diff --git a/advisories/unreviewed/2024/10/GHSA-4q89-84pm-r2p6/GHSA-4q89-84pm-r2p6.json b/advisories/unreviewed/2024/10/GHSA-4q89-84pm-r2p6/GHSA-4q89-84pm-r2p6.json index 405ceb892ce..b1c158521e8 100644 --- a/advisories/unreviewed/2024/10/GHSA-4q89-84pm-r2p6/GHSA-4q89-84pm-r2p6.json +++ b/advisories/unreviewed/2024/10/GHSA-4q89-84pm-r2p6/GHSA-4q89-84pm-r2p6.json @@ -25,7 +25,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-617" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-7xj4-f8gj-5g77/GHSA-7xj4-f8gj-5g77.json b/advisories/unreviewed/2024/10/GHSA-7xj4-f8gj-5g77/GHSA-7xj4-f8gj-5g77.json new file mode 100644 index 00000000000..03e69b7fcec --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7xj4-f8gj-5g77/GHSA-7xj4-f8gj-5g77.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xj4-f8gj-5g77", + "modified": "2024-10-07T06:30:21Z", + "published": "2024-10-07T06:30:21Z", + "aliases": [ + "CVE-2024-47335" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Form Bit Form – Contact Form Plugin allows SQL Injection.This issue affects Bit Form – Contact Form Plugin: from n/a through 2.13.11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47335" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bit-form/wordpress-bit-form-plugin-2-13-11-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T06:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xvv7-9gx9-6xh5/GHSA-xvv7-9gx9-6xh5.json b/advisories/unreviewed/2024/10/GHSA-xvv7-9gx9-6xh5/GHSA-xvv7-9gx9-6xh5.json new file mode 100644 index 00000000000..d85f84d70e2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xvv7-9gx9-6xh5/GHSA-xvv7-9gx9-6xh5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvv7-9gx9-6xh5", + "modified": "2024-10-07T06:30:21Z", + "published": "2024-10-07T06:30:21Z", + "aliases": [ + "CVE-2024-47344" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StylemixThemes uListing.This issue affects uListing: from n/a through 2.1.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47344" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ulisting/wordpress-ulisting-plugin-2-1-5-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T06:15:04Z" + } +} \ No newline at end of file