Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,760
Mitigations
Mitigation rules
16,024
No official patch
13,107
In triage
1,241
Published soon
69
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
tar
<= 7.5.20
NPM: node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
5.3
9 minutes ago
postcss
<= 8.5.17
NPM: PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
7.5
10 minutes ago
@prompty/core
<= 0.1.4
NPM: Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
10
11 minutes ago
mongoose
< 6.13.10
NPM: Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
6.5
12 minutes ago
velocityjs
<= 2.1.6
NPM: Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
9.8
14 minutes ago
@backstage/plugin-auth-backend
<= 0.29.1
NPM: @backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
4.7
14 minutes ago
trix
< 2.1.18
NPM: Trix: Stored XSS via HTMLParser attribute injection on paste
4.6
17 minutes ago
valibot
<= 1.4.1
NPM: Valibot: record() issue paths can make flatten() throw for inherited Object property names
6.9
20 minutes ago
seroval
<= 1.5.2
NPM: seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
9.8
21 minutes ago
@sveltejs/kit
<= 2.69.0
NPM: SvelteKit: Prototype pollution in file input deletion path in remote-function forms
4.3
37 minutes ago
@sveltejs/kit
<= 2.69.0
NPM: SvelteKit: Big remote form function payloads can cause Node process to crash
5.3
44 minutes ago
better-auth
>= 1.1.3, < 1.6.22
NPM: Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
8.3
51 minutes ago
@better-auth/stripe
>= 1.4.11, < 1.6.21
NPM: @better-auth/stripe: cross-organization billing tampering in organization subscription actions
7.1
52 minutes ago
@better-auth/scim
>= 1.4.0-beta.27, <= 1.6.21
NPM: @better-auth/scim: account takeover and stale access via SCIM provider-id collision
9.9
54 minutes ago
react-router
>= 7.0.0, < 7.18.0
NPM: React Router: Unauthenticated Denial of Service via Inefficient Route Matching
8.7
2 hours ago
liquidjs
<= 10.27.0
NPM: LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
8.2
2 hours ago
builder-util-runtime
< 9.7.0
NPM: electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
8.2
2 hours ago
app-builder-lib
< 26.15.0
NPM: electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`
7.8
2 hours ago
ARForms
<= 7.2.1
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
9 hours ago
SUMO Reward Points
<= 32.7.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
9 hours ago
Load more