> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://api.docs.modulards.com/modular-ds-public-api/security-health/vulnerabilities/list-vulnerabilities/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://api.docs.modulards.com/_mcp/server. # List vulnerabilities GET https://api.modulards.com/api/public/v1/vulnerabilities Lists the known vulnerabilities that affect the websites your token can reach, with one entry for each website and vulnerability pair: a vulnerability that affects three websites appears three times. Use it to answer questions such as "which of my websites have a critical vulnerability?" or to build a security overview across websites. Each entry names the affected website and component (WordPress, a plugin, a theme, PHP or the database engine), the severity, the affected version range and whether a fix exists yet. Severity uses the codes `c` critical, `h` high, `m` medium, `l` low and `n` none or informational, and the value `null` when it is unknown. The most severe come first unless you sort otherwise. Entries have no detail endpoint, so they carry no `self` link. Only websites your token can reach appear. Reference: https://api.docs.modulards.com/modular-ds-public-api/security-health/vulnerabilities/list-vulnerabilities ## Authentication - `Authorization` header (bearer token, required) — Personal access token created in the Modular DS dashboard; read-only tokens can only call GET endpoints. ## Request ### Query parameters - `filter[site][]` (string, optional) — Only the vulnerabilities of these websites, by website id. Several ids match any of them. - `filter[severity][]` (string, optional) — Only these severities: `c` critical, `h` high, `m` medium, `l` low, `n` none or informational, `null` unknown. Several values match any of them. - `sort` (string, optional) — Sort order. Accepted: `severity`, `discovered_at`, `name`; a leading `-` reverses the order. Default `-severity`, the most severe first (plain `severity` lists the least severe first). - `page[number]` (string, optional) — Page number, starting at 1. - `page[size]` (string, optional) — Rows per page, up to 50 (default 15). - `filter[component_type][]` (string, optional) — Only vulnerabilities in these kinds of component: `core` (WordPress), `plugin`, `theme`, `php`, `mariadb` or `mysql`. Several values match any of them. ## Response ### 200 200 - Vulnerabilities affecting the organization's websites - `data` (list of ApiPublicV1VulnerabilitiesGetResponsesContentApplicationJsonSchemaDataItems, optional) - `jsonapi` (ApiPublicV1VulnerabilitiesGetResponsesContentApplicationJsonSchemaJsonapi, optional) - `links` (ApiPublicV1VulnerabilitiesGetResponsesContentApplicationJsonSchemaLinks, optional) - `meta` (ApiPublicV1VulnerabilitiesGetResponsesContentApplicationJsonSchemaMeta, optional) ## Types ### ApiPublicV1VulnerabilitiesGetResponsesContentApplicationJsonSchemaDataItems - `attributes` (ApiPublicV1VulnerabilitiesGetResponsesContentApplicationJsonSchemaDataItemsAttributes, optional) - `id` (string, optional) - `type` (string, optional) ### ApiPublicV1VulnerabilitiesGetResponsesContentApplicationJsonSchemaJsonapi - `version` (string, optional) ### ApiPublicV1VulnerabilitiesGetResponsesContentApplicationJsonSchemaLinks - `first` (string, optional) - `last` (string, optional) - `next` (any, optional, nullable) - `prev` (any, optional, nullable) ### ApiPublicV1VulnerabilitiesGetResponsesContentApplicationJsonSchemaMeta - `current_page` (double, optional) - `from` (double, optional) - `last_page` (double, optional) - `links` (list of ApiPublicV1VulnerabilitiesGetResponsesContentApplicationJsonSchemaMetaLinksItems, optional) - `path` (string, optional) - `per_page` (double, optional) - `to` (double, optional) - `total` (double, optional) ### ApiPublicV1VulnerabilitiesGetResponsesContentApplicationJsonSchemaDataItemsAttributes - `affected_version_range` (string, optional, nullable) - `component` (ApiPublicV1VulnerabilitiesGetResponsesContentApplicationJsonSchemaDataItemsAttributesComponent, optional) - `description` (string, optional) - `discovered_at` (string, optional) - `name` (string, optional) - `score` (double, optional, nullable) - `severity` (string, optional) - `site` (ApiPublicV1VulnerabilitiesGetResponsesContentApplicationJsonSchemaDataItemsAttributesSite, optional) - `source_name` (string, optional) - `source_url` (string, optional) - `unfixed` (boolean, optional) ### ApiPublicV1VulnerabilitiesGetResponsesContentApplicationJsonSchemaMetaLinksItems - `active` (boolean, optional) - `label` (string, optional) - `url` (string, optional, nullable) ### ApiPublicV1VulnerabilitiesGetResponsesContentApplicationJsonSchemaDataItemsAttributesComponent - `id` (double, optional) - `name` (string, optional) - `slug` (string, optional) - `type` (string, optional) ### ApiPublicV1VulnerabilitiesGetResponsesContentApplicationJsonSchemaDataItemsAttributesSite - `id` (double, optional) - `name` (string, optional) ## Examples **Response** ```json { "data": [ { "attributes": { "affected_version_range": "<= 8.9.3", "component": { "id": 42, "name": "WooCommerce", "slug": "woocommerce", "type": "plugin" }, "description": "The WooCommerce plugin is vulnerable to reflected cross-site scripting via the wc_ajax parameter in versions up to and including 8.9.3 due to insufficient input sanitization and output escaping.", "discovered_at": "2026-09-01T08:00:00.000000Z", "name": "WooCommerce < 8.10 - Reflected Cross-Site Scripting", "score": 6.1, "severity": "h", "site": { "id": 12, "name": "Acme Shop" }, "source_name": "WPScan", "source_url": "https://wpscan.com/vulnerability/abcd1234", "unfixed": false }, "id": "551-12", "type": "site-vulnerabilities" }, { "attributes": { "affected_version_range": null, "component": { "id": 58, "name": "Contact Form Builder", "slug": "contact-form-builder", "type": "plugin" }, "description": "A vulnerability was reported for this component but has not yet been fully triaged by the source feed.", "discovered_at": "2026-09-18T07:30:00.000000Z", "name": "Unspecified plugin - Remote Code Execution", "score": null, "severity": "null", "site": { "id": 12, "name": "Acme Shop" }, "source_name": "Patchstack", "source_url": "https://patchstack.com/database/vulnerability/efgh5678", "unfixed": true }, "id": "612-12", "type": "site-vulnerabilities" } ], "jsonapi": { "version": "1.1" }, "links": { "first": "{{base_url}}/api/public/v1/vulnerabilities?page%5Bnumber%5D=1", "last": "{{base_url}}/api/public/v1/vulnerabilities?page%5Bnumber%5D=1", "next": null, "prev": null }, "meta": { "current_page": 1, "from": 1, "last_page": 1, "links": [ { "active": false, "label": "« Previous", "url": null }, { "active": true, "label": "1", "url": "{{base_url}}/api/public/v1/vulnerabilities?page%5Bnumber%5D=1" }, { "active": false, "label": "Next »", "url": null } ], "path": "{{base_url}}/api/public/v1/vulnerabilities", "per_page": 15, "to": 2, "total": 2 } } ``` **SDK Code** ```python 200 - Vulnerabilities affecting the organization's websites import requests url = "https://api.modulards.com/api/public/v1/vulnerabilities" headers = {"Authorization": "Bearer "} response = requests.get(url, headers=headers) print(response.json()) ``` ```javascript 200 - Vulnerabilities affecting the organization's websites const url = 'https://api.modulards.com/api/public/v1/vulnerabilities'; const options = {method: 'GET', headers: {Authorization: 'Bearer '}}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go 200 - Vulnerabilities affecting the organization's websites package main import ( "fmt" "net/http" "io" ) func main() { url := "https://api.modulards.com/api/public/v1/vulnerabilities" req, _ := http.NewRequest("GET", url, nil) req.Header.Add("Authorization", "Bearer ") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby 200 - Vulnerabilities affecting the organization's websites require 'uri' require 'net/http' url = URI("https://api.modulards.com/api/public/v1/vulnerabilities") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Get.new(url) request["Authorization"] = 'Bearer ' response = http.request(request) puts response.read_body ``` ```java 200 - Vulnerabilities affecting the organization's websites import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.get("https://api.modulards.com/api/public/v1/vulnerabilities") .header("Authorization", "Bearer ") .asString(); ``` ```php 200 - Vulnerabilities affecting the organization's websites request('GET', 'https://api.modulards.com/api/public/v1/vulnerabilities', [ 'headers' => [ 'Authorization' => 'Bearer ', ], ]); echo $response->getBody(); ``` ```csharp 200 - Vulnerabilities affecting the organization's websites using RestSharp; var client = new RestClient("https://api.modulards.com/api/public/v1/vulnerabilities"); var request = new RestRequest(Method.GET); request.AddHeader("Authorization", "Bearer "); IRestResponse response = client.Execute(request); ``` ```swift 200 - Vulnerabilities affecting the organization's websites import Foundation let headers = ["Authorization": "Bearer "] let request = NSMutableURLRequest(url: NSURL(string: "https://api.modulards.com/api/public/v1/vulnerabilities")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "GET" request.allHTTPHeaderFields = headers let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```