Skip to content

File tree

20 files changed

+727
-0
lines changed

20 files changed

+727
-0
lines changed
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-2x3r-qhc4-2pjr",
4+
"modified": "2024-09-12T06:30:22Z",
5+
"published": "2024-09-12T06:30:22Z",
6+
"aliases": [
7+
"CVE-2024-7859"
8+
],
9+
"details": "The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack",
10+
"severity": [
11+
12+
],
13+
"affected": [
14+
15+
],
16+
"references": [
17+
{
18+
"type": "ADVISORY",
19+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7859"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://wpscan.com/vulnerability/88cacd47-d900-478c-b833-c6c55fd4b082"
24+
}
25+
],
26+
"database_specific": {
27+
"cwe_ids": [
28+
29+
],
30+
"severity": null,
31+
"github_reviewed": false,
32+
"github_reviewed_at": null,
33+
"nvd_published_at": "2024-09-12T06:15:24Z"
34+
}
35+
}
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-52vm-8f6x-7r3p",
4+
"modified": "2024-09-12T06:30:22Z",
5+
"published": "2024-09-12T06:30:22Z",
6+
"aliases": [
7+
"CVE-2024-8054"
8+
],
9+
"details": "The MM-Breaking News WordPress plugin through 0.7.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.",
10+
"severity": [
11+
12+
],
13+
"affected": [
14+
15+
],
16+
"references": [
17+
{
18+
"type": "ADVISORY",
19+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8054"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://wpscan.com/vulnerability/f27deffc-9555-44bf-8dee-1891c210ecfd"
24+
}
25+
],
26+
"database_specific": {
27+
"cwe_ids": [
28+
29+
],
30+
"severity": null,
31+
"github_reviewed": false,
32+
"github_reviewed_at": null,
33+
"nvd_published_at": "2024-09-12T06:15:25Z"
34+
}
35+
}
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-6pj4-296c-2375",
4+
"modified": "2024-09-12T06:30:22Z",
5+
"published": "2024-09-12T06:30:22Z",
6+
"aliases": [
7+
"CVE-2024-7766"
8+
],
9+
"details": "The Adicon Server WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks",
10+
"severity": [
11+
12+
],
13+
"affected": [
14+
15+
],
16+
"references": [
17+
{
18+
"type": "ADVISORY",
19+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7766"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://wpscan.com/vulnerability/ca4d629e-ab55-4e5d-80c9-fddbc9c97259"
24+
}
25+
],
26+
"database_specific": {
27+
"cwe_ids": [
28+
29+
],
30+
"severity": null,
31+
"github_reviewed": false,
32+
"github_reviewed_at": null,
33+
"nvd_published_at": "2024-09-12T06:15:24Z"
34+
}
35+
}
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-6x3x-mhgp-4j2c",
4+
"modified": "2024-09-12T06:30:21Z",
5+
"published": "2024-09-12T06:30:21Z",
6+
"aliases": [
7+
"CVE-2024-6019"
8+
],
9+
"details": "The Music Request Manager WordPress plugin through 1.3 does not sanitise and escape incoming music requests, which could allow unauthenticated users to perform Cross-Site Scripting attacks against administrators",
10+
"severity": [
11+
12+
],
13+
"affected": [
14+
15+
],
16+
"references": [
17+
{
18+
"type": "ADVISORY",
19+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6019"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://wpscan.com/vulnerability/5899c5c9-a550-4c86-a41d-7fcc1e84a7d3"
24+
}
25+
],
26+
"database_specific": {
27+
"cwe_ids": [
28+
29+
],
30+
"severity": null,
31+
"github_reviewed": false,
32+
"github_reviewed_at": null,
33+
"nvd_published_at": "2024-09-12T06:15:24Z"
34+
}
35+
}
Lines changed: 58 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,58 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-g7qh-m9g7-242j",
4+
"modified": "2024-09-12T06:30:21Z",
5+
"published": "2024-09-12T06:30:21Z",
6+
"aliases": [
7+
"CVE-2024-8711"
8+
],
9+
"details": "A vulnerability, which was classified as problematic, has been found in SourceCodester Food Ordering Management System 1.0. Affected by this issue is some unknown functionality of the file /includes/. The manipulation leads to exposure of information through directory listing. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [
21+
22+
],
23+
"references": [
24+
{
25+
"type": "ADVISORY",
26+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8711"
27+
},
28+
{
29+
"type": "WEB",
30+
"url": "https://github.com/jz-qb/cve/blob/main/dir.md"
31+
},
32+
{
33+
"type": "WEB",
34+
"url": "https://vuldb.com/?ctiid.277220"
35+
},
36+
{
37+
"type": "WEB",
38+
"url": "https://vuldb.com/?id.277220"
39+
},
40+
{
41+
"type": "WEB",
42+
"url": "https://vuldb.com/?submit.405343"
43+
},
44+
{
45+
"type": "WEB",
46+
"url": "https://www.sourcecodester.com"
47+
}
48+
],
49+
"database_specific": {
50+
"cwe_ids": [
51+
"CWE-548"
52+
],
53+
"severity": "MODERATE",
54+
"github_reviewed": false,
55+
"github_reviewed_at": null,
56+
"nvd_published_at": "2024-09-12T04:15:07Z"
57+
}
58+
}
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-gr7c-mhmf-p6jj",
4+
"modified": "2024-09-12T06:30:22Z",
5+
"published": "2024-09-12T06:30:22Z",
6+
"aliases": [
7+
"CVE-2024-7861"
8+
],
9+
"details": "The Misiek Paypal WordPress plugin through 1.1.20090324 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.",
10+
"severity": [
11+
12+
],
13+
"affected": [
14+
15+
],
16+
"references": [
17+
{
18+
"type": "ADVISORY",
19+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7861"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://wpscan.com/vulnerability/df9aa795-ba16-4806-b01a-311f80aa52c0"
24+
}
25+
],
26+
"database_specific": {
27+
"cwe_ids": [
28+
29+
],
30+
"severity": null,
31+
"github_reviewed": false,
32+
"github_reviewed_at": null,
33+
"nvd_published_at": "2024-09-12T06:15:24Z"
34+
}
35+
}
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-j75g-rhx3-9jfv",
4+
"modified": "2024-09-12T06:30:22Z",
5+
"published": "2024-09-12T06:30:22Z",
6+
"aliases": [
7+
"CVE-2024-7817"
8+
],
9+
"details": "The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attackers to make logged in users delete arbitrary albums via a CSRF attack",
10+
"severity": [
11+
12+
],
13+
"affected": [
14+
15+
],
16+
"references": [
17+
{
18+
"type": "ADVISORY",
19+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7817"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://wpscan.com/vulnerability/ab09e5a3-f5ea-479f-be2d-366f8707775e"
24+
}
25+
],
26+
"database_specific": {
27+
"cwe_ids": [
28+
29+
],
30+
"severity": null,
31+
"github_reviewed": false,
32+
"github_reviewed_at": null,
33+
"nvd_published_at": "2024-09-12T06:15:24Z"
34+
}
35+
}
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-jj2m-7f8j-222w",
4+
"modified": "2024-09-12T06:30:22Z",
5+
"published": "2024-09-12T06:30:22Z",
6+
"aliases": [
7+
"CVE-2024-7822"
8+
],
9+
"details": "The Quick Code WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.",
10+
"severity": [
11+
12+
],
13+
"affected": [
14+
15+
],
16+
"references": [
17+
{
18+
"type": "ADVISORY",
19+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7822"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://wpscan.com/vulnerability/3a5bdd7e-7dd5-4749-9fad-ff4d7df20273"
24+
}
25+
],
26+
"database_specific": {
27+
"cwe_ids": [
28+
29+
],
30+
"severity": null,
31+
"github_reviewed": false,
32+
"github_reviewed_at": null,
33+
"nvd_published_at": "2024-09-12T06:15:24Z"
34+
}
35+
}
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-jq4w-q2w4-8qw3",
4+
"modified": "2024-09-12T06:30:22Z",
5+
"published": "2024-09-12T06:30:22Z",
6+
"aliases": [
7+
"CVE-2024-7818"
8+
],
9+
"details": "The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.",
10+
"severity": [
11+
12+
],
13+
"affected": [
14+
15+
],
16+
"references": [
17+
{
18+
"type": "ADVISORY",
19+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7818"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://wpscan.com/vulnerability/3d2263b9-e1e7-4e86-8475-5e468eef1826"
24+
}
25+
],
26+
"database_specific": {
27+
"cwe_ids": [
28+
29+
],
30+
"severity": null,
31+
"github_reviewed": false,
32+
"github_reviewed_at": null,
33+
"nvd_published_at": "2024-09-12T06:15:24Z"
34+
}
35+
}
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-m2wr-9pq6-49jc",
4+
"modified": "2024-09-12T06:30:21Z",
5+
"published": "2024-09-12T06:30:21Z",
6+
"aliases": [
7+
"CVE-2024-6017"
8+
],
9+
"details": "The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack",
10+
"severity": [
11+
12+
],
13+
"affected": [
14+
15+
],
16+
"references": [
17+
{
18+
"type": "ADVISORY",
19+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6017"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://wpscan.com/vulnerability/06d0559e-4389-4280-bbef-d100c0e07903"
24+
}
25+
],
26+
"database_specific": {
27+
"cwe_ids": [
28+
29+
],
30+
"severity": null,
31+
"github_reviewed": false,
32+
"github_reviewed_at": null,
33+
"nvd_published_at": "2024-09-12T06:15:23Z"
34+
}
35+
}

0 commit comments

Comments
 (0)