Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,791
Mitigations
Mitigation rules
16,024
No official patch
13,121
In triage
1,241
Published soon
63
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@budibase/server
<= 3.38.1
NPM: Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
7.6
18 minutes ago
@budibase/server
<= 3.38.1
NPM: Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
8.3
19 minutes ago
@budibase/server
<= 3.38.1
NPM: Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
5.7
19 minutes ago
@budibase/server
<= 3.38.1
NPM: Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
7.5
20 minutes ago
@budibase/server
<= 3.38.1
NPM: Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
0
22 minutes ago
@budibase/server
<= 3.38.1
NPM: Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
9
27 minutes ago
@budibase/server
<= 3.38.1
NPM: Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
8.5
27 minutes ago
@budibase/server
<= 3.38.1
NPM: Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs
7.7
28 minutes ago
@budibase/server
<= 3.38.1
NPM: Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
7
28 minutes ago
@budibase/server
<= 3.38.1
NPM: Budibase: SQL Injection via `multipleStatements: true`
9.6
30 minutes ago
@budibase/server
<= 3.38.1
NPM: Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
0
30 minutes ago
@budibase/server
< 3.39.25
NPM: Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
4.9
30 minutes ago
@budibase/server
<= 3.38.1
NPM: Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
4.3
32 minutes ago
@budibase/server
<= 3.38.1
NPM: Budibase: Privilege escalation via public role assignment API missing app-level authorization
8.8
32 minutes ago
react-server-dom-webpack
>= 19.0.0, < 19.0.8
NPM: react-server-dom: Denial of Service in Server Functions
7.5
33 minutes ago
react-server-dom-turbopack
>= 19.0.0, < 19.0.8
NPM: react-server-dom: Denial of Service in Server Functions
7.5
33 minutes ago
react-server-dom-parcel
>= 19.1.0, < 19.1.9
NPM: react-server-dom: Denial of Service in Server Functions
7.5
33 minutes ago
@anthropic-ai/claude-code
>= 2.1.38, < 2.1.163
NPM: Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
7.7
4 hours ago
js-yaml
>= 5.0.0, <= 5.2.1
NPM: js-yaml: Exponential parsing time in flow collections leads to denial of service
7.5
4 hours ago
react-router
>= 7.12.0, < 8.3.0
NPM: React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
7.1
5 hours ago
Load more