Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,753
Mitigations
Mitigation rules
16,024
No official patch
13,107
In triage
1,241
Published soon
73
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
react-router
>= 7.0.0, < 7.18.0
NPM: React Router: Unauthenticated Denial of Service via Inefficient Route Matching
8.7
57 minutes ago
liquidjs
<= 10.27.0
NPM: LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
8.2
59 minutes ago
builder-util-runtime
< 9.7.0
NPM: electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
8.2
1 hour ago
app-builder-lib
< 26.15.0
NPM: electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`
7.8
1 hour ago
ARForms
<= 7.2.1
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
7 hours ago
SUMO Reward Points
<= 32.7.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
7 hours ago
FormCraft 3
<= 3.9.14
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
8 hours ago
Contact Form 7 – Dynamic Text Extension
<= 5.0.6
Content Injection vulnerability
6.5
8 hours ago
AIWU
<= 1.5.4
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
8 hours ago
Lumise Product Designer
<= 2.1.1
Unauthenticated SQL Injection vulnerability
9.3
8 hours ago
Mobile DJ Manager
<= 1.7.8.4
Authenticated (Subscriber+) Privilege Escalation vulnerability
8.8
8 hours ago
GoDAM
<= 1.12.2
Unauthenticated Arbitrary File Upload vulnerability
10
8 hours ago
WP Ticket Customer Service Software & Support Ticket System
<= 6.0.5
Unauthenticated Code Injection vulnerability
10
8 hours ago
FoodBakery
<= 4.9
Authenticated (Subscriber+) Arbitrary File Deletion vulnerability
7.7
8 hours ago
react-router
>= 6.0.0, < 7.18.0
NPM: React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
5.1
19 hours ago
react-router
>= 7.9.6, <= 7.12.0
NPM: React Router: Open redirect leading to XSS
6.9
19 hours ago
react-router-dom
>= 6.30.2, <= 6.30.4
NPM: React Router: Open redirect leading to XSS
6.9
19 hours ago
react-router
>= 7.11.0, < 7.18.0
NPM: React Router: RSCErrorHandler Missing Protocol Validation (XSS)
6.9
19 hours ago
react-router
>= 6.4.0, < 7.18.0
NPM: React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
6.1
19 hours ago
find-my-way
<= 9.6.0
NPM: find-my-way: DDoS with HTTP2
7.5
19 hours ago
Load more