Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
54,161
Mitigations
Mitigation rules
17,863
No official patch
13,582
In triage
995
Published soon
124
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
Html5 Audio Player
<= 2.8.8
Cross Site Scripting (XSS) vulnerability
6.5
4 minutes ago
Restrict User Access – Membership Plugin with Force
<= 2.8.1
Broken Access Control vulnerability
5.3
7 minutes ago
WP Event Manager
<= 3.4.1
Broken Access Control vulnerability
5.4
7 minutes ago
Scripts n Styles
<= 3.5.8
Broken Access Control vulnerability
5.3
15 minutes ago
AI Translation for Polylang
<= 1.6.2
Broken Access Control vulnerability
5.4
30 minutes ago
JetBlocks For Elementor
<= 1.5.2.1
Cross Site Scripting (XSS) vulnerability
6.5
2 hours ago
Ocean Pro Demos
<= 1.5.4
Unauthenticated Stored Cross-Site Scripting vulnerability
7.2
4 hours ago
Ocean eComm Treasure Box
<= 1.8.0
Unauthenticated Stored Cross-Site Scripting vulnerability
7.2
4 hours ago
Redux Framework
<= 4.5.11
Redux Framework <= 4.5.11 – Authenticated (Subscriber+) Privilege Escalation vulnerability
6.8
4 hours ago
fast-jwt
<= 6.3.3
NPM: fast-jwt: Verifier cache accepts expired JWTs without iat.
4.2
13 hours ago
@adonisjs/http-server
<= 8.2.2
NPM: AdonisJS: Unencoded route parameters can produce open redirects
6.1
13 hours ago
fast-jwt
<= 6.3.0
NPM: fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly set
7.4
13 hours ago
fast-jwt
>= 6.2.0, <= 6.2.4
NPM: fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion
9.8
13 hours ago
fast-jwt
<= 6.2.4
NPM: fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and persists in the verifier cache)
5.9
13 hours ago
fast-jwt
<= 6.2.4
NPM: fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array
8.1
13 hours ago
fast-jwt
6.2.4
NPM: fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery
7.4
13 hours ago
praisonai
< 1.7.3
NPM: PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosure
8.6
13 hours ago
music-metadata
< 11.16.0
NPM: music-metadata: MP4 stsd sample-entry size==0 causes a synchronous infinite loop (DoS) — unreleased regression on master
6.2
16 hours ago
music-metadata
<= 11.12.3
NPM: music-metadata: Uncontrolled memory allocation in APEv2 parser
6.2
16 hours ago
music-metadata
<= 11.12.3
NPM: music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion DoS
6.2
16 hours ago
Load more