Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
53,006
Mitigations
Mitigation rules
17,321
No official patch
13,363
In triage
1,425
Published soon
32
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Virtue Premium
<= 4.10.22
Cross Site Scripting (XSS) vulnerability
6.5
16 minutes ago
Virtue Premium
<= 4.10.21
Cross Site Scripting (XSS) vulnerability
6.5
18 minutes ago
ReactPress
<= 3.4.0
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
37 minutes ago
Real Estate Manager
<= 7.3
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
41 minutes ago
Frontend Post Submission Manager Lite
<= 1.3.4
Unauthenticated Stored DOM-Based Cross-Site Scripting vulnerability
7.1
47 minutes ago
Post Views Stats Counter
<= 1.1.7
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
52 minutes ago
Product Designer App
<= 1.1.3
Unauthenticated Arbitrary File Read vulnerability
7.5
1 hour ago
Simply Schedule Appointments
<= 1.6.12.27
Authenticated (Subscriber+) Local File Inclusion vulnerability
7.5
1 hour ago
@nestjs/microservices
< 11.2.4
NPM: Nest: Remote process termination via a deeply nested microservice message pattern
7.5
8 hours ago
fast-uri
< 2.4.7
NPM: fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets
4.8
8 hours ago
fast-uri
>= 4.1.3, < 4.1.5
NPM: fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
4.8
8 hours ago
@xhmikosr/decompress
<= 10.2.1
NPM: @xhmikosr/decompress: Path traversal via symlink chain
9.1
8 hours ago
decompress
<= 4.2.1
NPM: @xhmikosr/decompress: Path traversal via symlink chain
9.1
8 hours ago
ip-address
<= 10.7.0
NPM: ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range
6.3
8 hours ago
ip-address
<= 10.7.0
NPM: ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process
6.3
8 hours ago
moment
>= 2.29.2, < 2.31.0
NPM: moment vulnerable to Path Traversal via crafted non-string locale name
5.9
8 hours ago
brace-expansion
< 1.1.21
NPM: brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service
5.3
8 hours ago
brace-expansion
< 1.1.20
NPM: brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
7.5
8 hours ago
brace-expansion
< 1.1.19
NPM: brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
7.5
8 hours ago
engine.io
>= 6.6.0, < 6.6.10
NPM: Socket.IO: Engine.IO Protocol Revision Mismatch DoS
7.5
8 hours ago
Load more