The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,247
Mitigations16,213
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
flowise<= 3.1.2
NPM: Flowise RCE via TypeORM DataSource
9
29 minutes ago
flowise-components<= 3.1.2
NPM: Flowise RCE via TypeORM DataSource
9
29 minutes ago
flowise<= 3.1.2
NPM: Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration
8.5
36 minutes ago
flowise<= 3.1.2
NPM: Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint
6
40 minutes ago
Booking Calendar Contact Form<= 1.0.23
Reflected Cross-Site Scripting vulnerability
7.1
3 hours ago
WP Event SOlution< 4.1.16
Unauthenticated Payment Bypass vulnerability
5.3
3 hours ago
WP Travel< 11.8.1
Unauthenticated Payment Bypass vulnerability
5.3
3 hours ago
Hide My WP Ghost< 7.0.05
IP Address Spoofing vulnerability
5.4
3 hours ago
Booking Calendar Contact Form<= 1.0.23
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
6.5
3 hours ago
Ultimate Product Catalogue<= 3.8.6
Authenticated (Contributor+) Arbitrary File Upload vulnerability
10
4 hours ago
Booking Calendar Contact Form<= 1.1.24
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
4 hours ago
Zoner - Real Estate< 4.2
WordPress Zoner - Real Estate WordPress Theme theme < 4.2 - Real Estate WordPress Theme < 4.2 - Cross-Site Scripting vulnerability
7.1
4 hours ago
Contact Form Builder, Contact Widget<= 1.6.1
Reflected Cross-Site Scripting vulnerability
7.1
4 hours ago
Flights &amp; Hotels Booking WP Plugin<= 2.3
Reflected Cross-Site Scripting vulnerability
7.1
4 hours ago
WOLF< 1.1.0
WordPress WOLF plugin < 1.1.0 - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS vulnerability
7.1
4 hours ago
International Sms For Contact Form 7 Integration<= 1.2
Reflected Cross-Site Scripting vulnerability
7.1
4 hours ago
FluentForm<= 6.2.7
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
4 hours ago
Easy Digital Downloads<= 3.6.9
Authenticated (Shop Manager+) Arbitrary File Upload vulnerability
9.1
4 hours ago
Wholesale For WooCommerce Lite – B2B & B2C Solution<= 2.0.5
Authenticated (Author+) Privilege Escalation vulnerability
7.2
4 hours ago
Database for CF7<= 1.2.6
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
5 hours ago