Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,932
Mitigations
Mitigation rules
17,300
No official patch
13,368
In triage
1,402
Published soon
21
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
nodemailer
>= 5.0.0, < 10.0.2
NPM: Nodemailer: Process-global DNS cache reuses TLS `servername` across transports, enabling cross-tenant SMTP credential disclosure
5.9
34 minutes ago
undici
>= 6.25.0, < 6.28.1
NPM: undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression
5.9
47 minutes ago
multer
>= 2.2.0, < 2.4.0
NPM: multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads
5.3
55 minutes ago
morgan
< 1.12.1
NPM: morgan vulnerable to Log Injection via unescaped double quote in quoted log fields
5.3
57 minutes ago
@angular/platform-server
<= 19.2.25
NPM: Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE
8.7
59 minutes ago
fast-uri
< 2.4.6
NPM: fast-uri vulnerable to authority injection via an unvalidated port in serialize
7.5
1 hour ago
fast-uri
2.4.5
NPM: fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority
7.5
1 hour ago
ip-address
<= 10.5.0
NPM: ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts
6.3
1 hour ago
ip-address
>= 10.2.0, <= 10.5.0
NPM: ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass
6.9
1 hour ago
@angular/platform-server
<= 19.2.25
NPM: Angular SSR: XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Content Elements
8.6
1 hour ago
@grpc/grpc-js-xds
< 1.13.1
NPM: @grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches
6.5
2 hours ago
scim-patch
< 0.9.2
NPM: scim-patch: Mutation of Inherited Built-in Method Objects
4.3
8 hours ago
code-ollama
<= 0.36.0
NPM: code-ollama: `grep_search` Command Injection via Unescaped `$()` Shell Substitution (CWE-78)
7.8
8 hours ago
WP Review Slider Pro
< 12.7.12
Subscriber+ Stored XSS vulnerability
6.5
8 hours ago
File Manager
7.2.2-8.0.4
Unauthenticated Database Backup Disclosure vulnerability
5.9
9 hours ago
Verge3D
4.1.0-4.13.0
Unauthenticated Payment Bypass vulnerability
5.3
9 hours ago
Best Payments Plugin for WP
4.6.20-4.6.25
Unauthenticated Payment Bypass vulnerability
5.3
9 hours ago
Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification
1.3.0-2.3.1
Blocked User Restriction Bypass vulnerability
5.4
9 hours ago
Bookly
< 28.3
Unauthenticated Payment Bypass vulnerability
5.3
9 hours ago
Contact Form by WPForms
1.5.0.1-2.0.2.0
Unauthenticated Arbitrary Shortcode Execution vulnerability
6.5
9 hours ago
Load more