The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total54,173
Mitigations17,868
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Before After Image Comparison – Image comparison for WP<= 1.1.21
Broken Access Control vulnerability
5.4
44 minutes ago
WPFunnels<= 3.13.3
Cross Site Scripting (XSS) vulnerability
6.5
54 minutes ago
All Bootstrap Blocks<= 1.3.31
Sensitive Data Exposure vulnerability
4.3
1 hour ago
Asgaros Forum<= 3.4.0
Broken Access Control vulnerability
4.3
1 hour ago
Html5 Audio Player<= 2.8.8
Cross Site Scripting (XSS) vulnerability
6.5
1 hour ago
Restrict User Access – Membership Plugin with Force<= 2.8.1
Broken Access Control vulnerability
5.3
1 hour ago
WP Event Manager<= 3.4.1
Broken Access Control vulnerability
5.4
1 hour ago
Scripts n Styles<= 3.5.8
Broken Access Control vulnerability
5.3
1 hour ago
AI Translation for Polylang<= 1.6.2
Broken Access Control vulnerability
5.4
1 hour ago
JetBlocks For Elementor<= 1.5.2.1
Cross Site Scripting (XSS) vulnerability
6.5
3 hours ago
Ocean Pro Demos<= 1.5.4
Unauthenticated Stored Cross-Site Scripting vulnerability
7.2
5 hours ago
Ocean eComm Treasure Box<= 1.8.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.2
5 hours ago
Redux Framework<= 4.5.11
Redux Framework <= 4.5.11 – Authenticated (Subscriber+) Privilege Escalation vulnerability
6.8
5 hours ago
fast-jwt<= 6.3.3
NPM: fast-jwt: Verifier cache accepts expired JWTs without iat.
4.2
14 hours ago
@adonisjs/http-server<= 8.2.2
NPM: AdonisJS: Unencoded route parameters can produce open redirects
6.1
14 hours ago
fast-jwt<= 6.3.0
NPM: fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly set
7.4
14 hours ago
fast-jwt>= 6.2.0, <= 6.2.4
NPM: fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion
9.8
14 hours ago
fast-jwt<= 6.2.4
NPM: fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and persists in the verifier cache)
5.9
14 hours ago
fast-jwt<= 6.2.4
NPM: fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array
8.1
14 hours ago
fast-jwt6.2.4
NPM: fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery
7.4
14 hours ago