Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,708
Mitigations
Mitigation rules
16,012
No official patch
13,107
In triage
1,269
Published soon
137
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
postcss
<= 8.5.11
NPM: PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
7.5
1 hour ago
next-auth
>= 5.0.0-beta.0, <= 5.0.0-beta.31
NPM: Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
9.1
1 hour ago
next-auth
>= 4.0.6, <= 4.24.14
NPM: Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
7.5
2 hours ago
@auth/core
>= 0.1.0, < 0.41.3
NPM: Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
7.5
2 hours ago
next-auth
>= 4.10.3, < 4.24.15
NPM: Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
9.1
2 hours ago
@auth/core
>= 0.1.0, < 0.41.3
NPM: Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
9.1
2 hours ago
next-auth
<= 4.24.14
NPM: Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
6.8
2 hours ago
@auth/core
<= 0.41.2
NPM: Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
6.8
2 hours ago
n8n
< 1.123.67
NPM: n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
5.3
17 hours ago
n8n
< 1.123.67
NPM: n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
5.8
17 hours ago
n8n
< 1.123.67
NPM: n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
5.8
17 hours ago
next
>= 14.1.1, < 15.5.21
NPM: Next.js: Server-Side Request Forgery in Server Actions on custom servers
8.3
17 hours ago
next
>= 13.0.0, < 15.5.21
NPM: Next.js: Cache confusion of response bodies for requests with bodies
6
17 hours ago
next
>= 13.0.0, < 15.5.21
NPM: Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
6.3
17 hours ago
next
>= 13.0.0, < 15.5.21
NPM: Next.js: Unbounded Server Action payload in Edge runtime
6.3
17 hours ago
next
>= 12.0.0, < 15.5.21
NPM: Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
8.3
17 hours ago
next
>= 15.5.0, < 15.5.21
NPM: Next.js: Denial of Service in the Image Optimization API using SVGs
6.3
17 hours ago
next
>= 13.0.0, < 15.5.21
NPM: Next.js: Unauthenticated disclosure of internal Server Function endpoints
6.3
17 hours ago
next
>= 16.0.0, < 16.2.11
NPM: Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
8.3
17 hours ago
next
>= 13.0.0, < 15.5.21
NPM: Next.js: Denial of Service in App Router using Server Actions
8.2
17 hours ago
Load more