Skip to content

Commit 5858e19

Browse files
Advisory Database Sync
1 parent 8687ab7 commit 5858e19

78 files changed

Lines changed: 3528 additions & 1 deletion

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎advisories/unreviewed/2025/09/GHSA-mcgc-fc7f-pj9h/GHSA-mcgc-fc7f-pj9h.json‎

Lines changed: 21 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-mcgc-fc7f-pj9h",
4-
"modified": "2025-09-08T00:30:19Z",
4+
"modified": "2026-09-18T09:31:06Z",
55
"published": "2025-09-08T00:30:19Z",
66
"aliases": [
77
"CVE-2025-10072"
@@ -31,6 +31,10 @@
3131
"type": "WEB",
3232
"url": "https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-10072.md"
3333
},
34+
{
35+
"type": "WEB",
36+
"url": "https://github.com/portabilis/i-educar/tree/2.11.0"
37+
},
3438
{
3539
"type": "WEB",
3640
"url": "https://vuldb.com/?ctiid.323020"
@@ -42,6 +46,22 @@
4246
{
4347
"type": "WEB",
4448
"url": "https://vuldb.com/?submit.644135"
49+
},
50+
{
51+
"type": "WEB",
52+
"url": "https://vuldb.com/cve/CVE-2025-10072"
53+
},
54+
{
55+
"type": "WEB",
56+
"url": "https://vuldb.com/submit/644135"
57+
},
58+
{
59+
"type": "WEB",
60+
"url": "https://vuldb.com/vuln/323020"
61+
},
62+
{
63+
"type": "WEB",
64+
"url": "https://vuldb.com/vuln/323020/cti"
4565
}
4666
],
4767
"database_specific": {
Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,36 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-2qx2-jcc3-gvwf",
4+
"modified": "2026-09-18T09:31:07Z",
5+
"published": "2026-09-18T09:31:07Z",
6+
"aliases": [
7+
"CVE-2026-12384"
8+
],
9+
"details": "Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse.\n\nThis issue affects TECHIN2B Application: from V1.0.7676.13 through 18092026.\nNOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12384"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1014"
25+
}
26+
],
27+
"database_specific": {
28+
"cwe_ids": [
29+
"CWE-639"
30+
],
31+
"severity": "HIGH",
32+
"github_reviewed": false,
33+
"github_reviewed_at": null,
34+
"nvd_published_at": "2026-09-18T08:16:58Z"
35+
}
36+
}
Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,36 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-32vm-v6w7-gjvc",
4+
"modified": "2026-09-18T09:31:09Z",
5+
"published": "2026-09-18T09:31:09Z",
6+
"aliases": [
7+
"CVE-2026-56597"
8+
],
9+
"details": "HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them to map the underlying network topology and identify potential internal targets.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56597"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0133917"
25+
}
26+
],
27+
"database_specific": {
28+
"cwe_ids": [
29+
"CWE-200"
30+
],
31+
"severity": "LOW",
32+
"github_reviewed": false,
33+
"github_reviewed_at": null,
34+
"nvd_published_at": "2026-09-18T09:16:42Z"
35+
}
36+
}
Lines changed: 72 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,72 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-34mw-p6wx-m38q",
4+
"modified": "2026-09-18T09:31:08Z",
5+
"published": "2026-09-18T09:31:08Z",
6+
"aliases": [
7+
"CVE-2026-85652"
8+
],
9+
"details": "The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'album_id' Shortcode Attribute in all versions up to, and including, 1.8.44 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. An Author-level user can store a SQL injection payload inside a published post's shortcode attribute, causing the payload to execute when any visitor renders the post; notably, the unsanitized value appears on both sides of a UNION query, potentially doubling the observable time-based delay.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85652"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://plugins.trac.wordpress.org/browser/photo-gallery/tags/1.8.42/framework/WDWLibrary.php#L75"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://plugins.trac.wordpress.org/browser/photo-gallery/tags/1.8.42/frontend/controllers/controller.php#L51"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://plugins.trac.wordpress.org/browser/photo-gallery/tags/1.8.42/frontend/models/model.php#L172"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://plugins.trac.wordpress.org/browser/photo-gallery/tags/1.8.42/frontend/models/model.php#L178"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://plugins.trac.wordpress.org/browser/photo-gallery/tags/1.8.44/framework/WDWLibrary.php#L75"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://plugins.trac.wordpress.org/browser/photo-gallery/tags/1.8.44/frontend/controllers/controller.php#L51"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://plugins.trac.wordpress.org/browser/photo-gallery/tags/1.8.44/frontend/models/model.php#L172"
49+
},
50+
{
51+
"type": "WEB",
52+
"url": "https://plugins.trac.wordpress.org/browser/photo-gallery/tags/1.8.44/frontend/models/model.php#L178"
53+
},
54+
{
55+
"type": "WEB",
56+
"url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3687152%40photo-gallery&new=3687152%40photo-gallery"
57+
},
58+
{
59+
"type": "WEB",
60+
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c9dca86f-b853-4d29-ae43-bd6ea74d058d?source=cve"
61+
}
62+
],
63+
"database_specific": {
64+
"cwe_ids": [
65+
"CWE-89"
66+
],
67+
"severity": "MODERATE",
68+
"github_reviewed": false,
69+
"github_reviewed_at": null,
70+
"nvd_published_at": "2026-09-18T08:17:01Z"
71+
}
72+
}
Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,36 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-357v-8fxm-wwhq",
4+
"modified": "2026-09-18T09:31:09Z",
5+
"published": "2026-09-18T09:31:09Z",
6+
"aliases": [
7+
"CVE-2026-6205"
8+
],
9+
"details": "An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct denial-of-service attacks.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6205"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://www.synology.com/en-global/security/advisory/Synology_SA_26_13"
25+
}
26+
],
27+
"database_specific": {
28+
"cwe_ids": [
29+
"CWE-73"
30+
],
31+
"severity": "HIGH",
32+
"github_reviewed": false,
33+
"github_reviewed_at": null,
34+
"nvd_published_at": "2026-09-18T09:16:42Z"
35+
}
36+
}
Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,48 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-3582-rw9h-cv52",
4+
"modified": "2026-09-18T09:31:08Z",
5+
"published": "2026-09-18T09:31:08Z",
6+
"aliases": [
7+
"CVE-2026-92249"
8+
],
9+
"details": "The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 1.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Table of Contents widget to be placed on a template that renders on the WordPress search-results page (e.g., a sitewide header or footer template) with the 'Limit ToC to Main Page Content' option left at its default value of No, so the widget scans the search-results heading that reflects the unsanitized `s` parameter.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92249"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://plugins.trac.wordpress.org/browser/qi-addons-for-elementor/tags/1.11/assets/js/main.js#L3185"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://plugins.trac.wordpress.org/browser/qi-addons-for-elementor/tags/1.11/assets/js/main.js#L3263"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3698642%40qi-addons-for-elementor&new=3698642%40qi-addons-for-elementor"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d623d4d6-2d76-4b4e-bd8b-69fe6ae352ca?source=cve"
37+
}
38+
],
39+
"database_specific": {
40+
"cwe_ids": [
41+
"CWE-79"
42+
],
43+
"severity": "MODERATE",
44+
"github_reviewed": false,
45+
"github_reviewed_at": null,
46+
"nvd_published_at": "2026-09-18T08:17:02Z"
47+
}
48+
}
Lines changed: 72 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,72 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-35gj-4m99-3jxg",
4+
"modified": "2026-09-18T09:31:07Z",
5+
"published": "2026-09-18T09:31:07Z",
6+
"aliases": [
7+
"CVE-2026-18442"
8+
],
9+
"details": "The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'wcfmmp_user_location_lng' parameter in all versions up to, and including, 3.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18442"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://plugins.trac.wordpress.org/browser/wc-multivendor-marketplace/tags/3.7.3/core/class-wcfmmp-frontend.php#L363"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://plugins.trac.wordpress.org/browser/wc-multivendor-marketplace/tags/3.7.3/core/class-wcfmmp-shipping.php#L315"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://plugins.trac.wordpress.org/browser/wc-multivendor-marketplace/tags/3.7.3/helpers/wcfmmp-core-functions.php#L982"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://plugins.trac.wordpress.org/browser/wc-multivendor-marketplace/tags/3.7.3/includes/shipping-gateways/class-wcfmmp-shipping-by-distance.php#L83"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://plugins.trac.wordpress.org/browser/wc-multivendor-marketplace/tags/3.8.0/core/class-wcfmmp-frontend.php#L363"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://plugins.trac.wordpress.org/browser/wc-multivendor-marketplace/tags/3.8.0/core/class-wcfmmp-shipping.php#L315"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://plugins.trac.wordpress.org/browser/wc-multivendor-marketplace/tags/3.8.0/helpers/wcfmmp-core-functions.php#L982"
49+
},
50+
{
51+
"type": "WEB",
52+
"url": "https://plugins.trac.wordpress.org/browser/wc-multivendor-marketplace/tags/3.8.0/includes/shipping-gateways/class-wcfmmp-shipping-by-distance.php#L83"
53+
},
54+
{
55+
"type": "WEB",
56+
"url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3672063%40wc-multivendor-marketplace&new=3672063%40wc-multivendor-marketplace"
57+
},
58+
{
59+
"type": "WEB",
60+
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/107f19b5-b67d-4242-b312-531c31b9a73c?source=cve"
61+
}
62+
],
63+
"database_specific": {
64+
"cwe_ids": [
65+
"CWE-89"
66+
],
67+
"severity": "HIGH",
68+
"github_reviewed": false,
69+
"github_reviewed_at": null,
70+
"nvd_published_at": "2026-09-18T08:17:00Z"
71+
}
72+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-35qw-6f3x-m64f",
4+
"modified": "2026-09-18T09:31:06Z",
5+
"published": "2026-09-18T09:31:06Z",
6+
"aliases": [
7+
"CVE-2026-86800"
8+
],
9+
"details": "The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before disabling its login and URL hiding protection, dropping that protection precisely when the request's verification value is missing or incorrect, which any visitor can arrange, allowing unauthenticated attackers to re-expose the concealed WordPress login page location.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86800"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://wpscan.com/vulnerability/01772455-89fe-4bcd-b3b7-c29b8646679d"
25+
}
26+
],
27+
"database_specific": {
28+
"cwe_ids": [],
29+
"severity": "MODERATE",
30+
"github_reviewed": false,
31+
"github_reviewed_at": null,
32+
"nvd_published_at": "2026-09-18T07:16:50Z"
33+
}
34+
}

0 commit comments

Comments
 (0)