrm6-4v97/GHSA-x8r2-wrm6-4v97.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-x9pw-qp8j-96f9/GHSA-x9pw-qp8j-96f9.json b/advisories/unreviewed/2025/05/GHSA-x9pw-qp8j-96f9/GHSA-x9pw-qp8j-96f9.json new file mode 100644 index 00000000000..14cde307a68 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x9pw-qp8j-96f9/GHSA-x9pw-qp8j-96f9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9pw-qp8j-96f9", + "modified": "2025-05-20T21:30:42Z", + "published": "2025-05-20T21:30:42Z", + "aliases": [ + "CVE-2025-44893" + ], + "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt_Rules_Apply_post function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44893" + }, + { + "type": "WEB", + "url": "https://lafdrew.github.io/2025/04/20/web-acl-mgmt-Rules-Apply-post-ruleName" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T20:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xfj4-w5m6-x8f6/GHSA-xfj4-w5m6-x8f6.json b/advisories/unreviewed/2025/05/GHSA-xfj4-w5m6-x8f6/GHSA-xfj4-w5m6-x8f6.json new file mode 100644 index 00000000000..29e7903953e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xfj4-w5m6-x8f6/GHSA-xfj4-w5m6-x8f6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xfj4-w5m6-x8f6", + "modified": "2025-05-20T21:30:43Z", + "published": "2025-05-20T21:30:42Z", + "aliases": [ + "CVE-2025-44886" + ], + "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the byruleEditName parameter in the web_acl_mgmt_Rules_Edit_postcontains function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44886" + }, + { + "type": "WEB", + "url": "https://lafdrew.github.io/2025/04/20/web-acl-mgmt-Rules-Edit-post-ruleEditName" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T20:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xj6f-gh33-gmgg/GHSA-xj6f-gh33-gmgg.json b/advisories/unreviewed/2025/05/GHSA-xj6f-gh33-gmgg/GHSA-xj6f-gh33-gmgg.json new file mode 100644 index 00000000000..2ca11218a2e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xj6f-gh33-gmgg/GHSA-xj6f-gh33-gmgg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xj6f-gh33-gmgg", + "modified": "2025-05-20T21:30:42Z", + "published": "2025-05-20T21:30:42Z", + "aliases": [ + "CVE-2025-44887" + ], + "details": "FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44887" + }, + { + "type": "WEB", + "url": "https://lafdrew.github.io/2025/04/20/web-radiusSrv-post-radIp" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T20:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xqrc-6556-5gcq/GHSA-xqrc-6556-5gcq.json b/advisories/unreviewed/2025/05/GHSA-xqrc-6556-5gcq/GHSA-xqrc-6556-5gcq.json index a5037f2cd6f..582b47c072a 100644 --- a/advisories/unreviewed/2025/05/GHSA-xqrc-6556-5gcq/GHSA-xqrc-6556-5gcq.json +++ b/advisories/unreviewed/2025/05/GHSA-xqrc-6556-5gcq/GHSA-xqrc-6556-5gcq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xqrc-6556-5gcq", - "modified": "2025-05-15T21:31:29Z", + "modified": "2025-05-20T21:30:34Z", "published": "2025-05-15T21:31:29Z", "aliases": [ "CVE-2024-12724" ], "details": "The WP DeskLite WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:36Z" diff --git a/advisories/unreviewed/2025/05/GHSA-xvf2-x5rr-6g4q/GHSA-xvf2-x5rr-6g4q.json b/advisories/unreviewed/2025/05/GHSA-xvf2-x5rr-6g4q/GHSA-xvf2-x5rr-6g4q.json index 3558424e82b..5b4f67e68e8 100644 --- a/advisories/unreviewed/2025/05/GHSA-xvf2-x5rr-6g4q/GHSA-xvf2-x5rr-6g4q.json +++ b/advisories/unreviewed/2025/05/GHSA-xvf2-x5rr-6g4q/GHSA-xvf2-x5rr-6g4q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xvf2-x5rr-6g4q", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-20T21:30:39Z", "published": "2025-05-15T21:31:31Z", "aliases": [ "CVE-2024-6693" ], "details": "The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:55Z" diff --git a/advisories/unreviewed/2025/05/GHSA-xw9h-x6h4-fc8r/GHSA-xw9h-x6h4-fc8r.json b/advisories/unreviewed/2025/05/GHSA-xw9h-x6h4-fc8r/GHSA-xw9h-x6h4-fc8r.json index ae4246e953a..84dfd678595 100644 --- a/advisories/unreviewed/2025/05/GHSA-xw9h-x6h4-fc8r/GHSA-xw9h-x6h4-fc8r.json +++ b/advisories/unreviewed/2025/05/GHSA-xw9h-x6h4-fc8r/GHSA-xw9h-x6h4-fc8r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xw9h-x6h4-fc8r", - "modified": "2025-05-15T21:31:30Z", + "modified": "2025-05-20T21:30:37Z", "published": "2025-05-15T21:31:30Z", "aliases": [ "CVE-2024-13828" ], "details": "The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:40Z" diff --git a/advisories/unreviewed/2025/05/GHSA-xwv7-jv97-x2cg/GHSA-xwv7-jv97-x2cg.json b/advisories/unreviewed/2025/05/GHSA-xwv7-jv97-x2cg/GHSA-xwv7-jv97-x2cg.json index c14aa3a75cd..4168a29fe68 100644 --- a/advisories/unreviewed/2025/05/GHSA-xwv7-jv97-x2cg/GHSA-xwv7-jv97-x2cg.json +++ b/advisories/unreviewed/2025/05/GHSA-xwv7-jv97-x2cg/GHSA-xwv7-jv97-x2cg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xwv7-jv97-x2cg", - "modified": "2025-05-15T21:31:34Z", + "modified": "2025-05-20T21:30:42Z", "published": "2025-05-15T21:31:34Z", "aliases": [ "CVE-2025-1286" ], "details": "The Download HTML TinyMCE Button WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:16:02Z"