The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,162
Mitigations16,153
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Simple Backup<= 2.7.11
Unauthenticated Arbitrary File Download vulnerability
7.5
5 minutes ago
BuddyPress<= 14.5.0
Authenticated (Subscriber+) PHP Object Injection vulnerability
8.8
7 minutes ago
Dharma Booking<= 2.28.3
Unauthenticated Local File Inclusion vulnerability
8.1
19 minutes ago
Membership by Supsystic<= 1.4.7
Unauthenticated SQL Injection vulnerability
9.3
27 minutes ago
Product Catalog 8<= 1.2.0
SQL Injection vulnerability
9.3
29 minutes ago
404 SEO Redirection<= 1.0
Unauthenticated SQL Injection vulnerability
9.3
30 minutes ago
WP Google Review Slider<= 6.1
Unauthenticated SQL Injection vulnerability
9.3
32 minutes ago
BBS e-Franchise< 1.1.4
SQL Injection vulnerability
9.3
34 minutes ago
WordPress Survey & Poll<= 1.5.7.3
Unauthenticated SQL Injection vulnerability
9.3
36 minutes ago
Wow Viral Signups<= 2.1
Unauthenticated SQL Injection vulnerability
9.3
40 minutes ago
Flights &amp; Hotels Booking WP Plugin<= 2.3
Unauthenticated SQL Injection vulnerability
9.3
42 minutes ago
PICA Photo Gallery <= 1.0
SQL Injection vulnerability
9.3
44 minutes ago
KittyCatfish<= 2.2
Unauthenticated SQL Injection vulnerability
9.3
51 minutes ago
Car Park Booking System for WordPress<= 1.0
Unauthenticated SQL Injection vulnerability
9.3
52 minutes ago
FleekDash V2<= 2.6.2.2
Missing Authorization to Authenticated (Subscriber+) Administrator Account Takeover vulnerability
8.8
54 minutes ago
@apostrophecms/seo<= 1.4.2
NPM: @apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
8.7
2 days ago
apostrophe<= 4.30.0
NPM: @apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
3.7
2 days ago
apostrophe<= 4.30.0
NPM: Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
9.1
2 days ago
sanitize-html>= 1.18.0, <= 2.17.4
NPM: sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes
5.4
2 days ago
@nocobase/plugin-notification-in-app-message<= 2.0.60
NPM: NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
10
2 days ago