The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,347
Mitigations17,070
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
@platejs/core< 53.3.11
NPM: @platejs/core HTML deserialization can trigger browser behavior during parsing
6.1
28 minutes ago
devalue< 5.9.1
NPM: Svelte devalue: DoS via malformed input
5.3
33 minutes ago
@libp2p/peer-store>= 8.0.0, < 12.0.24
NPM: libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addresses
8.2
2 hours ago
@libp2p/gossipsub>= 15.0.0, < 16.0.5
NPM: libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID
7.5
3 hours ago
exifreader<= 4.41.0
Memory Exhaustion
7.5
4 hours ago
CheckView Automated Testing< 2.3.2
Administrator Account Creation via REST API Authentication Bypass vulnerability
9.8
5 hours ago
Custom Fields< 1.5.1
Unauthenticated Arbitrary File Deletion via Path Traversal vulnerability
8.6
5 hours ago
Single Sign On For TNG< 2.2.0
Unauthenticated Arbitrary Password Reset vulnerability
9.8
5 hours ago
Dataverse Integration< 2.91
Contributor+ Server-Side Template Injection (SSTI) to Information Disclosure vulnerability
4.3
5 hours ago
WP Events Manager< 2.2.5
Unauthenticated Payment Bypass and Booking Status Update via IDOR vulnerability
5.3
5 hours ago
Five Star Restaurant Reservations< 2.7.23
Unauthenticated Payment Bypass and Booking Confirmation via IDOR vulnerability
5.3
5 hours ago
Ninja Forms< 3.14.10
Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default vulnerability
5.3
5 hours ago
miniOrange's Google Authenticator< 6.2.7
2FA Bypass via Password-Only Second-Factor Rebinding vulnerability
4.3
5 hours ago
Contest Gallery< 30.0.7
Unauthenticated Login-Protection and 2FA Bypass via post_cg_login vulnerability
4.8
5 hours ago
Event Booking Manager for WooCommerce (Pro)<= 5.0.2
Unauthenticated Price Manipulation vulnerability
5.3
5 hours ago
Newsletters< 4.16
Unauthenticated API Authentication Bypass via Type Juggling vulnerability
4.8
5 hours ago
Easy Booking – WooCommerce Booking &amp; Reservation Plugin< 3.5.0
Unauthenticated Minimum Booking Duration Bypass vulnerability
5.3
5 hours ago
WordPress File Upload< 5.1.7
File Overwrite via Race Condition vulnerability
5.4
5 hours ago
Contact Form by WPForms< 1.10.0.5
Unauthenticated PayPal Webhook Forgery vulnerability
5.3
5 hours ago
@tinacms/auth<= 1.1.3
NPM: Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site
8.8
6 hours ago