The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total54,182
Mitigations17,876
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Dashboard Notes<= 1.0.3
Cross Site Request Forgery (CSRF) vulnerability
7.1
31 minutes ago
Before After Image Comparison – Image comparison for WP<= 1.1.21
Broken Access Control vulnerability
5.4
1 hour ago
WPFunnels<= 3.13.3
Cross Site Scripting (XSS) vulnerability
6.5
1 hour ago
All Bootstrap Blocks<= 1.3.31
Sensitive Data Exposure vulnerability
4.3
1 hour ago
Asgaros Forum<= 3.4.0
Broken Access Control vulnerability
4.3
2 hours ago
Html5 Audio Player<= 2.8.8
Cross Site Scripting (XSS) vulnerability
6.5
2 hours ago
Restrict User Access – Membership Plugin with Force<= 2.8.1
Broken Access Control vulnerability
5.3
2 hours ago
WP Event Manager<= 3.4.1
Broken Access Control vulnerability
5.4
2 hours ago
Scripts n Styles<= 3.5.8
Broken Access Control vulnerability
5.3
2 hours ago
AI Translation for Polylang<= 1.6.2
Broken Access Control vulnerability
5.4
2 hours ago
JetBlocks For Elementor<= 1.5.2.1
Cross Site Scripting (XSS) vulnerability
6.5
4 hours ago
Ocean Pro Demos<= 1.5.4
Unauthenticated Stored Cross-Site Scripting vulnerability
7.2
6 hours ago
Ocean eComm Treasure Box<= 1.8.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.2
6 hours ago
Redux Framework<= 4.5.11
Redux Framework <= 4.5.11 – Authenticated (Subscriber+) Privilege Escalation vulnerability
6.8
6 hours ago
fast-jwt<= 6.3.3
NPM: fast-jwt: Verifier cache accepts expired JWTs without iat.
4.2
15 hours ago
@adonisjs/http-server<= 8.2.2
NPM: AdonisJS: Unencoded route parameters can produce open redirects
6.1
15 hours ago
fast-jwt<= 6.3.0
NPM: fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly set
7.4
15 hours ago
fast-jwt>= 6.2.0, <= 6.2.4
NPM: fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion
9.8
15 hours ago
fast-jwt<= 6.2.4
NPM: fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and persists in the verifier cache)
5.9
15 hours ago
fast-jwt<= 6.2.4
NPM: fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array
8.1
15 hours ago