Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,932
Mitigations
Mitigation rules
17,300
No official patch
13,368
In triage
1,402
Published soon
21
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
nodemailer
>= 5.0.0, < 10.0.2
NPM: Nodemailer: Process-global DNS cache reuses TLS `servername` across transports, enabling cross-tenant SMTP credential disclosure
5.9
1 hour ago
undici
>= 6.25.0, < 6.28.1
NPM: undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression
5.9
2 hours ago
multer
>= 2.2.0, < 2.4.0
NPM: multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads
5.3
2 hours ago
morgan
< 1.12.1
NPM: morgan vulnerable to Log Injection via unescaped double quote in quoted log fields
5.3
2 hours ago
@angular/platform-server
<= 19.2.25
NPM: Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE
8.7
2 hours ago
fast-uri
< 2.4.6
NPM: fast-uri vulnerable to authority injection via an unvalidated port in serialize
7.5
2 hours ago
fast-uri
2.4.5
NPM: fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority
7.5
2 hours ago
ip-address
<= 10.5.0
NPM: ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts
6.3
3 hours ago
ip-address
>= 10.2.0, <= 10.5.0
NPM: ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass
6.9
3 hours ago
@angular/platform-server
<= 19.2.25
NPM: Angular SSR: XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Content Elements
8.6
3 hours ago
@grpc/grpc-js-xds
< 1.13.1
NPM: @grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches
6.5
4 hours ago
scim-patch
< 0.9.2
NPM: scim-patch: Mutation of Inherited Built-in Method Objects
4.3
9 hours ago
code-ollama
<= 0.36.0
NPM: code-ollama: `grep_search` Command Injection via Unescaped `$()` Shell Substitution (CWE-78)
7.8
9 hours ago
WP Review Slider Pro
< 12.7.12
Subscriber+ Stored XSS vulnerability
6.5
10 hours ago
File Manager
7.2.2-8.0.4
Unauthenticated Database Backup Disclosure vulnerability
5.9
10 hours ago
Verge3D
4.1.0-4.13.0
Unauthenticated Payment Bypass vulnerability
5.3
10 hours ago
Best Payments Plugin for WP
4.6.20-4.6.25
Unauthenticated Payment Bypass vulnerability
5.3
10 hours ago
Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification
1.3.0-2.3.1
Blocked User Restriction Bypass vulnerability
5.4
10 hours ago
Bookly
< 28.3
Unauthenticated Payment Bypass vulnerability
5.3
10 hours ago
Contact Form by WPForms
1.5.0.1-2.0.2.0
Unauthenticated Arbitrary Shortcode Execution vulnerability
6.5
10 hours ago
Load more