Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,295
Mitigations
Mitigation rules
16,213
No official patch
13,189
In triage
1,139
Published soon
18
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
ghost
>= 6.27.0, < 6.44.0
NPM: Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
5.3
1 hour ago
ghost
>= 5.18.0, < 6.21.1
NPM: Ghost: Member existence leak via magic link sign-in response
5.3
1 hour ago
@tryghost/activitypub
< 3.1.0
NPM: XSS in Ghost's ActivityPub client
7.5
1 hour ago
ghost
>= 2.2.0, < 6.54.1
NPM: Ghost: Session Fixation in Ghost Admin
6.7
1 hour ago
ghost
>= 0.10.0, < 6.54.1
NPM: Ghost: Theme Upload Path Traversal
6.6
1 hour ago
ghost
>= 1.20.1, < 6.54.1
NPM: Ghost: Database Backup Path Traversal
5.5
1 hour ago
ghost
>= 0.10.0, < 6.54.1
NPM: Ghost: Server-Side Request Forgery in Image Fetching
4.1
1 hour ago
ghost
< 6.54.1
NPM: Ghost: Blind Password Hash Disclosure in Ghost Admin API
4.8
1 hour ago
ghost
>= 6.19.4, < 6.21.1
NPM: Ghost: Mobiledoc image-size fetch SSRF
5.4
1 hour ago
ghost
>= 6.0.9, < 6.21.1
NPM: Ghost: Server-side request forgery via DNS rebinding in external request handling
4
1 hour ago
ghost
>= 6.0.9, <= 6.21.0
NPM: Ghost: Private IP filtering bypass to make server-side requests to internal services
5.8
2 hours ago
ghost
>= 4.22.0, < 6.54.1
NPM: Ghost: Archived Offers can be Redeemed
4.8
2 hours ago
ghost
>= 6.19.4, < 6.21.1
NPM: Ghost: File Upload Content-Type Spoofing
5.4
2 hours ago
ghost
>= 5.26.0, < 6.54.1
NPM: Ghost: Cross-Site Scripting in Universal Import
5
2 hours ago
flowise
<= 3.1.2
NPM: Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service
9.2
3 hours ago
flowise
<= 3.1.2
NPM: Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
9.5
3 hours ago
flowise-components
<= 3.1.2
NPM: Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
9.5
3 hours ago
flowise
<= 3.1.2
NPM: Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
8.3
3 hours ago
flowise
<= 3.1.3
NPM: Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
6.3
3 hours ago
flowise
<= 3.1.2
NPM: Flowise: Missing Authorization on Execution Update Endpoint
7.1
3 hours ago
Load more