The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,022
Mitigations16,984
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
bbPress<= 2.6.14
Sensitive Data Exposure vulnerability
5.3
24/09/2026
OTP Login Woocommerce & Gravity Forms<= 2.7.2
Unauthenticated Authentication Bypass via Brute Force vulnerability
5.3
10 minutes ago
WooCommerce PDF Invoice Builder<= 2.0.8
Authenticated (Subscriber+) Insecure Direct Object Reference to Sensitive Order Information Disclosure vulnerability
6.5
11 minutes ago
Sky Addons for Elementor<= 3.8.4
SQL Injection vulnerability
7.6
22 minutes ago
Bold Page Builder<= 5.9.9
Cross Site Scripting (XSS) vulnerability
6.5
22 minutes ago
Simple Payment<= 2.5.4
Cross Site Scripting (XSS) vulnerability
6.5
23 minutes ago
Amelia<= 2.4.9
SQL Injection vulnerability
7.6
24 minutes ago
Slim SEO<= 4.10.0
Insecure Direct Object References (IDOR) vulnerability
4.3
25 minutes ago
Passster<= 4.3.13
Broken Access Control vulnerability
5.3
41 minutes ago
@jhb.software/payload-alt-text-plugin<= 0.7.0
NPM: @jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission
7.1
8 hours ago
@argos-ci/core<= 6.2.0
NPM: @argos-ci/core: CI Branch Name OS Command Injection
7.5
8 hours ago
omniroute<= 3.8.50
NPM: OmniRoute ACP Custom-Agent Remote Code Execution (RCE)
9.5
9 hours ago
n8n< 2.37.7
NPM: n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
5.9
9 hours ago
n8n< 2.37.7
NPM: n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
5.9
9 hours ago
n8n< 1.123.76
NPM: n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
5.3
9 hours ago
n8n< 2.37.7
NPM: n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
5.1
9 hours ago
n8n< 1.123.76
NPM: n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
5.9
9 hours ago
n8n< 1.123.76
NPM: n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
6
9 hours ago
n8n< 1.123.76
NPM: n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
6.3
9 hours ago
n8n< 1.123.76
NPM: n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
6.3
9 hours ago