diff --git a/advisories/unreviewed/2024/04/GHSA-6cjw-2w3q-pv7g/GHSA-6cjw-2w3q-pv7g.json b/advisories/unreviewed/2024/04/GHSA-6cjw-2w3q-pv7g/GHSA-6cjw-2w3q-pv7g.json index 0cf8ea6cb2d..f270321c249 100644 --- a/advisories/unreviewed/2024/04/GHSA-6cjw-2w3q-pv7g/GHSA-6cjw-2w3q-pv7g.json +++ b/advisories/unreviewed/2024/04/GHSA-6cjw-2w3q-pv7g/GHSA-6cjw-2w3q-pv7g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6cjw-2w3q-pv7g", - "modified": "2024-08-08T18:31:19Z", + "modified": "2025-06-06T15:30:34Z", "published": "2024-04-19T18:31:15Z", "aliases": [ "CVE-2023-50008" @@ -35,6 +35,18 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY" + }, { "type": "WEB", "url": "https://trac.ffmpeg.org/ticket/10701" diff --git a/advisories/unreviewed/2024/04/GHSA-9726-xp73-4p4q/GHSA-9726-xp73-4p4q.json b/advisories/unreviewed/2024/04/GHSA-9726-xp73-4p4q/GHSA-9726-xp73-4p4q.json index 4929b958758..04fa5ba9acb 100644 --- a/advisories/unreviewed/2024/04/GHSA-9726-xp73-4p4q/GHSA-9726-xp73-4p4q.json +++ b/advisories/unreviewed/2024/04/GHSA-9726-xp73-4p4q/GHSA-9726-xp73-4p4q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9726-xp73-4p4q", - "modified": "2024-07-03T18:36:06Z", + "modified": "2025-06-06T15:30:34Z", "published": "2024-04-19T18:31:15Z", "aliases": [ "CVE-2023-50009" @@ -39,6 +39,18 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY" + }, { "type": "WEB", "url": "https://trac.ffmpeg.org/ticket/10699" diff --git a/advisories/unreviewed/2024/04/GHSA-g3wp-whmx-cpqj/GHSA-g3wp-whmx-cpqj.json b/advisories/unreviewed/2024/04/GHSA-g3wp-whmx-cpqj/GHSA-g3wp-whmx-cpqj.json index e9d09049b01..51cd22180b2 100644 --- a/advisories/unreviewed/2024/04/GHSA-g3wp-whmx-cpqj/GHSA-g3wp-whmx-cpqj.json +++ b/advisories/unreviewed/2024/04/GHSA-g3wp-whmx-cpqj/GHSA-g3wp-whmx-cpqj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g3wp-whmx-cpqj", - "modified": "2024-07-03T18:36:06Z", + "modified": "2025-06-06T15:30:34Z", "published": "2024-04-19T18:31:15Z", "aliases": [ "CVE-2023-50010" @@ -35,6 +35,18 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY" + }, { "type": "WEB", "url": "https://trac.ffmpeg.org/ticket/10702" diff --git a/advisories/unreviewed/2024/04/GHSA-r8wj-r2jc-587q/GHSA-r8wj-r2jc-587q.json b/advisories/unreviewed/2024/04/GHSA-r8wj-r2jc-587q/GHSA-r8wj-r2jc-587q.json index b4f15a32d3d..18c916a905f 100644 --- a/advisories/unreviewed/2024/04/GHSA-r8wj-r2jc-587q/GHSA-r8wj-r2jc-587q.json +++ b/advisories/unreviewed/2024/04/GHSA-r8wj-r2jc-587q/GHSA-r8wj-r2jc-587q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r8wj-r2jc-587q", - "modified": "2024-07-03T18:36:06Z", + "modified": "2025-06-06T15:30:34Z", "published": "2024-04-19T18:31:14Z", "aliases": [ "CVE-2023-50007" @@ -35,6 +35,18 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6G7EYH2JAK5OJPVNC6AXYQ5K7YGYNCDN" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPETICRXUOGRIM4U3BCRTIKE3IZWCSBT" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE3ASLH6QF2E5OVJI5VA3JSEPJFFFMNY" + }, { "type": "WEB", "url": "https://trac.ffmpeg.org/ticket/10700" diff --git a/advisories/unreviewed/2024/05/GHSA-5mp7-g9p8-p9xx/GHSA-5mp7-g9p8-p9xx.json b/advisories/unreviewed/2024/05/GHSA-5mp7-g9p8-p9xx/GHSA-5mp7-g9p8-p9xx.json index c4b1587547b..e73fb7db625 100644 --- a/advisories/unreviewed/2024/05/GHSA-5mp7-g9p8-p9xx/GHSA-5mp7-g9p8-p9xx.json +++ b/advisories/unreviewed/2024/05/GHSA-5mp7-g9p8-p9xx/GHSA-5mp7-g9p8-p9xx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5mp7-g9p8-p9xx", - "modified": "2024-05-16T15:31:37Z", + "modified": "2025-06-06T15:30:34Z", "published": "2024-05-16T15:31:37Z", "aliases": [ "CVE-2024-4760" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4760" }, + { + "type": "WEB", + "url": "https://ww1.microchip.com/downloads/aemDocuments/documents/MCU32/ProductDocuments/SupportingCollateral/Security-Advisory-CVE-2024-4760.pdf" + }, { "type": "WEB", "url": "https://www.0x01team.com/hw_security/bypassing-microchip-atmel-sam-e70-s70-v70-v71-security" diff --git a/advisories/unreviewed/2025/06/GHSA-229c-m43q-2rqp/GHSA-229c-m43q-2rqp.json b/advisories/unreviewed/2025/06/GHSA-229c-m43q-2rqp/GHSA-229c-m43q-2rqp.json new file mode 100644 index 00000000000..4b6aba07efb --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-229c-m43q-2rqp/GHSA-229c-m43q-2rqp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-229c-m43q-2rqp", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-49235" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rometheme RTMKit Addons for Elementor allows Stored XSS. This issue affects RTMKit Addons for Elementor: from n/a through 1.6.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49235" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rometheme-for-elementor/vulnerability/wordpress-rtmkit-addons-for-elementor-plugin-1-6-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-22fr-57h7-x2qm/GHSA-22fr-57h7-x2qm.json b/advisories/unreviewed/2025/06/GHSA-22fr-57h7-x2qm/GHSA-22fr-57h7-x2qm.json new file mode 100644 index 00000000000..1d333e694ad --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-22fr-57h7-x2qm/GHSA-22fr-57h7-x2qm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22fr-57h7-x2qm", + "modified": "2025-06-06T15:30:52Z", + "published": "2025-06-06T15:30:52Z", + "aliases": [ + "CVE-2025-49446" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in minhlaobao Admin Notes allows Cross Site Request Forgery. This issue affects Admin Notes: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49446" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/admin-note/vulnerability/wordpress-admin-notes-1-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-272v-4hpv-gq59/GHSA-272v-4hpv-gq59.json b/advisories/unreviewed/2025/06/GHSA-272v-4hpv-gq59/GHSA-272v-4hpv-gq59.json new file mode 100644 index 00000000000..60fb3d6a9a0 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-272v-4hpv-gq59/GHSA-272v-4hpv-gq59.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-272v-4hpv-gq59", + "modified": "2025-06-06T15:30:45Z", + "published": "2025-06-06T15:30:45Z", + "aliases": [ + "CVE-2025-27334" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ángel C. Simple Google Static Map allows DOM-Based XSS. This issue affects Simple Google Static Map: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27334" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-google-static-map/vulnerability/wordpress-simple-google-static-map-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-27vr-5h5p-w59c/GHSA-27vr-5h5p-w59c.json b/advisories/unreviewed/2025/06/GHSA-27vr-5h5p-w59c/GHSA-27vr-5h5p-w59c.json new file mode 100644 index 00000000000..78944955112 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-27vr-5h5p-w59c/GHSA-27vr-5h5p-w59c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27vr-5h5p-w59c", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49308" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine allows PHP Local File Inclusion. This issue affects WP Travel Engine: from n/a through 6.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49308" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-travel-engine/vulnerability/wordpress-wp-travel-engine-6-5-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-2cw4-3jwf-xx2h/GHSA-2cw4-3jwf-xx2h.json b/advisories/unreviewed/2025/06/GHSA-2cw4-3jwf-xx2h/GHSA-2cw4-3jwf-xx2h.json new file mode 100644 index 00000000000..27e79de580e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-2cw4-3jwf-xx2h/GHSA-2cw4-3jwf-xx2h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cw4-3jwf-xx2h", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49270" + ], + "details": "Missing Authorization vulnerability in Mario Peshev WP-CRM System allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WP-CRM System: from n/a through 3.4.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49270" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-crm-system/vulnerability/wordpress-wp-crm-system-3-4-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-2gmr-34h7-prwx/GHSA-2gmr-34h7-prwx.json b/advisories/unreviewed/2025/06/GHSA-2gmr-34h7-prwx/GHSA-2gmr-34h7-prwx.json new file mode 100644 index 00000000000..03f38fabb8b --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-2gmr-34h7-prwx/GHSA-2gmr-34h7-prwx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gmr-34h7-prwx", + "modified": "2025-06-06T15:30:51Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49301" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift allows DOM-Based XSS. This issue affects Greenshift: from n/a through 11.5.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49301" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/greenshift-animation-and-page-builder-blocks/vulnerability/wordpress-greenshift-11-5-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-2j57-j25h-3fwc/GHSA-2j57-j25h-3fwc.json b/advisories/unreviewed/2025/06/GHSA-2j57-j25h-3fwc/GHSA-2j57-j25h-3fwc.json new file mode 100644 index 00000000000..d94e5335588 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-2j57-j25h-3fwc/GHSA-2j57-j25h-3fwc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2j57-j25h-3fwc", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-28974" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in mail250 Free WP Mail SMTP allows Stored XSS. This issue affects Free WP Mail SMTP: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28974" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/free-wp-mail-smtp/vulnerability/wordpress-free-wp-mail-smtp-plugin-1-0-cross-site-request-forgery-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-2mvw-xxr6-2f56/GHSA-2mvw-xxr6-2f56.json b/advisories/unreviewed/2025/06/GHSA-2mvw-xxr6-2f56/GHSA-2mvw-xxr6-2f56.json new file mode 100644 index 00000000000..d0d85a77794 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-2mvw-xxr6-2f56/GHSA-2mvw-xxr6-2f56.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mvw-xxr6-2f56", + "modified": "2025-06-06T15:30:51Z", + "published": "2025-06-06T15:30:51Z", + "aliases": [ + "CVE-2025-49310" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Frontend Dashboard allows Stored XSS. This issue affects Frontend Dashboard: from n/a through 2.2.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49310" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/frontend-dashboard/vulnerability/wordpress-frontend-dashboard-2-2-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-2q5h-qxrf-5429/GHSA-2q5h-qxrf-5429.json b/advisories/unreviewed/2025/06/GHSA-2q5h-qxrf-5429/GHSA-2q5h-qxrf-5429.json new file mode 100644 index 00000000000..c3014ec56d8 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-2q5h-qxrf-5429/GHSA-2q5h-qxrf-5429.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2q5h-qxrf-5429", + "modified": "2025-06-06T15:30:53Z", + "published": "2025-06-06T15:30:53Z", + "aliases": [ + "CVE-2025-5778" + ], + "details": "A vulnerability, which was classified as critical, was found in 1000 Projects ABC Courier Management System 1.0. Affected is an unknown function of the file /adminSQL. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5778" + }, + { + "type": "WEB", + "url": "https://github.com/ubfbuz3/cve/issues/18" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311322" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311322" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.591110" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-2x4r-f9mj-r6xq/GHSA-2x4r-f9mj-r6xq.json b/advisories/unreviewed/2025/06/GHSA-2x4r-f9mj-r6xq/GHSA-2x4r-f9mj-r6xq.json new file mode 100644 index 00000000000..8049187d683 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-2x4r-f9mj-r6xq/GHSA-2x4r-f9mj-r6xq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2x4r-f9mj-r6xq", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-30625" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt Pramschufer AppBanners allows Stored XSS. This issue affects AppBanners: from n/a through 1.5.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30625" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/appbanners/vulnerability/wordpress-appbanners-1-5-14-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-35f7-7pch-h2xv/GHSA-35f7-7pch-h2xv.json b/advisories/unreviewed/2025/06/GHSA-35f7-7pch-h2xv/GHSA-35f7-7pch-h2xv.json new file mode 100644 index 00000000000..2f07c01fddf --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-35f7-7pch-h2xv/GHSA-35f7-7pch-h2xv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35f7-7pch-h2xv", + "modified": "2025-06-06T15:30:45Z", + "published": "2025-06-06T15:30:45Z", + "aliases": [ + "CVE-2025-24772" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in cmsMinds Pay with Contact Form 7 allows Cross Site Request Forgery. This issue affects Pay with Contact Form 7: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24772" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pay-with-contact-form-7/vulnerability/wordpress-pay-with-contact-form-7-1-0-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3cj5-24c9-h5rw/GHSA-3cj5-24c9-h5rw.json b/advisories/unreviewed/2025/06/GHSA-3cj5-24c9-h5rw/GHSA-3cj5-24c9-h5rw.json new file mode 100644 index 00000000000..bdbe59f6497 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3cj5-24c9-h5rw/GHSA-3cj5-24c9-h5rw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cj5-24c9-h5rw", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-49236" + ], + "details": "Missing Authorization vulnerability in raychat Raychat allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Raychat: from n/a through 2.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49236" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/raychat/vulnerability/wordpress-raychat-2-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3fjw-qgvr-6mvc/GHSA-3fjw-qgvr-6mvc.json b/advisories/unreviewed/2025/06/GHSA-3fjw-qgvr-6mvc/GHSA-3fjw-qgvr-6mvc.json new file mode 100644 index 00000000000..4b7fb74fb16 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3fjw-qgvr-6mvc/GHSA-3fjw-qgvr-6mvc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3fjw-qgvr-6mvc", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49294" + ], + "details": "Insertion of Sensitive Information Into Sent Data vulnerability in CodeRevolution Crawlomatic Multisite Scraper Post Generator allows Retrieve Embedded Sensitive Data. This issue affects Crawlomatic Multisite Scraper Post Generator: from n/a through 2.6.8.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49294" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/crawlomatic-multipage-scraper-post-generator/vulnerability/wordpress-crawlomatic-multisite-scraper-post-generator-plugin-2-6-8-2-sensitive-data-exposure-via-log-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3g6g-5f5x-cgj7/GHSA-3g6g-5f5x-cgj7.json b/advisories/unreviewed/2025/06/GHSA-3g6g-5f5x-cgj7/GHSA-3g6g-5f5x-cgj7.json new file mode 100644 index 00000000000..df70167b513 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3g6g-5f5x-cgj7/GHSA-3g6g-5f5x-cgj7.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g6g-5f5x-cgj7", + "modified": "2025-06-06T15:30:54Z", + "published": "2025-06-06T15:30:53Z", + "aliases": [ + "CVE-2025-5782" + ], + "details": "A vulnerability, which was classified as critical, has been found in PHPGurukul Employee Record Management System 1.3. Affected by this issue is some unknown functionality of the file /resetpassword.php. The manipulation of the argument newpassword leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5782" + }, + { + "type": "WEB", + "url": "https://github.com/f1rstb100d/myCVE/issues/57" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311330" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311330" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.591202" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3p24-fq2f-mhqw/GHSA-3p24-fq2f-mhqw.json b/advisories/unreviewed/2025/06/GHSA-3p24-fq2f-mhqw/GHSA-3p24-fq2f-mhqw.json new file mode 100644 index 00000000000..e84e82de3fd --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3p24-fq2f-mhqw/GHSA-3p24-fq2f-mhqw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p24-fq2f-mhqw", + "modified": "2025-06-06T15:30:45Z", + "published": "2025-06-06T15:30:45Z", + "aliases": [ + "CVE-2023-26001" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marchetti Design Next Event Calendar allows Stored XSS. This issue affects Next Event Calendar: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26001" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/next-event-calendar/vulnerability/wordpress-next-event-calendar-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3pf8-v7f6-5947/GHSA-3pf8-v7f6-5947.json b/advisories/unreviewed/2025/06/GHSA-3pf8-v7f6-5947/GHSA-3pf8-v7f6-5947.json new file mode 100644 index 00000000000..7181f3f3d3c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3pf8-v7f6-5947/GHSA-3pf8-v7f6-5947.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pf8-v7f6-5947", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30946" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Michael Cannon Custom Bulk/Quick Edit allows Cross Site Request Forgery. This issue affects Custom Bulk/Quick Edit: from n/a through 1.6.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30946" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/custom-bulkquick-edit/vulnerability/wordpress-custom-bulk-quick-edit-1-6-10-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3w74-38gg-gj48/GHSA-3w74-38gg-gj48.json b/advisories/unreviewed/2025/06/GHSA-3w74-38gg-gj48/GHSA-3w74-38gg-gj48.json new file mode 100644 index 00000000000..b493f896748 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3w74-38gg-gj48/GHSA-3w74-38gg-gj48.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w74-38gg-gj48", + "modified": "2025-06-06T15:30:51Z", + "published": "2025-06-06T15:30:51Z", + "aliases": [ + "CVE-2025-49318" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPtouch WPtouch allows Stored XSS. This issue affects WPtouch: from n/a through 4.3.60.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49318" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wptouch/vulnerability/wordpress-wptouch-4-3-60-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3wfx-w72c-xg7v/GHSA-3wfx-w72c-xg7v.json b/advisories/unreviewed/2025/06/GHSA-3wfx-w72c-xg7v/GHSA-3wfx-w72c-xg7v.json new file mode 100644 index 00000000000..91a959f0d7c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3wfx-w72c-xg7v/GHSA-3wfx-w72c-xg7v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wfx-w72c-xg7v", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-28964" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in mangup Personal Favicon allows Stored XSS. This issue affects Personal Favicon: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28964" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/personal-favicon/vulnerability/wordpress-personal-favicon-plugin-2-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3wqv-4hq2-7gcp/GHSA-3wqv-4hq2-7gcp.json b/advisories/unreviewed/2025/06/GHSA-3wqv-4hq2-7gcp/GHSA-3wqv-4hq2-7gcp.json new file mode 100644 index 00000000000..70f24ccebb6 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3wqv-4hq2-7gcp/GHSA-3wqv-4hq2-7gcp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wqv-4hq2-7gcp", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30953" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Salesforce allows Phishing. This issue affects WP Gravity Forms Salesforce: from n/a through 1.4.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30953" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gf-salesforce-crmperks/vulnerability/wordpress-wp-gravity-forms-salesforce-1-4-7-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3x47-pxw6-fmvq/GHSA-3x47-pxw6-fmvq.json b/advisories/unreviewed/2025/06/GHSA-3x47-pxw6-fmvq/GHSA-3x47-pxw6-fmvq.json new file mode 100644 index 00000000000..6a9ed7310fc --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3x47-pxw6-fmvq/GHSA-3x47-pxw6-fmvq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x47-pxw6-fmvq", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49291" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form allows Cross Site Request Forgery. This issue affects Calculated Fields Form: from n/a through 5.3.58.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49291" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/calculated-fields-form/vulnerability/wordpress-calculated-fields-form-5-3-58-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-436p-8gmj-3rqv/GHSA-436p-8gmj-3rqv.json b/advisories/unreviewed/2025/06/GHSA-436p-8gmj-3rqv/GHSA-436p-8gmj-3rqv.json new file mode 100644 index 00000000000..7c612ead92d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-436p-8gmj-3rqv/GHSA-436p-8gmj-3rqv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-436p-8gmj-3rqv", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-27360" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar allows Cross Site Request Forgery. This issue affects Quick Event Calendar: from n/a through 1.4.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27360" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/quick-event-calendar/vulnerability/wordpress-quick-event-calendar-1-4-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-446v-89xj-w74v/GHSA-446v-89xj-w74v.json b/advisories/unreviewed/2025/06/GHSA-446v-89xj-w74v/GHSA-446v-89xj-w74v.json index fb118e1f8d6..971acb072b1 100644 --- a/advisories/unreviewed/2025/06/GHSA-446v-89xj-w74v/GHSA-446v-89xj-w74v.json +++ b/advisories/unreviewed/2025/06/GHSA-446v-89xj-w74v/GHSA-446v-89xj-w74v.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-44pj-p52j-6jrw/GHSA-44pj-p52j-6jrw.json b/advisories/unreviewed/2025/06/GHSA-44pj-p52j-6jrw/GHSA-44pj-p52j-6jrw.json new file mode 100644 index 00000000000..d6c6fdddec0 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-44pj-p52j-6jrw/GHSA-44pj-p52j-6jrw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44pj-p52j-6jrw", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49299" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPlugged.com WebHotelier allows Stored XSS. This issue affects WebHotelier: from n/a through 1.9.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49299" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/webhotelier/vulnerability/wordpress-webhotelier-1-9-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-479r-h4h5-wrgc/GHSA-479r-h4h5-wrgc.json b/advisories/unreviewed/2025/06/GHSA-479r-h4h5-wrgc/GHSA-479r-h4h5-wrgc.json new file mode 100644 index 00000000000..77e682352d1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-479r-h4h5-wrgc/GHSA-479r-h4h5-wrgc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-479r-h4h5-wrgc", + "modified": "2025-06-06T15:30:52Z", + "published": "2025-06-06T15:30:52Z", + "aliases": [ + "CVE-2025-49329" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Agile Logix Store Locator WordPress allows Upload a Web Shell to a Web Server. This issue affects Store Locator WordPress: from n/a through 1.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49329" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/agile-store-locator/vulnerability/wordpress-store-locator-wordpress-1-5-2-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-4c7c-h7w3-m357/GHSA-4c7c-h7w3-m357.json b/advisories/unreviewed/2025/06/GHSA-4c7c-h7w3-m357/GHSA-4c7c-h7w3-m357.json new file mode 100644 index 00000000000..90a3a49a536 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4c7c-h7w3-m357/GHSA-4c7c-h7w3-m357.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c7c-h7w3-m357", + "modified": "2025-06-06T15:30:53Z", + "published": "2025-06-06T15:30:53Z", + "aliases": [ + "CVE-2025-5764" + ], + "details": "A vulnerability was found in code-projects Laundry System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /data/insert_laundry.php. The manipulation of the argument Customer leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5764" + }, + { + "type": "WEB", + "url": "https://github.com/tuooo/CVE/issues/5" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311306" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311306" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.590800" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-4gv2-jpch-c3c4/GHSA-4gv2-jpch-c3c4.json b/advisories/unreviewed/2025/06/GHSA-4gv2-jpch-c3c4/GHSA-4gv2-jpch-c3c4.json new file mode 100644 index 00000000000..49eac37d460 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4gv2-jpch-c3c4/GHSA-4gv2-jpch-c3c4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gv2-jpch-c3c4", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-30634" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IWEBIX WP Featured Content Slider allows Stored XSS. This issue affects WP Featured Content Slider: from n/a through 2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30634" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-featured-content-slider/vulnerability/wordpress-wp-featured-content-slider-2-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-4p64-mj95-v5fc/GHSA-4p64-mj95-v5fc.json b/advisories/unreviewed/2025/06/GHSA-4p64-mj95-v5fc/GHSA-4p64-mj95-v5fc.json new file mode 100644 index 00000000000..7f9483a8c76 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4p64-mj95-v5fc/GHSA-4p64-mj95-v5fc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p64-mj95-v5fc", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49305" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode Product Catalog Simple allows Stored XSS. This issue affects Product Catalog Simple: from n/a through 1.8.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49305" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/post-type-x/vulnerability/wordpress-product-catalog-simple-1-8-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-4wfm-668h-mwq3/GHSA-4wfm-668h-mwq3.json b/advisories/unreviewed/2025/06/GHSA-4wfm-668h-mwq3/GHSA-4wfm-668h-mwq3.json new file mode 100644 index 00000000000..74a57abfae6 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4wfm-668h-mwq3/GHSA-4wfm-668h-mwq3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wfm-668h-mwq3", + "modified": "2025-06-06T15:30:52Z", + "published": "2025-06-06T15:30:52Z", + "aliases": [ + "CVE-2025-49328" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store Locator WordPress allows SQL Injection. This issue affects Store Locator WordPress: from n/a through 1.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49328" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/agile-store-locator/vulnerability/wordpress-store-locator-wordpress-1-5-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-4x22-h5rw-64w4/GHSA-4x22-h5rw-64w4.json b/advisories/unreviewed/2025/06/GHSA-4x22-h5rw-64w4/GHSA-4x22-h5rw-64w4.json new file mode 100644 index 00000000000..d8451b221e4 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4x22-h5rw-64w4/GHSA-4x22-h5rw-64w4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x22-h5rw-64w4", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-28958" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Vadim Bogaiskov Bg Orthodox Calendar allows Stored XSS. This issue affects Bg Orthodox Calendar: from n/a through 0.13.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28958" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bg-orthodox-calendar/vulnerability/wordpress-bg-orthodox-calendar-plugin-0-13-10-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-54qg-grqx-45xx/GHSA-54qg-grqx-45xx.json b/advisories/unreviewed/2025/06/GHSA-54qg-grqx-45xx/GHSA-54qg-grqx-45xx.json new file mode 100644 index 00000000000..4599e7c85b0 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-54qg-grqx-45xx/GHSA-54qg-grqx-45xx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54qg-grqx-45xx", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-29010" + ], + "details": "Missing Authorization vulnerability in eleopard Behance Portfolio Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Behance Portfolio Manager: from n/a through 1.7.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29010" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/portfolio-manager-powered-by-behance/vulnerability/wordpress-behance-portfolio-manager-1-7-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-54qv-m9fx-37mc/GHSA-54qv-m9fx-37mc.json b/advisories/unreviewed/2025/06/GHSA-54qv-m9fx-37mc/GHSA-54qv-m9fx-37mc.json new file mode 100644 index 00000000000..97a3219c64e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-54qv-m9fx-37mc/GHSA-54qv-m9fx-37mc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54qv-m9fx-37mc", + "modified": "2025-06-06T15:30:51Z", + "published": "2025-06-06T15:30:51Z", + "aliases": [ + "CVE-2025-49317" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in NTC WP Page Loading allows Cross Site Request Forgery. This issue affects WP Page Loading: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49317" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-page-loading/vulnerability/wordpress-wp-page-loading-1-0-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-5578-hhjg-f387/GHSA-5578-hhjg-f387.json b/advisories/unreviewed/2025/06/GHSA-5578-hhjg-f387/GHSA-5578-hhjg-f387.json new file mode 100644 index 00000000000..53ea7edbf61 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-5578-hhjg-f387/GHSA-5578-hhjg-f387.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5578-hhjg-f387", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49287" + ], + "details": "Missing Authorization vulnerability in WebToffee Product Feed for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Product Feed for WooCommerce: from n/a through 2.2.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49287" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/webtoffee-product-feed/vulnerability/wordpress-product-feed-for-woocommerce-2-2-8-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-55jp-3p8j-2972/GHSA-55jp-3p8j-2972.json b/advisories/unreviewed/2025/06/GHSA-55jp-3p8j-2972/GHSA-55jp-3p8j-2972.json new file mode 100644 index 00000000000..1eb7c5113ca --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-55jp-3p8j-2972/GHSA-55jp-3p8j-2972.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55jp-3p8j-2972", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30957" + ], + "details": "Missing Authorization vulnerability in BuddyDev Activity Plus Reloaded for BuddyPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Activity Plus Reloaded for BuddyPress: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30957" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bp-activity-plus-reloaded/vulnerability/wordpress-activity-plus-reloaded-for-buddypress-1-1-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-57xq-c793-mr49/GHSA-57xq-c793-mr49.json b/advisories/unreviewed/2025/06/GHSA-57xq-c793-mr49/GHSA-57xq-c793-mr49.json new file mode 100644 index 00000000000..bb3e1870da3 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-57xq-c793-mr49/GHSA-57xq-c793-mr49.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57xq-c793-mr49", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-30932" + ], + "details": "Missing Authorization vulnerability in WP Compress WP Compress for MainWP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Compress for MainWP: from n/a through 6.30.32.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30932" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-compress-mainwp/vulnerability/wordpress-wp-compress-for-mainwp-6-30-32-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-5938-c5fg-23fq/GHSA-5938-c5fg-23fq.json b/advisories/unreviewed/2025/06/GHSA-5938-c5fg-23fq/GHSA-5938-c5fg-23fq.json new file mode 100644 index 00000000000..f0bc613430b --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-5938-c5fg-23fq/GHSA-5938-c5fg-23fq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5938-c5fg-23fq", + "modified": "2025-06-06T15:30:45Z", + "published": "2025-06-06T15:30:45Z", + "aliases": [ + "CVE-2025-23969" + ], + "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in whassan KI Live Video Conferences allows Retrieve Embedded Sensitive Data. This issue affects KI Live Video Conferences: from n/a through 5.5.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23969" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ki-live-video-conferences/vulnerability/wordpress-ki-live-video-conferences-5-5-15-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-5977-9j8w-86w8/GHSA-5977-9j8w-86w8.json b/advisories/unreviewed/2025/06/GHSA-5977-9j8w-86w8/GHSA-5977-9j8w-86w8.json new file mode 100644 index 00000000000..f76bc7f0083 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-5977-9j8w-86w8/GHSA-5977-9j8w-86w8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5977-9j8w-86w8", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49269" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Anton Vanyukov Market Exporter allows Cross Site Request Forgery. This issue affects Market Exporter: from n/a through 2.0.22.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49269" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/market-exporter/vulnerability/wordpress-market-exporter-2-0-22-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-5fqh-wrrw-3qc9/GHSA-5fqh-wrrw-3qc9.json b/advisories/unreviewed/2025/06/GHSA-5fqh-wrrw-3qc9/GHSA-5fqh-wrrw-3qc9.json new file mode 100644 index 00000000000..dbb9b2da799 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-5fqh-wrrw-3qc9/GHSA-5fqh-wrrw-3qc9.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fqh-wrrw-3qc9", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-38000" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue()\n\nWhen enqueuing the first packet to an HFSC class, hfsc_enqueue() calls the\nchild qdisc's peek() operation before incrementing sch->q.qlen and\nsch->qstats.backlog. If the child qdisc uses qdisc_peek_dequeued(), this may\ntrigger an immediate dequeue and potential packet drop. In such cases,\nqdisc_tree_reduce_backlog() is called, but the HFSC qdisc's qlen and backlog\nhave not yet been updated, leading to inconsistent queue accounting. This\ncan leave an empty HFSC class in the active list, causing further\nconsequences like use-after-free.\n\nThis patch fixes the bug by moving the increment of sch->q.qlen and\nsch->qstats.backlog before the call to the child qdisc's peek() operation.\nThis ensures that queue length and backlog are always accurate when packet\ndrops or dequeues are triggered during the peek.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-38000" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1034e3310752e8675e313f7271b348914008719a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3f3a22eebbc32b4fa8ce9c1d5f9db214b45b9335" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3f981138109f63232a5fb7165938d4c945cc1b9d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/49b21795b8e5654a7df3d910a12e1060da4c04cf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/89c301e929a0db14ebd94b4d97764ce1d6981653" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/93c276942e75de0e5bc91576300d292e968f5a02" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f1dde3eb17dc1b8bd07aed00004b1e05fc87a3d4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f9f593e34d2fb67644372c8f7b033bdc622ad228" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-5fwv-wjgq-886f/GHSA-5fwv-wjgq-886f.json b/advisories/unreviewed/2025/06/GHSA-5fwv-wjgq-886f/GHSA-5fwv-wjgq-886f.json new file mode 100644 index 00000000000..e2f5ec376a2 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-5fwv-wjgq-886f/GHSA-5fwv-wjgq-886f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fwv-wjgq-886f", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-30937" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stefanledin Responsify WP allows Stored XSS. This issue affects Responsify WP: from n/a through 1.9.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30937" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/responsify-wp/vulnerability/wordpress-responsify-wp-1-9-11-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-5j35-3rhc-cv6r/GHSA-5j35-3rhc-cv6r.json b/advisories/unreviewed/2025/06/GHSA-5j35-3rhc-cv6r/GHSA-5j35-3rhc-cv6r.json new file mode 100644 index 00000000000..eb8d314846f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-5j35-3rhc-cv6r/GHSA-5j35-3rhc-cv6r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5j35-3rhc-cv6r", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-49250" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in cmoreira Team Showcase allows Code Injection. This issue affects Team Showcase: from n/a through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49250" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/team-showcase-cm/vulnerability/wordpress-team-showcase-plugin-25-05-13-arbitrary-shortcode-execution-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-5j95-g4c4-rmwm/GHSA-5j95-g4c4-rmwm.json b/advisories/unreviewed/2025/06/GHSA-5j95-g4c4-rmwm/GHSA-5j95-g4c4-rmwm.json new file mode 100644 index 00000000000..55184507de0 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-5j95-g4c4-rmwm/GHSA-5j95-g4c4-rmwm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5j95-g4c4-rmwm", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30950" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Wham All Currencies for WooCommerce allows Stored XSS. This issue affects All Currencies for WooCommerce: from n/a through 2.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30950" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-all-currencies/vulnerability/wordpress-all-currencies-for-woocommerce-2-4-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-5wcp-7q3x-hqr4/GHSA-5wcp-7q3x-hqr4.json b/advisories/unreviewed/2025/06/GHSA-5wcp-7q3x-hqr4/GHSA-5wcp-7q3x-hqr4.json index b053e0f1186..01fd9ff4301 100644 --- a/advisories/unreviewed/2025/06/GHSA-5wcp-7q3x-hqr4/GHSA-5wcp-7q3x-hqr4.json +++ b/advisories/unreviewed/2025/06/GHSA-5wcp-7q3x-hqr4/GHSA-5wcp-7q3x-hqr4.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-62gc-8jr5-x9pm/GHSA-62gc-8jr5-x9pm.json b/advisories/unreviewed/2025/06/GHSA-62gc-8jr5-x9pm/GHSA-62gc-8jr5-x9pm.json new file mode 100644 index 00000000000..1c60bb984f4 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-62gc-8jr5-x9pm/GHSA-62gc-8jr5-x9pm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62gc-8jr5-x9pm", + "modified": "2025-06-06T15:30:53Z", + "published": "2025-06-06T15:30:53Z", + "aliases": [ + "CVE-2025-27531" + ], + "details": "Deserialization of Untrusted Data vulnerability in Apache InLong. \n\nThis issue affects Apache InLong: from 1.13.0 before 2.1.0, \n\nthis issue would allow an authenticated attacker to read arbitrary files by double writing the param.\n\n\n\n\n\nUsers are recommended to upgrade to version 2.1.0, which fixes the issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27531" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/r62lkqrr739wvcb60j6ql6q63rh4bxx5" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/02/28/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-639h-q5mc-2xjf/GHSA-639h-q5mc-2xjf.json b/advisories/unreviewed/2025/06/GHSA-639h-q5mc-2xjf/GHSA-639h-q5mc-2xjf.json new file mode 100644 index 00000000000..355816adc12 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-639h-q5mc-2xjf/GHSA-639h-q5mc-2xjf.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-639h-q5mc-2xjf", + "modified": "2025-06-06T15:30:53Z", + "published": "2025-06-06T15:30:53Z", + "aliases": [ + "CVE-2025-5779" + ], + "details": "A vulnerability has been found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /birthing.php. The manipulation of the argument itr_no/comp_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5779" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/Thiasap/HCPMS_PHP_vulns/blob/main/sql%20injection%20in%20birthing.php.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311323" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311323" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.591127" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6574-h4qq-5ww5/GHSA-6574-h4qq-5ww5.json b/advisories/unreviewed/2025/06/GHSA-6574-h4qq-5ww5/GHSA-6574-h4qq-5ww5.json new file mode 100644 index 00000000000..eefb57f55b0 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6574-h4qq-5ww5/GHSA-6574-h4qq-5ww5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6574-h4qq-5ww5", + "modified": "2025-06-06T15:30:45Z", + "published": "2025-06-06T15:30:45Z", + "aliases": [ + "CVE-2025-24776" + ], + "details": "Missing Authorization vulnerability in codelobster Responsive Flipbooks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Responsive Flipbooks: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24776" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/responsive-flipbooks/vulnerability/wordpress-responsive-flipbooks-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-677h-p22r-wj4v/GHSA-677h-p22r-wj4v.json b/advisories/unreviewed/2025/06/GHSA-677h-p22r-wj4v/GHSA-677h-p22r-wj4v.json new file mode 100644 index 00000000000..02175dd54db --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-677h-p22r-wj4v/GHSA-677h-p22r-wj4v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-677h-p22r-wj4v", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-30638" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PowieT Powie's Uptime Robot allows Stored XSS. This issue affects Powie's Uptime Robot: from n/a through 0.9.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30638" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/powies-uptime-robot/vulnerability/wordpress-powie-s-uptime-robot-0-9-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-67vv-4mr9-2hvw/GHSA-67vv-4mr9-2hvw.json b/advisories/unreviewed/2025/06/GHSA-67vv-4mr9-2hvw/GHSA-67vv-4mr9-2hvw.json new file mode 100644 index 00000000000..23059a9e4f3 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-67vv-4mr9-2hvw/GHSA-67vv-4mr9-2hvw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67vv-4mr9-2hvw", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49289" + ], + "details": "Missing Authorization vulnerability in add-ons.org PDF for WPForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF for WPForms: from n/a through 5.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49289" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pdf-for-wpforms/vulnerability/wordpress-pdf-for-wpforms-5-5-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-68hc-jc4x-cvf7/GHSA-68hc-jc4x-cvf7.json b/advisories/unreviewed/2025/06/GHSA-68hc-jc4x-cvf7/GHSA-68hc-jc4x-cvf7.json new file mode 100644 index 00000000000..1795a5a06fc --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-68hc-jc4x-cvf7/GHSA-68hc-jc4x-cvf7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68hc-jc4x-cvf7", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-28950" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in David Shabtai Post Author allows Stored XSS. This issue affects Post Author: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28950" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/post-author/vulnerability/wordpress-post-author-1-1-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-69cc-vc8r-fj6g/GHSA-69cc-vc8r-fj6g.json b/advisories/unreviewed/2025/06/GHSA-69cc-vc8r-fj6g/GHSA-69cc-vc8r-fj6g.json new file mode 100644 index 00000000000..f0364fa5b23 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-69cc-vc8r-fj6g/GHSA-69cc-vc8r-fj6g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69cc-vc8r-fj6g", + "modified": "2025-06-06T15:30:45Z", + "published": "2025-06-06T15:30:45Z", + "aliases": [ + "CVE-2023-26003" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vipul Jariwala WP Post Corrector allows SQL Injection. This issue affects WP Post Corrector: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26003" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-post-corrector/vulnerability/wordpress-wp-post-corrector-1-0-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6c49-6xv3-mcq8/GHSA-6c49-6xv3-mcq8.json b/advisories/unreviewed/2025/06/GHSA-6c49-6xv3-mcq8/GHSA-6c49-6xv3-mcq8.json new file mode 100644 index 00000000000..25998d17dcb --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6c49-6xv3-mcq8/GHSA-6c49-6xv3-mcq8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c49-6xv3-mcq8", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49292" + ], + "details": "Improper Validation of Specified Quantity in Input vulnerability in Cozmoslabs Profile Builder allows Phishing. This issue affects Profile Builder: from n/a through 3.13.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49292" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/profile-builder/vulnerability/wordpress-profile-builder-3-13-8-content-spoofing-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6m24-69jj-qmwg/GHSA-6m24-69jj-qmwg.json b/advisories/unreviewed/2025/06/GHSA-6m24-69jj-qmwg/GHSA-6m24-69jj-qmwg.json new file mode 100644 index 00000000000..6e38a40233f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6m24-69jj-qmwg/GHSA-6m24-69jj-qmwg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m24-69jj-qmwg", + "modified": "2025-06-06T15:30:51Z", + "published": "2025-06-06T15:30:51Z", + "aliases": [ + "CVE-2025-49311" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CoolHappy The Events Calendar Countdown Addon allows Stored XSS. This issue affects The Events Calendar Countdown Addon: from n/a through 1.4.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49311" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/countdown-for-the-events-calendar/vulnerability/wordpress-the-events-calendar-countdown-addon-1-4-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6phg-97jv-fcw9/GHSA-6phg-97jv-fcw9.json b/advisories/unreviewed/2025/06/GHSA-6phg-97jv-fcw9/GHSA-6phg-97jv-fcw9.json new file mode 100644 index 00000000000..a3257a334d5 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6phg-97jv-fcw9/GHSA-6phg-97jv-fcw9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6phg-97jv-fcw9", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30977" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chaport Live Chat WP Live Chat + Chatbots Plugin for WordPress – Chaport allows Stored XSS. This issue affects WP Live Chat + Chatbots Plugin for WordPress – Chaport: from n/a through 1.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30977" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/chaport/vulnerability/wordpress-wp-live-chat-chatbots-plugin-for-wordpress-chaport-1-1-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6pvf-2x8w-rvmj/GHSA-6pvf-2x8w-rvmj.json b/advisories/unreviewed/2025/06/GHSA-6pvf-2x8w-rvmj/GHSA-6pvf-2x8w-rvmj.json new file mode 100644 index 00000000000..351317a02d8 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6pvf-2x8w-rvmj/GHSA-6pvf-2x8w-rvmj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pvf-2x8w-rvmj", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-28995" + ], + "details": "Missing Authorization vulnerability in viralloops Viral Loops WP Integration allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Viral Loops WP Integration: from n/a through 3.8.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28995" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/viral-loops-wp-integration/vulnerability/wordpress-viral-loops-wp-integration-3-8-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6pwc-frqj-6q7g/GHSA-6pwc-frqj-6q7g.json b/advisories/unreviewed/2025/06/GHSA-6pwc-frqj-6q7g/GHSA-6pwc-frqj-6q7g.json new file mode 100644 index 00000000000..1149aa2ff98 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6pwc-frqj-6q7g/GHSA-6pwc-frqj-6q7g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pwc-frqj-6q7g", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-30991" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada Premium Packages allows Stored XSS. This issue affects Premium Packages: from n/a through 6.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30991" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpdm-premium-packages/vulnerability/wordpress-premium-packages-6-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-72x3-8f3c-phjv/GHSA-72x3-8f3c-phjv.json b/advisories/unreviewed/2025/06/GHSA-72x3-8f3c-phjv/GHSA-72x3-8f3c-phjv.json new file mode 100644 index 00000000000..0baf7398bfb --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-72x3-8f3c-phjv/GHSA-72x3-8f3c-phjv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72x3-8f3c-phjv", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-30999" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fahad Mahmood WP Shopify allows PHP Local File Inclusion. This issue affects WP Shopify: from n/a through 1.5.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30999" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-shopify/vulnerability/wordpress-wp-shopify-1-5-3-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-74gp-97p3-5cv9/GHSA-74gp-97p3-5cv9.json b/advisories/unreviewed/2025/06/GHSA-74gp-97p3-5cv9/GHSA-74gp-97p3-5cv9.json new file mode 100644 index 00000000000..2fee6983514 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-74gp-97p3-5cv9/GHSA-74gp-97p3-5cv9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74gp-97p3-5cv9", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-49239" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce allows Cross Site Request Forgery. This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 5.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49239" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-delivery-notes/vulnerability/wordpress-print-invoice-delivery-notes-for-woocommerce-5-5-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-77gx-vcj4-hf9v/GHSA-77gx-vcj4-hf9v.json b/advisories/unreviewed/2025/06/GHSA-77gx-vcj4-hf9v/GHSA-77gx-vcj4-hf9v.json new file mode 100644 index 00000000000..22a4f8e0f40 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-77gx-vcj4-hf9v/GHSA-77gx-vcj4-hf9v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77gx-vcj4-hf9v", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49272" + ], + "details": "Missing Authorization vulnerability in sergiotrinity Trinity Audio allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Trinity Audio: from n/a through 5.20.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49272" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/trinity-audio/vulnerability/wordpress-trinity-audio-5-20-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7948-q9wp-544g/GHSA-7948-q9wp-544g.json b/advisories/unreviewed/2025/06/GHSA-7948-q9wp-544g/GHSA-7948-q9wp-544g.json new file mode 100644 index 00000000000..5fdd26c5e6f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7948-q9wp-544g/GHSA-7948-q9wp-544g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7948-q9wp-544g", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30974" + ], + "details": "Missing Authorization vulnerability in Akhtarujjaman Shuvo Post Grid Master allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post Grid Master: from n/a through 3.4.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30974" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ajax-filter-posts/vulnerability/wordpress-post-grid-master-3-4-13-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7f42-qfj5-3w48/GHSA-7f42-qfj5-3w48.json b/advisories/unreviewed/2025/06/GHSA-7f42-qfj5-3w48/GHSA-7f42-qfj5-3w48.json new file mode 100644 index 00000000000..3bd00f3dcb1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7f42-qfj5-3w48/GHSA-7f42-qfj5-3w48.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f42-qfj5-3w48", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-30934" + ], + "details": "Missing Authorization vulnerability in OLIVESYSTEM 診断ジェネレータ作成プラグイン allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects 診断ジェネレータ作成プラグイン: from n/a through 1.4.16.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30934" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/os-diagnosis-generator/vulnerability/wordpress-1-4-16-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7hmg-q99p-gw95/GHSA-7hmg-q99p-gw95.json b/advisories/unreviewed/2025/06/GHSA-7hmg-q99p-gw95/GHSA-7hmg-q99p-gw95.json new file mode 100644 index 00000000000..4eb7be1977f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7hmg-q99p-gw95/GHSA-7hmg-q99p-gw95.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hmg-q99p-gw95", + "modified": "2025-06-06T15:30:51Z", + "published": "2025-06-06T15:30:51Z", + "aliases": [ + "CVE-2025-49309" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Team Member allows Stored XSS. This issue affects HT Team Member: from n/a through 1.1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49309" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ht-team-member/vulnerability/wordpress-ht-team-member-1-1-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7hwc-894r-x5hw/GHSA-7hwc-894r-x5hw.json b/advisories/unreviewed/2025/06/GHSA-7hwc-894r-x5hw/GHSA-7hwc-894r-x5hw.json new file mode 100644 index 00000000000..23e1275e56d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7hwc-894r-x5hw/GHSA-7hwc-894r-x5hw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hwc-894r-x5hw", + "modified": "2025-06-06T15:30:52Z", + "published": "2025-06-06T15:30:52Z", + "aliases": [ + "CVE-2025-49327" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia ShortLinks Pro allows SQL Injection. This issue affects ShortLinks Pro: from n/a through 1.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49327" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/shortlinkspro/vulnerability/wordpress-shortlinks-pro-1-0-7-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7mxc-9hxm-j7ff/GHSA-7mxc-9hxm-j7ff.json b/advisories/unreviewed/2025/06/GHSA-7mxc-9hxm-j7ff/GHSA-7mxc-9hxm-j7ff.json new file mode 100644 index 00000000000..66ec63cd4b6 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7mxc-9hxm-j7ff/GHSA-7mxc-9hxm-j7ff.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mxc-9hxm-j7ff", + "modified": "2025-06-06T15:30:52Z", + "published": "2025-06-06T15:30:52Z", + "aliases": [ + "CVE-2025-49440" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Vuong Nguyen WP Security Master allows Cross Site Request Forgery. This issue affects WP Security Master: from n/a through 1.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49440" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-security-master/vulnerability/wordpress-wp-security-master-1-0-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7pq2-q8m4-x558/GHSA-7pq2-q8m4-x558.json b/advisories/unreviewed/2025/06/GHSA-7pq2-q8m4-x558/GHSA-7pq2-q8m4-x558.json new file mode 100644 index 00000000000..b896e33888e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7pq2-q8m4-x558/GHSA-7pq2-q8m4-x558.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pq2-q8m4-x558", + "modified": "2025-06-06T15:30:51Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49304" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeManas Search with Typesense allows Stored XSS. This issue affects Search with Typesense: from n/a through 2.0.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49304" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/search-with-typesense/vulnerability/wordpress-search-with-typesense-2-0-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7pwr-xw6h-c3h8/GHSA-7pwr-xw6h-c3h8.json b/advisories/unreviewed/2025/06/GHSA-7pwr-xw6h-c3h8/GHSA-7pwr-xw6h-c3h8.json new file mode 100644 index 00000000000..3ef39e54c2a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7pwr-xw6h-c3h8/GHSA-7pwr-xw6h-c3h8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pwr-xw6h-c3h8", + "modified": "2025-06-06T15:30:52Z", + "published": "2025-06-06T15:30:52Z", + "aliases": [ + "CVE-2025-49421" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Andrei Filonov WP Text Expander allows SQL Injection. This issue affects WP Text Expander: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49421" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-text-expander/vulnerability/wordpress-wp-text-expander-1-0-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7rw4-hfv5-c2v2/GHSA-7rw4-hfv5-c2v2.json b/advisories/unreviewed/2025/06/GHSA-7rw4-hfv5-c2v2/GHSA-7rw4-hfv5-c2v2.json index c82656e1b97..cc17b24fcf5 100644 --- a/advisories/unreviewed/2025/06/GHSA-7rw4-hfv5-c2v2/GHSA-7rw4-hfv5-c2v2.json +++ b/advisories/unreviewed/2025/06/GHSA-7rw4-hfv5-c2v2/GHSA-7rw4-hfv5-c2v2.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-7rxf-g9c5-px83/GHSA-7rxf-g9c5-px83.json b/advisories/unreviewed/2025/06/GHSA-7rxf-g9c5-px83/GHSA-7rxf-g9c5-px83.json new file mode 100644 index 00000000000..7eedda72f54 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7rxf-g9c5-px83/GHSA-7rxf-g9c5-px83.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rxf-g9c5-px83", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-29011" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CHR Designer YouTube Simple Gallery allows Stored XSS. This issue affects YouTube Simple Gallery: from n/a through 2.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29011" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/youtube-simple-gallery/vulnerability/wordpress-youtube-simple-gallery-2-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7w46-48fc-q6vj/GHSA-7w46-48fc-q6vj.json b/advisories/unreviewed/2025/06/GHSA-7w46-48fc-q6vj/GHSA-7w46-48fc-q6vj.json new file mode 100644 index 00000000000..0d492c3fd08 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7w46-48fc-q6vj/GHSA-7w46-48fc-q6vj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7w46-48fc-q6vj", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49298" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post allows Stored XSS. This issue affects Event post: from n/a through 5.10.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49298" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/event-post/vulnerability/wordpress-event-post-5-10-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7x4j-v4j7-c433/GHSA-7x4j-v4j7-c433.json b/advisories/unreviewed/2025/06/GHSA-7x4j-v4j7-c433/GHSA-7x4j-v4j7-c433.json new file mode 100644 index 00000000000..65f6b1d470b --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7x4j-v4j7-c433/GHSA-7x4j-v4j7-c433.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x4j-v4j7-c433", + "modified": "2025-06-06T15:30:52Z", + "published": "2025-06-06T15:30:52Z", + "aliases": [ + "CVE-2025-49442" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mostafa Shahiri Simple Nested Menu allows Stored XSS. This issue affects Simple Nested Menu: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49442" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-nested-menu/vulnerability/wordpress-simple-nested-menu-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-82wg-cw52-6chw/GHSA-82wg-cw52-6chw.json b/advisories/unreviewed/2025/06/GHSA-82wg-cw52-6chw/GHSA-82wg-cw52-6chw.json new file mode 100644 index 00000000000..f3a4ffb96a4 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-82wg-cw52-6chw/GHSA-82wg-cw52-6chw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82wg-cw52-6chw", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30994" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Emraan Cheema CubeWP – All-in-One Dynamic Content Framework allows Cross Site Request Forgery. This issue affects CubeWP – All-in-One Dynamic Content Framework: from n/a through 1.1.23.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30994" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cubewp-framework/vulnerability/wordpress-cubewp-all-in-one-dynamic-content-framework-plugin-1-1-23-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8437-r9r7-pr3c/GHSA-8437-r9r7-pr3c.json b/advisories/unreviewed/2025/06/GHSA-8437-r9r7-pr3c/GHSA-8437-r9r7-pr3c.json new file mode 100644 index 00000000000..3cf3095964d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8437-r9r7-pr3c/GHSA-8437-r9r7-pr3c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8437-r9r7-pr3c", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-28997" + ], + "details": "Missing Authorization vulnerability in EXEIdeas International WP AutoKeyword allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP AutoKeyword: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28997" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-autokeyword/vulnerability/wordpress-wp-autokeyword-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-85m8-h92q-hp3j/GHSA-85m8-h92q-hp3j.json b/advisories/unreviewed/2025/06/GHSA-85m8-h92q-hp3j/GHSA-85m8-h92q-hp3j.json new file mode 100644 index 00000000000..34b0494904d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-85m8-h92q-hp3j/GHSA-85m8-h92q-hp3j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85m8-h92q-hp3j", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-27359" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Seerox WP Media File Type Manager allows Cross Site Request Forgery. This issue affects WP Media File Type Manager: from n/a through 2.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27359" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-media-file-type-manager/vulnerability/wordpress-wp-media-file-type-manager-plugin-2-3-0-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8jr4-ppr5-wfrh/GHSA-8jr4-ppr5-wfrh.json b/advisories/unreviewed/2025/06/GHSA-8jr4-ppr5-wfrh/GHSA-8jr4-ppr5-wfrh.json new file mode 100644 index 00000000000..be006a4dd9c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8jr4-ppr5-wfrh/GHSA-8jr4-ppr5-wfrh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jr4-ppr5-wfrh", + "modified": "2025-06-06T15:30:52Z", + "published": "2025-06-06T15:30:52Z", + "aliases": [ + "CVE-2025-49445" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive UK Regional Map allows Cross Site Request Forgery. This issue affects Interactive UK Regional Map: from n/a through 2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49445" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/interactive-uk-regional-map/vulnerability/wordpress-interactive-uk-regional-map-plugin-2-0-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8q2c-v8f4-4hp8/GHSA-8q2c-v8f4-4hp8.json b/advisories/unreviewed/2025/06/GHSA-8q2c-v8f4-4hp8/GHSA-8q2c-v8f4-4hp8.json new file mode 100644 index 00000000000..51377367fa0 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8q2c-v8f4-4hp8/GHSA-8q2c-v8f4-4hp8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q2c-v8f4-4hp8", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-31000" + ], + "details": "Missing Authorization vulnerability in Miguel Fuentes Payment QR WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Payment QR WooCommerce: from n/a through 1.1.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31000" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/payment-qr-woo/vulnerability/wordpress-payment-qr-woocommerce-1-1-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8q8w-8225-6gq4/GHSA-8q8w-8225-6gq4.json b/advisories/unreviewed/2025/06/GHSA-8q8w-8225-6gq4/GHSA-8q8w-8225-6gq4.json new file mode 100644 index 00000000000..ff016b9f3f3 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8q8w-8225-6gq4/GHSA-8q8w-8225-6gq4.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q8w-8225-6gq4", + "modified": "2025-06-06T15:30:53Z", + "published": "2025-06-06T15:30:53Z", + "aliases": [ + "CVE-2025-0620" + ], + "details": "A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0620" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-0620" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370453" + }, + { + "type": "WEB", + "url": "https://www.samba.org/samba/security/CVE-2025-0620.html" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/06/03/8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8r92-qj37-xcfp/GHSA-8r92-qj37-xcfp.json b/advisories/unreviewed/2025/06/GHSA-8r92-qj37-xcfp/GHSA-8r92-qj37-xcfp.json new file mode 100644 index 00000000000..1eefc091fbb --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8r92-qj37-xcfp/GHSA-8r92-qj37-xcfp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r92-qj37-xcfp", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30986" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in _CreativeMedia_ Elite Video Player allows Cross Site Request Forgery. This issue affects Elite Video Player: from n/a through 10.0.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30986" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/elite-video-player/vulnerability/wordpress-elite-video-player-10-0-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8x6f-r2xv-wq6v/GHSA-8x6f-r2xv-wq6v.json b/advisories/unreviewed/2025/06/GHSA-8x6f-r2xv-wq6v/GHSA-8x6f-r2xv-wq6v.json new file mode 100644 index 00000000000..4aad64c237d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8x6f-r2xv-wq6v/GHSA-8x6f-r2xv-wq6v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8x6f-r2xv-wq6v", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-30637" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Deetronix Booking Ultra Pro allows Stored XSS. This issue affects Booking Ultra Pro: from n/a through 1.1.20.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30637" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/booking-ultra-pro/vulnerability/wordpress-booking-ultra-pro-1-1-20-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-93cp-8h44-p25m/GHSA-93cp-8h44-p25m.json b/advisories/unreviewed/2025/06/GHSA-93cp-8h44-p25m/GHSA-93cp-8h44-p25m.json new file mode 100644 index 00000000000..1b6b7a54ef7 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-93cp-8h44-p25m/GHSA-93cp-8h44-p25m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93cp-8h44-p25m", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30948" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Giraphix Creative Layouts for Elementor allows Cross Site Request Forgery. This issue affects Layouts for Elementor: from n/a through 1.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30948" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/layouts-for-elementor/vulnerability/wordpress-layouts-for-elementor-1-11-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-979j-r4j2-f7h3/GHSA-979j-r4j2-f7h3.json b/advisories/unreviewed/2025/06/GHSA-979j-r4j2-f7h3/GHSA-979j-r4j2-f7h3.json new file mode 100644 index 00000000000..3c6fafe2c4d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-979j-r4j2-f7h3/GHSA-979j-r4j2-f7h3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-979j-r4j2-f7h3", + "modified": "2025-06-06T15:30:52Z", + "published": "2025-06-06T15:30:52Z", + "aliases": [ + "CVE-2025-49439" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in mariusz88atelierweb Atelier Create CV allows Cross Site Request Forgery. This issue affects Atelier Create CV: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49439" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/atelier-create-cv/vulnerability/wordpress-atelier-create-cv-plugin-1-1-2-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-9fv7-hp8v-pjrp/GHSA-9fv7-hp8v-pjrp.json b/advisories/unreviewed/2025/06/GHSA-9fv7-hp8v-pjrp/GHSA-9fv7-hp8v-pjrp.json new file mode 100644 index 00000000000..4025412e222 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-9fv7-hp8v-pjrp/GHSA-9fv7-hp8v-pjrp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fv7-hp8v-pjrp", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-29008" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in ShawonPro SocialMark allows Server Side Request Forgery. This issue affects SocialMark: from n/a through 2.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29008" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/socialmark/vulnerability/wordpress-socialmark-2-0-7-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-9gr9-4pgq-vh88/GHSA-9gr9-4pgq-vh88.json b/advisories/unreviewed/2025/06/GHSA-9gr9-4pgq-vh88/GHSA-9gr9-4pgq-vh88.json new file mode 100644 index 00000000000..5b85c0f4228 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-9gr9-4pgq-vh88/GHSA-9gr9-4pgq-vh88.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gr9-4pgq-vh88", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-28948" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in codedraft Mediabay - WordPress Media Library Folders allows Reflected XSS. This issue affects Mediabay - WordPress Media Library Folders: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28948" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/mediabay/vulnerability/wordpress-mediabay-wordpress-media-library-folders-plugin-1-4-csrf-to-reflected-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-c45m-jf2p-jm7x/GHSA-c45m-jf2p-jm7x.json b/advisories/unreviewed/2025/06/GHSA-c45m-jf2p-jm7x/GHSA-c45m-jf2p-jm7x.json new file mode 100644 index 00000000000..7de5396f1ff --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-c45m-jf2p-jm7x/GHSA-c45m-jf2p-jm7x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c45m-jf2p-jm7x", + "modified": "2025-06-06T15:30:52Z", + "published": "2025-06-06T15:30:52Z", + "aliases": [ + "CVE-2025-49419" + ], + "details": "Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in esigngenie Foxit eSign for WordPress allows Retrieve Embedded Sensitive Data. This issue affects Foxit eSign for WordPress: from n/a through 2.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49419" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/esign-genie-for-wp/vulnerability/wordpress-foxit-esign-for-wordpress-2-0-3-other-vulnerability-type-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-c75r-6jvf-vrx7/GHSA-c75r-6jvf-vrx7.json b/advisories/unreviewed/2025/06/GHSA-c75r-6jvf-vrx7/GHSA-c75r-6jvf-vrx7.json index 7b538e4b68f..d5016609ea9 100644 --- a/advisories/unreviewed/2025/06/GHSA-c75r-6jvf-vrx7/GHSA-c75r-6jvf-vrx7.json +++ b/advisories/unreviewed/2025/06/GHSA-c75r-6jvf-vrx7/GHSA-c75r-6jvf-vrx7.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-c8qx-qgh7-63qg/GHSA-c8qx-qgh7-63qg.json b/advisories/unreviewed/2025/06/GHSA-c8qx-qgh7-63qg/GHSA-c8qx-qgh7-63qg.json new file mode 100644 index 00000000000..4c851b76381 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-c8qx-qgh7-63qg/GHSA-c8qx-qgh7-63qg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8qx-qgh7-63qg", + "modified": "2025-06-06T15:30:45Z", + "published": "2025-06-06T15:30:45Z", + "aliases": [ + "CVE-2023-26000" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hanhdo205 Bang tinh vay allows Stored XSS. This issue affects Bang tinh vay: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26000" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bang-tinh-lai-suat/vulnerability/wordpress-bang-tinh-vay-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-cf7x-fj46-85vx/GHSA-cf7x-fj46-85vx.json b/advisories/unreviewed/2025/06/GHSA-cf7x-fj46-85vx/GHSA-cf7x-fj46-85vx.json new file mode 100644 index 00000000000..2c654770183 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-cf7x-fj46-85vx/GHSA-cf7x-fj46-85vx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cf7x-fj46-85vx", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-31025" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blocksera Image Hover Effects Block allows Stored XSS. This issue affects Image Hover Effects Block: from n/a through 1.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31025" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/image-hover-effects-block/vulnerability/wordpress-image-hover-effects-block-1-4-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-cfwc-3pfx-265p/GHSA-cfwc-3pfx-265p.json b/advisories/unreviewed/2025/06/GHSA-cfwc-3pfx-265p/GHSA-cfwc-3pfx-265p.json new file mode 100644 index 00000000000..45b7d36ca5d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-cfwc-3pfx-265p/GHSA-cfwc-3pfx-265p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfwc-3pfx-265p", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-49237" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in POEditor POEditor allows Path Traversal. This issue affects POEditor: from n/a through 0.9.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49237" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/poeditor/vulnerability/wordpress-poeditor-plugin-0-9-10-csrf-to-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-cmp3-q2f2-v785/GHSA-cmp3-q2f2-v785.json b/advisories/unreviewed/2025/06/GHSA-cmp3-q2f2-v785/GHSA-cmp3-q2f2-v785.json new file mode 100644 index 00000000000..b49e46e0673 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-cmp3-q2f2-v785/GHSA-cmp3-q2f2-v785.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmp3-q2f2-v785", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-29005" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in weblizar HR Management Lite allows Cross Site Request Forgery. This issue affects HR Management Lite: from n/a through 3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29005" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hr-management-lite/vulnerability/wordpress-hr-management-lite-3-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-cxwc-xmw6-fqpx/GHSA-cxwc-xmw6-fqpx.json b/advisories/unreviewed/2025/06/GHSA-cxwc-xmw6-fqpx/GHSA-cxwc-xmw6-fqpx.json new file mode 100644 index 00000000000..ee533c71cc4 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-cxwc-xmw6-fqpx/GHSA-cxwc-xmw6-fqpx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxwc-xmw6-fqpx", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30941" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marvie Pons Pinterest Verify Meta Tag allows Stored XSS. This issue affects Pinterest Verify Meta Tag: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30941" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pinterest-verify-meta-tag/vulnerability/wordpress-pinterest-verify-meta-tag-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-f2q9-v7gq-wp5m/GHSA-f2q9-v7gq-wp5m.json b/advisories/unreviewed/2025/06/GHSA-f2q9-v7gq-wp5m/GHSA-f2q9-v7gq-wp5m.json new file mode 100644 index 00000000000..111f33cd499 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-f2q9-v7gq-wp5m/GHSA-f2q9-v7gq-wp5m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2q9-v7gq-wp5m", + "modified": "2025-06-06T15:30:45Z", + "published": "2025-06-06T15:30:45Z", + "aliases": [ + "CVE-2025-24762" + ], + "details": "Missing Authorization vulnerability in facturaone TicketBAI Facturas para WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects TicketBAI Facturas para WooCommerce: from n/a through 3.19.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24762" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-ticketbai/vulnerability/wordpress-ticketbai-facturas-para-woocommerce-3-19-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-f2rm-gf2x-xx53/GHSA-f2rm-gf2x-xx53.json b/advisories/unreviewed/2025/06/GHSA-f2rm-gf2x-xx53/GHSA-f2rm-gf2x-xx53.json new file mode 100644 index 00000000000..7990cc0ba83 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-f2rm-gf2x-xx53/GHSA-f2rm-gf2x-xx53.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2rm-gf2x-xx53", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-30636" + ], + "details": "Missing Authorization vulnerability in Ability, Inc Accessibility Suite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Accessibility Suite: from n/a through 4.19.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30636" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/online-accessibility/vulnerability/wordpress-accessibility-suite-4-19-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-f4cp-8pj4-jjjf/GHSA-f4cp-8pj4-jjjf.json b/advisories/unreviewed/2025/06/GHSA-f4cp-8pj4-jjjf/GHSA-f4cp-8pj4-jjjf.json new file mode 100644 index 00000000000..d3476f45234 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-f4cp-8pj4-jjjf/GHSA-f4cp-8pj4-jjjf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4cp-8pj4-jjjf", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-28952" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Jonathan Lau CubePoints allows Cross Site Request Forgery. This issue affects CubePoints: from n/a through 3.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28952" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cubepoints/vulnerability/wordpress-cubepoints-3-2-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-f4w9-fc64-c5xw/GHSA-f4w9-fc64-c5xw.json b/advisories/unreviewed/2025/06/GHSA-f4w9-fc64-c5xw/GHSA-f4w9-fc64-c5xw.json new file mode 100644 index 00000000000..c82adff78a3 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-f4w9-fc64-c5xw/GHSA-f4w9-fc64-c5xw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4w9-fc64-c5xw", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-49263" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WCVendors WC Vendors Marketplace allows Blind SQL Injection. This issue affects WC Vendors Marketplace: from n/a through 2.5.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49263" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wc-vendors/vulnerability/wordpress-wc-vendors-marketplace-2-5-6-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-f5m3-4m73-89p9/GHSA-f5m3-4m73-89p9.json b/advisories/unreviewed/2025/06/GHSA-f5m3-4m73-89p9/GHSA-f5m3-4m73-89p9.json new file mode 100644 index 00000000000..3e6b3c61101 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-f5m3-4m73-89p9/GHSA-f5m3-4m73-89p9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5m3-4m73-89p9", + "modified": "2025-06-06T15:30:45Z", + "published": "2025-06-06T15:30:45Z", + "aliases": [ + "CVE-2023-25997" + ], + "details": "Missing Authorization vulnerability in SolaPlugins Sola Support Ticket allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sola Support Ticket: from n/a through 3.17.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25997" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sola-support-tickets/vulnerability/wordpress-sola-support-ticket-3-17-arbitrary-content-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-f722-953q-p28x/GHSA-f722-953q-p28x.json b/advisories/unreviewed/2025/06/GHSA-f722-953q-p28x/GHSA-f722-953q-p28x.json new file mode 100644 index 00000000000..eef84ca9f1d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-f722-953q-p28x/GHSA-f722-953q-p28x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f722-953q-p28x", + "modified": "2025-06-06T15:30:45Z", + "published": "2025-06-06T15:30:45Z", + "aliases": [ + "CVE-2025-23971" + ], + "details": "Missing Authorization vulnerability in whassan KI Live Video Conferences allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects KI Live Video Conferences: from n/a through 5.5.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23971" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ki-live-video-conferences/vulnerability/wordpress-ki-live-video-conferences-5-5-15-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-f784-j9pw-cpp6/GHSA-f784-j9pw-cpp6.json b/advisories/unreviewed/2025/06/GHSA-f784-j9pw-cpp6/GHSA-f784-j9pw-cpp6.json new file mode 100644 index 00000000000..1ce877d3df8 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-f784-j9pw-cpp6/GHSA-f784-j9pw-cpp6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f784-j9pw-cpp6", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-49262" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shaonsina Sina Extension for Elementor allows Stored XSS. This issue affects Sina Extension for Elementor: from n/a through 3.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49262" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sina-extension-for-elementor/vulnerability/wordpress-sina-extension-for-elementor-3-6-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-f948-372f-wc53/GHSA-f948-372f-wc53.json b/advisories/unreviewed/2025/06/GHSA-f948-372f-wc53/GHSA-f948-372f-wc53.json new file mode 100644 index 00000000000..9b0fd68d98f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-f948-372f-wc53/GHSA-f948-372f-wc53.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f948-372f-wc53", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30954" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin allows Phishing. This issue affects WP Gravity Forms Constant Contact Plugin: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30954" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gf-constant-contact/vulnerability/wordpress-wp-gravity-forms-constant-contact-plugin-1-1-0-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-fmpq-8fjf-whqh/GHSA-fmpq-8fjf-whqh.json b/advisories/unreviewed/2025/06/GHSA-fmpq-8fjf-whqh/GHSA-fmpq-8fjf-whqh.json new file mode 100644 index 00000000000..b52741ebecd --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-fmpq-8fjf-whqh/GHSA-fmpq-8fjf-whqh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmpq-8fjf-whqh", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30940" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in melipayamak Melipayamak allows Stored XSS. This issue affects Melipayamak: from n/a through 2.2.12.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30940" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/melipayamak/vulnerability/wordpress-melipayamak-2-2-12-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-frv7-wqrj-85p7/GHSA-frv7-wqrj-85p7.json b/advisories/unreviewed/2025/06/GHSA-frv7-wqrj-85p7/GHSA-frv7-wqrj-85p7.json new file mode 100644 index 00000000000..65e25836736 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-frv7-wqrj-85p7/GHSA-frv7-wqrj-85p7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frv7-wqrj-85p7", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-28954" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in wphobby Backwp allows Path Traversal. This issue affects Backwp: from n/a through 2.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28954" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/backwp/vulnerability/wordpress-backwp-plugin-2-0-2-csrf-to-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-g6w2-rpgm-fp62/GHSA-g6w2-rpgm-fp62.json b/advisories/unreviewed/2025/06/GHSA-g6w2-rpgm-fp62/GHSA-g6w2-rpgm-fp62.json new file mode 100644 index 00000000000..713abef953d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-g6w2-rpgm-fp62/GHSA-g6w2-rpgm-fp62.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6w2-rpgm-fp62", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49285" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Cross Site Request Forgery. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 3.8.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49285" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gdpr-cookie-consent/vulnerability/wordpress-wp-cookie-notice-for-gdpr-ccpa-eprivacy-consent-3-8-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-g8p5-6v5g-j48p/GHSA-g8p5-6v5g-j48p.json b/advisories/unreviewed/2025/06/GHSA-g8p5-6v5g-j48p/GHSA-g8p5-6v5g-j48p.json new file mode 100644 index 00000000000..361d7dbe8fb --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-g8p5-6v5g-j48p/GHSA-g8p5-6v5g-j48p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8p5-6v5g-j48p", + "modified": "2025-06-06T15:30:52Z", + "published": "2025-06-06T15:30:52Z", + "aliases": [ + "CVE-2025-49449" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive Regional Map of Africa allows Cross Site Request Forgery. This issue affects Interactive Regional Map of Africa: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49449" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/interactive-map-of-africa/vulnerability/wordpress-interactive-regional-map-of-africa-1-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-g9w5-98q6-xrq3/GHSA-g9w5-98q6-xrq3.json b/advisories/unreviewed/2025/06/GHSA-g9w5-98q6-xrq3/GHSA-g9w5-98q6-xrq3.json new file mode 100644 index 00000000000..77a7bfa350d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-g9w5-98q6-xrq3/GHSA-g9w5-98q6-xrq3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9w5-98q6-xrq3", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30942" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Post Custom Templates Lite allows Stored XSS. This issue affects Post Custom Templates Lite: from n/a through 1.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30942" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/post-custom-templates-lite/vulnerability/wordpress-post-custom-templates-lite-1-14-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-gg2x-q5hw-wpj9/GHSA-gg2x-q5hw-wpj9.json b/advisories/unreviewed/2025/06/GHSA-gg2x-q5hw-wpj9/GHSA-gg2x-q5hw-wpj9.json new file mode 100644 index 00000000000..879a736da0c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-gg2x-q5hw-wpj9/GHSA-gg2x-q5hw-wpj9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gg2x-q5hw-wpj9", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-49241" + ], + "details": "Missing Authorization vulnerability in bobbingwide oik allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects oik: from n/a through 4.15.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49241" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/oik/vulnerability/wordpress-oik-4-15-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-ggvh-9fqr-3h76/GHSA-ggvh-9fqr-3h76.json b/advisories/unreviewed/2025/06/GHSA-ggvh-9fqr-3h76/GHSA-ggvh-9fqr-3h76.json new file mode 100644 index 00000000000..baa369c59a0 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-ggvh-9fqr-3h76/GHSA-ggvh-9fqr-3h76.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggvh-9fqr-3h76", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-49238" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup allows Cross Site Request Forgery. This issue affects Everest Backup: from n/a through 2.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49238" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/everest-backup/vulnerability/wordpress-everest-backup-2-3-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-gq8x-j28v-rmw8/GHSA-gq8x-j28v-rmw8.json b/advisories/unreviewed/2025/06/GHSA-gq8x-j28v-rmw8/GHSA-gq8x-j28v-rmw8.json new file mode 100644 index 00000000000..643a1a61ae7 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-gq8x-j28v-rmw8/GHSA-gq8x-j28v-rmw8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq8x-j28v-rmw8", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30980" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Simple Keyword to Link allows Cross Site Request Forgery. This issue affects Simple Keyword to Link: from n/a through 1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30980" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-keyword-to-link/vulnerability/wordpress-simple-keyword-to-link-1-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-gqj6-wggh-fx6m/GHSA-gqj6-wggh-fx6m.json b/advisories/unreviewed/2025/06/GHSA-gqj6-wggh-fx6m/GHSA-gqj6-wggh-fx6m.json new file mode 100644 index 00000000000..94b22afe932 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-gqj6-wggh-fx6m/GHSA-gqj6-wggh-fx6m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqj6-wggh-fx6m", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-28996" + ], + "details": "Missing Authorization vulnerability in Thad Allender GPP Slideshow allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GPP Slideshow: from n/a through 1.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28996" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gpp-slideshow/vulnerability/wordpress-gpp-slideshow-1-3-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-grf2-pc7r-hf9f/GHSA-grf2-pc7r-hf9f.json b/advisories/unreviewed/2025/06/GHSA-grf2-pc7r-hf9f/GHSA-grf2-pc7r-hf9f.json new file mode 100644 index 00000000000..a857444ae81 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-grf2-pc7r-hf9f/GHSA-grf2-pc7r-hf9f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grf2-pc7r-hf9f", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30978" + ], + "details": "Missing Authorization vulnerability in Dor Zuberi Slack Notifications by dorzki allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Slack Notifications by dorzki: from n/a through 2.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30978" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dorzki-notifications-to-slack/vulnerability/wordpress-slack-notifications-by-dorzki-2-0-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-grgc-75v9-qc7f/GHSA-grgc-75v9-qc7f.json b/advisories/unreviewed/2025/06/GHSA-grgc-75v9-qc7f/GHSA-grgc-75v9-qc7f.json new file mode 100644 index 00000000000..9977b50cc73 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-grgc-75v9-qc7f/GHSA-grgc-75v9-qc7f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grgc-75v9-qc7f", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49273" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Bill Minozzi WP Tools allows Cross Site Request Forgery. This issue affects WP Tools: from n/a through 5.24.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49273" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wptools/vulnerability/wordpress-wp-tools-5-24-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-gvhw-925r-f67g/GHSA-gvhw-925r-f67g.json b/advisories/unreviewed/2025/06/GHSA-gvhw-925r-f67g/GHSA-gvhw-925r-f67g.json new file mode 100644 index 00000000000..c6e14058579 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-gvhw-925r-f67g/GHSA-gvhw-925r-f67g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvhw-925r-f67g", + "modified": "2025-06-06T15:30:52Z", + "published": "2025-06-06T15:30:52Z", + "aliases": [ + "CVE-2025-49450" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mhallmann SEPA Girocode allows Stored XSS. This issue affects SEPA Girocode: from n/a through 0.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49450" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sepa-girocode/vulnerability/wordpress-sepa-girocode-0-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-gw97-cqwg-xmh4/GHSA-gw97-cqwg-xmh4.json b/advisories/unreviewed/2025/06/GHSA-gw97-cqwg-xmh4/GHSA-gw97-cqwg-xmh4.json new file mode 100644 index 00000000000..07224014d23 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-gw97-cqwg-xmh4/GHSA-gw97-cqwg-xmh4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gw97-cqwg-xmh4", + "modified": "2025-06-06T15:30:53Z", + "published": "2025-06-06T15:30:53Z", + "aliases": [ + "CVE-2025-5806" + ], + "details": "Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jenkins 1.641 and 1.625, resulting in a cross-site scripting (XSS) vulnerability exploitable by users able to change report content.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5806" + }, + { + "type": "WEB", + "url": "https://www.jenkins.io/security/advisory/2025-06-06/#SECURITY-3588" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T14:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-h2j3-px3x-p7fc/GHSA-h2j3-px3x-p7fc.json b/advisories/unreviewed/2025/06/GHSA-h2j3-px3x-p7fc/GHSA-h2j3-px3x-p7fc.json new file mode 100644 index 00000000000..b795ffda3c8 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-h2j3-px3x-p7fc/GHSA-h2j3-px3x-p7fc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2j3-px3x-p7fc", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-30995" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Widgetize Pages Light allows Stored XSS. This issue affects Widgetize Pages Light: from n/a through 3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30995" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/widgetize-pages-light/vulnerability/wordpress-widgetize-pages-light-plugin-3-0-cross-site-request-forgery-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-h6f6-gv69-8854/GHSA-h6f6-gv69-8854.json b/advisories/unreviewed/2025/06/GHSA-h6f6-gv69-8854/GHSA-h6f6-gv69-8854.json new file mode 100644 index 00000000000..3fda3885114 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-h6f6-gv69-8854/GHSA-h6f6-gv69-8854.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6f6-gv69-8854", + "modified": "2025-06-06T15:30:53Z", + "published": "2025-06-06T15:30:53Z", + "aliases": [ + "CVE-2025-5765" + ], + "details": "A vulnerability was found in code-projects Laundry System 1.0. It has been classified as problematic. This affects an unknown part of the file /data/edit_laundry.php. The manipulation of the argument Customer leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5765" + }, + { + "type": "WEB", + "url": "https://github.com/tuooo/CVE/issues/6" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311307" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311307" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.590809" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-h6vr-9wv8-4hq8/GHSA-h6vr-9wv8-4hq8.json b/advisories/unreviewed/2025/06/GHSA-h6vr-9wv8-4hq8/GHSA-h6vr-9wv8-4hq8.json new file mode 100644 index 00000000000..729a1d27523 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-h6vr-9wv8-4hq8/GHSA-h6vr-9wv8-4hq8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6vr-9wv8-4hq8", + "modified": "2025-06-06T15:30:52Z", + "published": "2025-06-06T15:30:52Z", + "aliases": [ + "CVE-2025-49332" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in codepeople WP Time Slots Booking Form allows Cross Site Request Forgery. This issue affects WP Time Slots Booking Form: from n/a through 1.2.30.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49332" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-time-slots-booking-form/vulnerability/wordpress-wp-time-slots-booking-form-1-2-30-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-h9gv-fp8g-jmjf/GHSA-h9gv-fp8g-jmjf.json b/advisories/unreviewed/2025/06/GHSA-h9gv-fp8g-jmjf/GHSA-h9gv-fp8g-jmjf.json new file mode 100644 index 00000000000..364de61de77 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-h9gv-fp8g-jmjf/GHSA-h9gv-fp8g-jmjf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9gv-fp8g-jmjf", + "modified": "2025-06-06T15:30:53Z", + "published": "2025-06-06T15:30:53Z", + "aliases": [ + "CVE-2025-49453" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Jatinder Pal Singh BP Profile as Homepage allows Stored XSS. This issue affects BP Profile as Homepage: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49453" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bp-profile-as-homepage/vulnerability/wordpress-bp-profile-as-homepage-plugin-1-1-cross-site-request-forgery-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hf8j-3v33-3943/GHSA-hf8j-3v33-3943.json b/advisories/unreviewed/2025/06/GHSA-hf8j-3v33-3943/GHSA-hf8j-3v33-3943.json new file mode 100644 index 00000000000..653d4251707 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hf8j-3v33-3943/GHSA-hf8j-3v33-3943.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf8j-3v33-3943", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-30931" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shamil Shafeev «Подсказки» от DaData.ru allows Stored XSS. This issue affects «Подсказки» от DaData.ru: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30931" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dadata-ru/vulnerability/wordpress-podskazki-ot-dadata-ru-1-0-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hh2g-8q2h-whg5/GHSA-hh2g-8q2h-whg5.json b/advisories/unreviewed/2025/06/GHSA-hh2g-8q2h-whg5/GHSA-hh2g-8q2h-whg5.json new file mode 100644 index 00000000000..4f21586b712 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hh2g-8q2h-whg5/GHSA-hh2g-8q2h-whg5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh2g-8q2h-whg5", + "modified": "2025-06-06T15:30:52Z", + "published": "2025-06-06T15:30:52Z", + "aliases": [ + "CVE-2025-49441" + ], + "details": "Missing Authorization vulnerability in WP Map Plugins Interactive Regional Map of Florida allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Interactive Regional Map of Florida: from n/a through 1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49441" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/interactive-map-of-florida/vulnerability/wordpress-interactive-regional-map-of-florida-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hhrv-88gm-j7wv/GHSA-hhrv-88gm-j7wv.json b/advisories/unreviewed/2025/06/GHSA-hhrv-88gm-j7wv/GHSA-hhrv-88gm-j7wv.json new file mode 100644 index 00000000000..52e001b82a0 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hhrv-88gm-j7wv/GHSA-hhrv-88gm-j7wv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhrv-88gm-j7wv", + "modified": "2025-06-06T15:30:51Z", + "published": "2025-06-06T15:30:51Z", + "aliases": [ + "CVE-2025-49314" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ovatheme BRW allows Stored XSS. This issue affects BRW: from n/a through 1.8.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49314" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ova-brw/vulnerability/wordpress-brw-1-8-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hjfc-fr87-qrcw/GHSA-hjfc-fr87-qrcw.json b/advisories/unreviewed/2025/06/GHSA-hjfc-fr87-qrcw/GHSA-hjfc-fr87-qrcw.json new file mode 100644 index 00000000000..d72fdbf4fdd --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hjfc-fr87-qrcw/GHSA-hjfc-fr87-qrcw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjfc-fr87-qrcw", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30976" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in wpdive Nexa Blocks allows Server Side Request Forgery. This issue affects Nexa Blocks: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30976" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nexa-blocks/vulnerability/wordpress-nexa-blocks-1-1-0-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hpj8-847g-hq6h/GHSA-hpj8-847g-hq6h.json b/advisories/unreviewed/2025/06/GHSA-hpj8-847g-hq6h/GHSA-hpj8-847g-hq6h.json new file mode 100644 index 00000000000..3d8efe66a74 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hpj8-847g-hq6h/GHSA-hpj8-847g-hq6h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpj8-847g-hq6h", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-30997" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Car Repair Services allows Server Side Request Forgery. This issue affects Car Repair Services: from n/a through 5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30997" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/car-repair-services/vulnerability/wordpress-car-repair-services-5-0-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hwvq-mjfg-g8qp/GHSA-hwvq-mjfg-g8qp.json b/advisories/unreviewed/2025/06/GHSA-hwvq-mjfg-g8qp/GHSA-hwvq-mjfg-g8qp.json new file mode 100644 index 00000000000..483a50021c0 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hwvq-mjfg-g8qp/GHSA-hwvq-mjfg-g8qp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwvq-mjfg-g8qp", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-30935" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NickDuncan Contact Form allows DOM-Based XSS. This issue affects Contact Form: from n/a through 2.0.12.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30935" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/contact-form-ready/vulnerability/wordpress-contact-form-2-0-12-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hxxj-pgmw-p98q/GHSA-hxxj-pgmw-p98q.json b/advisories/unreviewed/2025/06/GHSA-hxxj-pgmw-p98q/GHSA-hxxj-pgmw-p98q.json new file mode 100644 index 00000000000..d628d76e3b4 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hxxj-pgmw-p98q/GHSA-hxxj-pgmw-p98q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxxj-pgmw-p98q", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30952" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdive Nexa Blocks allows Stored XSS. This issue affects Nexa Blocks: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30952" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/nexa-blocks/vulnerability/wordpress-nexa-blocks-1-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-j224-44r5-g5gx/GHSA-j224-44r5-g5gx.json b/advisories/unreviewed/2025/06/GHSA-j224-44r5-g5gx/GHSA-j224-44r5-g5gx.json new file mode 100644 index 00000000000..e61f5d25ebc --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-j224-44r5-g5gx/GHSA-j224-44r5-g5gx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j224-44r5-g5gx", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-28986" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Webaholicson Epicwin Plugin allows SQL Injection. This issue affects Epicwin Plugin: from n/a through 1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28986" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/epicwin-subscribers/vulnerability/wordpress-epicwin-plugin-plugin-1-5-csrf-to-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-j69g-w3gv-65xq/GHSA-j69g-w3gv-65xq.json b/advisories/unreviewed/2025/06/GHSA-j69g-w3gv-65xq/GHSA-j69g-w3gv-65xq.json new file mode 100644 index 00000000000..fc31e5f27f1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-j69g-w3gv-65xq/GHSA-j69g-w3gv-65xq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j69g-w3gv-65xq", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-30629" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Codehaveli Bitly URL Shortener allows Cross Site Request Forgery. This issue affects Bitly URL Shortener: from n/a through 1.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30629" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/codehaveli-bitly-url-shortener/vulnerability/wordpress-bitly-url-shortener-1-3-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-j7g5-hmrm-fq9h/GHSA-j7g5-hmrm-fq9h.json b/advisories/unreviewed/2025/06/GHSA-j7g5-hmrm-fq9h/GHSA-j7g5-hmrm-fq9h.json new file mode 100644 index 00000000000..84fa973d398 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-j7g5-hmrm-fq9h/GHSA-j7g5-hmrm-fq9h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7g5-hmrm-fq9h", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49246" + ], + "details": "Missing Authorization vulnerability in cmoreira Testimonials Showcase allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Testimonials Showcase: from n/a through 1.9.16.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49246" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/testimonials-showcase/vulnerability/wordpress-testimonials-showcase-1-9-16-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-j8x8-h75r-56qj/GHSA-j8x8-h75r-56qj.json b/advisories/unreviewed/2025/06/GHSA-j8x8-h75r-56qj/GHSA-j8x8-h75r-56qj.json new file mode 100644 index 00000000000..704f5cbaf51 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-j8x8-h75r-56qj/GHSA-j8x8-h75r-56qj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8x8-h75r-56qj", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49248" + ], + "details": "Missing Authorization vulnerability in cmoreira Team Showcase allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Team Showcase: from n/a through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49248" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/team-showcase-cm/vulnerability/wordpress-team-showcase-25-05-13-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-j9w6-q392-h4mr/GHSA-j9w6-q392-h4mr.json b/advisories/unreviewed/2025/06/GHSA-j9w6-q392-h4mr/GHSA-j9w6-q392-h4mr.json new file mode 100644 index 00000000000..ddd4358793a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-j9w6-q392-h4mr/GHSA-j9w6-q392-h4mr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9w6-q392-h4mr", + "modified": "2025-06-06T15:30:51Z", + "published": "2025-06-06T15:30:51Z", + "aliases": [ + "CVE-2025-49313" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme BRW allows PHP Local File Inclusion. This issue affects BRW: from n/a through 1.8.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49313" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ova-brw/vulnerability/wordpress-brw-1-8-6-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jgff-87j3-r73h/GHSA-jgff-87j3-r73h.json b/advisories/unreviewed/2025/06/GHSA-jgff-87j3-r73h/GHSA-jgff-87j3-r73h.json new file mode 100644 index 00000000000..266e7883757 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jgff-87j3-r73h/GHSA-jgff-87j3-r73h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgff-87j3-r73h", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-30630" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pozzad Global Translator allows Stored XSS. This issue affects Global Translator: from n/a through 2.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30630" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/global-translator/vulnerability/wordpress-global-translator-2-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jj6x-g6x8-q7p9/GHSA-jj6x-g6x8-q7p9.json b/advisories/unreviewed/2025/06/GHSA-jj6x-g6x8-q7p9/GHSA-jj6x-g6x8-q7p9.json new file mode 100644 index 00000000000..8d6c0293ccc --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jj6x-g6x8-q7p9/GHSA-jj6x-g6x8-q7p9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jj6x-g6x8-q7p9", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49286" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP Table Builder WP Table Builder allows Cross Site Request Forgery. This issue affects WP Table Builder: from n/a through 2.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49286" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-table-builder/vulnerability/wordpress-wp-table-builder-2-0-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jp5g-xj2c-hhq4/GHSA-jp5g-xj2c-hhq4.json b/advisories/unreviewed/2025/06/GHSA-jp5g-xj2c-hhq4/GHSA-jp5g-xj2c-hhq4.json new file mode 100644 index 00000000000..9064c948eb9 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jp5g-xj2c-hhq4/GHSA-jp5g-xj2c-hhq4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jp5g-xj2c-hhq4", + "modified": "2025-06-06T15:30:52Z", + "published": "2025-06-06T15:30:52Z", + "aliases": [ + "CVE-2025-49425" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Adrian Hanft Konami Easter Egg allows Stored XSS. This issue affects Konami Easter Egg: from n/a through v0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49425" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/konami-easter-egg/vulnerability/wordpress-konami-easter-egg-v0-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jq8x-v7jw-v675/GHSA-jq8x-v7jw-v675.json b/advisories/unreviewed/2025/06/GHSA-jq8x-v7jw-v675/GHSA-jq8x-v7jw-v675.json new file mode 100644 index 00000000000..8e9b79b5abe --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jq8x-v7jw-v675/GHSA-jq8x-v7jw-v675.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq8x-v7jw-v675", + "modified": "2025-06-06T15:30:53Z", + "published": "2025-06-06T15:30:53Z", + "aliases": [ + "CVE-2025-5791" + ], + "details": "A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5791" + }, + { + "type": "WEB", + "url": "https://github.com/ogham/rust-users/issues/44" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-5791" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2370001" + }, + { + "type": "WEB", + "url": "https://crates.io/crates/users" + }, + { + "type": "WEB", + "url": "https://rustsec.org/advisories/RUSTSEC-2025-0040.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T14:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jwhw-x4j5-wcx9/GHSA-jwhw-x4j5-wcx9.json b/advisories/unreviewed/2025/06/GHSA-jwhw-x4j5-wcx9/GHSA-jwhw-x4j5-wcx9.json new file mode 100644 index 00000000000..5c13adfa92e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jwhw-x4j5-wcx9/GHSA-jwhw-x4j5-wcx9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwhw-x4j5-wcx9", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30958" + ], + "details": "Missing Authorization vulnerability in onOffice GmbH onOffice for WP-Websites allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects onOffice for WP-Websites: from n/a through 5.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30958" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/onoffice-for-wp-websites/vulnerability/wordpress-onoffice-for-wp-websites-5-7-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-m2m8-6367-hpxp/GHSA-m2m8-6367-hpxp.json b/advisories/unreviewed/2025/06/GHSA-m2m8-6367-hpxp/GHSA-m2m8-6367-hpxp.json new file mode 100644 index 00000000000..6e49273959e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-m2m8-6367-hpxp/GHSA-m2m8-6367-hpxp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2m8-6367-hpxp", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-30928" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vicchi WP Biographia allows Stored XSS. This issue affects WP Biographia: from n/a through 4.0.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30928" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-biographia/vulnerability/wordpress-wp-biographia-4-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-m535-wcvm-rcf9/GHSA-m535-wcvm-rcf9.json b/advisories/unreviewed/2025/06/GHSA-m535-wcvm-rcf9/GHSA-m535-wcvm-rcf9.json new file mode 100644 index 00000000000..420fdc7e96f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-m535-wcvm-rcf9/GHSA-m535-wcvm-rcf9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m535-wcvm-rcf9", + "modified": "2025-06-06T15:30:51Z", + "published": "2025-06-06T15:30:51Z", + "aliases": [ + "CVE-2025-49315" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PersianScript Persian Woocommerce SMS allows SQL Injection. This issue affects Persian Woocommerce SMS: from n/a through 7.0.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49315" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/persian-woocommerce-sms/vulnerability/wordpress-persian-woocommerce-sms-7-0-10-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-m9f2-xc45-f5wp/GHSA-m9f2-xc45-f5wp.json b/advisories/unreviewed/2025/06/GHSA-m9f2-xc45-f5wp/GHSA-m9f2-xc45-f5wp.json new file mode 100644 index 00000000000..5658b5a09fc --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-m9f2-xc45-f5wp/GHSA-m9f2-xc45-f5wp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9f2-xc45-f5wp", + "modified": "2025-06-06T15:30:51Z", + "published": "2025-06-06T15:30:51Z", + "aliases": [ + "CVE-2025-49323" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking allows SQL Injection. This issue affects Hydra Booking: from n/a through 1.1.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49323" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/hydra-booking/vulnerability/wordpress-hydra-booking-1-1-10-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-mj27-3vcf-w6g3/GHSA-mj27-3vcf-w6g3.json b/advisories/unreviewed/2025/06/GHSA-mj27-3vcf-w6g3/GHSA-mj27-3vcf-w6g3.json new file mode 100644 index 00000000000..e462339b955 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-mj27-3vcf-w6g3/GHSA-mj27-3vcf-w6g3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mj27-3vcf-w6g3", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49307" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Magazine3 WP Multilang allows PHP Local File Inclusion. This issue affects WP Multilang: from n/a through 2.4.19.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49307" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-multilang/vulnerability/wordpress-wp-multilang-2-4-19-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-mm2h-gh9g-xfgr/GHSA-mm2h-gh9g-xfgr.json b/advisories/unreviewed/2025/06/GHSA-mm2h-gh9g-xfgr/GHSA-mm2h-gh9g-xfgr.json new file mode 100644 index 00000000000..9b71e99c888 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-mm2h-gh9g-xfgr/GHSA-mm2h-gh9g-xfgr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm2h-gh9g-xfgr", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-30624" + ], + "details": "Missing Authorization vulnerability in WordLift WordLift allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WordLift: from n/a through 3.54.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30624" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wordlift/vulnerability/wordpress-wordlift-3-54-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-mq78-43mr-2m8c/GHSA-mq78-43mr-2m8c.json b/advisories/unreviewed/2025/06/GHSA-mq78-43mr-2m8c/GHSA-mq78-43mr-2m8c.json new file mode 100644 index 00000000000..692b7fe3885 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-mq78-43mr-2m8c/GHSA-mq78-43mr-2m8c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq78-43mr-2m8c", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49284" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in wp-buy WP Maintenance Mode & Site Under Construction allows Cross Site Request Forgery. This issue affects WP Maintenance Mode & Site Under Construction: from n/a through 4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49284" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-maintenance-mode-site-under-construction/vulnerability/wordpress-wp-maintenance-mode-site-under-construction-4-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-mr3x-q7wx-p856/GHSA-mr3x-q7wx-p856.json b/advisories/unreviewed/2025/06/GHSA-mr3x-q7wx-p856/GHSA-mr3x-q7wx-p856.json new file mode 100644 index 00000000000..70db250a51e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-mr3x-q7wx-p856/GHSA-mr3x-q7wx-p856.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr3x-q7wx-p856", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-29013" + ], + "details": "Missing Authorization vulnerability in faaiq Custom Category/Post Type Post order allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Custom Category/Post Type Post order: from n/a through 1.5.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29013" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/custom-post-order-category/vulnerability/wordpress-custom-category-post-type-post-order-1-5-9-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-mrwp-rfj5-cqph/GHSA-mrwp-rfj5-cqph.json b/advisories/unreviewed/2025/06/GHSA-mrwp-rfj5-cqph/GHSA-mrwp-rfj5-cqph.json new file mode 100644 index 00000000000..538043bfb60 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-mrwp-rfj5-cqph/GHSA-mrwp-rfj5-cqph.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrwp-rfj5-cqph", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-30632" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in pozzad Global Translator allows Cross Site Request Forgery. This issue affects Global Translator: from n/a through 2.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30632" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/global-translator/vulnerability/wordpress-global-translator-2-0-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-mww5-xvq9-f9hp/GHSA-mww5-xvq9-f9hp.json b/advisories/unreviewed/2025/06/GHSA-mww5-xvq9-f9hp/GHSA-mww5-xvq9-f9hp.json new file mode 100644 index 00000000000..7c87a123d1d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-mww5-xvq9-f9hp/GHSA-mww5-xvq9-f9hp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mww5-xvq9-f9hp", + "modified": "2025-06-06T15:30:52Z", + "published": "2025-06-06T15:30:52Z", + "aliases": [ + "CVE-2025-49427" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Burnette Abbie Expander allows Stored XSS. This issue affects Abbie Expander: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49427" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/abbie-expander/vulnerability/wordpress-abbie-expander-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-p6ff-97p8-xxmr/GHSA-p6ff-97p8-xxmr.json b/advisories/unreviewed/2025/06/GHSA-p6ff-97p8-xxmr/GHSA-p6ff-97p8-xxmr.json new file mode 100644 index 00000000000..ebf9948eda5 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-p6ff-97p8-xxmr/GHSA-p6ff-97p8-xxmr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6ff-97p8-xxmr", + "modified": "2025-06-06T15:30:53Z", + "published": "2025-06-06T15:30:53Z", + "aliases": [ + "CVE-2025-38002" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/fdinfo: grab ctx->uring_lock around io_uring_show_fdinfo()\n\nNot everything requires locking in there, which is why the 'has_lock'\nvariable exists. But enough does that it's a bit unwieldy to manage.\nWrap the whole thing in a ->uring_lock trylock, and just return\nwith no output if we fail to grab it. The existing trylock() will\nalready have greatly diminished utility/output for the failure case.\n\nThis fixes an issue with reading the SQE fields, if the ring is being\nactively resized at the same time.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-38002" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bdb7d2ec2e31c46c45d1f32667dfa8216a72705e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d871198ee431d90f5308d53998c1ba1d5db5619a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-p97q-75c4-gq7q/GHSA-p97q-75c4-gq7q.json b/advisories/unreviewed/2025/06/GHSA-p97q-75c4-gq7q/GHSA-p97q-75c4-gq7q.json new file mode 100644 index 00000000000..1a124bc4b34 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-p97q-75c4-gq7q/GHSA-p97q-75c4-gq7q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p97q-75c4-gq7q", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30981" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in tggfref WP-Recall allows Privilege Escalation. This issue affects WP-Recall: from n/a through 16.26.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30981" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-recall/vulnerability/wordpress-wp-recall-plugin-16-26-14-csrf-to-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-p9ph-6ww4-r598/GHSA-p9ph-6ww4-r598.json b/advisories/unreviewed/2025/06/GHSA-p9ph-6ww4-r598/GHSA-p9ph-6ww4-r598.json new file mode 100644 index 00000000000..6115f93aaca --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-p9ph-6ww4-r598/GHSA-p9ph-6ww4-r598.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9ph-6ww4-r598", + "modified": "2025-06-06T15:30:52Z", + "published": "2025-06-06T15:30:52Z", + "aliases": [ + "CVE-2025-49333" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wp.insider Simple Membership allows Stored XSS. This issue affects Simple Membership: from n/a through 4.6.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49333" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/simple-membership/vulnerability/wordpress-simple-membership-4-6-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-pf64-rrx4-wwpm/GHSA-pf64-rrx4-wwpm.json b/advisories/unreviewed/2025/06/GHSA-pf64-rrx4-wwpm/GHSA-pf64-rrx4-wwpm.json new file mode 100644 index 00000000000..e3abd13a631 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-pf64-rrx4-wwpm/GHSA-pf64-rrx4-wwpm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf64-rrx4-wwpm", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-28989" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arildur Read More Login allows Stored XSS. This issue affects Read More Login: from n/a through 2.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28989" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/read-more-login/vulnerability/wordpress-read-more-login-2-0-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-pmr2-6qw8-g5h4/GHSA-pmr2-6qw8-g5h4.json b/advisories/unreviewed/2025/06/GHSA-pmr2-6qw8-g5h4/GHSA-pmr2-6qw8-g5h4.json new file mode 100644 index 00000000000..50a60b9896b --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-pmr2-6qw8-g5h4/GHSA-pmr2-6qw8-g5h4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmr2-6qw8-g5h4", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-49243" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sevenspark ShiftNav – Responsive Mobile Menu allows Stored XSS. This issue affects ShiftNav – Responsive Mobile Menu: from n/a through 1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49243" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/shiftnav-responsive-mobile-menu/vulnerability/wordpress-shiftnav-responsive-mobile-menu-1-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-pmwx-4xrc-36xv/GHSA-pmwx-4xrc-36xv.json b/advisories/unreviewed/2025/06/GHSA-pmwx-4xrc-36xv/GHSA-pmwx-4xrc-36xv.json new file mode 100644 index 00000000000..b3035c924c4 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-pmwx-4xrc-36xv/GHSA-pmwx-4xrc-36xv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmwx-4xrc-36xv", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30951" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stiofan BlockStrap Page Builder - Bootstrap Blocks allows Stored XSS. This issue affects BlockStrap Page Builder - Bootstrap Blocks: from n/a through 0.1.36.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30951" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/blockstrap-page-builder-blocks/vulnerability/wordpress-blockstrap-page-builder-bootstrap-blocks-0-1-36-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-pqg7-w24c-x8cv/GHSA-pqg7-w24c-x8cv.json b/advisories/unreviewed/2025/06/GHSA-pqg7-w24c-x8cv/GHSA-pqg7-w24c-x8cv.json new file mode 100644 index 00000000000..6068c8bfcc5 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-pqg7-w24c-x8cv/GHSA-pqg7-w24c-x8cv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqg7-w24c-x8cv", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-30930" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unreal Themes ACF: Yandex Maps Field allows Stored XSS. This issue affects ACF: Yandex Maps Field: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30930" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/acf-yandex-maps-field/vulnerability/wordpress-acf-yandex-maps-field-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-prm5-xmq3-344w/GHSA-prm5-xmq3-344w.json b/advisories/unreviewed/2025/06/GHSA-prm5-xmq3-344w/GHSA-prm5-xmq3-344w.json new file mode 100644 index 00000000000..a416dd050a3 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-prm5-xmq3-344w/GHSA-prm5-xmq3-344w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prm5-xmq3-344w", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-28981" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Soli WP Mail Options allows Stored XSS. This issue affects WP Mail Options: from n/a through 0.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28981" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-mail-options/vulnerability/wordpress-wp-mail-options-plugin-0-2-3-cross-site-request-forgery-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-pvp2-4qqp-rvh5/GHSA-pvp2-4qqp-rvh5.json b/advisories/unreviewed/2025/06/GHSA-pvp2-4qqp-rvh5/GHSA-pvp2-4qqp-rvh5.json new file mode 100644 index 00000000000..b39fa9868e9 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-pvp2-4qqp-rvh5/GHSA-pvp2-4qqp-rvh5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvp2-4qqp-rvh5", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-49268" + ], + "details": "Missing Authorization vulnerability in Soft8Soft LLC Verge3D allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Verge3D: from n/a through 4.9.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49268" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/verge3d/vulnerability/wordpress-verge3d-4-9-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-pwjp-r4cj-h394/GHSA-pwjp-r4cj-h394.json b/advisories/unreviewed/2025/06/GHSA-pwjp-r4cj-h394/GHSA-pwjp-r4cj-h394.json new file mode 100644 index 00000000000..4366d1cb432 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-pwjp-r4cj-h394/GHSA-pwjp-r4cj-h394.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwjp-r4cj-h394", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-49242" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sevenspark Bellows Accordion Menu allows Stored XSS. This issue affects Bellows Accordion Menu: from n/a through 1.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49242" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bellows-accordion-menu/vulnerability/wordpress-bellows-accordion-menu-1-4-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-pxh8-hqmf-3q7p/GHSA-pxh8-hqmf-3q7p.json b/advisories/unreviewed/2025/06/GHSA-pxh8-hqmf-3q7p/GHSA-pxh8-hqmf-3q7p.json new file mode 100644 index 00000000000..582f217cac0 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-pxh8-hqmf-3q7p/GHSA-pxh8-hqmf-3q7p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxh8-hqmf-3q7p", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-28994" + ], + "details": "Missing Authorization vulnerability in viralloops Viral Loops WP Integration allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Viral Loops WP Integration: from n/a through 3.8.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28994" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/viral-loops-wp-integration/vulnerability/wordpress-viral-loops-wp-integration-3-8-1-broken-access-control-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-pxpm-gqm6-6pwh/GHSA-pxpm-gqm6-6pwh.json b/advisories/unreviewed/2025/06/GHSA-pxpm-gqm6-6pwh/GHSA-pxpm-gqm6-6pwh.json index 39086b0a97d..889361d73b9 100644 --- a/advisories/unreviewed/2025/06/GHSA-pxpm-gqm6-6pwh/GHSA-pxpm-gqm6-6pwh.json +++ b/advisories/unreviewed/2025/06/GHSA-pxpm-gqm6-6pwh/GHSA-pxpm-gqm6-6pwh.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/06/GHSA-q3pw-ff2j-j9x5/GHSA-q3pw-ff2j-j9x5.json b/advisories/unreviewed/2025/06/GHSA-q3pw-ff2j-j9x5/GHSA-q3pw-ff2j-j9x5.json new file mode 100644 index 00000000000..3cbbc11e814 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-q3pw-ff2j-j9x5/GHSA-q3pw-ff2j-j9x5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3pw-ff2j-j9x5", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-30927" + ], + "details": "Missing Authorization vulnerability in Wordapp Team Wordapp allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Wordapp: from n/a through 1.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30927" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wordapp/vulnerability/wordpress-wordapp-1-7-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-q5w3-ffhf-j4gq/GHSA-q5w3-ffhf-j4gq.json b/advisories/unreviewed/2025/06/GHSA-q5w3-ffhf-j4gq/GHSA-q5w3-ffhf-j4gq.json new file mode 100644 index 00000000000..200ed7ec795 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-q5w3-ffhf-j4gq/GHSA-q5w3-ffhf-j4gq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5w3-ffhf-j4gq", + "modified": "2025-06-06T15:30:54Z", + "published": "2025-06-06T15:30:53Z", + "aliases": [ + "CVE-2025-41646" + ], + "details": "An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to full compromise of the device", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41646" + }, + { + "type": "WEB", + "url": "https://psirt.kunbus.com/.well-known/csaf/white/2025/kunbus-2025-0000003.json" + }, + { + "type": "WEB", + "url": "https://www.kunbus.com/en/productsecurity/Kunbus-2025-0000003" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-704" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-q65x-6qf2-r7c9/GHSA-q65x-6qf2-r7c9.json b/advisories/unreviewed/2025/06/GHSA-q65x-6qf2-r7c9/GHSA-q65x-6qf2-r7c9.json new file mode 100644 index 00000000000..ac0fbe9f7a9 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-q65x-6qf2-r7c9/GHSA-q65x-6qf2-r7c9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q65x-6qf2-r7c9", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-49240" + ], + "details": "Missing Authorization vulnerability in nK DocsPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects DocsPress: from n/a through 2.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49240" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/docspress/vulnerability/wordpress-docspress-2-5-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-q7j4-jjmp-4h73/GHSA-q7j4-jjmp-4h73.json b/advisories/unreviewed/2025/06/GHSA-q7j4-jjmp-4h73/GHSA-q7j4-jjmp-4h73.json new file mode 100644 index 00000000000..922ce6e7543 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-q7j4-jjmp-4h73/GHSA-q7j4-jjmp-4h73.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7j4-jjmp-4h73", + "modified": "2025-06-06T15:30:52Z", + "published": "2025-06-06T15:30:52Z", + "aliases": [ + "CVE-2025-49435" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Hasina77 Wp Easy Allopass allows Cross Site Request Forgery. This issue affects Wp Easy Allopass: from n/a through 4.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49435" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wordpress-easy-allopass/vulnerability/wordpress-wp-easy-allopass-4-1-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-q8xh-qgh4-qq6g/GHSA-q8xh-qgh4-qq6g.json b/advisories/unreviewed/2025/06/GHSA-q8xh-qgh4-qq6g/GHSA-q8xh-qgh4-qq6g.json new file mode 100644 index 00000000000..97d17ec36fa --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-q8xh-qgh4-qq6g/GHSA-q8xh-qgh4-qq6g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8xh-qgh4-qq6g", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-30939" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debashish IFrame Widget allows Stored XSS. This issue affects IFrame Widget: from n/a through 4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30939" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/iframe-widget/vulnerability/wordpress-iframe-widget-4-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-q9hm-gr74-fgcp/GHSA-q9hm-gr74-fgcp.json b/advisories/unreviewed/2025/06/GHSA-q9hm-gr74-fgcp/GHSA-q9hm-gr74-fgcp.json new file mode 100644 index 00000000000..3bf3b652434 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-q9hm-gr74-fgcp/GHSA-q9hm-gr74-fgcp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9hm-gr74-fgcp", + "modified": "2025-06-06T15:30:45Z", + "published": "2025-06-06T15:30:45Z", + "aliases": [ + "CVE-2025-26590" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nir Complete Google Seo Scan allows SQL Injection. This issue affects Complete Google Seo Scan: from n/a through 3.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26590" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/complete-google-seo-scan/vulnerability/wordpress-complete-google-seo-scan-3-5-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-qj8x-h4qp-2qvv/GHSA-qj8x-h4qp-2qvv.json b/advisories/unreviewed/2025/06/GHSA-qj8x-h4qp-2qvv/GHSA-qj8x-h4qp-2qvv.json new file mode 100644 index 00000000000..d956987963f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-qj8x-h4qp-2qvv/GHSA-qj8x-h4qp-2qvv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qj8x-h4qp-2qvv", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30989" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Renzo Tejada Libro de Reclamaciones y Quejas allows SQL Injection. This issue affects Libro de Reclamaciones y Quejas: from n/a through 0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30989" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/libro-de-reclamaciones-y-quejas/vulnerability/wordpress-libro-de-reclamaciones-y-quejas-0-9-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-qp5x-4mww-ph6q/GHSA-qp5x-4mww-ph6q.json b/advisories/unreviewed/2025/06/GHSA-qp5x-4mww-ph6q/GHSA-qp5x-4mww-ph6q.json new file mode 100644 index 00000000000..dc3a70044c5 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-qp5x-4mww-ph6q/GHSA-qp5x-4mww-ph6q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp5x-4mww-ph6q", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30956" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Booqable Rental Software Booqable Rental allows Cross Site Request Forgery. This issue affects Booqable Rental: from n/a through 2.4.20.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30956" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/booqable-rental-reservations/vulnerability/wordpress-booqable-rental-2-4-20-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-qpx8-vpfc-6qq4/GHSA-qpx8-vpfc-6qq4.json b/advisories/unreviewed/2025/06/GHSA-qpx8-vpfc-6qq4/GHSA-qpx8-vpfc-6qq4.json new file mode 100644 index 00000000000..6f1161cb966 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-qpx8-vpfc-6qq4/GHSA-qpx8-vpfc-6qq4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpx8-vpfc-6qq4", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49306" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchsquare WP Social Widget allows Stored XSS. This issue affects WP Social Widget: from n/a through 2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49306" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-social-widget/vulnerability/wordpress-wp-social-widget-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-r263-rp96-99fp/GHSA-r263-rp96-99fp.json b/advisories/unreviewed/2025/06/GHSA-r263-rp96-99fp/GHSA-r263-rp96-99fp.json new file mode 100644 index 00000000000..bcabbb98f02 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-r263-rp96-99fp/GHSA-r263-rp96-99fp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r263-rp96-99fp", + "modified": "2025-06-06T15:30:45Z", + "published": "2025-06-06T15:30:45Z", + "aliases": [ + "CVE-2025-26593" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in FasterThemes FastBook allows Cross Site Request Forgery. This issue affects FastBook: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26593" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fastbook-responsive-appointment-booking-and-scheduling-system/vulnerability/wordpress-fastbook-1-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-r424-5crh-rhc3/GHSA-r424-5crh-rhc3.json b/advisories/unreviewed/2025/06/GHSA-r424-5crh-rhc3/GHSA-r424-5crh-rhc3.json new file mode 100644 index 00000000000..833e5162e30 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-r424-5crh-rhc3/GHSA-r424-5crh-rhc3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r424-5crh-rhc3", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-49244" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vova Shortcodes Ultimate allows Stored XSS. This issue affects Shortcodes Ultimate: from n/a through 7.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49244" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/shortcodes-ultimate/vulnerability/wordpress-shortcodes-ultimate-7-3-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-r5vf-jv8j-63xv/GHSA-r5vf-jv8j-63xv.json b/advisories/unreviewed/2025/06/GHSA-r5vf-jv8j-63xv/GHSA-r5vf-jv8j-63xv.json new file mode 100644 index 00000000000..4931b0a117b --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-r5vf-jv8j-63xv/GHSA-r5vf-jv8j-63xv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5vf-jv8j-63xv", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30945" + ], + "details": "Missing Authorization vulnerability in taskbuilder Taskbuilder allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Taskbuilder: from n/a through 4.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30945" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/taskbuilder/vulnerability/wordpress-taskbuilder-4-0-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-r85g-xxp8-j43r/GHSA-r85g-xxp8-j43r.json b/advisories/unreviewed/2025/06/GHSA-r85g-xxp8-j43r/GHSA-r85g-xxp8-j43r.json new file mode 100644 index 00000000000..43bbb0df4e1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-r85g-xxp8-j43r/GHSA-r85g-xxp8-j43r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r85g-xxp8-j43r", + "modified": "2025-06-06T15:30:52Z", + "published": "2025-06-06T15:30:52Z", + "aliases": [ + "CVE-2025-49429" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Burnette Video Embeds allows Stored XSS. This issue affects Video Embeds: from n/a through 0.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49429" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/video-embeds/vulnerability/wordpress-video-embeds-0-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rh23-w5x7-xjm4/GHSA-rh23-w5x7-xjm4.json b/advisories/unreviewed/2025/06/GHSA-rh23-w5x7-xjm4/GHSA-rh23-w5x7-xjm4.json new file mode 100644 index 00000000000..4712824511e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rh23-w5x7-xjm4/GHSA-rh23-w5x7-xjm4.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh23-w5x7-xjm4", + "modified": "2025-06-06T15:30:53Z", + "published": "2025-06-06T15:30:53Z", + "aliases": [ + "CVE-2025-38001" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: hfsc: Address reentrant enqueue adding class to eltree twice\n\nSavino says:\n \"We are writing to report that this recent patch\n (141d34391abbb315d68556b7c67ad97885407547) [1]\n can be bypassed, and a UAF can still occur when HFSC is utilized with\n NETEM.\n\n The patch only checks the cl->cl_nactive field to determine whether\n it is the first insertion or not [2], but this field is only\n incremented by init_vf [3].\n\n By using HFSC_RSC (which uses init_ed) [4], it is possible to bypass the\n check and insert the class twice in the eltree.\n Under normal conditions, this would lead to an infinite loop in\n hfsc_dequeue for the reasons we already explained in this report [5].\n\n However, if TBF is added as root qdisc and it is configured with a\n very low rate,\n it can be utilized to prevent packets from being dequeued.\n This behavior can be exploited to perform subsequent insertions in the\n HFSC eltree and cause a UAF.\"\n\nTo fix both the UAF and the infinite loop, with netem as an hfsc child,\ncheck explicitly in hfsc_enqueue whether the class is already in the eltree\nwhenever the HFSC_RSC flag is set.\n\n[1] https://web.git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=141d34391abbb315d68556b7c67ad97885407547\n[2] https://elixir.bootlin.com/linux/v6.15-rc5/source/net/sched/sch_hfsc.c#L1572\n[3] https://elixir.bootlin.com/linux/v6.15-rc5/source/net/sched/sch_hfsc.c#L677\n[4] https://elixir.bootlin.com/linux/v6.15-rc5/source/net/sched/sch_hfsc.c#L1574\n[5] https://lore.kernel.org/netdev/8DuRWwfqjoRDLDmBMlIfbrsZg9Gx50DHJc1ilxsEBNe2D6NMoigR_eIRIG0LOjMc3r10nUUZtArXx4oZBIdUfZQrwjcQhdinnMis_0G7VEk=@willsroot.io/T/#u", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-38001" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/295f7c579b07b5b7cf2dffe485f71cc2f27647cb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2c928b3a0b04a431ffcd6c8b7d88a267124a3a28" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2f2190ce4ca972051cac6a8d7937448f8cb9673c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/39ed887b1dd2d6b720f87e86692ac3006cc111c8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e38eaaabfb7fffbb371a51150203e19eee5d70e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6672e6c00810056acaac019fe26cdc26fee8a66c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a0ec22fa20b252edbe070a9de8501eef63c17ef5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e5bee633cc276410337d54b99f77fbc1ad8801e5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rp75-8437-wxr3/GHSA-rp75-8437-wxr3.json b/advisories/unreviewed/2025/06/GHSA-rp75-8437-wxr3/GHSA-rp75-8437-wxr3.json new file mode 100644 index 00000000000..90762589950 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rp75-8437-wxr3/GHSA-rp75-8437-wxr3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rp75-8437-wxr3", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-30627" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in regolithsjk Elegant Visitor Counter allows Stored XSS. This issue affects Elegant Visitor Counter: from n/a through 3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30627" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/elegant-visitor-counter/vulnerability/wordpress-elegant-visitor-counter-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rpm2-9qcj-mmxg/GHSA-rpm2-9qcj-mmxg.json b/advisories/unreviewed/2025/06/GHSA-rpm2-9qcj-mmxg/GHSA-rpm2-9qcj-mmxg.json new file mode 100644 index 00000000000..f5bb14a6271 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rpm2-9qcj-mmxg/GHSA-rpm2-9qcj-mmxg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpm2-9qcj-mmxg", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-49073" + ], + "details": "Deserialization of Untrusted Data vulnerability in Axiomthemes Sweet Dessert allows Object Injection.This issue affects Sweet Dessert: from n/a before 1.1.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49073" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/sweet-dessert/vulnerability/wordpress-sweet-dessert-1-1-13-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rr7f-98cj-4548/GHSA-rr7f-98cj-4548.json b/advisories/unreviewed/2025/06/GHSA-rr7f-98cj-4548/GHSA-rr7f-98cj-4548.json new file mode 100644 index 00000000000..158f2ef0211 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rr7f-98cj-4548/GHSA-rr7f-98cj-4548.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rr7f-98cj-4548", + "modified": "2025-06-06T15:30:51Z", + "published": "2025-06-06T15:30:51Z", + "aliases": [ + "CVE-2025-49324" + ], + "details": "Missing Authorization vulnerability in PickPlugins Job Board Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Job Board Manager: from n/a through 2.1.60.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49324" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/job-board-manager/vulnerability/wordpress-job-board-manager-2-1-60-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rvgc-93hr-656r/GHSA-rvgc-93hr-656r.json b/advisories/unreviewed/2025/06/GHSA-rvgc-93hr-656r/GHSA-rvgc-93hr-656r.json new file mode 100644 index 00000000000..78c750d4550 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rvgc-93hr-656r/GHSA-rvgc-93hr-656r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvgc-93hr-656r", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-28966" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in dilemma123 Recent Posts Slider Responsive allows Stored XSS. This issue affects Recent Posts Slider Responsive: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28966" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/recent-posts-slider-responsive/vulnerability/wordpress-recent-posts-slider-responsive-plugin-1-0-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rwqr-q4vq-f32c/GHSA-rwqr-q4vq-f32c.json b/advisories/unreviewed/2025/06/GHSA-rwqr-q4vq-f32c/GHSA-rwqr-q4vq-f32c.json new file mode 100644 index 00000000000..931d869bb0c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rwqr-q4vq-f32c/GHSA-rwqr-q4vq-f32c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwqr-q4vq-f32c", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-28984" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in storepro Subscription Renewal Reminders for WooCommerce allows Cross Site Request Forgery. This issue affects Subscription Renewal Reminders for WooCommerce: from n/a through 1.3.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28984" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/subscriptions-renewal-reminders/vulnerability/wordpress-subscription-renewal-reminders-for-woocommerce-plugin-1-3-7-cross-site-request-forgery-to-notice-dismissal-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-v2f7-4fhr-863x/GHSA-v2f7-4fhr-863x.json b/advisories/unreviewed/2025/06/GHSA-v2f7-4fhr-863x/GHSA-v2f7-4fhr-863x.json new file mode 100644 index 00000000000..43832891c02 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-v2f7-4fhr-863x/GHSA-v2f7-4fhr-863x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2f7-4fhr-863x", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49288" + ], + "details": "Missing Authorization vulnerability in Rustaurius Ultimate WP Mail allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate WP Mail: from n/a through 1.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49288" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-wp-mail/vulnerability/wordpress-ultimate-wp-mail-1-3-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-v2rm-fxfj-qw78/GHSA-v2rm-fxfj-qw78.json b/advisories/unreviewed/2025/06/GHSA-v2rm-fxfj-qw78/GHSA-v2rm-fxfj-qw78.json new file mode 100644 index 00000000000..2c23a69a754 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-v2rm-fxfj-qw78/GHSA-v2rm-fxfj-qw78.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2rm-fxfj-qw78", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-28985" + ], + "details": "Missing Authorization vulnerability in Elastic Email Elastic Email Subscribe Form allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Elastic Email Subscribe Form: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28985" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/elastic-email-subscribe-form/vulnerability/wordpress-elastic-email-subscribe-form-1-2-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-v36v-345v-jgx9/GHSA-v36v-345v-jgx9.json b/advisories/unreviewed/2025/06/GHSA-v36v-345v-jgx9/GHSA-v36v-345v-jgx9.json new file mode 100644 index 00000000000..9b3e167cf57 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-v36v-345v-jgx9/GHSA-v36v-345v-jgx9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v36v-345v-jgx9", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-29003" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mva7 The Holiday Calendar allows Stored XSS. This issue affects The Holiday Calendar: from n/a through 1.18.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29003" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/the-holiday-calendar/vulnerability/wordpress-the-holiday-calendar-1-18-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-v486-r9jc-fp92/GHSA-v486-r9jc-fp92.json b/advisories/unreviewed/2025/06/GHSA-v486-r9jc-fp92/GHSA-v486-r9jc-fp92.json new file mode 100644 index 00000000000..18e66f6fac5 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-v486-r9jc-fp92/GHSA-v486-r9jc-fp92.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v486-r9jc-fp92", + "modified": "2025-06-06T15:30:45Z", + "published": "2025-06-06T15:30:45Z", + "aliases": [ + "CVE-2023-25995" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in choicehomemortgage AI Mortgage Calculator allows PHP Local File Inclusion. This issue affects AI Mortgage Calculator: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25995" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ai-mortgage-calculator/vulnerability/wordpress-ai-mortgage-calculator-1-0-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-v887-v4v9-fw53/GHSA-v887-v4v9-fw53.json b/advisories/unreviewed/2025/06/GHSA-v887-v4v9-fw53/GHSA-v887-v4v9-fw53.json new file mode 100644 index 00000000000..8c38dfe25dc --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-v887-v4v9-fw53/GHSA-v887-v4v9-fw53.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v887-v4v9-fw53", + "modified": "2025-06-06T15:30:46Z", + "published": "2025-06-06T15:30:46Z", + "aliases": [ + "CVE-2025-29006" + ], + "details": "Missing Authorization vulnerability in centangle Direct Checkout for WooCommerce Lite allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Direct Checkout for WooCommerce Lite: from n/a through 1.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29006" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-direct-checkout-lite/vulnerability/wordpress-direct-checkout-for-woocommerce-lite-1-0-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-vgjw-hj6p-g7jm/GHSA-vgjw-hj6p-g7jm.json b/advisories/unreviewed/2025/06/GHSA-vgjw-hj6p-g7jm/GHSA-vgjw-hj6p-g7jm.json new file mode 100644 index 00000000000..51c2d6667ba --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-vgjw-hj6p-g7jm/GHSA-vgjw-hj6p-g7jm.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgjw-hj6p-g7jm", + "modified": "2025-06-06T15:30:53Z", + "published": "2025-06-06T15:30:53Z", + "aliases": [ + "CVE-2025-5766" + ], + "details": "A vulnerability was found in code-projects Laundry System 1.0. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5766" + }, + { + "type": "WEB", + "url": "https://github.com/tuooo/CVE/issues/7" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311308" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311308" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.590851" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-vr7m-g7mw-78wm/GHSA-vr7m-g7mw-78wm.json b/advisories/unreviewed/2025/06/GHSA-vr7m-g7mw-78wm/GHSA-vr7m-g7mw-78wm.json new file mode 100644 index 00000000000..4973cecacfb --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-vr7m-g7mw-78wm/GHSA-vr7m-g7mw-78wm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr7m-g7mw-78wm", + "modified": "2025-06-06T15:30:47Z", + "published": "2025-06-06T15:30:47Z", + "aliases": [ + "CVE-2025-30938" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in broadly Broadly for WordPress allows Stored XSS. This issue affects Broadly for WordPress: from n/a through 3.0.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30938" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/broadly/vulnerability/wordpress-broadly-for-wordpress-3-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-vrgq-8x87-23c7/GHSA-vrgq-8x87-23c7.json b/advisories/unreviewed/2025/06/GHSA-vrgq-8x87-23c7/GHSA-vrgq-8x87-23c7.json new file mode 100644 index 00000000000..5a03c67cab2 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-vrgq-8x87-23c7/GHSA-vrgq-8x87-23c7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrgq-8x87-23c7", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30990" + ], + "details": "Missing Authorization vulnerability in ThemeHunk ThemeHunk allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ThemeHunk: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30990" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/themehunk-megamenu-plus/vulnerability/wordpress-themehunk-1-1-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-w2w6-xw4v-xw9x/GHSA-w2w6-xw4v-xw9x.json b/advisories/unreviewed/2025/06/GHSA-w2w6-xw4v-xw9x/GHSA-w2w6-xw4v-xw9x.json new file mode 100644 index 00000000000..2726407367b --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-w2w6-xw4v-xw9x/GHSA-w2w6-xw4v-xw9x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2w6-xw4v-xw9x", + "modified": "2025-06-06T15:30:49Z", + "published": "2025-06-06T15:30:49Z", + "aliases": [ + "CVE-2025-49072" + ], + "details": "Deserialization of Untrusted Data vulnerability in AncoraThemes Mr. Murphy allows Object Injection.This issue affects Mr. Murphy: from n/a before 1.2.12.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49072" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/mr-murphy/vulnerability/wordpress-mr-murphy-1-2-12-1-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-w453-h34p-m23g/GHSA-w453-h34p-m23g.json b/advisories/unreviewed/2025/06/GHSA-w453-h34p-m23g/GHSA-w453-h34p-m23g.json new file mode 100644 index 00000000000..354502bfe63 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-w453-h34p-m23g/GHSA-w453-h34p-m23g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w453-h34p-m23g", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49293" + ], + "details": "Missing Authorization vulnerability in CodeRevolution Crawlomatic Multisite Scraper Post Generator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Crawlomatic Multisite Scraper Post Generator: from n/a through 2.6.8.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49293" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/crawlomatic-multipage-scraper-post-generator/vulnerability/wordpress-crawlomatic-multisite-scraper-post-generator-2-6-8-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-w7qj-8x38-58m7/GHSA-w7qj-8x38-58m7.json b/advisories/unreviewed/2025/06/GHSA-w7qj-8x38-58m7/GHSA-w7qj-8x38-58m7.json new file mode 100644 index 00000000000..eacadd0598d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-w7qj-8x38-58m7/GHSA-w7qj-8x38-58m7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7qj-8x38-58m7", + "modified": "2025-06-06T15:30:52Z", + "published": "2025-06-06T15:30:52Z", + "aliases": [ + "CVE-2025-49326" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia GamiPress allows SQL Injection. This issue affects GamiPress: from n/a through 7.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49326" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gamipress/vulnerability/wordpress-gamipress-7-4-5-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-w8x8-758c-78v5/GHSA-w8x8-758c-78v5.json b/advisories/unreviewed/2025/06/GHSA-w8x8-758c-78v5/GHSA-w8x8-758c-78v5.json new file mode 100644 index 00000000000..1e5527d699f --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-w8x8-758c-78v5/GHSA-w8x8-758c-78v5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8x8-758c-78v5", + "modified": "2025-06-06T15:30:52Z", + "published": "2025-06-06T15:30:52Z", + "aliases": [ + "CVE-2025-49443" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris McCoy Bacon Ipsum allows Stored XSS. This issue affects Bacon Ipsum: from n/a through 2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49443" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bacon-ipsum/vulnerability/wordpress-bacon-ipsum-2-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-wpc4-cvh9-79p3/GHSA-wpc4-cvh9-79p3.json b/advisories/unreviewed/2025/06/GHSA-wpc4-cvh9-79p3/GHSA-wpc4-cvh9-79p3.json new file mode 100644 index 00000000000..385bc515a30 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-wpc4-cvh9-79p3/GHSA-wpc4-cvh9-79p3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpc4-cvh9-79p3", + "modified": "2025-06-06T15:30:51Z", + "published": "2025-06-06T15:30:51Z", + "aliases": [ + "CVE-2025-49325" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Automattic Newspack Newsletters allows Phishing. This issue affects Newspack Newsletters: from n/a through 3.13.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49325" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/newspack-newsletters/vulnerability/wordpress-newspack-newsletters-3-13-0-open-redirection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-wqvf-m5cv-vfhr/GHSA-wqvf-m5cv-vfhr.json b/advisories/unreviewed/2025/06/GHSA-wqvf-m5cv-vfhr/GHSA-wqvf-m5cv-vfhr.json new file mode 100644 index 00000000000..32caeeb95ff --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-wqvf-m5cv-vfhr/GHSA-wqvf-m5cv-vfhr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqvf-m5cv-vfhr", + "modified": "2025-06-06T15:30:48Z", + "published": "2025-06-06T15:30:48Z", + "aliases": [ + "CVE-2025-30968" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in jokerbr313 Advanced Post List allows Cross Site Request Forgery. This issue affects Advanced Post List: from n/a through 0.5.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30968" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/advanced-post-list/vulnerability/wordpress-advanced-post-list-0-5-6-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-x267-5qgc-g5mj/GHSA-x267-5qgc-g5mj.json b/advisories/unreviewed/2025/06/GHSA-x267-5qgc-g5mj/GHSA-x267-5qgc-g5mj.json new file mode 100644 index 00000000000..e1e43980d16 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-x267-5qgc-g5mj/GHSA-x267-5qgc-g5mj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x267-5qgc-g5mj", + "modified": "2025-06-06T15:30:45Z", + "published": "2025-06-06T15:30:45Z", + "aliases": [ + "CVE-2023-26002" + ], + "details": "Missing Authorization vulnerability in 6Storage 6Storage Rentals allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects 6Storage Rentals: from n/a through 2.19.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26002" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/6storage-rentals/vulnerability/wordpress-6storage-rentals-2-19-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-x92c-3vm7-wq3m/GHSA-x92c-3vm7-wq3m.json b/advisories/unreviewed/2025/06/GHSA-x92c-3vm7-wq3m/GHSA-x92c-3vm7-wq3m.json new file mode 100644 index 00000000000..464201464de --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-x92c-3vm7-wq3m/GHSA-x92c-3vm7-wq3m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x92c-3vm7-wq3m", + "modified": "2025-06-06T15:30:50Z", + "published": "2025-06-06T15:30:50Z", + "aliases": [ + "CVE-2025-49283" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Matthias Nordwig Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant allows Cross Site Request Forgery. This issue affects Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant: from n/a through 4.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49283" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gdpr-compliant-recaptcha-for-all-forms/vulnerability/wordpress-anti-spam-spam-protection-recaptcha-for-all-forms-and-gdpr-compliant-4-1-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-xcxx-7vqc-qj5x/GHSA-xcxx-7vqc-qj5x.json b/advisories/unreviewed/2025/06/GHSA-xcxx-7vqc-qj5x/GHSA-xcxx-7vqc-qj5x.json new file mode 100644 index 00000000000..e357cab2325 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-xcxx-7vqc-qj5x/GHSA-xcxx-7vqc-qj5x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcxx-7vqc-qj5x", + "modified": "2025-06-06T15:30:45Z", + "published": "2025-06-06T15:30:45Z", + "aliases": [ + "CVE-2025-24763" + ], + "details": "Missing Authorization vulnerability in Pascal Casier bbPress API allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects bbPress API: from n/a through 1.0.14.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24763" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bbp-api/vulnerability/wordpress-bbpress-api-1-0-14-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-xh2w-2259-wcg6/GHSA-xh2w-2259-wcg6.json b/advisories/unreviewed/2025/06/GHSA-xh2w-2259-wcg6/GHSA-xh2w-2259-wcg6.json new file mode 100644 index 00000000000..21f5276ba31 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-xh2w-2259-wcg6/GHSA-xh2w-2259-wcg6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh2w-2259-wcg6", + "modified": "2025-06-06T15:30:51Z", + "published": "2025-06-06T15:30:51Z", + "aliases": [ + "CVE-2025-49322" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeedProd 404 Page by SeedProd allows Stored XSS. This issue affects 404 Page by SeedProd: from n/a through n/a.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49322" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/404-page/vulnerability/wordpress-404-page-by-seedprod-1-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-xm3q-vf5j-mg52/GHSA-xm3q-vf5j-mg52.json b/advisories/unreviewed/2025/06/GHSA-xm3q-vf5j-mg52/GHSA-xm3q-vf5j-mg52.json new file mode 100644 index 00000000000..720bafb2b22 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-xm3q-vf5j-mg52/GHSA-xm3q-vf5j-mg52.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xm3q-vf5j-mg52", + "modified": "2025-06-06T15:30:53Z", + "published": "2025-06-06T15:30:53Z", + "aliases": [ + "CVE-2025-5780" + ], + "details": "A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /view_dental.php. The manipulation of the argument itr_no leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5780" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/Thiasap/HCPMS_PHP_vulns/blob/main/sql%20injection%20in%20view_dental.php.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311324" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311324" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.591128" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-xm9g-m236-mvcw/GHSA-xm9g-m236-mvcw.json b/advisories/unreviewed/2025/06/GHSA-xm9g-m236-mvcw/GHSA-xm9g-m236-mvcw.json new file mode 100644 index 00000000000..0af3df487f2 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-xm9g-m236-mvcw/GHSA-xm9g-m236-mvcw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xm9g-m236-mvcw", + "modified": "2025-06-06T15:30:51Z", + "published": "2025-06-06T15:30:51Z", + "aliases": [ + "CVE-2025-49320" + ], + "details": "Missing Authorization vulnerability in fraudlabspro FraudLabs Pro for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FraudLabs Pro for WooCommerce: from n/a through 2.22.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49320" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fraudlabs-pro-for-woocommerce/vulnerability/wordpress-fraudlabs-pro-for-woocommerce-2-22-11-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-xvfh-9hmq-g2vh/GHSA-xvfh-9hmq-g2vh.json b/advisories/unreviewed/2025/06/GHSA-xvfh-9hmq-g2vh/GHSA-xvfh-9hmq-g2vh.json new file mode 100644 index 00000000000..e24c96da3ad --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-xvfh-9hmq-g2vh/GHSA-xvfh-9hmq-g2vh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvfh-9hmq-g2vh", + "modified": "2025-06-06T15:30:45Z", + "published": "2025-06-06T15:30:45Z", + "aliases": [ + "CVE-2025-24778" + ], + "details": "Missing Authorization vulnerability in De paragon No Spam At All allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects No Spam At All: from n/a through 1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24778" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/no-spam-at-all/vulnerability/wordpress-no-spam-at-all-1-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-06T13:15:26Z" + } +} \ No newline at end of file