The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total51,490
Mitigations16,840
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Broken Link Checker<= 2.4.13
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
1 hour ago
FluentCart<= 1.6.2
Authenticated (Custom+) Arbitrary File Deletion vulnerability
7.7
1 hour ago
WP Project Manager Pro<= 4.0.1
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
2 hours ago
Måne<= 1.7
Unauthenticated Local File Inclusion vulnerability
8.1
2 hours ago
WordPress Persistent Login<= 3.1.0
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
2 hours ago
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent<= 4.4.1
Unauthenticated Arbitrary File Upload vulnerability
10
2 hours ago
TranslatePress<= 3.3.1
Unauthenticated Account Takeover vulnerability
9.8
2 hours ago
Formidable Charts<= 2.0.1
Unauthenticated Arbitrary File Read via 'frm_graph' Parameter vulnerability
7.5
3 hours ago
sanitize-html>= 1.9.0, <= 2.17.6
NPM: ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass
5.4
11 hours ago
nanoid< 3.3.12
NPM: nanoid: Integer Overflow or Wraparound
7.4
13 hours ago
pnpm>= 10.7.0, < 10.34.5
NPM: pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml
7.4
13 hours ago
Easy Waveform Player<= 1.2.2
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
13 hours ago
pnpm>= 12.0.0-alpha.0, < 12.0.0-alpha.5
NPM: pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project
7.1
13 hours ago
@appium/base-driver<= 10.6.0
NPM: Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes
6.5
13 hours ago
Divi<= 4.27.5
Authenticated (Contributor+) Stored Cross-Site Scripting via Contact Form 'redirect_url' Shortcode Parameter vulnerability
6.5
15 hours ago
SigmaForms Pro – AI Generated Forms<= 1.4.11
Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field vulnerability
8.6
15 hours ago
DevKit Pro<= 2.3.0
Authenticated (Subscriber+) Arbitrary Theme Installation / Remote Code Execution via 'qqfile' Parameter vulnerability
8.8
15 hours ago
browserslist<= 4.28.6
NPM: Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM
7.5
16 hours ago
browserslist<= 4.28.6
NPM: Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)
7.5
16 hours ago
mysql2< 3.22.0
NPM: MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials
8.2
16 hours ago