Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,601
Mitigations
Mitigation rules
15,990
No official patch
13,086
In triage
1,298
Published soon
91
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
n8n
< 1.123.64
NPM: n8n: Google Service Account Private Key Exposed in JWT Header
5.1
1 hour ago
n8n
< 1.123.64
NPM: n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
8.4
1 hour ago
n8n
< 1.123.64
NPM: n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
8.2
1 hour ago
n8n
< 1.123.64
NPM: n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
8.9
1 hour ago
n8n
< 2.29.8
NPM: n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool
7.2
1 hour ago
PIMP - Creative MultiPurpose
<= 1.7
WordPress PIMP - Creative MultiPurpose theme <= 1.7 - Cross Site Request Forgery (CSRF) vulnerability
4.3
7 hours ago
fast-uri
>= 2.3.1, <= 2.4.2
NPM: fast-uri vulnerable to host confusion via literal backslash authority delimiter
7.5
21 hours ago
sharp
< 0.35.0
NPM: sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
7
21 hours ago
fast-xml-parser
>= 5.9.3, < 5.10.1
NPM: fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
8.7
21 hours ago
@hono/node-server
>= 2.0.0, <= 2.0.9
NPM: Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
5.3
21 hours ago
typeorm
< 0.3.31
NPM: TypeORM: migration:generate template-literal code injection
5.7
21 hours ago
svgo
>= 1.0.0, < 2.8.3
NPM: SVGO removeScripts plugin leaves some executable scripts intact
8.2
1 day ago
dompurify
<= 3.4.11
NPM: DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
2.1
1 day ago
@vitest/browser
< 3.2.7
NPM: @vitest/browser: Browser Mode provider commands bypass the file-access permission gate
9.4
1 day ago
@sigstore/oci
< 0.7.1
NPM: Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
9.6
1 day ago
@opentelemetry/propagator-jaeger
< 2.9.0
NPM: OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
7.5
1 day ago
linkify-it
<= 5.0.1
NPM: linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
7.5
1 day ago
aws-cdk-lib
< 2.260.0
NPM: aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling
7.3
1 day ago
fast-uri
>= 2.3.1, < 2.4.2
NPM: fast-uri vulnerable to host confusion via failed IDN canonicalization
7.5
1 day ago
immutable
< 4.3.9
NPM: Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
8.7
1 day ago
Load more