The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,089
Mitigations17,016
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
yayson<= 4.2.0
NPM: yayson: Prototype pollution in Store/LegacyStore deserialization
9.1
22 minutes ago
@mockoon/commons-server< 9.7.0
NPM: @Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
8.8
29 minutes ago
@mockoon/cli< 9.7.0
NPM: @Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
8.8
29 minutes ago
@mockoon/commons-server<= 9.6.1
NPM: @Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
6.5
29 minutes ago
@mockoon/cli<= 9.6.1
NPM: @Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
6.5
29 minutes ago
mcp-from-openapi>= 2.3.0, < 2.5.0
NPM: FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix
8.5
32 minutes ago
@frontmcp/adapters>= 1.2.1, < 1.5.0
NPM: FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix
8.5
32 minutes ago
frontmcp>= 1.2.1, < 1.5.0
NPM: FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix
8.5
32 minutes ago
The Events Calendar<= 6.17.4
Unauthenticated PHP Object Injection to Remote Code Execution vulnerability
9.8
3 hours ago
The Events Calendar<= 6.17.3
Unauthenticated Code Injection to Remote Code Execution vulnerability
9.8
3 hours ago
GEO my WordPress<= 4.5.5.3
Unauthenticated Local File Inclusion vulnerability
7.5
3 hours ago
MPG<= 4.2.1
Unauthenticated SQL Injection vulnerability
9.3
3 hours ago
Tutor LMS<= 4.0.7
Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution vulnerability
8.8
3 hours ago
bbPress<= 2.6.14
Sensitive Data Exposure vulnerability
5.3
3 hours ago
DT LMS – elearning, WordPress LMS Plugin<= 1.1
Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification vulnerability
5.3
3 hours ago
ElasticPress<= 5.3.4
Sensitive Data Exposure vulnerability
5.3
4 hours ago
Master Addons for Elementor<= 3.2.2
Broken Access Control vulnerability
7.1
4 hours ago
WP-Members<= 3.5.6
Reflected Cross-Site Scripting vulnerability
7.1
8 hours ago
Registration Form for WooCommerce1.1.0-1.1.2
Contributor+ Privilege Escalation vulnerability
8.8
8 hours ago
Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons< 3.3.3
Unauthenticated Stored XSS vulnerability
7.1
8 hours ago