From f9a7ac8d59ca005dfc0881c6f935df5537831fda Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 26 Mar 2024 09:34:33 +0000 Subject: [PATCH] Publish Advisories GHSA-24jp-gg22-pxj3 GHSA-3j8g-45hc-8h5f GHSA-56mr-5wh4-v4mf GHSA-7497-c5pf-w9rv GHSA-7p33-pjfm-c7hj GHSA-8rgx-p5cx-vq85 GHSA-9rc6-45fq-m9ff GHSA-m6h2-9w6w-xj46 GHSA-mmch-m456-f59q GHSA-phwp-8rqx-x9g5 GHSA-r8r7-4wvf-px33 GHSA-r99f-79rc-6fjj GHSA-xvvp-cjh4-8phq --- .../GHSA-24jp-gg22-pxj3.json | 38 ++++++++++++ .../GHSA-3j8g-45hc-8h5f.json | 38 ++++++++++++ .../GHSA-56mr-5wh4-v4mf.json | 38 ++++++++++++ .../GHSA-7497-c5pf-w9rv.json | 38 ++++++++++++ .../GHSA-7p33-pjfm-c7hj.json | 38 ++++++++++++ .../GHSA-8rgx-p5cx-vq85.json | 58 +++++++++++++++++ .../GHSA-9rc6-45fq-m9ff.json | 6 +- .../GHSA-m6h2-9w6w-xj46.json | 42 +++++++++++++ .../GHSA-mmch-m456-f59q.json | 62 +++++++++++++++++++ .../GHSA-phwp-8rqx-x9g5.json | 38 ++++++++++++ .../GHSA-r8r7-4wvf-px33.json | 42 +++++++++++++ .../GHSA-r99f-79rc-6fjj.json | 38 ++++++++++++ .../GHSA-xvvp-cjh4-8phq.json | 31 ++++++++++ 13 files changed, 506 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/03/GHSA-24jp-gg22-pxj3/GHSA-24jp-gg22-pxj3.json create mode 100644 advisories/unreviewed/2024/03/GHSA-3j8g-45hc-8h5f/GHSA-3j8g-45hc-8h5f.json create mode 100644 advisories/unreviewed/2024/03/GHSA-56mr-5wh4-v4mf/GHSA-56mr-5wh4-v4mf.json create mode 100644 advisories/unreviewed/2024/03/GHSA-7497-c5pf-w9rv/GHSA-7497-c5pf-w9rv.json create mode 100644 advisories/unreviewed/2024/03/GHSA-7p33-pjfm-c7hj/GHSA-7p33-pjfm-c7hj.json create mode 100644 advisories/unreviewed/2024/03/GHSA-8rgx-p5cx-vq85/GHSA-8rgx-p5cx-vq85.json create mode 100644 advisories/unreviewed/2024/03/GHSA-m6h2-9w6w-xj46/GHSA-m6h2-9w6w-xj46.json create mode 100644 advisories/unreviewed/2024/03/GHSA-mmch-m456-f59q/GHSA-mmch-m456-f59q.json create mode 100644 advisories/unreviewed/2024/03/GHSA-phwp-8rqx-x9g5/GHSA-phwp-8rqx-x9g5.json create mode 100644 advisories/unreviewed/2024/03/GHSA-r8r7-4wvf-px33/GHSA-r8r7-4wvf-px33.json create mode 100644 advisories/unreviewed/2024/03/GHSA-r99f-79rc-6fjj/GHSA-r99f-79rc-6fjj.json create mode 100644 advisories/unreviewed/2024/03/GHSA-xvvp-cjh4-8phq/GHSA-xvvp-cjh4-8phq.json diff --git a/advisories/unreviewed/2024/03/GHSA-24jp-gg22-pxj3/GHSA-24jp-gg22-pxj3.json b/advisories/unreviewed/2024/03/GHSA-24jp-gg22-pxj3/GHSA-24jp-gg22-pxj3.json new file mode 100644 index 00000000000..b17a3bbeb34 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-24jp-gg22-pxj3/GHSA-24jp-gg22-pxj3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24jp-gg22-pxj3", + "modified": "2024-03-26T09:32:58Z", + "published": "2024-03-26T09:32:58Z", + "aliases": [ + "CVE-2023-51416" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in EnvialoSimple EnvĂ­aloSimple.This issue affects EnvĂ­aloSimple: from n/a through 2.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51416" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/envialosimple-email-marketing-y-newsletters-gratis/wordpress-envialosimple-plugin-2-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T08:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-3j8g-45hc-8h5f/GHSA-3j8g-45hc-8h5f.json b/advisories/unreviewed/2024/03/GHSA-3j8g-45hc-8h5f/GHSA-3j8g-45hc-8h5f.json new file mode 100644 index 00000000000..6ef7c64e08e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3j8g-45hc-8h5f/GHSA-3j8g-45hc-8h5f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j8g-45hc-8h5f", + "modified": "2024-03-26T09:32:58Z", + "published": "2024-03-26T09:32:58Z", + "aliases": [ + "CVE-2023-23991" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPdevelop / Oplugins Booking Calendar allows SQL Injection.This issue affects Booking Calendar: from n/a through 9.4.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23991" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/booking/wordpress-booking-calendar-plugin-9-4-2-sql-injection?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-56mr-5wh4-v4mf/GHSA-56mr-5wh4-v4mf.json b/advisories/unreviewed/2024/03/GHSA-56mr-5wh4-v4mf/GHSA-56mr-5wh4-v4mf.json new file mode 100644 index 00000000000..042ba2976cf --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-56mr-5wh4-v4mf/GHSA-56mr-5wh4-v4mf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56mr-5wh4-v4mf", + "modified": "2024-03-26T09:32:57Z", + "published": "2024-03-26T09:32:57Z", + "aliases": [ + "CVE-2024-2889" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for Amazon allows Stored XSS.This issue affects WP-Lister Lite for Amazon: from n/a through 2.6.11.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2889" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-lister-for-amazon/wordpress-wp-lister-lite-for-amazon-plugin-2-6-11-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T07:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7497-c5pf-w9rv/GHSA-7497-c5pf-w9rv.json b/advisories/unreviewed/2024/03/GHSA-7497-c5pf-w9rv/GHSA-7497-c5pf-w9rv.json new file mode 100644 index 00000000000..ebde2fca359 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7497-c5pf-w9rv/GHSA-7497-c5pf-w9rv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7497-c5pf-w9rv", + "modified": "2024-03-26T09:32:58Z", + "published": "2024-03-26T09:32:58Z", + "aliases": [ + "CVE-2024-24805" + ], + "details": "Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Generator: from n/a through 3.1.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24805" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-dummy-content-generator/wordpress-wp-dummy-content-generator-plugin-3-1-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7p33-pjfm-c7hj/GHSA-7p33-pjfm-c7hj.json b/advisories/unreviewed/2024/03/GHSA-7p33-pjfm-c7hj/GHSA-7p33-pjfm-c7hj.json new file mode 100644 index 00000000000..ae7e979eb66 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7p33-pjfm-c7hj/GHSA-7p33-pjfm-c7hj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p33-pjfm-c7hj", + "modified": "2024-03-26T09:32:58Z", + "published": "2024-03-26T09:32:58Z", + "aliases": [ + "CVE-2023-33322" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Front End Users allows Reflected XSS.This issue affects Front End Users: from n/a before 3.2.25.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33322" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/front-end-only-users/wordpress-front-end-users-plugin-3-2-25-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8rgx-p5cx-vq85/GHSA-8rgx-p5cx-vq85.json b/advisories/unreviewed/2024/03/GHSA-8rgx-p5cx-vq85/GHSA-8rgx-p5cx-vq85.json new file mode 100644 index 00000000000..d84ab1d31e6 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8rgx-p5cx-vq85/GHSA-8rgx-p5cx-vq85.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rgx-p5cx-vq85", + "modified": "2024-03-26T09:32:57Z", + "published": "2024-03-26T09:32:57Z", + "aliases": [ + "CVE-2023-49839" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KlbTheme Cosmetsy theme (core plugin), KlbTheme Partdo theme (core plugin), KlbTheme Bacola theme (core plugin), KlbTheme Medibazar theme (core plugin), KlbTheme Furnob theme (core plugin), KlbTheme Clotya theme (core plugin) allows Reflected XSS.This issue affects Cosmetsy theme (core plugin): from n/a through 1.3.0; Partdo theme (core plugin): from n/a through 1.0.9; Bacola theme (core plugin): from n/a through 1.3.3; Medibazar theme (core plugin): from n/a through 1.2.3; Furnob theme (core plugin): from n/a through 1.1.7; Clotya theme (core plugin): from n/a through 1.1.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49839" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bacola-core/wordpress-bacola-core-plugin-1-3-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/clotya-core/wordpress-clotya-core-plugin-1-1-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cosmetsy-core/wordpress-cosmetsy-core-plugin-1-3-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/furnob-core/wordpress-furnob-core-plugin-1-1-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/medibazar-core/wordpress-medibazar-core-plugin-1-2-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/partdo-core/wordpress-partdo-core-plugin-1-0-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T08:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9rc6-45fq-m9ff/GHSA-9rc6-45fq-m9ff.json b/advisories/unreviewed/2024/03/GHSA-9rc6-45fq-m9ff/GHSA-9rc6-45fq-m9ff.json index b068a252568..d1f1843c914 100644 --- a/advisories/unreviewed/2024/03/GHSA-9rc6-45fq-m9ff/GHSA-9rc6-45fq-m9ff.json +++ b/advisories/unreviewed/2024/03/GHSA-9rc6-45fq-m9ff/GHSA-9rc6-45fq-m9ff.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9rc6-45fq-m9ff", - "modified": "2024-03-23T18:30:42Z", + "modified": "2024-03-26T09:32:57Z", "published": "2024-03-23T18:30:42Z", "aliases": [ "CVE-2024-2849" @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.257770" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.303123" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-m6h2-9w6w-xj46/GHSA-m6h2-9w6w-xj46.json b/advisories/unreviewed/2024/03/GHSA-m6h2-9w6w-xj46/GHSA-m6h2-9w6w-xj46.json new file mode 100644 index 00000000000..a8cdcdeae3d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-m6h2-9w6w-xj46/GHSA-m6h2-9w6w-xj46.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6h2-9w6w-xj46", + "modified": "2024-03-26T09:32:58Z", + "published": "2024-03-26T09:32:58Z", + "aliases": [ + "CVE-2023-32237" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem (Elementor), CodexThemes TheGem (WPBakery) allows Stored XSS.This issue affects TheGem (Elementor): from n/a before 5.8.1.1; TheGem (WPBakery): from n/a before 5.8.1.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32237" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/thegem-elementor/wordpress-thegem-elementor-theme-5-7-2-auth-stored-cross-site-scripting-xss-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/thegem/wordpress-thegem-wpbakery-theme-5-7-2-authenticated-cross-site-scripting-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-mmch-m456-f59q/GHSA-mmch-m456-f59q.json b/advisories/unreviewed/2024/03/GHSA-mmch-m456-f59q/GHSA-mmch-m456-f59q.json new file mode 100644 index 00000000000..984575c6f26 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-mmch-m456-f59q/GHSA-mmch-m456-f59q.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmch-m456-f59q", + "modified": "2024-03-26T09:32:58Z", + "published": "2024-03-26T09:32:58Z", + "aliases": [ + "CVE-2023-49838" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in KlbTheme Clotya theme, KlbTheme Cosmetsy theme, KlbTheme Furnob theme, KlbTheme Bacola theme, KlbTheme Partdo theme, KlbTheme Medibazar theme, KlbTheme Machic theme.This issue affects Clotya theme: from n/a through 1.1.6; Cosmetsy theme: from n/a through 1.7.7; Furnob theme: from n/a through 1.2.2; Bacola theme: from n/a through 1.3.3; Partdo theme: from n/a through 1.1.1; Medibazar theme: from n/a through 1.8.6; Machic theme: from n/a through 1.2.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49838" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bacola/wordpress-bacola-theme-1-3-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/clotya/wordpress-clotya-theme-1-1-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cosmetsy/wordpress-cosmetsy-theme-1-7-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/furnob/wordpress-furnob-theme-1-2-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/machic/wordpress-machic-theme-1-2-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/medibazar/wordpress-medibazar-theme-1-8-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/partdo/wordpress-partdo-theme-1-1-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-phwp-8rqx-x9g5/GHSA-phwp-8rqx-x9g5.json b/advisories/unreviewed/2024/03/GHSA-phwp-8rqx-x9g5/GHSA-phwp-8rqx-x9g5.json new file mode 100644 index 00000000000..a827694baac --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-phwp-8rqx-x9g5/GHSA-phwp-8rqx-x9g5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phwp-8rqx-x9g5", + "modified": "2024-03-26T09:32:58Z", + "published": "2024-03-26T09:32:58Z", + "aliases": [ + "CVE-2023-7251" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS.This issue affects User Submitted Posts: from n/a through 20230901.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7251" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/user-submitted-posts/wordpress-user-submitted-posts-plugin-20230901-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-r8r7-4wvf-px33/GHSA-r8r7-4wvf-px33.json b/advisories/unreviewed/2024/03/GHSA-r8r7-4wvf-px33/GHSA-r8r7-4wvf-px33.json new file mode 100644 index 00000000000..dddf17722af --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-r8r7-4wvf-px33/GHSA-r8r7-4wvf-px33.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8r7-4wvf-px33", + "modified": "2024-03-26T09:32:58Z", + "published": "2024-03-26T09:32:58Z", + "aliases": [ + "CVE-2023-6175" + ], + "details": "NetScreen file parser crash in Wireshark 4.0.0 to 4.0.10 and 3.6.0 to 3.6.18 allows denial of service via crafted capture file", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6175" + }, + { + "type": "WEB", + "url": "https://gitlab.com/wireshark/wireshark/-/issues/19404" + }, + { + "type": "WEB", + "url": "https://www.wireshark.org/security/wnpa-sec-2023-29.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T08:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-r99f-79rc-6fjj/GHSA-r99f-79rc-6fjj.json b/advisories/unreviewed/2024/03/GHSA-r99f-79rc-6fjj/GHSA-r99f-79rc-6fjj.json new file mode 100644 index 00000000000..879b52e4389 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-r99f-79rc-6fjj/GHSA-r99f-79rc-6fjj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r99f-79rc-6fjj", + "modified": "2024-03-26T09:32:58Z", + "published": "2024-03-26T09:32:58Z", + "aliases": [ + "CVE-2023-45771" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Contact Form With Captcha allows Reflected XSS.This issue affects Contact Form With Captcha: from n/a through 1.6.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45771" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/contact-form-with-captcha/wordpress-contact-form-with-captcha-plugin-1-6-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-xvvp-cjh4-8phq/GHSA-xvvp-cjh4-8phq.json b/advisories/unreviewed/2024/03/GHSA-xvvp-cjh4-8phq/GHSA-xvvp-cjh4-8phq.json new file mode 100644 index 00000000000..775f2669d7e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-xvvp-cjh4-8phq/GHSA-xvvp-cjh4-8phq.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvvp-cjh4-8phq", + "modified": "2024-03-26T09:32:58Z", + "published": "2024-03-26T09:32:58Z", + "aliases": [ + "CVE-2023-41696" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41696" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-26T09:15:09Z" + } +} \ No newline at end of file