The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,017
Mitigations16,983
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
bbPress<= 2.6.14
Sensitive Data Exposure vulnerability
5.3
24/09/2026
Bold Page Builder<= 5.9.9
Cross Site Scripting (XSS) vulnerability
6.5
2 minutes ago
Simple Payment<= 2.5.4
Cross Site Scripting (XSS) vulnerability
6.5
3 minutes ago
Amelia<= 2.4.9
SQL Injection vulnerability
7.6
4 minutes ago
Slim SEO<= 4.10.0
Insecure Direct Object References (IDOR) vulnerability
4.3
5 minutes ago
Passster<= 4.3.13
Broken Access Control vulnerability
5.3
21 minutes ago
@jhb.software/payload-alt-text-plugin<= 0.7.0
NPM: @jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission
7.1
8 hours ago
@argos-ci/core<= 6.2.0
NPM: @argos-ci/core: CI Branch Name OS Command Injection
7.5
8 hours ago
omniroute<= 3.8.50
NPM: OmniRoute ACP Custom-Agent Remote Code Execution (RCE)
9.5
9 hours ago
n8n< 2.37.7
NPM: n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
5.9
9 hours ago
n8n< 2.37.7
NPM: n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
5.9
9 hours ago
n8n< 1.123.76
NPM: n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
5.3
9 hours ago
n8n< 2.37.7
NPM: n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
5.1
9 hours ago
n8n< 1.123.76
NPM: n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
5.9
9 hours ago
n8n< 1.123.76
NPM: n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
6
9 hours ago
n8n< 1.123.76
NPM: n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
6.3
9 hours ago
n8n< 1.123.76
NPM: n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
6.3
9 hours ago
n8n< 2.37.7
NPM: n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
6
9 hours ago
n8n< 1.123.76
NPM: n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
5.3
9 hours ago
Masteriyo - LMS<= 3.4.0
WordPress Masteriyo - LMS plugin <= 3.4.0 - Broken Access Control vulnerability
5.3
9 hours ago