Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,515
Mitigations
Mitigation rules
15,981
No official patch
13,046
In triage
1,396
Published soon
16
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
fast-uri
>= 2.3.1, <= 2.4.2
NPM: fast-uri vulnerable to host confusion via literal backslash authority delimiter
7.5
1 hour ago
sharp
< 0.35.0
NPM: sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
7
1 hour ago
fast-xml-parser
>= 5.9.3, < 5.10.1
NPM: fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
8.7
1 hour ago
@hono/node-server
>= 2.0.0, <= 2.0.9
NPM: Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
5.3
1 hour ago
typeorm
< 0.3.31
NPM: TypeORM: migration:generate template-literal code injection
5.7
1 hour ago
svgo
>= 1.0.0, < 2.8.3
NPM: SVGO removeScripts plugin leaves some executable scripts intact
8.2
3 hours ago
dompurify
<= 3.4.11
NPM: DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
2.1
3 hours ago
@vitest/browser
< 3.2.7
NPM: @vitest/browser: Browser Mode provider commands bypass the file-access permission gate
9.4
3 hours ago
@sigstore/oci
< 0.7.1
NPM: Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
9.6
3 hours ago
@opentelemetry/propagator-jaeger
< 2.9.0
NPM: OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
7.5
4 hours ago
linkify-it
<= 5.0.1
NPM: linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
7.5
4 hours ago
aws-cdk-lib
< 2.260.0
NPM: aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling
7.3
4 hours ago
fast-uri
>= 2.3.1, < 2.4.2
NPM: fast-uri vulnerable to host confusion via failed IDN canonicalization
7.5
4 hours ago
immutable
< 4.3.9
NPM: Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
8.7
4 hours ago
immutable
< 4.3.9
NPM: Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
7.5
4 hours ago
hono
>= 4.11.8, < 4.12.27
NPM: hono/jsx does not isolate context per request, leading to cross-request data disclosure
6.5
4 hours ago
hono
>= 4.0.0, < 4.12.27
NPM: Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
6.1
4 hours ago
hono
>= 4.3.3, < 4.12.27
NPM: Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
4.8
5 hours ago
@hono/node-server
< 2.0.5
NPM: Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
5.9
5 hours ago
Easy Form Builder
<= 4.0.11
Unauthenticated Privilege Escalation to Administrator vulnerability
9.8
16 hours ago
Load more