The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total51,574
Mitigations16,860
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
@tiptap/core>= 2.0.0-alpha.0, < 3.30.4
NPM: Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes
6.4
25 minutes ago
pnpm< 10.34.5
NPM: pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph
7.1
33 minutes ago
pnpm< 10.34.5
NPM: pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install
7.5
33 minutes ago
@humanfs/node< 0.16.8
NPM: humanfs: Recursive copy follows symlinked files and copies data from outside the source tree
5.7
43 minutes ago
@faker-js/faker<= 10.4.0
NPM: Faker: helpers.fake exploitable into arbritary code execution
7.8
50 minutes ago
Classified Listing<= 6.1.1
Broken Access Control vulnerability
5.4
3 hours ago
Rentsyst<= 2.1.2
Broken Access Control vulnerability
5.3
3 hours ago
Grand Tour<= 5.5.1
Cross Site Request Forgery (CSRF) vulnerability
5.4
3 hours ago
Gallery PhotoBlocks<= 1.3.4
Cross Site Scripting (XSS) vulnerability
6.5
4 hours ago
WP Go Maps<= 10.1.08
Denial of Service Attack vulnerability
5.3
4 hours ago
Really Simple SSL<= 9.8.0
Denial of Service Attack vulnerability
5.3
4 hours ago
Broken Link Checker<= 2.4.14
Server Side Request Forgery (SSRF) vulnerability
5.5
4 hours ago
Mang Board WP<= 2.3.8
Cross Site Request Forgery (CSRF) vulnerability
8.8
4 hours ago
PublishPress Permissions<= 4.8.3
Insecure Direct Object References (IDOR) vulnerability
5.3
4 hours ago
Simply Schedule Appointments<= 1.6.12.23
Cross Site Request Forgery (CSRF) vulnerability
8.8
5 hours ago
Ultimate Gift Cards For WooCommerce<= 3.2.9
Broken Access Control vulnerability
5.3
5 hours ago
Activity Log<= 2.13.1
Cross Site Request Forgery (CSRF) vulnerability
7.1
5 hours ago
Broken Link Checker<= 2.4.13
Unauthenticated Stored Cross-Site Scripting vulnerability
7.1
7 hours ago
FluentCart<= 1.6.2
Authenticated (Custom+) Arbitrary File Deletion vulnerability
7.7
8 hours ago
WP Project Manager Pro<= 4.0.1
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
8 hours ago