Automattic

    Dashboard / Vendors

    Products: 36
    Vulnerabilities: 102
    Known Exploited: 0
    4
    Critical Level Threats
    26
    High Level Threats
    69
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-48888

    WordPress WooCommerce plugin < 11.1.0 - Denial of Service Attack vulnerability

    Last Modified: Sep 08, 2026
    Published: Sep 08, 2026

    CVE-2026-57777

    WordPress WooCommerce plugin < 11.0 - SQL Injection vulnerability

    Last Modified: Sep 04, 2026
    Published: Sep 04, 2026

    CVE-2026-73562

    Mongoose: Prototype pollution in the update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)

    Last Modified: Aug 14, 2026
    Published: Aug 13, 2026

    CVE-2026-42334

    Mongoose: Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection

    Last Modified: May 15, 2026
    Published: May 14, 2026

    CVE-2022-50958

    WordPress Plugin Jetpack 9.1 Cross Site Scripting via grunion-form-view.php

    Last Modified: May 11, 2026
    Published: May 10, 2026
    Items Per Page
    Automattic Vulnerabilities & Security CVEs | CVE-DB