The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total51,481
Mitigations16,832
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
sanitize-html>= 1.9.0, <= 2.17.6
NPM: ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass
5.4
1 hour ago
nanoid< 3.3.12
NPM: nanoid: Integer Overflow or Wraparound
7.4
3 hours ago
pnpm>= 10.7.0, < 10.34.5
NPM: pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml
7.4
3 hours ago
pnpm>= 12.0.0-alpha.0, < 12.0.0-alpha.5
NPM: pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project
7.1
4 hours ago
@appium/base-driver<= 10.6.0
NPM: Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes
6.5
4 hours ago
Divi<= 4.27.5
Authenticated (Contributor+) Stored Cross-Site Scripting via Contact Form 'redirect_url' Shortcode Parameter vulnerability
6.5
5 hours ago
SigmaForms Pro – AI Generated Forms<= 1.4.11
Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field vulnerability
8.6
6 hours ago
DevKit Pro<= 2.3.0
Authenticated (Subscriber+) Arbitrary Theme Installation / Remote Code Execution via 'qqfile' Parameter vulnerability
8.8
6 hours ago
browserslist<= 4.28.6
NPM: Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM
7.5
6 hours ago
browserslist<= 4.28.6
NPM: Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)
7.5
6 hours ago
mysql2< 3.22.0
NPM: MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials
8.2
6 hours ago
Amelia8.0-9.6.2
WordPress Booking for Appointments and Events Calendar - Amelia (Premium) plugin 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId' vulnerability
9.8
6 hours ago
Divi<= 4.27.6
Authenticated (Contributor+) Stored Cross-Site Scripting via Dynamic Content (Legacy JSON Format) Shortcode vulnerability
6.5
8 hours ago
WP File Download<= 6.3.4
Authenticated (Subscriber+) Arbitrary File Deletion via 'remoteurl' Parameter vulnerability
7.7
8 hours ago
Gravity Forms<= 3.0.2
Unauthenticated Arbitrary File Upload via State/Chunk Hash Confusion vulnerability
9
16 hours ago
WPBakery Page Builder<= 8.7.4
Authenticated (Subscriber+) Stored Cross-Site Scripting via 'data' Parameter vulnerability
6.5
16 hours ago
Welcart e-Commerce<= 2.12.1
Unauthenticated Stored Cross-Site Scripting via 'custom_order' Parameter vulnerability
7.1
16 hours ago
Nokri<= 1.6.6
WordPress Nokri - Job Board WordPress Theme plugin <= 1.6.6 - Unauthenticated Privilege Escalation via 'token' Parameter vulnerability
9.8
16 hours ago
Simple Membership<= 4.8.1
Unauthenticated Authentication Bypass to Administrator Account Takeover via Multisite Identity Binding vulnerability
9.8
16 hours ago
FS Poster<= 8.0.1
Authenticated (Subscriber+) Remote Code Execution via FFmpeg Path Setting vulnerability
8.8
16 hours ago