The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total51,593
Mitigations16,860
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
@platejs/docx-io< 53.3.2
NPM: Plate: SSRF with response disclosure in DOCX image embedding
8.2
30 minutes ago
link-preview-js<= 4.0.3
NPM: link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897
7.5
1 hour ago
fast-uri>= 2.4.2, < 2.4.5
NPM: fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references
7.5
7 hours ago
fast-uri>= 2.3.1, < 2.4.5
NPM: fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
7.5
7 hours ago
fast-uri>= 2.4.1, < 2.4.5
NPM: fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding
7.5
7 hours ago
fast-uri>= 2.3.1, < 2.4.5
NPM: fast-uri vulnerable to host confusion via percent-encoded scheme normalization
7.5
7 hours ago
@xmldom/xmldom>= 0.7.0, <= 0.8.14
NPM: xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization
6.3
7 hours ago
xmldom<= 0.6.0
NPM: xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization
6.3
7 hours ago
fastify>= 5.8.3, < 5.12.1
NPM: fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count
6.1
7 hours ago
fastify< 5.12.1
NPM: fastify vulnerable to schema validation bypass via root primitive coercion mismatch
5.4
7 hours ago
apostrophe<= 4.32.0
NPM: ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
7.1
7 hours ago
@apostrophecms/import-export<= 3.6.1
NPM: ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal
6.5
7 hours ago
orval< 8.22.0
NPM: Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
7.1
7 hours ago
orval< 8.21.0
NPM: Orval: Import-time RCE via query-parameter default -> zod module-level template literal
9.3
7 hours ago
orval< 8.21.0
NPM: Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client
9.3
7 hours ago
@aborruso/ckan-mcp-server< 0.4.112
NPM: CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)
5.3
7 hours ago
qs>= 6.14.2, <= 6.15.3
NPM: qs array-limit bypass via bracket-key comma parsing
3.7
7 hours ago
qs>= 2.2.5, < 6.16.0
NPM: qs: Denial of Service via Attacker Controlled isBuffer
5.3
7 hours ago
@tiptap/core>= 2.0.0-alpha.0, < 3.30.4
NPM: Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes
6.4
8 hours ago
pnpm< 10.34.5
NPM: pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph
7.1
8 hours ago