Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,774
Mitigations
Mitigation rules
16,024
No official patch
13,108
In triage
1,241
Published soon
67
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@anthropic-ai/claude-code
>= 2.1.38, < 2.1.163
NPM: Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
7.7
44 minutes ago
js-yaml
>= 5.0.0, <= 5.2.1
NPM: js-yaml: Exponential parsing time in flow collections leads to denial of service
7.5
50 minutes ago
react-router
>= 7.12.0, < 8.3.0
NPM: React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
7.1
53 minutes ago
aws-cdk-lib
< 2.253.0
NPM: AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
53 minutes ago
@aws-cdk/aws-codebuild
>= 1.75.0, <= 1.204.0
NPM: AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
53 minutes ago
@fastify/static
<= 10.1.1
NPM: @fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
5.3
54 minutes ago
@fastify/static
<= 10.1.0
NPM: @fastify/static vulnerable to route guard bypass via path traversal
7.5
54 minutes ago
tar
<= 7.5.20
NPM: node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
5.3
1 hour ago
postcss
<= 8.5.17
NPM: PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
7.5
1 hour ago
@prompty/core
<= 0.1.4
NPM: Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
10
1 hour ago
mongoose
< 6.13.10
NPM: Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
6.5
1 hour ago
velocityjs
<= 2.1.6
NPM: Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
9.8
1 hour ago
@backstage/plugin-auth-backend
<= 0.29.1
NPM: @backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
4.7
1 hour ago
trix
< 2.1.18
NPM: Trix: Stored XSS via HTMLParser attribute injection on paste
4.6
1 hour ago
valibot
<= 1.4.1
NPM: Valibot: record() issue paths can make flatten() throw for inherited Object property names
6.9
1 hour ago
seroval
<= 1.5.2
NPM: seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
9.8
1 hour ago
@sveltejs/kit
<= 2.69.0
NPM: SvelteKit: Prototype pollution in file input deletion path in remote-function forms
4.3
1 hour ago
@sveltejs/kit
<= 2.69.0
NPM: SvelteKit: Big remote form function payloads can cause Node process to crash
5.3
1 hour ago
better-auth
>= 1.1.3, < 1.6.22
NPM: Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
8.3
1 hour ago
@better-auth/stripe
>= 1.4.11, < 1.6.21
NPM: @better-auth/stripe: cross-organization billing tampering in organization subscription actions
7.1
1 hour ago
Load more