Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 704/1777
6.1
CVE-2025-1286

The Download HTML TinyMCE Button WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting

4.8
CVE-2025-1033

The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape some of its settings, which could allow high

6.1
CVE-2025-0688

The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape

6.1
CVE-2025-0687

The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape

4.8
CVE-2025-0329

The AI ChatBot for WordPress WordPress plugin before 6.2.4 does not sanitise and escape some of its settings, which cou

4.8
CVE-2024-9882

The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses WordPress plugin before 1.9.4 does

5.4
CVE-2024-9879

The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a S

5.4
CVE-2024-9838

The Auto Affiliate Links WordPress plugin before 6.4.7 does not sanitize and escape a parameter before using it in a SQL

6.5
CVE-2024-9765

The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of th

5.4
CVE-2024-9711

The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, w

5.4
CVE-2024-9709

The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, w

5.4
CVE-2024-9663

The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high

5.4
CVE-2024-9662

The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high

5.4
CVE-2024-9645

The Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry WordPress plugin before 2.2.93 does not validate

5.4
CVE-2024-9599

The Popup Box WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high p

6.5
CVE-2024-9450

The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check

4.8
CVE-2024-9390

The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could al

5.4
CVE-2024-9238

The AVIF Uploader WordPress plugin before 1.1.1 does not sanitise uploaded SVG files, which could allow users with a rol

4.8
CVE-2024-9236

The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privil

4.3
CVE-2024-9233

The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could

4.8
CVE-2024-9227

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its set

4.8
CVE-2024-9182

The Maspik WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could allow high priv

5.4
CVE-2024-8854

The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow hi

5.4
CVE-2024-8851

The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow hi

4.8
CVE-2024-8759

The Nested Pages WordPress plugin before 3.2.9 does not sanitise and escape some of its settings, which could allow high

6.1
CVE-2024-8703

The Z-Downloads WordPress plugin before 1.11.6 does not sanitise and escape some parameters when outputting them in the

4.8
CVE-2024-8702

The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow hi

4.8
CVE-2024-8701

The events-calendar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow

4.8
CVE-2024-8670

The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which coul

4.8
CVE-2024-8620

The MapPress Maps for WordPress plugin before 2.93 does not sanitise and escape some of its settings, which could allow

4.8
CVE-2024-8619

The Ajax Search Lite WordPress plugin before 4.12.3 does not sanitise and escape some of its settings, which could allo

4.8
CVE-2024-8618

The Page Builder: Pagelayer WordPress plugin before 1.9.0 does not sanitise and escape some of its settings, which coul

4.8
CVE-2024-8617

The Quiz Maker WordPress plugin before 6.5.9.9 does not sanitize and escape some of its settings, which could allow high

4.8
CVE-2024-8542

The Everest Forms WordPress plugin before 3.0.3.1 does not sanitise and escape some of its settings, which could allow

4.8
CVE-2024-8493

The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow h

4.8
CVE-2024-8492

The Hustle WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high pri

4.8
CVE-2024-8426

The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which coul

4.3
CVE-2024-8398

The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, whi

5.4
CVE-2024-8397

The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers whe

6.5
CVE-2024-8286

The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which co

4.8
CVE-2024-8284

The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow

4.3
CVE-2024-8245

The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could a

4.8
CVE-2024-8187

The Smart Post Show WordPress plugin before 3.0.1 does not sanitise and escape some of its settings, which could allow

6.1
CVE-2024-8095

The BabelZ WordPress plugin through 1.1.5 does not have CSRF check in some places, and is missing sanitisation as well

6.5
CVE-2024-8094

The Ntz Antispam WordPress plugin through 2.0e does not have CSRF check in place when updating its settings, which could

6.1
CVE-2024-8090

The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation a

6.1
CVE-2024-8085

The PeoplePond WordPress plugin through 1.1.9 does not have CSRF check in some places, and is missing sanitisation as we

4.3
CVE-2024-8082

The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could

4.3
CVE-2024-8050

The Custom Author Base WordPress plugin through 1.1.1 does not have CSRF check in place when updating its settings, whic

6.1
CVE-2024-8032

The Smooth Gallery Replacement WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sani

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started