The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total49,758
Mitigations16,024
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
@sveltejs/kit<= 2.69.0
NPM: SvelteKit: Prototype pollution in file input deletion path in remote-function forms
4.3
11 minutes ago
@sveltejs/kit<= 2.69.0
NPM: SvelteKit: Big remote form function payloads can cause Node process to crash
5.3
18 minutes ago
better-auth>= 1.1.3, < 1.6.22
NPM: Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
8.3
25 minutes ago
@better-auth/stripe>= 1.4.11, < 1.6.21
NPM: @better-auth/stripe: cross-organization billing tampering in organization subscription actions
7.1
25 minutes ago
@better-auth/scim>= 1.4.0-beta.27, <= 1.6.21
NPM: @better-auth/scim: account takeover and stale access via SCIM provider-id collision
9.9
28 minutes ago
react-router>= 7.0.0, < 7.18.0
NPM: React Router: Unauthenticated Denial of Service via Inefficient Route Matching
8.7
2 hours ago
liquidjs<= 10.27.0
NPM: LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
8.2
2 hours ago
builder-util-runtime< 9.7.0
NPM: electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
8.2
2 hours ago
app-builder-lib< 26.15.0
NPM: electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`
7.8
2 hours ago
ARForms<= 7.2.1
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
8 hours ago
SUMO Reward Points<= 32.7.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
8 hours ago
FormCraft 3<= 3.9.14
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
9 hours ago
Contact Form 7 – Dynamic Text Extension<= 5.0.6
Content Injection vulnerability
6.5
9 hours ago
AIWU<= 1.5.4
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
9 hours ago
Lumise Product Designer<= 2.1.1
Unauthenticated SQL Injection vulnerability
9.3
9 hours ago
Mobile DJ Manager<= 1.7.8.4
Authenticated (Subscriber+) Privilege Escalation vulnerability
8.8
9 hours ago
GoDAM<= 1.12.2
Unauthenticated Arbitrary File Upload vulnerability
10
9 hours ago
WP Ticket Customer Service Software & Support Ticket System<= 6.0.5
Unauthenticated Code Injection vulnerability
10
9 hours ago
FoodBakery<= 4.9
Authenticated (Subscriber+) Arbitrary File Deletion vulnerability
7.7
10 hours ago
react-router>= 6.0.0, < 7.18.0
NPM: React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
5.1
20 hours ago