Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
54,133
Mitigations
Mitigation rules
17,856
No official patch
13,576
In triage
991
Published soon
133
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
handlebars
>= 4.0.0, <= 4.7.9
NPM: Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates
4.7
1 hour ago
handlebars
>= 4.0.0, <= 4.7.9
NPM: Handlebars: JavaScript Injection via AST Type Confusion in compile (bypass of CVE-2026-33937)
9.8
1 hour ago
handlebars
>= 4.0.0, <= 4.7.9
NPM: Handlebars: JavaScript Injection via Own Property Check Bypass
9.2
1 hour ago
@langchain/mongodb
<= 1.3.0
NPM: LangChain: MongoDBChatMessageHistory query injection can allow cross-session access
6
1 hour ago
generator-jhipster
>= 7.0.0, < 9.4.0
NPM: JHipster: SQL Injection in the Parameter of JHipster-Generated Reactive (WebFlux + R2DBC) Applicationssort
8.8
1 hour ago
react-jhipster
<= 1.0.3
NPM: JHipster: Generated Applications Allow Stored XSS via Unrestricted Blob ContentType Opened as Same-Origin Blob
7.6
1 hour ago
generator-jhipster
< 9.4.0
NPM: JHipster: Generated Applications Allow Stored XSS via Unrestricted Blob ContentType Opened as Same-Origin Blob
7.6
1 hour ago
msgpack5
< 6.1.0
NPM: msgpack5: Truncated map32 headers throw an unexpected error
7.5
1 hour ago
msgpack5
< 6.1.0
NPM: msgpack5: Many buffered values can exhaust the streaming decoder stack
7.5
1 hour ago
msgpack5
< 6.1.0
NPM: msgpack5: Reserved byte can cause unbounded stream buffering
5.9
1 hour ago
msgpack5
< 6.1.0
NPM: msgpack5: Partial options disable prototype protection
6.5
1 hour ago
msgpack5
< 6.1.0
NPM: msgpack5: Deeply nested input can exhaust the decoder stack
5.3
1 hour ago
msgpack5
< 6.1.0
NPM: msgpack5: Quadratic parsing in the streaming decoder
5.9
1 hour ago
msgpack5
< 6.1.0
NPM: msgpack5: Decoding negative int64 values mutates the input buffer
3.7
1 hour ago
Wallet System for WooCommerce
< 2.8.0
Subscriber+ Wallet Balance Manipulation vulnerability
6.5
5 hours ago
Easy Digital Downloads
< 3.7.1
Unauthenticated Account Creation with Registration Disabled vulnerability
5.3
5 hours ago
TutorStarter
< 4.0.4
Unauthenticated User Registration Bypass vulnerability
5.3
5 hours ago
Airwallex Online Payments Gateway
< 1.36.0
Unauthenticated Payment Bypass vulnerability
5.3
5 hours ago
Zotpress
<= 7.4.4
Cross Site Scripting (XSS) vulnerability
6.5
6 hours ago
Tutor LMS
<= 4.1.1
Race Condition vulnerability
5.3
6 hours ago
Load more