The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,157
Mitigations16,140
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
@nocobase/plugin-notification-in-app-message<= 2.0.60
NPM: NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
10
1 hour ago
jodit< 4.13.6
NPM: Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization
5.3
1 hour ago
jodit< 4.12.28
NPM: Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
7.2
2 hours ago
jodit< 4.12.18
NPM: Jodit has prototype pollution via Jodit.configure() / ConfigMerge
6.3
2 hours ago
jodit<= 4.12.30
NPM: Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS
5.4
2 hours ago
@phun-ky/defaults-deep< 2.0.5
NPM: @phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging
7.3
3 hours ago
hashi-vault-js<= 0.5.1
NPM: hashi-vault-js has a path traversal and query parameter injection
8.7
4 hours ago
dssrf<= 1.0.4
NPM: dssrf: any users using 1.1.1.1 DNS is impacted by SSRF
8.7
4 hours ago
re2<= 1.25.1
NPM: re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS)
5.7
4 hours ago
re2<= 1.25.1
NPM: re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS)
6.2
4 hours ago
nx>= 17.0.4, < 22.7.2
NPM: `nx graph` dev server permissive CORS policy
5.9
4 hours ago
@dynatrace-oss/dynatrace-mcp-server<= 1.8.7
NPM: `@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation
7.5
5 hours ago
@dynatrace-oss/dynatrace-mcp-server< 2.0.0
NPM: @dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification
4.2
5 hours ago
@dynatrace-oss/dynatrace-mcp-server< 2.1.1
NPM: @dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL
4.3
5 hours ago
Simply Poll <= 1.4.1
Unauthenticated SQL Injection vulnerability
9.3
11 hours ago
UsersWP< 1.2.67
Two-Factor Authentication Bypass vulnerability
7.1
11 hours ago
Meta Box AIO<= 3.8.0
Missing Authorization to Unauthenticated Arbitrary Post Deletion vulnerability
9.1
12 hours ago
WP Fast Total Search<= 1.80.280
Unauthenticated SQL Injection vulnerability
9.3
12 hours ago
Plugin Organizer<= 10.2.4
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
12 hours ago
Fluent Forms Pro Add On Pack<= 6.2.6
Authenticated (Subscriber+) PHP Object Injection to Arbitrary User Password Change vulnerability
8.8
12 hours ago