Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
54,131
Mitigations
Mitigation rules
17,856
No official patch
13,578
In triage
991
Published soon
133
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
handlebars
>= 4.0.0, <= 4.7.9
NPM: Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates
4.7
45 minutes ago
handlebars
>= 4.0.0, <= 4.7.9
NPM: Handlebars: JavaScript Injection via AST Type Confusion in compile (bypass of CVE-2026-33937)
9.8
45 minutes ago
handlebars
>= 4.0.0, <= 4.7.9
NPM: Handlebars: JavaScript Injection via Own Property Check Bypass
9.2
45 minutes ago
@langchain/mongodb
<= 1.3.0
NPM: LangChain: MongoDBChatMessageHistory query injection can allow cross-session access
6
45 minutes ago
generator-jhipster
>= 7.0.0, < 9.4.0
NPM: JHipster: SQL Injection in the Parameter of JHipster-Generated Reactive (WebFlux + R2DBC) Applicationssort
8.8
57 minutes ago
react-jhipster
<= 1.0.3
NPM: JHipster: Generated Applications Allow Stored XSS via Unrestricted Blob ContentType Opened as Same-Origin Blob
7.6
57 minutes ago
generator-jhipster
< 9.4.0
NPM: JHipster: Generated Applications Allow Stored XSS via Unrestricted Blob ContentType Opened as Same-Origin Blob
7.6
57 minutes ago
msgpack5
< 6.1.0
NPM: msgpack5: Truncated map32 headers throw an unexpected error
7.5
57 minutes ago
msgpack5
< 6.1.0
NPM: msgpack5: Many buffered values can exhaust the streaming decoder stack
7.5
57 minutes ago
msgpack5
< 6.1.0
NPM: msgpack5: Reserved byte can cause unbounded stream buffering
5.9
57 minutes ago
msgpack5
< 6.1.0
NPM: msgpack5: Partial options disable prototype protection
6.5
57 minutes ago
msgpack5
< 6.1.0
NPM: msgpack5: Deeply nested input can exhaust the decoder stack
5.3
57 minutes ago
msgpack5
< 6.1.0
NPM: msgpack5: Quadratic parsing in the streaming decoder
5.9
58 minutes ago
msgpack5
< 6.1.0
NPM: msgpack5: Decoding negative int64 values mutates the input buffer
3.7
58 minutes ago
Wallet System for WooCommerce
< 2.8.0
Subscriber+ Wallet Balance Manipulation vulnerability
6.5
4 hours ago
Easy Digital Downloads
< 3.7.1
Unauthenticated Account Creation with Registration Disabled vulnerability
5.3
4 hours ago
TutorStarter
< 4.0.4
Unauthenticated User Registration Bypass vulnerability
5.3
4 hours ago
Airwallex Online Payments Gateway
< 1.36.0
Unauthenticated Payment Bypass vulnerability
5.3
4 hours ago
Zotpress
<= 7.4.4
Cross Site Scripting (XSS) vulnerability
6.5
5 hours ago
Tutor LMS
<= 4.1.1
Race Condition vulnerability
5.3
5 hours ago
Load more