The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,781
Mitigations16,529
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
@tinacms/cli< 2.5.2
NPM: Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root
6.5
1 hour ago
next-tinacms-s3< 23.0.4
NPM: Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters)
5.4
1 hour ago
next-tinacms-dos< 23.0.4
NPM: Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters)
5.4
1 hour ago
next-tinacms-azure< 14.0.4
NPM: Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters)
5.4
1 hour ago
next-tinacms-cloudinary< 26.0.4
NPM: Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters)
5.4
1 hour ago
@logto/tunnel<= 0.3.8
NPM: logto-tunnel serves files outside --experience-path via path traversal
8.7
2 hours ago
mcp-searxng< 1.12.0
NPM: SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
5.5
3 hours ago
mcp-searxng< 1.2.1
NPM: SearXNG MCP Server: Additional hardened-mode SSRF bypasses
6.3
3 hours ago
mcp-searxng< 1.2.1
NPM: SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
6.5
3 hours ago
@contentful/mcp-server< 1.7.19
NPM: Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
7.7
3 hours ago
@contentful/mcp-tools< 0.4.5
NPM: Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
7.7
3 hours ago
claude-faf-mcp<= 5.7.1
NPM: claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
7.5
3 hours ago
faf-mcp<= 2.1.2
NPM: faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
7.5
3 hours ago
grok-faf-mcp<= 1.5.2
NPM: grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
7.5
3 hours ago
Elementor Pro<= 4.2.1
Arbitrary File Upload vulnerability
9
5 hours ago
Welcart e-Commerce< 2.11.32
Editor+ SQL Injection via CSV Import vulnerability
8.5
10 hours ago
Brizy< 2.8.19
WordPress Brizy - Page Builder plugin < 2.8.19 - Author+ Stored XSS via brizy_set_project Global Project Code Asset vulnerability
5.9
10 hours ago
Brizy< 2.8.19
WordPress Brizy - Page Builder plugin < 2.8.19 - Contributor+ Stored XSS via Featured Image Focal Point vulnerability
6.5
10 hours ago
Contest Gallery< 30.0.7
Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library vulnerability
2.7
10 hours ago
Classified Listing< 5.4.4
Contributor+ Store Revenue Total Disclosure via rtcl_revenue_order_search vulnerability
4.3
10 hours ago