Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,510
Mitigations
Mitigation rules
15,981
No official patch
13,046
In triage
1,396
Published soon
16
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
svgo
>= 1.0.0, < 2.8.3
NPM: SVGO removeScripts plugin leaves some executable scripts intact
8.2
16 minutes ago
dompurify
<= 3.4.11
NPM: DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
2.1
17 minutes ago
@vitest/browser
< 3.2.7
NPM: @vitest/browser: Browser Mode provider commands bypass the file-access permission gate
9.4
21 minutes ago
@sigstore/oci
< 0.7.1
NPM: Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
9.6
24 minutes ago
@opentelemetry/propagator-jaeger
< 2.9.0
NPM: OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
7.5
50 minutes ago
linkify-it
<= 5.0.1
NPM: linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
7.5
51 minutes ago
aws-cdk-lib
< 2.260.0
NPM: aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling
7.3
53 minutes ago
fast-uri
>= 2.3.1, < 2.4.2
NPM: fast-uri vulnerable to host confusion via failed IDN canonicalization
7.5
54 minutes ago
immutable
< 4.3.9
NPM: Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
8.7
55 minutes ago
immutable
< 4.3.9
NPM: Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
7.5
1 hour ago
hono
>= 4.11.8, < 4.12.27
NPM: hono/jsx does not isolate context per request, leading to cross-request data disclosure
6.5
1 hour ago
hono
>= 4.0.0, < 4.12.27
NPM: Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
6.1
1 hour ago
hono
>= 4.3.3, < 4.12.27
NPM: Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
4.8
1 hour ago
@hono/node-server
< 2.0.5
NPM: Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
5.9
1 hour ago
Easy Form Builder
<= 4.0.11
Unauthenticated Privilege Escalation to Administrator vulnerability
9.8
13 hours ago
astro
>= 7.0.0, < 7.0.6
NPM: Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
5.1
20 hours ago
@astrojs/netlify
< 8.1.2
NPM: @astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
3.7
20 hours ago
body-parser
< 1.20.6
NPM: body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
3.7
20 hours ago
@astrojs/node
>= 8.1.0, < 11.0.2
NPM: @astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
2.1
20 hours ago
astro
< 7.0.6
NPM: Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
5.1
20 hours ago
Load more