diff --git a/advisories/unreviewed/2024/12/GHSA-2hhg-24wg-6mmv/GHSA-2hhg-24wg-6mmv.json b/advisories/unreviewed/2024/12/GHSA-2hhg-24wg-6mmv/GHSA-2hhg-24wg-6mmv.json new file mode 100644 index 00000000000..6b48405ee41 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2hhg-24wg-6mmv/GHSA-2hhg-24wg-6mmv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hhg-24wg-6mmv", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56225" + ], + "details": "Missing Authorization vulnerability in Leap13 Premium Addons for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Premium Addons for Elementor: from n/a through 4.10.56.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56225" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/premium-addons-for-elementor/vulnerability/wordpress-premium-addons-for-elementor-plugin-4-10-56-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2v2m-h8mc-wjvq/GHSA-2v2m-h8mc-wjvq.json b/advisories/unreviewed/2024/12/GHSA-2v2m-h8mc-wjvq/GHSA-2v2m-h8mc-wjvq.json new file mode 100644 index 00000000000..07aeba867d1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2v2m-h8mc-wjvq/GHSA-2v2m-h8mc-wjvq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v2m-h8mc-wjvq", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56220" + ], + "details": "Incorrect Privilege Assignment vulnerability in SSL Wireless SSL Wireless SMS Notification allows Privilege Escalation.This issue affects SSL Wireless SMS Notification: from n/a through 3.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56220" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ssl-wireless-sms-notification/vulnerability/wordpress-ssl-wireless-sms-notification-plugin-3-5-0-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2vmj-9h29-92pm/GHSA-2vmj-9h29-92pm.json b/advisories/unreviewed/2024/12/GHSA-2vmj-9h29-92pm/GHSA-2vmj-9h29-92pm.json new file mode 100644 index 00000000000..7f171fe2e8c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2vmj-9h29-92pm/GHSA-2vmj-9h29-92pm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2vmj-9h29-92pm", + "modified": "2024-12-31T12:30:45Z", + "published": "2024-12-31T12:30:45Z", + "aliases": [ + "CVE-2024-13061" + ], + "details": "The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated remote attackers can still deceive the server to obtain tokens of arbitrary users, which can then be used to log into the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13061" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-8340-d8b16-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-8339-570fa-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T12:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4j9j-7fmg-vxjm/GHSA-4j9j-7fmg-vxjm.json b/advisories/unreviewed/2024/12/GHSA-4j9j-7fmg-vxjm/GHSA-4j9j-7fmg-vxjm.json new file mode 100644 index 00000000000..db113be52c9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4j9j-7fmg-vxjm/GHSA-4j9j-7fmg-vxjm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4j9j-7fmg-vxjm", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56224" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ledenbeheer allows Stored XSS.This issue affects Ledenbeheer: from n/a through 2.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56224" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ledenbeheer-external-connection/vulnerability/wordpress-ledenbeheer-plugin-2-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-53wc-433f-29g7/GHSA-53wc-433f-29g7.json b/advisories/unreviewed/2024/12/GHSA-53wc-433f-29g7/GHSA-53wc-433f-29g7.json new file mode 100644 index 00000000000..bd04e48ff77 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-53wc-433f-29g7/GHSA-53wc-433f-29g7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53wc-433f-29g7", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56223" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood Gulri Slider allows Reflected XSS.This issue affects Gulri Slider: from n/a through 3.5.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56223" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gulri-slider/vulnerability/wordpress-gulri-slider-plugin-3-5-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5c87-492r-w9m4/GHSA-5c87-492r-w9m4.json b/advisories/unreviewed/2024/12/GHSA-5c87-492r-w9m4/GHSA-5c87-492r-w9m4.json new file mode 100644 index 00000000000..fad2a79cbcb --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5c87-492r-w9m4/GHSA-5c87-492r-w9m4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c87-492r-w9m4", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-12108" + ], + "details": "In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12108" + }, + { + "type": "WEB", + "url": "https://www.progress.com/network-monitoring" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5gfp-4j74-xjmq/GHSA-5gfp-4j74-xjmq.json b/advisories/unreviewed/2024/12/GHSA-5gfp-4j74-xjmq/GHSA-5gfp-4j74-xjmq.json new file mode 100644 index 00000000000..4b53edc9494 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5gfp-4j74-xjmq/GHSA-5gfp-4j74-xjmq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gfp-4j74-xjmq", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56230" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dynamic Web Lab Dynamic Product Category Grid, Slider for WooCommerce allows PHP Local File Inclusion.This issue affects Dynamic Product Category Grid, Slider for WooCommerce: from n/a through 1.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56230" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dynamic-product-categories-design/vulnerability/wordpress-dynamic-product-category-grid-slider-for-woocommerce-plugin-1-1-3-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5jph-hg2x-m54g/GHSA-5jph-hg2x-m54g.json b/advisories/unreviewed/2024/12/GHSA-5jph-hg2x-m54g/GHSA-5jph-hg2x-m54g.json new file mode 100644 index 00000000000..0f5af27d724 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5jph-hg2x-m54g/GHSA-5jph-hg2x-m54g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jph-hg2x-m54g", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56232" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Alexander Volkov WP Nice Loader allows Stored XSS.This issue affects WP Nice Loader: from n/a through 0.1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56232" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-nice-loader/vulnerability/wordpress-wp-nice-loader-plugin-0-1-0-4-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-68j8-wgc6-45qw/GHSA-68j8-wgc6-45qw.json b/advisories/unreviewed/2024/12/GHSA-68j8-wgc6-45qw/GHSA-68j8-wgc6-45qw.json new file mode 100644 index 00000000000..c8010dd059b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-68j8-wgc6-45qw/GHSA-68j8-wgc6-45qw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68j8-wgc6-45qw", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56227" + ], + "details": "Missing Authorization vulnerability in WP Royal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Royal Elementor Addons: from n/a through 1.7.1001.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56227" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/royal-elementor-addons/vulnerability/wordpress-royal-elementor-addons-plugin-1-7-1001-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-72wf-rghh-33px/GHSA-72wf-rghh-33px.json b/advisories/unreviewed/2024/12/GHSA-72wf-rghh-33px/GHSA-72wf-rghh-33px.json new file mode 100644 index 00000000000..b098a1b2655 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-72wf-rghh-33px/GHSA-72wf-rghh-33px.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72wf-rghh-33px", + "modified": "2024-12-31T12:30:45Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56235" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Coupon Plugin Coupon allows DOM-Based XSS.This issue affects Coupon: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56235" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/coupon-lite/vulnerability/wordpress-coupon-plugin-1-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-76cg-c4pp-x5qq/GHSA-76cg-c4pp-x5qq.json b/advisories/unreviewed/2024/12/GHSA-76cg-c4pp-x5qq/GHSA-76cg-c4pp-x5qq.json new file mode 100644 index 00000000000..f77bc18b4df --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-76cg-c4pp-x5qq/GHSA-76cg-c4pp-x5qq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76cg-c4pp-x5qq", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56221" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elicus WPMozo Addons Lite for Elementor allows Stored XSS.This issue affects WPMozo Addons Lite for Elementor: from n/a through 1.2.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56221" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpmozo-addons-lite-for-elementor/vulnerability/wordpress-wpmozo-addons-lite-for-elementor-plugin-1-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8hmw-7m42-f6p5/GHSA-8hmw-7m42-f6p5.json b/advisories/unreviewed/2024/12/GHSA-8hmw-7m42-f6p5/GHSA-8hmw-7m42-f6p5.json new file mode 100644 index 00000000000..f29aa31f174 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8hmw-7m42-f6p5/GHSA-8hmw-7m42-f6p5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hmw-7m42-f6p5", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56209" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeventhQueen Kleo allows Reflected XSS.This issue affects Kleo: from n/a before 5.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56209" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/kleo/vulnerability/wordpress-kleo-theme-5-4-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8r69-9xff-443j/GHSA-8r69-9xff-443j.json b/advisories/unreviewed/2024/12/GHSA-8r69-9xff-443j/GHSA-8r69-9xff-443j.json new file mode 100644 index 00000000000..3395d3ac3c8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8r69-9xff-443j/GHSA-8r69-9xff-443j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r69-9xff-443j", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56214" + ], + "details": "Path Traversal: '.../...//' vulnerability in DeluxeThemes Userpro allows Path Traversal.This issue affects Userpro: from n/a through 5.1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56214" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/userpro/vulnerability/wordpress-userpro-plugin-5-1-9-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9h55-3q8w-9x37/GHSA-9h55-3q8w-9x37.json b/advisories/unreviewed/2024/12/GHSA-9h55-3q8w-9x37/GHSA-9h55-3q8w-9x37.json new file mode 100644 index 00000000000..ffce218dfed --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9h55-3q8w-9x37/GHSA-9h55-3q8w-9x37.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h55-3q8w-9x37", + "modified": "2024-12-31T12:30:45Z", + "published": "2024-12-31T12:30:45Z", + "aliases": [ + "CVE-2024-56265" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPWeb WooCommerce PDF Vouchers allows Reflected XSS.This issue affects WooCommerce PDF Vouchers: from n/a before 4.9.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56265" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-pdf-vouchers/vulnerability/wordpress-woocommerce-pdf-vouchers-plugin-4-9-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9r3x-236x-5gv8/GHSA-9r3x-236x-5gv8.json b/advisories/unreviewed/2024/12/GHSA-9r3x-236x-5gv8/GHSA-9r3x-236x-5gv8.json new file mode 100644 index 00000000000..1802d671f4a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9r3x-236x-5gv8/GHSA-9r3x-236x-5gv8.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r3x-236x-5gv8", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-13069" + ], + "details": "A vulnerability was found in SourceCodester Multi Role Login System 1.0. It has been classified as problematic. Affected is an unknown function of the file /endpoint/add-user.php. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13069" + }, + { + "type": "WEB", + "url": "https://github.com/shaturo1337/POCs/blob/main/Stored%20XSS%20Vulnerability%20in%20Multi%20Role%20Login%20System.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289824" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289824" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.469520" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-g4x4-cxv7-86m6/GHSA-g4x4-cxv7-86m6.json b/advisories/unreviewed/2024/12/GHSA-g4x4-cxv7-86m6/GHSA-g4x4-cxv7-86m6.json new file mode 100644 index 00000000000..dcb8a130d09 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-g4x4-cxv7-86m6/GHSA-g4x4-cxv7-86m6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4x4-cxv7-86m6", + "modified": "2024-12-31T12:30:45Z", + "published": "2024-12-31T12:30:45Z", + "aliases": [ + "CVE-2024-56256" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andy Fragen Embed PDF Viewer allows Stored XSS.This issue affects Embed PDF Viewer: from n/a through 2.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56256" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/embed-pdf-viewer/vulnerability/wordpress-embed-pdf-viewer-plugin-2-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gjrg-88x4-jg2g/GHSA-gjrg-88x4-jg2g.json b/advisories/unreviewed/2024/12/GHSA-gjrg-88x4-jg2g/GHSA-gjrg-88x4-jg2g.json new file mode 100644 index 00000000000..f5803ec7298 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gjrg-88x4-jg2g/GHSA-gjrg-88x4-jg2g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjrg-88x4-jg2g", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56211" + ], + "details": "Missing Authorization vulnerability in DeluxeThemes Userpro.This issue affects Userpro: from n/a through 5.1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56211" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/userpro/vulnerability/wordpress-userpro-plugin-5-1-9-authenticated-arbitrary-user-meta-update-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h99j-qmgw-6ggg/GHSA-h99j-qmgw-6ggg.json b/advisories/unreviewed/2024/12/GHSA-h99j-qmgw-6ggg/GHSA-h99j-qmgw-6ggg.json new file mode 100644 index 00000000000..2bc7510e193 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h99j-qmgw-6ggg/GHSA-h99j-qmgw-6ggg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h99j-qmgw-6ggg", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-12106" + ], + "details": "In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12106" + }, + { + "type": "WEB", + "url": "https://www.progress.com/network-monitoring" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j5v2-fwv6-5gpw/GHSA-j5v2-fwv6-5gpw.json b/advisories/unreviewed/2024/12/GHSA-j5v2-fwv6-5gpw/GHSA-j5v2-fwv6-5gpw.json new file mode 100644 index 00000000000..92efd29157a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j5v2-fwv6-5gpw/GHSA-j5v2-fwv6-5gpw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5v2-fwv6-5gpw", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56233" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kinhelios Kintpv Wooconnect allows Stored XSS.This issue affects Kintpv Wooconnect: from n/a through 8.129.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56233" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/kintpv-connect/vulnerability/wordpress-kintpv-wooconnect-plugin-8-129-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m872-cr23-mrr9/GHSA-m872-cr23-mrr9.json b/advisories/unreviewed/2024/12/GHSA-m872-cr23-mrr9/GHSA-m872-cr23-mrr9.json new file mode 100644 index 00000000000..f9cc7f847b9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m872-cr23-mrr9/GHSA-m872-cr23-mrr9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m872-cr23-mrr9", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56216" + ], + "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themify Themify Builder allows PHP Local File Inclusion.This issue affects Themify Builder: from n/a through 7.6.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56216" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/themify-builder/vulnerability/wordpress-themify-builder-plugin-7-6-3-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-mf7c-82jr-gfh2/GHSA-mf7c-82jr-gfh2.json b/advisories/unreviewed/2024/12/GHSA-mf7c-82jr-gfh2/GHSA-mf7c-82jr-gfh2.json new file mode 100644 index 00000000000..01f6f27bffc --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-mf7c-82jr-gfh2/GHSA-mf7c-82jr-gfh2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf7c-82jr-gfh2", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56213" + ], + "details": "Path Traversal: '.../...//' vulnerability in Themewinter Eventin allows Path Traversal.This issue affects Eventin: from n/a through 4.0.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56213" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-event-solution/vulnerability/wordpress-eventin-plugin-4-0-7-contributor-limited-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-p9cp-6ffg-fqqc/GHSA-p9cp-6ffg-fqqc.json b/advisories/unreviewed/2024/12/GHSA-p9cp-6ffg-fqqc/GHSA-p9cp-6ffg-fqqc.json new file mode 100644 index 00000000000..dfba93bb0c5 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-p9cp-6ffg-fqqc/GHSA-p9cp-6ffg-fqqc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9cp-6ffg-fqqc", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56234" + ], + "details": "Missing Authorization vulnerability in VW THEMES VW Automobile Lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Automobile Lite: from n/a through 2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56234" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/vw-automobile-lite/vulnerability/wordpress-vw-automobile-lite-theme-2-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pfpg-w2wm-jprg/GHSA-pfpg-w2wm-jprg.json b/advisories/unreviewed/2024/12/GHSA-pfpg-w2wm-jprg/GHSA-pfpg-w2wm-jprg.json new file mode 100644 index 00000000000..12f311e710d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pfpg-w2wm-jprg/GHSA-pfpg-w2wm-jprg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfpg-w2wm-jprg", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56222" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Codebard CodeBard Help Desk allows Cross Site Request Forgery.This issue affects CodeBard Help Desk: from n/a through 1.1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56222" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/codebard-help-desk/vulnerability/wordpress-codebard-help-desk-plugin-1-1-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-pjf2-m9w6-vc7q/GHSA-pjf2-m9w6-vc7q.json b/advisories/unreviewed/2024/12/GHSA-pjf2-m9w6-vc7q/GHSA-pjf2-m9w6-vc7q.json new file mode 100644 index 00000000000..c9b232686ce --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-pjf2-m9w6-vc7q/GHSA-pjf2-m9w6-vc7q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjf2-m9w6-vc7q", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56231" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debuggers Studio SaasPricing allows DOM-Based XSS.This issue affects SaasPricing: from n/a through 1.1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56231" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/saaspricing/vulnerability/wordpress-saaspricing-plugin-1-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qcw5-mhgm-5rc7/GHSA-qcw5-mhgm-5rc7.json b/advisories/unreviewed/2024/12/GHSA-qcw5-mhgm-5rc7/GHSA-qcw5-mhgm-5rc7.json new file mode 100644 index 00000000000..ea5d31d23cf --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qcw5-mhgm-5rc7/GHSA-qcw5-mhgm-5rc7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcw5-mhgm-5rc7", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56228" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist for WooCommerce: Multi Wishlists Per Customer allows Reflected XSS.This issue affects Wishlist for WooCommerce: Multi Wishlists Per Customer: from n/a through 3.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56228" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wish-list-for-woocommerce/vulnerability/wordpress-wishlist-for-woocommerce-multi-wishlists-per-customer-plugin-3-1-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qqrh-4fhf-m9rw/GHSA-qqrh-4fhf-m9rw.json b/advisories/unreviewed/2024/12/GHSA-qqrh-4fhf-m9rw/GHSA-qqrh-4fhf-m9rw.json new file mode 100644 index 00000000000..47d5f031e3a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qqrh-4fhf-m9rw/GHSA-qqrh-4fhf-m9rw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqrh-4fhf-m9rw", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56210" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DeluxeThemes Userpro allows Reflected XSS.This issue affects Userpro: from n/a through 5.1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56210" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/userpro/vulnerability/wordpress-userpro-plugin-5-1-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qv2c-9cgg-8g7p/GHSA-qv2c-9cgg-8g7p.json b/advisories/unreviewed/2024/12/GHSA-qv2c-9cgg-8g7p/GHSA-qv2c-9cgg-8g7p.json new file mode 100644 index 00000000000..fc98460958d --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qv2c-9cgg-8g7p/GHSA-qv2c-9cgg-8g7p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv2c-9cgg-8g7p", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56218" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in AuRise Creative, SevenSpark Contact Form 7 Dynamic Text Extension allows Cross Site Request Forgery.This issue affects Contact Form 7 Dynamic Text Extension: from n/a through 5.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56218" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/contact-form-7-dynamic-text-extension/vulnerability/wordpress-contact-form-7-dynamic-text-extension-plugin-5-0-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vf7h-r8hg-75jj/GHSA-vf7h-r8hg-75jj.json b/advisories/unreviewed/2024/12/GHSA-vf7h-r8hg-75jj/GHSA-vf7h-r8hg-75jj.json new file mode 100644 index 00000000000..6bd7feb95ad --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vf7h-r8hg-75jj/GHSA-vf7h-r8hg-75jj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vf7h-r8hg-75jj", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-12105" + ], + "details": "In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12105" + }, + { + "type": "WEB", + "url": "https://www.progress.com/network-monitoring" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vr96-c7gf-6gvh/GHSA-vr96-c7gf-6gvh.json b/advisories/unreviewed/2024/12/GHSA-vr96-c7gf-6gvh/GHSA-vr96-c7gf-6gvh.json new file mode 100644 index 00000000000..ede0296f708 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vr96-c7gf-6gvh/GHSA-vr96-c7gf-6gvh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr96-c7gf-6gvh", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56229" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56229" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/searchiq/vulnerability/wordpress-searchiq-plugin-4-6-cross-site-requst-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w3c7-53rc-4cf4/GHSA-w3c7-53rc-4cf4.json b/advisories/unreviewed/2024/12/GHSA-w3c7-53rc-4cf4/GHSA-w3c7-53rc-4cf4.json new file mode 100644 index 00000000000..2b69c60bc28 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w3c7-53rc-4cf4/GHSA-w3c7-53rc-4cf4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3c7-53rc-4cf4", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56212" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DeluxeThemes Userpro.This issue affects Userpro: from n/a through 5.1.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56212" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/userpro/vulnerability/wordpress-userpro-plugin-5-1-9-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w6hf-97c7-45mp/GHSA-w6hf-97c7-45mp.json b/advisories/unreviewed/2024/12/GHSA-w6hf-97c7-45mp/GHSA-w6hf-97c7-45mp.json new file mode 100644 index 00000000000..9350c7d5066 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w6hf-97c7-45mp/GHSA-w6hf-97c7-45mp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6hf-97c7-45mp", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56226" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons allows Reflected XSS.This issue affects Royal Elementor Addons: from n/a through 1.7.1001.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56226" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/royal-elementor-addons/vulnerability/wordpress-royal-elementor-addons-plugin-1-7-1001-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wp3p-hj94-j835/GHSA-wp3p-hj94-j835.json b/advisories/unreviewed/2024/12/GHSA-wp3p-hj94-j835/GHSA-wp3p-hj94-j835.json new file mode 100644 index 00000000000..c9ab1636e9f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wp3p-hj94-j835/GHSA-wp3p-hj94-j835.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp3p-hj94-j835", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56219" + ], + "details": "Missing Authorization vulnerability in MarketingFire Widget Options allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Widget Options: from n/a through 4.0.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56219" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/widget-options/vulnerability/wordpress-widget-options-plugin-4-0-6-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wxm7-9gw3-47wq/GHSA-wxm7-9gw3-47wq.json b/advisories/unreviewed/2024/12/GHSA-wxm7-9gw3-47wq/GHSA-wxm7-9gw3-47wq.json new file mode 100644 index 00000000000..185e4af1afa --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wxm7-9gw3-47wq/GHSA-wxm7-9gw3-47wq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxm7-9gw3-47wq", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56217" + ], + "details": "Missing Authorization vulnerability in W3 Eden, Inc. Download Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a through 3.3.03.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56217" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/download-manager/vulnerability/wordpress-download-manager-plugin-3-3-03-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xq88-r3w7-9fw6/GHSA-xq88-r3w7-9fw6.json b/advisories/unreviewed/2024/12/GHSA-xq88-r3w7-9fw6/GHSA-xq88-r3w7-9fw6.json new file mode 100644 index 00000000000..7b9cfd68723 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xq88-r3w7-9fw6/GHSA-xq88-r3w7-9fw6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xq88-r3w7-9fw6", + "modified": "2024-12-31T12:30:44Z", + "published": "2024-12-31T12:30:44Z", + "aliases": [ + "CVE-2024-56215" + ], + "details": "Missing Authorization vulnerability in Stephen Sherrard Member Directory and Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Member Directory and Contact Form: from n/a through 1.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56215" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pta-member-directory/vulnerability/wordpress-member-directory-and-contact-form-plugin-1-7-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-31T11:15:07Z" + } +} \ No newline at end of file