The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,548
Mitigations16,395
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Admin Custom Login<= 3.6.4
Authenticated (Administrator+) Stored Cross-Site Scripting via 'Message Above Login Form' Setting vulnerability
5.9
27 minutes ago
ECS – Ele Custom Skin for Elementor< 4.3.8
Contributor+ Arbitrary Post Binding and Global Preset Modification via Dynamic Repeater Handlers vulnerability
3.8
28 minutes ago
Backup Migration< 2.1.7
Admin+ Privilege Escalation via Post-Restore Auto-Login vulnerability
7.2
29 minutes ago
Product Feed PRO for WooCommerce< 13.5.7
Unauthenticated Feed Configuration Disclosure vulnerability
5.3
30 minutes ago
ECS – Ele Custom Skin for Elementor< 4.3.8
Contributor+ Stored XSS via Dynamic Repeater Bindings vulnerability
6.5
31 minutes ago
Simply Schedule Appointments< 1.6.12.17
Team Member+ User Email Disclosure via Users and Customers REST Endpoints vulnerability
2.7
31 minutes ago
ECS – Ele Custom Skin for Elementor< 4.3.8
Unauthenticated Private Content Disclosure via ecsload vulnerability
5.3
32 minutes ago
Multilingual CMS<= 4.9.5
Authenticated (Translator+) SQL Injection via 'sorting' Parameter vulnerability
8.5
36 minutes ago
Link Library<= 7.9.4
Unauthenticated Arbitrary File Deletion via link_url Parameter vulnerability
8.6
36 minutes ago
Templately<= 3.7.1
Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Import Attachment Filename Mismatch vulnerability
8.8
41 minutes ago
Real Estate Manager Pro<= 12.8.6
Authenticated (Subscriber+) Privilege Escalation via 'user_has_cap' Filter ID Collision vulnerability
8.8
49 minutes ago
mlflow< 3.15.0
NPM: MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id
7.1
10 hours ago
mlflow< 3.15.0
NPM: MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
6.5
10 hours ago
9router<= 0.5.4
NPM: 9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint
8.6
10 hours ago
chrome-devtools-mcp>= 0.24.0, <= 1.0.1
NPM: chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots
6.1
10 hours ago
Forminator<= 1.56.1
Unauth. Arbitrary File Upload
9.8
13 hours ago
ep_etherpad-lite<= 1.8.14
NPM: Etherpad has stored XSS in HTML export via unescaped attribute-pool values
8.7
14 hours ago
ep_etherpad-lite<= 1.8.14
NPM: Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling
0
14 hours ago
vm2<= 3.11.5
NPM: vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass
7.5
14 hours ago
vm2<= 3.11.5
NPM: vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
10
14 hours ago