The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,094
Mitigations16,087
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Subscriptions for WooCommerce<= 2.0.0
Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation vulnerability
7.2
8 hours ago
mathlive<= 0.109.2
NPM: mathlive's Lack of Escaping of HTML allows for XSS
6.3
12 hours ago
@aws/agentcore>= 0.3.0-preview.7.0, <= 0.3.0-preview.9.0
NPM: AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
9
13 hours ago
@dynatrace-oss/dynatrace-mcp-server< 1.8.7
NPM: @dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
3.7
14 hours ago
Improved Save Button<= 1.2.1
Authenticated (Author+) Second-Order SQL Injection vulnerability
8.5
15 hours ago
swagger-typescript-api<= 13.12.1
NPM: swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
8.3
15 hours ago
swagger-typescript-api<= 13.12.1
NPM: swagger-typescript-api vulnerable to code injection via unescaped enum string values
8.3
15 hours ago
swagger-typescript-api<= 13.12.1
NPM: swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
8.3
15 hours ago
swagger-typescript-api<= 13.12.1
NPM: swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
6.1
15 hours ago
swagger-typescript-api<= 13.12.1
NPM: swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
8.3
15 hours ago
swagger-typescript-api<= 13.12.1
NPM: swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
7.4
15 hours ago
المنتور فارسی<= 2.8.1
Unauthenticated Price Manipulation vulnerability
5.3
15 hours ago
WP Compress< 7.10.04
Reflected XSS vulnerability
7.1
18 hours ago
Sina Extension for Elementor< 3.10.2
Reflected XSS vulnerability
7.1
18 hours ago
MPG< 4.1.8
Reflected XSS vulnerability
7.1
18 hours ago
Simply Schedule Appointments< 1.6.12.4
Unauthenticated Stored XSS vulnerability
7.1
18 hours ago
WowOptin< 1.4.38
Unauthenticated Opt-in Deactivation and Template Row Injection vulnerability
7.5
18 hours ago
Software Issue Manager< 5.1.0
Unauthenticated SQL Injection vulnerability
9.3
18 hours ago
Document Gallery< 5.1.1
Reflected XSS vulnerability
7.1
18 hours ago
Praison SEO WordPress< 5.0.7
Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure) vulnerability
7.5
19 hours ago