The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,162
Mitigations16,157
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Brandfolder<= 3.0
Unauthenticated Local File Inclusion vulnerability
8.1
5 minutes ago
WP with Spritz<= 1.0
Unauthenticated Local File Inclusion vulnerability
8.1
10 minutes ago
Simple Backup<= 2.7.11
Unauthenticated Arbitrary File Download vulnerability
7.5
15 minutes ago
BuddyPress<= 14.5.0
Authenticated (Subscriber+) PHP Object Injection vulnerability
8.8
17 minutes ago
Dharma Booking<= 2.28.3
Unauthenticated Local File Inclusion vulnerability
8.1
29 minutes ago
Membership by Supsystic<= 1.4.7
Unauthenticated SQL Injection vulnerability
9.3
37 minutes ago
Product Catalog 8<= 1.2.0
SQL Injection vulnerability
9.3
39 minutes ago
404 SEO Redirection<= 1.0
Unauthenticated SQL Injection vulnerability
9.3
40 minutes ago
WP Google Review Slider<= 6.1
Unauthenticated SQL Injection vulnerability
9.3
42 minutes ago
BBS e-Franchise< 1.1.4
SQL Injection vulnerability
9.3
44 minutes ago
WordPress Survey & Poll<= 1.5.7.3
Unauthenticated SQL Injection vulnerability
9.3
46 minutes ago
Wow Viral Signups<= 2.1
Unauthenticated SQL Injection vulnerability
9.3
50 minutes ago
Flights &amp; Hotels Booking WP Plugin<= 2.3
Unauthenticated SQL Injection vulnerability
9.3
52 minutes ago
PICA Photo Gallery <= 1.0
SQL Injection vulnerability
9.3
54 minutes ago
KittyCatfish<= 2.2
Unauthenticated SQL Injection vulnerability
9.3
1 hour ago
Car Park Booking System for WordPress<= 1.0
Unauthenticated SQL Injection vulnerability
9.3
1 hour ago
FleekDash V2<= 2.6.2.2
Missing Authorization to Authenticated (Subscriber+) Administrator Account Takeover vulnerability
8.8
1 hour ago
@apostrophecms/seo<= 1.4.2
NPM: @apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
8.7
2 days ago
apostrophe<= 4.30.0
NPM: @apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
3.7
2 days ago
apostrophe<= 4.30.0
NPM: Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
9.1
2 days ago