Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,868
Mitigations
Mitigation rules
16,064
No official patch
13,134
In triage
1,194
Published soon
58
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@nocobase/plugin-collection-sql
< 2.0.62
NPM: NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
6.8
57 minutes ago
qti-neon
1.0.0
NPM: QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
8.6
5 hours ago
@novu/application-generic
< 3.17.0
NPM: @novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition
6.8
6 hours ago
@wakaru/cli
>= 1.0.0, < 1.4.0
NPM: @wakaru/cli arbitrary file write during bundle unpack
7.1
7 hours ago
@frontmcp/adapters
<= 1.5.5
NPM: FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
5.9
3 days ago
quasar
<= 2.21.4
NPM: Quasar: Prototype pollution in the extend() utility
5.6
3 days ago
shescape
>= 2.1.11, < 2.1.14
NPM: Shescape: Quadratic-time denial of service in the flag-protection
8.7
3 days ago
shescape
< 2.1.14
NPM: Shescape: Home-directory disclosure in assignment context on Unix with Dash
6.3
3 days ago
shescape
< 2.1.14
NPM: Shescape: Shell injection via unescaped parentheses on Windows with CMD
9.2
3 days ago
shescape
< 2.1.14
NPM: Shescape: Path disclosure on Unix with Zsh
6.3
3 days ago
brace-expansion
<= 5.0.7
NPM: brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
7.5
3 days ago
sm-crypto
< 0.5.0
NPM: sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
9.1
4 days ago
@anephenix/hub
< 0.2.16
NPM: @anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
7.5
4 days ago
@budibase/server
<= 3.38.1
NPM: Budibase: SSRF via bare fetch() in uploadUrl during AI table generation
4.9
4 days ago
@budibase/server
<= 3.38.1
NPM: Budibase: SSRF via DNS rebinding in the REST datasource integration
8.5
4 days ago
@budibase/server
<= 3.38.1
NPM: Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete
7.1
4 days ago
@budibase/server
<= 3.38.1
NPM: Budibase: Account Enumeration via Login Lockout Response Differential
5.3
4 days ago
@budibase/server
<= 3.38.1
NPM: Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
7.7
4 days ago
@budibase/server
<= 3.38.1
NPM: Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
7.6
4 days ago
@budibase/server
<= 3.38.1
NPM: Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
8.3
4 days ago
Load more