Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,215
Mitigations
Mitigation rules
16,217
No official patch
13,221
In triage
1,095
Published soon
43
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
WordPress
< 7.0.3
Subscriber+ Site Creation vulnerability
7.1
20 minutes ago
js-yaml
>= 3.0.0, < 3.15.1
NPM: JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
7.5
50 minutes ago
nx
>= 20.8.0, < 22.7.7
NPM: Nx: Zip-Slip in the self-hosted remote cache
8.7
1 hour ago
@nx/s3-cache
<= 5.0.7
NPM: Nx: Zip-Slip in the self-hosted remote cache
8.7
1 hour ago
@nx/gcs-cache
<= 5.0.7
NPM: Nx: Zip-Slip in the self-hosted remote cache
8.7
1 hour ago
@nx/azure-cache
<= 5.0.7
NPM: Nx: Zip-Slip in the self-hosted remote cache
8.7
1 hour ago
@nx/shared-fs-cache
<= 5.0.7
NPM: Nx: Zip-Slip in the self-hosted remote cache
8.7
1 hour ago
@nx/powerpack-s3-cache
<= 5.0.7
NPM: Nx: Zip-Slip in the self-hosted remote cache
8.7
1 hour ago
@nx/powerpack-gcs-cache
<= 5.0.7
NPM: Nx: Zip-Slip in the self-hosted remote cache
8.7
1 hour ago
@nx/powerpack-azure-cache
<= 5.0.7
NPM: Nx: Zip-Slip in the self-hosted remote cache
8.7
1 hour ago
@nx/powerpack-shared-fs-cache
<= 5.0.7
NPM: Nx: Zip-Slip in the self-hosted remote cache
8.7
1 hour ago
mermaid
>= 11.6.0, < 11.16.1
NPM: Mermaid radar diagrams are vulnerable to DoS
5.3
1 hour ago
mermaid
< 10.9.8
NPM: Mermaid configuration APIs allow prototype pollution
2.4
1 hour ago
mermaid
< 10.9.8
NPM: Mermaid allows CSS injection applying to sibling elements of the diagram
5.3
1 hour ago
mermaid
>= 11.5.0, < 11.16.1
NPM: Mermaid Architecture diagrams are vulnerable to prototype pollution
6.5
1 hour ago
mermaid
>= 10.6.0, < 10.9.8
NPM: Mermaid XY Charts are vulnerable to an infinite loop DoS
5.3
1 hour ago
WordPress
< 7.0.3
Reflected XSS to RCE vulnerability
7.1
1 hour ago
Simply Schedule Appointments
< 1.6.12.6
Unauthenticated Appointment Data Disclosure and Mass Deletion vulnerability
6.5
9 hours ago
Simple Restrict
< 1.2.9
Contributor+ Restricted Content Disclosure vulnerability
2.7
9 hours ago
ChatBot for eCommerce – WoowBot
< 4.8.4
Unauthenticated Gemini API Key Abuse vulnerability
6.5
9 hours ago
Load more