The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total52,604
Mitigations17,177
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
MarketKing<= 2.1.70
Broken Access Control vulnerability
5.3
3 minutes ago
The Post Grid<= 7.9.5
Cross Site Scripting (XSS) vulnerability
6.5
32 minutes ago
WPC Product Bundles for WooCommerce<= 8.6.6
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
1 hour ago
Rename wp-login.php to anything you want<= 2.0.1
Unauthenticated SQL Injection vulnerability
7.5
1 hour ago
Ninja Forms3.15.3
Unauthenticated PHP Object Injection vulnerability
7.5
2 hours ago
unleash-server< 8.0.3
NPM: Unleash: Missing await on permission check + cross-project IDOR in admin API
7.1
12 hours ago
unleash-server< 8.0.3
NPM: Unleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit log
4.3
12 hours ago
unleash-server< 8.0.3
NPM: Unleash: Clone-feature lets a user copy a feature from a project they cannot read
5.3
12 hours ago
unleash-server< 8.0.3
NPM: Unleash: CR-approval email renders user-controlled raw HTML
2.1
12 hours ago
@novu/js<= 3.17.0
NPM: Novu: Stored XSS in In-App Inbox via notification redirect.url javascript: scheme
5.1
12 hours ago
mppx< 0.8.2
NPM: mppx: Gas Draining with access list
6.9
12 hours ago
mppx< 0.8.1
NPM: mppx: Gas Draining with padding
6.9
12 hours ago
@deepstream/server10.1.0
NPM: deepstream: PATCH_MULTI action bypasses Valve permission system allowing unauthorized record writes
8.8
13 hours ago
request-filtering-agent< 3.2.1
NPM: request-filtering-agent: Synchronous throw from createConnection() for literal private-IP hosts bypasses req.on('error'), crashing the Node.js process
7.5
13 hours ago
Advanced Contact form 7 DB<= 2.1.1
Missing Authorization to Authenticated (Contributor+) Information Disclosure vulnerability
6.5
15 hours ago
WP User Manager<= 2.9.19
Broken Access Control vulnerability
5.3
16 hours ago
9router<= 0.5.4
NPM: 9Router has a Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header
5.3
16 hours ago
9router<= 0.5.4
NPM: 9Router has an Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header
7.3
16 hours ago
TrustedLogin Connector<= 2.0.3
Sensitive Data Exposure vulnerability
5.3
17 hours ago
@aborruso/ckan-mcp-server<= 0.4.107
NPM: @aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509
5.7
18 hours ago