From e770b44937cc51d35f3ecc3819178f65d3b66de7 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 27 Mar 2025 12:32:12 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-cg5m-p8pg-93cg.json | 5 ++- .../GHSA-g46h-v66c-w8j9.json | 3 +- .../GHSA-29w2-8xf2-3r76.json | 36 +++++++++++++++++ .../GHSA-2h2q-74g8-r928.json | 36 +++++++++++++++++ .../GHSA-2m8r-5qhj-3fj7.json | 36 +++++++++++++++++ .../GHSA-2pm5-4pq3-87vj.json | 36 +++++++++++++++++ .../GHSA-2q4j-vw33-3v48.json | 36 +++++++++++++++++ .../GHSA-2wcw-5cjw-6vvc.json | 36 +++++++++++++++++ .../GHSA-333p-49h6-q8x3.json | 36 +++++++++++++++++ .../GHSA-35wx-v489-5vx6.json | 36 +++++++++++++++++ .../GHSA-39hm-72f3-v7g5.json | 36 +++++++++++++++++ .../GHSA-3rcf-g93x-vh3q.json | 36 +++++++++++++++++ .../GHSA-3xr9-6gqg-crhm.json | 36 +++++++++++++++++ .../GHSA-4cf8-g4pg-xxgx.json | 36 +++++++++++++++++ .../GHSA-4cqp-8pqq-phx4.json | 36 +++++++++++++++++ .../GHSA-4h4w-ghj2-qq29.json | 36 +++++++++++++++++ .../GHSA-4j5q-99p5-6474.json | 36 +++++++++++++++++ .../GHSA-4px8-8h5w-7vjp.json | 36 +++++++++++++++++ .../GHSA-5668-2qvm-f379.json | 36 +++++++++++++++++ .../GHSA-56fh-r9cp-h38v.json | 36 +++++++++++++++++ .../GHSA-58q6-pf3m-3mmp.json | 36 +++++++++++++++++ .../GHSA-5hgx-hrhf-w9m2.json | 36 +++++++++++++++++ .../GHSA-5vcc-mv82-47r3.json | 36 +++++++++++++++++ .../GHSA-62vh-3h8m-r6v7.json | 36 +++++++++++++++++ .../GHSA-63x6-9wf8-mmhm.json | 36 +++++++++++++++++ .../GHSA-67vp-3jr4-fr25.json | 36 +++++++++++++++++ .../GHSA-68q3-w8qh-6ccx.json | 36 +++++++++++++++++ .../GHSA-6975-55r6-82m5.json | 36 +++++++++++++++++ .../GHSA-6hvm-wxhp-cc87.json | 36 +++++++++++++++++ .../GHSA-6mj8-c74f-xjxv.json | 36 +++++++++++++++++ .../GHSA-6pvc-73mw-q5m6.json | 36 +++++++++++++++++ .../GHSA-6xxm-jx55-r734.json | 36 +++++++++++++++++ .../GHSA-734p-q4p5-pqxr.json | 36 +++++++++++++++++ .../GHSA-754m-7w2g-84q3.json | 36 +++++++++++++++++ .../GHSA-77gh-56wm-q4rx.json | 36 +++++++++++++++++ .../GHSA-78jc-mm83-fpr5.json | 36 +++++++++++++++++ .../GHSA-793r-p6pf-pxvj.json | 36 +++++++++++++++++ .../GHSA-7c42-x8gc-fmvq.json | 36 +++++++++++++++++ .../GHSA-7fxg-279r-rhqq.json | 36 +++++++++++++++++ .../GHSA-7hjv-369x-3cwv.json | 36 +++++++++++++++++ .../GHSA-7prm-xhfc-rpv3.json | 36 +++++++++++++++++ .../GHSA-7v39-9g8v-3xw9.json | 36 +++++++++++++++++ .../GHSA-7x3g-q3pp-h6vc.json | 36 +++++++++++++++++ .../GHSA-844v-fv9f-vwrm.json | 36 +++++++++++++++++ .../GHSA-85r5-jr4g-929w.json | 36 +++++++++++++++++ .../GHSA-8c9h-3vrw-wm5g.json | 36 +++++++++++++++++ .../GHSA-8ghx-hvh4-2xqh.json | 36 +++++++++++++++++ .../GHSA-8gq8-fx5p-97wr.json | 36 +++++++++++++++++ .../GHSA-8w7v-wg9w-c7jm.json | 36 +++++++++++++++++ .../GHSA-8x8v-fchv-5c38.json | 36 +++++++++++++++++ .../GHSA-928p-7p66-959p.json | 36 +++++++++++++++++ .../GHSA-9f59-hcqf-jhx4.json | 36 +++++++++++++++++ .../GHSA-9f5g-g6xj-3q44.json | 36 +++++++++++++++++ .../GHSA-9hpv-6cfm-9c9q.json | 36 +++++++++++++++++ .../GHSA-9v27-96h9-9xrq.json | 36 +++++++++++++++++ .../GHSA-c5px-mrpf-jph6.json | 36 +++++++++++++++++ .../GHSA-cpxp-6rch-m2c3.json | 36 +++++++++++++++++ .../GHSA-crfg-5924-rr3v.json | 36 +++++++++++++++++ .../GHSA-f8w7-gf8j-vvv3.json | 36 +++++++++++++++++ .../GHSA-f92x-c56c-pf59.json | 36 +++++++++++++++++ .../GHSA-ffj3-w9r8-4m9m.json | 36 +++++++++++++++++ .../GHSA-fhpg-4j4x-74cv.json | 36 +++++++++++++++++ .../GHSA-fhw5-vp5p-7wxx.json | 36 +++++++++++++++++ .../GHSA-fxjm-4m3m-24xv.json | 40 +++++++++++++++++++ .../GHSA-g829-4gfh-rg4v.json | 36 +++++++++++++++++ .../GHSA-g8wj-xwrp-45vq.json | 36 +++++++++++++++++ .../GHSA-g9fj-vvm8-xfvj.json | 36 +++++++++++++++++ .../GHSA-gh86-cj5c-g55j.json | 36 +++++++++++++++++ .../GHSA-gh9x-wq33-hmvv.json | 36 +++++++++++++++++ .../GHSA-gjhw-839g-27wc.json | 36 +++++++++++++++++ .../GHSA-gp5w-jxvw-43ff.json | 36 +++++++++++++++++ .../GHSA-gq83-8fqj-xc3j.json | 36 +++++++++++++++++ .../GHSA-gv5c-qwvr-2qq7.json | 36 +++++++++++++++++ .../GHSA-h4p3-ffc4-4vw5.json | 36 +++++++++++++++++ .../GHSA-h535-j96r-875v.json | 36 +++++++++++++++++ .../GHSA-h5gw-682p-v2c8.json | 36 +++++++++++++++++ .../GHSA-h5q6-96r6-f7qq.json | 36 +++++++++++++++++ .../GHSA-h9pf-446x-9hv5.json | 36 +++++++++++++++++ .../GHSA-hhmh-4792-pf49.json | 36 +++++++++++++++++ .../GHSA-hmgv-7gr3-j5q3.json | 36 +++++++++++++++++ .../GHSA-hp8h-p3w5-3x52.json | 36 +++++++++++++++++ .../GHSA-j878-h237-vhcm.json | 36 +++++++++++++++++ .../GHSA-jg55-46h5-pq76.json | 36 +++++++++++++++++ .../GHSA-jmhj-4wgh-cqpx.json | 36 +++++++++++++++++ .../GHSA-m99c-f758-cpx9.json | 36 +++++++++++++++++ .../GHSA-m9v4-8vpr-cf66.json | 36 +++++++++++++++++ .../GHSA-mc44-cf28-88w6.json | 36 +++++++++++++++++ .../GHSA-mc5q-7r6f-q289.json | 36 +++++++++++++++++ .../GHSA-mr63-pqhx-87fh.json | 36 +++++++++++++++++ .../GHSA-mx8c-52f3-fxr6.json | 36 +++++++++++++++++ .../GHSA-p26f-fw78-p227.json | 36 +++++++++++++++++ .../GHSA-p5hx-48gr-36cj.json | 36 +++++++++++++++++ .../GHSA-p8xc-gghv-3vfp.json | 36 +++++++++++++++++ .../GHSA-pj72-96mg-hvmq.json | 36 +++++++++++++++++ .../GHSA-q3h2-vr58-4cr3.json | 36 +++++++++++++++++ .../GHSA-qcm4-6wmx-254g.json | 36 +++++++++++++++++ .../GHSA-qhwm-jg9v-rw55.json | 36 +++++++++++++++++ .../GHSA-qm5m-qmr4-7xjp.json | 36 +++++++++++++++++ .../GHSA-qrww-fvjf-83pv.json | 36 +++++++++++++++++ .../GHSA-qxch-j636-m8qc.json | 36 +++++++++++++++++ .../GHSA-r2rj-82xh-h6px.json | 36 +++++++++++++++++ .../GHSA-r73f-pr65-xxgg.json | 36 +++++++++++++++++ .../GHSA-rpjr-7xhj-qm95.json | 36 +++++++++++++++++ .../GHSA-rv5p-vq45-gc4r.json | 36 +++++++++++++++++ .../GHSA-v2fq-9w48-jj62.json | 36 +++++++++++++++++ .../GHSA-v6p2-q97p-rvqj.json | 36 +++++++++++++++++ .../GHSA-v6pj-45gc-fg24.json | 36 +++++++++++++++++ .../GHSA-vph9-j5h2-h3xp.json | 36 +++++++++++++++++ .../GHSA-w2c7-4rv6-wc59.json | 36 +++++++++++++++++ .../GHSA-w2qm-hvp5-mjwc.json | 36 +++++++++++++++++ .../GHSA-w755-j5x5-cpjx.json | 36 +++++++++++++++++ .../GHSA-w89r-rwcf-75w7.json | 36 +++++++++++++++++ .../GHSA-w978-xrc7-3v35.json | 36 +++++++++++++++++ .../GHSA-wcr9-xqp2-2pqv.json | 36 +++++++++++++++++ .../GHSA-wg9v-hwjw-wm7j.json | 36 +++++++++++++++++ .../GHSA-x3cf-5gqm-6j2g.json | 36 +++++++++++++++++ .../GHSA-x4qh-62jr-rhwm.json | 36 +++++++++++++++++ .../GHSA-x6cg-v5q2-p8xv.json | 36 +++++++++++++++++ .../GHSA-x728-fv32-49g6.json | 36 +++++++++++++++++ .../GHSA-xg7j-j7fr-8hhf.json | 36 +++++++++++++++++ .../GHSA-xpxj-fcm9-9v47.json | 36 +++++++++++++++++ .../GHSA-xx43-h94m-wj64.json | 36 +++++++++++++++++ 122 files changed, 4329 insertions(+), 3 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-29w2-8xf2-3r76/GHSA-29w2-8xf2-3r76.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2h2q-74g8-r928/GHSA-2h2q-74g8-r928.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2m8r-5qhj-3fj7/GHSA-2m8r-5qhj-3fj7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2pm5-4pq3-87vj/GHSA-2pm5-4pq3-87vj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2q4j-vw33-3v48/GHSA-2q4j-vw33-3v48.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2wcw-5cjw-6vvc/GHSA-2wcw-5cjw-6vvc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-333p-49h6-q8x3/GHSA-333p-49h6-q8x3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-35wx-v489-5vx6/GHSA-35wx-v489-5vx6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-39hm-72f3-v7g5/GHSA-39hm-72f3-v7g5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3rcf-g93x-vh3q/GHSA-3rcf-g93x-vh3q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3xr9-6gqg-crhm/GHSA-3xr9-6gqg-crhm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4cf8-g4pg-xxgx/GHSA-4cf8-g4pg-xxgx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4cqp-8pqq-phx4/GHSA-4cqp-8pqq-phx4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4h4w-ghj2-qq29/GHSA-4h4w-ghj2-qq29.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4j5q-99p5-6474/GHSA-4j5q-99p5-6474.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4px8-8h5w-7vjp/GHSA-4px8-8h5w-7vjp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5668-2qvm-f379/GHSA-5668-2qvm-f379.json create mode 100644 advisories/unreviewed/2025/03/GHSA-56fh-r9cp-h38v/GHSA-56fh-r9cp-h38v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-58q6-pf3m-3mmp/GHSA-58q6-pf3m-3mmp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5hgx-hrhf-w9m2/GHSA-5hgx-hrhf-w9m2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5vcc-mv82-47r3/GHSA-5vcc-mv82-47r3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-62vh-3h8m-r6v7/GHSA-62vh-3h8m-r6v7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-63x6-9wf8-mmhm/GHSA-63x6-9wf8-mmhm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-67vp-3jr4-fr25/GHSA-67vp-3jr4-fr25.json create mode 100644 advisories/unreviewed/2025/03/GHSA-68q3-w8qh-6ccx/GHSA-68q3-w8qh-6ccx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6975-55r6-82m5/GHSA-6975-55r6-82m5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6hvm-wxhp-cc87/GHSA-6hvm-wxhp-cc87.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6mj8-c74f-xjxv/GHSA-6mj8-c74f-xjxv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6pvc-73mw-q5m6/GHSA-6pvc-73mw-q5m6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6xxm-jx55-r734/GHSA-6xxm-jx55-r734.json create mode 100644 advisories/unreviewed/2025/03/GHSA-734p-q4p5-pqxr/GHSA-734p-q4p5-pqxr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-754m-7w2g-84q3/GHSA-754m-7w2g-84q3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-77gh-56wm-q4rx/GHSA-77gh-56wm-q4rx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-78jc-mm83-fpr5/GHSA-78jc-mm83-fpr5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-793r-p6pf-pxvj/GHSA-793r-p6pf-pxvj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7c42-x8gc-fmvq/GHSA-7c42-x8gc-fmvq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7fxg-279r-rhqq/GHSA-7fxg-279r-rhqq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7hjv-369x-3cwv/GHSA-7hjv-369x-3cwv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7prm-xhfc-rpv3/GHSA-7prm-xhfc-rpv3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7v39-9g8v-3xw9/GHSA-7v39-9g8v-3xw9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7x3g-q3pp-h6vc/GHSA-7x3g-q3pp-h6vc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-844v-fv9f-vwrm/GHSA-844v-fv9f-vwrm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-85r5-jr4g-929w/GHSA-85r5-jr4g-929w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8c9h-3vrw-wm5g/GHSA-8c9h-3vrw-wm5g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8ghx-hvh4-2xqh/GHSA-8ghx-hvh4-2xqh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8gq8-fx5p-97wr/GHSA-8gq8-fx5p-97wr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8w7v-wg9w-c7jm/GHSA-8w7v-wg9w-c7jm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8x8v-fchv-5c38/GHSA-8x8v-fchv-5c38.json create mode 100644 advisories/unreviewed/2025/03/GHSA-928p-7p66-959p/GHSA-928p-7p66-959p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9f59-hcqf-jhx4/GHSA-9f59-hcqf-jhx4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9f5g-g6xj-3q44/GHSA-9f5g-g6xj-3q44.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9hpv-6cfm-9c9q/GHSA-9hpv-6cfm-9c9q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9v27-96h9-9xrq/GHSA-9v27-96h9-9xrq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c5px-mrpf-jph6/GHSA-c5px-mrpf-jph6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cpxp-6rch-m2c3/GHSA-cpxp-6rch-m2c3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-crfg-5924-rr3v/GHSA-crfg-5924-rr3v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f8w7-gf8j-vvv3/GHSA-f8w7-gf8j-vvv3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f92x-c56c-pf59/GHSA-f92x-c56c-pf59.json create mode 100644 advisories/unreviewed/2025/03/GHSA-ffj3-w9r8-4m9m/GHSA-ffj3-w9r8-4m9m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fhpg-4j4x-74cv/GHSA-fhpg-4j4x-74cv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fhw5-vp5p-7wxx/GHSA-fhw5-vp5p-7wxx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fxjm-4m3m-24xv/GHSA-fxjm-4m3m-24xv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g829-4gfh-rg4v/GHSA-g829-4gfh-rg4v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g8wj-xwrp-45vq/GHSA-g8wj-xwrp-45vq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g9fj-vvm8-xfvj/GHSA-g9fj-vvm8-xfvj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gh86-cj5c-g55j/GHSA-gh86-cj5c-g55j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gh9x-wq33-hmvv/GHSA-gh9x-wq33-hmvv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gjhw-839g-27wc/GHSA-gjhw-839g-27wc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gp5w-jxvw-43ff/GHSA-gp5w-jxvw-43ff.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gq83-8fqj-xc3j/GHSA-gq83-8fqj-xc3j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gv5c-qwvr-2qq7/GHSA-gv5c-qwvr-2qq7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h4p3-ffc4-4vw5/GHSA-h4p3-ffc4-4vw5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h535-j96r-875v/GHSA-h535-j96r-875v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h5gw-682p-v2c8/GHSA-h5gw-682p-v2c8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h5q6-96r6-f7qq/GHSA-h5q6-96r6-f7qq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h9pf-446x-9hv5/GHSA-h9pf-446x-9hv5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hhmh-4792-pf49/GHSA-hhmh-4792-pf49.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hmgv-7gr3-j5q3/GHSA-hmgv-7gr3-j5q3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hp8h-p3w5-3x52/GHSA-hp8h-p3w5-3x52.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j878-h237-vhcm/GHSA-j878-h237-vhcm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jg55-46h5-pq76/GHSA-jg55-46h5-pq76.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jmhj-4wgh-cqpx/GHSA-jmhj-4wgh-cqpx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m99c-f758-cpx9/GHSA-m99c-f758-cpx9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m9v4-8vpr-cf66/GHSA-m9v4-8vpr-cf66.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mc44-cf28-88w6/GHSA-mc44-cf28-88w6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mc5q-7r6f-q289/GHSA-mc5q-7r6f-q289.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mr63-pqhx-87fh/GHSA-mr63-pqhx-87fh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mx8c-52f3-fxr6/GHSA-mx8c-52f3-fxr6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p26f-fw78-p227/GHSA-p26f-fw78-p227.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p5hx-48gr-36cj/GHSA-p5hx-48gr-36cj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p8xc-gghv-3vfp/GHSA-p8xc-gghv-3vfp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pj72-96mg-hvmq/GHSA-pj72-96mg-hvmq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q3h2-vr58-4cr3/GHSA-q3h2-vr58-4cr3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qcm4-6wmx-254g/GHSA-qcm4-6wmx-254g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qhwm-jg9v-rw55/GHSA-qhwm-jg9v-rw55.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qm5m-qmr4-7xjp/GHSA-qm5m-qmr4-7xjp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qrww-fvjf-83pv/GHSA-qrww-fvjf-83pv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qxch-j636-m8qc/GHSA-qxch-j636-m8qc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r2rj-82xh-h6px/GHSA-r2rj-82xh-h6px.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r73f-pr65-xxgg/GHSA-r73f-pr65-xxgg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rpjr-7xhj-qm95/GHSA-rpjr-7xhj-qm95.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rv5p-vq45-gc4r/GHSA-rv5p-vq45-gc4r.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v2fq-9w48-jj62/GHSA-v2fq-9w48-jj62.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v6p2-q97p-rvqj/GHSA-v6p2-q97p-rvqj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v6pj-45gc-fg24/GHSA-v6pj-45gc-fg24.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vph9-j5h2-h3xp/GHSA-vph9-j5h2-h3xp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w2c7-4rv6-wc59/GHSA-w2c7-4rv6-wc59.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w2qm-hvp5-mjwc/GHSA-w2qm-hvp5-mjwc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w755-j5x5-cpjx/GHSA-w755-j5x5-cpjx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w89r-rwcf-75w7/GHSA-w89r-rwcf-75w7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w978-xrc7-3v35/GHSA-w978-xrc7-3v35.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wcr9-xqp2-2pqv/GHSA-wcr9-xqp2-2pqv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wg9v-hwjw-wm7j/GHSA-wg9v-hwjw-wm7j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x3cf-5gqm-6j2g/GHSA-x3cf-5gqm-6j2g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x4qh-62jr-rhwm/GHSA-x4qh-62jr-rhwm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x6cg-v5q2-p8xv/GHSA-x6cg-v5q2-p8xv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x728-fv32-49g6/GHSA-x728-fv32-49g6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xg7j-j7fr-8hhf/GHSA-xg7j-j7fr-8hhf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xpxj-fcm9-9v47/GHSA-xpxj-fcm9-9v47.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xx43-h94m-wj64/GHSA-xx43-h94m-wj64.json diff --git a/advisories/unreviewed/2024/02/GHSA-cg5m-p8pg-93cg/GHSA-cg5m-p8pg-93cg.json b/advisories/unreviewed/2024/02/GHSA-cg5m-p8pg-93cg/GHSA-cg5m-p8pg-93cg.json index b8d91bfc25f..4cbe6b40335 100644 --- a/advisories/unreviewed/2024/02/GHSA-cg5m-p8pg-93cg/GHSA-cg5m-p8pg-93cg.json +++ b/advisories/unreviewed/2024/02/GHSA-cg5m-p8pg-93cg/GHSA-cg5m-p8pg-93cg.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-cg5m-p8pg-93cg", - "modified": "2024-02-26T18:30:29Z", + "modified": "2025-03-27T12:30:34Z", "published": "2024-02-26T18:30:29Z", "aliases": [ "CVE-2024-0436" ], - "details": "Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password protection mode via a timing attack given the linear nature of the `!==` used for comparison.\n\nThe risk is minified by the additional overhead of the request, which varies in a non-constant nature making the attack less reliable to execute ", + "details": "Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password protection mode via a timing attack given the linear nature of the `!==` used for comparison.\n\nThe risk is minified by the additional overhead of the request, which varies in a non-constant nature making the attack less reliable to execute", "severity": [ { "type": "CVSS_V3", @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-764" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/02/GHSA-g46h-v66c-w8j9/GHSA-g46h-v66c-w8j9.json b/advisories/unreviewed/2024/02/GHSA-g46h-v66c-w8j9/GHSA-g46h-v66c-w8j9.json index fcfc9b2d66d..a9b7f13537b 100644 --- a/advisories/unreviewed/2024/02/GHSA-g46h-v66c-w8j9/GHSA-g46h-v66c-w8j9.json +++ b/advisories/unreviewed/2024/02/GHSA-g46h-v66c-w8j9/GHSA-g46h-v66c-w8j9.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-22" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-29w2-8xf2-3r76/GHSA-29w2-8xf2-3r76.json b/advisories/unreviewed/2025/03/GHSA-29w2-8xf2-3r76/GHSA-29w2-8xf2-3r76.json new file mode 100644 index 00000000000..80bbeee2327 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-29w2-8xf2-3r76/GHSA-29w2-8xf2-3r76.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29w2-8xf2-3r76", + "modified": "2025-03-27T12:30:43Z", + "published": "2025-03-27T12:30:43Z", + "aliases": [ + "CVE-2025-30919" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Store Locator Widgets Store Locator Widget allows Stored XSS. This issue affects Store Locator Widget: from n/a through 20200131.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30919" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/store-locator-widget/vulnerability/wordpress-store-locator-widget-plugin-20200131-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2h2q-74g8-r928/GHSA-2h2q-74g8-r928.json b/advisories/unreviewed/2025/03/GHSA-2h2q-74g8-r928/GHSA-2h2q-74g8-r928.json new file mode 100644 index 00000000000..675f4f8b423 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2h2q-74g8-r928/GHSA-2h2q-74g8-r928.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2h2q-74g8-r928", + "modified": "2025-03-27T12:30:35Z", + "published": "2025-03-27T12:30:35Z", + "aliases": [ + "CVE-2025-30764" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in AntoineH Football Pool allows Cross Site Request Forgery. This issue affects Football Pool: from n/a through 2.12.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30764" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/football-pool/vulnerability/wordpress-football-pool-plugin-2-12-2-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2m8r-5qhj-3fj7/GHSA-2m8r-5qhj-3fj7.json b/advisories/unreviewed/2025/03/GHSA-2m8r-5qhj-3fj7/GHSA-2m8r-5qhj-3fj7.json new file mode 100644 index 00000000000..8f4ba82b7b1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2m8r-5qhj-3fj7/GHSA-2m8r-5qhj-3fj7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2m8r-5qhj-3fj7", + "modified": "2025-03-27T12:30:39Z", + "published": "2025-03-27T12:30:39Z", + "aliases": [ + "CVE-2025-30843" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in setriosoft bizcalendar-web allows SQL Injection. This issue affects bizcalendar-web: from n/a through 1.1.0.34.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30843" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bizcalendar-web/vulnerability/wordpress-bizcalendar-web-plugin-1-1-0-34-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2pm5-4pq3-87vj/GHSA-2pm5-4pq3-87vj.json b/advisories/unreviewed/2025/03/GHSA-2pm5-4pq3-87vj/GHSA-2pm5-4pq3-87vj.json new file mode 100644 index 00000000000..feb963e4be7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2pm5-4pq3-87vj/GHSA-2pm5-4pq3-87vj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2pm5-4pq3-87vj", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30824" + ], + "details": "Missing Authorization vulnerability in Israpil Textmetrics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Textmetrics: from n/a through 3.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30824" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/webtexttool/vulnerability/wordpress-textmetrics-plugin-3-6-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2q4j-vw33-3v48/GHSA-2q4j-vw33-3v48.json b/advisories/unreviewed/2025/03/GHSA-2q4j-vw33-3v48/GHSA-2q4j-vw33-3v48.json new file mode 100644 index 00000000000..e8ddbc8fc4a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2q4j-vw33-3v48/GHSA-2q4j-vw33-3v48.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2q4j-vw33-3v48", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30780" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cubecolour Audio Album allows Stored XSS. This issue affects Audio Album: from n/a through 1.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30780" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/audio-album/vulnerability/wordpress-audio-album-1-5-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2wcw-5cjw-6vvc/GHSA-2wcw-5cjw-6vvc.json b/advisories/unreviewed/2025/03/GHSA-2wcw-5cjw-6vvc/GHSA-2wcw-5cjw-6vvc.json new file mode 100644 index 00000000000..71c8a8d7d35 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2wcw-5cjw-6vvc/GHSA-2wcw-5cjw-6vvc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wcw-5cjw-6vvc", + "modified": "2025-03-27T12:30:41Z", + "published": "2025-03-27T12:30:41Z", + "aliases": [ + "CVE-2025-30881" + ], + "details": "Missing Authorization vulnerability in ThemeHunk Big Store allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Big Store: from n/a through 2.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30881" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/big-store/vulnerability/wordpress-big-store-theme-2-0-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-333p-49h6-q8x3/GHSA-333p-49h6-q8x3.json b/advisories/unreviewed/2025/03/GHSA-333p-49h6-q8x3/GHSA-333p-49h6-q8x3.json new file mode 100644 index 00000000000..8ecf7a1eb69 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-333p-49h6-q8x3/GHSA-333p-49h6-q8x3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-333p-49h6-q8x3", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:36Z", + "aliases": [ + "CVE-2025-30786" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oooorgle Quotes llama allows DOM-Based XSS. This issue affects Quotes llama: from n/a through 3.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30786" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quotes-llama/vulnerability/wordpress-quotes-llama-3-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-35wx-v489-5vx6/GHSA-35wx-v489-5vx6.json b/advisories/unreviewed/2025/03/GHSA-35wx-v489-5vx6/GHSA-35wx-v489-5vx6.json new file mode 100644 index 00000000000..d54b9d8b2b6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-35wx-v489-5vx6/GHSA-35wx-v489-5vx6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35wx-v489-5vx6", + "modified": "2025-03-27T12:30:42Z", + "published": "2025-03-27T12:30:42Z", + "aliases": [ + "CVE-2025-30909" + ], + "details": "Missing Authorization vulnerability in Conversios Conversios.io allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Conversios.io: from n/a through 7.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30909" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/enhanced-e-commerce-for-woocommerce-store/vulnerability/wordpress-conversios-io-plugin-7-2-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-39hm-72f3-v7g5/GHSA-39hm-72f3-v7g5.json b/advisories/unreviewed/2025/03/GHSA-39hm-72f3-v7g5/GHSA-39hm-72f3-v7g5.json new file mode 100644 index 00000000000..5ec117b0951 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-39hm-72f3-v7g5/GHSA-39hm-72f3-v7g5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39hm-72f3-v7g5", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30830" + ], + "details": "Missing Authorization vulnerability in Hossni Mubarak Cool Author Box allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Cool Author Box: from n/a through 2.9.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30830" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hm-cool-author-box-widget/vulnerability/wordpress-cool-author-box-plugin-2-9-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3rcf-g93x-vh3q/GHSA-3rcf-g93x-vh3q.json b/advisories/unreviewed/2025/03/GHSA-3rcf-g93x-vh3q/GHSA-3rcf-g93x-vh3q.json new file mode 100644 index 00000000000..50f02055aa3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3rcf-g93x-vh3q/GHSA-3rcf-g93x-vh3q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rcf-g93x-vh3q", + "modified": "2025-03-27T12:30:40Z", + "published": "2025-03-27T12:30:40Z", + "aliases": [ + "CVE-2025-30874" + ], + "details": "Missing Authorization vulnerability in Jose Specific Content For Mobile allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Specific Content For Mobile: from n/a through 0.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30874" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/specific-content-for-mobile/vulnerability/wordpress-specific-content-for-mobile-plugin-0-5-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3xr9-6gqg-crhm/GHSA-3xr9-6gqg-crhm.json b/advisories/unreviewed/2025/03/GHSA-3xr9-6gqg-crhm/GHSA-3xr9-6gqg-crhm.json new file mode 100644 index 00000000000..4ac5b7618a4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3xr9-6gqg-crhm/GHSA-3xr9-6gqg-crhm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xr9-6gqg-crhm", + "modified": "2025-03-27T12:30:35Z", + "published": "2025-03-27T12:30:35Z", + "aliases": [ + "CVE-2025-30763" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Olaf Lederer EO4WP allows Stored XSS. This issue affects EO4WP: from n/a through 1.0.8.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30763" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fw-integration-for-emailoctopus/vulnerability/wordpress-eo4wp-1-0-8-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4cf8-g4pg-xxgx/GHSA-4cf8-g4pg-xxgx.json b/advisories/unreviewed/2025/03/GHSA-4cf8-g4pg-xxgx/GHSA-4cf8-g4pg-xxgx.json new file mode 100644 index 00000000000..5d197f984c8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4cf8-g4pg-xxgx/GHSA-4cf8-g4pg-xxgx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cf8-g4pg-xxgx", + "modified": "2025-03-27T12:30:42Z", + "published": "2025-03-27T12:30:42Z", + "aliases": [ + "CVE-2025-30900" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Subscriptions Zoho Billing – Embed Payment Form allows Stored XSS. This issue affects Zoho Billing – Embed Payment Form: from n/a through 4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30900" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/zoho-subscriptions/vulnerability/wordpress-zoho-billing-embed-payment-form-plugin-4-0-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4cqp-8pqq-phx4/GHSA-4cqp-8pqq-phx4.json b/advisories/unreviewed/2025/03/GHSA-4cqp-8pqq-phx4/GHSA-4cqp-8pqq-phx4.json new file mode 100644 index 00000000000..79ea4d9a830 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4cqp-8pqq-phx4/GHSA-4cqp-8pqq-phx4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cqp-8pqq-phx4", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30801" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Abu Bakar TWB Woocommerce Reviews allows Cross Site Request Forgery. This issue affects TWB Woocommerce Reviews: from n/a through 1.7.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30801" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/twb-woocommerce-reviews/vulnerability/wordpress-twb-woocommerce-reviews-plugin-1-7-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4h4w-ghj2-qq29/GHSA-4h4w-ghj2-qq29.json b/advisories/unreviewed/2025/03/GHSA-4h4w-ghj2-qq29/GHSA-4h4w-ghj2-qq29.json new file mode 100644 index 00000000000..de6f49fd8b8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4h4w-ghj2-qq29/GHSA-4h4w-ghj2-qq29.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4h4w-ghj2-qq29", + "modified": "2025-03-27T12:30:42Z", + "published": "2025-03-27T12:30:42Z", + "aliases": [ + "CVE-2025-30898" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mahdi Yousefi [MahdiY] افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) allows Stored XSS. This issue affects افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری): from n/a through 4.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30898" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/persian-woocommerce-shipping/vulnerability/wordpress-fzonh-hml-o-nkl-oo-mrs-st-sht-z-o-sf-rsh-motor-plugin-4-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4j5q-99p5-6474/GHSA-4j5q-99p5-6474.json b/advisories/unreviewed/2025/03/GHSA-4j5q-99p5-6474/GHSA-4j5q-99p5-6474.json new file mode 100644 index 00000000000..70fa566fdfa --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4j5q-99p5-6474/GHSA-4j5q-99p5-6474.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4j5q-99p5-6474", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30789" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in clearoutio Clearout Email Validator allows Stored XSS. This issue affects Clearout Email Validator: from n/a through 3.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30789" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/clearout-email-validator/vulnerability/wordpress-clearout-email-validator-3-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4px8-8h5w-7vjp/GHSA-4px8-8h5w-7vjp.json b/advisories/unreviewed/2025/03/GHSA-4px8-8h5w-7vjp/GHSA-4px8-8h5w-7vjp.json new file mode 100644 index 00000000000..c4104e71413 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4px8-8h5w-7vjp/GHSA-4px8-8h5w-7vjp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4px8-8h5w-7vjp", + "modified": "2025-03-27T12:30:42Z", + "published": "2025-03-27T12:30:42Z", + "aliases": [ + "CVE-2025-30896" + ], + "details": "Missing Authorization vulnerability in weDevs WP ERP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP ERP: from n/a through 1.13.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30896" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/erp/vulnerability/wordpress-wp-erp-plugin-1-13-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5668-2qvm-f379/GHSA-5668-2qvm-f379.json b/advisories/unreviewed/2025/03/GHSA-5668-2qvm-f379/GHSA-5668-2qvm-f379.json new file mode 100644 index 00000000000..599a05317ac --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5668-2qvm-f379/GHSA-5668-2qvm-f379.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5668-2qvm-f379", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30804" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in maennchen1.de wpShopGermany IT-RECHT KANZLEI allows Cross Site Request Forgery. This issue affects wpShopGermany IT-RECHT KANZLEI: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30804" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpshopgermany-it-recht-kanzlei/vulnerability/wordpress-wpshopgermany-it-recht-kanzlei-plugin-2-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-56fh-r9cp-h38v/GHSA-56fh-r9cp-h38v.json b/advisories/unreviewed/2025/03/GHSA-56fh-r9cp-h38v/GHSA-56fh-r9cp-h38v.json new file mode 100644 index 00000000000..44f66b5c5f9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-56fh-r9cp-h38v/GHSA-56fh-r9cp-h38v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56fh-r9cp-h38v", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30811" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Javier Revilla ValidateCertify allows Cross Site Request Forgery. This issue affects ValidateCertify: from n/a through 1.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30811" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/validar-certificados-de-cursos/vulnerability/wordpress-validatecertify-plugin-1-6-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-58q6-pf3m-3mmp/GHSA-58q6-pf3m-3mmp.json b/advisories/unreviewed/2025/03/GHSA-58q6-pf3m-3mmp/GHSA-58q6-pf3m-3mmp.json new file mode 100644 index 00000000000..b950248e597 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-58q6-pf3m-3mmp/GHSA-58q6-pf3m-3mmp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58q6-pf3m-3mmp", + "modified": "2025-03-27T12:30:43Z", + "published": "2025-03-27T12:30:43Z", + "aliases": [ + "CVE-2025-31141" + ], + "details": "In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31141" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5hgx-hrhf-w9m2/GHSA-5hgx-hrhf-w9m2.json b/advisories/unreviewed/2025/03/GHSA-5hgx-hrhf-w9m2/GHSA-5hgx-hrhf-w9m2.json new file mode 100644 index 00000000000..0ebcf89b74f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5hgx-hrhf-w9m2/GHSA-5hgx-hrhf-w9m2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hgx-hrhf-w9m2", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30818" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mlaza jAlbum Bridge allows DOM-Based XSS. This issue affects jAlbum Bridge: from n/a through 2.0.17.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30818" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jalbum-bridge/vulnerability/wordpress-jalbum-bridge-plugin-2-0-17-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5vcc-mv82-47r3/GHSA-5vcc-mv82-47r3.json b/advisories/unreviewed/2025/03/GHSA-5vcc-mv82-47r3/GHSA-5vcc-mv82-47r3.json new file mode 100644 index 00000000000..35798af69d2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5vcc-mv82-47r3/GHSA-5vcc-mv82-47r3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vcc-mv82-47r3", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30806" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Constantin Boiangiu Vimeotheque allows SQL Injection. This issue affects Vimeotheque: from n/a through 2.3.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30806" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/codeflavors-vimeo-video-post-lite/vulnerability/wordpress-vimeotheque-plugin-2-3-4-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-62vh-3h8m-r6v7/GHSA-62vh-3h8m-r6v7.json b/advisories/unreviewed/2025/03/GHSA-62vh-3h8m-r6v7/GHSA-62vh-3h8m-r6v7.json new file mode 100644 index 00000000000..29d43fd58e1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-62vh-3h8m-r6v7/GHSA-62vh-3h8m-r6v7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62vh-3h8m-r6v7", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30838" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CozyThemes Cozy Blocks allows Stored XSS. This issue affects Cozy Blocks: from n/a through 2.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30838" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cozy-addons/vulnerability/wordpress-cozy-blocks-plugin-2-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-63x6-9wf8-mmhm/GHSA-63x6-9wf8-mmhm.json b/advisories/unreviewed/2025/03/GHSA-63x6-9wf8-mmhm/GHSA-63x6-9wf8-mmhm.json new file mode 100644 index 00000000000..f12b502aacc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-63x6-9wf8-mmhm/GHSA-63x6-9wf8-mmhm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63x6-9wf8-mmhm", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30795" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FunnelKit Automation By Autonami allows Phishing. This issue affects Automation By Autonami: from n/a through 3.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30795" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-marketing-automations/vulnerability/wordpress-automation-by-autonami-plugin-3-5-1-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-67vp-3jr4-fr25/GHSA-67vp-3jr4-fr25.json b/advisories/unreviewed/2025/03/GHSA-67vp-3jr4-fr25/GHSA-67vp-3jr4-fr25.json new file mode 100644 index 00000000000..524b71adb28 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-67vp-3jr4-fr25/GHSA-67vp-3jr4-fr25.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67vp-3jr4-fr25", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30823" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Boone Gorges Anthologize allows Cross Site Request Forgery. This issue affects Anthologize: from n/a through 0.8.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30823" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/anthologize/vulnerability/wordpress-anthologize-plugin-0-8-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-68q3-w8qh-6ccx/GHSA-68q3-w8qh-6ccx.json b/advisories/unreviewed/2025/03/GHSA-68q3-w8qh-6ccx/GHSA-68q3-w8qh-6ccx.json new file mode 100644 index 00000000000..7641b6af34f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-68q3-w8qh-6ccx/GHSA-68q3-w8qh-6ccx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68q3-w8qh-6ccx", + "modified": "2025-03-27T12:30:39Z", + "published": "2025-03-27T12:30:39Z", + "aliases": [ + "CVE-2025-30864" + ], + "details": "Missing Authorization vulnerability in falselight Exchange Rates allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Exchange Rates: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30864" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/exchange-rates/vulnerability/wordpress-exchange-rates-plugin-1-2-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6975-55r6-82m5/GHSA-6975-55r6-82m5.json b/advisories/unreviewed/2025/03/GHSA-6975-55r6-82m5/GHSA-6975-55r6-82m5.json new file mode 100644 index 00000000000..cabb4f63786 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6975-55r6-82m5/GHSA-6975-55r6-82m5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6975-55r6-82m5", + "modified": "2025-03-27T12:30:36Z", + "published": "2025-03-27T12:30:36Z", + "aliases": [ + "CVE-2025-30771" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alain-Aymerick FRANCOIS WP Cassify allows DOM-Based XSS. This issue affects WP Cassify: from n/a through 2.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30771" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-cassify/vulnerability/wordpress-wp-cassify-2-3-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6hvm-wxhp-cc87/GHSA-6hvm-wxhp-cc87.json b/advisories/unreviewed/2025/03/GHSA-6hvm-wxhp-cc87/GHSA-6hvm-wxhp-cc87.json new file mode 100644 index 00000000000..d3026be85ec --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6hvm-wxhp-cc87/GHSA-6hvm-wxhp-cc87.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hvm-wxhp-cc87", + "modified": "2025-03-27T12:30:43Z", + "published": "2025-03-27T12:30:43Z", + "aliases": [ + "CVE-2025-30922" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in simplebooklet Simplebooklet PDF Viewer and Embedder allows Stored XSS. This issue affects Simplebooklet PDF Viewer and Embedder: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30922" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simplebooklet/vulnerability/wordpress-simplebooklet-pdf-viewer-and-embedder-plugin-1-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6mj8-c74f-xjxv/GHSA-6mj8-c74f-xjxv.json b/advisories/unreviewed/2025/03/GHSA-6mj8-c74f-xjxv/GHSA-6mj8-c74f-xjxv.json new file mode 100644 index 00000000000..4aceebcf226 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6mj8-c74f-xjxv/GHSA-6mj8-c74f-xjxv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mj8-c74f-xjxv", + "modified": "2025-03-27T12:30:36Z", + "published": "2025-03-27T12:30:36Z", + "aliases": [ + "CVE-2025-30773" + ], + "details": "Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress allows Object Injection. This issue affects TranslatePress: from n/a through 2.9.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30773" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/translatepress-multilingual/vulnerability/wordpress-translatepress-2-9-6-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6pvc-73mw-q5m6/GHSA-6pvc-73mw-q5m6.json b/advisories/unreviewed/2025/03/GHSA-6pvc-73mw-q5m6/GHSA-6pvc-73mw-q5m6.json new file mode 100644 index 00000000000..f0db3980edf --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6pvc-73mw-q5m6/GHSA-6pvc-73mw-q5m6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pvc-73mw-q5m6", + "modified": "2025-03-27T12:30:41Z", + "published": "2025-03-27T12:30:41Z", + "aliases": [ + "CVE-2025-30888" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in silverplugins217 Custom Fields Account Registration For Woocommerce allows Cross Site Request Forgery. This issue affects Custom Fields Account Registration For Woocommerce: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30888" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/custom-fields-account-registration-for-woocommerce/vulnerability/wordpress-custom-fields-account-registration-for-woocommerce-plugin-1-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6xxm-jx55-r734/GHSA-6xxm-jx55-r734.json b/advisories/unreviewed/2025/03/GHSA-6xxm-jx55-r734/GHSA-6xxm-jx55-r734.json new file mode 100644 index 00000000000..12444428702 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6xxm-jx55-r734/GHSA-6xxm-jx55-r734.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xxm-jx55-r734", + "modified": "2025-03-27T12:30:39Z", + "published": "2025-03-27T12:30:39Z", + "aliases": [ + "CVE-2025-30857" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in PressMaximum Currency Switcher for WooCommerce allows Stored XSS. This issue affects Currency Switcher for WooCommerce: from n/a through 0.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30857" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/currency-switcher-for-woocommerce/vulnerability/wordpress-currency-switcher-for-woocommerce-plugin-0-0-7-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-734p-q4p5-pqxr/GHSA-734p-q4p5-pqxr.json b/advisories/unreviewed/2025/03/GHSA-734p-q4p5-pqxr/GHSA-734p-q4p5-pqxr.json new file mode 100644 index 00000000000..5424d32a76a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-734p-q4p5-pqxr/GHSA-734p-q4p5-pqxr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-734p-q4p5-pqxr", + "modified": "2025-03-27T12:30:43Z", + "published": "2025-03-27T12:30:43Z", + "aliases": [ + "CVE-2025-30921" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Software Newsletters allows SQL Injection. This issue affects Newsletters: from n/a through 4.9.9.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30921" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/newsletters-lite/vulnerability/wordpress-newsletters-plugin-4-9-9-7-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-754m-7w2g-84q3/GHSA-754m-7w2g-84q3.json b/advisories/unreviewed/2025/03/GHSA-754m-7w2g-84q3/GHSA-754m-7w2g-84q3.json new file mode 100644 index 00000000000..35537574957 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-754m-7w2g-84q3/GHSA-754m-7w2g-84q3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-754m-7w2g-84q3", + "modified": "2025-03-27T12:30:36Z", + "published": "2025-03-27T12:30:35Z", + "aliases": [ + "CVE-2025-30767" + ], + "details": "Missing Authorization vulnerability in add-ons.org PDF for WPForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF for WPForms: from n/a through 5.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30767" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pdf-for-wpforms/vulnerability/wordpress-pdf-for-wpforms-plugin-5-3-0-arbitrary-shortcode-execution-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-77gh-56wm-q4rx/GHSA-77gh-56wm-q4rx.json b/advisories/unreviewed/2025/03/GHSA-77gh-56wm-q4rx/GHSA-77gh-56wm-q4rx.json new file mode 100644 index 00000000000..56b68b62ca4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-77gh-56wm-q4rx/GHSA-77gh-56wm-q4rx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77gh-56wm-q4rx", + "modified": "2025-03-27T12:30:43Z", + "published": "2025-03-27T12:30:43Z", + "aliases": [ + "CVE-2025-30923" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in powerfulwp Gift Message for WooCommerce allows Cross Site Request Forgery. This issue affects Gift Message for WooCommerce: from n/a through 1.7.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30923" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gift-message-for-woocommerce/vulnerability/wordpress-gift-message-for-woocommerce-plugin-1-7-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-78jc-mm83-fpr5/GHSA-78jc-mm83-fpr5.json b/advisories/unreviewed/2025/03/GHSA-78jc-mm83-fpr5/GHSA-78jc-mm83-fpr5.json new file mode 100644 index 00000000000..95925d0374b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-78jc-mm83-fpr5/GHSA-78jc-mm83-fpr5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78jc-mm83-fpr5", + "modified": "2025-03-27T12:30:39Z", + "published": "2025-03-27T12:30:39Z", + "aliases": [ + "CVE-2025-30845" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in webangon The Pack Elementor addons allows PHP Local File Inclusion. This issue affects The Pack Elementor addons: from n/a through 2.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30845" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/the-pack-addon/vulnerability/wordpress-the-pack-elementor-addons-plugin-2-1-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-793r-p6pf-pxvj/GHSA-793r-p6pf-pxvj.json b/advisories/unreviewed/2025/03/GHSA-793r-p6pf-pxvj/GHSA-793r-p6pf-pxvj.json new file mode 100644 index 00000000000..fc5f6049983 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-793r-p6pf-pxvj/GHSA-793r-p6pf-pxvj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-793r-p6pf-pxvj", + "modified": "2025-03-27T12:30:43Z", + "published": "2025-03-27T12:30:43Z", + "aliases": [ + "CVE-2025-30925" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webangon The Pack Elementor addons allows Stored XSS. This issue affects The Pack Elementor addons: from n/a through 2.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30925" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/the-pack-addon/vulnerability/wordpress-the-pack-elementor-addons-plugin-2-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7c42-x8gc-fmvq/GHSA-7c42-x8gc-fmvq.json b/advisories/unreviewed/2025/03/GHSA-7c42-x8gc-fmvq/GHSA-7c42-x8gc-fmvq.json new file mode 100644 index 00000000000..9a93a926468 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7c42-x8gc-fmvq/GHSA-7c42-x8gc-fmvq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c42-x8gc-fmvq", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30813" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in listamester Listamester allows Stored XSS. This issue affects Listamester: from n/a through 2.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30813" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/listamester/vulnerability/wordpress-listamester-plugin-2-3-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7fxg-279r-rhqq/GHSA-7fxg-279r-rhqq.json b/advisories/unreviewed/2025/03/GHSA-7fxg-279r-rhqq/GHSA-7fxg-279r-rhqq.json new file mode 100644 index 00000000000..34b551caac4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7fxg-279r-rhqq/GHSA-7fxg-279r-rhqq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fxg-279r-rhqq", + "modified": "2025-03-27T12:30:40Z", + "published": "2025-03-27T12:30:40Z", + "aliases": [ + "CVE-2025-30867" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SearchIQ SearchIQ allows Stored XSS. This issue affects SearchIQ: from n/a through 4.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30867" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/searchiq/vulnerability/wordpress-searchiq-plugin-4-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7hjv-369x-3cwv/GHSA-7hjv-369x-3cwv.json b/advisories/unreviewed/2025/03/GHSA-7hjv-369x-3cwv/GHSA-7hjv-369x-3cwv.json new file mode 100644 index 00000000000..2e131600093 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7hjv-369x-3cwv/GHSA-7hjv-369x-3cwv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hjv-369x-3cwv", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30816" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Nks publish post email notification allows Cross Site Request Forgery. This issue affects publish post email notification: from n/a through 1.0.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30816" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/publish-post-email-notification/vulnerability/wordpress-publish-post-email-notification-plugin-1-0-2-3-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7prm-xhfc-rpv3/GHSA-7prm-xhfc-rpv3.json b/advisories/unreviewed/2025/03/GHSA-7prm-xhfc-rpv3/GHSA-7prm-xhfc-rpv3.json new file mode 100644 index 00000000000..349fa692a50 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7prm-xhfc-rpv3/GHSA-7prm-xhfc-rpv3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7prm-xhfc-rpv3", + "modified": "2025-03-27T12:30:42Z", + "published": "2025-03-27T12:30:42Z", + "aliases": [ + "CVE-2025-30914" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in XpeedStudio Metform allows Server Side Request Forgery. This issue affects Metform: from n/a through 3.9.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30914" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/metform/vulnerability/wordpress-metform-elementor-contact-form-builder-plugin-3-9-2-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7v39-9g8v-3xw9/GHSA-7v39-9g8v-3xw9.json b/advisories/unreviewed/2025/03/GHSA-7v39-9g8v-3xw9/GHSA-7v39-9g8v-3xw9.json new file mode 100644 index 00000000000..9f205a8e990 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7v39-9g8v-3xw9/GHSA-7v39-9g8v-3xw9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v39-9g8v-3xw9", + "modified": "2025-03-27T12:30:42Z", + "published": "2025-03-27T12:30:42Z", + "aliases": [ + "CVE-2025-30903" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Mills SyntaxHighlighter Evolved allows DOM-Based XSS. This issue affects SyntaxHighlighter Evolved: from n/a through 3.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30903" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/syntaxhighlighter/vulnerability/wordpress-syntaxhighlighter-evolved-plugin-3-7-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7x3g-q3pp-h6vc/GHSA-7x3g-q3pp-h6vc.json b/advisories/unreviewed/2025/03/GHSA-7x3g-q3pp-h6vc/GHSA-7x3g-q3pp-h6vc.json new file mode 100644 index 00000000000..1de85ba637c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7x3g-q3pp-h6vc/GHSA-7x3g-q3pp-h6vc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x3g-q3pp-h6vc", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30788" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Eli EZ SQL Reports Shortcode Widget and DB Backup allows SQL Injection. This issue affects EZ SQL Reports Shortcode Widget and DB Backup: from n/a through 5.25.08.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30788" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/elisqlreports/vulnerability/wordpress-ez-sql-reports-shortcode-widget-and-db-backup-plugin-5-25-08-csrf-to-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-844v-fv9f-vwrm/GHSA-844v-fv9f-vwrm.json b/advisories/unreviewed/2025/03/GHSA-844v-fv9f-vwrm/GHSA-844v-fv9f-vwrm.json new file mode 100644 index 00000000000..54568439535 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-844v-fv9f-vwrm/GHSA-844v-fv9f-vwrm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-844v-fv9f-vwrm", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30810" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smackcoders Lead Form Data Collection to CRM allows Blind SQL Injection. This issue affects Lead Form Data Collection to CRM: from n/a through 3.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30810" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-leads-builder-any-crm/vulnerability/wordpress-lead-form-data-collection-to-crm-plugin-3-0-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-85r5-jr4g-929w/GHSA-85r5-jr4g-929w.json b/advisories/unreviewed/2025/03/GHSA-85r5-jr4g-929w/GHSA-85r5-jr4g-929w.json new file mode 100644 index 00000000000..0b5550437e3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-85r5-jr4g-929w/GHSA-85r5-jr4g-929w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85r5-jr4g-929w", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30779" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nick Doneren met Mollie allows Stored XSS. This issue affects Doneren met Mollie: from n/a through 2.10.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30779" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/doneren-met-mollie/vulnerability/wordpress-doneren-met-mollie-2-10-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8c9h-3vrw-wm5g/GHSA-8c9h-3vrw-wm5g.json b/advisories/unreviewed/2025/03/GHSA-8c9h-3vrw-wm5g/GHSA-8c9h-3vrw-wm5g.json new file mode 100644 index 00000000000..29257ea0a30 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8c9h-3vrw-wm5g/GHSA-8c9h-3vrw-wm5g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8c9h-3vrw-wm5g", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:36Z", + "aliases": [ + "CVE-2025-30775" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech Private Limited WPGuppy allows SQL Injection. This issue affects WPGuppy: from n/a through 1.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30775" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpguppy-lite/vulnerability/wordpress-wpguppy-plugin-1-1-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8ghx-hvh4-2xqh/GHSA-8ghx-hvh4-2xqh.json b/advisories/unreviewed/2025/03/GHSA-8ghx-hvh4-2xqh/GHSA-8ghx-hvh4-2xqh.json new file mode 100644 index 00000000000..3e2c387ab76 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8ghx-hvh4-2xqh/GHSA-8ghx-hvh4-2xqh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8ghx-hvh4-2xqh", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30836" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LatePoint LatePoint allows Stored XSS. This issue affects LatePoint: from n/a through 5.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30836" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/latepoint/vulnerability/wordpress-latepoint-plugin-5-1-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8gq8-fx5p-97wr/GHSA-8gq8-fx5p-97wr.json b/advisories/unreviewed/2025/03/GHSA-8gq8-fx5p-97wr/GHSA-8gq8-fx5p-97wr.json new file mode 100644 index 00000000000..5ec5c11dda7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8gq8-fx5p-97wr/GHSA-8gq8-fx5p-97wr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gq8-fx5p-97wr", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30785" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle Subscribe to Download Lite allows PHP Local File Inclusion. This issue affects Subscribe to Download Lite: from n/a through 1.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30785" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/subscribe-to-download-lite/vulnerability/wordpress-subscribe-to-download-lite-1-2-9-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8w7v-wg9w-c7jm/GHSA-8w7v-wg9w-c7jm.json b/advisories/unreviewed/2025/03/GHSA-8w7v-wg9w-c7jm/GHSA-8w7v-wg9w-c7jm.json new file mode 100644 index 00000000000..909ac52fba6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8w7v-wg9w-c7jm/GHSA-8w7v-wg9w-c7jm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w7v-wg9w-c7jm", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30833" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Soft8Soft LLC Verge3D allows Cross Site Request Forgery. This issue affects Verge3D: from n/a through 4.8.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30833" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/verge3d/vulnerability/wordpress-verge3d-publishing-and-e-commerce-plugin-4-8-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8x8v-fchv-5c38/GHSA-8x8v-fchv-5c38.json b/advisories/unreviewed/2025/03/GHSA-8x8v-fchv-5c38/GHSA-8x8v-fchv-5c38.json new file mode 100644 index 00000000000..577f125f41b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8x8v-fchv-5c38/GHSA-8x8v-fchv-5c38.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x8v-fchv-5c38", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30819" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Igor Benic Simple Giveaways allows SQL Injection. This issue affects Simple Giveaways: from n/a through 2.48.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30819" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/giveasap/vulnerability/wordpress-simple-giveaways-plugin-2-48-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-928p-7p66-959p/GHSA-928p-7p66-959p.json b/advisories/unreviewed/2025/03/GHSA-928p-7p66-959p/GHSA-928p-7p66-959p.json new file mode 100644 index 00000000000..c592a3a0e65 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-928p-7p66-959p/GHSA-928p-7p66-959p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-928p-7p66-959p", + "modified": "2025-03-27T12:30:40Z", + "published": "2025-03-27T12:30:40Z", + "aliases": [ + "CVE-2025-30865" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in fuzzoid 3DPrint Lite allows Cross Site Request Forgery. This issue affects 3DPrint Lite: from n/a through 2.1.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30865" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/3dprint-lite/vulnerability/wordpress-3dprint-lite-plugin-2-1-3-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9f59-hcqf-jhx4/GHSA-9f59-hcqf-jhx4.json b/advisories/unreviewed/2025/03/GHSA-9f59-hcqf-jhx4/GHSA-9f59-hcqf-jhx4.json new file mode 100644 index 00000000000..7944baa79ab --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9f59-hcqf-jhx4/GHSA-9f59-hcqf-jhx4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f59-hcqf-jhx4", + "modified": "2025-03-27T12:30:40Z", + "published": "2025-03-27T12:30:40Z", + "aliases": [ + "CVE-2025-30872" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Nitin Prakash Product Author for WooCommerce allows Cross Site Request Forgery. This issue affects Product Author for WooCommerce: from n/a through 1.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30872" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wc-product-author/vulnerability/wordpress-product-author-for-woocommerce-plugin-1-0-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9f5g-g6xj-3q44/GHSA-9f5g-g6xj-3q44.json b/advisories/unreviewed/2025/03/GHSA-9f5g-g6xj-3q44/GHSA-9f5g-g6xj-3q44.json new file mode 100644 index 00000000000..13eaeedb713 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9f5g-g6xj-3q44/GHSA-9f5g-g6xj-3q44.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f5g-g6xj-3q44", + "modified": "2025-03-27T12:30:42Z", + "published": "2025-03-27T12:30:42Z", + "aliases": [ + "CVE-2025-30893" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LeadConnector LeadConnector allows DOM-Based XSS. This issue affects LeadConnector: from n/a through 3.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30893" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/leadconnector/vulnerability/wordpress-leadconnector-plugin-3-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9hpv-6cfm-9c9q/GHSA-9hpv-6cfm-9c9q.json b/advisories/unreviewed/2025/03/GHSA-9hpv-6cfm-9c9q/GHSA-9hpv-6cfm-9c9q.json new file mode 100644 index 00000000000..6c69c8d5abf --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9hpv-6cfm-9c9q/GHSA-9hpv-6cfm-9c9q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hpv-6cfm-9c9q", + "modified": "2025-03-27T12:30:35Z", + "published": "2025-03-27T12:30:35Z", + "aliases": [ + "CVE-2025-30766" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy Addons for Elementor allows DOM-Based XSS. This issue affects Happy Addons for Elementor: from n/a through 3.16.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30766" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/happy-elementor-addons/vulnerability/wordpress-happy-addons-for-elementor-3-16-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9v27-96h9-9xrq/GHSA-9v27-96h9-9xrq.json b/advisories/unreviewed/2025/03/GHSA-9v27-96h9-9xrq/GHSA-9v27-96h9-9xrq.json new file mode 100644 index 00000000000..a5ba846c0fc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9v27-96h9-9xrq/GHSA-9v27-96h9-9xrq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v27-96h9-9xrq", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30820" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in HT Plugins WishSuite allows PHP Local File Inclusion. This issue affects WishSuite: from n/a through 1.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30820" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wishsuite/vulnerability/wordpress-wishsuite-plugin-1-4-4-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c5px-mrpf-jph6/GHSA-c5px-mrpf-jph6.json b/advisories/unreviewed/2025/03/GHSA-c5px-mrpf-jph6/GHSA-c5px-mrpf-jph6.json new file mode 100644 index 00000000000..c93a6e9383d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c5px-mrpf-jph6/GHSA-c5px-mrpf-jph6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5px-mrpf-jph6", + "modified": "2025-03-27T12:30:39Z", + "published": "2025-03-27T12:30:39Z", + "aliases": [ + "CVE-2025-30854" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Saso Serial Codes Generator and Validator with WooCommerce Support allows Cross Site Request Forgery. This issue affects Serial Codes Generator and Validator with WooCommerce Support: from n/a through 2.7.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30854" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/serial-codes-generator-and-validator/vulnerability/wordpress-serial-codes-generator-and-validator-with-woocommerce-support-plugin-2-7-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cpxp-6rch-m2c3/GHSA-cpxp-6rch-m2c3.json b/advisories/unreviewed/2025/03/GHSA-cpxp-6rch-m2c3/GHSA-cpxp-6rch-m2c3.json new file mode 100644 index 00000000000..a0db9547487 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cpxp-6rch-m2c3/GHSA-cpxp-6rch-m2c3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpxp-6rch-m2c3", + "modified": "2025-03-27T12:30:36Z", + "published": "2025-03-27T12:30:36Z", + "aliases": [ + "CVE-2025-30772" + ], + "details": "Missing Authorization vulnerability in WPClever WPC Smart Upsell Funnel for WooCommerce allows Privilege Escalation. This issue affects WPC Smart Upsell Funnel for WooCommerce: from n/a through 3.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30772" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpc-smart-upsell-funnel/vulnerability/wordpress-wpc-smart-upsell-funnel-for-woocommerce-plugin-3-0-4-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-crfg-5924-rr3v/GHSA-crfg-5924-rr3v.json b/advisories/unreviewed/2025/03/GHSA-crfg-5924-rr3v/GHSA-crfg-5924-rr3v.json new file mode 100644 index 00000000000..f2c7be7f5c9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-crfg-5924-rr3v/GHSA-crfg-5924-rr3v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crfg-5924-rr3v", + "modified": "2025-03-27T12:30:42Z", + "published": "2025-03-27T12:30:42Z", + "aliases": [ + "CVE-2025-30895" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in magepeopleteam WpEvently allows PHP Local File Inclusion. This issue affects WpEvently: from n/a through 4.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30895" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mage-eventpress/vulnerability/wordpress-wpevently-plugin-4-2-9-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f8w7-gf8j-vvv3/GHSA-f8w7-gf8j-vvv3.json b/advisories/unreviewed/2025/03/GHSA-f8w7-gf8j-vvv3/GHSA-f8w7-gf8j-vvv3.json new file mode 100644 index 00000000000..7281ec92c47 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f8w7-gf8j-vvv3/GHSA-f8w7-gf8j-vvv3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8w7-gf8j-vvv3", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30828" + ], + "details": "Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Timetics: from n/a through 1.0.29.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30828" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/timetics/vulnerability/wordpress-timetics-plugin-1-0-29-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f92x-c56c-pf59/GHSA-f92x-c56c-pf59.json b/advisories/unreviewed/2025/03/GHSA-f92x-c56c-pf59/GHSA-f92x-c56c-pf59.json new file mode 100644 index 00000000000..72d0eabe4c0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f92x-c56c-pf59/GHSA-f92x-c56c-pf59.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f92x-c56c-pf59", + "modified": "2025-03-27T12:30:39Z", + "published": "2025-03-27T12:30:39Z", + "aliases": [ + "CVE-2025-30859" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ali2woo AliNext allows Phishing. This issue affects AliNext: from n/a through 3.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30859" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ali2woo-lite/vulnerability/wordpress-alinext-plugin-3-5-1-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-ffj3-w9r8-4m9m/GHSA-ffj3-w9r8-4m9m.json b/advisories/unreviewed/2025/03/GHSA-ffj3-w9r8-4m9m/GHSA-ffj3-w9r8-4m9m.json new file mode 100644 index 00000000000..2a927436c0c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-ffj3-w9r8-4m9m/GHSA-ffj3-w9r8-4m9m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffj3-w9r8-4m9m", + "modified": "2025-03-27T12:30:36Z", + "published": "2025-03-27T12:30:35Z", + "aliases": [ + "CVE-2025-30768" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mlaza jAlbum Bridge allows Stored XSS. This issue affects jAlbum Bridge: from n/a through 2.0.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30768" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jalbum-bridge/vulnerability/wordpress-jalbum-bridge-2-0-18-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fhpg-4j4x-74cv/GHSA-fhpg-4j4x-74cv.json b/advisories/unreviewed/2025/03/GHSA-fhpg-4j4x-74cv/GHSA-fhpg-4j4x-74cv.json new file mode 100644 index 00000000000..1bec12ec3d9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fhpg-4j4x-74cv/GHSA-fhpg-4j4x-74cv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhpg-4j4x-74cv", + "modified": "2025-03-27T12:30:41Z", + "published": "2025-03-27T12:30:41Z", + "aliases": [ + "CVE-2025-30890" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SuitePlugins Login Widget for Ultimate Member allows PHP Local File Inclusion. This issue affects Login Widget for Ultimate Member: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30890" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/login-widget-for-ultimate-member/vulnerability/wordpress-login-widget-for-ultimate-member-plugin-1-1-2-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fhw5-vp5p-7wxx/GHSA-fhw5-vp5p-7wxx.json b/advisories/unreviewed/2025/03/GHSA-fhw5-vp5p-7wxx/GHSA-fhw5-vp5p-7wxx.json new file mode 100644 index 00000000000..2e425c141fc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fhw5-vp5p-7wxx/GHSA-fhw5-vp5p-7wxx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhw5-vp5p-7wxx", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30781" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WPFactory Scheduled & Automatic Order Status Controller for WooCommerce allows Phishing. This issue affects Scheduled & Automatic Order Status Controller for WooCommerce: from n/a through 3.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30781" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/order-status-rules-for-woocommerce/vulnerability/wordpress-scheduled-automatic-order-status-controller-for-woocommerce-3-7-1-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fxjm-4m3m-24xv/GHSA-fxjm-4m3m-24xv.json b/advisories/unreviewed/2025/03/GHSA-fxjm-4m3m-24xv/GHSA-fxjm-4m3m-24xv.json new file mode 100644 index 00000000000..ca1ab5f5f66 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fxjm-4m3m-24xv/GHSA-fxjm-4m3m-24xv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxjm-4m3m-24xv", + "modified": "2025-03-27T12:30:35Z", + "published": "2025-03-27T12:30:35Z", + "aliases": [ + "CVE-2025-29993" + ], + "details": "The affected versions of PowerCMS allow HTTP header injection. This vulnerability can be leveraged to direct the affected product to send email with a tampered URL, such as password reset mail.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29993" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN39026557" + }, + { + "type": "WEB", + "url": "https://www.powercms.jp/news/release-powercms-661-528-459.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g829-4gfh-rg4v/GHSA-g829-4gfh-rg4v.json b/advisories/unreviewed/2025/03/GHSA-g829-4gfh-rg4v/GHSA-g829-4gfh-rg4v.json new file mode 100644 index 00000000000..3984630eaed --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g829-4gfh-rg4v/GHSA-g829-4gfh-rg4v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g829-4gfh-rg4v", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30791" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdever Cart tracking for WooCommerce allows SQL Injection. This issue affects Cart tracking for WooCommerce: from n/a through 1.0.16.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30791" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cart-tracking-for-woocommerce/vulnerability/wordpress-cart-tracking-for-woocommerce-plugin-1-0-16-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g8wj-xwrp-45vq/GHSA-g8wj-xwrp-45vq.json b/advisories/unreviewed/2025/03/GHSA-g8wj-xwrp-45vq/GHSA-g8wj-xwrp-45vq.json new file mode 100644 index 00000000000..1f1c08bc745 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g8wj-xwrp-45vq/GHSA-g8wj-xwrp-45vq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8wj-xwrp-45vq", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30817" + ], + "details": "Missing Authorization vulnerability in wpzita Z Companion allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Z Companion: from n/a through 1.0.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30817" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/z-companion/vulnerability/wordpress-z-companion-plugin-1-0-13-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g9fj-vvm8-xfvj/GHSA-g9fj-vvm8-xfvj.json b/advisories/unreviewed/2025/03/GHSA-g9fj-vvm8-xfvj/GHSA-g9fj-vvm8-xfvj.json new file mode 100644 index 00000000000..ce7a7eae6db --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g9fj-vvm8-xfvj/GHSA-g9fj-vvm8-xfvj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9fj-vvm8-xfvj", + "modified": "2025-03-27T12:30:36Z", + "published": "2025-03-27T12:30:36Z", + "aliases": [ + "CVE-2025-30770" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Charitable allows DOM-Based XSS. This issue affects Charitable: from n/a through 1.8.4.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30770" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/charitable/vulnerability/wordpress-charitable-1-8-4-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gh86-cj5c-g55j/GHSA-gh86-cj5c-g55j.json b/advisories/unreviewed/2025/03/GHSA-gh86-cj5c-g55j/GHSA-gh86-cj5c-g55j.json new file mode 100644 index 00000000000..4719fc52f6c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gh86-cj5c-g55j/GHSA-gh86-cj5c-g55j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh86-cj5c-g55j", + "modified": "2025-03-27T12:30:40Z", + "published": "2025-03-27T12:30:40Z", + "aliases": [ + "CVE-2025-30866" + ], + "details": "Missing Authorization vulnerability in Giannis Kipouros Terms & Conditions Per Product allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Terms & Conditions Per Product: from n/a through 1.2.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30866" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/terms-and-conditions-per-product/vulnerability/wordpress-terms-conditions-per-product-plugin-1-2-15-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gh9x-wq33-hmvv/GHSA-gh9x-wq33-hmvv.json b/advisories/unreviewed/2025/03/GHSA-gh9x-wq33-hmvv/GHSA-gh9x-wq33-hmvv.json new file mode 100644 index 00000000000..16e9732fbad --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gh9x-wq33-hmvv/GHSA-gh9x-wq33-hmvv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh9x-wq33-hmvv", + "modified": "2025-03-27T12:30:39Z", + "published": "2025-03-27T12:30:39Z", + "aliases": [ + "CVE-2025-30856" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in theme funda Custom Field For WP Job Manager allows Cross Site Request Forgery. This issue affects Custom Field For WP Job Manager: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30856" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/custom-field-for-wp-job-manager/vulnerability/wordpress-custom-field-for-wp-job-manager-plugin-1-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gjhw-839g-27wc/GHSA-gjhw-839g-27wc.json b/advisories/unreviewed/2025/03/GHSA-gjhw-839g-27wc/GHSA-gjhw-839g-27wc.json new file mode 100644 index 00000000000..cac4896bea3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gjhw-839g-27wc/GHSA-gjhw-839g-27wc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjhw-839g-27wc", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30803" + ], + "details": "Missing Authorization vulnerability in Greg Ross Just Writing Statistics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Just Writing Statistics: from n/a through 5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30803" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/just-writing-statistics/vulnerability/wordpress-just-writing-statistics-plugin-5-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gp5w-jxvw-43ff/GHSA-gp5w-jxvw-43ff.json b/advisories/unreviewed/2025/03/GHSA-gp5w-jxvw-43ff/GHSA-gp5w-jxvw-43ff.json new file mode 100644 index 00000000000..9f3b2869528 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gp5w-jxvw-43ff/GHSA-gp5w-jxvw-43ff.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gp5w-jxvw-43ff", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30826" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lannoy IP Locator allows DOM-Based XSS. This issue affects IP Locator: from n/a through 4.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30826" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ip-locator/vulnerability/wordpress-ip-locator-plugin-4-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gq83-8fqj-xc3j/GHSA-gq83-8fqj-xc3j.json b/advisories/unreviewed/2025/03/GHSA-gq83-8fqj-xc3j/GHSA-gq83-8fqj-xc3j.json new file mode 100644 index 00000000000..1bd7f61ed23 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gq83-8fqj-xc3j/GHSA-gq83-8fqj-xc3j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq83-8fqj-xc3j", + "modified": "2025-03-27T12:30:41Z", + "published": "2025-03-27T12:30:41Z", + "aliases": [ + "CVE-2025-30884" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Bit Apps Bit Integrations allows Phishing. This issue affects Bit Integrations: from n/a through 2.4.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30884" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bit-integrations/vulnerability/wordpress-bit-integrations-plugin-2-4-10-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gv5c-qwvr-2qq7/GHSA-gv5c-qwvr-2qq7.json b/advisories/unreviewed/2025/03/GHSA-gv5c-qwvr-2qq7/GHSA-gv5c-qwvr-2qq7.json new file mode 100644 index 00000000000..25c94d07b22 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gv5c-qwvr-2qq7/GHSA-gv5c-qwvr-2qq7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv5c-qwvr-2qq7", + "modified": "2025-03-27T12:30:39Z", + "published": "2025-03-27T12:30:39Z", + "aliases": [ + "CVE-2025-30863" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms allows Cross Site Request Forgery. This issue affects Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through 1.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30863" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/integration-for-contact-form-7-and-google-sheets/vulnerability/wordpress-integration-for-google-sheets-and-contact-form-7-wpforms-elementor-ninja-forms-plugin-1-0-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h4p3-ffc4-4vw5/GHSA-h4p3-ffc4-4vw5.json b/advisories/unreviewed/2025/03/GHSA-h4p3-ffc4-4vw5/GHSA-h4p3-ffc4-4vw5.json new file mode 100644 index 00000000000..cb35d1b7182 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h4p3-ffc4-4vw5/GHSA-h4p3-ffc4-4vw5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4p3-ffc4-4vw5", + "modified": "2025-03-27T12:30:41Z", + "published": "2025-03-27T12:30:41Z", + "aliases": [ + "CVE-2025-30891" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam WpTravelly allows PHP Local File Inclusion. This issue affects WpTravelly: from n/a through 1.8.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30891" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tour-booking-manager/vulnerability/wordpress-wptravelly-plugin-1-8-7-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h535-j96r-875v/GHSA-h535-j96r-875v.json b/advisories/unreviewed/2025/03/GHSA-h535-j96r-875v/GHSA-h535-j96r-875v.json new file mode 100644 index 00000000000..27a66f75571 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h535-j96r-875v/GHSA-h535-j96r-875v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h535-j96r-875v", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30814" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme The Post Grid allows PHP Local File Inclusion. This issue affects The Post Grid: from n/a through 7.7.17.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30814" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/the-post-grid/vulnerability/wordpress-the-post-grid-plugin-7-7-17-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h5gw-682p-v2c8/GHSA-h5gw-682p-v2c8.json b/advisories/unreviewed/2025/03/GHSA-h5gw-682p-v2c8/GHSA-h5gw-682p-v2c8.json new file mode 100644 index 00000000000..094b10f89ed --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h5gw-682p-v2c8/GHSA-h5gw-682p-v2c8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5gw-682p-v2c8", + "modified": "2025-03-27T12:30:40Z", + "published": "2025-03-27T12:30:40Z", + "aliases": [ + "CVE-2025-30871" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine allows PHP Local File Inclusion. This issue affects WP Travel Engine: from n/a through 6.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30871" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-travel-engine/vulnerability/wordpress-wp-travel-engine-plugin-6-3-5-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h5q6-96r6-f7qq/GHSA-h5q6-96r6-f7qq.json b/advisories/unreviewed/2025/03/GHSA-h5q6-96r6-f7qq/GHSA-h5q6-96r6-f7qq.json new file mode 100644 index 00000000000..41e9f39a52d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h5q6-96r6-f7qq/GHSA-h5q6-96r6-f7qq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5q6-96r6-f7qq", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30805" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in wpdesk Flexible Cookies allows Cross Site Request Forgery. This issue affects Flexible Cookies: from n/a through 1.1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30805" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/flexible-cookies/vulnerability/wordpress-flexible-cookies-plugin-1-1-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h9pf-446x-9hv5/GHSA-h9pf-446x-9hv5.json b/advisories/unreviewed/2025/03/GHSA-h9pf-446x-9hv5/GHSA-h9pf-446x-9hv5.json new file mode 100644 index 00000000000..9ef6a1114c3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h9pf-446x-9hv5/GHSA-h9pf-446x-9hv5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9pf-446x-9hv5", + "modified": "2025-03-27T12:30:39Z", + "published": "2025-03-27T12:30:39Z", + "aliases": [ + "CVE-2025-30862" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Bill Minozzi reCAPTCHA for all allows Cross Site Request Forgery. This issue affects reCAPTCHA for all: from n/a through 2.22.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30862" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/recaptcha-for-all/vulnerability/wordpress-recaptcha-for-all-plugin-2-22-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hhmh-4792-pf49/GHSA-hhmh-4792-pf49.json b/advisories/unreviewed/2025/03/GHSA-hhmh-4792-pf49/GHSA-hhmh-4792-pf49.json new file mode 100644 index 00000000000..9e3fee43974 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hhmh-4792-pf49/GHSA-hhmh-4792-pf49.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhmh-4792-pf49", + "modified": "2025-03-27T12:30:43Z", + "published": "2025-03-27T12:30:43Z", + "aliases": [ + "CVE-2025-31139" + ], + "details": "In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31139" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hmgv-7gr3-j5q3/GHSA-hmgv-7gr3-j5q3.json b/advisories/unreviewed/2025/03/GHSA-hmgv-7gr3-j5q3/GHSA-hmgv-7gr3-j5q3.json new file mode 100644 index 00000000000..28e6f4e22a2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hmgv-7gr3-j5q3/GHSA-hmgv-7gr3-j5q3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmgv-7gr3-j5q3", + "modified": "2025-03-27T12:30:43Z", + "published": "2025-03-27T12:30:43Z", + "aliases": [ + "CVE-2025-30920" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in teastudio.pl WP Posts Carousel allows Stored XSS. This issue affects WP Posts Carousel: from n/a through 1.3.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30920" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-posts-carousel/vulnerability/wordpress-wp-posts-carousel-plugin-1-3-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hp8h-p3w5-3x52/GHSA-hp8h-p3w5-3x52.json b/advisories/unreviewed/2025/03/GHSA-hp8h-p3w5-3x52/GHSA-hp8h-p3w5-3x52.json new file mode 100644 index 00000000000..65b96c780e7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hp8h-p3w5-3x52/GHSA-hp8h-p3w5-3x52.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp8h-p3w5-3x52", + "modified": "2025-03-27T12:30:39Z", + "published": "2025-03-27T12:30:39Z", + "aliases": [ + "CVE-2025-30850" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sfaerber Dr. Flex allows Stored XSS. This issue affects Dr. Flex: from n/a through 2.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30850" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dr-flex/vulnerability/wordpress-dr-flex-plugin-2-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j878-h237-vhcm/GHSA-j878-h237-vhcm.json b/advisories/unreviewed/2025/03/GHSA-j878-h237-vhcm/GHSA-j878-h237-vhcm.json new file mode 100644 index 00000000000..55fd525b817 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j878-h237-vhcm/GHSA-j878-h237-vhcm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j878-h237-vhcm", + "modified": "2025-03-27T12:30:39Z", + "published": "2025-03-27T12:30:39Z", + "aliases": [ + "CVE-2025-30847" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashley Novelist allows Stored XSS. This issue affects Novelist: from n/a through 1.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30847" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/novelist/vulnerability/wordpress-novelist-plugin-1-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jg55-46h5-pq76/GHSA-jg55-46h5-pq76.json b/advisories/unreviewed/2025/03/GHSA-jg55-46h5-pq76/GHSA-jg55-46h5-pq76.json new file mode 100644 index 00000000000..1441398fada --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jg55-46h5-pq76/GHSA-jg55-46h5-pq76.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jg55-46h5-pq76", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30832" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Event Post allows DOM-Based XSS. This issue affects Themify Event Post: from n/a through 1.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30832" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/themify-event-post/vulnerability/wordpress-themify-event-post-plugin-1-3-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jmhj-4wgh-cqpx/GHSA-jmhj-4wgh-cqpx.json b/advisories/unreviewed/2025/03/GHSA-jmhj-4wgh-cqpx/GHSA-jmhj-4wgh-cqpx.json new file mode 100644 index 00000000000..49f0b5739e5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jmhj-4wgh-cqpx/GHSA-jmhj-4wgh-cqpx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmhj-4wgh-cqpx", + "modified": "2025-03-27T12:30:36Z", + "published": "2025-03-27T12:30:36Z", + "aliases": [ + "CVE-2025-30777" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in PalsCode Support Genix allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Support Genix: from n/a through 1.4.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30777" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/support-genix-lite/vulnerability/wordpress-support-genix-1-4-11-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m99c-f758-cpx9/GHSA-m99c-f758-cpx9.json b/advisories/unreviewed/2025/03/GHSA-m99c-f758-cpx9/GHSA-m99c-f758-cpx9.json new file mode 100644 index 00000000000..83a3cb5054c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m99c-f758-cpx9/GHSA-m99c-f758-cpx9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m99c-f758-cpx9", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30822" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Hakik Zaman Custom Login Logo allows Cross Site Request Forgery. This issue affects Custom Login Logo: from n/a through 1.1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30822" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ideal-wp-login-logo-changer/vulnerability/wordpress-custom-login-logo-plugin-1-1-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m9v4-8vpr-cf66/GHSA-m9v4-8vpr-cf66.json b/advisories/unreviewed/2025/03/GHSA-m9v4-8vpr-cf66/GHSA-m9v4-8vpr-cf66.json new file mode 100644 index 00000000000..769d2f89130 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m9v4-8vpr-cf66/GHSA-m9v4-8vpr-cf66.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9v4-8vpr-cf66", + "modified": "2025-03-27T12:30:42Z", + "published": "2025-03-27T12:30:42Z", + "aliases": [ + "CVE-2025-30899" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration allows Stored XSS. This issue affects User Registration: from n/a through 4.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30899" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/user-registration/vulnerability/wordpress-user-registration-plugin-4-0-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mc44-cf28-88w6/GHSA-mc44-cf28-88w6.json b/advisories/unreviewed/2025/03/GHSA-mc44-cf28-88w6/GHSA-mc44-cf28-88w6.json new file mode 100644 index 00000000000..9997b2c9144 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mc44-cf28-88w6/GHSA-mc44-cf28-88w6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc44-cf28-88w6", + "modified": "2025-03-27T12:30:41Z", + "published": "2025-03-27T12:30:41Z", + "aliases": [ + "CVE-2025-30879" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in moreconvert MC Woocommerce Wishlist allows SQL Injection. This issue affects MC Woocommerce Wishlist: from n/a through 1.8.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30879" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/smart-wishlist-for-more-convert/vulnerability/wordpress-mc-woocommerce-wishlist-plugin-1-8-9-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mc5q-7r6f-q289/GHSA-mc5q-7r6f-q289.json b/advisories/unreviewed/2025/03/GHSA-mc5q-7r6f-q289/GHSA-mc5q-7r6f-q289.json new file mode 100644 index 00000000000..f4b3292e411 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mc5q-7r6f-q289/GHSA-mc5q-7r6f-q289.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc5q-7r6f-q289", + "modified": "2025-03-27T12:30:36Z", + "published": "2025-03-27T12:30:36Z", + "aliases": [ + "CVE-2025-30784" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Shuffle WP Subscription Forms allows SQL Injection. This issue affects WP Subscription Forms: from n/a through 1.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30784" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-subscription-forms/vulnerability/wordpress-wp-subscription-forms-1-2-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mr63-pqhx-87fh/GHSA-mr63-pqhx-87fh.json b/advisories/unreviewed/2025/03/GHSA-mr63-pqhx-87fh/GHSA-mr63-pqhx-87fh.json new file mode 100644 index 00000000000..8a7c7059635 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mr63-pqhx-87fh/GHSA-mr63-pqhx-87fh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr63-pqhx-87fh", + "modified": "2025-03-27T12:30:39Z", + "published": "2025-03-27T12:30:39Z", + "aliases": [ + "CVE-2025-30861" + ], + "details": "Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Five Star Restaurant Reservations: from n/a through 2.6.29.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30861" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/restaurant-reservations/vulnerability/wordpress-five-star-restaurant-reservations-plugin-2-6-29-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mx8c-52f3-fxr6/GHSA-mx8c-52f3-fxr6.json b/advisories/unreviewed/2025/03/GHSA-mx8c-52f3-fxr6/GHSA-mx8c-52f3-fxr6.json new file mode 100644 index 00000000000..252e13b58bd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mx8c-52f3-fxr6/GHSA-mx8c-52f3-fxr6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx8c-52f3-fxr6", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30815" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Saeed Sattar Beglou Hesabfa Accounting allows Cross Site Request Forgery. This issue affects Hesabfa Accounting: from n/a through 2.1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30815" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hesabfa-accounting/vulnerability/wordpress-hesabfa-accounting-plugin-2-1-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p26f-fw78-p227/GHSA-p26f-fw78-p227.json b/advisories/unreviewed/2025/03/GHSA-p26f-fw78-p227/GHSA-p26f-fw78-p227.json new file mode 100644 index 00000000000..06747561b1d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p26f-fw78-p227/GHSA-p26f-fw78-p227.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p26f-fw78-p227", + "modified": "2025-03-27T12:30:36Z", + "published": "2025-03-27T12:30:36Z", + "aliases": [ + "CVE-2025-30769" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in alexvtn WIP WooCarousel Lite allows Stored XSS. This issue affects WIP WooCarousel Lite: from n/a through 1.1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30769" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wip-woocarousel-lite/vulnerability/wordpress-wip-woocarousel-lite-plugin-1-1-7-cross-site-request-forgery-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p5hx-48gr-36cj/GHSA-p5hx-48gr-36cj.json b/advisories/unreviewed/2025/03/GHSA-p5hx-48gr-36cj/GHSA-p5hx-48gr-36cj.json new file mode 100644 index 00000000000..da86f22be4c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p5hx-48gr-36cj/GHSA-p5hx-48gr-36cj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5hx-48gr-36cj", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30800" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atawai Gum Elementor Addon allows Stored XSS. This issue affects Gum Elementor Addon: from n/a through 1.3.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30800" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gum-elementor-addon/vulnerability/wordpress-gum-elementor-addon-plugin-1-3-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p8xc-gghv-3vfp/GHSA-p8xc-gghv-3vfp.json b/advisories/unreviewed/2025/03/GHSA-p8xc-gghv-3vfp/GHSA-p8xc-gghv-3vfp.json new file mode 100644 index 00000000000..6363febb93c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p8xc-gghv-3vfp/GHSA-p8xc-gghv-3vfp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8xc-gghv-3vfp", + "modified": "2025-03-27T12:30:39Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30846" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jetmonsters Restaurant Menu by MotoPress allows PHP Local File Inclusion. This issue affects Restaurant Menu by MotoPress: from n/a through 2.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30846" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mp-restaurant-menu/vulnerability/wordpress-restaurant-menu-by-motopress-plugin-2-4-4-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pj72-96mg-hvmq/GHSA-pj72-96mg-hvmq.json b/advisories/unreviewed/2025/03/GHSA-pj72-96mg-hvmq/GHSA-pj72-96mg-hvmq.json new file mode 100644 index 00000000000..515a55741a0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pj72-96mg-hvmq/GHSA-pj72-96mg-hvmq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj72-96mg-hvmq", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30809" + ], + "details": "Missing Authorization vulnerability in Shahjada Live Forms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Live Forms: from n/a through 4.8.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30809" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/liveforms/vulnerability/wordpress-wordpress-contact-form-drag-and-drop-form-builder-plugin-live-forms-plugin-4-8-4-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q3h2-vr58-4cr3/GHSA-q3h2-vr58-4cr3.json b/advisories/unreviewed/2025/03/GHSA-q3h2-vr58-4cr3/GHSA-q3h2-vr58-4cr3.json new file mode 100644 index 00000000000..94cde327b22 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q3h2-vr58-4cr3/GHSA-q3h2-vr58-4cr3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3h2-vr58-4cr3", + "modified": "2025-03-27T12:30:39Z", + "published": "2025-03-27T12:30:39Z", + "aliases": [ + "CVE-2025-30851" + ], + "details": "Missing Authorization vulnerability in Tickera Tickera allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Tickera: from n/a through 3.5.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30851" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/tickera-event-ticketing-system/vulnerability/wordpress-tickera-plugin-3-5-5-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qcm4-6wmx-254g/GHSA-qcm4-6wmx-254g.json b/advisories/unreviewed/2025/03/GHSA-qcm4-6wmx-254g/GHSA-qcm4-6wmx-254g.json new file mode 100644 index 00000000000..aa97bad58db --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qcm4-6wmx-254g/GHSA-qcm4-6wmx-254g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcm4-6wmx-254g", + "modified": "2025-03-27T12:30:40Z", + "published": "2025-03-27T12:30:40Z", + "aliases": [ + "CVE-2025-30877" + ], + "details": "Missing Authorization vulnerability in fatcatapps Quiz Cat allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Quiz Cat: from n/a through 3.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30877" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quiz-cat/vulnerability/wordpress-quiz-cat-plugin-3-0-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qhwm-jg9v-rw55/GHSA-qhwm-jg9v-rw55.json b/advisories/unreviewed/2025/03/GHSA-qhwm-jg9v-rw55/GHSA-qhwm-jg9v-rw55.json new file mode 100644 index 00000000000..d07c551abbb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qhwm-jg9v-rw55/GHSA-qhwm-jg9v-rw55.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhwm-jg9v-rw55", + "modified": "2025-03-27T12:30:41Z", + "published": "2025-03-27T12:30:41Z", + "aliases": [ + "CVE-2025-30885" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Bit Apps Bit Form – Contact Form Plugin allows Phishing. This issue affects Bit Form – Contact Form Plugin: from n/a through 2.18.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30885" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bit-form/vulnerability/wordpress-bit-form-plugin-2-18-0-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qm5m-qmr4-7xjp/GHSA-qm5m-qmr4-7xjp.json b/advisories/unreviewed/2025/03/GHSA-qm5m-qmr4-7xjp/GHSA-qm5m-qmr4-7xjp.json new file mode 100644 index 00000000000..920580b8f78 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qm5m-qmr4-7xjp/GHSA-qm5m-qmr4-7xjp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm5m-qmr4-7xjp", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30812" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Addons for Elementor allows Stored XSS. This issue affects SKT Addons for Elementor: from n/a through 3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30812" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/skt-addons-for-elementor/vulnerability/wordpress-skt-addons-for-elementor-plugin-3-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qrww-fvjf-83pv/GHSA-qrww-fvjf-83pv.json b/advisories/unreviewed/2025/03/GHSA-qrww-fvjf-83pv/GHSA-qrww-fvjf-83pv.json new file mode 100644 index 00000000000..5f2f5e6313e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qrww-fvjf-83pv/GHSA-qrww-fvjf-83pv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrww-fvjf-83pv", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30821" + ], + "details": "Missing Authorization vulnerability in otacke SNORDIAN's H5PxAPIkatchu allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects SNORDIAN's H5PxAPIkatchu: from n/a through 0.4.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30821" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/h5pxapikatchu/vulnerability/wordpress-snordian-s-h5pxapikatchu-plugin-0-4-14-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qxch-j636-m8qc/GHSA-qxch-j636-m8qc.json b/advisories/unreviewed/2025/03/GHSA-qxch-j636-m8qc/GHSA-qxch-j636-m8qc.json new file mode 100644 index 00000000000..70c2f7df925 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qxch-j636-m8qc/GHSA-qxch-j636-m8qc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qxch-j636-m8qc", + "modified": "2025-03-27T12:30:42Z", + "published": "2025-03-27T12:30:42Z", + "aliases": [ + "CVE-2025-30904" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Chartify allows Stored XSS. This issue affects Chartify: from n/a through 3.1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30904" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/chart-builder/vulnerability/wordpress-chartify-plugin-3-1-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r2rj-82xh-h6px/GHSA-r2rj-82xh-h6px.json b/advisories/unreviewed/2025/03/GHSA-r2rj-82xh-h6px/GHSA-r2rj-82xh-h6px.json new file mode 100644 index 00000000000..82c8085b3ac --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r2rj-82xh-h6px/GHSA-r2rj-82xh-h6px.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2rj-82xh-h6px", + "modified": "2025-03-27T12:30:35Z", + "published": "2025-03-27T12:30:35Z", + "aliases": [ + "CVE-2025-30765" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPPOOL FlexStock allows Blind SQL Injection. This issue affects FlexStock: from n/a through 3.13.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30765" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/stock-sync-with-google-sheet-for-woocommerce/vulnerability/wordpress-flexstock-3-13-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r73f-pr65-xxgg/GHSA-r73f-pr65-xxgg.json b/advisories/unreviewed/2025/03/GHSA-r73f-pr65-xxgg/GHSA-r73f-pr65-xxgg.json new file mode 100644 index 00000000000..e7a57b98dca --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r73f-pr65-xxgg/GHSA-r73f-pr65-xxgg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r73f-pr65-xxgg", + "modified": "2025-03-27T12:30:43Z", + "published": "2025-03-27T12:30:43Z", + "aliases": [ + "CVE-2025-30918" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codemacher Structured Content allows Stored XSS. This issue affects Structured Content: from n/a through 1.6.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30918" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/structured-content/vulnerability/wordpress-structured-content-plugin-1-6-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rpjr-7xhj-qm95/GHSA-rpjr-7xhj-qm95.json b/advisories/unreviewed/2025/03/GHSA-rpjr-7xhj-qm95/GHSA-rpjr-7xhj-qm95.json new file mode 100644 index 00000000000..79eaaa035fe --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rpjr-7xhj-qm95/GHSA-rpjr-7xhj-qm95.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpjr-7xhj-qm95", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30792" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zumbo Comment Approved Notifier Extended allows Stored XSS. This issue affects Comment Approved Notifier Extended: from n/a through 5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30792" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/comment-approved-notifier-extended/vulnerability/wordpress-comment-approved-notifier-extended-plugin-5-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rv5p-vq45-gc4r/GHSA-rv5p-vq45-gc4r.json b/advisories/unreviewed/2025/03/GHSA-rv5p-vq45-gc4r/GHSA-rv5p-vq45-gc4r.json new file mode 100644 index 00000000000..f38b1d98061 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rv5p-vq45-gc4r/GHSA-rv5p-vq45-gc4r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv5p-vq45-gc4r", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30799" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pagup WP Google Street View allows Stored XSS. This issue affects WP Google Street View: from n/a through 1.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30799" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-google-street-view/vulnerability/wordpress-wp-google-street-view-plugin-1-1-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v2fq-9w48-jj62/GHSA-v2fq-9w48-jj62.json b/advisories/unreviewed/2025/03/GHSA-v2fq-9w48-jj62/GHSA-v2fq-9w48-jj62.json new file mode 100644 index 00000000000..7c3cb4eca8e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v2fq-9w48-jj62/GHSA-v2fq-9w48-jj62.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2fq-9w48-jj62", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30783" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in jgwhite33 WP Google Review Slider allows SQL Injection. This issue affects WP Google Review Slider: from n/a through 16.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30783" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-google-places-review-slider/vulnerability/wordpress-wp-google-review-slider-plugin-16-0-csrf-to-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v6p2-q97p-rvqj/GHSA-v6p2-q97p-rvqj.json b/advisories/unreviewed/2025/03/GHSA-v6p2-q97p-rvqj/GHSA-v6p2-q97p-rvqj.json new file mode 100644 index 00000000000..74957b0df46 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v6p2-q97p-rvqj/GHSA-v6p2-q97p-rvqj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6p2-q97p-rvqj", + "modified": "2025-03-27T12:30:42Z", + "published": "2025-03-27T12:30:42Z", + "aliases": [ + "CVE-2025-30907" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SecuPress SecuPress Free allows DOM-Based XSS. This issue affects SecuPress Free: from n/a through 2.2.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30907" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/secupress/vulnerability/wordpress-secupress-free-plugin-2-2-5-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v6pj-45gc-fg24/GHSA-v6pj-45gc-fg24.json b/advisories/unreviewed/2025/03/GHSA-v6pj-45gc-fg24/GHSA-v6pj-45gc-fg24.json new file mode 100644 index 00000000000..30ac7e8e58d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v6pj-45gc-fg24/GHSA-v6pj-45gc-fg24.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6pj-45gc-fg24", + "modified": "2025-03-27T12:30:36Z", + "published": "2025-03-27T12:30:36Z", + "aliases": [ + "CVE-2025-30776" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webvitaly Sitekit allows Stored XSS. This issue affects Sitekit: from n/a through 1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30776" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sitekit/vulnerability/wordpress-sitekit-1-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vph9-j5h2-h3xp/GHSA-vph9-j5h2-h3xp.json b/advisories/unreviewed/2025/03/GHSA-vph9-j5h2-h3xp/GHSA-vph9-j5h2-h3xp.json new file mode 100644 index 00000000000..45b96342c67 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vph9-j5h2-h3xp/GHSA-vph9-j5h2-h3xp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vph9-j5h2-h3xp", + "modified": "2025-03-27T12:30:41Z", + "published": "2025-03-27T12:30:41Z", + "aliases": [ + "CVE-2025-30887" + ], + "details": "Missing Authorization vulnerability in magepeopleteam WpEvently allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpEvently: from n/a through 4.2.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30887" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mage-eventpress/vulnerability/wordpress-wpevently-plugin-4-2-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w2c7-4rv6-wc59/GHSA-w2c7-4rv6-wc59.json b/advisories/unreviewed/2025/03/GHSA-w2c7-4rv6-wc59/GHSA-w2c7-4rv6-wc59.json new file mode 100644 index 00000000000..7995982b575 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w2c7-4rv6-wc59/GHSA-w2c7-4rv6-wc59.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2c7-4rv6-wc59", + "modified": "2025-03-27T12:30:43Z", + "published": "2025-03-27T12:30:43Z", + "aliases": [ + "CVE-2025-31140" + ], + "details": "In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31140" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w2qm-hvp5-mjwc/GHSA-w2qm-hvp5-mjwc.json b/advisories/unreviewed/2025/03/GHSA-w2qm-hvp5-mjwc/GHSA-w2qm-hvp5-mjwc.json new file mode 100644 index 00000000000..d0cda8e4b89 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w2qm-hvp5-mjwc/GHSA-w2qm-hvp5-mjwc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2qm-hvp5-mjwc", + "modified": "2025-03-27T12:30:42Z", + "published": "2025-03-27T12:30:42Z", + "aliases": [ + "CVE-2025-30894" + ], + "details": "Missing Authorization vulnerability in Epsiloncool WP Fast Total Search allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Fast Total Search: from n/a through 1.79.262.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30894" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fulltext-search/vulnerability/wordpress-wp-fast-total-search-plugin-1-79-262-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w755-j5x5-cpjx/GHSA-w755-j5x5-cpjx.json b/advisories/unreviewed/2025/03/GHSA-w755-j5x5-cpjx/GHSA-w755-j5x5-cpjx.json new file mode 100644 index 00000000000..8ba27ec7c60 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w755-j5x5-cpjx/GHSA-w755-j5x5-cpjx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w755-j5x5-cpjx", + "modified": "2025-03-27T12:30:40Z", + "published": "2025-03-27T12:30:40Z", + "aliases": [ + "CVE-2025-30868" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in DynamicWebLab Team Manager allows PHP Local File Inclusion. This issue affects Team Manager: from n/a through 2.1.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30868" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-team-manager/vulnerability/wordpress-team-manager-plugin-2-1-23-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w89r-rwcf-75w7/GHSA-w89r-rwcf-75w7.json b/advisories/unreviewed/2025/03/GHSA-w89r-rwcf-75w7/GHSA-w89r-rwcf-75w7.json new file mode 100644 index 00000000000..b1034ac29b0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w89r-rwcf-75w7/GHSA-w89r-rwcf-75w7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w89r-rwcf-75w7", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30790" + ], + "details": "Missing Authorization vulnerability in alexvtn Chatbox Manager allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Chatbox Manager: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30790" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wa-chatbox-manager/vulnerability/wordpress-chatbox-manager-1-2-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w978-xrc7-3v35/GHSA-w978-xrc7-3v35.json b/advisories/unreviewed/2025/03/GHSA-w978-xrc7-3v35/GHSA-w978-xrc7-3v35.json new file mode 100644 index 00000000000..5b94bb05f36 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w978-xrc7-3v35/GHSA-w978-xrc7-3v35.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w978-xrc7-3v35", + "modified": "2025-03-27T12:30:42Z", + "published": "2025-03-27T12:30:42Z", + "aliases": [ + "CVE-2025-30912" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Float menu allows Cross Site Request Forgery. This issue affects Float menu: from n/a through 6.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30912" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/float-menu/vulnerability/wordpress-float-menu-plugin-6-1-2-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wcr9-xqp2-2pqv/GHSA-wcr9-xqp2-2pqv.json b/advisories/unreviewed/2025/03/GHSA-wcr9-xqp2-2pqv/GHSA-wcr9-xqp2-2pqv.json new file mode 100644 index 00000000000..b71c30faf72 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wcr9-xqp2-2pqv/GHSA-wcr9-xqp2-2pqv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcr9-xqp2-2pqv", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30839" + ], + "details": "Missing Authorization vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Taxi Booking Manager for WooCommerce: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30839" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ecab-taxi-booking-manager/vulnerability/wordpress-taxi-booking-manager-for-woocommerce-plugin-1-2-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wg9v-hwjw-wm7j/GHSA-wg9v-hwjw-wm7j.json b/advisories/unreviewed/2025/03/GHSA-wg9v-hwjw-wm7j/GHSA-wg9v-hwjw-wm7j.json new file mode 100644 index 00000000000..270a5c04e42 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wg9v-hwjw-wm7j/GHSA-wg9v-hwjw-wm7j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg9v-hwjw-wm7j", + "modified": "2025-03-27T12:30:37Z", + "published": "2025-03-27T12:30:37Z", + "aliases": [ + "CVE-2025-30787" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Eli EZ SQL Reports Shortcode Widget and DB Backup allows Stored XSS. This issue affects EZ SQL Reports Shortcode Widget and DB Backup: from n/a through 5.25.08.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30787" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/elisqlreports/vulnerability/wordpress-ez-sql-reports-shortcode-widget-and-db-backup-plugin-5-25-08-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x3cf-5gqm-6j2g/GHSA-x3cf-5gqm-6j2g.json b/advisories/unreviewed/2025/03/GHSA-x3cf-5gqm-6j2g/GHSA-x3cf-5gqm-6j2g.json new file mode 100644 index 00000000000..1f9eb91d54f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x3cf-5gqm-6j2g/GHSA-x3cf-5gqm-6j2g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3cf-5gqm-6j2g", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30842" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in pixolette Christmas Panda allows Cross Site Request Forgery. This issue affects Christmas Panda: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30842" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/christmas-panda/vulnerability/wordpress-christmas-panda-plugin-1-0-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x4qh-62jr-rhwm/GHSA-x4qh-62jr-rhwm.json b/advisories/unreviewed/2025/03/GHSA-x4qh-62jr-rhwm/GHSA-x4qh-62jr-rhwm.json new file mode 100644 index 00000000000..d193dd1b7c8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x4qh-62jr-rhwm/GHSA-x4qh-62jr-rhwm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4qh-62jr-rhwm", + "modified": "2025-03-27T12:30:41Z", + "published": "2025-03-27T12:30:41Z", + "aliases": [ + "CVE-2025-30883" + ], + "details": "Missing Authorization vulnerability in richplugins Trust.Reviews allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Trust.Reviews: from n/a through 2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30883" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fb-reviews-widget/vulnerability/wordpress-trust-reviews-plugin-2-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x6cg-v5q2-p8xv/GHSA-x6cg-v5q2-p8xv.json b/advisories/unreviewed/2025/03/GHSA-x6cg-v5q2-p8xv/GHSA-x6cg-v5q2-p8xv.json new file mode 100644 index 00000000000..1199a2c0567 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x6cg-v5q2-p8xv/GHSA-x6cg-v5q2-p8xv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6cg-v5q2-p8xv", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30829" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themewinter WPCafe allows PHP Local File Inclusion. This issue affects WPCafe: from n/a through 2.2.31.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30829" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-cafe/vulnerability/wordpress-wpcafe-plugin-2-2-31-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x728-fv32-49g6/GHSA-x728-fv32-49g6.json b/advisories/unreviewed/2025/03/GHSA-x728-fv32-49g6/GHSA-x728-fv32-49g6.json new file mode 100644 index 00000000000..a77e319ff3e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x728-fv32-49g6/GHSA-x728-fv32-49g6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x728-fv32-49g6", + "modified": "2025-03-27T12:30:39Z", + "published": "2025-03-27T12:30:39Z", + "aliases": [ + "CVE-2025-30860" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jory Hogeveen Off-Canvas Sidebars & Menus (Slidebars) allows DOM-Based XSS. This issue affects Off-Canvas Sidebars & Menus (Slidebars): from n/a through 0.5.8.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30860" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/off-canvas-sidebars/vulnerability/wordpress-off-canvas-sidebars-menus-slidebars-plugin-0-5-8-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xg7j-j7fr-8hhf/GHSA-xg7j-j7fr-8hhf.json b/advisories/unreviewed/2025/03/GHSA-xg7j-j7fr-8hhf/GHSA-xg7j-j7fr-8hhf.json new file mode 100644 index 00000000000..3fa2e8adfc9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xg7j-j7fr-8hhf/GHSA-xg7j-j7fr-8hhf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xg7j-j7fr-8hhf", + "modified": "2025-03-27T12:30:38Z", + "published": "2025-03-27T12:30:38Z", + "aliases": [ + "CVE-2025-30831" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themifyme Themify Event Post allows PHP Local File Inclusion. This issue affects Themify Event Post: from n/a through 1.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30831" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/themify-event-post/vulnerability/wordpress-themify-event-post-plugin-1-3-2-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xpxj-fcm9-9v47/GHSA-xpxj-fcm9-9v47.json b/advisories/unreviewed/2025/03/GHSA-xpxj-fcm9-9v47/GHSA-xpxj-fcm9-9v47.json new file mode 100644 index 00000000000..b4bc69cbb58 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xpxj-fcm9-9v47/GHSA-xpxj-fcm9-9v47.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpxj-fcm9-9v47", + "modified": "2025-03-27T12:30:42Z", + "published": "2025-03-27T12:30:42Z", + "aliases": [ + "CVE-2025-30897" + ], + "details": "Missing Authorization vulnerability in Adnan Analytify allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Analytify: from n/a through 5.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30897" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-analytify/vulnerability/wordpress-analytify-plugin-5-5-1-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xx43-h94m-wj64/GHSA-xx43-h94m-wj64.json b/advisories/unreviewed/2025/03/GHSA-xx43-h94m-wj64/GHSA-xx43-h94m-wj64.json new file mode 100644 index 00000000000..76d27181941 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xx43-h94m-wj64/GHSA-xx43-h94m-wj64.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xx43-h94m-wj64", + "modified": "2025-03-27T12:30:40Z", + "published": "2025-03-27T12:30:40Z", + "aliases": [ + "CVE-2025-30873" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift allows Stored XSS. This issue affects Greenshift: from n/a through 11.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30873" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/greenshift-animation-and-page-builder-blocks/vulnerability/wordpress-greenshift-plugin-11-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T11:15:48Z" + } +} \ No newline at end of file