The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,233
Mitigations16,192
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Google Tag Manager<= 1.22.3
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
41 minutes ago
Academy LMS<= 3.8.2
Subscriber+ Sensitive Information Disclosure vulnerability
6.5
47 minutes ago
ElementsKit Elementor addons Lite< 3.10.01
Subsite Administrator+ PHP Code Injection vulnerability
7.2
50 minutes ago
JS Help Desk< 3.1.4
Unauthenticated Arbitrary Ticket File Attachment Upload vulnerability
5.3
50 minutes ago
JS Help Desk< 3.1.4
Subscriber+ Sensitive Information Disclosure vulnerability
6.5
55 minutes ago
NewStatPress< 1.4.5
Unauthenticated Stored XSS vulnerability
7.1
56 minutes ago
GiveWP< 4.16.3
Unauthenticated Payment Gateway Restriction Bypass vulnerability
5.3
1 hour ago
Link Library< 7.9.4
Reflected Cross-Site Scripting vulnerability
7.1
1 hour ago
Kirki< 6.0.13
Unauthenticated PHP Object Injection vulnerability
9.8
1 hour ago
Survey Maker< 5.1.7.7
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
1 hour ago
Realtyna Organic IDX plugin<= 5.3.0
Authenticated (Subscriber+) Arbitrary File Upload vulnerability
8.8
1 hour ago
WP Go Maps< 10.1.04
Unauthenticated SQL Injection vulnerability
9.3
1 hour ago
FluentCart< 1.5.3
Unauthenticated Order PII Disclosure vulnerability
7.5
2 hours ago
FlxWoo< 3.1.1
Unauthenticated Payment Bypass vulnerability
7.5
2 hours ago
Realtyna Organic IDX plugin<= 5.2.0
Unauthenticated Arbitrary File Upload vulnerability
10
2 hours ago
sequelize< 6.37.4
NPM: Sequelize: SQL Injection (Oracle DB)
9.8
12 hours ago
hono< 4.12.34
NPM: Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
5.3
12 hours ago
ip-address<= 10.3.0
NPM: ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
7.7
12 hours ago
ip-address>= 10.1.1, <= 10.2.1
NPM: ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks
6.9
12 hours ago
ip-address>= 10.1.1, <= 10.2.0
NPM: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
6.9
12 hours ago