Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,915
Mitigations
Mitigation rules
16,087
No official patch
13,136
In triage
1,162
Published soon
32
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@dynatrace-oss/dynatrace-mcp-server
< 1.8.7
NPM: @dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
3.7
39 minutes ago
swagger-typescript-api
<= 13.12.1
NPM: swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
8.3
1 hour ago
swagger-typescript-api
<= 13.12.1
NPM: swagger-typescript-api vulnerable to code injection via unescaped enum string values
8.3
1 hour ago
swagger-typescript-api
<= 13.12.1
NPM: swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
8.3
1 hour ago
swagger-typescript-api
<= 13.12.1
NPM: swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
6.1
1 hour ago
swagger-typescript-api
<= 13.12.1
NPM: swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
8.3
1 hour ago
swagger-typescript-api
<= 13.12.1
NPM: swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
7.4
1 hour ago
WP Compress
< 7.10.04
Reflected XSS vulnerability
7.1
4 hours ago
Sina Extension for Elementor
< 3.10.2
Reflected XSS vulnerability
7.1
4 hours ago
MPG
< 4.1.8
Reflected XSS vulnerability
7.1
4 hours ago
Simply Schedule Appointments
< 1.6.12.4
Unauthenticated Stored XSS vulnerability
7.1
4 hours ago
WowOptin
< 1.4.38
Unauthenticated Opt-in Deactivation and Template Row Injection vulnerability
7.5
4 hours ago
Software Issue Manager
< 5.1.0
Unauthenticated SQL Injection vulnerability
9.3
4 hours ago
Document Gallery
< 5.1.1
Reflected XSS vulnerability
7.1
5 hours ago
Praison SEO WordPress
< 5.0.7
Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure) vulnerability
7.5
5 hours ago
CAFEHAUS API
<= 1.0.0
Unauthenticated Arbitrary User Password Reset vulnerability
9.8
5 hours ago
ProfileGrid
< 5.9.9.7
Unauthenticated Payment Bypass and Forced Group Membership vulnerability
6.5
5 hours ago
WooCommerce Clover Payment Gateway
< 1.3.6
Unauthenticated Payment Bypass vulnerability
7.5
5 hours ago
ProfilePress
< 4.16.18
Unauthenticated Privilege Escalation vulnerability
9.8
5 hours ago
Masteriyo - LMS
< 2.3.1
Unauthenticated Arbitrary User Session Termination (Denial of Service) vulnerability
9.1
5 hours ago
Load more