The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,532
Mitigations16,392
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Forminator<= 1.56.1
Unauth. Arbitrary File Upload
9.8
1 hour ago
ep_etherpad-lite<= 1.8.14
NPM: Etherpad has stored XSS in HTML export via unescaped attribute-pool values
8.7
2 hours ago
ep_etherpad-lite<= 1.8.14
NPM: Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling
0
2 hours ago
vm2<= 3.11.5
NPM: vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass
7.5
2 hours ago
vm2<= 3.11.5
NPM: vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
10
2 hours ago
vm2<= 3.11.5
NPM: vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
9.8
2 hours ago
vm2<= 3.11.5
NPM: VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE
9.9
2 hours ago
vm2<= 3.11.5
NPM: vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
8.7
2 hours ago
Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms<= 6.0
Broken Access Control vulnerability
5.4
2 hours ago
RomethemeForm For Elementor<= 1.2.6
Broken Access Control vulnerability
4.3
2 hours ago
WP Table Builder<= 2.2.0
Broken Access Control vulnerability
4.3
2 hours ago
3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery<= 1.16.20
Sensitive Data Exposure vulnerability
5.3
2 hours ago
Shortcodes and extra features for Phlox theme<= 2.17.22
Sensitive Data Exposure vulnerability
5.3
2 hours ago
Razorpay for WooCommerce<= 4.8.7
Insecure Direct Object References (IDOR) vulnerability
5.3
2 hours ago
@medplum/core<= 5.1.5
NPM: Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage
7.1
6 hours ago
deepmerge-ts< 8.0.0
NPM: DeepmergeTS has stack exhaustion when merging recursive object graphs
8.2
6 hours ago
TrueBooker<= 1.2.6
Unauthenticated Account Takeover via Insecure Direct Object Reference in 'truebooker_wp_user_id' Parameter vulnerability
9.8
8 hours ago
Wholesale Market<= 2.2.2
Authenticated (Subscriber+) Privilege Escalation via 'role_required' Parameter vulnerability
8.8
8 hours ago
KiviCare<= 4.5.1
Authenticated (Doctor+) SQL Injection via 'searchTerm' Parameter vulnerability
8.5
8 hours ago
Groundhogg<= 4.5.14
Authenticated (Vendor+) SQL Injection via 'tag_query' Parameter vulnerability
8.5
8 hours ago