The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total53,776
Mitigations17,719
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
WordPress<= 7.1.2
Contributor+ DoS via infinite loop in WP_Http::make_absolute_url() vulnerability
4.3
9 minutes ago
WordPress<= 7.1.2
Sensitive Data Exposure vulnerability
6.9
19 minutes ago
Kirki<= 6.3.1
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
38 minutes ago
payload< 3.90.0
NPM: Payload didn't enforce field-level password update restrictions
7.6
1 hour ago
payload>= 3.0.0, < 3.90.0
NPM: Payload: ReDoS in Multipart Content-Type Validation
8.7
1 hour ago
payload>= 3.0.0, < 3.90.0
NPM: Payload vulnerable to API key disclosure through ordinary document reads
7.7
1 hour ago
@payloadcms/plugin-ecommerce< 3.90.0
NPM: Payload Ecommerce has an order confirmation validation issue
8.8
1 hour ago
payload< 3.90.0
NPM: Payload relationship-query authorization bypass
6.9
1 hour ago
payload>= 3.0.0, < 3.90.0
NPM: Payload: Token refresh and password reset responses may expose restricted user fields
7.1
1 hour ago
payload> 3.0.0, < 3.90.0
NPM: Payload: Field access control bypass on auth collections
9.3
1 hour ago
@payloadcms/plugin-stripe< 3.90.0
NPM: Payload: Insufficient Access Control in Stripe REST Proxy
6.4
1 hour ago
@payloadcms/plugin-mcp>= 3.61.0, < 3.88.0
NPM: Payload: Improper access control for MCP API keys
8.6
1 hour ago
@payloadcms/plugin-import-export>= 3.0.0, < 3.88.0
NPM: Payload: Prototype pollution in Payload Import Export plugin
9.3
1 hour ago
payload>= 3.0.0, < 3.88.0
NPM: Payload: SQL Injection in SQLite and Postgres
9.8
1 hour ago
@payloadcms/next>= 3.31.0, < 3.88.0
NPM: Payload: Untrusted redirect URL parameter exploit
6.1
1 hour ago
payload>= 3.40.0, < 3.88.0
NPM: Payload: Untrusted redirect URL parameter exploit
6.1
1 hour ago
payload>= 3.0.0, < 3.90.0
NPM: Payload: Polymorphic join queries could disclose hidden fields
7.1
1 hour ago
payload>= 3.0.0, < 3.90.0
NPM: Payload: Password hashes use insufficient PBKDF2 iterations
5.7
2 hours ago
payload< 3.88.0
NPM: Payload: Sort queries could expose protected field information
6.9
2 hours ago
@modelcontextprotocol/client>= 2.0.0, < 2.2.0
NPM: MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server
7.5
2 hours ago