The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,290
Mitigations16,213
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
ghost>= 1.20.1, < 6.54.1
NPM: Ghost: Database Backup Path Traversal
5.5
7 minutes ago
ghost>= 0.10.0, < 6.54.1
NPM: Ghost: Server-Side Request Forgery in Image Fetching
4.1
10 minutes ago
ghost< 6.54.1
NPM: Ghost: Blind Password Hash Disclosure in Ghost Admin API
4.8
20 minutes ago
ghost>= 6.19.4, < 6.21.1
NPM: Ghost: Mobiledoc image-size fetch SSRF
5.4
23 minutes ago
ghost>= 6.0.9, < 6.21.1
NPM: Ghost: Server-side request forgery via DNS rebinding in external request handling
4
24 minutes ago
ghost>= 6.0.9, <= 6.21.0
NPM: Ghost: Private IP filtering bypass to make server-side requests to internal services
5.8
35 minutes ago
ghost>= 4.22.0, < 6.54.1
NPM: Ghost: Archived Offers can be Redeemed
4.8
37 minutes ago
ghost>= 6.19.4, < 6.21.1
NPM: Ghost: File Upload Content-Type Spoofing
5.4
43 minutes ago
ghost>= 5.26.0, < 6.54.1
NPM: Ghost: Cross-Site Scripting in Universal Import
5
45 minutes ago
flowise<= 3.1.2
NPM: Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service
9.2
2 hours ago
flowise<= 3.1.2
NPM: Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
9.5
2 hours ago
flowise-components<= 3.1.2
NPM: Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
9.5
2 hours ago
flowise<= 3.1.2
NPM: Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
8.3
2 hours ago
flowise<= 3.1.3
NPM: Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
6.3
2 hours ago
flowise<= 3.1.2
NPM: Flowise: Missing Authorization on Execution Update Endpoint
7.1
2 hours ago
flowise<= 3.1.2
NPM: Flowise: Cross-Workspace OAuth2 Credential Metadata Leak
7.6
3 hours ago
flowise<= 3.1.2
NPM: Flowise: Incomplete Credential Redaction Exposes Secrets via API
6.5
3 hours ago
flowise<= 3.1.2
NPM: Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
8.3
3 hours ago
flowise<= 3.1.2
NPM: Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
7.1
3 hours ago
flowise<= 3.1.2
NPM: Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
9.4
4 hours ago