Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
49,490
Mitigations
Mitigation rules
15,977
No official patch
13,050
In triage
1,419
Published soon
9
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Easy Form Builder
<= 4.0.11
Unauthenticated Privilege Escalation to Administrator vulnerability
9.8
4 hours ago
astro
>= 7.0.0, < 7.0.6
NPM: Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
5.1
11 hours ago
@astrojs/netlify
< 8.1.2
NPM: @astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
3.7
11 hours ago
body-parser
< 1.20.6
NPM: body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
3.7
11 hours ago
@astrojs/node
>= 8.1.0, < 11.0.2
NPM: @astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
2.1
11 hours ago
astro
< 7.0.6
NPM: Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
5.1
11 hours ago
@astrojs/rss
>= 1.0.0, < 4.0.19
NPM: @astrojs/rss: XML Injection via Unescaped RSS Feed Fields
4.3
11 hours ago
astro
>= 3.10.0, < 7.0.4
NPM: Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
2.1
11 hours ago
axios
>= 0.31.1, < 0.33.0
NPM: Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
8.3
12 hours ago
axios
>= 0.31.1, < 0.33.0
NPM: Axios form serializer maxDepth bypass via {} metatoken
6.9
12 hours ago
axios
>= 0.8.0, < 0.33.0
NPM: Axios: Nested axios option objects can consume polluted prototype values
6.3
12 hours ago
axios
>= 1.13.0, < 1.18.0
NPM: Axios: HTTP/2 streamed uploads bypass `maxBodyLength`
6.3
12 hours ago
axios
>= 1.7.0, < 1.18.0
NPM: Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
6.3
12 hours ago
axios
< 0.33.0
NPM: Axios: Prototype pollution gadgets can alter axios request construction
6.3
12 hours ago
axios
>= 0.31.0, < 0.33.0
NPM: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
6.9
12 hours ago
protobufjs
>= 8.2.0, <= 8.6.4
NPM: protobufjs: Text Format string map parsing can mutate returned map object prototype
4.8
12 hours ago
protobufjs
>= 7.5.0, <= 7.6.4
NPM: protobufjs: Denial of Service via infinite loop in .proto option parsing
5.3
12 hours ago
webpack-dev-server
<= 5.2.5
NPM: webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
5.3
12 hours ago
webpack-dev-server
<= 5.2.5
NPM: webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
4.7
12 hours ago
astro
>= 6.4.7, < 6.4.8
NPM: Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
8.2
12 hours ago
Load more