The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total54,165
Mitigations17,863
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Before After Image Comparison – Image comparison for WP<= 1.1.21
Broken Access Control vulnerability
5.4
22 minutes ago
WPFunnels<= 3.13.3
Cross Site Scripting (XSS) vulnerability
6.5
32 minutes ago
All Bootstrap Blocks<= 1.3.31
Sensitive Data Exposure vulnerability
4.3
47 minutes ago
Asgaros Forum<= 3.4.0
Broken Access Control vulnerability
4.3
52 minutes ago
Html5 Audio Player<= 2.8.8
Cross Site Scripting (XSS) vulnerability
6.5
53 minutes ago
Restrict User Access – Membership Plugin with Force<= 2.8.1
Broken Access Control vulnerability
5.3
56 minutes ago
WP Event Manager<= 3.4.1
Broken Access Control vulnerability
5.4
56 minutes ago
Scripts n Styles<= 3.5.8
Broken Access Control vulnerability
5.3
1 hour ago
AI Translation for Polylang<= 1.6.2
Broken Access Control vulnerability
5.4
1 hour ago
JetBlocks For Elementor<= 1.5.2.1
Cross Site Scripting (XSS) vulnerability
6.5
3 hours ago
Ocean Pro Demos<= 1.5.4
Unauthenticated Stored Cross-Site Scripting vulnerability
7.2
5 hours ago
Ocean eComm Treasure Box<= 1.8.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.2
5 hours ago
Redux Framework<= 4.5.11
Redux Framework <= 4.5.11 – Authenticated (Subscriber+) Privilege Escalation vulnerability
6.8
5 hours ago
fast-jwt<= 6.3.3
NPM: fast-jwt: Verifier cache accepts expired JWTs without iat.
4.2
14 hours ago
@adonisjs/http-server<= 8.2.2
NPM: AdonisJS: Unencoded route parameters can produce open redirects
6.1
14 hours ago
fast-jwt<= 6.3.0
NPM: fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly set
7.4
14 hours ago
fast-jwt>= 6.2.0, <= 6.2.4
NPM: fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion
9.8
14 hours ago
fast-jwt<= 6.2.4
NPM: fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and persists in the verifier cache)
5.9
14 hours ago
fast-jwt<= 6.2.4
NPM: fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array
8.1
14 hours ago
fast-jwt6.2.4
NPM: fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery
7.4
14 hours ago