Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
51,951
Mitigations
Mitigation rules
16,968
No official patch
13,342
In triage
1,213
Published soon
28
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@openhop/server
<= 0.3.5
NPM: @openhop/server: Path Traversal in Flow ID File Operations
8.3
3 hours ago
functype-mcp-server
<= 1.4.3
NPM: functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import
7.8
3 hours ago
@yeger/turbo-graph
<= 2.8.8
NPM: @yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run
8.8
3 hours ago
nuxt-ollama
>= 1.2.26, < 1.3.1
NPM: Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients
7.5
3 hours ago
smol-toml
<= 1.7.0
NPM: smol-toml: Denial of Service via malformed TOML documents
8.2
8 hours ago
Brevo
<= 3.1.77
Reflected Cross-Site Scripting vulnerability
7.1
13 hours ago
TelSender
<= 1.14.14
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
13 hours ago
Podlove Podcast Publisher
<= 4.5.1
Arbitrary File Upload vulnerability
N/A
13 hours ago
Drag and Drop File Upload for Elementor Forms
<= 1.6.0
Unauthenticated Arbitrary File Upload via 'type' Parameter vulnerability
10
13 hours ago
SlideShowPro SC
<= 1.0.2
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
13 hours ago
CI HUB Connector
<= 1.2.106
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
13 hours ago
Inquiry Cart
<= 3.4.2
Cross-Site Request Forgery vulnerability
6.1
13 hours ago
Gallagher Website Design
<= 2.6.4
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
13 hours ago
Table Manager
<= 1.0.0
Authenticated (Contributor+) Sensitive Information Exposure vulnerability
4.3
13 hours ago
HTTP Headers
<= 1.19.2
Authenticated (Administrator+) External Control of File Name or Path to RCE vulnerability
7.2
13 hours ago
TP Restore Categories And Taxonomies
<= 1.0.1
Missing Authorization to Authenticated (Subscriber+) Taxonomy Deletion vulnerability
5.4
13 hours ago
CalJ Shabbat Times
<= 1.5
Authenticated (Subscriber+) Arbitrary Settings Modification vulnerability
5.3
13 hours ago
Gutentools
<= 1.1.3
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
13 hours ago
RTMKit
<= 2.0.2
Authenticated (Author+) Local File Inclusion vulnerability
7.2
13 hours ago
RTMKit
<= 2.0.7
Authenticated (Contributor+) Limited Local File Inclusion vulnerability
4.3
13 hours ago
Load more