The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,334
Mitigations17,067
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
WP Events Manager< 2.2.5
Unauthenticated Payment Bypass and Booking Status Update via IDOR vulnerability
5.3
17 minutes ago
Five Star Restaurant Reservations< 2.7.23
Unauthenticated Payment Bypass and Booking Confirmation via IDOR vulnerability
5.3
17 minutes ago
Ninja Forms< 3.14.10
Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default vulnerability
5.3
19 minutes ago
miniOrange's Google Authenticator< 6.2.7
2FA Bypass via Password-Only Second-Factor Rebinding vulnerability
4.3
20 minutes ago
Contest Gallery< 30.0.7
Unauthenticated Login-Protection and 2FA Bypass via post_cg_login vulnerability
4.8
21 minutes ago
Event Booking Manager for WooCommerce (Pro)<= 5.0.2
Unauthenticated Price Manipulation vulnerability
5.3
22 minutes ago
Newsletters< 4.16
Unauthenticated API Authentication Bypass via Type Juggling vulnerability
4.8
23 minutes ago
Easy Booking – WooCommerce Booking &amp; Reservation Plugin< 3.5.0
Unauthenticated Minimum Booking Duration Bypass vulnerability
5.3
25 minutes ago
WordPress File Upload< 5.1.7
File Overwrite via Race Condition vulnerability
5.4
26 minutes ago
Contact Form by WPForms< 1.10.0.5
Unauthenticated PayPal Webhook Forgery vulnerability
5.3
27 minutes ago
@tinacms/auth<= 1.1.3
NPM: Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site
8.8
41 minutes ago
next-tinacms-azure<= 15.0.0
NPM: Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site
8.8
41 minutes ago
@redocly/cli< 1.34.17
NPM: Redocly CLI: Path traversal when using `split` command
4.4
41 minutes ago
@orpc/server<= 1.14.7
NPM: oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass
6.3
47 minutes ago
@cyclonedx/cyclonedx-npm< 6.0.0
NPM: @cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windows
8.5
49 minutes ago
@vendure/core< 3.7.0
NPM: Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification
9.1
50 minutes ago
@vendure/core>= 1.0.0, < 3.6.5
NPM: Vendure: Shop API list queries can return non-public entities when filterOperator is OR
5.3
50 minutes ago
vendure/core<= 3.6.4
NPM: Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends
7.5
50 minutes ago
@vendure/dashboard< 3.6.5
NPM: Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions
8.7
50 minutes ago
nuxt-og-image>= 6.0.2, < 6.7.0
NPM: Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter
6.9
51 minutes ago