The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,016
Mitigations16,983
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
bbPress<= 2.6.14
Sensitive Data Exposure vulnerability
5.3
24/09/2026
@jhb.software/payload-alt-text-plugin<= 0.7.0
NPM: @jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission
7.1
31 minutes ago
@argos-ci/core<= 6.2.0
NPM: @argos-ci/core: CI Branch Name OS Command Injection
7.5
36 minutes ago
omniroute<= 3.8.50
NPM: OmniRoute ACP Custom-Agent Remote Code Execution (RCE)
9.5
1 hour ago
n8n< 2.37.7
NPM: n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
5.9
1 hour ago
n8n< 2.37.7
NPM: n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
5.9
1 hour ago
n8n< 1.123.76
NPM: n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
5.3
1 hour ago
n8n< 2.37.7
NPM: n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
5.1
1 hour ago
n8n< 1.123.76
NPM: n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
5.9
2 hours ago
n8n< 1.123.76
NPM: n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
6
2 hours ago
n8n< 1.123.76
NPM: n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
6.3
2 hours ago
n8n< 1.123.76
NPM: n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
6.3
2 hours ago
n8n< 2.37.7
NPM: n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
6
2 hours ago
n8n< 1.123.76
NPM: n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
5.3
2 hours ago
Masteriyo - LMS<= 3.4.0
WordPress Masteriyo - LMS plugin <= 3.4.0 - Broken Access Control vulnerability
5.3
2 hours ago
RTMKit<= 2.1.5
Cross Site Request Forgery (CSRF) vulnerability
5.4
2 hours ago
Starter Templates<= 4.7.5
Insecure Direct Object References (IDOR) vulnerability
4.3
2 hours ago
Flexible Quantity – Measurement Price Calculator for WooCommerce<= 2.3.21
Broken Access Control vulnerability
5.3
2 hours ago
Booktics<= 1.0.24
Broken Access Control vulnerability
5.3
2 hours ago
Visual Composer Website Builder<= 45.16.1
Cross Site Scripting (XSS) vulnerability
6.5
2 hours ago