The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,728
Mitigations17,195
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
YAHMAN Add-ons< 0.9.31
Unauthenticated Arbitrary File Upload vulnerability
9
5 minutes ago
elysia< 1.4.29
NPM: elysia has Inefficient Algorithmic Complexity and Interpretation Conflict
7.5
8 hours ago
@fecommunity/reactpress<= 3.6.0
NPM: ReactPress has SQL injection via dynamic column names in TypeORM query builders
7.5
9 hours ago
Spectra<= 2.20.0
Authenticated (Contributor+) Sensitive Information Exposure vulnerability
7.5
9 hours ago
Kirki<= 6.2.0
Unauthenticated Blind Server-Side Request Forgery vulnerability
5.4
9 hours ago
@openc3/vue-common>= 5.0.6, <= 7.2.1
NPM: OpenC3 COSMOS: Stored, cross-user XSS via Telemetry screen BUTTON widget
7.6
9 hours ago
WP Multilang<= 2.4.31
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
10 hours ago
YOP Poll<= 7.0.10
Unauthenticated Origin Validation Error to Administrator Account Takeover vulnerability
8.8
10 hours ago
Admin Notices Manager<= 1.6.0
SQL Injection vulnerability
7.6
11 hours ago
W4 Post List<= 3.0.6
SQL Injection vulnerability
7.6
11 hours ago
9router<= 0.5.2
NPM: 9router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade
8.7
12 hours ago
9router<= 0.5.2
NPM: 9router: Kiro region injection allows authenticated SSRF with Authorization header forwarding
6.4
12 hours ago
9router<= 0.4.80
NPM: 9router: Image prefetch DNS rebinding allows SSRF to internal services
7.4
12 hours ago
9router<= 0.4.80
NPM: 9router /v1 APIs has unauthenticated access via reverse proxy locality collapse
8.3
12 hours ago
Safe SVG<= 2.5.0
Insecure Direct Object References (IDOR) vulnerability
4.3
13 hours ago
Estatik<= 4.3.5
SQL Injection vulnerability
7.6
13 hours ago
Safe SVG<= 2.5.0
Cross Site Scripting (XSS) vulnerability
6.5
13 hours ago
Gutenberg Blocks by Kadence Blocks<= 3.7.11
Cross Site Scripting (XSS) vulnerability
6.5
13 hours ago
SiteSkite<= 2.1.7
Insecure Direct Object References (IDOR) vulnerability
4.3
13 hours ago
Team<= 6.0.0
Insecure Direct Object References (IDOR) vulnerability
5.3
13 hours ago