The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total51,597
Mitigations16,861
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Photo Gallery by 10Web< 1.8.44
Reflected XSS vulnerability
7.1
2 minutes ago
Backup Guard3.1.7.9-3.1.23.3
Subscriber+ Privilege Escalation vulnerability
7.1
13 minutes ago
ACF Extended< 0.9.2.7
Unauthenticated Administrator Account Takeover vulnerability
8.1
24 minutes ago
ACF Extended0.9.2.2-0.9.2.6
Unauthenticated Privilege Escalation vulnerability
8.1
31 minutes ago
@dicebear/core<= 9.4.2
NPM: DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)
4.7
7 hours ago
@dicebear/initials<= 9.4.2
NPM: DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)
4.7
7 hours ago
@platejs/docx-io< 53.3.2
NPM: Plate: SSRF with response disclosure in DOCX image embedding
8.2
8 hours ago
link-preview-js<= 4.0.3
NPM: link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897
7.5
8 hours ago
Divi<= 4.27.6
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
10 hours ago
GutenKit<= 2.4.4
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
6.5
14 hours ago
fast-uri>= 2.4.2, < 2.4.5
NPM: fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references
7.5
14 hours ago
fast-uri>= 2.3.1, < 2.4.5
NPM: fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
7.5
14 hours ago
fast-uri>= 2.4.1, < 2.4.5
NPM: fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding
7.5
14 hours ago
fast-uri>= 2.3.1, < 2.4.5
NPM: fast-uri vulnerable to host confusion via percent-encoded scheme normalization
7.5
14 hours ago
@xmldom/xmldom>= 0.7.0, <= 0.8.14
NPM: xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization
6.3
15 hours ago
xmldom<= 0.6.0
NPM: xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization
6.3
15 hours ago
fastify>= 5.8.3, < 5.12.1
NPM: fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count
6.1
15 hours ago
fastify< 5.12.1
NPM: fastify vulnerable to schema validation bypass via root primitive coercion mismatch
5.4
15 hours ago
apostrophe<= 4.32.0
NPM: ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
7.1
15 hours ago
@apostrophecms/import-export<= 3.6.1
NPM: ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal
6.5
15 hours ago