diff --git a/advisories/unreviewed/2024/05/GHSA-hg6j-8h7m-3w3j/GHSA-hg6j-8h7m-3w3j.json b/advisories/unreviewed/2024/05/GHSA-hg6j-8h7m-3w3j/GHSA-hg6j-8h7m-3w3j.json index 23c25b74a39..c55415d6f17 100644 --- a/advisories/unreviewed/2024/05/GHSA-hg6j-8h7m-3w3j/GHSA-hg6j-8h7m-3w3j.json +++ b/advisories/unreviewed/2024/05/GHSA-hg6j-8h7m-3w3j/GHSA-hg6j-8h7m-3w3j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hg6j-8h7m-3w3j", - "modified": "2024-05-07T18:30:33Z", + "modified": "2025-04-19T03:31:26Z", "published": "2024-05-07T18:30:33Z", "aliases": [ "CVE-2024-27982" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://hackerone.com/reports/2237099" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250418-0001" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-83g6-wm8c-3hx9/GHSA-83g6-wm8c-3hx9.json b/advisories/unreviewed/2024/12/GHSA-83g6-wm8c-3hx9/GHSA-83g6-wm8c-3hx9.json index a0985fb1f31..181904e2020 100644 --- a/advisories/unreviewed/2024/12/GHSA-83g6-wm8c-3hx9/GHSA-83g6-wm8c-3hx9.json +++ b/advisories/unreviewed/2024/12/GHSA-83g6-wm8c-3hx9/GHSA-83g6-wm8c-3hx9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-83g6-wm8c-3hx9", - "modified": "2024-12-13T18:31:56Z", + "modified": "2025-04-19T03:31:27Z", "published": "2024-12-12T03:33:07Z", "aliases": [ "CVE-2024-54534" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54534" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250418-0002" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/121837" diff --git a/advisories/unreviewed/2025/01/GHSA-r9fv-h47r-823f/GHSA-r9fv-h47r-823f.json b/advisories/unreviewed/2025/01/GHSA-r9fv-h47r-823f/GHSA-r9fv-h47r-823f.json index 03b91c578bc..27250450af6 100644 --- a/advisories/unreviewed/2025/01/GHSA-r9fv-h47r-823f/GHSA-r9fv-h47r-823f.json +++ b/advisories/unreviewed/2025/01/GHSA-r9fv-h47r-823f/GHSA-r9fv-h47r-823f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r9fv-h47r-823f", - "modified": "2025-01-27T21:30:53Z", + "modified": "2025-04-19T03:31:27Z", "published": "2025-01-20T15:31:22Z", "aliases": [ "CVE-2024-13176" @@ -55,6 +55,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20250124-0005" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250418-0010" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/01/20/2" diff --git a/advisories/unreviewed/2025/04/GHSA-4658-qgx5-q5g3/GHSA-4658-qgx5-q5g3.json b/advisories/unreviewed/2025/04/GHSA-4658-qgx5-q5g3/GHSA-4658-qgx5-q5g3.json new file mode 100644 index 00000000000..bc1a14a0ed8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4658-qgx5-q5g3/GHSA-4658-qgx5-q5g3.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4658-qgx5-q5g3", + "modified": "2025-04-19T03:31:27Z", + "published": "2025-04-19T03:31:27Z", + "aliases": [ + "CVE-2025-43893" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43893" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T03:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4w4c-3fhx-c3w8/GHSA-4w4c-3fhx-c3w8.json b/advisories/unreviewed/2025/04/GHSA-4w4c-3fhx-c3w8/GHSA-4w4c-3fhx-c3w8.json new file mode 100644 index 00000000000..6bb6adaefa1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4w4c-3fhx-c3w8/GHSA-4w4c-3fhx-c3w8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4w4c-3fhx-c3w8", + "modified": "2025-04-19T03:31:27Z", + "published": "2025-04-19T03:31:27Z", + "aliases": [ + "CVE-2025-3278" + ], + "details": "The UrbanGo Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.4. This is due to the plugin allowing users who are registering new accounts to set their own role or by supplying 'user_register_role' field. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the administrator role.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3278" + }, + { + "type": "WEB", + "url": "https://themeforest.net/item/urbango-directory-and-listing-wordpress-theme/22712624" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/913ffe0c-c8f8-4cda-be9a-96c056d4c4a8?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T03:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-53hw-hvww-v6v8/GHSA-53hw-hvww-v6v8.json b/advisories/unreviewed/2025/04/GHSA-53hw-hvww-v6v8/GHSA-53hw-hvww-v6v8.json index ca814ca1d0b..e6cc591e6f4 100644 --- a/advisories/unreviewed/2025/04/GHSA-53hw-hvww-v6v8/GHSA-53hw-hvww-v6v8.json +++ b/advisories/unreviewed/2025/04/GHSA-53hw-hvww-v6v8/GHSA-53hw-hvww-v6v8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-53hw-hvww-v6v8", - "modified": "2025-04-15T21:31:48Z", + "modified": "2025-04-19T03:31:27Z", "published": "2025-04-15T21:31:48Z", "aliases": [ "CVE-2025-30722" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30722" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250418-0005" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2025.html" diff --git a/advisories/unreviewed/2025/04/GHSA-5hvr-5483-gj3f/GHSA-5hvr-5483-gj3f.json b/advisories/unreviewed/2025/04/GHSA-5hvr-5483-gj3f/GHSA-5hvr-5483-gj3f.json new file mode 100644 index 00000000000..ae10dddf2c1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5hvr-5483-gj3f/GHSA-5hvr-5483-gj3f.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hvr-5483-gj3f", + "modified": "2025-04-19T03:31:27Z", + "published": "2025-04-19T03:31:27Z", + "aliases": [ + "CVE-2025-43895" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43895" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T03:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5xv7-xrgm-g78v/GHSA-5xv7-xrgm-g78v.json b/advisories/unreviewed/2025/04/GHSA-5xv7-xrgm-g78v/GHSA-5xv7-xrgm-g78v.json index 14f64692355..783264bbf69 100644 --- a/advisories/unreviewed/2025/04/GHSA-5xv7-xrgm-g78v/GHSA-5xv7-xrgm-g78v.json +++ b/advisories/unreviewed/2025/04/GHSA-5xv7-xrgm-g78v/GHSA-5xv7-xrgm-g78v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5xv7-xrgm-g78v", - "modified": "2025-04-15T21:31:45Z", + "modified": "2025-04-19T03:31:27Z", "published": "2025-04-15T21:31:45Z", "aliases": [ "CVE-2025-21588" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21588" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250418-0008" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2025.html" diff --git a/advisories/unreviewed/2025/04/GHSA-6xrp-g57p-cr3v/GHSA-6xrp-g57p-cr3v.json b/advisories/unreviewed/2025/04/GHSA-6xrp-g57p-cr3v/GHSA-6xrp-g57p-cr3v.json new file mode 100644 index 00000000000..ca3a2cbec01 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6xrp-g57p-cr3v/GHSA-6xrp-g57p-cr3v.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xrp-g57p-cr3v", + "modified": "2025-04-19T03:31:27Z", + "published": "2025-04-19T03:31:27Z", + "aliases": [ + "CVE-2025-43897" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43897" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T03:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7g4r-49h3-32mr/GHSA-7g4r-49h3-32mr.json b/advisories/unreviewed/2025/04/GHSA-7g4r-49h3-32mr/GHSA-7g4r-49h3-32mr.json index 9ff6bc8058e..7c83813a190 100644 --- a/advisories/unreviewed/2025/04/GHSA-7g4r-49h3-32mr/GHSA-7g4r-49h3-32mr.json +++ b/advisories/unreviewed/2025/04/GHSA-7g4r-49h3-32mr/GHSA-7g4r-49h3-32mr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7g4r-49h3-32mr", - "modified": "2025-04-15T21:31:45Z", + "modified": "2025-04-19T03:31:27Z", "published": "2025-04-15T21:31:44Z", "aliases": [ "CVE-2025-21583" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21583" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250418-0009" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2025.html" diff --git a/advisories/unreviewed/2025/04/GHSA-9356-wjh4-9wpv/GHSA-9356-wjh4-9wpv.json b/advisories/unreviewed/2025/04/GHSA-9356-wjh4-9wpv/GHSA-9356-wjh4-9wpv.json new file mode 100644 index 00000000000..31c00be97aa --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9356-wjh4-9wpv/GHSA-9356-wjh4-9wpv.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9356-wjh4-9wpv", + "modified": "2025-04-19T03:31:27Z", + "published": "2025-04-19T03:31:27Z", + "aliases": [ + "CVE-2025-43896" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43896" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T03:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9hhp-cv8g-63fg/GHSA-9hhp-cv8g-63fg.json b/advisories/unreviewed/2025/04/GHSA-9hhp-cv8g-63fg/GHSA-9hhp-cv8g-63fg.json new file mode 100644 index 00000000000..e76cba72648 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9hhp-cv8g-63fg/GHSA-9hhp-cv8g-63fg.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hhp-cv8g-63fg", + "modified": "2025-04-19T03:31:27Z", + "published": "2025-04-19T03:31:27Z", + "aliases": [ + "CVE-2025-43901" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43901" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T03:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fm2p-hxg8-3rvv/GHSA-fm2p-hxg8-3rvv.json b/advisories/unreviewed/2025/04/GHSA-fm2p-hxg8-3rvv/GHSA-fm2p-hxg8-3rvv.json new file mode 100644 index 00000000000..fbf11c0d030 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fm2p-hxg8-3rvv/GHSA-fm2p-hxg8-3rvv.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm2p-hxg8-3rvv", + "modified": "2025-04-19T03:31:27Z", + "published": "2025-04-19T03:31:27Z", + "aliases": [ + "CVE-2025-43894" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43894" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T03:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hcwj-629m-xh6w/GHSA-hcwj-629m-xh6w.json b/advisories/unreviewed/2025/04/GHSA-hcwj-629m-xh6w/GHSA-hcwj-629m-xh6w.json new file mode 100644 index 00000000000..2404cc13a6a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hcwj-629m-xh6w/GHSA-hcwj-629m-xh6w.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcwj-629m-xh6w", + "modified": "2025-04-19T03:31:27Z", + "published": "2025-04-19T03:31:27Z", + "aliases": [ + "CVE-2025-43898" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43898" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T03:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j689-xjmx-x4qh/GHSA-j689-xjmx-x4qh.json b/advisories/unreviewed/2025/04/GHSA-j689-xjmx-x4qh/GHSA-j689-xjmx-x4qh.json new file mode 100644 index 00000000000..79ce9d9a1c1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j689-xjmx-x4qh/GHSA-j689-xjmx-x4qh.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j689-xjmx-x4qh", + "modified": "2025-04-19T03:31:27Z", + "published": "2025-04-19T03:31:27Z", + "aliases": [ + "CVE-2025-43899" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43899" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T03:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mggc-p7wh-5pvx/GHSA-mggc-p7wh-5pvx.json b/advisories/unreviewed/2025/04/GHSA-mggc-p7wh-5pvx/GHSA-mggc-p7wh-5pvx.json new file mode 100644 index 00000000000..370454c1990 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mggc-p7wh-5pvx/GHSA-mggc-p7wh-5pvx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mggc-p7wh-5pvx", + "modified": "2025-04-19T03:31:27Z", + "published": "2025-04-19T03:31:27Z", + "aliases": [ + "CVE-2025-3284" + ], + "details": "The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.3. This is due to missing or incorrect nonce validation on the user_registration_pro_delete_account() function. This makes it possible for unauthenticated attackers to force delete users, including administrators, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3284" + }, + { + "type": "WEB", + "url": "https://wpuserregistration.com/changelog" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4616b609-e8dc-4004-a5b7-2de3e83719be?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T03:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mxpq-3mg3-vqx7/GHSA-mxpq-3mg3-vqx7.json b/advisories/unreviewed/2025/04/GHSA-mxpq-3mg3-vqx7/GHSA-mxpq-3mg3-vqx7.json index a4cbb36ebbe..96649508ddd 100644 --- a/advisories/unreviewed/2025/04/GHSA-mxpq-3mg3-vqx7/GHSA-mxpq-3mg3-vqx7.json +++ b/advisories/unreviewed/2025/04/GHSA-mxpq-3mg3-vqx7/GHSA-mxpq-3mg3-vqx7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mxpq-3mg3-vqx7", - "modified": "2025-04-15T21:31:47Z", + "modified": "2025-04-19T03:31:27Z", "published": "2025-04-15T21:31:47Z", "aliases": [ "CVE-2025-30706" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30706" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250418-0007" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2025.html" diff --git a/advisories/unreviewed/2025/04/GHSA-qh4r-w9x4-6fq2/GHSA-qh4r-w9x4-6fq2.json b/advisories/unreviewed/2025/04/GHSA-qh4r-w9x4-6fq2/GHSA-qh4r-w9x4-6fq2.json index 97403b99a42..942324dc71b 100644 --- a/advisories/unreviewed/2025/04/GHSA-qh4r-w9x4-6fq2/GHSA-qh4r-w9x4-6fq2.json +++ b/advisories/unreviewed/2025/04/GHSA-qh4r-w9x4-6fq2/GHSA-qh4r-w9x4-6fq2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qh4r-w9x4-6fq2", - "modified": "2025-04-15T21:31:46Z", + "modified": "2025-04-19T03:31:27Z", "published": "2025-04-15T21:31:46Z", "aliases": [ "CVE-2025-30691" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30691" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250418-0004" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2025.html" diff --git a/advisories/unreviewed/2025/04/GHSA-vvq7-6fc5-677w/GHSA-vvq7-6fc5-677w.json b/advisories/unreviewed/2025/04/GHSA-vvq7-6fc5-677w/GHSA-vvq7-6fc5-677w.json new file mode 100644 index 00000000000..0837e72a39a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vvq7-6fc5-677w/GHSA-vvq7-6fc5-677w.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvq7-6fc5-677w", + "modified": "2025-04-19T03:31:27Z", + "published": "2025-04-19T03:31:27Z", + "aliases": [ + "CVE-2025-43900" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43900" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T03:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x43c-732c-cxf3/GHSA-x43c-732c-cxf3.json b/advisories/unreviewed/2025/04/GHSA-x43c-732c-cxf3/GHSA-x43c-732c-cxf3.json new file mode 100644 index 00000000000..df0f4c5d0a4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x43c-732c-cxf3/GHSA-x43c-732c-cxf3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x43c-732c-cxf3", + "modified": "2025-04-19T03:31:27Z", + "published": "2025-04-19T03:31:27Z", + "aliases": [ + "CVE-2025-2010" + ], + "details": "The JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin plugin for WordPress is vulnerable to SQL Injection via the 'jobwp_upload_resume' parameter in all versions up to, and including, 2.3.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2010" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3271612/jobwp/tags/2.4.0/core/job_application.php?old=3230672&old_path=jobwp%2Ftags%2F2.3.9%2Fcore%2Fjob_application.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b3b658f0-b9d8-4b7f-8d40-39ce185ef797?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-19T03:15:13Z" + } +} \ No newline at end of file