The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,939
Mitigations17,308
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
HT Contact Form 7<= 2.10.2
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
1 hour ago
ConvertPlus<= 3.6.3
Authenticated (Subscriber+) PHP Object Injection vulnerability
8.8
2 hours ago
nodemailer>= 5.0.0, < 10.0.2
NPM: Nodemailer: Process-global DNS cache reuses TLS `servername` across transports, enabling cross-tenant SMTP credential disclosure
5.9
11 hours ago
undici>= 6.25.0, < 6.28.1
NPM: undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression
5.9
11 hours ago
multer>= 2.2.0, < 2.4.0
NPM: multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads
5.3
11 hours ago
morgan< 1.12.1
NPM: morgan vulnerable to Log Injection via unescaped double quote in quoted log fields
5.3
11 hours ago
@angular/platform-server<= 19.2.25
NPM: Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE
8.7
11 hours ago
fast-uri< 2.4.6
NPM: fast-uri vulnerable to authority injection via an unvalidated port in serialize
7.5
11 hours ago
fast-uri2.4.5
NPM: fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority
7.5
11 hours ago
ip-address<= 10.5.0
NPM: ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts
6.3
12 hours ago
ip-address>= 10.2.0, <= 10.5.0
NPM: ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass
6.9
12 hours ago
@angular/platform-server<= 19.2.25
NPM: Angular SSR: XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Content Elements
8.6
12 hours ago
@grpc/grpc-js-xds< 1.13.1
NPM: @grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches
6.5
13 hours ago
scim-patch< 0.9.2
NPM: scim-patch: Mutation of Inherited Built-in Method Objects
4.3
19 hours ago
code-ollama<= 0.36.0
NPM: code-ollama: `grep_search` Command Injection via Unescaped `$()` Shell Substitution (CWE-78)
7.8
19 hours ago
WP Review Slider Pro< 12.7.12
Subscriber+ Stored XSS vulnerability
6.5
19 hours ago
File Manager7.2.2-8.0.4
Unauthenticated Database Backup Disclosure vulnerability
5.9
19 hours ago
Verge3D4.1.0-4.13.0
Unauthenticated Payment Bypass vulnerability
5.3
19 hours ago
Best Payments Plugin for WP4.6.20-4.6.25
Unauthenticated Payment Bypass vulnerability
5.3
19 hours ago
Blacklist Manager &#8211; WooCommerce Anti-Fraud, Blacklist &amp; Checkout Verification1.3.0-2.3.1
Blocked User Restriction Bypass vulnerability
5.4
19 hours ago