Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,252
Mitigations
Mitigation rules
16,235
No official patch
13,227
In triage
1,095
Published soon
44
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
jsii-diff
< 1.131.0
NPM: jsii-diff: Command Injection via npm: package argument
7.8
29 minutes ago
@sveltejs/kit
<= 2.70.1
NPM: SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
5.3
1 hour ago
nuxt
>= 3.21.7, < 3.21.10
NPM: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
5.3
1 hour ago
dompurify
<= 3.4.12
NPM: DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
5.1
3 hours ago
WordPress
< 7.0.3
SSRF vulnerability
5.4
15 hours ago
WordPress
< 7.0.3
CSS Injection vulnerability
5.9
15 hours ago
WordPress
< 7.0.3
Sensitive Data Exposure vulnerability
5.3
15 hours ago
WordPress
< 7.0.3
Sensitive Data Exposure vulnerability
5.3
16 hours ago
WordPress
< 7.0.3
Stored XSS vulnerabiliity
6.5
16 hours ago
WordPress
7.0-7.0.2
Unauthenticated Sensitive Data Exposure vulnerability
5.3
20 hours ago
WordPress
< 7.0.3
Multiple Contributor+ Stored XSS vulnerabilities
6.5
20 hours ago
re2
<= 1.26.0
NPM: node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript
5.1
21 hours ago
re2
<= 1.25.0
NPM: node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length
6.2
21 hours ago
ngx-extended-pdf-viewer
>= 27.0.0-rc.0, < 29.0.0-rc.3
NPM: ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633
8.6
21 hours ago
pdfjs-dist
>= 5.6.83, < 6.2.108
NPM: PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF
8.6
21 hours ago
WordPress
< 7.0.3
Subscriber+ Site Creation vulnerability
7.1
21 hours ago
js-yaml
>= 3.0.0, < 3.15.1
NPM: JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
7.5
22 hours ago
nx
>= 20.8.0, < 22.7.7
NPM: Nx: Zip-Slip in the self-hosted remote cache
8.7
22 hours ago
@nx/s3-cache
<= 5.0.7
NPM: Nx: Zip-Slip in the self-hosted remote cache
8.7
22 hours ago
@nx/gcs-cache
<= 5.0.7
NPM: Nx: Zip-Slip in the self-hosted remote cache
8.7
22 hours ago
Load more