From abf274a4235c6ebdbdc649f3ae135c16ab8e2b75 Mon Sep 17 00:00:00 2001 From: "tastendruck[bot]" <191388063+tastendruck[bot]@users.noreply.github.com> Date: Fri, 7 Aug 2026 06:50:22 +0000 Subject: [PATCH] :robot: `go generate ./...` Automated commit by the `Update Data` workflow. --- internal/data/assets/plugin_73747265616d811c9dc5_gen.json | 2 +- ...5722d6170706f696e746d656e742d626f6f6b696e67811c9dc5_gen.json | 2 +- ...f6e732d666f722d636f6e746163742d666f726d2d37811c9dc5_gen.json | 2 +- ...174657761792d666f722d776f6f636f6d6d65726365811c9dc5_gen.json | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/internal/data/assets/plugin_73747265616d811c9dc5_gen.json b/internal/data/assets/plugin_73747265616d811c9dc5_gen.json index 8fd12569..8d6936fc 100644 --- a/internal/data/assets/plugin_73747265616d811c9dc5_gen.json +++ b/internal/data/assets/plugin_73747265616d811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/26926973-36b7-4ad2-8267-2de4749159ab/stream","title":"Stream <= 3.8.1 - Admin+ SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-10-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"26926973-36b7-4ad2-8267-2de4749159ab"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/26926973-36b7-4ad2-8267-2de4749159ab?source=api-prod","cve":"CVE-2021-24772","affectedVersions":"<=3.8.1","severity":"high"},{"advisoryId":"WPSECADV/WF/67f81b8a-ef0a-4b6d-a1ee-3e19bda6fd96/stream","title":"Stream <= 3.9.1 - Missing Authorization to Sensitive Information Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"67f81b8a-ef0a-4b6d-a1ee-3e19bda6fd96"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/67f81b8a-ef0a-4b6d-a1ee-3e19bda6fd96?source=api-prod","cve":"CVE-2022-4384","affectedVersions":"<=3.9.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/8680ad0a-7513-408d-a62d-ffb0b0e7addb/stream","title":"Stream <= 4.0.2 - Authenticated (Admin+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"8680ad0a-7513-408d-a62d-ffb0b0e7addb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8680ad0a-7513-408d-a62d-ffb0b0e7addb?source=api-prod","cve":"CVE-2024-13879","affectedVersions":"<=4.0.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/9d15e418-36bb-4f53-ac67-8f6122591dd2/stream","title":"Stream <= 4.0.1 - Cross-Site Request Forgery to Arbitrary Options Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"9d15e418-36bb-4f53-ac67-8f6122591dd2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9d15e418-36bb-4f53-ac67-8f6122591dd2?source=api-prod","cve":"CVE-2024-7423","affectedVersions":"<=4.0.1","severity":"high"},{"advisoryId":"WPSECADV/WF/d58e4317-8ad5-40d5-98b8-f8f07ab37e1f/stream","title":"Stream <= 3.9.2 - Missing Authorization via load_alerts_settings\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"d58e4317-8ad5-40d5-98b8-f8f07ab37e1f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d58e4317-8ad5-40d5-98b8-f8f07ab37e1f?source=api-prod","cve":"CVE-2022-43450","affectedVersions":"<3.9.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/e7203b5c-5753-453c-8fc2-26fcebdeea5b/stream","title":"Stream <= 3.9.2 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"e7203b5c-5753-453c-8fc2-26fcebdeea5b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e7203b5c-5753-453c-8fc2-26fcebdeea5b?source=api-prod","cve":"CVE-2022-43490","affectedVersions":"<=3.9.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/ecd68933-e808-4816-b9d2-7491194f2347/stream","title":"Stream <= 3.0.5 - Sensitive Data Exposure\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-05-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"ecd68933-e808-4816-b9d2-7491194f2347"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ecd68933-e808-4816-b9d2-7491194f2347?source=api-prod","affectedVersions":"<=3.0.5","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/26926973-36b7-4ad2-8267-2de4749159ab/stream","title":"Stream <= 3.8.1 - Admin+ SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2021-10-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"26926973-36b7-4ad2-8267-2de4749159ab"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/26926973-36b7-4ad2-8267-2de4749159ab?source=api-prod","cve":"CVE-2021-24772","affectedVersions":"<=3.8.1","severity":"high"},{"advisoryId":"WPSECADV/WF/67f81b8a-ef0a-4b6d-a1ee-3e19bda6fd96/stream","title":"Stream <= 3.9.1 - Missing Authorization to Sensitive Information Disclosure\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-01-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"67f81b8a-ef0a-4b6d-a1ee-3e19bda6fd96"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/67f81b8a-ef0a-4b6d-a1ee-3e19bda6fd96?source=api-prod","cve":"CVE-2022-4384","affectedVersions":"<=3.9.1","severity":"medium"},{"advisoryId":"WPSECADV/WF/8680ad0a-7513-408d-a62d-ffb0b0e7addb/stream","title":"Stream <= 4.0.2 - Authenticated (Admin+) Server-Side Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-02-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"8680ad0a-7513-408d-a62d-ffb0b0e7addb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8680ad0a-7513-408d-a62d-ffb0b0e7addb?source=api-prod","cve":"CVE-2024-13879","affectedVersions":"<=4.0.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/9d15e418-36bb-4f53-ac67-8f6122591dd2/stream","title":"Stream <= 4.0.1 - Cross-Site Request Forgery to Arbitrary Options Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-09-12 00:00:00","sources":[{"name":"Wordfence","remoteId":"9d15e418-36bb-4f53-ac67-8f6122591dd2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9d15e418-36bb-4f53-ac67-8f6122591dd2?source=api-prod","cve":"CVE-2024-7423","affectedVersions":"<=4.0.1","severity":"high"},{"advisoryId":"WPSECADV/WF/b7c7e45a-581e-4cf0-83ac-cbca816701f1/stream","title":"Stream <= 4.2.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via Heartbeat API\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-08-06 16:25:31","sources":[{"name":"Wordfence","remoteId":"b7c7e45a-581e-4cf0-83ac-cbca816701f1"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b7c7e45a-581e-4cf0-83ac-cbca816701f1?source=api-prod","cve":"CVE-2026-11907","affectedVersions":"<=4.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/d58e4317-8ad5-40d5-98b8-f8f07ab37e1f/stream","title":"Stream <= 3.9.2 - Missing Authorization via load_alerts_settings\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-25 00:00:00","sources":[{"name":"Wordfence","remoteId":"d58e4317-8ad5-40d5-98b8-f8f07ab37e1f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d58e4317-8ad5-40d5-98b8-f8f07ab37e1f?source=api-prod","cve":"CVE-2022-43450","affectedVersions":"<3.9.3","severity":"medium"},{"advisoryId":"WPSECADV/WF/e7203b5c-5753-453c-8fc2-26fcebdeea5b/stream","title":"Stream <= 3.9.2 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"e7203b5c-5753-453c-8fc2-26fcebdeea5b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e7203b5c-5753-453c-8fc2-26fcebdeea5b?source=api-prod","cve":"CVE-2022-43490","affectedVersions":"<=3.9.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/ecd68933-e808-4816-b9d2-7491194f2347/stream","title":"Stream <= 3.0.5 - Sensitive Data Exposure\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2016-05-31 00:00:00","sources":[{"name":"Wordfence","remoteId":"ecd68933-e808-4816-b9d2-7491194f2347"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ecd68933-e808-4816-b9d2-7491194f2347?source=api-prod","affectedVersions":"<=3.0.5","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_74727565626f6f6b65722d6170706f696e746d656e742d626f6f6b696e67811c9dc5_gen.json b/internal/data/assets/plugin_74727565626f6f6b65722d6170706f696e746d656e742d626f6f6b696e67811c9dc5_gen.json index 26411f11..2edee990 100644 --- a/internal/data/assets/plugin_74727565626f6f6b65722d6170706f696e746d656e742d626f6f6b696e67811c9dc5_gen.json +++ b/internal/data/assets/plugin_74727565626f6f6b65722d6170706f696e746d656e742d626f6f6b696e67811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/4192f1eb-e52a-4b79-8795-ef79c687e9ae/truebooker-appointment-booking","title":"TrueBooker – Appointment Booking and Scheduler System <= 1.2.3 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"4192f1eb-e52a-4b79-8795-ef79c687e9ae"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4192f1eb-e52a-4b79-8795-ef79c687e9ae?source=api-prod","cve":"CVE-2026-61950","affectedVersions":"<=1.2.3","severity":"high"},{"advisoryId":"WPSECADV/WF/4ebe8b63-ea43-4e39-9fdf-e28fb4638433/truebooker-appointment-booking","title":"Truebooker - Appointment Booking and Scheduler Plugin <= 1.1.4 - Sensitive Information Exposure via Views Files\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-30 16:18:30","sources":[{"name":"Wordfence","remoteId":"4ebe8b63-ea43-4e39-9fdf-e28fb4638433"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4ebe8b63-ea43-4e39-9fdf-e28fb4638433?source=api-prod","cve":"CVE-2026-1797","affectedVersions":"<=1.1.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/71257639-2ba5-4ac2-b4fe-8f22311b6482/truebooker-appointment-booking","title":"TrueBooker – Appointment Booking and Scheduler System <= 1.1.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-06-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"71257639-2ba5-4ac2-b4fe-8f22311b6482"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/71257639-2ba5-4ac2-b4fe-8f22311b6482?source=api-prod","cve":"CVE-2026-48881","affectedVersions":"<=1.1.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/95e79929-332f-42bc-b2ad-00b8867dcb86/truebooker-appointment-booking","title":"TrueBooker <= 1.0.7 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"95e79929-332f-42bc-b2ad-00b8867dcb86"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/95e79929-332f-42bc-b2ad-00b8867dcb86?source=api-prod","cve":"CVE-2025-47543","affectedVersions":"<=1.0.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/971d40d2-428f-49d9-8918-89843980f177/truebooker-appointment-booking","title":"TrueBooker <= 1.0.3 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"971d40d2-428f-49d9-8918-89843980f177"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/971d40d2-428f-49d9-8918-89843980f177?source=api-prod","cve":"CVE-2024-6924","affectedVersions":"<=1.0.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/9b0e973b-f0bf-44d1-b964-e259f68291aa/truebooker-appointment-booking","title":"TrueBooker <= 1.2.2 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-27 20:17:19","sources":[{"name":"Wordfence","remoteId":"9b0e973b-f0bf-44d1-b964-e259f68291aa"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9b0e973b-f0bf-44d1-b964-e259f68291aa?source=api-prod","cve":"CVE-2026-13161","affectedVersions":"<=1.2.2","severity":"high"},{"advisoryId":"WPSECADV/WF/b3940953-fdd4-4759-8476-a421cfbbbd30/truebooker-appointment-booking","title":"TrueBooker <= 1.1.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"b3940953-fdd4-4759-8476-a421cfbbbd30"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b3940953-fdd4-4759-8476-a421cfbbbd30?source=api-prod","cve":"CVE-2025-67581","affectedVersions":"<=1.1.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/bc36c9e4-5f6d-4cb8-85b3-f02e00b6d3cb/truebooker-appointment-booking","title":"TrueBooker <= 1.1.6 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"bc36c9e4-5f6d-4cb8-85b3-f02e00b6d3cb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bc36c9e4-5f6d-4cb8-85b3-f02e00b6d3cb?source=api-prod","cve":"CVE-2026-39663","affectedVersions":"<=1.1.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/be8afa0c-af65-46d7-af07-de67353eddb5/truebooker-appointment-booking","title":"TrueBooker – Appointment Booking and Scheduler System <= 1.2.3 - Unauthenticated Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"be8afa0c-af65-46d7-af07-de67353eddb5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/be8afa0c-af65-46d7-af07-de67353eddb5?source=api-prod","cve":"CVE-2026-61951","affectedVersions":"<=1.2.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/cf3d2b0f-667f-469e-a1de-3be213cd7007/truebooker-appointment-booking","title":"TrueBooker <= 1.0.2 - Cross-Site Request Forgery to Settings Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"cf3d2b0f-667f-469e-a1de-3be213cd7007"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cf3d2b0f-667f-469e-a1de-3be213cd7007?source=api-prod","cve":"CVE-2024-6925","affectedVersions":"<=1.0.2","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/4192f1eb-e52a-4b79-8795-ef79c687e9ae/truebooker-appointment-booking","title":"TrueBooker – Appointment Booking and Scheduler System <= 1.2.3 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-16 00:00:00","sources":[{"name":"Wordfence","remoteId":"4192f1eb-e52a-4b79-8795-ef79c687e9ae"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4192f1eb-e52a-4b79-8795-ef79c687e9ae?source=api-prod","cve":"CVE-2026-61950","affectedVersions":"<=1.2.3","severity":"high"},{"advisoryId":"WPSECADV/WF/4ebe8b63-ea43-4e39-9fdf-e28fb4638433/truebooker-appointment-booking","title":"Truebooker - Appointment Booking and Scheduler Plugin <= 1.1.4 - Sensitive Information Exposure via Views Files\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-30 16:18:30","sources":[{"name":"Wordfence","remoteId":"4ebe8b63-ea43-4e39-9fdf-e28fb4638433"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4ebe8b63-ea43-4e39-9fdf-e28fb4638433?source=api-prod","cve":"CVE-2026-1797","affectedVersions":"<=1.1.4","severity":"medium"},{"advisoryId":"WPSECADV/WF/71257639-2ba5-4ac2-b4fe-8f22311b6482/truebooker-appointment-booking","title":"TrueBooker – Appointment Booking and Scheduler System <= 1.1.9 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-06-02 00:00:00","sources":[{"name":"Wordfence","remoteId":"71257639-2ba5-4ac2-b4fe-8f22311b6482"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/71257639-2ba5-4ac2-b4fe-8f22311b6482?source=api-prod","cve":"CVE-2026-48881","affectedVersions":"<=1.1.9","severity":"medium"},{"advisoryId":"WPSECADV/WF/95e79929-332f-42bc-b2ad-00b8867dcb86/truebooker-appointment-booking","title":"TrueBooker <= 1.0.7 - Cross-Site Request Forgery\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-05-07 00:00:00","sources":[{"name":"Wordfence","remoteId":"95e79929-332f-42bc-b2ad-00b8867dcb86"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/95e79929-332f-42bc-b2ad-00b8867dcb86?source=api-prod","cve":"CVE-2025-47543","affectedVersions":"<=1.0.7","severity":"medium"},{"advisoryId":"WPSECADV/WF/971d40d2-428f-49d9-8918-89843980f177/truebooker-appointment-booking","title":"TrueBooker <= 1.0.3 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"971d40d2-428f-49d9-8918-89843980f177"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/971d40d2-428f-49d9-8918-89843980f177?source=api-prod","cve":"CVE-2024-6924","affectedVersions":"<=1.0.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/9b0e973b-f0bf-44d1-b964-e259f68291aa/truebooker-appointment-booking","title":"TrueBooker <= 1.2.2 - Unauthenticated SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-27 20:17:19","sources":[{"name":"Wordfence","remoteId":"9b0e973b-f0bf-44d1-b964-e259f68291aa"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9b0e973b-f0bf-44d1-b964-e259f68291aa?source=api-prod","cve":"CVE-2026-13161","affectedVersions":"<=1.2.2","severity":"high"},{"advisoryId":"WPSECADV/WF/afe10c10-cace-4ce4-a813-6fda04c8d3dd/truebooker-appointment-booking","title":"TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'truebooker_wp_user_id'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-08-06 16:23:19","sources":[{"name":"Wordfence","remoteId":"afe10c10-cace-4ce4-a813-6fda04c8d3dd"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/afe10c10-cace-4ce4-a813-6fda04c8d3dd?source=api-prod","cve":"CVE-2026-14365","affectedVersions":"<=1.2.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/b3940953-fdd4-4759-8476-a421cfbbbd30/truebooker-appointment-booking","title":"TrueBooker <= 1.1.0 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-15 00:00:00","sources":[{"name":"Wordfence","remoteId":"b3940953-fdd4-4759-8476-a421cfbbbd30"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b3940953-fdd4-4759-8476-a421cfbbbd30?source=api-prod","cve":"CVE-2025-67581","affectedVersions":"<=1.1.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/bc36c9e4-5f6d-4cb8-85b3-f02e00b6d3cb/truebooker-appointment-booking","title":"TrueBooker <= 1.1.6 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-02-18 00:00:00","sources":[{"name":"Wordfence","remoteId":"bc36c9e4-5f6d-4cb8-85b3-f02e00b6d3cb"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bc36c9e4-5f6d-4cb8-85b3-f02e00b6d3cb?source=api-prod","cve":"CVE-2026-39663","affectedVersions":"<=1.1.6","severity":"medium"},{"advisoryId":"WPSECADV/WF/be8afa0c-af65-46d7-af07-de67353eddb5/truebooker-appointment-booking","title":"TrueBooker – Appointment Booking and Scheduler System <= 1.2.3 - Unauthenticated Privilege Escalation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-17 00:00:00","sources":[{"name":"Wordfence","remoteId":"be8afa0c-af65-46d7-af07-de67353eddb5"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/be8afa0c-af65-46d7-af07-de67353eddb5?source=api-prod","cve":"CVE-2026-61951","affectedVersions":"<=1.2.3","severity":"critical"},{"advisoryId":"WPSECADV/WF/cf3d2b0f-667f-469e-a1de-3be213cd7007/truebooker-appointment-booking","title":"TrueBooker <= 1.0.2 - Cross-Site Request Forgery to Settings Update\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2024-08-10 00:00:00","sources":[{"name":"Wordfence","remoteId":"cf3d2b0f-667f-469e-a1de-3be213cd7007"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/cf3d2b0f-667f-469e-a1de-3be213cd7007?source=api-prod","cve":"CVE-2024-6925","affectedVersions":"<=1.0.2","severity":"medium"},{"advisoryId":"WPSECADV/WF/f441477e-35b8-42ae-b71c-3fdba126021b/truebooker-appointment-booking","title":"TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset via 'tbab-userid'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-08-06 16:24:20","sources":[{"name":"Wordfence","remoteId":"f441477e-35b8-42ae-b71c-3fdba126021b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f441477e-35b8-42ae-b71c-3fdba126021b?source=api-prod","cve":"CVE-2026-14364","affectedVersions":"<=1.2.3","severity":"critical"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_756c74696d6174652d6164646f6e732d666f722d636f6e746163742d666f726d2d37811c9dc5_gen.json b/internal/data/assets/plugin_756c74696d6174652d6164646f6e732d666f722d636f6e746163742d666f726d2d37811c9dc5_gen.json index 6bc87a8f..972cc425 100644 --- a/internal/data/assets/plugin_756c74696d6174652d6164646f6e732d666f722d636f6e746163742d666f726d2d37811c9dc5_gen.json +++ b/internal/data/assets/plugin_756c74696d6174652d6164646f6e732d666f722d636f6e746163742d666f726d2d37811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/015942ef-fb6c-4b58-ab67-f7e903321f32/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.5.34 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"015942ef-fb6c-4b58-ab67-f7e903321f32"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/015942ef-fb6c-4b58-ab67-f7e903321f32?source=api-prod","cve":"CVE-2026-24945","affectedVersions":"<=3.5.34","severity":"medium"},{"advisoryId":"WPSECADV/WF/1723a465-75ca-4fea-ad9c-d96ffb5625a8/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.1.28 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"1723a465-75ca-4fea-ad9c-d96ffb5625a8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1723a465-75ca-4fea-ad9c-d96ffb5625a8?source=api-prod","cve":"CVE-2023-2803","affectedVersions":"<3.1.29","severity":"medium"},{"advisoryId":"WPSECADV/WF/2be06087-4616-47bb-8a33-3bba97c47cb2/ultimate-addons-for-contact-form-7","title":"Ultra Addons for Contact Form 7 <= 3.5.36 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"2be06087-4616-47bb-8a33-3bba97c47cb2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2be06087-4616-47bb-8a33-3bba97c47cb2?source=api-prod","cve":"CVE-2026-32460","affectedVersions":"<=3.5.36","severity":"medium"},{"advisoryId":"WPSECADV/WF/364946a5-ce1e-4872-895d-e7cf795a04f7/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.2.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"364946a5-ce1e-4872-895d-e7cf795a04f7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/364946a5-ce1e-4872-895d-e7cf795a04f7?source=api-prod","cve":"CVE-2023-49766","affectedVersions":"<=3.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/3af9ece0-1556-4457-87ee-343daec5e74f/ultimate-addons-for-contact-form-7","title":"Ultra Addons for Contact Form 7 <= 3.5.33 - Missing Authorization to Authenticated (Subscriber+) to Generate Form Submission PDF\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-11 17:40:29","sources":[{"name":"Wordfence","remoteId":"3af9ece0-1556-4457-87ee-343daec5e74f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3af9ece0-1556-4457-87ee-343daec5e74f?source=api-prod","cve":"CVE-2025-14356","affectedVersions":"<=3.5.33","severity":"medium"},{"advisoryId":"WPSECADV/WF/5b839658-c472-40f0-855f-7201baeb790f/ultimate-addons-for-contact-form-7","title":"Ultra Addons for Contact Form 7 <= 3.5.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via UACF7_CUSTOM_FIELDS Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-30 20:53:07","sources":[{"name":"Wordfence","remoteId":"5b839658-c472-40f0-855f-7201baeb790f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5b839658-c472-40f0-855f-7201baeb790f?source=api-prod","cve":"CVE-2025-6756","affectedVersions":"<=3.5.21","severity":"medium"},{"advisoryId":"WPSECADV/WF/5db5c5e0-f2ba-4082-b3eb-33cc0ce418e8/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.1.23 - Authenticated (Subscriber+) SQL Injection via id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"5db5c5e0-f2ba-4082-b3eb-33cc0ce418e8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5db5c5e0-f2ba-4082-b3eb-33cc0ce418e8?source=api-prod","cve":"CVE-2023-30495","affectedVersions":"<=3.1.23","severity":"high"},{"advisoryId":"WPSECADV/WF/697f3432-63b7-42d6-b188-812165cd2020/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.5.12 - Authenticated (Administrator+) Arbitrary File Upload via 'save_options'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-17 22:49:16","sources":[{"name":"Wordfence","remoteId":"697f3432-63b7-42d6-b188-812165cd2020"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/697f3432-63b7-42d6-b188-812165cd2020?source=api-prod","cve":"CVE-2025-6220","affectedVersions":"<=3.5.12","severity":"high"},{"advisoryId":"WPSECADV/WF/6d1517d4-79d0-4d4b-b54d-86e00dabd874/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.1.28 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"6d1517d4-79d0-4d4b-b54d-86e00dabd874"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6d1517d4-79d0-4d4b-b54d-86e00dabd874?source=api-prod","cve":"CVE-2023-2802","affectedVersions":"<3.1.29","severity":"medium"},{"advisoryId":"WPSECADV/WF/73720e67-79e5-4b4c-8720-e28ad718b2b3/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.2.10 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"73720e67-79e5-4b4c-8720-e28ad718b2b3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/73720e67-79e5-4b4c-8720-e28ad718b2b3?source=api-prod","cve":"CVE-2023-47693","affectedVersions":"<=3.2.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/817ca119-ddaf-4525-beee-68c4e0aac544/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.1.23 - Authenticated(Subscriber+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-06-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"817ca119-ddaf-4525-beee-68c4e0aac544"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/817ca119-ddaf-4525-beee-68c4e0aac544?source=api-prod","cve":"CVE-2023-1615","affectedVersions":"=3.1.23","severity":"high"},{"advisoryId":"WPSECADV/WF/922c029e-57a9-4c18-8598-9ea3bbc2ab69/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.5.45 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"922c029e-57a9-4c18-8598-9ea3bbc2ab69"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/922c029e-57a9-4c18-8598-9ea3bbc2ab69?source=api-prod","cve":"CVE-2026-65439","affectedVersions":"<=3.5.45","severity":"high"},{"advisoryId":"WPSECADV/WF/d857324c-94c9-471a-9da8-0b8c9bb50262/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.1.0 - Reflected Cross-Site Scripting via 'page'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"d857324c-94c9-471a-9da8-0b8c9bb50262"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d857324c-94c9-471a-9da8-0b8c9bb50262?source=api-prod","cve":"CVE-2023-30493","affectedVersions":"<=3.1.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/f10e5eef-1ccf-4f98-b0e9-5ed05b3881a6/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.1.23 - Unauthenticated SQL Injection via form_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"f10e5eef-1ccf-4f98-b0e9-5ed05b3881a6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f10e5eef-1ccf-4f98-b0e9-5ed05b3881a6?source=api-prod","cve":"CVE-2022-47586","affectedVersions":"<=3.1.23","severity":"critical"},{"advisoryId":"WPSECADV/WF/f49e48cb-7d0b-4bcf-9090-869472b8442a/ultimate-addons-for-contact-form-7","title":"Ultra Addons for Contact Form 7 3.5.11 - 3.5.19 - Unauthenticated Stored Cross-Site Scripting via Database module\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-25 20:51:54","sources":[{"name":"Wordfence","remoteId":"f49e48cb-7d0b-4bcf-9090-869472b8442a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f49e48cb-7d0b-4bcf-9090-869472b8442a?source=api-prod","cve":"CVE-2025-6212","affectedVersions":">=3.5.11,<=3.5.19","severity":"high"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/015942ef-fb6c-4b58-ab67-f7e903321f32/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.5.34 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-13 00:00:00","sources":[{"name":"Wordfence","remoteId":"015942ef-fb6c-4b58-ab67-f7e903321f32"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/015942ef-fb6c-4b58-ab67-f7e903321f32?source=api-prod","cve":"CVE-2026-24945","affectedVersions":"<=3.5.34","severity":"medium"},{"advisoryId":"WPSECADV/WF/1723a465-75ca-4fea-ad9c-d96ffb5625a8/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.1.28 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"1723a465-75ca-4fea-ad9c-d96ffb5625a8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1723a465-75ca-4fea-ad9c-d96ffb5625a8?source=api-prod","cve":"CVE-2023-2803","affectedVersions":"<3.1.29","severity":"medium"},{"advisoryId":"WPSECADV/WF/2be06087-4616-47bb-8a33-3bba97c47cb2/ultimate-addons-for-contact-form-7","title":"Ultra Addons for Contact Form 7 <= 3.5.36 - Authenticated (Contributor+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-03-14 00:00:00","sources":[{"name":"Wordfence","remoteId":"2be06087-4616-47bb-8a33-3bba97c47cb2"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2be06087-4616-47bb-8a33-3bba97c47cb2?source=api-prod","cve":"CVE-2026-32460","affectedVersions":"<=3.5.36","severity":"medium"},{"advisoryId":"WPSECADV/WF/364946a5-ce1e-4872-895d-e7cf795a04f7/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.2.0 - Reflected Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-12-04 00:00:00","sources":[{"name":"Wordfence","remoteId":"364946a5-ce1e-4872-895d-e7cf795a04f7"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/364946a5-ce1e-4872-895d-e7cf795a04f7?source=api-prod","cve":"CVE-2023-49766","affectedVersions":"<=3.2.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/3af9ece0-1556-4457-87ee-343daec5e74f/ultimate-addons-for-contact-form-7","title":"Ultra Addons for Contact Form 7 <= 3.5.33 - Missing Authorization to Authenticated (Subscriber+) to Generate Form Submission PDF\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-12-11 17:40:29","sources":[{"name":"Wordfence","remoteId":"3af9ece0-1556-4457-87ee-343daec5e74f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3af9ece0-1556-4457-87ee-343daec5e74f?source=api-prod","cve":"CVE-2025-14356","affectedVersions":"<=3.5.33","severity":"medium"},{"advisoryId":"WPSECADV/WF/5b839658-c472-40f0-855f-7201baeb790f/ultimate-addons-for-contact-form-7","title":"Ultra Addons for Contact Form 7 <= 3.5.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via UACF7_CUSTOM_FIELDS Shortcode\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-30 20:53:07","sources":[{"name":"Wordfence","remoteId":"5b839658-c472-40f0-855f-7201baeb790f"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5b839658-c472-40f0-855f-7201baeb790f?source=api-prod","cve":"CVE-2025-6756","affectedVersions":"<=3.5.21","severity":"medium"},{"advisoryId":"WPSECADV/WF/5db5c5e0-f2ba-4082-b3eb-33cc0ce418e8/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.1.23 - Authenticated (Subscriber+) SQL Injection via id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-04-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"5db5c5e0-f2ba-4082-b3eb-33cc0ce418e8"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5db5c5e0-f2ba-4082-b3eb-33cc0ce418e8?source=api-prod","cve":"CVE-2023-30495","affectedVersions":"<=3.1.23","severity":"high"},{"advisoryId":"WPSECADV/WF/697f3432-63b7-42d6-b188-812165cd2020/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.5.12 - Authenticated (Administrator+) Arbitrary File Upload via 'save_options'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-17 22:49:16","sources":[{"name":"Wordfence","remoteId":"697f3432-63b7-42d6-b188-812165cd2020"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/697f3432-63b7-42d6-b188-812165cd2020?source=api-prod","cve":"CVE-2025-6220","affectedVersions":"<=3.5.12","severity":"high"},{"advisoryId":"WPSECADV/WF/6d1517d4-79d0-4d4b-b54d-86e00dabd874/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.1.28 - Authenticated (Admin+) Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-07-24 00:00:00","sources":[{"name":"Wordfence","remoteId":"6d1517d4-79d0-4d4b-b54d-86e00dabd874"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/6d1517d4-79d0-4d4b-b54d-86e00dabd874?source=api-prod","cve":"CVE-2023-2802","affectedVersions":"<3.1.29","severity":"medium"},{"advisoryId":"WPSECADV/WF/73720e67-79e5-4b4c-8720-e28ad718b2b3/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.2.10 - Missing Authorization\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-11-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"73720e67-79e5-4b4c-8720-e28ad718b2b3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/73720e67-79e5-4b4c-8720-e28ad718b2b3?source=api-prod","cve":"CVE-2023-47693","affectedVersions":"<=3.2.10","severity":"medium"},{"advisoryId":"WPSECADV/WF/817ca119-ddaf-4525-beee-68c4e0aac544/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.1.23 - Authenticated(Subscriber+) SQL Injection\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-06-08 00:00:00","sources":[{"name":"Wordfence","remoteId":"817ca119-ddaf-4525-beee-68c4e0aac544"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/817ca119-ddaf-4525-beee-68c4e0aac544?source=api-prod","cve":"CVE-2023-1615","affectedVersions":"=3.1.23","severity":"high"},{"advisoryId":"WPSECADV/WF/922c029e-57a9-4c18-8598-9ea3bbc2ab69/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.5.45 - Unauthenticated Stored Cross-Site Scripting\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-07-27 00:00:00","sources":[{"name":"Wordfence","remoteId":"922c029e-57a9-4c18-8598-9ea3bbc2ab69"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/922c029e-57a9-4c18-8598-9ea3bbc2ab69?source=api-prod","cve":"CVE-2026-65439","affectedVersions":"<=3.5.45","severity":"high"},{"advisoryId":"WPSECADV/WF/b111bfd5-3eff-4255-9123-cae38bfb73c3/ultimate-addons-for-contact-form-7","title":"Ultra Addons for Contact Form 7 <= 3.5.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via Slider Attributes\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-08-06 16:21:57","sources":[{"name":"Wordfence","remoteId":"b111bfd5-3eff-4255-9123-cae38bfb73c3"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b111bfd5-3eff-4255-9123-cae38bfb73c3?source=api-prod","cve":"CVE-2026-12801","affectedVersions":"<=3.5.43","severity":"medium"},{"advisoryId":"WPSECADV/WF/d857324c-94c9-471a-9da8-0b8c9bb50262/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.1.0 - Reflected Cross-Site Scripting via 'page'\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-08-28 00:00:00","sources":[{"name":"Wordfence","remoteId":"d857324c-94c9-471a-9da8-0b8c9bb50262"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d857324c-94c9-471a-9da8-0b8c9bb50262?source=api-prod","cve":"CVE-2023-30493","affectedVersions":"<=3.1.0","severity":"medium"},{"advisoryId":"WPSECADV/WF/f10e5eef-1ccf-4f98-b0e9-5ed05b3881a6/ultimate-addons-for-contact-form-7","title":"Ultimate Addons for Contact Form 7 <= 3.1.23 - Unauthenticated SQL Injection via form_id\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2023-05-09 00:00:00","sources":[{"name":"Wordfence","remoteId":"f10e5eef-1ccf-4f98-b0e9-5ed05b3881a6"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f10e5eef-1ccf-4f98-b0e9-5ed05b3881a6?source=api-prod","cve":"CVE-2022-47586","affectedVersions":"<=3.1.23","severity":"critical"},{"advisoryId":"WPSECADV/WF/f49e48cb-7d0b-4bcf-9090-869472b8442a/ultimate-addons-for-contact-form-7","title":"Ultra Addons for Contact Form 7 3.5.11 - 3.5.19 - Unauthenticated Stored Cross-Site Scripting via Database module\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2025-06-25 20:51:54","sources":[{"name":"Wordfence","remoteId":"f49e48cb-7d0b-4bcf-9090-869472b8442a"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f49e48cb-7d0b-4bcf-9090-869472b8442a?source=api-prod","cve":"CVE-2025-6212","affectedVersions":">=3.5.11,<=3.5.19","severity":"high"}] \ No newline at end of file diff --git a/internal/data/assets/plugin_77697a69742d676174657761792d666f722d776f6f636f6d6d65726365811c9dc5_gen.json b/internal/data/assets/plugin_77697a69742d676174657761792d666f722d776f6f636f6d6d65726365811c9dc5_gen.json index 3c87b794..81c3b7c9 100644 --- a/internal/data/assets/plugin_77697a69742d676174657761792d666f722d776f6f636f6d6d65726365811c9dc5_gen.json +++ b/internal/data/assets/plugin_77697a69742d676174657761792d666f722d776f6f636f6d6d65726365811c9dc5_gen.json @@ -1 +1 @@ -[{"advisoryId":"WPSECADV/WF/b6926c2c-79d4-477c-a2eb-ba62545f2e2b/wizit-gateway-for-woocommerce","title":"Wizit Gateway for WooCommerce <= 1.2.9 - Missing Authentication to Unauthenticated Arbitrary Order Cancellation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-23 19:23:49","sources":[{"name":"Wordfence","remoteId":"b6926c2c-79d4-477c-a2eb-ba62545f2e2b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b6926c2c-79d4-477c-a2eb-ba62545f2e2b?source=api-prod","cve":"CVE-2025-14843","affectedVersions":"<=1.2.9","severity":"medium"}] \ No newline at end of file +[{"advisoryId":"WPSECADV/WF/b6926c2c-79d4-477c-a2eb-ba62545f2e2b/wizit-gateway-for-woocommerce","title":"Wizit Gateway for WooCommerce <= 1.3.1 - Missing Authentication to Unauthenticated Arbitrary Order Cancellation\n### Copyright 1999-2026 The MITRE Corporation\nCVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.\nhttps://www.cve.org/Legal/TermsOfUse\n### Copyright 2012-2026 Defiant Inc.\nDefiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.\nhttps://www.wordfence.com/wordfence-intelligence-terms-and-conditions/","reportedAt":"2026-01-23 19:23:49","sources":[{"name":"Wordfence","remoteId":"b6926c2c-79d4-477c-a2eb-ba62545f2e2b"}],"link":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b6926c2c-79d4-477c-a2eb-ba62545f2e2b?source=api-prod","cve":"CVE-2025-14843","affectedVersions":"<=1.3.1","severity":"medium"}] \ No newline at end of file