The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,014
Mitigations16,983
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
bbPress<= 2.6.14
Sensitive Data Exposure vulnerability
5.3
24/09/2026
omniroute<= 3.8.50
NPM: OmniRoute ACP Custom-Agent Remote Code Execution (RCE)
9.5
1 hour ago
n8n< 2.37.7
NPM: n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
5.9
1 hour ago
n8n< 2.37.7
NPM: n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
5.9
1 hour ago
n8n< 1.123.76
NPM: n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
5.3
1 hour ago
n8n< 2.37.7
NPM: n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
5.1
1 hour ago
n8n< 1.123.76
NPM: n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
5.9
1 hour ago
n8n< 1.123.76
NPM: n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
6
1 hour ago
n8n< 1.123.76
NPM: n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
6.3
1 hour ago
n8n< 1.123.76
NPM: n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
6.3
1 hour ago
n8n< 2.37.7
NPM: n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
6
1 hour ago
n8n< 1.123.76
NPM: n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
5.3
1 hour ago
Masteriyo - LMS<= 3.4.0
WordPress Masteriyo - LMS plugin <= 3.4.0 - Broken Access Control vulnerability
5.3
1 hour ago
RTMKit<= 2.1.5
Cross Site Request Forgery (CSRF) vulnerability
5.4
1 hour ago
Starter Templates<= 4.7.5
Insecure Direct Object References (IDOR) vulnerability
4.3
1 hour ago
Flexible Quantity – Measurement Price Calculator for WooCommerce<= 2.3.21
Broken Access Control vulnerability
5.3
1 hour ago
Booktics<= 1.0.24
Broken Access Control vulnerability
5.3
1 hour ago
Visual Composer Website Builder<= 45.16.1
Cross Site Scripting (XSS) vulnerability
6.5
1 hour ago
Site Kit by Google<= 1.186.0
Cross Site Request Forgery (CSRF) vulnerability
4.3
1 hour ago
Quiz And Survey Master<= 11.2.5
Insecure Direct Object References (IDOR) vulnerability
5.3
1 hour ago