Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
53,158
Mitigations
Mitigation rules
17,346
No official patch
13,360
In triage
1,357
Published soon
45
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
fastify
< 5.12.5
NPM: fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses
5.9
6 hours ago
hono
< 4.13.7
NPM: hono/jsx renders plain strings unescaped in boundary components, leading to XSS
4.7
6 hours ago
fastify
< 5.12.2
NPM: fastify vulnerable to request body replacement via an async validation result collision
8.1
6 hours ago
fastify
>= 4.0.0, < 5.12.2
NPM: fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
7.5
6 hours ago
fastify
< 5.12.2
NPM: fastify vulnerable to request validation bypass via skipped boolean false schemas
7.5
6 hours ago
fastify
< 5.12.2
NPM: fastify vulnerable to header validation bypass via incomplete schema case normalization
7.5
6 hours ago
@astrojs/netlify
>= 5.2.0, <= 8.2.3
NPM: Astro: Netlify Image CDN allowlist bypass enables SSRF
6.3
6 hours ago
@astrojs/node
<= 11.1.2
NPM: Astro: Malformed port in the Host header can crash the Node adapter
8.2
6 hours ago
Essential Blocks for Gutenberg
<= 6.4.5
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
5.9
9 hours ago
Calculated Fields Form
<= 5.5.1.3
Reflected DOM-Based Cross-Site Scripting vulnerability
4.7
9 hours ago
LearnPress
<= 4.4.8
Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure vulnerability
5.3
10 hours ago
@angular/router
<= 19.2.25
NPM: Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters
8.2
14 hours ago
serialize-javascript
>= 7.1.1, < 7.1.2
NPM: Serialize JavaScript: Cross-site scripting (XSS) via unescaped </script> in serialized function bodies
2.3
14 hours ago
Popular Posts
<= 7.4.2
Unauthenticated Information Disclosure in 'post_type' and 'context' Parameters vulnerability
5.3
14 hours ago
dompurify
>= 3.4.13, <= 3.4.15
NPM: DOMPurify: IN_PLACE: node-removing afterSanitize hook leaves detached subtree event handlers armed, causing DOM XSS
2.3
14 hours ago
@grpc/grpc-js
< 1.13.6
NPM: @grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized
7.4
14 hours ago
@grpc/grpc-js
< 1.13.6
NPM: @grpc/grpc-js: The server transmits some error messages thrown by method handlers to the client in status messages
3.7
14 hours ago
axios
>= 1.0.0, < 1.20.0
NPM: Axios: Header Injection via Inherited headers After Minimal Interceptor
6.9
14 hours ago
axios
>= 1.12.0, < 1.20.0
NPM: Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders
6.9
14 hours ago
axios
>= 1.15.2, < 1.20.0
NPM: Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection
7.6
14 hours ago
Load more