The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total54,163
Mitigations17,863
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
All Bootstrap Blocks<= 1.3.31
Sensitive Data Exposure vulnerability
4.3
9 minutes ago
Asgaros Forum<= 3.4.0
Broken Access Control vulnerability
4.3
14 minutes ago
Html5 Audio Player<= 2.8.8
Cross Site Scripting (XSS) vulnerability
6.5
15 minutes ago
Restrict User Access – Membership Plugin with Force<= 2.8.1
Broken Access Control vulnerability
5.3
18 minutes ago
WP Event Manager<= 3.4.1
Broken Access Control vulnerability
5.4
18 minutes ago
Scripts n Styles<= 3.5.8
Broken Access Control vulnerability
5.3
26 minutes ago
AI Translation for Polylang<= 1.6.2
Broken Access Control vulnerability
5.4
41 minutes ago
JetBlocks For Elementor<= 1.5.2.1
Cross Site Scripting (XSS) vulnerability
6.5
2 hours ago
Ocean Pro Demos<= 1.5.4
Unauthenticated Stored Cross-Site Scripting vulnerability
7.2
4 hours ago
Ocean eComm Treasure Box<= 1.8.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.2
4 hours ago
Redux Framework<= 4.5.11
Redux Framework <= 4.5.11 – Authenticated (Subscriber+) Privilege Escalation vulnerability
6.8
4 hours ago
fast-jwt<= 6.3.3
NPM: fast-jwt: Verifier cache accepts expired JWTs without iat.
4.2
13 hours ago
@adonisjs/http-server<= 8.2.2
NPM: AdonisJS: Unencoded route parameters can produce open redirects
6.1
13 hours ago
fast-jwt<= 6.3.0
NPM: fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly set
7.4
13 hours ago
fast-jwt>= 6.2.0, <= 6.2.4
NPM: fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion
9.8
13 hours ago
fast-jwt<= 6.2.4
NPM: fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and persists in the verifier cache)
5.9
13 hours ago
fast-jwt<= 6.2.4
NPM: fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array
8.1
13 hours ago
fast-jwt6.2.4
NPM: fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery
7.4
13 hours ago
praisonai< 1.7.3
NPM: PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosure
8.6
13 hours ago
music-metadata< 11.16.0
NPM: music-metadata: MP4 stsd sample-entry size==0 causes a synchronous infinite loop (DoS) — unreleased regression on master
6.2
16 hours ago