Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
51,574
Mitigations
Mitigation rules
16,860
No official patch
13,332
In triage
1,093
Published soon
38
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@apostrophecms/import-export
<= 3.6.1
NPM: ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal
6.5
16 minutes ago
orval
< 8.22.0
NPM: Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
7.1
17 minutes ago
orval
< 8.21.0
NPM: Orval: Import-time RCE via query-parameter default -> zod module-level template literal
9.3
18 minutes ago
orval
< 8.21.0
NPM: Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client
9.3
19 minutes ago
@aborruso/ckan-mcp-server
< 0.4.112
NPM: CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)
5.3
19 minutes ago
qs
>= 6.14.2, <= 6.15.3
NPM: qs array-limit bypass via bracket-key comma parsing
3.7
25 minutes ago
qs
>= 2.2.5, < 6.16.0
NPM: qs: Denial of Service via Attacker Controlled isBuffer
5.3
27 minutes ago
@tiptap/core
>= 2.0.0-alpha.0, < 3.30.4
NPM: Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes
6.4
27 minutes ago
pnpm
< 10.34.5
NPM: pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph
7.1
35 minutes ago
pnpm
< 10.34.5
NPM: pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install
7.5
35 minutes ago
@humanfs/node
< 0.16.8
NPM: humanfs: Recursive copy follows symlinked files and copies data from outside the source tree
5.7
44 minutes ago
@faker-js/faker
<= 10.4.0
NPM: Faker: helpers.fake exploitable into arbritary code execution
7.8
51 minutes ago
Classified Listing
<= 6.1.1
Broken Access Control vulnerability
5.4
3 hours ago
Rentsyst
<= 2.1.2
Broken Access Control vulnerability
5.3
3 hours ago
Grand Tour
<= 5.5.1
Cross Site Request Forgery (CSRF) vulnerability
5.4
3 hours ago
Gallery PhotoBlocks
<= 1.3.4
Cross Site Scripting (XSS) vulnerability
6.5
4 hours ago
WP Go Maps
<= 10.1.08
Denial of Service Attack vulnerability
5.3
4 hours ago
Really Simple SSL
<= 9.8.0
Denial of Service Attack vulnerability
5.3
4 hours ago
Broken Link Checker
<= 2.4.14
Server Side Request Forgery (SSRF) vulnerability
5.5
4 hours ago
Mang Board WP
<= 2.3.8
Cross Site Request Forgery (CSRF) vulnerability
8.8
4 hours ago
Load more