Skip to content

Commit 1918208

Browse files
Sync EUVD catalog: Mon May 25 00:54:43 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent c4fa3da commit 1918208

138 files changed

Lines changed: 4334 additions & 232 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/2026/04/EUVD-2017-18965.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,15 +2,15 @@
22
"id": "EUVD-2017-18965",
33
"enisaUuid": "d339999c-4a4f-3b15-9079-bd5723baa210",
44
"description": "MDwiki contains a cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript by injecting malicious code through the location hash parameter. Attackers can craft URLs with JavaScript payloads in the hash fragment that are parsed and rendered without sanitization, causing the injected scripts to execute in the victim's browser context.",
5-
"datePublished": "Apr 12, 2026, 3:30:25 PM",
6-
"dateUpdated": "Apr 12, 2026, 3:30:25 PM",
5+
"datePublished": "Apr 12, 2026, 12:28:42 PM",
6+
"dateUpdated": "May 24, 2026, 1:36:13 AM",
77
"baseScore": 5.1,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
10-
"references": "https://www.exploit-db.com/exploits/46097\nhttps://www.vulncheck.com/advisories/mdwiki-cross-site-scripting-via-location-hash-parameter\nhttps://nvd.nist.gov/vuln/detail/CVE-2017-20239\n",
10+
"references": "https://www.exploit-db.com/exploits/46097\nhttps://www.vulncheck.com/advisories/mdwiki-cross-site-scripting-via-location-hash-parameter\n",
1111
"aliases": "GHSA-gp82-mmj7-m5w2\nCVE-2017-20239\n",
1212
"assigner": "VulnCheck",
13-
"epss": 0.0,
13+
"epss": 0.02,
1414
"enisaIdProduct": [
1515
{
1616
"id": "dd351865-44df-3936-8bde-83c3b18d1a68",

advisories/2026/04/EUVD-2018-21746.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,15 +2,15 @@
22
"id": "EUVD-2018-21746",
33
"enisaUuid": "b703b821-34d3-3755-b8a7-1ae3f8b781bb",
44
"description": "MyBB Like Plugin 3.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating posts or threads with unvalidated subject content. Attackers can craft post subjects containing script tags that execute when other users view the attacker's profile, where liked posts are displayed without sanitization.",
5-
"datePublished": "Apr 4, 2026, 3:30:20 PM",
6-
"dateUpdated": "Apr 4, 2026, 3:30:20 PM",
5+
"datePublished": "Apr 4, 2026, 1:51:12 PM",
6+
"dateUpdated": "May 24, 2026, 1:36:13 AM",
77
"baseScore": 5.1,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
10-
"references": "https://www.exploit-db.com/exploits/45179\nhttps://community.mybb.com/mods.php?action=view&pid=360\nhttps://www.vulncheck.com/advisories/mybb-like-plugin-cross-site-scripting-via-user-profiles\nhttps://nvd.nist.gov/vuln/detail/CVE-2018-25247\n",
10+
"references": "https://www.exploit-db.com/exploits/45179\nhttps://community.mybb.com/mods.php?action=view&pid=360\nhttps://www.vulncheck.com/advisories/mybb-like-plugin-cross-site-scripting-via-user-profiles\n",
1111
"aliases": "CVE-2018-25247\nGHSA-rh85-6vwm-xgq4\n",
1212
"assigner": "VulnCheck",
13-
"epss": 0.0,
13+
"epss": 0.04,
1414
"enisaIdProduct": [
1515
{
1616
"id": "6967cc36-bc49-365f-bb34-9adfa9b4d850",

advisories/2026/04/EUVD-2018-21748.json

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -2,15 +2,15 @@
22
"id": "EUVD-2018-21748",
33
"enisaUuid": "c92aec72-3bbf-3010-a886-7d56df4a837c",
44
"description": "MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through the download title field. Attackers can submit a new download with HTML/JavaScript code in the title parameter, which executes when administrators validate the download in downloads.php.",
5-
"datePublished": "Apr 4, 2026, 3:30:20 PM",
6-
"dateUpdated": "Apr 4, 2026, 3:30:20 PM",
5+
"datePublished": "Apr 4, 2026, 1:51:13 PM",
6+
"dateUpdated": "May 24, 2026, 1:36:14 AM",
77
"baseScore": 5.1,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
10-
"references": "https://www.exploit-db.com/exploits/44400\nhttps://community.mybb.com/mods.php?action=view&pid=854\nhttps://www.vulncheck.com/advisories/mybb-downloads-plugin-persistent-xss-via-downloads-php\nhttps://nvd.nist.gov/vuln/detail/CVE-2018-25248\n",
11-
"aliases": "CVE-2018-25248\n",
10+
"references": "https://www.exploit-db.com/exploits/44400\nhttps://community.mybb.com/mods.php?action=view&pid=854\nhttps://www.vulncheck.com/advisories/mybb-downloads-plugin-persistent-xss-via-downloads-php\n",
11+
"aliases": "CVE-2018-25248\nGHSA-8mwv-4frr-pwqr\n",
1212
"assigner": "VulnCheck",
13-
"epss": 0.0,
13+
"epss": 0.03,
1414
"enisaIdProduct": [
1515
{
1616
"id": "35f360b6-bfe1-376b-9091-d1059a6f487f",

advisories/2026/04/EUVD-2018-21751.json

Lines changed: 14 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2,16 +2,24 @@
22
"id": "EUVD-2018-21751",
33
"enisaUuid": "6bb6ca30-18de-3865-a238-ca8ab15714b7",
44
"description": "MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through arcade game score comments. Attackers can add crafted HTML and JavaScript payloads in the comment field that execute when other users view or edit the comment.",
5-
"datePublished": "Apr 4, 2026, 3:30:20 PM",
6-
"dateUpdated": "Apr 4, 2026, 3:30:20 PM",
5+
"datePublished": "Apr 4, 2026, 1:51:14 PM",
6+
"dateUpdated": "May 24, 2026, 1:36:15 AM",
77
"baseScore": 5.1,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
10-
"references": "https://www.exploit-db.com/exploits/44186\nhttps://community.mybb.com/mods.php?action=view&pid=411\nhttps://www.vulncheck.com/advisories/mybb-my-arcade-plugin-persistent-xss-via-comment\nhttps://nvd.nist.gov/vuln/detail/CVE-2018-25249\n",
11-
"aliases": "CVE-2018-25249\n",
10+
"references": "https://www.exploit-db.com/exploits/44186\nhttps://community.mybb.com/mods.php?action=view&pid=411\nhttps://www.vulncheck.com/advisories/mybb-my-arcade-plugin-persistent-xss-via-comment\n",
11+
"aliases": "CVE-2018-25249\nGHSA-4mc8-7jpg-4r7r\n",
1212
"assigner": "VulnCheck",
13-
"epss": 0.0,
14-
"enisaIdProduct": [],
13+
"epss": 0.01,
14+
"enisaIdProduct": [
15+
{
16+
"id": "fef50786-8f0d-3c98-81e9-a16ce0e64ae8",
17+
"product": {
18+
"name": "MyBB My Arcade Plugin"
19+
},
20+
"product_version": "1.3"
21+
}
22+
],
1523
"enisaIdVendor": [
1624
{
1725
"id": "94412556-9aa9-348e-8def-652ab71e8094",

advisories/2026/04/EUVD-2018-21752.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,15 +2,15 @@
22
"id": "EUVD-2018-21752",
33
"enisaUuid": "8ca7d723-8c91-3454-80d2-bee52b26f26a",
44
"description": "MyBB Last User's Threads in Profile Plugin 1.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by crafting thread subjects with script tags. Attackers can create threads with script payloads in the subject field that execute when users visit the attacker's profile page.",
5-
"datePublished": "Apr 4, 2026, 3:30:20 PM",
6-
"dateUpdated": "Apr 4, 2026, 3:30:20 PM",
5+
"datePublished": "Apr 4, 2026, 1:51:14 PM",
6+
"dateUpdated": "May 24, 2026, 1:36:16 AM",
77
"baseScore": 5.1,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
10-
"references": "https://www.exploit-db.com/exploits/44339\nhttps://community.mybb.com/mods.php?action=view&pid=910\nhttps://www.vulncheck.com/advisories/mybb-last-user-s-threads-in-profile-plugin-persistent-xss\nhttps://nvd.nist.gov/vuln/detail/CVE-2018-25250\n",
10+
"references": "https://www.exploit-db.com/exploits/44339\nhttps://community.mybb.com/mods.php?action=view&pid=910\nhttps://www.vulncheck.com/advisories/mybb-last-user-s-threads-in-profile-plugin-persistent-xss\n",
1111
"aliases": "CVE-2018-25250\nGHSA-8grq-4hc4-mrpv\n",
1212
"assigner": "VulnCheck",
13-
"epss": 0.0,
13+
"epss": 0.03,
1414
"enisaIdProduct": [
1515
{
1616
"id": "2419b5f5-59ab-3cf0-8a8e-5f23f6975b93",

advisories/2026/04/EUVD-2018-21785.json

Lines changed: 10 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,15 +2,15 @@
22
"id": "EUVD-2018-21785",
33
"enisaUuid": "fae76258-ac04-3c85-9119-15815ef5e92c",
44
"description": "ICEWARP 11.0.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML elements into emails by embedding base64-encoded payloads in object and embed tags. Attackers can craft emails containing data URIs with embedded scripts that execute in the client when the email is viewed, compromising user sessions and stealing sensitive information.",
5-
"datePublished": "Apr 22, 2026, 6:31:44 PM",
6-
"dateUpdated": "Apr 22, 2026, 6:31:44 PM",
5+
"datePublished": "Apr 22, 2026, 2:57:03 PM",
6+
"dateUpdated": "May 24, 2026, 1:36:16 AM",
77
"baseScore": 5.1,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
10-
"references": "https://www.exploit-db.com/exploits/45974\nhttp://www.icewarp.com/\nhttps://www.vulncheck.com/advisories/icewarp-cross-site-scripting-via-email-html-injection\nhttps://nvd.nist.gov/vuln/detail/CVE-2018-25269\n",
10+
"references": "https://www.exploit-db.com/exploits/45974\nhttp://www.icewarp.com/\nhttps://www.vulncheck.com/advisories/icewarp-cross-site-scripting-via-email-html-injection\n",
1111
"aliases": "GHSA-xx24-qg5f-3r29\nCVE-2018-25269\n",
1212
"assigner": "VulnCheck",
13-
"epss": 0.0,
13+
"epss": 0.03,
1414
"enisaIdProduct": [
1515
{
1616
"id": "227cc17c-d869-3197-a5ad-256176e17330",
@@ -28,6 +28,12 @@
2828
}
2929
],
3030
"enisaIdVendor": [
31+
{
32+
"id": "6c0f22c3-084a-3665-9a82-8aab2f5a489f",
33+
"vendor": {
34+
"name": "Icewarp"
35+
}
36+
},
3137
{
3238
"id": "fac5ca1f-9bd4-3f40-9976-2702ab052309",
3339
"vendor": {

advisories/2026/04/EUVD-2018-21830.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,12 +3,12 @@
33
"enisaUuid": "5d44aee0-21a3-3e21-a1e5-e4b131bf4cf3",
44
"description": "MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating threads with crafted subject lines. Attackers can create threads with script tags in the subject parameter to execute arbitrary JavaScript in the browsers of all users viewing the index page.",
55
"datePublished": "Apr 29, 2026, 7:24:39 PM",
6-
"dateUpdated": "Apr 30, 2026, 1:07:56 PM",
6+
"dateUpdated": "May 24, 2026, 1:36:17 AM",
77
"baseScore": 5.1,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
1010
"references": "https://www.exploit-db.com/exploits/44420\nhttps://community.mybb.com/mods.php?action=view&pid=191\nhttps://www.vulncheck.com/advisories/mybb-recent-threads-persistent-cross-site-scripting\n",
11-
"aliases": "CVE-2018-25309\n",
11+
"aliases": "CVE-2018-25309\nGHSA-gcf4-8qvj-pjm9\n",
1212
"assigner": "VulnCheck",
1313
"epss": 0.03,
1414
"enisaIdProduct": [

advisories/2026/04/EUVD-2023-60549.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,15 +2,15 @@
22
"id": "EUVD-2023-60549",
33
"enisaUuid": "352b1acc-12e3-31c0-82f2-75ca4fa39578",
44
"description": "WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the isMobile parameter. Attackers can craft malicious URLs containing JavaScript payloads in the isMobile GET parameter at the /mobile-app/v3/ endpoint to execute arbitrary code in victims' browsers and steal session tokens or credentials.",
5-
"datePublished": "Apr 9, 2026, 9:31:30 PM",
6-
"dateUpdated": "Apr 9, 2026, 9:31:30 PM",
5+
"datePublished": "Apr 9, 2026, 8:54:48 PM",
6+
"dateUpdated": "May 24, 2026, 1:37:39 AM",
77
"baseScore": 5.1,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
10-
"references": "https://www.exploit-db.com/exploits/51663\nhttps://www.adivaha.com/\nhttps://wordpress.org/plugins/adiaha-hotel/\nhttps://www.vulncheck.com/advisories/wordpress-adivaha-travel-plugin-reflected-xss-via-ismobile\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-54358\n",
10+
"references": "https://www.exploit-db.com/exploits/51663\nhttps://www.adivaha.com/\nhttps://wordpress.org/plugins/adiaha-hotel/\nhttps://www.vulncheck.com/advisories/wordpress-adivaha-travel-plugin-reflected-xss-via-ismobile\n",
1111
"aliases": "GHSA-46qr-c6wf-gmhj\nCVE-2023-54358\n",
1212
"assigner": "VulnCheck",
13-
"epss": 0.0,
13+
"epss": 0.12,
1414
"enisaIdProduct": [
1515
{
1616
"id": "f45b9ab5-4355-3df4-8b84-843fa0236ba4",

advisories/2026/04/EUVD-2023-60552.json

Lines changed: 10 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,15 +2,15 @@
22
"id": "EUVD-2023-60552",
33
"enisaUuid": "6fcf1c21-25c2-3e2b-900e-f11277c339cb",
44
"description": "Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the review_id URL parameter. Attackers can craft malicious links containing JavaScript payloads that execute in victims' browsers when clicked, enabling session hijacking or credential theft.",
5-
"datePublished": "Apr 9, 2026, 9:31:30 PM",
6-
"dateUpdated": "Apr 9, 2026, 9:31:30 PM",
5+
"datePublished": "Apr 9, 2026, 8:54:50 PM",
6+
"dateUpdated": "May 24, 2026, 1:37:39 AM",
77
"baseScore": 5.1,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
10-
"references": "https://www.exploit-db.com/exploits/51645\nhttps://jlexart.com/\nhttps://extensions.joomla.org/extension/jlex-review/\nhttps://www.vulncheck.com/advisories/joomla-jlex-review-reflected-xss-via-review-id-parameter\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-54360\n",
10+
"references": "https://www.exploit-db.com/exploits/51645\nhttps://jlexart.com/\nhttps://extensions.joomla.org/extension/jlex-review/\nhttps://www.vulncheck.com/advisories/joomla-jlex-review-reflected-xss-via-review-id-parameter\n",
1111
"aliases": "GHSA-9g66-6jg8-w8jc\nCVE-2023-54360\n",
1212
"assigner": "VulnCheck",
13-
"epss": 0.0,
13+
"epss": 0.04,
1414
"enisaIdProduct": [
1515
{
1616
"id": "a8742107-67df-3bd5-be71-d9afbc552eec",
@@ -26,6 +26,12 @@
2626
"vendor": {
2727
"name": "jlexart"
2828
}
29+
},
30+
{
31+
"id": "e799a0c8-7787-39fb-bb50-e28e810df89b",
32+
"vendor": {
33+
"name": "jlexart"
34+
}
2935
}
3036
]
3137
}

advisories/2026/04/EUVD-2023-60554.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,15 +2,15 @@
22
"id": "EUVD-2023-60554",
33
"enisaUuid": "96468547-eaaa-3296-8bcb-0448aecc004e",
44
"description": "Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the filter_keyword parameter. Attackers can craft URLs containing JavaScript payloads in the filter_keyword GET parameter of the all-properties-with-map endpoint to execute arbitrary code in victim browsers and steal session tokens or credentials.",
5-
"datePublished": "Apr 9, 2026, 9:31:30 PM",
6-
"dateUpdated": "Apr 9, 2026, 9:31:30 PM",
5+
"datePublished": "Apr 9, 2026, 8:54:51 PM",
6+
"dateUpdated": "May 24, 2026, 1:37:40 AM",
77
"baseScore": 5.1,
88
"baseScoreVersion": "4.0",
99
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
10-
"references": "https://www.exploit-db.com/exploits/51640\nhttp://thethinkery.net\nhttps://extensions.joomla.org/extension/vertical-markets/real-estate/iproperty/\nhttps://www.vulncheck.com/advisories/joomla-iproperty-real-estate-reflected-xss-via-filter-keyword\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-54361\n",
10+
"references": "https://www.exploit-db.com/exploits/51640\nhttp://thethinkery.net\nhttps://extensions.joomla.org/extension/vertical-markets/real-estate/iproperty/\nhttps://www.vulncheck.com/advisories/joomla-iproperty-real-estate-reflected-xss-via-filter-keyword\n",
1111
"aliases": "GHSA-xmgp-65vp-rxq2\nCVE-2023-54361\n",
1212
"assigner": "VulnCheck",
13-
"epss": 0.0,
13+
"epss": 0.04,
1414
"enisaIdProduct": [
1515
{
1616
"id": "45dcdda6-688e-3e91-8e4c-f8cee089dac9",

0 commit comments

Comments
 (0)