The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,175
Mitigations16,181
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
postcss<= 8.5.22
NPM: PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset
6.3
1 hour ago
brace-expansion< 1.1.18
NPM: brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
7.5
1 hour ago
@angular/core<= 19.2.25
NPM: Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes
7.6
1 hour ago
@angular/compiler<= 19.2.25
NPM: Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes
7.6
1 hour ago
@angular/platform-server<= 19.2.25
NPM: Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)
8.6
2 hours ago
@angular/common<= 19.2.25
NPM: Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning
8.8
2 hours ago
VikBooking Hotel Booking Engine & PMS<= 1.8.13
Reflected Cross-Site Scripting vulnerability
7.1
5 hours ago
WPify Woo Czech<= 5.4.16
Authenticated (Shop Manager+) Privilege Escalation vulnerability
7.2
6 hours ago
Checkout Field Editor for WooCommerce (Pro)<= 3.7.7
Authenticated (Subscriber+) Path Traversal to Arbitrary File Read vulnerability
6.5
6 hours ago
Nexter Blocks<= 5.0.0
Authenticated (Subscriber+) Path Traversal to Arbitrary CSS/JS File Deletion vulnerability
4.3
6 hours ago
StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart<= 2.1.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
6 hours ago
VikBooking Hotel Booking Engine & PMS<= 1.8.13
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
6 hours ago
Paid Memberships Pro<= 3.8.1
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
6 hours ago
Tablesome< 1.1.31
Unauthenticated Post Creation and Modification vulnerability
6.5
6 hours ago
Contact Form Entries< 1.5.3
Reflected XSS vulnerability
7.1
6 hours ago
Quiz And Survey Master< 11.1.3
Unauthenticated User Enumeration and Password Oracle vulnerability
5.3
7 hours ago
Bookly< 27.8
Unauthenticated SQL Injection vulnerability
9.3
7 hours ago
Hotel Booking Lite< 6.0.4
Subscriber+ Sensitive Data Disclosure vulnerability
7.5
7 hours ago
Remote API<= 0.2
Unauthenticated PHP Object Injection vulnerability
9.8
7 hours ago
Ultimate Addons for WPBakery Page Builder< 3.21.4
Unauthenticated Custom Icon Font Deletion vulnerability
6.5
7 hours ago