Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,187
Mitigations
Mitigation rules
16,181
No official patch
13,189
In triage
1,133
Published soon
8
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
sequelize
< 6.37.4
NPM: Sequelize: SQL Injection (Oracle DB)
9.8
1 hour ago
hono
< 4.12.34
NPM: Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
5.3
1 hour ago
ip-address
<= 10.3.0
NPM: ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
7.7
2 hours ago
ip-address
>= 10.1.1, <= 10.2.1
NPM: ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks
6.9
2 hours ago
ip-address
>= 10.1.1, <= 10.2.0
NPM: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
6.9
2 hours ago
undici
< 6.28.0
NPM: undici vulnerable to CRLF Injection via blob-like body 'type' property
4.2
2 hours ago
undici
>= 7.0.0, < 7.29.0
NPM: undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
5.9
2 hours ago
undici
< 6.28.0
NPM: undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
4.8
2 hours ago
undici
< 6.28.0
NPM: undici vulnerable to downstream response desynchronization via retry interceptor
4.8
2 hours ago
undici
>= 7.0.0, < 7.29.0
NPM: undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
7.4
2 hours ago
fast-uri
< 2.4.4
NPM: fast-uri vulnerable to host confusion via backslash authority introducer
7.5
2 hours ago
socket.io-parser
< 3.3.6
NPM: Socket.IO: Zero-attachment Memory Exhaustion
7.5
2 hours ago
postcss
<= 8.5.22
NPM: PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset
6.3
4 hours ago
brace-expansion
< 1.1.18
NPM: brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
7.5
5 hours ago
@angular/core
<= 19.2.25
NPM: Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes
7.6
5 hours ago
@angular/compiler
<= 19.2.25
NPM: Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes
7.6
5 hours ago
@angular/platform-server
<= 19.2.25
NPM: Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)
8.6
5 hours ago
@angular/common
<= 19.2.25
NPM: Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning
8.8
6 hours ago
VikBooking Hotel Booking Engine & PMS
<= 1.8.13
Reflected Cross-Site Scripting vulnerability
7.1
9 hours ago
WPify Woo Czech
<= 5.4.16
Authenticated (Shop Manager+) Privilege Escalation vulnerability
7.2
9 hours ago
Load more