The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,530
Mitigations16,391
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Forminator<= 1.56.1
Unauth. Arbitrary File Upload
9.8
01/01/2100
vm2<= 3.11.5
NPM: vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass
7.5
31 minutes ago
vm2<= 3.11.5
NPM: vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
10
31 minutes ago
vm2<= 3.11.5
NPM: vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
9.8
31 minutes ago
vm2<= 3.11.5
NPM: VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE
9.9
31 minutes ago
vm2<= 3.11.5
NPM: vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
8.7
32 minutes ago
Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms<= 6.0
Broken Access Control vulnerability
5.4
47 minutes ago
RomethemeForm For Elementor<= 1.2.6
Broken Access Control vulnerability
4.3
47 minutes ago
WP Table Builder<= 2.2.0
Broken Access Control vulnerability
4.3
52 minutes ago
3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery<= 1.16.20
Sensitive Data Exposure vulnerability
5.3
53 minutes ago
Shortcodes and extra features for Phlox theme<= 2.17.22
Sensitive Data Exposure vulnerability
5.3
54 minutes ago
Razorpay for WooCommerce<= 4.8.7
Insecure Direct Object References (IDOR) vulnerability
5.3
55 minutes ago
@medplum/core<= 5.1.5
NPM: Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage
7.1
4 hours ago
deepmerge-ts< 8.0.0
NPM: DeepmergeTS has stack exhaustion when merging recursive object graphs
8.2
4 hours ago
TrueBooker<= 1.2.6
Unauthenticated Account Takeover via Insecure Direct Object Reference in 'truebooker_wp_user_id' Parameter vulnerability
9.8
6 hours ago
Wholesale Market<= 2.2.2
Authenticated (Subscriber+) Privilege Escalation via 'role_required' Parameter vulnerability
8.8
6 hours ago
KiviCare<= 4.5.1
Authenticated (Doctor+) SQL Injection via 'searchTerm' Parameter vulnerability
8.5
6 hours ago
Groundhogg<= 4.5.14
Authenticated (Vendor+) SQL Injection via 'tag_query' Parameter vulnerability
8.5
6 hours ago
Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant<= 5.1
Unauthenticated Stored Cross-Site Scripting via 'action' Parameter vulnerability
7.1
6 hours ago
Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant<= 5.1
Authenticated (Editor+) SQL Injection via Pattern JSON Keys/Values vulnerability
7.6
6 hours ago