Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,262
Mitigations
Mitigation rules
16,235
No official patch
13,231
In triage
1,095
Published soon
16
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
crypto-js
< 4.0.0
NPM: crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
9
1 day ago
hono
>= 3.8.0, < 4.12.34
NPM: Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure
4.8
1 day ago
hono
>= 4.7.0, < 4.12.34
NPM: Hono: Proxy Helper does not remove response headers listed in the `Connection` header
3.7
1 day ago
hono
>= 4.12.0, < 4.12.34
NPM: Hono: Algorithmic Complexity DoS in Language Middleware
5.3
1 day ago
jsii-diff
< 1.131.0
NPM: jsii-diff: Command Injection via npm: package argument
7.8
1 day ago
@sveltejs/kit
<= 2.70.1
NPM: SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
5.3
1 day ago
nuxt
>= 3.21.7, < 3.21.10
NPM: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
5.3
1 day ago
dompurify
<= 3.4.12
NPM: DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
5.1
1 day ago
WPJAM Basic
<= 7.0.2.1
Sensitive Data Exposure vulnerability
7.5
2 days ago
Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK)
<= 1.0.7
Broken Access Control vulnerability
7.5
2 days ago
Visitor Traffic Real Time Statistics Pro
<= 11.10
SQL Injection vulnerability
8.5
2 days ago
Visitor Traffic Real Time Statistics Pro
<= 11.10
Cross Site Scripting (XSS) vulnerability
7.1
2 days ago
WP-Stats
<= 2.56
Cross Site Scripting (XSS) vulnerability
7.1
2 days ago
Car Rental Manager
<= 1.3.7
Broken Access Control vulnerability
5.3
2 days ago
WordPress
< 7.0.3
SSRF vulnerability
5.4
2 days ago
WordPress
< 7.0.3
CSS Injection vulnerability
5.9
2 days ago
WordPress
< 7.0.3
Sensitive Data Exposure vulnerability
5.3
2 days ago
WordPress
< 7.0.3
Sensitive Data Exposure vulnerability
5.3
2 days ago
WordPress
< 7.0.3
Stored XSS vulnerabiliity
6.5
2 days ago
WordPress
7.0-7.0.2
Unauthenticated Sensitive Data Exposure vulnerability
5.3
2 days ago
Load more