diff --git a/advisories/unreviewed/2023/11/GHSA-fh8c-9pw4-5fjj/GHSA-fh8c-9pw4-5fjj.json b/advisories/unreviewed/2023/11/GHSA-fh8c-9pw4-5fjj/GHSA-fh8c-9pw4-5fjj.json index 79ecd92ef4f..a233846abbf 100644 --- a/advisories/unreviewed/2023/11/GHSA-fh8c-9pw4-5fjj/GHSA-fh8c-9pw4-5fjj.json +++ b/advisories/unreviewed/2023/11/GHSA-fh8c-9pw4-5fjj/GHSA-fh8c-9pw4-5fjj.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-fh8c-9pw4-5fjj", - "modified": "2023-11-21T00:30:27Z", + "modified": "2025-05-19T15:30:29Z", "published": "2023-11-21T00:30:27Z", "aliases": [ "CVE-2023-6142" ], - "details": "Dev blog v1.0 allows to exploit an XSS through an unrestricted file upload, together with a bad entropy of filenames. With this an attacker can upload a malicious HTML file, then guess the filename of the uploaded file and send it to a potential victim.\n", + "details": "Dev blog v1.0 allows to exploit an XSS through an unrestricted file upload, together with a bad entropy of filenames. With this an attacker can upload a malicious HTML file, then guess the filename of the uploaded file and send it to a potential victim.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/11/GHSA-fwg4-q55q-w62p/GHSA-fwg4-q55q-w62p.json b/advisories/unreviewed/2023/11/GHSA-fwg4-q55q-w62p/GHSA-fwg4-q55q-w62p.json index 401f6904391..05169cc7f49 100644 --- a/advisories/unreviewed/2023/11/GHSA-fwg4-q55q-w62p/GHSA-fwg4-q55q-w62p.json +++ b/advisories/unreviewed/2023/11/GHSA-fwg4-q55q-w62p/GHSA-fwg4-q55q-w62p.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-fwg4-q55q-w62p", - "modified": "2024-06-07T15:30:34Z", + "modified": "2025-05-19T15:30:29Z", "published": "2023-11-21T00:30:27Z", "aliases": [ "CVE-2023-6199" ], - "details": "Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.\n", + "details": "Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-372v-gvcg-hfrh/GHSA-372v-gvcg-hfrh.json b/advisories/unreviewed/2023/12/GHSA-372v-gvcg-hfrh/GHSA-372v-gvcg-hfrh.json index 4a00a0828bd..82a56eeea8c 100644 --- a/advisories/unreviewed/2023/12/GHSA-372v-gvcg-hfrh/GHSA-372v-gvcg-hfrh.json +++ b/advisories/unreviewed/2023/12/GHSA-372v-gvcg-hfrh/GHSA-372v-gvcg-hfrh.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-372v-gvcg-hfrh", - "modified": "2023-12-27T18:30:20Z", + "modified": "2025-05-19T15:30:29Z", "published": "2023-12-20T18:30:33Z", "aliases": [ "CVE-2023-49269" ], - "details": "Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'adults' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.\n\n", + "details": "Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'adults' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-4827-2m3r-j4qh/GHSA-4827-2m3r-j4qh.json b/advisories/unreviewed/2023/12/GHSA-4827-2m3r-j4qh/GHSA-4827-2m3r-j4qh.json index f516535de36..a548583c45b 100644 --- a/advisories/unreviewed/2023/12/GHSA-4827-2m3r-j4qh/GHSA-4827-2m3r-j4qh.json +++ b/advisories/unreviewed/2023/12/GHSA-4827-2m3r-j4qh/GHSA-4827-2m3r-j4qh.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-4827-2m3r-j4qh", - "modified": "2024-01-02T15:30:24Z", + "modified": "2025-05-19T15:30:31Z", "published": "2023-12-21T18:30:23Z", "aliases": [ "CVE-2023-45119" ], - "details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'n' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n", + "details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'n' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-9g9h-7mhh-5mcr/GHSA-9g9h-7mhh-5mcr.json b/advisories/unreviewed/2023/12/GHSA-9g9h-7mhh-5mcr/GHSA-9g9h-7mhh-5mcr.json index ae376380b74..33621a1e5aa 100644 --- a/advisories/unreviewed/2023/12/GHSA-9g9h-7mhh-5mcr/GHSA-9g9h-7mhh-5mcr.json +++ b/advisories/unreviewed/2023/12/GHSA-9g9h-7mhh-5mcr/GHSA-9g9h-7mhh-5mcr.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-9g9h-7mhh-5mcr", - "modified": "2023-12-27T00:30:25Z", + "modified": "2025-05-19T15:30:30Z", "published": "2023-12-20T21:30:35Z", "aliases": [ "CVE-2023-49271" ], - "details": "Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_out_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.\n\n", + "details": "Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_out_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-9pmm-p2wc-hfx4/GHSA-9pmm-p2wc-hfx4.json b/advisories/unreviewed/2023/12/GHSA-9pmm-p2wc-hfx4/GHSA-9pmm-p2wc-hfx4.json index 8d63fc95c17..acaac34d1de 100644 --- a/advisories/unreviewed/2023/12/GHSA-9pmm-p2wc-hfx4/GHSA-9pmm-p2wc-hfx4.json +++ b/advisories/unreviewed/2023/12/GHSA-9pmm-p2wc-hfx4/GHSA-9pmm-p2wc-hfx4.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-9pmm-p2wc-hfx4", - "modified": "2024-01-02T15:30:24Z", + "modified": "2025-05-19T15:30:31Z", "published": "2023-12-21T18:30:23Z", "aliases": [ "CVE-2023-45120" ], - "details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'qid' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n", + "details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'qid' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-j4xm-8c7j-fjwj/GHSA-j4xm-8c7j-fjwj.json b/advisories/unreviewed/2023/12/GHSA-j4xm-8c7j-fjwj/GHSA-j4xm-8c7j-fjwj.json index 1b00f978d04..540d756d5ad 100644 --- a/advisories/unreviewed/2023/12/GHSA-j4xm-8c7j-fjwj/GHSA-j4xm-8c7j-fjwj.json +++ b/advisories/unreviewed/2023/12/GHSA-j4xm-8c7j-fjwj/GHSA-j4xm-8c7j-fjwj.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-j4xm-8c7j-fjwj", - "modified": "2024-01-02T15:30:24Z", + "modified": "2025-05-19T15:30:30Z", "published": "2023-12-21T18:30:22Z", "aliases": [ "CVE-2023-45115" ], - "details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'ch' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n", + "details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'ch' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-j6r8-x8pp-9mcq/GHSA-j6r8-x8pp-9mcq.json b/advisories/unreviewed/2023/12/GHSA-j6r8-x8pp-9mcq/GHSA-j6r8-x8pp-9mcq.json index df83bf62a8e..8ba0c9f6c2a 100644 --- a/advisories/unreviewed/2023/12/GHSA-j6r8-x8pp-9mcq/GHSA-j6r8-x8pp-9mcq.json +++ b/advisories/unreviewed/2023/12/GHSA-j6r8-x8pp-9mcq/GHSA-j6r8-x8pp-9mcq.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-j6r8-x8pp-9mcq", - "modified": "2024-02-01T18:31:07Z", + "modified": "2025-05-19T15:30:30Z", "published": "2023-12-20T21:30:35Z", "aliases": [ "CVE-2023-49272" ], - "details": "Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'children' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.\n\n", + "details": "Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'children' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-jxpp-2jgf-79rr/GHSA-jxpp-2jgf-79rr.json b/advisories/unreviewed/2023/12/GHSA-jxpp-2jgf-79rr/GHSA-jxpp-2jgf-79rr.json index feba00fa98d..b969f8d6eff 100644 --- a/advisories/unreviewed/2023/12/GHSA-jxpp-2jgf-79rr/GHSA-jxpp-2jgf-79rr.json +++ b/advisories/unreviewed/2023/12/GHSA-jxpp-2jgf-79rr/GHSA-jxpp-2jgf-79rr.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-jxpp-2jgf-79rr", - "modified": "2024-01-02T15:30:24Z", + "modified": "2025-05-19T15:30:31Z", "published": "2023-12-21T18:30:22Z", "aliases": [ "CVE-2023-45118" ], - "details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'fdid' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n", + "details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'fdid' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-ppqr-xhhp-8qc5/GHSA-ppqr-xhhp-8qc5.json b/advisories/unreviewed/2023/12/GHSA-ppqr-xhhp-8qc5/GHSA-ppqr-xhhp-8qc5.json index c37eb2f8b5d..e372adc6df9 100644 --- a/advisories/unreviewed/2023/12/GHSA-ppqr-xhhp-8qc5/GHSA-ppqr-xhhp-8qc5.json +++ b/advisories/unreviewed/2023/12/GHSA-ppqr-xhhp-8qc5/GHSA-ppqr-xhhp-8qc5.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-ppqr-xhhp-8qc5", - "modified": "2023-12-27T00:30:25Z", + "modified": "2025-05-19T15:30:30Z", "published": "2023-12-20T21:30:35Z", "aliases": [ "CVE-2023-49270" ], - "details": "Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_in_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.\n\n", + "details": "Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_in_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-qjw8-8m2x-jvh6/GHSA-qjw8-8m2x-jvh6.json b/advisories/unreviewed/2023/12/GHSA-qjw8-8m2x-jvh6/GHSA-qjw8-8m2x-jvh6.json index ee8c011a941..2b949821822 100644 --- a/advisories/unreviewed/2023/12/GHSA-qjw8-8m2x-jvh6/GHSA-qjw8-8m2x-jvh6.json +++ b/advisories/unreviewed/2023/12/GHSA-qjw8-8m2x-jvh6/GHSA-qjw8-8m2x-jvh6.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-qjw8-8m2x-jvh6", - "modified": "2024-01-02T15:30:24Z", + "modified": "2025-05-19T15:30:30Z", "published": "2023-12-21T18:30:22Z", "aliases": [ "CVE-2023-45117" ], - "details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'eid' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n", + "details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'eid' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-vg76-xrj2-3p56/GHSA-vg76-xrj2-3p56.json b/advisories/unreviewed/2023/12/GHSA-vg76-xrj2-3p56/GHSA-vg76-xrj2-3p56.json index df2d697e2b0..7069d428a27 100644 --- a/advisories/unreviewed/2023/12/GHSA-vg76-xrj2-3p56/GHSA-vg76-xrj2-3p56.json +++ b/advisories/unreviewed/2023/12/GHSA-vg76-xrj2-3p56/GHSA-vg76-xrj2-3p56.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-vg76-xrj2-3p56", - "modified": "2024-01-02T15:30:24Z", + "modified": "2025-05-19T15:30:31Z", "published": "2023-12-21T18:30:23Z", "aliases": [ "CVE-2023-45121" ], - "details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'desc' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n", + "details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'desc' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/12/GHSA-xqm8-jv67-vcvj/GHSA-xqm8-jv67-vcvj.json b/advisories/unreviewed/2023/12/GHSA-xqm8-jv67-vcvj/GHSA-xqm8-jv67-vcvj.json index 3a0007f16e8..bea85b41540 100644 --- a/advisories/unreviewed/2023/12/GHSA-xqm8-jv67-vcvj/GHSA-xqm8-jv67-vcvj.json +++ b/advisories/unreviewed/2023/12/GHSA-xqm8-jv67-vcvj/GHSA-xqm8-jv67-vcvj.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-xqm8-jv67-vcvj", - "modified": "2024-01-02T15:30:24Z", + "modified": "2025-05-19T15:30:30Z", "published": "2023-12-21T18:30:22Z", "aliases": [ "CVE-2023-45116" ], - "details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'demail' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n", + "details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'demail' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-8vgq-xc89-pg94/GHSA-8vgq-xc89-pg94.json b/advisories/unreviewed/2024/03/GHSA-8vgq-xc89-pg94/GHSA-8vgq-xc89-pg94.json index b5c46fc4940..2ee01b178e5 100644 --- a/advisories/unreviewed/2024/03/GHSA-8vgq-xc89-pg94/GHSA-8vgq-xc89-pg94.json +++ b/advisories/unreviewed/2024/03/GHSA-8vgq-xc89-pg94/GHSA-8vgq-xc89-pg94.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-w3mf-qg63-54vm/GHSA-w3mf-qg63-54vm.json b/advisories/unreviewed/2024/03/GHSA-w3mf-qg63-54vm/GHSA-w3mf-qg63-54vm.json index 5d9289a9e0f..7c401b03951 100644 --- a/advisories/unreviewed/2024/03/GHSA-w3mf-qg63-54vm/GHSA-w3mf-qg63-54vm.json +++ b/advisories/unreviewed/2024/03/GHSA-w3mf-qg63-54vm/GHSA-w3mf-qg63-54vm.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-x5jp-245w-xc3w/GHSA-x5jp-245w-xc3w.json b/advisories/unreviewed/2024/03/GHSA-x5jp-245w-xc3w/GHSA-x5jp-245w-xc3w.json index 57ab5bc7297..31dbdfb0380 100644 --- a/advisories/unreviewed/2024/03/GHSA-x5jp-245w-xc3w/GHSA-x5jp-245w-xc3w.json +++ b/advisories/unreviewed/2024/03/GHSA-x5jp-245w-xc3w/GHSA-x5jp-245w-xc3w.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-3q9p-q428-g22j/GHSA-3q9p-q428-g22j.json b/advisories/unreviewed/2024/04/GHSA-3q9p-q428-g22j/GHSA-3q9p-q428-g22j.json index d2821843ddc..ff06b8698f9 100644 --- a/advisories/unreviewed/2024/04/GHSA-3q9p-q428-g22j/GHSA-3q9p-q428-g22j.json +++ b/advisories/unreviewed/2024/04/GHSA-3q9p-q428-g22j/GHSA-3q9p-q428-g22j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-v5gh-4369-4w97/GHSA-v5gh-4369-4w97.json b/advisories/unreviewed/2024/04/GHSA-v5gh-4369-4w97/GHSA-v5gh-4369-4w97.json index 0dc34a7fc87..b82a1d71f0e 100644 --- a/advisories/unreviewed/2024/04/GHSA-v5gh-4369-4w97/GHSA-v5gh-4369-4w97.json +++ b/advisories/unreviewed/2024/04/GHSA-v5gh-4369-4w97/GHSA-v5gh-4369-4w97.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v5gh-4369-4w97", - "modified": "2024-04-08T06:31:30Z", + "modified": "2025-05-19T15:30:31Z", "published": "2024-04-08T06:31:30Z", "aliases": [ "CVE-2024-1956" ], "details": "The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape the parameters before outputting it back in the response of an unauthenticated request, leading to a Reflected Cross-Site Scripting", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T05:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-v74g-7hwm-jpjc/GHSA-v74g-7hwm-jpjc.json b/advisories/unreviewed/2024/04/GHSA-v74g-7hwm-jpjc/GHSA-v74g-7hwm-jpjc.json index 4d35e9dc93c..08c0f650905 100644 --- a/advisories/unreviewed/2024/04/GHSA-v74g-7hwm-jpjc/GHSA-v74g-7hwm-jpjc.json +++ b/advisories/unreviewed/2024/04/GHSA-v74g-7hwm-jpjc/GHSA-v74g-7hwm-jpjc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-w7x4-hw9x-fprc/GHSA-w7x4-hw9x-fprc.json b/advisories/unreviewed/2024/04/GHSA-w7x4-hw9x-fprc/GHSA-w7x4-hw9x-fprc.json index c38a9d360f5..a77554a3bc0 100644 --- a/advisories/unreviewed/2024/04/GHSA-w7x4-hw9x-fprc/GHSA-w7x4-hw9x-fprc.json +++ b/advisories/unreviewed/2024/04/GHSA-w7x4-hw9x-fprc/GHSA-w7x4-hw9x-fprc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-58g3-hfh7-p3ch/GHSA-58g3-hfh7-p3ch.json b/advisories/unreviewed/2024/05/GHSA-58g3-hfh7-p3ch/GHSA-58g3-hfh7-p3ch.json index 970c15b0903..1303e7f64a5 100644 --- a/advisories/unreviewed/2024/05/GHSA-58g3-hfh7-p3ch/GHSA-58g3-hfh7-p3ch.json +++ b/advisories/unreviewed/2024/05/GHSA-58g3-hfh7-p3ch/GHSA-58g3-hfh7-p3ch.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-9hfh-q9rg-j934/GHSA-9hfh-q9rg-j934.json b/advisories/unreviewed/2024/05/GHSA-9hfh-q9rg-j934/GHSA-9hfh-q9rg-j934.json index 59add272fba..141b73d0db0 100644 --- a/advisories/unreviewed/2024/05/GHSA-9hfh-q9rg-j934/GHSA-9hfh-q9rg-j934.json +++ b/advisories/unreviewed/2024/05/GHSA-9hfh-q9rg-j934/GHSA-9hfh-q9rg-j934.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-g8vg-m5vq-4hcq/GHSA-g8vg-m5vq-4hcq.json b/advisories/unreviewed/2024/05/GHSA-g8vg-m5vq-4hcq/GHSA-g8vg-m5vq-4hcq.json index dae1038843d..2022f170923 100644 --- a/advisories/unreviewed/2024/05/GHSA-g8vg-m5vq-4hcq/GHSA-g8vg-m5vq-4hcq.json +++ b/advisories/unreviewed/2024/05/GHSA-g8vg-m5vq-4hcq/GHSA-g8vg-m5vq-4hcq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-hc4m-mm2c-rjg7/GHSA-hc4m-mm2c-rjg7.json b/advisories/unreviewed/2024/05/GHSA-hc4m-mm2c-rjg7/GHSA-hc4m-mm2c-rjg7.json index a503fdca593..17af1ad084d 100644 --- a/advisories/unreviewed/2024/05/GHSA-hc4m-mm2c-rjg7/GHSA-hc4m-mm2c-rjg7.json +++ b/advisories/unreviewed/2024/05/GHSA-hc4m-mm2c-rjg7/GHSA-hc4m-mm2c-rjg7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-m3m5-w4hq-w7x6/GHSA-m3m5-w4hq-w7x6.json b/advisories/unreviewed/2024/05/GHSA-m3m5-w4hq-w7x6/GHSA-m3m5-w4hq-w7x6.json index 64f81e938a7..341307c71d3 100644 --- a/advisories/unreviewed/2024/05/GHSA-m3m5-w4hq-w7x6/GHSA-m3m5-w4hq-w7x6.json +++ b/advisories/unreviewed/2024/05/GHSA-m3m5-w4hq-w7x6/GHSA-m3m5-w4hq-w7x6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-m79q-pr9f-vqvg/GHSA-m79q-pr9f-vqvg.json b/advisories/unreviewed/2024/05/GHSA-m79q-pr9f-vqvg/GHSA-m79q-pr9f-vqvg.json index 0cc48572247..241e70d987b 100644 --- a/advisories/unreviewed/2024/05/GHSA-m79q-pr9f-vqvg/GHSA-m79q-pr9f-vqvg.json +++ b/advisories/unreviewed/2024/05/GHSA-m79q-pr9f-vqvg/GHSA-m79q-pr9f-vqvg.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-j67h-vvfp-vgmq/GHSA-j67h-vvfp-vgmq.json b/advisories/unreviewed/2024/06/GHSA-j67h-vvfp-vgmq/GHSA-j67h-vvfp-vgmq.json index bb55ce04219..47eb3f78c7f 100644 --- a/advisories/unreviewed/2024/06/GHSA-j67h-vvfp-vgmq/GHSA-j67h-vvfp-vgmq.json +++ b/advisories/unreviewed/2024/06/GHSA-j67h-vvfp-vgmq/GHSA-j67h-vvfp-vgmq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-2rv8-6398-pqxg/GHSA-2rv8-6398-pqxg.json b/advisories/unreviewed/2024/07/GHSA-2rv8-6398-pqxg/GHSA-2rv8-6398-pqxg.json index 9a06379ccb3..6578ba84b5a 100644 --- a/advisories/unreviewed/2024/07/GHSA-2rv8-6398-pqxg/GHSA-2rv8-6398-pqxg.json +++ b/advisories/unreviewed/2024/07/GHSA-2rv8-6398-pqxg/GHSA-2rv8-6398-pqxg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-53c2-8q6v-xx43/GHSA-53c2-8q6v-xx43.json b/advisories/unreviewed/2024/07/GHSA-53c2-8q6v-xx43/GHSA-53c2-8q6v-xx43.json index a74f85ca8e3..cfe4001c889 100644 --- a/advisories/unreviewed/2024/07/GHSA-53c2-8q6v-xx43/GHSA-53c2-8q6v-xx43.json +++ b/advisories/unreviewed/2024/07/GHSA-53c2-8q6v-xx43/GHSA-53c2-8q6v-xx43.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-7pxg-99jf-7vvf/GHSA-7pxg-99jf-7vvf.json b/advisories/unreviewed/2024/07/GHSA-7pxg-99jf-7vvf/GHSA-7pxg-99jf-7vvf.json index b30504ce71b..a04f862ef41 100644 --- a/advisories/unreviewed/2024/07/GHSA-7pxg-99jf-7vvf/GHSA-7pxg-99jf-7vvf.json +++ b/advisories/unreviewed/2024/07/GHSA-7pxg-99jf-7vvf/GHSA-7pxg-99jf-7vvf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-7qj5-648p-27v4/GHSA-7qj5-648p-27v4.json b/advisories/unreviewed/2024/07/GHSA-7qj5-648p-27v4/GHSA-7qj5-648p-27v4.json index b10eb93109a..a8fd5c03404 100644 --- a/advisories/unreviewed/2024/07/GHSA-7qj5-648p-27v4/GHSA-7qj5-648p-27v4.json +++ b/advisories/unreviewed/2024/07/GHSA-7qj5-648p-27v4/GHSA-7qj5-648p-27v4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-cqmh-x8qq-7fj3/GHSA-cqmh-x8qq-7fj3.json b/advisories/unreviewed/2024/07/GHSA-cqmh-x8qq-7fj3/GHSA-cqmh-x8qq-7fj3.json index a08774d8503..f54cc87932c 100644 --- a/advisories/unreviewed/2024/07/GHSA-cqmh-x8qq-7fj3/GHSA-cqmh-x8qq-7fj3.json +++ b/advisories/unreviewed/2024/07/GHSA-cqmh-x8qq-7fj3/GHSA-cqmh-x8qq-7fj3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-pgmc-r2x5-p7pg/GHSA-pgmc-r2x5-p7pg.json b/advisories/unreviewed/2024/07/GHSA-pgmc-r2x5-p7pg/GHSA-pgmc-r2x5-p7pg.json index d674b167cf0..459ff8a3ed8 100644 --- a/advisories/unreviewed/2024/07/GHSA-pgmc-r2x5-p7pg/GHSA-pgmc-r2x5-p7pg.json +++ b/advisories/unreviewed/2024/07/GHSA-pgmc-r2x5-p7pg/GHSA-pgmc-r2x5-p7pg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-v28p-w2jr-63vq/GHSA-v28p-w2jr-63vq.json b/advisories/unreviewed/2024/07/GHSA-v28p-w2jr-63vq/GHSA-v28p-w2jr-63vq.json index 7ad6678ef38..26f0e3dd324 100644 --- a/advisories/unreviewed/2024/07/GHSA-v28p-w2jr-63vq/GHSA-v28p-w2jr-63vq.json +++ b/advisories/unreviewed/2024/07/GHSA-v28p-w2jr-63vq/GHSA-v28p-w2jr-63vq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-gcm6-cm5p-jg47/GHSA-gcm6-cm5p-jg47.json b/advisories/unreviewed/2025/04/GHSA-gcm6-cm5p-jg47/GHSA-gcm6-cm5p-jg47.json index 3b459555ef9..4bb9f3337a6 100644 --- a/advisories/unreviewed/2025/04/GHSA-gcm6-cm5p-jg47/GHSA-gcm6-cm5p-jg47.json +++ b/advisories/unreviewed/2025/04/GHSA-gcm6-cm5p-jg47/GHSA-gcm6-cm5p-jg47.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gcm6-cm5p-jg47", - "modified": "2025-04-15T21:31:48Z", + "modified": "2025-05-19T15:30:35Z", "published": "2025-04-15T21:31:48Z", "aliases": [ "CVE-2025-30733" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30733" }, + { + "type": "WEB", + "url": "https://driftnet.io/blog/oracle-tns-memory-leak" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2025.html" diff --git a/advisories/unreviewed/2025/05/GHSA-2fmr-2c6h-79j9/GHSA-2fmr-2c6h-79j9.json b/advisories/unreviewed/2025/05/GHSA-2fmr-2c6h-79j9/GHSA-2fmr-2c6h-79j9.json new file mode 100644 index 00000000000..8e5440a488b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2fmr-2c6h-79j9/GHSA-2fmr-2c6h-79j9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fmr-2c6h-79j9", + "modified": "2025-05-19T15:31:01Z", + "published": "2025-05-19T15:31:01Z", + "aliases": [ + "CVE-2025-48254" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Change Add to Cart Button Text for WooCommerce allows Stored XSS. This issue affects Change Add to Cart Button Text for WooCommerce: from n/a through 2.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48254" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/add-to-cart-button-labels-for-woocommerce/vulnerability/wordpress-change-add-to-cart-button-text-for-woocommerce-2-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2j86-v657-3w4j/GHSA-2j86-v657-3w4j.json b/advisories/unreviewed/2025/05/GHSA-2j86-v657-3w4j/GHSA-2j86-v657-3w4j.json index 0dceff9f632..2af6c7b773b 100644 --- a/advisories/unreviewed/2025/05/GHSA-2j86-v657-3w4j/GHSA-2j86-v657-3w4j.json +++ b/advisories/unreviewed/2025/05/GHSA-2j86-v657-3w4j/GHSA-2j86-v657-3w4j.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-2m9r-8wqr-rccv/GHSA-2m9r-8wqr-rccv.json b/advisories/unreviewed/2025/05/GHSA-2m9r-8wqr-rccv/GHSA-2m9r-8wqr-rccv.json new file mode 100644 index 00000000000..3b3da7e8d65 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2m9r-8wqr-rccv/GHSA-2m9r-8wqr-rccv.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2m9r-8wqr-rccv", + "modified": "2025-05-19T15:30:40Z", + "published": "2025-05-19T15:30:40Z", + "aliases": [ + "CVE-2025-4782" + ], + "details": "A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /sms/admin/?page=receiving/view_receiving&id=1. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4782" + }, + { + "type": "WEB", + "url": "https://github.com/th3w0lf-1337/Vulnerabilities/blob/main/SMS-PHP/SQLi/Receiving/info.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309082" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309082" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.572195" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T15:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2mj9-934c-5ccv/GHSA-2mj9-934c-5ccv.json b/advisories/unreviewed/2025/05/GHSA-2mj9-934c-5ccv/GHSA-2mj9-934c-5ccv.json new file mode 100644 index 00000000000..e6bba42696f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2mj9-934c-5ccv/GHSA-2mj9-934c-5ccv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mj9-934c-5ccv", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48269" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts allows DOM-Based XSS. This issue affects WPAdverts: from n/a through 2.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48269" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wpadverts/vulnerability/wordpress-wpadverts-2-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2w97-78m3-mph6/GHSA-2w97-78m3-mph6.json b/advisories/unreviewed/2025/05/GHSA-2w97-78m3-mph6/GHSA-2w97-78m3-mph6.json new file mode 100644 index 00000000000..7175e06c9b0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2w97-78m3-mph6/GHSA-2w97-78m3-mph6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w97-78m3-mph6", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48277" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stylemix Cost Calculator Builder allows Stored XSS. This issue affects Cost Calculator Builder: from n/a through 3.2.74.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48277" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cost-calculator-builder/vulnerability/wordpress-cost-calculator-builder-3-2-74-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-39f6-jqc4-9rwp/GHSA-39f6-jqc4-9rwp.json b/advisories/unreviewed/2025/05/GHSA-39f6-jqc4-9rwp/GHSA-39f6-jqc4-9rwp.json new file mode 100644 index 00000000000..ef231d6377a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-39f6-jqc4-9rwp/GHSA-39f6-jqc4-9rwp.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39f6-jqc4-9rwp", + "modified": "2025-05-19T15:30:40Z", + "published": "2025-05-19T15:30:40Z", + "aliases": [ + "CVE-2025-4781" + ], + "details": "A vulnerability classified as critical has been found in PHPGurukul Park Ticketing Management System 2.0. Affected is an unknown function of the file /forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4781" + }, + { + "type": "WEB", + "url": "https://github.com/f1rstb100d/myCVE/issues/6" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309078" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309078" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.572164" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T15:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3gx9-8889-ccm7/GHSA-3gx9-8889-ccm7.json b/advisories/unreviewed/2025/05/GHSA-3gx9-8889-ccm7/GHSA-3gx9-8889-ccm7.json new file mode 100644 index 00000000000..3f1be88baa2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3gx9-8889-ccm7/GHSA-3gx9-8889-ccm7.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gx9-8889-ccm7", + "modified": "2025-05-19T15:31:00Z", + "published": "2025-05-19T15:31:00Z", + "aliases": [ + "CVE-2025-30072" + ], + "details": "Tiiwee X1 Alarm System TWX1HAKV2 allows Authentication Bypass by Capture-replay, leading to physical Access to the protected facilities without triggering an alarm.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30072" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2025-006.txt" + }, + { + "type": "WEB", + "url": "https://www.tiiwee.com/collections/x1-alarm-systems" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2025/May/20" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3j7f-43fq-vpg9/GHSA-3j7f-43fq-vpg9.json b/advisories/unreviewed/2025/05/GHSA-3j7f-43fq-vpg9/GHSA-3j7f-43fq-vpg9.json new file mode 100644 index 00000000000..651c9c0dcff --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3j7f-43fq-vpg9/GHSA-3j7f-43fq-vpg9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j7f-43fq-vpg9", + "modified": "2025-05-19T15:31:01Z", + "published": "2025-05-19T15:31:01Z", + "aliases": [ + "CVE-2025-48249" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory EAN for WooCommerce allows Stored XSS. This issue affects EAN for WooCommerce: from n/a through 5.4.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48249" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ean-for-woocommerce/vulnerability/wordpress-ean-for-woocommerce-5-4-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3p57-rq4q-233x/GHSA-3p57-rq4q-233x.json b/advisories/unreviewed/2025/05/GHSA-3p57-rq4q-233x/GHSA-3p57-rq4q-233x.json new file mode 100644 index 00000000000..111094e5fe0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3p57-rq4q-233x/GHSA-3p57-rq4q-233x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p57-rq4q-233x", + "modified": "2025-05-19T15:30:40Z", + "published": "2025-05-19T15:30:40Z", + "aliases": [ + "CVE-2025-4478" + ], + "details": "A flaw was found in the gnome-remote-desktop used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot and is likely due to a NULL pointer dereference. Rebooting is required to recover the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4478" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-4478" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2365232" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-16T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-42hp-7325-hwqx/GHSA-42hp-7325-hwqx.json b/advisories/unreviewed/2025/05/GHSA-42hp-7325-hwqx/GHSA-42hp-7325-hwqx.json new file mode 100644 index 00000000000..caae9092b8c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-42hp-7325-hwqx/GHSA-42hp-7325-hwqx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42hp-7325-hwqx", + "modified": "2025-05-19T15:31:01Z", + "published": "2025-05-19T15:31:01Z", + "aliases": [ + "CVE-2025-48240" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Cost of Goods for WooCommerce allows Stored XSS. This issue affects Cost of Goods for WooCommerce: from n/a through 3.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48240" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/cost-of-goods-for-woocommerce/vulnerability/wordpress-cost-of-goods-for-woocommerce-3-7-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-43hr-6fp9-6wgg/GHSA-43hr-6fp9-6wgg.json b/advisories/unreviewed/2025/05/GHSA-43hr-6fp9-6wgg/GHSA-43hr-6fp9-6wgg.json new file mode 100644 index 00000000000..4d18e4bef0f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-43hr-6fp9-6wgg/GHSA-43hr-6fp9-6wgg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43hr-6fp9-6wgg", + "modified": "2025-05-19T15:31:00Z", + "published": "2025-05-19T15:31:00Z", + "aliases": [ + "CVE-2024-55063" + ], + "details": "Multiple Code Injection vulnerabilities in EasyVirt DC NetScope <= 8.7.0 allows remote authenticated attackers to execute arbitrary code via the (1) lang parameter to /international/keyboard/options; the (2) keyboard_layout or (3) keyboard_variant parameter to /international/settings/keyboard; the (4) timezone parameter to /international/settings/timezone.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55063" + }, + { + "type": "WEB", + "url": "https://github.com/Elymaro/CVE/blob/main/EasyVirt/CVE-2024-55063.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-43qr-pjmr-cgfv/GHSA-43qr-pjmr-cgfv.json b/advisories/unreviewed/2025/05/GHSA-43qr-pjmr-cgfv/GHSA-43qr-pjmr-cgfv.json index b0b743eaffa..a0586f42ae9 100644 --- a/advisories/unreviewed/2025/05/GHSA-43qr-pjmr-cgfv/GHSA-43qr-pjmr-cgfv.json +++ b/advisories/unreviewed/2025/05/GHSA-43qr-pjmr-cgfv/GHSA-43qr-pjmr-cgfv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-43qr-pjmr-cgfv", - "modified": "2025-05-17T15:30:25Z", + "modified": "2025-05-19T15:30:38Z", "published": "2025-05-14T15:31:37Z", "aliases": [ "CVE-2024-54779" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://blog.brillantit.com/exploiting-pfsense-xss-command-injection-cloud-hijack" }, + { + "type": "WEB", + "url": "https://docs.netgate.com/downloads/pfSense-SA-25_01.webgui.asc" + }, { "type": "WEB", "url": "https://www.netgate.com/blog/important-security-updates-for-pfsense-plus-24.11-and-ce-2.7.2" diff --git a/advisories/unreviewed/2025/05/GHSA-48v5-2vrv-8g64/GHSA-48v5-2vrv-8g64.json b/advisories/unreviewed/2025/05/GHSA-48v5-2vrv-8g64/GHSA-48v5-2vrv-8g64.json index d8c8de88930..d67252c1f42 100644 --- a/advisories/unreviewed/2025/05/GHSA-48v5-2vrv-8g64/GHSA-48v5-2vrv-8g64.json +++ b/advisories/unreviewed/2025/05/GHSA-48v5-2vrv-8g64/GHSA-48v5-2vrv-8g64.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-4f4p-52mc-m3g8/GHSA-4f4p-52mc-m3g8.json b/advisories/unreviewed/2025/05/GHSA-4f4p-52mc-m3g8/GHSA-4f4p-52mc-m3g8.json new file mode 100644 index 00000000000..db53c62de5d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4f4p-52mc-m3g8/GHSA-4f4p-52mc-m3g8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f4p-52mc-m3g8", + "modified": "2025-05-19T15:31:01Z", + "published": "2025-05-19T15:31:01Z", + "aliases": [ + "CVE-2025-48243" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Bill Minozzi reCAPTCHA for all allows Cross Site Request Forgery. This issue affects reCAPTCHA for all: from n/a through 2.26.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48243" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/recaptcha-for-all/vulnerability/wordpress-recaptcha-for-all-2-26-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4h92-m3v8-rjmc/GHSA-4h92-m3v8-rjmc.json b/advisories/unreviewed/2025/05/GHSA-4h92-m3v8-rjmc/GHSA-4h92-m3v8-rjmc.json new file mode 100644 index 00000000000..69996638ca4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4h92-m3v8-rjmc/GHSA-4h92-m3v8-rjmc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4h92-m3v8-rjmc", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48259" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Juan Carlos WP Mapa Politico España allows Cross Site Request Forgery. This issue affects WP Mapa Politico España: from n/a through 3.8.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48259" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-mapa-politico-spain/vulnerability/wordpress-wp-mapa-politico-espana-plugin-3-8-0-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4h9h-538f-3p9h/GHSA-4h9h-538f-3p9h.json b/advisories/unreviewed/2025/05/GHSA-4h9h-538f-3p9h/GHSA-4h9h-538f-3p9h.json new file mode 100644 index 00000000000..ca082fc9238 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4h9h-538f-3p9h/GHSA-4h9h-538f-3p9h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4h9h-538f-3p9h", + "modified": "2025-05-19T15:31:01Z", + "published": "2025-05-19T15:31:01Z", + "aliases": [ + "CVE-2025-48247" + ], + "details": "Missing Authorization vulnerability in Blair Williams Shortlinks by Pretty Links allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Shortlinks by Pretty Links: from n/a through 3.6.15.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48247" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/pretty-link/vulnerability/wordpress-shortlinks-by-pretty-links-3-6-15-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4mmg-25h6-f798/GHSA-4mmg-25h6-f798.json b/advisories/unreviewed/2025/05/GHSA-4mmg-25h6-f798/GHSA-4mmg-25h6-f798.json new file mode 100644 index 00000000000..08294d235f4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4mmg-25h6-f798/GHSA-4mmg-25h6-f798.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mmg-25h6-f798", + "modified": "2025-05-19T15:30:57Z", + "published": "2025-05-19T15:30:57Z", + "aliases": [ + "CVE-2025-4933" + ], + "details": "A vulnerability, which was classified as critical, was found in ponaravindb Hospital-Management-System 1.0. This affects an unknown part of the file /doctor-panel.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4933" + }, + { + "type": "WEB", + "url": "https://github.com/zylv0002/SQLi-ponaravindb-HMS" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309495" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309495" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.579678" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T13:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-536f-5mf3-xj62/GHSA-536f-5mf3-xj62.json b/advisories/unreviewed/2025/05/GHSA-536f-5mf3-xj62/GHSA-536f-5mf3-xj62.json new file mode 100644 index 00000000000..72e8d230b1d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-536f-5mf3-xj62/GHSA-536f-5mf3-xj62.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-536f-5mf3-xj62", + "modified": "2025-05-19T15:31:01Z", + "published": "2025-05-19T15:31:01Z", + "aliases": [ + "CVE-2025-48239" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Product Notes Tab & Private Admin Notes for WooCommerce allows Stored XSS. This issue affects Product Notes Tab & Private Admin Notes for WooCommerce: from n/a through 3.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48239" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/product-notes-for-woocommerce/vulnerability/wordpress-product-notes-tab-private-admin-notes-for-woocommerce-3-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5fc3-jmj8-2xvr/GHSA-5fc3-jmj8-2xvr.json b/advisories/unreviewed/2025/05/GHSA-5fc3-jmj8-2xvr/GHSA-5fc3-jmj8-2xvr.json new file mode 100644 index 00000000000..3da272cd1b6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5fc3-jmj8-2xvr/GHSA-5fc3-jmj8-2xvr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fc3-jmj8-2xvr", + "modified": "2025-05-19T15:31:00Z", + "published": "2025-05-19T15:31:00Z", + "aliases": [ + "CVE-2025-48233" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in affmngr Affiliates Manager Google reCAPTCHA Integration allows Stored XSS. This issue affects Affiliates Manager Google reCAPTCHA Integration: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48233" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/affiliates-manager-google-recaptcha-integration/vulnerability/wordpress-affiliates-manager-google-recaptcha-integration-plugin-1-0-6-cross-site-request-forgery-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5xjm-gxc3-2jcj/GHSA-5xjm-gxc3-2jcj.json b/advisories/unreviewed/2025/05/GHSA-5xjm-gxc3-2jcj/GHSA-5xjm-gxc3-2jcj.json new file mode 100644 index 00000000000..fde30901e7b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5xjm-gxc3-2jcj/GHSA-5xjm-gxc3-2jcj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xjm-gxc3-2jcj", + "modified": "2025-05-19T15:31:01Z", + "published": "2025-05-19T15:31:00Z", + "aliases": [ + "CVE-2025-48236" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bunny.net bunny.net allows Stored XSS. This issue affects bunny.net: from n/a through 2.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48236" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bunnycdn/vulnerability/wordpress-bunny-net-2-3-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-69ff-p6qw-gw54/GHSA-69ff-p6qw-gw54.json b/advisories/unreviewed/2025/05/GHSA-69ff-p6qw-gw54/GHSA-69ff-p6qw-gw54.json new file mode 100644 index 00000000000..e3d292ee729 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-69ff-p6qw-gw54/GHSA-69ff-p6qw-gw54.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69ff-p6qw-gw54", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48288" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor allows Stored XSS. This issue affects ElementInvader Addons for Elementor: from n/a through 1.3.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48288" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/elementinvader-addons-for-elementor/vulnerability/wordpress-elementinvader-addons-for-elementor-1-3-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-74qj-hh4h-8ffm/GHSA-74qj-hh4h-8ffm.json b/advisories/unreviewed/2025/05/GHSA-74qj-hh4h-8ffm/GHSA-74qj-hh4h-8ffm.json new file mode 100644 index 00000000000..dba84a43920 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-74qj-hh4h-8ffm/GHSA-74qj-hh4h-8ffm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74qj-hh4h-8ffm", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48272" + ], + "details": "Missing Authorization vulnerability in wpjobportal WP Job Portal allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Job Portal: from n/a through 2.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48272" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-job-portal/vulnerability/wordpress-wp-job-portal-2-3-2-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-78gr-w2ph-m22p/GHSA-78gr-w2ph-m22p.json b/advisories/unreviewed/2025/05/GHSA-78gr-w2ph-m22p/GHSA-78gr-w2ph-m22p.json new file mode 100644 index 00000000000..c8d7c994859 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-78gr-w2ph-m22p/GHSA-78gr-w2ph-m22p.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78gr-w2ph-m22p", + "modified": "2025-05-19T15:30:59Z", + "published": "2025-05-19T15:30:59Z", + "aliases": [ + "CVE-2025-4934" + ], + "details": "A vulnerability has been found in PHPGurukul User Registration & Login and User Management System 3.3 and classified as critical. This vulnerability affects unknown code of the file /edit-profile.php. The manipulation of the argument Contact leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4934" + }, + { + "type": "WEB", + "url": "https://github.com/LitBot123/mycve/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309496" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309496" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.579759" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T14:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7m8r-4pgh-wxhw/GHSA-7m8r-4pgh-wxhw.json b/advisories/unreviewed/2025/05/GHSA-7m8r-4pgh-wxhw/GHSA-7m8r-4pgh-wxhw.json new file mode 100644 index 00000000000..7f3353e0215 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7m8r-4pgh-wxhw/GHSA-7m8r-4pgh-wxhw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m8r-4pgh-wxhw", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48265" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Pektsekye Year Make Model Search for WooCommerce allows Cross Site Request Forgery. This issue affects Year Make Model Search for WooCommerce: from n/a through 1.0.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48265" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ymm-search/vulnerability/wordpress-year-make-model-search-for-woocommerce-plugin-1-0-11-cross-site-request-forgery-csrf-to-settings-change-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7q3w-f4rc-vr9m/GHSA-7q3w-f4rc-vr9m.json b/advisories/unreviewed/2025/05/GHSA-7q3w-f4rc-vr9m/GHSA-7q3w-f4rc-vr9m.json index 8ec2dd83037..d9979af2484 100644 --- a/advisories/unreviewed/2025/05/GHSA-7q3w-f4rc-vr9m/GHSA-7q3w-f4rc-vr9m.json +++ b/advisories/unreviewed/2025/05/GHSA-7q3w-f4rc-vr9m/GHSA-7q3w-f4rc-vr9m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-401" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-7qj7-8mqv-3fr7/GHSA-7qj7-8mqv-3fr7.json b/advisories/unreviewed/2025/05/GHSA-7qj7-8mqv-3fr7/GHSA-7qj7-8mqv-3fr7.json new file mode 100644 index 00000000000..44cb933b6cd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7qj7-8mqv-3fr7/GHSA-7qj7-8mqv-3fr7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qj7-8mqv-3fr7", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48262" + ], + "details": "Missing Authorization vulnerability in Michael Revellin-Clerc Url Rewrite Analyzer allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Url Rewrite Analyzer: from n/a through 1.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48262" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/url-rewrite-analyzer/vulnerability/wordpress-url-rewrite-analyzer-1-3-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7rcm-4jcj-r4q6/GHSA-7rcm-4jcj-r4q6.json b/advisories/unreviewed/2025/05/GHSA-7rcm-4jcj-r4q6/GHSA-7rcm-4jcj-r4q6.json index 3f4f7090cef..20e3c65237b 100644 --- a/advisories/unreviewed/2025/05/GHSA-7rcm-4jcj-r4q6/GHSA-7rcm-4jcj-r4q6.json +++ b/advisories/unreviewed/2025/05/GHSA-7rcm-4jcj-r4q6/GHSA-7rcm-4jcj-r4q6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7rcm-4jcj-r4q6", - "modified": "2025-05-18T15:30:20Z", + "modified": "2025-05-19T15:30:51Z", "published": "2025-05-18T15:30:20Z", "aliases": [ "CVE-2025-48219" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://www.etsi.org/deliver/etsi_ts/124200_124299/124229/15.10.00_60/ts_124229v151000p.pdf" + }, + { + "type": "WEB", + "url": "https://www.ispreview.co.uk/index.php/2025/05/o2-uk-fixes-volte-flaw-that-exposed-user-mobile-location-data.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-857j-r974-fpc4/GHSA-857j-r974-fpc4.json b/advisories/unreviewed/2025/05/GHSA-857j-r974-fpc4/GHSA-857j-r974-fpc4.json new file mode 100644 index 00000000000..cce4eb861ca --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-857j-r974-fpc4/GHSA-857j-r974-fpc4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-857j-r974-fpc4", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48266" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 Active Products Tables for WooCommerce allows Stored XSS. This issue affects Active Products Tables for WooCommerce: from n/a through 1.0.6.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48266" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/profit-products-tables-for-woocommerce/vulnerability/wordpress-active-products-tables-for-woocommerce-1-0-6-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-85m3-mg8g-54v6/GHSA-85m3-mg8g-54v6.json b/advisories/unreviewed/2025/05/GHSA-85m3-mg8g-54v6/GHSA-85m3-mg8g-54v6.json new file mode 100644 index 00000000000..6dcfc75b056 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-85m3-mg8g-54v6/GHSA-85m3-mg8g-54v6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85m3-mg8g-54v6", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48276" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder allows Stored XSS. This issue affects Visual Composer Website Builder: from n/a through 45.11.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48276" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/visualcomposer/vulnerability/wordpress-visual-composer-website-builder-45-11-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8g92-fqgw-q495/GHSA-8g92-fqgw-q495.json b/advisories/unreviewed/2025/05/GHSA-8g92-fqgw-q495/GHSA-8g92-fqgw-q495.json new file mode 100644 index 00000000000..5e4f3c4d418 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8g92-fqgw-q495/GHSA-8g92-fqgw-q495.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g92-fqgw-q495", + "modified": "2025-05-19T15:30:59Z", + "published": "2025-05-19T15:30:59Z", + "aliases": [ + "CVE-2025-44108" + ], + "details": "A stored Cross-Site Scripting (XSS) vulnerability exists in the administration panel of Flatpress CMS before 1.4 via the gallery captions component. An attacker with admin privileges can inject a malicious JavaScript payload into the system, which is then stored persistently.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44108" + }, + { + "type": "WEB", + "url": "https://github.com/flatpressblog/flatpress/commit/24a6feacf1747ec19725b52c097715c8ab9c4559" + }, + { + "type": "WEB", + "url": "https://github.com/flatpressblog/flatpress/releases/tag/1.3.1" + }, + { + "type": "WEB", + "url": "https://github.com/flatpressblog/flatpress/releases/tag/1.4.rc2" + }, + { + "type": "WEB", + "url": "https://harish0x.github.io/blog/CVE-2025-44108" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8p9j-879p-799j/GHSA-8p9j-879p-799j.json b/advisories/unreviewed/2025/05/GHSA-8p9j-879p-799j/GHSA-8p9j-879p-799j.json new file mode 100644 index 00000000000..ff6a107efb3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8p9j-879p-799j/GHSA-8p9j-879p-799j.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p9j-879p-799j", + "modified": "2025-05-19T15:30:59Z", + "published": "2025-05-19T15:30:59Z", + "aliases": [ + "CVE-2025-28371" + ], + "details": "EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function. The device fails to validate the current password, allowing an attacker to submit a password change request with an invalid current password and set a new password.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28371" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1kQFOyFQYycKynIBjbU8bMx2gYTG3Bxi2/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://pastebin.com/raw/EnL1XT2n" + }, + { + "type": "WEB", + "url": "https://pastebin.com/raw/hziq1nGH" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T14:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8q84-3937-w4rx/GHSA-8q84-3937-w4rx.json b/advisories/unreviewed/2025/05/GHSA-8q84-3937-w4rx/GHSA-8q84-3937-w4rx.json index 4ed2982391c..e5b690a0b64 100644 --- a/advisories/unreviewed/2025/05/GHSA-8q84-3937-w4rx/GHSA-8q84-3937-w4rx.json +++ b/advisories/unreviewed/2025/05/GHSA-8q84-3937-w4rx/GHSA-8q84-3937-w4rx.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-8vfx-w466-r4hp/GHSA-8vfx-w466-r4hp.json b/advisories/unreviewed/2025/05/GHSA-8vfx-w466-r4hp/GHSA-8vfx-w466-r4hp.json new file mode 100644 index 00000000000..aff98fa4acc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8vfx-w466-r4hp/GHSA-8vfx-w466-r4hp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vfx-w466-r4hp", + "modified": "2025-05-19T15:31:01Z", + "published": "2025-05-19T15:31:01Z", + "aliases": [ + "CVE-2025-48250" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Coupons & Add to Cart by URL Links for WooCommerce allows Stored XSS. This issue affects Coupons & Add to Cart by URL Links for WooCommerce: from n/a through 1.7.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48250" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/url-coupons-for-woocommerce-by-algoritmika/vulnerability/wordpress-coupons-add-to-cart-by-url-links-for-woocommerce-1-7-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-938p-4c9x-3mpw/GHSA-938p-4c9x-3mpw.json b/advisories/unreviewed/2025/05/GHSA-938p-4c9x-3mpw/GHSA-938p-4c9x-3mpw.json index 936389db8b5..2eda9e37c2c 100644 --- a/advisories/unreviewed/2025/05/GHSA-938p-4c9x-3mpw/GHSA-938p-4c9x-3mpw.json +++ b/advisories/unreviewed/2025/05/GHSA-938p-4c9x-3mpw/GHSA-938p-4c9x-3mpw.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-cpr4-r4g2-phc7/GHSA-cpr4-r4g2-phc7.json b/advisories/unreviewed/2025/05/GHSA-cpr4-r4g2-phc7/GHSA-cpr4-r4g2-phc7.json new file mode 100644 index 00000000000..9b098c80cdb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cpr4-r4g2-phc7/GHSA-cpr4-r4g2-phc7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpr4-r4g2-phc7", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48258" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jetmonsters Mega Menu Block allows Stored XSS. This issue affects Mega Menu Block: from n/a through 1.0.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48258" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/getwid-megamenu/vulnerability/wordpress-mega-menu-block-1-0-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f89j-4hpj-5qjm/GHSA-f89j-4hpj-5qjm.json b/advisories/unreviewed/2025/05/GHSA-f89j-4hpj-5qjm/GHSA-f89j-4hpj-5qjm.json index 18d8c8f9fd5..db7fadd27d4 100644 --- a/advisories/unreviewed/2025/05/GHSA-f89j-4hpj-5qjm/GHSA-f89j-4hpj-5qjm.json +++ b/advisories/unreviewed/2025/05/GHSA-f89j-4hpj-5qjm/GHSA-f89j-4hpj-5qjm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f89j-4hpj-5qjm", - "modified": "2025-05-14T21:31:19Z", + "modified": "2025-05-19T15:30:39Z", "published": "2025-05-14T21:31:19Z", "aliases": [ "CVE-2024-45516" ], "details": "An issue was discovered in Zimbra Collaboration (ZCS) 9.0.0 before Patch 43, 10.0.x before 10.0.12, 10.1.x before 10.1.4, and 8.8.15 before Patch 47. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the victim's session, potentially leading to unauthorized access to sensitive information. This issue arises from insufficient sanitization of HTML content, including malformed tags with embedded JavaScript. The vulnerability is triggered when the victim views a specially crafted email in the Classic UI, causing the malicious script to execute. No further user interaction is required beyond viewing the email.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T20:15:20Z" diff --git a/advisories/unreviewed/2025/05/GHSA-f8vr-vg6x-hfpr/GHSA-f8vr-vg6x-hfpr.json b/advisories/unreviewed/2025/05/GHSA-f8vr-vg6x-hfpr/GHSA-f8vr-vg6x-hfpr.json index f0fc8a35d26..ebed74374ef 100644 --- a/advisories/unreviewed/2025/05/GHSA-f8vr-vg6x-hfpr/GHSA-f8vr-vg6x-hfpr.json +++ b/advisories/unreviewed/2025/05/GHSA-f8vr-vg6x-hfpr/GHSA-f8vr-vg6x-hfpr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f8vr-vg6x-hfpr", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-19T15:30:39Z", "published": "2025-05-15T21:31:31Z", "aliases": [ "CVE-2024-3062" ], "details": "The Save as Image Plugin by Pdfcrowd WordPress plugin before 3.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:53Z" diff --git a/advisories/unreviewed/2025/05/GHSA-fm8h-3cch-f289/GHSA-fm8h-3cch-f289.json b/advisories/unreviewed/2025/05/GHSA-fm8h-3cch-f289/GHSA-fm8h-3cch-f289.json new file mode 100644 index 00000000000..76574a1a8ee --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fm8h-3cch-f289/GHSA-fm8h-3cch-f289.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm8h-3cch-f289", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48282" + ], + "details": "Missing Authorization vulnerability in Majestic Support Majestic Support allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Majestic Support: from n/a through 1.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48282" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/majestic-support/vulnerability/wordpress-majestic-support-1-1-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fp2g-4h6f-28h2/GHSA-fp2g-4h6f-28h2.json b/advisories/unreviewed/2025/05/GHSA-fp2g-4h6f-28h2/GHSA-fp2g-4h6f-28h2.json new file mode 100644 index 00000000000..32544d4ca2a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fp2g-4h6f-28h2/GHSA-fp2g-4h6f-28h2.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp2g-4h6f-28h2", + "modified": "2025-05-19T15:31:00Z", + "published": "2025-05-19T15:31:00Z", + "aliases": [ + "CVE-2025-3908" + ], + "details": "The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permissions of that destination directory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3908" + }, + { + "type": "WEB", + "url": "https://community.openvpn.net/Security%20Announcements/CVE-2025-3908" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fww9-frrw-h6q2/GHSA-fww9-frrw-h6q2.json b/advisories/unreviewed/2025/05/GHSA-fww9-frrw-h6q2/GHSA-fww9-frrw-h6q2.json index 3124e81ba59..9132907454b 100644 --- a/advisories/unreviewed/2025/05/GHSA-fww9-frrw-h6q2/GHSA-fww9-frrw-h6q2.json +++ b/advisories/unreviewed/2025/05/GHSA-fww9-frrw-h6q2/GHSA-fww9-frrw-h6q2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fww9-frrw-h6q2", - "modified": "2025-05-19T06:30:36Z", + "modified": "2025-05-19T15:30:54Z", "published": "2025-05-19T06:30:36Z", "aliases": [ "CVE-2025-2524" ], "details": "The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-19T06:15:19Z" diff --git a/advisories/unreviewed/2025/05/GHSA-g396-3cc5-qh6g/GHSA-g396-3cc5-qh6g.json b/advisories/unreviewed/2025/05/GHSA-g396-3cc5-qh6g/GHSA-g396-3cc5-qh6g.json new file mode 100644 index 00000000000..86850736341 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g396-3cc5-qh6g/GHSA-g396-3cc5-qh6g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g396-3cc5-qh6g", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48341" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Maker by 10Web allows Stored XSS. This issue affects Form Maker by 10Web: from n/a through 1.15.33.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48341" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/form-maker/vulnerability/wordpress-form-maker-by-10web-1-15-33-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g3qx-rm6q-4cv4/GHSA-g3qx-rm6q-4cv4.json b/advisories/unreviewed/2025/05/GHSA-g3qx-rm6q-4cv4/GHSA-g3qx-rm6q-4cv4.json new file mode 100644 index 00000000000..4a42ed67aba --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g3qx-rm6q-4cv4/GHSA-g3qx-rm6q-4cv4.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3qx-rm6q-4cv4", + "modified": "2025-05-19T15:30:58Z", + "published": "2025-05-19T15:30:58Z", + "aliases": [ + "CVE-2024-4878" + ], + "details": "Rejected reason: Unused CVE record, incorrectly reserved", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4878" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g73v-4c9j-8g2p/GHSA-g73v-4c9j-8g2p.json b/advisories/unreviewed/2025/05/GHSA-g73v-4c9j-8g2p/GHSA-g73v-4c9j-8g2p.json new file mode 100644 index 00000000000..b0e3e526418 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g73v-4c9j-8g2p/GHSA-g73v-4c9j-8g2p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g73v-4c9j-8g2p", + "modified": "2025-05-19T15:31:01Z", + "published": "2025-05-19T15:31:01Z", + "aliases": [ + "CVE-2025-48238" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in awcode AWcode Toolkit allows Stored XSS. This issue affects AWcode Toolkit: from n/a through 1.0.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48238" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/awcode-toolkit/vulnerability/wordpress-awcode-toolkit-plugin-1-0-18-cross-site-request-forgery-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g7vx-258p-5gcp/GHSA-g7vx-258p-5gcp.json b/advisories/unreviewed/2025/05/GHSA-g7vx-258p-5gcp/GHSA-g7vx-258p-5gcp.json new file mode 100644 index 00000000000..2baefe5370e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g7vx-258p-5gcp/GHSA-g7vx-258p-5gcp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7vx-258p-5gcp", + "modified": "2025-05-19T15:31:01Z", + "published": "2025-05-19T15:31:01Z", + "aliases": [ + "CVE-2025-48242" + ], + "details": "Missing Authorization vulnerability in wpWax Legal Pages allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Legal Pages: from n/a through 1.4.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48242" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/legal-pages/vulnerability/wordpress-legal-pages-1-4-5-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g9pq-w83x-6p92/GHSA-g9pq-w83x-6p92.json b/advisories/unreviewed/2025/05/GHSA-g9pq-w83x-6p92/GHSA-g9pq-w83x-6p92.json index 1be847044a9..daa9fcc2476 100644 --- a/advisories/unreviewed/2025/05/GHSA-g9pq-w83x-6p92/GHSA-g9pq-w83x-6p92.json +++ b/advisories/unreviewed/2025/05/GHSA-g9pq-w83x-6p92/GHSA-g9pq-w83x-6p92.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g9pq-w83x-6p92", - "modified": "2025-05-19T06:30:36Z", + "modified": "2025-05-19T15:30:54Z", "published": "2025-05-19T06:30:36Z", "aliases": [ "CVE-2025-2560" ], "details": "The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-19T06:15:19Z" diff --git a/advisories/unreviewed/2025/05/GHSA-gcf6-vgcr-474f/GHSA-gcf6-vgcr-474f.json b/advisories/unreviewed/2025/05/GHSA-gcf6-vgcr-474f/GHSA-gcf6-vgcr-474f.json index a77b7847610..300835cc2a3 100644 --- a/advisories/unreviewed/2025/05/GHSA-gcf6-vgcr-474f/GHSA-gcf6-vgcr-474f.json +++ b/advisories/unreviewed/2025/05/GHSA-gcf6-vgcr-474f/GHSA-gcf6-vgcr-474f.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-401" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-gfj3-q5hw-vpv9/GHSA-gfj3-q5hw-vpv9.json b/advisories/unreviewed/2025/05/GHSA-gfj3-q5hw-vpv9/GHSA-gfj3-q5hw-vpv9.json new file mode 100644 index 00000000000..b51be3c58de --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gfj3-q5hw-vpv9/GHSA-gfj3-q5hw-vpv9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfj3-q5hw-vpv9", + "modified": "2025-05-19T15:31:01Z", + "published": "2025-05-19T15:31:01Z", + "aliases": [ + "CVE-2025-48248" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Sitewide Discount for WooCommerce: Apply Discount to All Products allows Stored XSS. This issue affects Sitewide Discount for WooCommerce: Apply Discount to All Products: from n/a through 2.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48248" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/global-shop-discount-for-woocommerce/vulnerability/wordpress-sitewide-discount-for-woocommerce-apply-discount-to-all-products-2-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gp6h-4cq7-x6fq/GHSA-gp6h-4cq7-x6fq.json b/advisories/unreviewed/2025/05/GHSA-gp6h-4cq7-x6fq/GHSA-gp6h-4cq7-x6fq.json new file mode 100644 index 00000000000..82a966d35dc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gp6h-4cq7-x6fq/GHSA-gp6h-4cq7-x6fq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gp6h-4cq7-x6fq", + "modified": "2025-05-19T15:31:01Z", + "published": "2025-05-19T15:31:01Z", + "aliases": [ + "CVE-2025-48253" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Free Shipping Bar: Amount Left for Free Shipping for WooCommerce allows Stored XSS. This issue affects Free Shipping Bar: Amount Left for Free Shipping for WooCommerce: from n/a through 2.4.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48253" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/amount-left-free-shipping-woocommerce/vulnerability/wordpress-free-shipping-bar-amount-left-for-free-shipping-for-woocommerce-2-4-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h49j-3qg4-9jxw/GHSA-h49j-3qg4-9jxw.json b/advisories/unreviewed/2025/05/GHSA-h49j-3qg4-9jxw/GHSA-h49j-3qg4-9jxw.json new file mode 100644 index 00000000000..541edb9abf5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h49j-3qg4-9jxw/GHSA-h49j-3qg4-9jxw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h49j-3qg4-9jxw", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48260" + ], + "details": "Missing Authorization vulnerability in Ninja Team GDPR CCPA Compliance Support allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GDPR CCPA Compliance Support: from n/a through 2.7.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48260" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ninja-gdpr-compliance/vulnerability/wordpress-gdpr-ccpa-compliance-support-2-7-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h53g-gc6r-59pf/GHSA-h53g-gc6r-59pf.json b/advisories/unreviewed/2025/05/GHSA-h53g-gc6r-59pf/GHSA-h53g-gc6r-59pf.json new file mode 100644 index 00000000000..b4b64f73b14 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h53g-gc6r-59pf/GHSA-h53g-gc6r-59pf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h53g-gc6r-59pf", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48263" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MultiVendorX MultiVendorX allows Stored XSS. This issue affects MultiVendorX: from n/a through 4.2.22.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48263" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/dc-woocommerce-multi-vendor/vulnerability/wordpress-multivendorx-4-2-22-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h5vf-4rpp-pjc8/GHSA-h5vf-4rpp-pjc8.json b/advisories/unreviewed/2025/05/GHSA-h5vf-4rpp-pjc8/GHSA-h5vf-4rpp-pjc8.json index a1f7c0c5451..dece53cc238 100644 --- a/advisories/unreviewed/2025/05/GHSA-h5vf-4rpp-pjc8/GHSA-h5vf-4rpp-pjc8.json +++ b/advisories/unreviewed/2025/05/GHSA-h5vf-4rpp-pjc8/GHSA-h5vf-4rpp-pjc8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h5vf-4rpp-pjc8", - "modified": "2025-05-19T06:30:36Z", + "modified": "2025-05-19T15:30:54Z", "published": "2025-05-19T06:30:36Z", "aliases": [ "CVE-2025-2561" ], "details": "The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-19T06:15:19Z" diff --git a/advisories/unreviewed/2025/05/GHSA-h8vr-q495-8mwj/GHSA-h8vr-q495-8mwj.json b/advisories/unreviewed/2025/05/GHSA-h8vr-q495-8mwj/GHSA-h8vr-q495-8mwj.json index a3221d08a38..df054a2a5ac 100644 --- a/advisories/unreviewed/2025/05/GHSA-h8vr-q495-8mwj/GHSA-h8vr-q495-8mwj.json +++ b/advisories/unreviewed/2025/05/GHSA-h8vr-q495-8mwj/GHSA-h8vr-q495-8mwj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h8vr-q495-8mwj", - "modified": "2025-05-14T18:30:50Z", + "modified": "2025-05-19T15:30:39Z", "published": "2025-05-14T18:30:50Z", "aliases": [ "CVE-2025-47710" ], "details": "Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-288" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T17:15:50Z" diff --git a/advisories/unreviewed/2025/05/GHSA-hgm8-3fqg-vm48/GHSA-hgm8-3fqg-vm48.json b/advisories/unreviewed/2025/05/GHSA-hgm8-3fqg-vm48/GHSA-hgm8-3fqg-vm48.json new file mode 100644 index 00000000000..e626986e69f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hgm8-3fqg-vm48/GHSA-hgm8-3fqg-vm48.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgm8-3fqg-vm48", + "modified": "2025-05-19T15:31:03Z", + "published": "2025-05-19T15:31:03Z", + "aliases": [ + "CVE-2025-48344" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ed4becky Rootspersona allows Cross Site Request Forgery. This issue affects Rootspersona: from n/a through 3.7.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48344" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rootspersona/vulnerability/wordpress-rootspersona-3-7-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hjrr-xg22-g28q/GHSA-hjrr-xg22-g28q.json b/advisories/unreviewed/2025/05/GHSA-hjrr-xg22-g28q/GHSA-hjrr-xg22-g28q.json new file mode 100644 index 00000000000..9052668f72c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hjrr-xg22-g28q/GHSA-hjrr-xg22-g28q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjrr-xg22-g28q", + "modified": "2025-05-19T15:31:01Z", + "published": "2025-05-19T15:31:01Z", + "aliases": [ + "CVE-2025-48252" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Back Button Widget allows Stored XSS. This issue affects Back Button Widget: from n/a through 1.6.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48252" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/back-button-widget/vulnerability/wordpress-back-button-widget-1-6-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j8jm-mfcc-3cwx/GHSA-j8jm-mfcc-3cwx.json b/advisories/unreviewed/2025/05/GHSA-j8jm-mfcc-3cwx/GHSA-j8jm-mfcc-3cwx.json new file mode 100644 index 00000000000..c7955f0c47e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j8jm-mfcc-3cwx/GHSA-j8jm-mfcc-3cwx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8jm-mfcc-3cwx", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48264" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in artiosmedia Product Code for WooCommerce allows Cross Site Request Forgery. This issue affects Product Code for WooCommerce: from n/a through 1.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48264" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/product-code-for-woocommerce/vulnerability/wordpress-product-code-for-woocommerce-plugin-1-5-0-csrf-to-database-update-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jfgc-xwhp-r9rr/GHSA-jfgc-xwhp-r9rr.json b/advisories/unreviewed/2025/05/GHSA-jfgc-xwhp-r9rr/GHSA-jfgc-xwhp-r9rr.json new file mode 100644 index 00000000000..ad198225c10 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jfgc-xwhp-r9rr/GHSA-jfgc-xwhp-r9rr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfgc-xwhp-r9rr", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48268" + ], + "details": "Missing Authorization vulnerability in Guru Team Bot for Telegram on WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bot for Telegram on WooCommerce: from n/a through 1.2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48268" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bot-for-telegram-on-woocommerce/vulnerability/wordpress-bot-for-telegram-on-woocommerce-1-2-6-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m3r9-g8hh-v79g/GHSA-m3r9-g8hh-v79g.json b/advisories/unreviewed/2025/05/GHSA-m3r9-g8hh-v79g/GHSA-m3r9-g8hh-v79g.json new file mode 100644 index 00000000000..06da3b35fc7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m3r9-g8hh-v79g/GHSA-m3r9-g8hh-v79g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3r9-g8hh-v79g", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48256" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xylus Themes Import Social Events allows Stored XSS. This issue affects Import Social Events: from n/a through 1.8.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48256" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/import-facebook-events/vulnerability/wordpress-import-social-events-1-8-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mgxw-4c3p-hwg4/GHSA-mgxw-4c3p-hwg4.json b/advisories/unreviewed/2025/05/GHSA-mgxw-4c3p-hwg4/GHSA-mgxw-4c3p-hwg4.json index 5b336411989..4ee0d02b7e6 100644 --- a/advisories/unreviewed/2025/05/GHSA-mgxw-4c3p-hwg4/GHSA-mgxw-4c3p-hwg4.json +++ b/advisories/unreviewed/2025/05/GHSA-mgxw-4c3p-hwg4/GHSA-mgxw-4c3p-hwg4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mgxw-4c3p-hwg4", - "modified": "2025-05-19T06:30:36Z", + "modified": "2025-05-19T15:30:54Z", "published": "2025-05-19T06:30:36Z", "aliases": [ "CVE-2025-1627" ], "details": "The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-19T06:15:18Z" diff --git a/advisories/unreviewed/2025/05/GHSA-mhq7-845r-m6gh/GHSA-mhq7-845r-m6gh.json b/advisories/unreviewed/2025/05/GHSA-mhq7-845r-m6gh/GHSA-mhq7-845r-m6gh.json index 24c936a74c9..a3c1c1271a1 100644 --- a/advisories/unreviewed/2025/05/GHSA-mhq7-845r-m6gh/GHSA-mhq7-845r-m6gh.json +++ b/advisories/unreviewed/2025/05/GHSA-mhq7-845r-m6gh/GHSA-mhq7-845r-m6gh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mhq7-845r-m6gh", - "modified": "2025-05-19T06:30:35Z", + "modified": "2025-05-19T15:30:54Z", "published": "2025-05-19T06:30:35Z", "aliases": [ "CVE-2025-1625" ], "details": "The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Counter block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-19T06:15:17Z" diff --git a/advisories/unreviewed/2025/05/GHSA-mqhr-6wmj-4wqg/GHSA-mqhr-6wmj-4wqg.json b/advisories/unreviewed/2025/05/GHSA-mqhr-6wmj-4wqg/GHSA-mqhr-6wmj-4wqg.json index e4d6ea618a3..f7951466819 100644 --- a/advisories/unreviewed/2025/05/GHSA-mqhr-6wmj-4wqg/GHSA-mqhr-6wmj-4wqg.json +++ b/advisories/unreviewed/2025/05/GHSA-mqhr-6wmj-4wqg/GHSA-mqhr-6wmj-4wqg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mqhr-6wmj-4wqg", - "modified": "2025-05-14T18:30:50Z", + "modified": "2025-05-19T15:30:39Z", "published": "2025-05-14T18:30:50Z", "aliases": [ "CVE-2025-47709" ], "details": "Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T17:15:50Z" diff --git a/advisories/unreviewed/2025/05/GHSA-mrm5-rcc3-c57j/GHSA-mrm5-rcc3-c57j.json b/advisories/unreviewed/2025/05/GHSA-mrm5-rcc3-c57j/GHSA-mrm5-rcc3-c57j.json new file mode 100644 index 00000000000..fcb3e144f2f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mrm5-rcc3-c57j/GHSA-mrm5-rcc3-c57j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrm5-rcc3-c57j", + "modified": "2025-05-19T15:31:01Z", + "published": "2025-05-19T15:31:00Z", + "aliases": [ + "CVE-2025-48235" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bogdan Bendziukov WP Image Mask allows DOM-Based XSS. This issue affects WP Image Mask: from n/a through 3.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48235" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-image-mask/vulnerability/wordpress-wp-image-mask-3-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pf2r-7m8j-fr73/GHSA-pf2r-7m8j-fr73.json b/advisories/unreviewed/2025/05/GHSA-pf2r-7m8j-fr73/GHSA-pf2r-7m8j-fr73.json new file mode 100644 index 00000000000..15f527d1c12 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pf2r-7m8j-fr73/GHSA-pf2r-7m8j-fr73.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf2r-7m8j-fr73", + "modified": "2025-05-19T15:31:01Z", + "published": "2025-05-19T15:31:00Z", + "aliases": [ + "CVE-2025-48237" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist for WooCommerce allows Stored XSS. This issue affects Wishlist for WooCommerce: from n/a through 3.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48237" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wish-list-for-woocommerce/vulnerability/wordpress-wishlist-for-woocommerce-3-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pfwq-w8h6-7g84/GHSA-pfwq-w8h6-7g84.json b/advisories/unreviewed/2025/05/GHSA-pfwq-w8h6-7g84/GHSA-pfwq-w8h6-7g84.json new file mode 100644 index 00000000000..e19c8795e8f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pfwq-w8h6-7g84/GHSA-pfwq-w8h6-7g84.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfwq-w8h6-7g84", + "modified": "2025-05-19T15:31:00Z", + "published": "2025-05-19T15:31:00Z", + "aliases": [ + "CVE-2025-48232" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xpro Xpro Addons For Beaver Builder – Lite allows Stored XSS. This issue affects Xpro Addons For Beaver Builder – Lite: from n/a through 1.5.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48232" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/xpro-addons-beaver-builder-elementor/vulnerability/wordpress-xpro-addons-for-beaver-builder-lite-1-5-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pvr2-jc9j-hvv3/GHSA-pvr2-jc9j-hvv3.json b/advisories/unreviewed/2025/05/GHSA-pvr2-jc9j-hvv3/GHSA-pvr2-jc9j-hvv3.json new file mode 100644 index 00000000000..09f531f435e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pvr2-jc9j-hvv3/GHSA-pvr2-jc9j-hvv3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvr2-jc9j-hvv3", + "modified": "2025-05-19T15:31:03Z", + "published": "2025-05-19T15:31:03Z", + "aliases": [ + "CVE-2025-48285" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in sbouey Falang multilanguage allows Cross Site Request Forgery. This issue affects Falang multilanguage: from n/a through 1.3.61.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48285" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/falang/vulnerability/wordpress-falang-multilanguage-1-3-61-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pwfh-8xv9-vgc2/GHSA-pwfh-8xv9-vgc2.json b/advisories/unreviewed/2025/05/GHSA-pwfh-8xv9-vgc2/GHSA-pwfh-8xv9-vgc2.json index 3d77266b29e..6c5cc841fd5 100644 --- a/advisories/unreviewed/2025/05/GHSA-pwfh-8xv9-vgc2/GHSA-pwfh-8xv9-vgc2.json +++ b/advisories/unreviewed/2025/05/GHSA-pwfh-8xv9-vgc2/GHSA-pwfh-8xv9-vgc2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pwfh-8xv9-vgc2", - "modified": "2025-05-14T18:30:50Z", + "modified": "2025-05-19T15:30:38Z", "published": "2025-05-14T18:30:50Z", "aliases": [ "CVE-2025-47706" ], "details": "Authentication Bypass by Capture-replay vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Remote Services with Stolen Credentials.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-294" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-14T17:15:49Z" diff --git a/advisories/unreviewed/2025/05/GHSA-pwxw-rg6p-2vjx/GHSA-pwxw-rg6p-2vjx.json b/advisories/unreviewed/2025/05/GHSA-pwxw-rg6p-2vjx/GHSA-pwxw-rg6p-2vjx.json index 6a720ab76cb..808805968eb 100644 --- a/advisories/unreviewed/2025/05/GHSA-pwxw-rg6p-2vjx/GHSA-pwxw-rg6p-2vjx.json +++ b/advisories/unreviewed/2025/05/GHSA-pwxw-rg6p-2vjx/GHSA-pwxw-rg6p-2vjx.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-q2x2-x5wc-3cp8/GHSA-q2x2-x5wc-3cp8.json b/advisories/unreviewed/2025/05/GHSA-q2x2-x5wc-3cp8/GHSA-q2x2-x5wc-3cp8.json index d645eccf0c9..f9fbb6c8c48 100644 --- a/advisories/unreviewed/2025/05/GHSA-q2x2-x5wc-3cp8/GHSA-q2x2-x5wc-3cp8.json +++ b/advisories/unreviewed/2025/05/GHSA-q2x2-x5wc-3cp8/GHSA-q2x2-x5wc-3cp8.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-q728-q98w-r3qx/GHSA-q728-q98w-r3qx.json b/advisories/unreviewed/2025/05/GHSA-q728-q98w-r3qx/GHSA-q728-q98w-r3qx.json new file mode 100644 index 00000000000..4727b8e421b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q728-q98w-r3qx/GHSA-q728-q98w-r3qx.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q728-q98w-r3qx", + "modified": "2025-05-19T15:30:59Z", + "published": "2025-05-19T15:30:59Z", + "aliases": [ + "CVE-2025-4935" + ], + "details": "A vulnerability was found in SourceCodester Stock Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /php_action/changePassword.php. The manipulation of the argument user_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4935" + }, + { + "type": "WEB", + "url": "https://github.com/hubCVE2025/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309497" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309497" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.579798" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T14:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qcf6-9r7h-r3r4/GHSA-qcf6-9r7h-r3r4.json b/advisories/unreviewed/2025/05/GHSA-qcf6-9r7h-r3r4/GHSA-qcf6-9r7h-r3r4.json new file mode 100644 index 00000000000..e1f972407f3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qcf6-9r7h-r3r4/GHSA-qcf6-9r7h-r3r4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcf6-9r7h-r3r4", + "modified": "2025-05-19T15:31:01Z", + "published": "2025-05-19T15:31:01Z", + "aliases": [ + "CVE-2025-48246" + ], + "details": "Missing Authorization vulnerability in The Events Calendar The Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Events Calendar: from n/a through 6.11.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48246" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/the-events-calendar/vulnerability/wordpress-the-events-calendar-6-11-2-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qr34-4c24-g8fp/GHSA-qr34-4c24-g8fp.json b/advisories/unreviewed/2025/05/GHSA-qr34-4c24-g8fp/GHSA-qr34-4c24-g8fp.json index 12e53058e9a..a4b0ef151de 100644 --- a/advisories/unreviewed/2025/05/GHSA-qr34-4c24-g8fp/GHSA-qr34-4c24-g8fp.json +++ b/advisories/unreviewed/2025/05/GHSA-qr34-4c24-g8fp/GHSA-qr34-4c24-g8fp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-qw69-f8h9-c7h9/GHSA-qw69-f8h9-c7h9.json b/advisories/unreviewed/2025/05/GHSA-qw69-f8h9-c7h9/GHSA-qw69-f8h9-c7h9.json new file mode 100644 index 00000000000..1598ca45df7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qw69-f8h9-c7h9/GHSA-qw69-f8h9-c7h9.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw69-f8h9-c7h9", + "modified": "2025-05-19T15:30:57Z", + "published": "2025-05-19T15:30:57Z", + "aliases": [ + "CVE-2025-4932" + ], + "details": "A vulnerability, which was classified as critical, has been found in projectworlds Online Lawyer Management System 1.0. Affected by this issue is some unknown functionality of the file /lawyer_registation.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4932" + }, + { + "type": "WEB", + "url": "https://github.com/hhhanxx/attack/issues/12" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309494" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309494" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.579676" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T13:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qw9p-xh57-vvwj/GHSA-qw9p-xh57-vvwj.json b/advisories/unreviewed/2025/05/GHSA-qw9p-xh57-vvwj/GHSA-qw9p-xh57-vvwj.json index 784729cd545..8bf5e9e0f4e 100644 --- a/advisories/unreviewed/2025/05/GHSA-qw9p-xh57-vvwj/GHSA-qw9p-xh57-vvwj.json +++ b/advisories/unreviewed/2025/05/GHSA-qw9p-xh57-vvwj/GHSA-qw9p-xh57-vvwj.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-191" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-r5r2-8fvf-q8hf/GHSA-r5r2-8fvf-q8hf.json b/advisories/unreviewed/2025/05/GHSA-r5r2-8fvf-q8hf/GHSA-r5r2-8fvf-q8hf.json new file mode 100644 index 00000000000..9a70a04cd4c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r5r2-8fvf-q8hf/GHSA-r5r2-8fvf-q8hf.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5r2-8fvf-q8hf", + "modified": "2025-05-19T15:31:03Z", + "published": "2025-05-19T15:31:03Z", + "aliases": [ + "CVE-2025-4937" + ], + "details": "A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4937" + }, + { + "type": "WEB", + "url": "https://github.com/Angel12345623/CVE/blob/main/CVE_3.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309499" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309499" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.579830" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r9m9-c69f-7vx9/GHSA-r9m9-c69f-7vx9.json b/advisories/unreviewed/2025/05/GHSA-r9m9-c69f-7vx9/GHSA-r9m9-c69f-7vx9.json new file mode 100644 index 00000000000..815b8058d0b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r9m9-c69f-7vx9/GHSA-r9m9-c69f-7vx9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9m9-c69f-7vx9", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48255" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in videowhisper Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP allows Cross Site Request Forgery. This issue affects Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP: from n/a through 6.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48255" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/videowhisper-live-streaming-integration/vulnerability/wordpress-broadcast-live-video-live-streaming-webrtc-hls-rtsp-rtmp-6-2-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r9w4-h7h7-xvfr/GHSA-r9w4-h7h7-xvfr.json b/advisories/unreviewed/2025/05/GHSA-r9w4-h7h7-xvfr/GHSA-r9w4-h7h7-xvfr.json new file mode 100644 index 00000000000..f8587728a16 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r9w4-h7h7-xvfr/GHSA-r9w4-h7h7-xvfr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9w4-h7h7-xvfr", + "modified": "2025-05-19T15:31:03Z", + "published": "2025-05-19T15:31:03Z", + "aliases": [ + "CVE-2025-48342" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in RedefiningTheWeb Dynamic Pricing & Discounts Lite for WooCommerce allows Cross Site Request Forgery. This issue affects Dynamic Pricing & Discounts Lite for WooCommerce: from n/a through 2.0.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48342" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-dynamic-pricing-discounts-lite/vulnerability/wordpress-dynamic-pricing-discounts-lite-for-woocommerce-2-0-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rfrq-gwcc-2wcq/GHSA-rfrq-gwcc-2wcq.json b/advisories/unreviewed/2025/05/GHSA-rfrq-gwcc-2wcq/GHSA-rfrq-gwcc-2wcq.json index 1ec16451699..3e82afb557e 100644 --- a/advisories/unreviewed/2025/05/GHSA-rfrq-gwcc-2wcq/GHSA-rfrq-gwcc-2wcq.json +++ b/advisories/unreviewed/2025/05/GHSA-rfrq-gwcc-2wcq/GHSA-rfrq-gwcc-2wcq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rfrq-gwcc-2wcq", - "modified": "2025-05-19T06:30:35Z", + "modified": "2025-05-19T15:30:54Z", "published": "2025-05-19T06:30:35Z", "aliases": [ "CVE-2025-1626" ], "details": "The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-19T06:15:18Z" diff --git a/advisories/unreviewed/2025/05/GHSA-rrcx-vcp9-h6c7/GHSA-rrcx-vcp9-h6c7.json b/advisories/unreviewed/2025/05/GHSA-rrcx-vcp9-h6c7/GHSA-rrcx-vcp9-h6c7.json new file mode 100644 index 00000000000..03e7b7a4cc8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rrcx-vcp9-h6c7/GHSA-rrcx-vcp9-h6c7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrcx-vcp9-h6c7", + "modified": "2025-05-19T15:31:00Z", + "published": "2025-05-19T15:31:00Z", + "aliases": [ + "CVE-2025-43714" + ], + "details": "The ChatGPT system through 2025-03-30 performs inline rendering of SVG documents (instead of, for example, rendering them as text inside a code block), which enables HTML injection within most modern graphical web browsers.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43714" + }, + { + "type": "WEB", + "url": "https://medium.com/@zer0dac/chatgpt-a-potential-phishing-vector-via-html-injection-bf703c79590a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rrjv-57mm-j6cm/GHSA-rrjv-57mm-j6cm.json b/advisories/unreviewed/2025/05/GHSA-rrjv-57mm-j6cm/GHSA-rrjv-57mm-j6cm.json index 03b3cc02936..7bd7a5aa915 100644 --- a/advisories/unreviewed/2025/05/GHSA-rrjv-57mm-j6cm/GHSA-rrjv-57mm-j6cm.json +++ b/advisories/unreviewed/2025/05/GHSA-rrjv-57mm-j6cm/GHSA-rrjv-57mm-j6cm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-248" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-v398-g2r2-2f7r/GHSA-v398-g2r2-2f7r.json b/advisories/unreviewed/2025/05/GHSA-v398-g2r2-2f7r/GHSA-v398-g2r2-2f7r.json new file mode 100644 index 00000000000..ba132359fb6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v398-g2r2-2f7r/GHSA-v398-g2r2-2f7r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v398-g2r2-2f7r", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48278" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in davidfcarr RSVPMarker allows SQL Injection. This issue affects RSVPMarker : from n/a through 11.5.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48278" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/rsvpmaker/vulnerability/wordpress-rsvpmarker-11-5-6-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vcqf-8qmf-qc2r/GHSA-vcqf-8qmf-qc2r.json b/advisories/unreviewed/2025/05/GHSA-vcqf-8qmf-qc2r/GHSA-vcqf-8qmf-qc2r.json new file mode 100644 index 00000000000..bb319db0b96 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vcqf-8qmf-qc2r/GHSA-vcqf-8qmf-qc2r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcqf-8qmf-qc2r", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48270" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks allows DOM-Based XSS. This issue affects SKT Blocks: from n/a through 2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48270" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/skt-blocks/vulnerability/wordpress-skt-blocks-2-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vgrj-mg42-7vqg/GHSA-vgrj-mg42-7vqg.json b/advisories/unreviewed/2025/05/GHSA-vgrj-mg42-7vqg/GHSA-vgrj-mg42-7vqg.json new file mode 100644 index 00000000000..616c0d137a8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vgrj-mg42-7vqg/GHSA-vgrj-mg42-7vqg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgrj-mg42-7vqg", + "modified": "2025-05-19T15:31:00Z", + "published": "2025-05-19T15:30:59Z", + "aliases": [ + "CVE-2024-51106" + ], + "details": "A cross-site scripting (XSS) vulnerability in the component mcgs/admin/aboutus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the pagetitle parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51106" + }, + { + "type": "WEB", + "url": "https://github.com/0xBhushan/Writeups/blob/main/CVE/phpGurukul/Medical%20Card%20Generation%20System/Stored%20XSS-About%20Us.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vm4g-9v9f-c5x3/GHSA-vm4g-9v9f-c5x3.json b/advisories/unreviewed/2025/05/GHSA-vm4g-9v9f-c5x3/GHSA-vm4g-9v9f-c5x3.json index 74695395ef9..91874707f6b 100644 --- a/advisories/unreviewed/2025/05/GHSA-vm4g-9v9f-c5x3/GHSA-vm4g-9v9f-c5x3.json +++ b/advisories/unreviewed/2025/05/GHSA-vm4g-9v9f-c5x3/GHSA-vm4g-9v9f-c5x3.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-vmgx-r4vg-xq35/GHSA-vmgx-r4vg-xq35.json b/advisories/unreviewed/2025/05/GHSA-vmgx-r4vg-xq35/GHSA-vmgx-r4vg-xq35.json new file mode 100644 index 00000000000..e064dcd5b32 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vmgx-r4vg-xq35/GHSA-vmgx-r4vg-xq35.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmgx-r4vg-xq35", + "modified": "2025-05-19T15:31:00Z", + "published": "2025-05-19T15:31:00Z", + "aliases": [ + "CVE-2025-48234" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Blocks Ultimate Blocks allows DOM-Based XSS. This issue affects Ultimate Blocks: from n/a through 3.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48234" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/ultimate-blocks/vulnerability/wordpress-ultimate-blocks-3-3-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w3pg-gj6v-vr2v/GHSA-w3pg-gj6v-vr2v.json b/advisories/unreviewed/2025/05/GHSA-w3pg-gj6v-vr2v/GHSA-w3pg-gj6v-vr2v.json new file mode 100644 index 00000000000..23baeda5202 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w3pg-gj6v-vr2v/GHSA-w3pg-gj6v-vr2v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3pg-gj6v-vr2v", + "modified": "2025-05-19T15:31:03Z", + "published": "2025-05-19T15:31:03Z", + "aliases": [ + "CVE-2025-48284" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in shohei.tanaka Japanized For WooCommerce allows Cross Site Request Forgery. This issue affects Japanized For WooCommerce: from n/a through 2.6.40.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48284" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-for-japan/vulnerability/wordpress-japanized-for-woocommerce-2-6-40-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wfrh-ccv8-ffqp/GHSA-wfrh-ccv8-ffqp.json b/advisories/unreviewed/2025/05/GHSA-wfrh-ccv8-ffqp/GHSA-wfrh-ccv8-ffqp.json new file mode 100644 index 00000000000..adbef1ea3d9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wfrh-ccv8-ffqp/GHSA-wfrh-ccv8-ffqp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfrh-ccv8-ffqp", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48280" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia AutomatorWP allows Blind SQL Injection. This issue affects AutomatorWP: from n/a through 5.2.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48280" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/automatorwp/vulnerability/wordpress-automatorwp-5-2-1-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wmcj-rj62-7q33/GHSA-wmcj-rj62-7q33.json b/advisories/unreviewed/2025/05/GHSA-wmcj-rj62-7q33/GHSA-wmcj-rj62-7q33.json new file mode 100644 index 00000000000..6c12bfd98a7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wmcj-rj62-7q33/GHSA-wmcj-rj62-7q33.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmcj-rj62-7q33", + "modified": "2025-05-19T15:31:02Z", + "published": "2025-05-19T15:31:02Z", + "aliases": [ + "CVE-2025-48257" + ], + "details": "Missing Authorization vulnerability in Projectopia Projectopia allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Projectopia: from n/a through 5.1.17.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48257" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/projectopia-core/vulnerability/wordpress-projectopia-5-1-17-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wmgm-jqrv-9fx8/GHSA-wmgm-jqrv-9fx8.json b/advisories/unreviewed/2025/05/GHSA-wmgm-jqrv-9fx8/GHSA-wmgm-jqrv-9fx8.json new file mode 100644 index 00000000000..c2f245677ea --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wmgm-jqrv-9fx8/GHSA-wmgm-jqrv-9fx8.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmgm-jqrv-9fx8", + "modified": "2025-05-19T15:31:03Z", + "published": "2025-05-19T15:31:03Z", + "aliases": [ + "CVE-2025-4936" + ], + "details": "A vulnerability was found in projectworlds Online Food Ordering System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin-page.php. The manipulation of the argument 1_price leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4936" + }, + { + "type": "WEB", + "url": "https://github.com/sknadklasdls/CVE/issues/3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309498" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309498" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.579823" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wr8q-wf72-mf6m/GHSA-wr8q-wf72-mf6m.json b/advisories/unreviewed/2025/05/GHSA-wr8q-wf72-mf6m/GHSA-wr8q-wf72-mf6m.json index 67ba4246fac..081521dc94a 100644 --- a/advisories/unreviewed/2025/05/GHSA-wr8q-wf72-mf6m/GHSA-wr8q-wf72-mf6m.json +++ b/advisories/unreviewed/2025/05/GHSA-wr8q-wf72-mf6m/GHSA-wr8q-wf72-mf6m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wr8q-wf72-mf6m", - "modified": "2025-05-15T21:31:31Z", + "modified": "2025-05-19T15:30:39Z", "published": "2025-05-15T21:31:31Z", "aliases": [ "CVE-2024-2869" ], "details": "The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-15T20:15:49Z" diff --git a/advisories/unreviewed/2025/05/GHSA-x332-7vgm-8pp2/GHSA-x332-7vgm-8pp2.json b/advisories/unreviewed/2025/05/GHSA-x332-7vgm-8pp2/GHSA-x332-7vgm-8pp2.json index 80675a84ccd..9b3bb43a439 100644 --- a/advisories/unreviewed/2025/05/GHSA-x332-7vgm-8pp2/GHSA-x332-7vgm-8pp2.json +++ b/advisories/unreviewed/2025/05/GHSA-x332-7vgm-8pp2/GHSA-x332-7vgm-8pp2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-122" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/05/GHSA-x4rr-8g8f-6q94/GHSA-x4rr-8g8f-6q94.json b/advisories/unreviewed/2025/05/GHSA-x4rr-8g8f-6q94/GHSA-x4rr-8g8f-6q94.json new file mode 100644 index 00000000000..1392cbe1f0c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x4rr-8g8f-6q94/GHSA-x4rr-8g8f-6q94.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4rr-8g8f-6q94", + "modified": "2025-05-19T15:31:01Z", + "published": "2025-05-19T15:31:01Z", + "aliases": [ + "CVE-2025-48251" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Additional Custom Emails & Recipients for WooCommerce allows Stored XSS. This issue affects Additional Custom Emails & Recipients for WooCommerce: from n/a through 3.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48251" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/custom-emails-for-woocommerce/vulnerability/wordpress-additional-custom-emails-recipients-for-woocommerce-3-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xpv7-5pmx-7r5h/GHSA-xpv7-5pmx-7r5h.json b/advisories/unreviewed/2025/05/GHSA-xpv7-5pmx-7r5h/GHSA-xpv7-5pmx-7r5h.json new file mode 100644 index 00000000000..c353891a471 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xpv7-5pmx-7r5h/GHSA-xpv7-5pmx-7r5h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpv7-5pmx-7r5h", + "modified": "2025-05-19T15:31:03Z", + "published": "2025-05-19T15:31:03Z", + "aliases": [ + "CVE-2025-48346" + ], + "details": "Missing Authorization vulnerability in Etsy360 Embed and Integrate Etsy Shop allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Embed and Integrate Etsy Shop: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48346" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/embed-and-integrate-etsy-shop/vulnerability/wordpress-embed-and-integrate-etsy-shop-1-0-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xw5w-5r82-mf3j/GHSA-xw5w-5r82-mf3j.json b/advisories/unreviewed/2025/05/GHSA-xw5w-5r82-mf3j/GHSA-xw5w-5r82-mf3j.json new file mode 100644 index 00000000000..43c81276333 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xw5w-5r82-mf3j/GHSA-xw5w-5r82-mf3j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw5w-5r82-mf3j", + "modified": "2025-05-19T15:31:01Z", + "published": "2025-05-19T15:31:01Z", + "aliases": [ + "CVE-2025-48244" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48244" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/exclusive-addons-for-elementor/vulnerability/wordpress-exclusive-addons-elementor-2-7-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T15:15:27Z" + } +} \ No newline at end of file