The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,968
Mitigations16,613
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Fluent Support Pro<= 2.3.1
Broken Access Control vulnerability
5.4
9 minutes ago
FluentCRM Pro<= 3.1.12
SQL Injection vulnerability
7.6
10 minutes ago
Shared Files<= 1.7.69
Server Side Request Forgery (SSRF) vulnerability
6.4
11 minutes ago
Booking and Rental Manager<= 2.7.5
Broken Access Control vulnerability
5.3
19 minutes ago
Templately< 3.7.1
Unauthenticated Administrator Templately Cloud Connection Overwrite vulnerability
6.5
2 hours ago
Kirki< 6.2.1
Unauthenticated Arbitrary Shortcode Execution via Form Email Actions vulnerability
6.5
2 hours ago
TeraWallet – For WooCommerce< 1.6.10
WordPress TeraWallet - Wallet for WooCommerce plugin < 1.6.10 - Subscriber+ Wallet Balance Inflation via Discounted Top-Up vulnerability
4.3
3 hours ago
EONSR AEO Agent<= 3.7.9
Unauthenticated Stored XSS via Scheduled Post Creation vulnerability
7.1
3 hours ago
Infility Global<= 2.15.34
Cross Site Scripting (XSS) vulnerability
6.5
3 hours ago
Chat On Desk Order Notifications< 1.0.9
Unauthenticated Account Takeover vulnerability
8.1
3 hours ago
SMS Alert Order Notifications< 3.9.8
Unauthenticated Account Takeover vulnerability
9.8
3 hours ago
jsonata< 1.8.8
NPM: JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
9.3
2 days ago
jsonata< 1.8.8
NPM: JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
9.3
2 days ago
jsonata<= 1.8.7
NPM: JSONata: Arbitrary Code Execution via crafted JSONata expressions
9.3
2 days ago
@keystone-6/core<= 6.5.2
NPM: Keystone vulnerable to `graphql.maxTake` bypass with negative `take`
7.5
2 days ago
defuddle<= 0.19.0
NPM: Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors
8.2
2 days ago
unleash-server< 8.0.3
NPM: Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username
4.1
2 days ago
unleash-server< 7.5.2
NPM: Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers
5.5
2 days ago
unleash-server< 7.5.2
NPM: Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter
7.5
2 days ago
Wawp<= 4.8.6
Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure vulnerability
9.8
2 days ago