Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
53,750
Mitigations
Mitigation rules
17,716
No official patch
13,491
In triage
1,074
Published soon
131
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
sharp
< 0.35.5
NPM: sharp : Vulnerability in librsvg dependency CVE-2026-96889
8.9
57 minutes ago
shell-quote
>= 1.8.4, < 1.11.0
NPM: shell-quote: `quote()` command injection via a line terminator in a token after a `{ comment }` token
8.1
1 hour ago
pbkdf2
<= 3.1.6
NPM: pbkdf2 rehashes long passwords on every iteration, enabling denial of service
3.7
1 hour ago
elegro Crypto Payment
<= 1.0.1
Unauthenticated Arbitrary Order Status Change vulnerability
5.3
3 hours ago
Deema Payment Gateway
<= 1.1.2
Unauthenticated Payment Confirmation Forgery vulnerability
5.3
4 hours ago
Deema Payment Gateway
<= 1.1.2
Unauthenticated Payment Bypass and Order Manipulation vulnerability
5.3
4 hours ago
JetElements For Elementor
<= 2.9.2.2
Cross Site Scripting (XSS) vulnerability
6.5
6 hours ago
Slider Pro
<= 1.0.0
Unauthenticated Sensitive Data Disclosure vulnerability
5.3
8 hours ago
File Media Renamer
<= 1.3
Author+ Arbitrary File Rename vulnerability
6.5
8 hours ago
Fast Courier
<= 5.2.3
Unauthenticated Order Fulfillment Update vulnerability
5.3
8 hours ago
@simple-git/argv-parser
< 2.0.1
NPM: simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection
9.2
14 hours ago
simple-git
>= 3.15.0, < 4.0.1
NPM: simple-git unsafe-operation guard does not block trailer command configuration
9.2
14 hours ago
simple-git
<= 3.36.0
NPM: simple-git allows command execution through unblocked Git configuration includes
8.1
14 hours ago
simple-git
<= 3.36.0
NPM: simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (residual of CVE-2026-28291)
8.1
14 hours ago
@socket.io/cluster-engine
< 0.1.1
NPM: Socket.IO: Prototype Pollution via Unsafe Client Session Lookup
7.5
14 hours ago
dompurify
<= 3.4.15
NPM: DOMPurify: IN_PLACE returns a force-removed rawtext root whose text carries attacker markup — pure HTML reparse executes
0
14 hours ago
smol-toml
<= 1.8.0
NPM: smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line
5.3
15 hours ago
katex
>= 0.11.0, < 0.18.2
NPM: KaTeX: Existing prototype pollution can bypass trust restrictions
2.1
15 hours ago
seroval
>= 0.12.0, <= 1.6.0
NPM: Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of GHSA-mv8w-475r-vwqw)
9.8
15 hours ago
seroval
<= 1.6.2
NPM: Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserialization
7.5
15 hours ago
Load more