The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,161
Mitigations16,152
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Membership by Supsystic<= 1.4.7
Unauthenticated SQL Injection vulnerability
9.3
17 minutes ago
Product Catalog 8<= 1.2.0
SQL Injection vulnerability
9.3
19 minutes ago
404 SEO Redirection<= 1.0
Unauthenticated SQL Injection vulnerability
9.3
19 minutes ago
WP Google Review Slider<= 6.1
Unauthenticated SQL Injection vulnerability
9.3
21 minutes ago
BBS e-Franchise< 1.1.4
SQL Injection vulnerability
9.3
24 minutes ago
WordPress Survey & Poll<= 1.5.7.3
Unauthenticated SQL Injection vulnerability
9.3
26 minutes ago
Wow Viral Signups<= 2.1
Unauthenticated SQL Injection vulnerability
9.3
30 minutes ago
Flights &amp; Hotels Booking WP Plugin<= 2.3
Unauthenticated SQL Injection vulnerability
9.3
31 minutes ago
PICA Photo Gallery <= 1.0
SQL Injection vulnerability
9.3
34 minutes ago
KittyCatfish<= 2.2
Unauthenticated SQL Injection vulnerability
9.3
40 minutes ago
Car Park Booking System for WordPress<= 1.0
Unauthenticated SQL Injection vulnerability
9.3
42 minutes ago
FleekDash V2<= 2.6.2.2
Missing Authorization to Authenticated (Subscriber+) Administrator Account Takeover vulnerability
8.8
44 minutes ago
@apostrophecms/seo<= 1.4.2
NPM: @apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
8.7
2 days ago
apostrophe<= 4.30.0
NPM: @apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
3.7
2 days ago
apostrophe<= 4.30.0
NPM: Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
9.1
2 days ago
sanitize-html>= 1.18.0, <= 2.17.4
NPM: sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes
5.4
2 days ago
@nocobase/plugin-notification-in-app-message<= 2.0.60
NPM: NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
10
2 days ago
jodit< 4.13.6
NPM: Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization
5.3
2 days ago
jodit< 4.12.28
NPM: Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
7.2
2 days ago
jodit< 4.12.18
NPM: Jodit has prototype pollution via Jodit.configure() / ConfigMerge
6.3
2 days ago