The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total51,906
Mitigations16,951
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Repeater Fields for Gravity Forms<= 3.0.4
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
2 hours ago
Product Filter by WBW<= 3.4.2
Reflected Cross-Site Scripting vulnerability
7.1
2 hours ago
WP Crowdfunding<= 2.2.1
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
2 hours ago
WP EasyCart<= 5.9.3
Authenticated (Store Manager+) Privilege Escalation to ec_ajax_save_page_default_options AJAX Action vulnerability
7.2
2 hours ago
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent<= 4.4.1
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
2 hours ago
PublishPress Capabilities<= 2.50.0
Authenticated (Editor+) Privilege Escalation to Fresh-Install Default Capability Grant vulnerability
7.2
2 hours ago
YITH WooCommerce Waitlist Premium<= 3.35.0
Authenticated (Subscriber+) Privilege Escalation to Admin vulnerability
8.8
3 hours ago
WP Plugin Bluehost<= 4.19.0
Unauthenticated Authentication Bypass vulnerability
9.8
3 hours ago
WP Plugin Web<= 2.3.5
Unauthenticated Authentication Bypass vulnerability
9.8
3 hours ago
WP Plugin Crazy Domains<= 2.5.2
Unauthenticated Authentication Bypass vulnerability
9.8
3 hours ago
WP Module Data<= 2.9.7
Unauthenticated Authentication Bypass vulnerability
9.8
3 hours ago
WP Plugin Hostgator<= 3.2.0
Unauthenticated Authentication Bypass vulnerability
9.8
3 hours ago
Next-Cart Store to WooCommerce Migration<= 3.9.8
Unauthenticated Authentication Bypass via Default '__token__' Fallback in REST Migration Endpoint vulnerability
8.1
3 hours ago
n8n< 2.37.7
NPM: n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy
5.3
12 hours ago
nodemailer< 9.1.0
NPM: Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
6.5
12 hours ago
nodemailer< 9.1.0
NPM: Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
7.5
12 hours ago
nodemailer>= 6.9.16, < 9.1.0
NPM: Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
6.5
12 hours ago
@typespec/openapi3<= 1.15.0
NPM: OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
7.1
12 hours ago
@typespec/compiler<= 1.15.0
NPM: OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
7.1
12 hours ago
multer< 2.3.0
NPM: multer vulnerable to Denial of Service via crafted multipart field names
7.5
12 hours ago