Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,774
Mitigations
Mitigation rules
16,024
No official patch
13,108
In triage
1,241
Published soon
67
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@anthropic-ai/claude-code
>= 2.1.38, < 2.1.163
NPM: Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
7.7
3 hours ago
js-yaml
>= 5.0.0, <= 5.2.1
NPM: js-yaml: Exponential parsing time in flow collections leads to denial of service
7.5
3 hours ago
react-router
>= 7.12.0, < 8.3.0
NPM: React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
7.1
3 hours ago
aws-cdk-lib
< 2.253.0
NPM: AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
3 hours ago
@aws-cdk/aws-codebuild
>= 1.75.0, <= 1.204.0
NPM: AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
3 hours ago
@fastify/static
<= 10.1.1
NPM: @fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
5.3
3 hours ago
@fastify/static
<= 10.1.0
NPM: @fastify/static vulnerable to route guard bypass via path traversal
7.5
3 hours ago
tar
<= 7.5.20
NPM: node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
5.3
4 hours ago
postcss
<= 8.5.17
NPM: PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
7.5
4 hours ago
@prompty/core
<= 0.1.4
NPM: Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
10
4 hours ago
mongoose
< 6.13.10
NPM: Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
6.5
4 hours ago
velocityjs
<= 2.1.6
NPM: Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
9.8
4 hours ago
@backstage/plugin-auth-backend
<= 0.29.1
NPM: @backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
4.7
4 hours ago
trix
< 2.1.18
NPM: Trix: Stored XSS via HTMLParser attribute injection on paste
4.6
4 hours ago
valibot
<= 1.4.1
NPM: Valibot: record() issue paths can make flatten() throw for inherited Object property names
6.9
4 hours ago
seroval
<= 1.5.2
NPM: seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
9.8
4 hours ago
@sveltejs/kit
<= 2.69.0
NPM: SvelteKit: Prototype pollution in file input deletion path in remote-function forms
4.3
4 hours ago
@sveltejs/kit
<= 2.69.0
NPM: SvelteKit: Big remote form function payloads can cause Node process to crash
5.3
4 hours ago
better-auth
>= 1.1.3, < 1.6.22
NPM: Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
8.3
4 hours ago
@better-auth/stripe
>= 1.4.11, < 1.6.21
NPM: @better-auth/stripe: cross-organization billing tampering in organization subscription actions
7.1
4 hours ago
Load more