Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 36/1777
6.5
CVE-2026-19711

The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's

6.5
CVE-2026-19613

The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeate

6.4
CVE-2026-18402

The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting v

4.9
CVE-2026-17582

The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7

6.4
CVE-2026-16775

The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cros

6.4
CVE-2026-16758

The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all

6.4
CVE-2026-15790

The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,

6.4
CVE-2026-15604

The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin

5.7
CVE-2026-15384

The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the au

4.9
CVE-2026-15351

The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to

4.3
CVE-2026-15345

The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization

6.5
CVE-2026-15056

The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vul

5.4
CVE-2026-13712

The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before ou

6.6
CVE-2026-10035

The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and

6.3
CVE-2026-19933

A weakness has been identified in DefaultFuction Customer-Relationship-Management-In-C-Project 2.0. Impacted is the func

6.3
CVE-2026-19932

A security flaw has been discovered in DefaultFuction Notice-System-Managent 2.0. This issue affects the function Groovy

5.4
CVE-2026-18385

The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – Profile

4.3
CVE-2026-16779

The Kubio AI Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin

6.5
CVE-2026-16079

The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attribute in Post Content

6.5
CVE-2026-15963

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injectio

6.4
CVE-2026-15726

The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Shortcode Attribute in

4.9
CVE-2026-15602

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the

5.3
CVE-2026-15441

The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and including, 5.6.0 vi

6.4
CVE-2026-15066

The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in a

6.1
CVE-2026-15009

The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vu

6.5
CVE-2026-13358

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Ins

4.3
CVE-2026-13167

The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulne

4.3
CVE-2026-12905

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7

4.4
CVE-2026-12477

The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripti

6.4
CVE-2026-11780

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Sc

4.3
CVE-2025-10005

The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Insecure

4.4
CVE-2026-2487

The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi

6.3
CVE-2026-19930

A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the file htdocs/user/ca

6.3
CVE-2026-19929

A vulnerability was identified in OpenBoxes up to 0.9.6. This impacts the function buildZebraTemplate of the file grails

6.3
CVE-2026-19928

A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/co

6.3
CVE-2026-19927

A vulnerability was found in OpenBoxes up to 0.9.7. The impacted element is the function Upload of the file grails-app/c

4.7
CVE-2026-19925

A vulnerability was detected in SourceCodester Stock Management System 1.0. This issue affects some unknown processing o

6.3
CVE-2026-19923

A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /ch

6.3
CVE-2026-19921

A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown

6.3
CVE-2026-19920

A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown function of the file

6.3
CVE-2026-19918

A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_statu

6.3
CVE-2026-19917

A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unknown function of the

4.8
CVE-2026-73055

Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on

6.2
CVE-2026-73047

siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attribute-view

5.3
CVE-2026-19903

A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db

4.2
CVE-2026-18165

@fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8.3.0, the plugin val

6.3
CVE-2026-19894

A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected is an unknown function of t

6.5
CVE-2026-12248

The WPML Multilingual CMS plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in all version

4.3
CVE-2026-73632

Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization

4.3
CVE-2026-73631

Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state c

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started