The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total54,133
Mitigations17,856
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
handlebars>= 4.0.0, <= 4.7.9
NPM: Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates
4.7
1 hour ago
handlebars>= 4.0.0, <= 4.7.9
NPM: Handlebars: JavaScript Injection via AST Type Confusion in compile (bypass of CVE-2026-33937)
9.8
1 hour ago
handlebars>= 4.0.0, <= 4.7.9
NPM: Handlebars: JavaScript Injection via Own Property Check Bypass
9.2
1 hour ago
@langchain/mongodb<= 1.3.0
NPM: LangChain: MongoDBChatMessageHistory query injection can allow cross-session access
6
1 hour ago
generator-jhipster>= 7.0.0, < 9.4.0
NPM: JHipster: SQL Injection in the Parameter of JHipster-Generated Reactive (WebFlux + R2DBC) Applicationssort
8.8
1 hour ago
react-jhipster<= 1.0.3
NPM: JHipster: Generated Applications Allow Stored XSS via Unrestricted Blob ContentType Opened as Same-Origin Blob
7.6
1 hour ago
generator-jhipster< 9.4.0
NPM: JHipster: Generated Applications Allow Stored XSS via Unrestricted Blob ContentType Opened as Same-Origin Blob
7.6
1 hour ago
msgpack5< 6.1.0
NPM: msgpack5: Truncated map32 headers throw an unexpected error
7.5
1 hour ago
msgpack5< 6.1.0
NPM: msgpack5: Many buffered values can exhaust the streaming decoder stack
7.5
1 hour ago
msgpack5< 6.1.0
NPM: msgpack5: Reserved byte can cause unbounded stream buffering
5.9
1 hour ago
msgpack5< 6.1.0
NPM: msgpack5: Partial options disable prototype protection
6.5
1 hour ago
msgpack5< 6.1.0
NPM: msgpack5: Deeply nested input can exhaust the decoder stack
5.3
1 hour ago
msgpack5< 6.1.0
NPM: msgpack5: Quadratic parsing in the streaming decoder
5.9
1 hour ago
msgpack5< 6.1.0
NPM: msgpack5: Decoding negative int64 values mutates the input buffer
3.7
1 hour ago
Wallet System for WooCommerce< 2.8.0
Subscriber+ Wallet Balance Manipulation vulnerability
6.5
5 hours ago
Easy Digital Downloads< 3.7.1
Unauthenticated Account Creation with Registration Disabled vulnerability
5.3
5 hours ago
TutorStarter< 4.0.4
Unauthenticated User Registration Bypass vulnerability
5.3
5 hours ago
Airwallex Online Payments Gateway< 1.36.0
Unauthenticated Payment Bypass vulnerability
5.3
5 hours ago
Zotpress<= 7.4.4
Cross Site Scripting (XSS) vulnerability
6.5
6 hours ago
Tutor LMS<= 4.1.1
Race Condition vulnerability
5.3
6 hours ago