From f6eac15575c7ce830712d7160d9c1a02336e4ddf Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 29 May 2025 09:32:38 +0000 Subject: [PATCH] Publish Advisories GHSA-54qp-w9cp-g8g3 GHSA-65wf-c9wx-f4v7 GHSA-7wfq-7p2f-6344 GHSA-9589-mpwg-8xq6 GHSA-99xf-gcww-2c64 GHSA-9qwg-ch53-9rxw GHSA-f4vp-qjpg-x8wq GHSA-fp4x-j6ch-w8q5 GHSA-wcmh-fj7m-gv6r GHSA-78jm-3rg9-qvxq GHSA-9c2j-cwmf-39vw GHSA-cvpp-rmjx-5x2m GHSA-gq3q-6947-35qj GHSA-p2qp-gwg4-3p43 GHSA-qhm6-4q4w-cv6h GHSA-v7hj-8fmw-5mw6 --- .../GHSA-54qp-w9cp-g8g3.json | 6 +- .../GHSA-65wf-c9wx-f4v7.json | 6 +- .../GHSA-7wfq-7p2f-6344.json | 6 +- .../GHSA-9589-mpwg-8xq6.json | 6 +- .../GHSA-99xf-gcww-2c64.json | 6 +- .../GHSA-9qwg-ch53-9rxw.json | 6 +- .../GHSA-f4vp-qjpg-x8wq.json | 6 +- .../GHSA-fp4x-j6ch-w8q5.json | 6 +- .../GHSA-wcmh-fj7m-gv6r.json | 6 +- .../GHSA-78jm-3rg9-qvxq.json | 34 +++++++++++ .../GHSA-9c2j-cwmf-39vw.json | 44 ++++++++++++++ .../GHSA-cvpp-rmjx-5x2m.json | 6 +- .../GHSA-gq3q-6947-35qj.json | 48 +++++++++++++++ .../GHSA-p2qp-gwg4-3p43.json | 6 +- .../GHSA-qhm6-4q4w-cv6h.json | 60 +++++++++++++++++++ .../GHSA-v7hj-8fmw-5mw6.json | 6 +- 16 files changed, 246 insertions(+), 12 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-78jm-3rg9-qvxq/GHSA-78jm-3rg9-qvxq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9c2j-cwmf-39vw/GHSA-9c2j-cwmf-39vw.json create mode 100644 advisories/unreviewed/2025/05/GHSA-gq3q-6947-35qj/GHSA-gq3q-6947-35qj.json create mode 100644 advisories/unreviewed/2025/05/GHSA-qhm6-4q4w-cv6h/GHSA-qhm6-4q4w-cv6h.json diff --git a/advisories/unreviewed/2025/04/GHSA-54qp-w9cp-g8g3/GHSA-54qp-w9cp-g8g3.json b/advisories/unreviewed/2025/04/GHSA-54qp-w9cp-g8g3/GHSA-54qp-w9cp-g8g3.json index 6c620747d95..b94fb1e0acc 100644 --- a/advisories/unreviewed/2025/04/GHSA-54qp-w9cp-g8g3/GHSA-54qp-w9cp-g8g3.json +++ b/advisories/unreviewed/2025/04/GHSA-54qp-w9cp-g8g3/GHSA-54qp-w9cp-g8g3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-54qp-w9cp-g8g3", - "modified": "2025-05-13T21:30:31Z", + "modified": "2025-05-29T09:30:59Z", "published": "2025-04-03T15:31:19Z", "aliases": [ "CVE-2025-32053" @@ -39,6 +39,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:7436" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:8292" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32053" diff --git a/advisories/unreviewed/2025/04/GHSA-65wf-c9wx-f4v7/GHSA-65wf-c9wx-f4v7.json b/advisories/unreviewed/2025/04/GHSA-65wf-c9wx-f4v7/GHSA-65wf-c9wx-f4v7.json index fe221487a2b..bf9a6fc1edf 100644 --- a/advisories/unreviewed/2025/04/GHSA-65wf-c9wx-f4v7/GHSA-65wf-c9wx-f4v7.json +++ b/advisories/unreviewed/2025/04/GHSA-65wf-c9wx-f4v7/GHSA-65wf-c9wx-f4v7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-65wf-c9wx-f4v7", - "modified": "2025-04-14T15:31:59Z", + "modified": "2025-05-29T09:30:59Z", "published": "2025-04-14T15:31:59Z", "aliases": [ "CVE-2025-32910" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32910" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:8292" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32910" diff --git a/advisories/unreviewed/2025/04/GHSA-7wfq-7p2f-6344/GHSA-7wfq-7p2f-6344.json b/advisories/unreviewed/2025/04/GHSA-7wfq-7p2f-6344/GHSA-7wfq-7p2f-6344.json index e7b26c50857..11794bb5e3e 100644 --- a/advisories/unreviewed/2025/04/GHSA-7wfq-7p2f-6344/GHSA-7wfq-7p2f-6344.json +++ b/advisories/unreviewed/2025/04/GHSA-7wfq-7p2f-6344/GHSA-7wfq-7p2f-6344.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7wfq-7p2f-6344", - "modified": "2025-05-26T12:30:29Z", + "modified": "2025-05-29T09:30:59Z", "published": "2025-04-14T15:31:58Z", "aliases": [ "CVE-2025-32907" @@ -39,6 +39,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:8128" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:8292" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32907" diff --git a/advisories/unreviewed/2025/04/GHSA-9589-mpwg-8xq6/GHSA-9589-mpwg-8xq6.json b/advisories/unreviewed/2025/04/GHSA-9589-mpwg-8xq6/GHSA-9589-mpwg-8xq6.json index abaeae66c5b..5340973354b 100644 --- a/advisories/unreviewed/2025/04/GHSA-9589-mpwg-8xq6/GHSA-9589-mpwg-8xq6.json +++ b/advisories/unreviewed/2025/04/GHSA-9589-mpwg-8xq6/GHSA-9589-mpwg-8xq6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9589-mpwg-8xq6", - "modified": "2025-05-13T15:32:11Z", + "modified": "2025-05-29T09:30:59Z", "published": "2025-04-14T15:31:58Z", "aliases": [ "CVE-2025-32913" @@ -55,6 +55,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:7436" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:8292" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32913" diff --git a/advisories/unreviewed/2025/04/GHSA-99xf-gcww-2c64/GHSA-99xf-gcww-2c64.json b/advisories/unreviewed/2025/04/GHSA-99xf-gcww-2c64/GHSA-99xf-gcww-2c64.json index d90187b5008..cba2b72af05 100644 --- a/advisories/unreviewed/2025/04/GHSA-99xf-gcww-2c64/GHSA-99xf-gcww-2c64.json +++ b/advisories/unreviewed/2025/04/GHSA-99xf-gcww-2c64/GHSA-99xf-gcww-2c64.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-99xf-gcww-2c64", - "modified": "2025-05-13T21:30:31Z", + "modified": "2025-05-29T09:30:59Z", "published": "2025-04-03T15:31:19Z", "aliases": [ "CVE-2025-32050" @@ -39,6 +39,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:7436" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:8292" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32050" diff --git a/advisories/unreviewed/2025/04/GHSA-9qwg-ch53-9rxw/GHSA-9qwg-ch53-9rxw.json b/advisories/unreviewed/2025/04/GHSA-9qwg-ch53-9rxw/GHSA-9qwg-ch53-9rxw.json index a024812443c..1632ad8f277 100644 --- a/advisories/unreviewed/2025/04/GHSA-9qwg-ch53-9rxw/GHSA-9qwg-ch53-9rxw.json +++ b/advisories/unreviewed/2025/04/GHSA-9qwg-ch53-9rxw/GHSA-9qwg-ch53-9rxw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9qwg-ch53-9rxw", - "modified": "2025-05-13T21:30:31Z", + "modified": "2025-05-29T09:30:59Z", "published": "2025-04-03T15:31:19Z", "aliases": [ "CVE-2025-32052" @@ -39,6 +39,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:7436" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:8292" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32052" diff --git a/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json b/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json index 77324dc180e..06f620b19b7 100644 --- a/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json +++ b/advisories/unreviewed/2025/04/GHSA-f4vp-qjpg-x8wq/GHSA-f4vp-qjpg-x8wq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f4vp-qjpg-x8wq", - "modified": "2025-05-13T21:30:31Z", + "modified": "2025-05-29T09:30:59Z", "published": "2025-04-14T15:31:58Z", "aliases": [ "CVE-2025-32906" @@ -59,6 +59,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:7505" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:8292" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32906" diff --git a/advisories/unreviewed/2025/04/GHSA-fp4x-j6ch-w8q5/GHSA-fp4x-j6ch-w8q5.json b/advisories/unreviewed/2025/04/GHSA-fp4x-j6ch-w8q5/GHSA-fp4x-j6ch-w8q5.json index 24b8bee3658..7ad08a1c655 100644 --- a/advisories/unreviewed/2025/04/GHSA-fp4x-j6ch-w8q5/GHSA-fp4x-j6ch-w8q5.json +++ b/advisories/unreviewed/2025/04/GHSA-fp4x-j6ch-w8q5/GHSA-fp4x-j6ch-w8q5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fp4x-j6ch-w8q5", - "modified": "2025-05-13T15:32:11Z", + "modified": "2025-05-29T09:30:59Z", "published": "2025-04-15T18:31:45Z", "aliases": [ "CVE-2025-32911" @@ -55,6 +55,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:7436" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:8292" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32911" diff --git a/advisories/unreviewed/2025/04/GHSA-wcmh-fj7m-gv6r/GHSA-wcmh-fj7m-gv6r.json b/advisories/unreviewed/2025/04/GHSA-wcmh-fj7m-gv6r/GHSA-wcmh-fj7m-gv6r.json index ec81d685a64..cd2489cfd86 100644 --- a/advisories/unreviewed/2025/04/GHSA-wcmh-fj7m-gv6r/GHSA-wcmh-fj7m-gv6r.json +++ b/advisories/unreviewed/2025/04/GHSA-wcmh-fj7m-gv6r/GHSA-wcmh-fj7m-gv6r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wcmh-fj7m-gv6r", - "modified": "2025-04-14T15:31:59Z", + "modified": "2025-05-29T09:30:59Z", "published": "2025-04-14T15:31:59Z", "aliases": [ "CVE-2025-32909" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32909" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:8292" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32909" diff --git a/advisories/unreviewed/2025/05/GHSA-78jm-3rg9-qvxq/GHSA-78jm-3rg9-qvxq.json b/advisories/unreviewed/2025/05/GHSA-78jm-3rg9-qvxq/GHSA-78jm-3rg9-qvxq.json new file mode 100644 index 00000000000..c1682cecd6f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-78jm-3rg9-qvxq/GHSA-78jm-3rg9-qvxq.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78jm-3rg9-qvxq", + "modified": "2025-05-29T09:31:00Z", + "published": "2025-05-29T09:31:00Z", + "aliases": [ + "CVE-2025-4687" + ], + "details": "In Teltonika Networks Remote Management System (RMS), it is possible to perform account pre-hijacking by misusing the invite functionality. If a victim has a pending invite and registers to the platform directly, they are added to the attackers company without their knowledge. The victims account and their company can then be managed by the attacker.This issue affects RMS: before 5.7.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:L/VI:L/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4687" + }, + { + "type": "WEB", + "url": "https://jowin922.medium.com/cve-2025-4687-pre-account-takeover-through-invite-on-teletonika-rms-website-972335378829" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T09:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9c2j-cwmf-39vw/GHSA-9c2j-cwmf-39vw.json b/advisories/unreviewed/2025/05/GHSA-9c2j-cwmf-39vw/GHSA-9c2j-cwmf-39vw.json new file mode 100644 index 00000000000..39801a0de93 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9c2j-cwmf-39vw/GHSA-9c2j-cwmf-39vw.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9c2j-cwmf-39vw", + "modified": "2025-05-29T09:31:00Z", + "published": "2025-05-29T09:31:00Z", + "aliases": [ + "CVE-2025-4670" + ], + "details": "The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's edd_receipt shortcode in all versions up to, and including, 3.3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4670" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3301852" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/easy-digital-downloads/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/95c5bfc5-53b3-482f-856b-db6b6cac93a2?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T09:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cvpp-rmjx-5x2m/GHSA-cvpp-rmjx-5x2m.json b/advisories/unreviewed/2025/05/GHSA-cvpp-rmjx-5x2m/GHSA-cvpp-rmjx-5x2m.json index 2646930c5e8..a79d2726ce6 100644 --- a/advisories/unreviewed/2025/05/GHSA-cvpp-rmjx-5x2m/GHSA-cvpp-rmjx-5x2m.json +++ b/advisories/unreviewed/2025/05/GHSA-cvpp-rmjx-5x2m/GHSA-cvpp-rmjx-5x2m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cvpp-rmjx-5x2m", - "modified": "2025-05-15T21:31:26Z", + "modified": "2025-05-29T09:30:59Z", "published": "2025-05-14T00:32:21Z", "aliases": [ "CVE-2025-47905" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47905" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00040.html" + }, { "type": "WEB", "url": "https://varnish-cache.org/security/VSV00016.html" diff --git a/advisories/unreviewed/2025/05/GHSA-gq3q-6947-35qj/GHSA-gq3q-6947-35qj.json b/advisories/unreviewed/2025/05/GHSA-gq3q-6947-35qj/GHSA-gq3q-6947-35qj.json new file mode 100644 index 00000000000..36d43d6b204 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gq3q-6947-35qj/GHSA-gq3q-6947-35qj.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq3q-6947-35qj", + "modified": "2025-05-29T09:31:00Z", + "published": "2025-05-29T09:31:00Z", + "aliases": [ + "CVE-2025-5122" + ], + "details": "The Map Block Leaflet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5122" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/map-block-leaflet/trunk/build/leaflet-map-block/render.php#L41" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3302407" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/map-block-leaflet/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/372f1cf3-df33-444c-b31e-8f71d128e30b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T09:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p2qp-gwg4-3p43/GHSA-p2qp-gwg4-3p43.json b/advisories/unreviewed/2025/05/GHSA-p2qp-gwg4-3p43/GHSA-p2qp-gwg4-3p43.json index dfdd77f89e8..3d6efa03e31 100644 --- a/advisories/unreviewed/2025/05/GHSA-p2qp-gwg4-3p43/GHSA-p2qp-gwg4-3p43.json +++ b/advisories/unreviewed/2025/05/GHSA-p2qp-gwg4-3p43/GHSA-p2qp-gwg4-3p43.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p2qp-gwg4-3p43", - "modified": "2025-05-25T09:33:47Z", + "modified": "2025-05-29T09:31:00Z", "published": "2025-05-25T09:33:47Z", "aliases": [ "CVE-2025-5146" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://anonymous.4open.science/r/netcore_command_injection2-4583F2DA" }, + { + "type": "WEB", + "url": "https://github.com/Exploo0Osion/netcore_command_injection_2" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.310234" diff --git a/advisories/unreviewed/2025/05/GHSA-qhm6-4q4w-cv6h/GHSA-qhm6-4q4w-cv6h.json b/advisories/unreviewed/2025/05/GHSA-qhm6-4q4w-cv6h/GHSA-qhm6-4q4w-cv6h.json new file mode 100644 index 00000000000..0ad1e15139e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qhm6-4q4w-cv6h/GHSA-qhm6-4q4w-cv6h.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhm6-4q4w-cv6h", + "modified": "2025-05-29T09:31:00Z", + "published": "2025-05-29T09:31:00Z", + "aliases": [ + "CVE-2025-5286" + ], + "details": "The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘additional_settings’ parameter in all versions up to, and including, 5.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5286" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/bold-page-builder/tags/5.3.6/content_elements/bt_bb_content_slider/bt_bb_content_slider.php#L156" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/bold-page-builder/tags/5.3.6/content_elements/bt_bb_content_slider/bt_bb_content_slider.php#L176" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/bold-page-builder/tags/5.3.6/content_elements/bt_bb_content_slider/bt_bb_content_slider.php#L7" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/bold-page-builder/tags/5.3.7/content_elements/bt_bb_content_slider/bt_bb_content_slider.php#L156" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3302452" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/bold-page-builder/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9ae076e4-ad15-4069-be10-f0f4aced4132?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-29T09:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v7hj-8fmw-5mw6/GHSA-v7hj-8fmw-5mw6.json b/advisories/unreviewed/2025/05/GHSA-v7hj-8fmw-5mw6/GHSA-v7hj-8fmw-5mw6.json index 8815df3fa61..8c11acde439 100644 --- a/advisories/unreviewed/2025/05/GHSA-v7hj-8fmw-5mw6/GHSA-v7hj-8fmw-5mw6.json +++ b/advisories/unreviewed/2025/05/GHSA-v7hj-8fmw-5mw6/GHSA-v7hj-8fmw-5mw6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v7hj-8fmw-5mw6", - "modified": "2025-05-25T12:30:24Z", + "modified": "2025-05-29T09:31:00Z", "published": "2025-05-25T12:30:24Z", "aliases": [ "CVE-2025-5147" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://anonymous.4open.science/r/netcore_command_injection3-54DFaW2G" }, + { + "type": "WEB", + "url": "https://github.com/Exploo0Osion/netcore_command_injection_3" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.310235"