Skip to content

Commit 709e8cd

Browse files
Sync EUVD catalog: Tue Jun 9 00:52:49 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent c513b78 commit 709e8cd

247 files changed

Lines changed: 13576 additions & 58 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2020-31250",
3+
"enisaUuid": "89130d45-8086-3df1-9f6a-19c8c6a3a1c7",
4+
"description": "OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials in cleartext.",
5+
"datePublished": "Jun 8, 2026, 3:05:09 PM",
6+
"dateUpdated": "Jun 8, 2026, 6:49:00 PM",
7+
"baseScore": 6.5,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N",
10+
"references": "https://github.com/OfflineIMAP/offlineimap3/commit/46505c53ef995455d66c685f9ec3ff6ea93dbb74\nhttps://github.com/OfflineIMAP/offlineimap3/issues/222\nhttps://github.com/OfflineIMAP/offlineimap/issues/669\nhttps://pypi.org/project/offlineimap/#history\n",
11+
"aliases": "CVE-2020-37248\nGHSA-899r-9fxv-q4xm\n",
12+
"assigner": "mitre",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "828ab580-b927-3873-9601-5a1e318b20c3",
17+
"product": {
18+
"name": "offlineimap",
19+
"vendor": {
20+
"name": "offlineimap"
21+
}
22+
},
23+
"product_version": "0 <8.0.3"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "7e15a661-c793-3e7e-b267-0baf94152592",
29+
"vendor": {
30+
"name": "offlineimap"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2021-34848",
3+
"enisaUuid": "5aac94d6-20df-34d4-9abc-ee60259e4c7d",
4+
"description": "WordPress Plugin WP-Paginate 2.1.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by manipulating the preset parameter. Attackers can submit POST requests to the plugin settings page with script payloads in the preset parameter that are stored and executed when administrators view the settings.",
5+
"datePublished": "Jun 8, 2026, 1:55:25 AM",
6+
"dateUpdated": "Jun 8, 2026, 4:32:56 PM",
7+
"baseScore": 5.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/49355\nhttps://wordpress.org/plugins/wp-paginate/\nhttps://www.vulncheck.com/advisories/wordpress-plugin-wp-paginate-stored-xss-via-preset\n",
11+
"aliases": "GHSA-8prr-62q3-84mp\nCVE-2021-47982\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "12004c0f-c1ff-3705-bfc3-13e5ea9f14f5",
17+
"product": {
18+
"name": "WP-Paginate",
19+
"vendor": {
20+
"name": "Unknown"
21+
}
22+
},
23+
"product_version": "2.1.3"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "e5847026-c360-35fa-8c76-409a733f2e64",
29+
"vendor": {
30+
"name": "maxfoundry"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2021-34849",
3+
"enisaUuid": "38f8934e-93fa-36a1-99e0-1f7a6fbe087d",
4+
"description": "WordPress Plugin Stripe Payments 2.0.39 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the AcceptStripePayments-settings[currency_code] parameter. Attackers can submit POST requests to /wp-admin/options.php with script payloads in the currency_code field to execute arbitrary JavaScript in administrator browsers when settings are viewed.",
5+
"datePublished": "Jun 8, 2026, 1:55:26 AM",
6+
"dateUpdated": "Jun 8, 2026, 1:55:26 AM",
7+
"baseScore": 5.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/49354\nhttps://wordpress.org/plugins/stripe-payments/#developers\nhttps://www.vulncheck.com/advisories/wordpress-plugin-stripe-payments-stored-xss-via-currency-code\n",
11+
"aliases": "CVE-2021-47983\nGHSA-g9mx-rrvw-6m52\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "2e81cbd8-ab6f-3be6-9cd8-8315b633457a",
17+
"product": {
18+
"name": "Accept Stripe Payments",
19+
"vendor": {
20+
"name": "wptipsntricks"
21+
}
22+
},
23+
"product_version": "2.0.39"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "4e809ea8-7d16-3196-8d86-88589abe58a1",
29+
"vendor": {
30+
"name": "mra13"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2021-34850",
3+
"enisaUuid": "83e7006d-4e02-3d43-8d8a-087b7994098e",
4+
"description": "WordPress Plugin WP24 Domain Check 1.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input to the fieldnameDomain parameter. Attackers can inject JavaScript payloads through the plugin settings form at options.php that execute in the browsers of administrators viewing the settings page.",
5+
"datePublished": "Jun 8, 2026, 1:55:26 AM",
6+
"dateUpdated": "Jun 8, 2026, 1:38:29 PM",
7+
"baseScore": 5.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/49377\nhttps://wordpress.org/plugins/wp24-domain-check/\nhttps://www.vulncheck.com/advisories/wordpress-plugin-wp24-domain-check-stored-xss\n",
11+
"aliases": "GHSA-2gq4-h2qw-hmmh\nCVE-2021-47984\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "f04dde11-b601-3ba9-ae96-85d17c660ee1",
17+
"product": {
18+
"name": "WP24 Domain Check",
19+
"vendor": {
20+
"name": "WP24"
21+
}
22+
},
23+
"product_version": "1.6.2"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "f67f2aa6-ded3-3bc8-ad4e-f306008c8a50",
29+
"vendor": {
30+
"name": "WP24"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2022-56000",
3+
"enisaUuid": "43f48241-a1f9-375d-9153-6e3cd2046565",
4+
"description": "WordPress Plugin admin-word-count-column 2.2 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting null byte injection in the path parameter. Attackers can send GET requests to download-csv.php with a crafted path parameter containing directory traversal sequences and null bytes to bypass file restrictions and read sensitive files like system configuration.",
5+
"datePublished": "Jun 8, 2026, 1:55:27 AM",
6+
"dateUpdated": "Jun 8, 2026, 12:59:18 PM",
7+
"baseScore": 6.9,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/50845\nhttps://wordpress.org/plugins/admin-word-count-column/\nhttps://www.vulncheck.com/advisories/wordpress-plugin-admin-word-count-column-local-file-read\n",
11+
"aliases": "GHSA-x7v7-749j-rvh3\nCVE-2022-50953\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "18c6fc26-8034-3665-9c00-7189df35cdfd",
17+
"product": {
18+
"name": "admin-word-count-column",
19+
"vendor": {
20+
"name": "brooks24"
21+
}
22+
},
23+
"product_version": "2.2"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "3218f50d-adbd-3b86-ab04-48cfc1c2dade",
29+
"vendor": {
30+
"name": "brooks24"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2023-60581",
3+
"enisaUuid": "b885646b-f459-39be-ac7c-17d691f5b26c",
4+
"description": "WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector that allows unauthenticated attackers to upload and execute arbitrary PHP files. Attackers can send POST requests to the connector.minimal.php endpoint with mkfile and put commands to create malicious PHP files in the file_manager directory and execute them on the server.",
5+
"datePublished": "Jun 8, 2026, 1:55:28 AM",
6+
"dateUpdated": "Jun 8, 2026, 1:55:28 AM",
7+
"baseScore": 8.7,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/51788\nhttps://www.vulncheck.com/advisories/wordpress-augmented-reality-plugin-remote-code-execution-unauthenticated\n",
11+
"aliases": "CVE-2023-54350\nGHSA-2qg7-25w5-v2qc\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "81a92b51-23b3-3cc6-9d7d-3de915530d30",
17+
"product": {
18+
"name": "Augmented Reality",
19+
"vendor": {
20+
"name": "webandprint"
21+
}
22+
},
23+
"product_version": "7.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "2ef0bec5-f6a4-3c71-8ad7-0861c63ad2f4",
29+
"vendor": {
30+
"name": "webandprint"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2023-60582",
3+
"enisaUuid": "b6999c1f-1701-3a31-8acd-5ddf8f855a82",
4+
"description": "WordPress Sonaar Music Plugin 4.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the comment functionality. Attackers can submit JavaScript payloads in the comment parameter to wp-comments-post.php which are stored and executed in the browsers of users viewing the affected playlist pages.",
5+
"datePublished": "Jun 8, 2026, 1:55:29 AM",
6+
"dateUpdated": "Jun 8, 2026, 11:01:45 AM",
7+
"baseScore": 5.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/51739\nhttps://www.vulncheck.com/advisories/wordpress-sonaar-music-plugin-stored-xss-via-comments\n",
11+
"aliases": "CVE-2023-54351\nGHSA-mqpf-p827-ffx5\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "709135bc-eba8-34ad-b863-0f8e70aa263f",
17+
"product": {
18+
"name": "Sonaar Music Plugin",
19+
"vendor": {
20+
"name": "sonaar"
21+
}
22+
},
23+
"product_version": "4.7"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "7b38f0cd-7135-377d-9a27-0c6c7ffdfb90",
29+
"vendor": {
30+
"name": "sonaar"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2023-60583",
3+
"enisaUuid": "229d73da-272b-3fe4-a978-f7b7d771be28",
4+
"description": "WordPress Seotheme contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by uploading malicious files to the theme directory. Attackers can access the uploaded PHP shell at /wp-content/themes/seotheme/mar.php to execute system commands and upload additional files for persistent access.",
5+
"datePublished": "Jun 8, 2026, 1:55:29 AM",
6+
"dateUpdated": "Jun 8, 2026, 4:32:49 PM",
7+
"baseScore": 9.3,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/51789\nhttps://www.vulncheck.com/advisories/wordpress-seotheme-remote-code-execution-unauthenticated\n",
11+
"aliases": "CVE-2023-54352\nGHSA-mc6x-cw9h-wfr5\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "0980a16d-f3d1-3ceb-8e86-102f0c0aa40a",
17+
"product": {
18+
"name": "Travelscape",
19+
"vendor": {
20+
"name": "WP Travel Kit"
21+
}
22+
},
23+
"product_version": "1.0.3"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "c6af6028-3f4e-3629-a292-1968326d83f5",
29+
"vendor": {
30+
"name": "WP Travel Kit"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2024-55614",
3+
"enisaUuid": "c6c7893f-bb7f-38d3-a8e3-8dd25ffea587",
4+
"description": "WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticated attackers to upload arbitrary files by accessing the ups.php endpoint. Attackers can upload PHP files through the file upload form in the plugin directory to execute arbitrary code on the server.",
5+
"datePublished": "Jun 8, 2026, 1:55:30 AM",
6+
"dateUpdated": "Jun 8, 2026, 1:37:35 PM",
7+
"baseScore": 9.3,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/51998\nhttps://wordpress.org\nhttps://wordpress.org/plugins/background-image-cropper/\nhttps://www.vulncheck.com/advisories/wordpress-background-image-cropper-remote-code-execution\n",
11+
"aliases": "GHSA-x5xw-hc63-vrfp\nCVE-2024-58348\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "4929dee1-bab4-3c7e-81e1-d9b1a1afa4bd",
17+
"product": {
18+
"name": "Background Image Cropper",
19+
"vendor": {
20+
"name": "background-image-cropper"
21+
}
22+
},
23+
"product_version": "1.2"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "951cbcce-51b7-3705-9d8d-87f4672eef2e",
29+
"vendor": {
30+
"name": "background-image-cropper"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2024-55615",
3+
"enisaUuid": "102bc98a-ec42-31ff-a19b-6e00d72848d1",
4+
"description": "WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting insufficient validation in the theme's upload functionality. Attackers can upload arbitrary files to the theme directory and execute them to achieve remote code execution on the affected WordPress installation.",
5+
"datePublished": "Jun 8, 2026, 1:55:31 AM",
6+
"dateUpdated": "Jun 8, 2026, 12:59:54 PM",
7+
"baseScore": 9.3,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/51969\nhttps://www.vulncheck.com/advisories/wordpress-theme-travelscape-arbitrary-file-upload\n",
11+
"aliases": "GHSA-976h-hgxf-4vrc\nCVE-2024-58349\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "aec1046f-36ad-33a2-93a3-3f6d9acc8ed8",
17+
"product": {
18+
"name": "Travelscape",
19+
"vendor": {
20+
"name": "WP Travel Kit"
21+
}
22+
},
23+
"product_version": "1.0.3"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "f207f182-e777-39bc-b0a3-8651c6c20f2c",
29+
"vendor": {
30+
"name": "WP Travel Kit"
31+
}
32+
}
33+
]
34+
}

0 commit comments

Comments
 (0)