The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,295
Mitigations16,213
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
ghost>= 6.27.0, < 6.44.0
NPM: Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
5.3
1 hour ago
ghost>= 5.18.0, < 6.21.1
NPM: Ghost: Member existence leak via magic link sign-in response
5.3
1 hour ago
@tryghost/activitypub< 3.1.0
NPM: XSS in Ghost's ActivityPub client
7.5
1 hour ago
ghost>= 2.2.0, < 6.54.1
NPM: Ghost: Session Fixation in Ghost Admin
6.7
1 hour ago
ghost>= 0.10.0, < 6.54.1
NPM: Ghost: Theme Upload Path Traversal
6.6
1 hour ago
ghost>= 1.20.1, < 6.54.1
NPM: Ghost: Database Backup Path Traversal
5.5
1 hour ago
ghost>= 0.10.0, < 6.54.1
NPM: Ghost: Server-Side Request Forgery in Image Fetching
4.1
1 hour ago
ghost< 6.54.1
NPM: Ghost: Blind Password Hash Disclosure in Ghost Admin API
4.8
1 hour ago
ghost>= 6.19.4, < 6.21.1
NPM: Ghost: Mobiledoc image-size fetch SSRF
5.4
1 hour ago
ghost>= 6.0.9, < 6.21.1
NPM: Ghost: Server-side request forgery via DNS rebinding in external request handling
4
2 hours ago
ghost>= 6.0.9, <= 6.21.0
NPM: Ghost: Private IP filtering bypass to make server-side requests to internal services
5.8
2 hours ago
ghost>= 4.22.0, < 6.54.1
NPM: Ghost: Archived Offers can be Redeemed
4.8
2 hours ago
ghost>= 6.19.4, < 6.21.1
NPM: Ghost: File Upload Content-Type Spoofing
5.4
2 hours ago
ghost>= 5.26.0, < 6.54.1
NPM: Ghost: Cross-Site Scripting in Universal Import
5
2 hours ago
flowise<= 3.1.2
NPM: Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service
9.2
3 hours ago
flowise<= 3.1.2
NPM: Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
9.5
3 hours ago
flowise-components<= 3.1.2
NPM: Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
9.5
3 hours ago
flowise<= 3.1.2
NPM: Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
8.3
4 hours ago
flowise<= 3.1.3
NPM: Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
6.3
4 hours ago
flowise<= 3.1.2
NPM: Flowise: Missing Authorization on Execution Update Endpoint
7.1
4 hours ago