Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
53,756
Mitigations
Mitigation rules
17,716
No official patch
13,489
In triage
1,076
Published soon
131
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
payload
>= 3.0.0, < 3.90.0
NPM: Payload: Password hashes use insufficient PBKDF2 iterations
5.7
26 minutes ago
payload
< 3.88.0
NPM: Payload: Sort queries could expose protected field information
6.9
26 minutes ago
@modelcontextprotocol/client
>= 2.0.0, < 2.2.0
NPM: MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server
7.5
29 minutes ago
@modelcontextprotocol/sdk
>= 1.12.0, < 1.31.0
NPM: MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server
7.5
29 minutes ago
i18next-http-backend
< 4.0.2
NPM: i18next-http-backend incomplete URL validation permits SSRF
3.7
31 minutes ago
@langchain/redis
<= 1.1.0
NPM: LangChain: RediSearch Filter Injection via Unescaped Tag/Text Values
2.3
32 minutes ago
sharp
< 0.35.5
NPM: sharp : Vulnerability in librsvg dependency CVE-2026-96889
8.9
2 hours ago
shell-quote
>= 1.8.4, < 1.11.0
NPM: shell-quote: `quote()` command injection via a line terminator in a token after a `{ comment }` token
8.1
2 hours ago
pbkdf2
<= 3.1.6
NPM: pbkdf2 rehashes long passwords on every iteration, enabling denial of service
3.7
2 hours ago
elegro Crypto Payment
<= 1.0.1
Unauthenticated Arbitrary Order Status Change vulnerability
5.3
4 hours ago
Deema Payment Gateway
<= 1.1.2
Unauthenticated Payment Confirmation Forgery vulnerability
5.3
6 hours ago
Deema Payment Gateway
<= 1.1.2
Unauthenticated Payment Bypass and Order Manipulation vulnerability
5.3
6 hours ago
JetElements For Elementor
<= 2.9.2.2
Cross Site Scripting (XSS) vulnerability
6.5
7 hours ago
Slider Pro
<= 1.0.0
Unauthenticated Sensitive Data Disclosure vulnerability
5.3
10 hours ago
File Media Renamer
<= 1.3
Author+ Arbitrary File Rename vulnerability
6.5
10 hours ago
Fast Courier
<= 5.2.3
Unauthenticated Order Fulfillment Update vulnerability
5.3
10 hours ago
@simple-git/argv-parser
< 2.0.1
NPM: simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection
9.2
16 hours ago
simple-git
>= 3.15.0, < 4.0.1
NPM: simple-git unsafe-operation guard does not block trailer command configuration
9.2
16 hours ago
simple-git
<= 3.36.0
NPM: simple-git allows command execution through unblocked Git configuration includes
8.1
16 hours ago
simple-git
<= 3.36.0
NPM: simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (residual of CVE-2026-28291)
8.1
16 hours ago
Load more