The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total53,256
Mitigations17,429
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Ninja Forms<= 3.15.4
Unauthenticated Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission vulnerability
7.1
5 hours ago
Ninja Forms File Uploads Extension<= 3.3.34
WordPress Ninja Forms - File Uploads plugin <= 3.3.34 - Unauthenticated Arbitrary File Upload vulnerability
10
5 hours ago
Super Forms<= 6.3.316
Authenticated (Subscriber+) Privilege Escalation vulnerability
8.8
5 hours ago
Super Forms<= 6.3.316
Unauthenticated Path Traversal to Arbitrary File Read vulnerability
7.5
5 hours ago
DevKit Pro<= 2.3.0
Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow vulnerability
9.8
6 hours ago
CTX Feed Pro<= 7.6.12
Authenticated (Administrator+) Remote Code Execution vulnerability
7.2
6 hours ago
vm2>= 3.11.4, <= 3.11.6
NPM: vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks
6.8
6 hours ago
vm2>= 3.9.6, <= 3.11.6
NPM: vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape
9.9
7 hours ago
vm2<= 3.11.6
host-realm require() is reachable from sandboxed scripts
8.6
7 hours ago
vm2>= 3.11.3, <= 3.11.6
NPM: vm2 exposes host HTTPS credentials and TLS traffic through globalAgent
10
7 hours ago
vm2<= 3.11.6
NPM: vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package
9.9
7 hours ago
vm2<= 3.11.6
NPM: vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes
8.5
7 hours ago
vm2<= 3.11.6
NPM: vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process
9.9
7 hours ago
vm2>= 3.9.6, <= 3.11.6
NPM: vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor
4
7 hours ago
vm2>= 3.11.4, <= 3.11.6
NPM: vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE
9
7 hours ago
vm23.11.6
NPM: vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection
10
7 hours ago
vm2>= 3.11.3, <= 3.11.6
NPM: vm2 allows a sandboxed plugin to execute native code through `node:sqlite`
9.9
7 hours ago
vm2>= 3.11.3, <= 3.11.6
NPM: vm2 crypto builtin loads attacker native code through setEngine
9.9
7 hours ago
vm2>= 3.10.2, <= 3.11.6
NPM: vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
9.8
7 hours ago
vm2>= 3.11.3, <= 3.11.6
NPM: vm2 NodeVM can replace the host process TLS trust store
10
7 hours ago