Skip to content

Commit ab02c6a

Browse files
Sync EUVD catalog: Wed Jun 10 00:58:59 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 709e8cd commit ab02c6a

675 files changed

Lines changed: 50179 additions & 3 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2009-5128",
3+
"enisaUuid": "6fb8dd65-03db-3d55-8a54-e2e556544d32",
4+
"description": "Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks.\n\nCatalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to impersonate the victim.",
5+
"datePublished": "Jun 9, 2026, 7:34:51 AM",
6+
"dateUpdated": "Jun 9, 2026, 3:21:06 PM",
7+
"baseScore": 9.1,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
10+
"references": "https://metacpan.org/release/ETHER/Catalyst-Plugin-Authentication-0.10_027/changes\nhttps://github.com/perl-catalyst/Catalyst-Plugin-Authentication/commit/b1385ea87a2491b64f33169222af19982d0acce3.patch\nhttps://metacpan.org/pod/Catalyst::Plugin::Session#change_session_id\nhttps://metacpan.org/pod/Plack::Middleware::Session#change_id\n",
11+
"aliases": "GHSA-pfqm-wq4x-p42c\nCVE-2009-10007\n",
12+
"assigner": "CPANSec",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "df124016-edb9-3f1b-b163-ea471102a002",
17+
"product": {
18+
"name": "Catalyst::Plugin::Authentication",
19+
"vendor": {
20+
"name": "JJNAPIORK"
21+
}
22+
},
23+
"product_version": "0 <0.10_027"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "a041393c-e16c-345a-9e58-cf8ade7a4bd2",
29+
"vendor": {
30+
"name": "ether"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2016-10875",
3+
"enisaUuid": "c396452d-97b8-36b6-b20e-2f4bf9c43110",
4+
"description": "Simply Poll 1.4.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the 'pollid' POST parameter. Attackers can send requests to the admin-ajax.php endpoint with the 'spAjaxResults' action and malicious 'pollid' values to execute arbitrary SQL queries and read sensitive data from the WordPress database.",
5+
"datePublished": "Jun 9, 2026, 11:48:30 AM",
6+
"dateUpdated": "Jun 9, 2026, 1:09:44 PM",
7+
"baseScore": 8.8,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/40971\nhttps://wordpress.org/plugins/simply-poll/\nhttps://tad.group\nhttps://www.vulncheck.com/advisories/simply-poll-plugin-for-wordpress-sql-injection\n",
11+
"aliases": "GHSA-72ph-53q2-5h66\nCVE-2016-20062\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "d5bd58e9-a605-3e8c-8f99-2d46f77706c9",
17+
"product": {
18+
"name": "Simply Poll",
19+
"vendor": {
20+
"name": "Ollie Armstrong"
21+
}
22+
},
23+
"product_version": "1.4.1"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "0290cb4a-2eeb-33cd-94a7-63b1fd989742",
29+
"vendor": {
30+
"name": "Ollie Armstrong"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2016-10876",
3+
"enisaUuid": "d5c59fcf-599f-3d38-a547-32eb7aa438cc",
4+
"description": "Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries by injecting malicious code through the message parameter. Attackers can access the admin interface and supply crafted SQL statements in the message parameter to extract sensitive database information including user credentials and site configuration data.",
5+
"datePublished": "Jun 9, 2026, 11:48:31 AM",
6+
"dateUpdated": "Jun 9, 2026, 4:10:28 PM",
7+
"baseScore": 7.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/40870\nhttps://wordpress.org/plugins/simple-personal-message/\nhttp://lenonleite.com.br/\nhttp://target/wp-admin/admin.php?page=simple-personal-message-outbox&action=view&message=0%20UNION%20SELECT%201,2.3,name,5,slug,7,8,9,10,11,12%20FROM%20wp_terms%20WHERE%20term_id=1\nhttps://www.vulncheck.com/advisories/single-personal-message-wordpress-plugin-sql-injection\n",
11+
"aliases": "CVE-2016-20063\nGHSA-w9r3-v9m2-5vxp\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "ca503155-8a58-3073-8284-6786f3675803",
17+
"product": {
18+
"name": "Single Personal Message",
19+
"vendor": {
20+
"name": "Md. Shamim Shahnewaz"
21+
}
22+
},
23+
"product_version": "1.0.3"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "f67e4c38-a5ee-3630-b840-167f9af3783f",
29+
"vendor": {
30+
"name": "Md. Shamim Shahnewaz"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2016-10877",
3+
"enisaUuid": "f1e5e443-7f53-3d4e-9f03-eda0d7e4443e",
4+
"description": "WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting an unescaped parameter in the include functionality. Attackers can supply directory traversal sequences through the wpv-image GET parameter to access sensitive files like system configuration and credentials.",
5+
"datePublished": "Jun 9, 2026, 11:48:31 AM",
6+
"dateUpdated": "Jun 9, 2026, 1:16:31 PM",
7+
"baseScore": 6.9,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/40850\nhttps://wordpress.org/plugins/wp-vault/\nhttp://lenonleite.com.br/\nhttps://www.vulncheck.com/advisories/wp-vault-local-file-inclusion-via-wpv-image-parameter\n",
11+
"aliases": "CVE-2016-20064\nGHSA-wqf8-xh9h-w6pf\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "3266a97e-bde8-3760-b3e8-3a6d9786f8ac",
17+
"product": {
18+
"name": "WP Vault",
19+
"vendor": {
20+
"name": "myasui"
21+
}
22+
},
23+
"product_version": "0.8.6.6"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "7b682d21-300b-31aa-a4c2-9f65cb0eee72",
29+
"vendor": {
30+
"name": "myasui"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2016-10878",
3+
"enisaUuid": "94d72f98-d5f8-3579-aada-dde1b089dfd2",
4+
"description": "Product Catalog 8 1.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the selectedCategory parameter. Attackers can submit POST requests to the admin-ajax.php endpoint with the UpdateCategoryList action to extract sensitive database information from WordPress tables.",
5+
"datePublished": "Jun 9, 2026, 11:48:32 AM",
6+
"dateUpdated": "Jun 9, 2026, 3:12:53 PM",
7+
"baseScore": 8.8,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/40783\nhttps://wordpress.org/plugins/product-catalog-8/\nhttp://lenonleite.com.br/\nhttps://www.vulncheck.com/advisories/product-catalog-8-plugin-wordpress-sql-injection\n",
11+
"aliases": "GHSA-j9gf-hrp2-6fx3\nCVE-2016-20065\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "f3ac138c-03ef-35bc-b04a-00deed788720",
17+
"product": {
18+
"name": "Product Catalog 8",
19+
"vendor": {
20+
"name": "EvWill"
21+
}
22+
},
23+
"product_version": "1.2.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "1006df5f-a37f-3a4b-89f9-d3cfde22b1a0",
29+
"vendor": {
30+
"name": "EvWill"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2017-18969",
3+
"enisaUuid": "07ea9da5-ed54-355c-9a6b-68f12563bbec",
4+
"description": "WordPress Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the space_id parameter. Attackers can send GET requests to the booking-page endpoint with malicious space_id values using AND SLEEP() payloads to extract sensitive database information.",
5+
"datePublished": "Jun 9, 2026, 11:48:33 AM",
6+
"dateUpdated": "Jun 9, 2026, 2:09:07 PM",
7+
"baseScore": 8.8,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/43012\nhttps://codecanyon.net/item/car-park-booking-wordpress-plugin/20284035\nhttps://www.vulncheck.com/advisories/wordpress-car-park-booking-plugin-sql-injection-via-space-id\n",
11+
"aliases": "GHSA-6f58-v6v9-pjm9\nCVE-2017-20243\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "a81d2bb3-744c-3ed1-9b55-af969397a9a3",
17+
"product": {
18+
"name": "Car Park Booking System",
19+
"vendor": {
20+
"name": "QuanticaLabs"
21+
}
22+
},
23+
"product_version": "1.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "36965711-dbc5-3602-aa7e-485caddc20e8",
29+
"vendor": {
30+
"name": "QuanticaLabs"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2017-18970",
3+
"enisaUuid": "027fad26-d2f5-339e-a177-833e04463d33",
4+
"description": "Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to read arbitrary database information by exploiting an unescaped POST parameter. Attackers can inject SQL code through the 'mwpformid' parameter in requests to the admin-ajax.php endpoint with the 'send_mwp_form' action to extract sensitive database contents.",
5+
"datePublished": "Jun 9, 2026, 11:48:34 AM",
6+
"dateUpdated": "Jun 9, 2026, 1:09:54 PM",
7+
"baseScore": 8.8,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/41922\nhttp://wow-company.com/\nhttps://tad.group\nhttps://wordpress.org/plugins/mwp-forms/\nhttps://www.vulncheck.com/advisories/wow-forms-wordpress-plugin-sql-injection\n",
11+
"aliases": "CVE-2017-20244\nGHSA-7jrg-cpg8-x952\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "df2dec0a-ce90-342b-97ea-05c2a8f0074b",
17+
"product": {
18+
"name": "Wow Forms",
19+
"vendor": {
20+
"name": "Wow-Company"
21+
}
22+
},
23+
"product_version": "2.1"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "84b8f81a-3c00-3262-acb8-197f3cfdc482",
29+
"vendor": {
30+
"name": "Wow-Company"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2017-18971",
3+
"enisaUuid": "5070723b-76ef-3619-98f6-28b02b729903",
4+
"description": "Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by exploiting the unescaped 'idsignup' POST parameter. Attackers can send crafted requests to the admin-ajax.php endpoint with malicious SQL payloads in the 'idsignup' parameter to read arbitrary data from the database.",
5+
"datePublished": "Jun 9, 2026, 11:48:34 AM",
6+
"dateUpdated": "Jun 9, 2026, 1:09:18 PM",
7+
"baseScore": 8.8,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/41921\nhttp://wow-company.com/\nhttps://tad.group\nhttps://wordpress.org/plugins/mwp-viral-signup/\nhttps://www.vulncheck.com/advisories/wow-viral-signups-wordpress-plugin-sql-injection\n",
11+
"aliases": "CVE-2017-20245\nGHSA-xq4v-2p5j-7jj7\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "62fb44d2-5464-39c6-90e9-a8b8f3b029fa",
17+
"product": {
18+
"name": "Wow Viral Signups",
19+
"vendor": {
20+
"name": "Wow-Company"
21+
}
22+
},
23+
"product_version": "2.1"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "7ac440c0-92cd-3d1c-bcad-a7005c589911",
29+
"vendor": {
30+
"name": "Wow-Company"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2017-18972",
3+
"enisaUuid": "1b84cb9f-4212-3a99-8d44-f000138f4d14",
4+
"description": "KittyCatfish 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to read database contents by exploiting an unescaped GET parameter. Attackers can inject SQL code through the 'kc_ad' parameter in base.css.php or kittycatfish.php to extract sensitive database information using boolean-based blind or time-based blind techniques.",
5+
"datePublished": "Jun 9, 2026, 11:48:35 AM",
6+
"dateUpdated": "Jun 9, 2026, 4:11:14 PM",
7+
"baseScore": 8.8,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/41919\nhttps://wordpress.org/plugins-wp/kittycatfish/\nhttps://tad.group\nhttps://www.vulncheck.com/advisories/kittycatfish-plugin-for-wordpress-sql-injection\n",
11+
"aliases": "GHSA-8xx3-4969-rp3q\nCVE-2017-20246\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "f4954463-7550-3ec5-aafa-43d23c948477",
17+
"product": {
18+
"name": "KittyCatfish",
19+
"vendor": {
20+
"name": "Missilesilo"
21+
}
22+
},
23+
"product_version": "2.2"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "7e23249b-7015-3f60-b167-a5180751067e",
29+
"vendor": {
30+
"name": "Missilesilo"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2017-18973",
3+
"enisaUuid": "64ce2b83-3434-3e7a-b70d-b6f354a97989",
4+
"description": "WordPress Plugin PICA Photo Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the aid parameter. Attackers can send GET requests with crafted SQL payloads in the aid parameter to extract sensitive database information including user credentials and table contents.",
5+
"datePublished": "Jun 9, 2026, 11:48:36 AM",
6+
"dateUpdated": "Jun 9, 2026, 1:01:53 PM",
7+
"baseScore": 8.8,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/41569\nhttps://www.apptha.com/\nhttps://www.vulncheck.com/advisories/wordpress-plugin-pica-photo-gallery-sql-injection\n",
11+
"aliases": "GHSA-23pq-pv24-pjcg\nCVE-2017-20247\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "4da1ec4c-66ef-3963-9c1a-6699b498c848",
17+
"product": {
18+
"name": "PICA Photo Gallery",
19+
"vendor": {
20+
"name": "Apptha"
21+
}
22+
},
23+
"product_version": "1.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "e55e4484-aa2f-3303-b8a0-2cbe68b8ae05",
29+
"vendor": {
30+
"name": "Apptha"
31+
}
32+
}
33+
]
34+
}

0 commit comments

Comments
 (0)