Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,738
Mitigations
Mitigation rules
16,015
No official patch
13,112
In triage
1,264
Published soon
136
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Mobile DJ Manager
<= 1.7.8.4
Authenticated (Subscriber+) Privilege Escalation vulnerability
8.8
11 minutes ago
GoDAM
<= 1.12.2
Unauthenticated Arbitrary File Upload vulnerability
10
17 minutes ago
WP Ticket Customer Service Software & Support Ticket System
<= 6.0.5
Unauthenticated Code Injection vulnerability
10
28 minutes ago
FoodBakery
<= 4.9
Authenticated (Subscriber+) Arbitrary File Deletion vulnerability
7.7
33 minutes ago
react-router
>= 6.0.0, < 7.18.0
NPM: React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
5.1
11 hours ago
react-router
>= 7.9.6, <= 7.12.0
NPM: React Router: Open redirect leading to XSS
6.9
11 hours ago
react-router-dom
>= 6.30.2, <= 6.30.4
NPM: React Router: Open redirect leading to XSS
6.9
11 hours ago
react-router
>= 7.11.0, < 7.18.0
NPM: React Router: RSCErrorHandler Missing Protocol Validation (XSS)
6.9
11 hours ago
react-router
>= 6.4.0, < 7.18.0
NPM: React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
6.1
11 hours ago
find-my-way
<= 9.6.0
NPM: find-my-way: DDoS with HTTP2
7.5
11 hours ago
postcss
<= 8.5.11
NPM: PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
7.5
15 hours ago
next-auth
>= 5.0.0-beta.0, <= 5.0.0-beta.31
NPM: Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
9.1
15 hours ago
next-auth
>= 4.0.6, <= 4.24.14
NPM: Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
7.5
15 hours ago
@auth/core
>= 0.1.0, < 0.41.3
NPM: Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
7.5
15 hours ago
next-auth
>= 4.10.3, < 4.24.15
NPM: Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
9.1
15 hours ago
@auth/core
>= 0.1.0, < 0.41.3
NPM: Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
9.1
15 hours ago
next-auth
<= 4.24.14
NPM: Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
6.8
16 hours ago
@auth/core
<= 0.41.2
NPM: Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
6.8
16 hours ago
n8n
< 1.123.67
NPM: n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
5.3
1 day ago
n8n
< 1.123.67
NPM: n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
5.8
1 day ago
Load more