Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,600
Mitigations
Mitigation rules
17,172
No official patch
13,372
In triage
1,420
Published soon
1
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
unleash-server
< 8.0.3
NPM: Unleash: Missing await on permission check + cross-project IDOR in admin API
7.1
2 hours ago
unleash-server
< 8.0.3
NPM: Unleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit log
4.3
2 hours ago
unleash-server
< 8.0.3
NPM: Unleash: Clone-feature lets a user copy a feature from a project they cannot read
5.3
2 hours ago
unleash-server
< 8.0.3
NPM: Unleash: CR-approval email renders user-controlled raw HTML
2.1
2 hours ago
@novu/js
<= 3.17.0
NPM: Novu: Stored XSS in In-App Inbox via notification redirect.url javascript: scheme
5.1
2 hours ago
mppx
< 0.8.2
NPM: mppx: Gas Draining with access list
6.9
2 hours ago
mppx
< 0.8.1
NPM: mppx: Gas Draining with padding
6.9
2 hours ago
@deepstream/server
10.1.0
NPM: deepstream: PATCH_MULTI action bypasses Valve permission system allowing unauthorized record writes
8.8
3 hours ago
request-filtering-agent
< 3.2.1
NPM: request-filtering-agent: Synchronous throw from createConnection() for literal private-IP hosts bypasses req.on('error'), crashing the Node.js process
7.5
3 hours ago
Advanced Contact form 7 DB
<= 2.1.1
Missing Authorization to Authenticated (Contributor+) Information Disclosure vulnerability
6.5
5 hours ago
WP User Manager
<= 2.9.19
Broken Access Control vulnerability
5.3
6 hours ago
9router
<= 0.5.4
NPM: 9Router has a Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header
5.3
6 hours ago
9router
<= 0.5.4
NPM: 9Router has an Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header
7.3
6 hours ago
TrustedLogin Connector
<= 2.0.3
Sensitive Data Exposure vulnerability
5.3
7 hours ago
@aborruso/ckan-mcp-server
<= 0.4.107
NPM: @aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509
5.7
8 hours ago
@sync-in/server
<= 2.4.0
NPM: Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory)
5.3
8 hours ago
@sync-in/server
<= 2.3.0
NPM: Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`
6.5
8 hours ago
@sync-in/server
<= 2.3.0
NPM: Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`
8.1
8 hours ago
@sync-in/server
<= 2.3.0
NPM: @sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`
6.8
8 hours ago
@roomi-fields/notebooklm-mcp
>= 1.6.0, < 2.0.3
NPM: @roomi-fields/notebooklm-mcp has a path traversal in vault.batch tool that allows arbitrary file write outside intended vault directory
7.1
8 hours ago
Load more