The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,161
Mitigations16,140
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
@apostrophecms/seo<= 1.4.2
NPM: @apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
8.7
3 hours ago
apostrophe<= 4.30.0
NPM: Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
9.1
3 hours ago
@nocobase/plugin-notification-in-app-message<= 2.0.60
NPM: NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
10
6 hours ago
jodit< 4.12.28
NPM: Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
7.2
6 hours ago
@phun-ky/defaults-deep< 2.0.5
NPM: @phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging
7.3
7 hours ago
hashi-vault-js<= 0.5.1
NPM: hashi-vault-js has a path traversal and query parameter injection
8.7
8 hours ago
dssrf<= 1.0.4
NPM: dssrf: any users using 1.1.1.1 DNS is impacted by SSRF
8.7
8 hours ago
@dynatrace-oss/dynatrace-mcp-server<= 1.8.7
NPM: `@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation
7.5
9 hours ago
Simply Poll <= 1.4.1
Unauthenticated SQL Injection vulnerability
9.3
16 hours ago
Meta Box AIO<= 3.8.0
Missing Authorization to Unauthenticated Arbitrary Post Deletion vulnerability
9.1
16 hours ago
WP Fast Total Search<= 1.80.280
Unauthenticated SQL Injection vulnerability
9.3
16 hours ago
Plugin Organizer<= 10.2.4
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
16 hours ago
Fluent Forms Pro Add On Pack<= 6.2.6
Authenticated (Subscriber+) PHP Object Injection to Arbitrary User Password Change vulnerability
8.8
16 hours ago
WPDM – Premium Packages<= 6.2.0
Unauthenticated SQL Injection vulnerability
9.3
17 hours ago
TrueBooker<= 1.2.2
Unauthenticated SQL Injection vulnerability
9.3
17 hours ago
Taskbuilder<= 5.0.9
Authenticated (Subscriber+) SQL Injection vulnerability
8.5
17 hours ago
Web Directory Free<= 1.7.13
Unauthenticated SQL Injection vulnerability
9.3
18 hours ago
Demi &#8211; One Click Demo Import, Backup &amp; Site Migration<= 0.0.7
Unauthenticated Arbitrary Directory Deletion vulnerability
7.5
18 hours ago
Customer Switching< 2.1.3
Customer+ Privilege Escalation to Administrator vulnerability
8.8
18 hours ago
@aws-amplify/codegen-ui-react<= 2.20.2
NPM: AWS Amplify Studio UI Component Properties Has an Input Validation Issue
9.5
1 day ago