Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
51,595
Mitigations
Mitigation rules
16,860
No official patch
13,334
In triage
1,093
Published soon
37
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@dicebear/core
<= 9.4.2
NPM: DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)
4.7
53 minutes ago
@dicebear/initials
<= 9.4.2
NPM: DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)
4.7
53 minutes ago
@platejs/docx-io
< 53.3.2
NPM: Plate: SSRF with response disclosure in DOCX image embedding
8.2
1 hour ago
link-preview-js
<= 4.0.3
NPM: link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897
7.5
2 hours ago
fast-uri
>= 2.4.2, < 2.4.5
NPM: fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references
7.5
7 hours ago
fast-uri
>= 2.3.1, < 2.4.5
NPM: fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
7.5
7 hours ago
fast-uri
>= 2.4.1, < 2.4.5
NPM: fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding
7.5
7 hours ago
fast-uri
>= 2.3.1, < 2.4.5
NPM: fast-uri vulnerable to host confusion via percent-encoded scheme normalization
7.5
7 hours ago
@xmldom/xmldom
>= 0.7.0, <= 0.8.14
NPM: xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization
6.3
8 hours ago
xmldom
<= 0.6.0
NPM: xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization
6.3
8 hours ago
fastify
>= 5.8.3, < 5.12.1
NPM: fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count
6.1
8 hours ago
fastify
< 5.12.1
NPM: fastify vulnerable to schema validation bypass via root primitive coercion mismatch
5.4
8 hours ago
apostrophe
<= 4.32.0
NPM: ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
7.1
8 hours ago
@apostrophecms/import-export
<= 3.6.1
NPM: ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal
6.5
8 hours ago
orval
< 8.22.0
NPM: Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
7.1
8 hours ago
orval
< 8.21.0
NPM: Orval: Import-time RCE via query-parameter default -> zod module-level template literal
9.3
8 hours ago
orval
< 8.21.0
NPM: Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client
9.3
8 hours ago
@aborruso/ckan-mcp-server
< 0.4.112
NPM: CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)
5.3
8 hours ago
qs
>= 6.14.2, <= 6.15.3
NPM: qs array-limit bypass via bracket-key comma parsing
3.7
8 hours ago
qs
>= 2.2.5, < 6.16.0
NPM: qs: Denial of Service via Attacker Controlled isBuffer
5.3
8 hours ago
Load more