List vulnerabilities
Lists the known vulnerabilities that affect the websites your token can reach, with one entry for each website and vulnerability pair: a vulnerability that affects three websites appears three times. Use it to answer questions such as “which of my websites have a critical vulnerability?” or to build a security overview across websites.
Each entry names the affected website and component (WordPress, a plugin, a theme, PHP or the database engine), the severity, the affected version range and whether a fix exists yet.
Severity uses the codes c critical, h high, m medium, l low and n none or informational, and the value null when it is unknown. The most severe come first unless you sort otherwise.
Entries have no detail endpoint, so they carry no self link. Only websites your token can reach appear.
Authentication
Personal access token created in the Modular DS dashboard; read-only tokens can only call GET endpoints.
Query parameters
Only these severities: c critical, h high, m medium, l low, n none or informational, null unknown. Several values match any of them.
Sort order. Accepted: severity, discovered_at, name; a leading - reverses the order. Default -severity, the most severe first (plain severity lists the least severe first).
Rows per page, up to 50 (default 15).
Only vulnerabilities in these kinds of component: core (WordPress), plugin, theme, php, mariadb or mysql. Several values match any of them.
Response
200 - Vulnerabilities affecting the organization's websites
