Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,782
Mitigations
Mitigation rules
16,024
No official patch
13,112
In triage
1,241
Published soon
63
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@budibase/server
<= 3.38.1
NPM: Budibase: SQL Injection via `multipleStatements: true`
9.6
10 minutes ago
@budibase/server
<= 3.38.1
NPM: Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
0
10 minutes ago
@budibase/server
< 3.39.25
NPM: Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
4.9
10 minutes ago
@budibase/server
<= 3.38.1
NPM: Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
4.3
12 minutes ago
@budibase/server
<= 3.38.1
NPM: Budibase: Privilege escalation via public role assignment API missing app-level authorization
8.8
12 minutes ago
react-server-dom-webpack
>= 19.0.0, < 19.0.8
NPM: react-server-dom: Denial of Service in Server Functions
7.5
13 minutes ago
react-server-dom-turbopack
>= 19.0.0, < 19.0.8
NPM: react-server-dom: Denial of Service in Server Functions
7.5
13 minutes ago
react-server-dom-parcel
>= 19.1.0, < 19.1.9
NPM: react-server-dom: Denial of Service in Server Functions
7.5
13 minutes ago
@anthropic-ai/claude-code
>= 2.1.38, < 2.1.163
NPM: Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
7.7
4 hours ago
js-yaml
>= 5.0.0, <= 5.2.1
NPM: js-yaml: Exponential parsing time in flow collections leads to denial of service
7.5
4 hours ago
react-router
>= 7.12.0, < 8.3.0
NPM: React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
7.1
4 hours ago
aws-cdk-lib
< 2.253.0
NPM: AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
4 hours ago
@aws-cdk/aws-codebuild
>= 1.75.0, <= 1.204.0
NPM: AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
4 hours ago
@fastify/static
<= 10.1.1
NPM: @fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
5.3
4 hours ago
@fastify/static
<= 10.1.0
NPM: @fastify/static vulnerable to route guard bypass via path traversal
7.5
4 hours ago
tar
<= 7.5.20
NPM: node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
5.3
4 hours ago
postcss
<= 8.5.17
NPM: PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
7.5
5 hours ago
@prompty/core
<= 0.1.4
NPM: Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
10
5 hours ago
mongoose
< 6.13.10
NPM: Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
6.5
5 hours ago
velocityjs
<= 2.1.6
NPM: Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
9.8
5 hours ago
Load more