Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,600
Mitigations
Mitigation rules
17,172
No official patch
13,372
In triage
1,420
Published soon
1
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
unleash-server
< 8.0.3
NPM: Unleash: Missing await on permission check + cross-project IDOR in admin API
7.1
1 hour ago
unleash-server
< 8.0.3
NPM: Unleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit log
4.3
1 hour ago
unleash-server
< 8.0.3
NPM: Unleash: Clone-feature lets a user copy a feature from a project they cannot read
5.3
1 hour ago
unleash-server
< 8.0.3
NPM: Unleash: CR-approval email renders user-controlled raw HTML
2.1
1 hour ago
@novu/js
<= 3.17.0
NPM: Novu: Stored XSS in In-App Inbox via notification redirect.url javascript: scheme
5.1
1 hour ago
mppx
< 0.8.2
NPM: mppx: Gas Draining with access list
6.9
1 hour ago
mppx
< 0.8.1
NPM: mppx: Gas Draining with padding
6.9
1 hour ago
@deepstream/server
10.1.0
NPM: deepstream: PATCH_MULTI action bypasses Valve permission system allowing unauthorized record writes
8.8
1 hour ago
request-filtering-agent
< 3.2.1
NPM: request-filtering-agent: Synchronous throw from createConnection() for literal private-IP hosts bypasses req.on('error'), crashing the Node.js process
7.5
1 hour ago
Advanced Contact form 7 DB
<= 2.1.1
Missing Authorization to Authenticated (Contributor+) Information Disclosure vulnerability
6.5
4 hours ago
WP User Manager
<= 2.9.19
Broken Access Control vulnerability
5.3
4 hours ago
9router
<= 0.5.4
NPM: 9Router has a Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header
5.3
5 hours ago
9router
<= 0.5.4
NPM: 9Router has an Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header
7.3
5 hours ago
TrustedLogin Connector
<= 2.0.3
Sensitive Data Exposure vulnerability
5.3
5 hours ago
@aborruso/ckan-mcp-server
<= 0.4.107
NPM: @aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509
5.7
6 hours ago
@sync-in/server
<= 2.4.0
NPM: Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory)
5.3
6 hours ago
@sync-in/server
<= 2.3.0
NPM: Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`
6.5
6 hours ago
@sync-in/server
<= 2.3.0
NPM: Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`
8.1
6 hours ago
@sync-in/server
<= 2.3.0
NPM: @sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`
6.8
6 hours ago
@roomi-fields/notebooklm-mcp
>= 1.6.0, < 2.0.3
NPM: @roomi-fields/notebooklm-mcp has a path traversal in vault.batch tool that allows arbitrary file write outside intended vault directory
7.1
6 hours ago
Load more