The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total51,373
Mitigations16,786
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
mariadb< 3.2.4
NPM: MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets
6.5
23 minutes ago
mariadb< 3.2.4
NPM: MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
5.9
1 hour ago
mariadb< 3.2.4
NPM: MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`
7.5
4 hours ago
9router< 0.5.2
NPM: 9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
8.2
4 hours ago
9router< 0.5.2
NPM: 9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
8.6
4 hours ago
Forminator< 1.57.0.7
Authenticated Privilege Escalation vulnerability
9.8
9 hours ago
Amelia9.0-9.7
Provider+ Arbitrary Provider Password Update vulnerability
4.7
9 hours ago
Events Manager<= 7.4.0.1
Reflected Cross-Site Scripting via 'header_format' Parameter vulnerability
7.1
9 hours ago
All-in-One WP Migration Unlimited Extension<= 2.84
Authenticated (Subscriber+) Stored Cross-Site Scripting via 'ai1wm_backups_path' Parameter vulnerability
6.5
9 hours ago
Return Refund and Exchange For WooCommerce< 4.6.4
Unauthenticated Guest Order Message Disclosure and Manipulation vulnerability
6.5
9 hours ago
Customer Reviews for WooCommerce<= 5.106.0
Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form vulnerability
7.1
9 hours ago
Squeeze< 1.7.12
Author+ Arbitrary File Upload vulnerability
9.1
9 hours ago
Pods< 3.3.9.1
Author+ RCE vulnerability
9.1
9 hours ago
12 Step Meeting List3.17-3.19.16
Unauthenticated Stored XSS vulnerability
7.1
9 hours ago
AI Engine3.4.0-3.7.1
Unauthenticated Arbitrary AI Query Execution vulnerability
5.6
9 hours ago
CMP – Coming Soon & Maintenance< 4.1.18
Editor+ Privilege Escalation vulnerability
9.8
9 hours ago
Document Embedder< 2.3.1
Unauthenticated Private Document Download vulnerability
5.3
9 hours ago
Order Tip for WooCommerce< 1.6.0
Shop Manager+ Arbitrary File Deletion vulnerability
8.6
9 hours ago
TranslatePress<= 3.2.6
Authenticated (Subscriber+) Stored Cross-Site Scripting via Approved Comment Body in Translation Editor vulnerability
6.5
9 hours ago
Content Mask1.8.0-1.8.5.4
Contributor Publish Capability Bypass vulnerability
2.7
9 hours ago