The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total49,749
Mitigations16,024
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
ARForms<= 7.2.1
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
4 hours ago
SUMO Reward Points<= 32.7.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
5 hours ago
FormCraft 3<= 3.9.14
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
5 hours ago
Contact Form 7 – Dynamic Text Extension<= 5.0.6
Content Injection vulnerability
6.5
5 hours ago
AIWU<= 1.5.4
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
5 hours ago
Lumise Product Designer<= 2.1.1
Unauthenticated SQL Injection vulnerability
9.3
5 hours ago
Mobile DJ Manager<= 1.7.8.4
Authenticated (Subscriber+) Privilege Escalation vulnerability
8.8
5 hours ago
GoDAM<= 1.12.2
Unauthenticated Arbitrary File Upload vulnerability
10
6 hours ago
WP Ticket Customer Service Software & Support Ticket System<= 6.0.5
Unauthenticated Code Injection vulnerability
10
6 hours ago
FoodBakery<= 4.9
Authenticated (Subscriber+) Arbitrary File Deletion vulnerability
7.7
6 hours ago
react-router>= 6.0.0, < 7.18.0
NPM: React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
5.1
16 hours ago
react-router>= 7.9.6, <= 7.12.0
NPM: React Router: Open redirect leading to XSS
6.9
16 hours ago
react-router-dom>= 6.30.2, <= 6.30.4
NPM: React Router: Open redirect leading to XSS
6.9
16 hours ago
react-router>= 7.11.0, < 7.18.0
NPM: React Router: RSCErrorHandler Missing Protocol Validation (XSS)
6.9
16 hours ago
react-router>= 6.4.0, < 7.18.0
NPM: React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
6.1
16 hours ago
find-my-way<= 9.6.0
NPM: find-my-way: DDoS with HTTP2
7.5
16 hours ago
postcss<= 8.5.11
NPM: PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
7.5
21 hours ago
next-auth>= 5.0.0-beta.0, <= 5.0.0-beta.31
NPM: Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
9.1
21 hours ago
next-auth>= 4.0.6, <= 4.24.14
NPM: Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
7.5
21 hours ago
@auth/core>= 0.1.0, < 0.41.3
NPM: Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
7.5
21 hours ago