Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,256
Mitigations
Mitigation rules
16,235
No official patch
13,227
In triage
1,095
Published soon
44
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
crypto-js
< 4.0.0
NPM: crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
9
2 hours ago
hono
>= 3.8.0, < 4.12.34
NPM: Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure
4.8
2 hours ago
hono
>= 4.7.0, < 4.12.34
NPM: Hono: Proxy Helper does not remove response headers listed in the `Connection` header
3.7
2 hours ago
hono
>= 4.12.0, < 4.12.34
NPM: Hono: Algorithmic Complexity DoS in Language Middleware
5.3
2 hours ago
jsii-diff
< 1.131.0
NPM: jsii-diff: Command Injection via npm: package argument
7.8
3 hours ago
@sveltejs/kit
<= 2.70.1
NPM: SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
5.3
4 hours ago
nuxt
>= 3.21.7, < 3.21.10
NPM: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
5.3
4 hours ago
dompurify
<= 3.4.12
NPM: DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
5.1
5 hours ago
WordPress
< 7.0.3
SSRF vulnerability
5.4
18 hours ago
WordPress
< 7.0.3
CSS Injection vulnerability
5.9
18 hours ago
WordPress
< 7.0.3
Sensitive Data Exposure vulnerability
5.3
18 hours ago
WordPress
< 7.0.3
Sensitive Data Exposure vulnerability
5.3
18 hours ago
WordPress
< 7.0.3
Stored XSS vulnerabiliity
6.5
18 hours ago
WordPress
7.0-7.0.2
Unauthenticated Sensitive Data Exposure vulnerability
5.3
22 hours ago
WordPress
< 7.0.3
Multiple Contributor+ Stored XSS vulnerabilities
6.5
23 hours ago
re2
<= 1.26.0
NPM: node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript
5.1
23 hours ago
re2
<= 1.25.0
NPM: node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length
6.2
23 hours ago
ngx-extended-pdf-viewer
>= 27.0.0-rc.0, < 29.0.0-rc.3
NPM: ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633
8.6
1 day ago
pdfjs-dist
>= 5.6.83, < 6.2.108
NPM: PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF
8.6
1 day ago
WordPress
< 7.0.3
Subscriber+ Site Creation vulnerability
7.1
1 day ago
Load more