The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,161
Mitigations16,140
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
@apostrophecms/seo<= 1.4.2
NPM: @apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
8.7
1 hour ago
apostrophe<= 4.30.0
NPM: @apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
3.7
1 hour ago
apostrophe<= 4.30.0
NPM: Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
9.1
1 hour ago
sanitize-html>= 1.18.0, <= 2.17.4
NPM: sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes
5.4
1 hour ago
@nocobase/plugin-notification-in-app-message<= 2.0.60
NPM: NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
10
3 hours ago
jodit< 4.13.6
NPM: Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization
5.3
3 hours ago
jodit< 4.12.28
NPM: Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
7.2
3 hours ago
jodit< 4.12.18
NPM: Jodit has prototype pollution via Jodit.configure() / ConfigMerge
6.3
3 hours ago
jodit<= 4.12.30
NPM: Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS
5.4
3 hours ago
@phun-ky/defaults-deep< 2.0.5
NPM: @phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging
7.3
5 hours ago
hashi-vault-js<= 0.5.1
NPM: hashi-vault-js has a path traversal and query parameter injection
8.7
6 hours ago
dssrf<= 1.0.4
NPM: dssrf: any users using 1.1.1.1 DNS is impacted by SSRF
8.7
6 hours ago
re2<= 1.25.1
NPM: re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS)
5.7
6 hours ago
re2<= 1.25.1
NPM: re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS)
6.2
6 hours ago
nx>= 17.0.4, < 22.7.2
NPM: `nx graph` dev server permissive CORS policy
5.9
6 hours ago
@dynatrace-oss/dynatrace-mcp-server<= 1.8.7
NPM: `@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation
7.5
7 hours ago
@dynatrace-oss/dynatrace-mcp-server< 2.0.0
NPM: @dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification
4.2
7 hours ago
@dynatrace-oss/dynatrace-mcp-server< 2.1.1
NPM: @dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL
4.3
7 hours ago
Simply Poll <= 1.4.1
Unauthenticated SQL Injection vulnerability
9.3
13 hours ago
UsersWP< 1.2.67
Two-Factor Authentication Bypass vulnerability
7.1
13 hours ago