Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,161
Mitigations
Mitigation rules
16,140
No official patch
13,202
In triage
1,140
Published soon
7
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@apostrophecms/seo
<= 1.4.2
NPM: @apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
8.7
1 day ago
apostrophe
<= 4.30.0
NPM: @apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
3.7
1 day ago
apostrophe
<= 4.30.0
NPM: Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
9.1
1 day ago
sanitize-html
>= 1.18.0, <= 2.17.4
NPM: sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes
5.4
1 day ago
@nocobase/plugin-notification-in-app-message
<= 2.0.60
NPM: NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
10
1 day ago
jodit
< 4.13.6
NPM: Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization
5.3
1 day ago
jodit
< 4.12.28
NPM: Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
7.2
1 day ago
jodit
< 4.12.18
NPM: Jodit has prototype pollution via Jodit.configure() / ConfigMerge
6.3
1 day ago
jodit
<= 4.12.30
NPM: Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS
5.4
1 day ago
@phun-ky/defaults-deep
< 2.0.5
NPM: @phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging
7.3
2 days ago
hashi-vault-js
<= 0.5.1
NPM: hashi-vault-js has a path traversal and query parameter injection
8.7
2 days ago
dssrf
<= 1.0.4
NPM: dssrf: any users using 1.1.1.1 DNS is impacted by SSRF
8.7
2 days ago
re2
<= 1.25.1
NPM: re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS)
5.7
2 days ago
re2
<= 1.25.1
NPM: re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS)
6.2
2 days ago
nx
>= 17.0.4, < 22.7.2
NPM: `nx graph` dev server permissive CORS policy
5.9
2 days ago
@dynatrace-oss/dynatrace-mcp-server
<= 1.8.7
NPM: `@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation
7.5
2 days ago
@dynatrace-oss/dynatrace-mcp-server
< 2.0.0
NPM: @dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification
4.2
2 days ago
@dynatrace-oss/dynatrace-mcp-server
< 2.1.1
NPM: @dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL
4.3
2 days ago
MasterStudy LMS
<= 3.7.39
Broken Access Control vulnerability
5.3
2 days ago
WP Maps
<= 4.9.6
Sensitive Data Exposure vulnerability
4.3
2 days ago
Load more