The Download HTML TinyMCE Button WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting
The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape some of its settings, which could allow high
The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape
The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape
The AI ChatBot for WordPress WordPress plugin before 6.2.4 does not sanitise and escape some of its settings, which cou
The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses WordPress plugin before 1.9.4 does
The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a S
The Auto Affiliate Links WordPress plugin before 6.4.7 does not sanitize and escape a parameter before using it in a SQL
The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of th
The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, w
The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, w
The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high
The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high
The Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry WordPress plugin before 2.2.93 does not validate
The Popup Box WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high p
The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check
The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could al
The AVIF Uploader WordPress plugin before 1.1.1 does not sanitise uploaded SVG files, which could allow users with a rol
The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privil
The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its set
The Maspik WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could allow high priv
The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow hi
The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow hi
The Nested Pages WordPress plugin before 3.2.9 does not sanitise and escape some of its settings, which could allow high
The Z-Downloads WordPress plugin before 1.11.6 does not sanitise and escape some parameters when outputting them in the
The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow hi
The events-calendar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow
The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which coul
The MapPress Maps for WordPress plugin before 2.93 does not sanitise and escape some of its settings, which could allow
The Ajax Search Lite WordPress plugin before 4.12.3 does not sanitise and escape some of its settings, which could allo
The Page Builder: Pagelayer WordPress plugin before 1.9.0 does not sanitise and escape some of its settings, which coul
The Quiz Maker WordPress plugin before 6.5.9.9 does not sanitize and escape some of its settings, which could allow high
The Everest Forms WordPress plugin before 3.0.3.1 does not sanitise and escape some of its settings, which could allow
The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow h
The Hustle WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high pri
The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which coul
The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, whi
The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers whe
The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which co
The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow
The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could a
The Smart Post Show WordPress plugin before 3.0.1 does not sanitise and escape some of its settings, which could allow
The BabelZ WordPress plugin through 1.1.5 does not have CSRF check in some places, and is missing sanitisation as well
The Ntz Antispam WordPress plugin through 2.0e does not have CSRF check in place when updating its settings, which could
The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation a
The PeoplePond WordPress plugin through 1.1.9 does not have CSRF check in some places, and is missing sanitisation as we
The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could
The Custom Author Base WordPress plugin through 1.1.1 does not have CSRF check in place when updating its settings, whic
The Smooth Gallery Replacement WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sani
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started