Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 705/1777
6.5
CVE-2024-8031

The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which files can be downloade

4.3
CVE-2024-8009

The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers

4.3
CVE-2024-7984

The Joy Of Text Lite WordPress plugin through 2.3.1 does not have CSRF check in place when updating its settings, which

4.8
CVE-2024-7769

The ClickSold IDX WordPress plugin through 1.90 does not sanitise and escape some of its settings, which could allow hig

6.1
CVE-2024-7761

In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you

4.8
CVE-2024-7759

The PWA for WP WordPress plugin before 1.7.72 does not sanitise and escape some of its settings, which could allow high

4.8
CVE-2024-7758

The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could all

4.8
CVE-2024-7556

The Simple Share WordPress plugin through 0.5.3 does not sanitise and escape some of its settings, which could allow hig

4.8
CVE-2024-6798

The DL Verification WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow hi

4.8
CVE-2024-6797

The DL Robots.txt WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high

5.4
CVE-2024-6718

The PVN Auth Popup WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before o

4.8
CVE-2024-6713

The PVN Auth Popup WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow h

6.1
CVE-2024-6712

The MapFig Studio WordPress plugin through 0.2.1 does not have CSRF check in some places, and is missing sanitisation as

4.8
CVE-2024-6708

The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting

4.8
CVE-2024-6693

The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high priv

6.1
CVE-2024-6690

The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirectio

5.4
CVE-2024-6668

The ProfilePro WordPress plugin through 1.3 does not sanitise and escape some parameters and lacks proper access control

6.1
CVE-2024-6667

The KBucket: Your Curated Content in WordPress plugin before 4.1.5 does not sanitise and escape a parameter before outpu

4.8
CVE-2024-6665

The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, wh

4.8
CVE-2024-6478

The CTT Expresso para WooCommerce WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, whic

4.8
CVE-2024-6462

The DL Yandex Metrika WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow

4.8
CVE-2024-6335

The Tracking Code Manager WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could a

5.4
CVE-2024-5440

The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.3 does not validate and escape some of its short

4.8
CVE-2024-5026

The CM Tooltip Glossary WordPress plugin before 4.3.4 does not sanitise and escape some of its settings, which could all

6.4
CVE-2024-4665

The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing use

6.8
CVE-2024-3901

The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blo

4.8
CVE-2024-3062

The Save as Image Plugin by Pdfcrowd WordPress plugin before 3.2.2 does not sanitise and escape some of its settings, wh

4.8
CVE-2024-2869

The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could

4.8
CVE-2024-2643

The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin

4.8
CVE-2024-1663

The Ultimate Noindex Nofollow Tool II WordPress plugin before 1.3.6 does not sanitise and escape some of its settings, w

6.1
CVE-2024-13865

The S3Player WordPress plugin through 4.2.1 does not sanitise and escape a parameter before outputting it back in the p

6.1
CVE-2024-13828

The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape a parameter before outputting it back in the

6.1
CVE-2024-13823

The 360 Product Rotation WordPress plugin through 1.5.8 does not sanitise and escape a parameter before outputting it ba

4.8
CVE-2024-13730

The Podlove Podcast Publisher WordPress plugin before 4.2.1 does not sanitise and escape some of its settings, which cou

4.8
CVE-2024-13729

The Podlove Podcast Publisher WordPress plugin before 4.1.24 does not sanitise and escape some of its settings, which co

6.1
CVE-2024-13727

The MemberSpace WordPress plugin before 2.1.14 does not sanitise and escape a parameter before outputting it back in th

4.8
CVE-2024-13621

The GDPR Framework By Data443 WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which cou

6.1
CVE-2024-13619

The LifterLMS WordPress plugin before 8.0.1 does not sanitise and escape a parameter before outputting it back in the p

4.8
CVE-2024-13616

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.7.2 does not sanitise and escape some of its setting

4.8
CVE-2024-13486

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow

4.8
CVE-2024-13482

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow

4.8
CVE-2024-13384

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.24 does not sanitise and escape some

4.8
CVE-2024-13383

The HD Quiz WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high priv

4.8
CVE-2024-13382

The Calculated Fields Form WordPress plugin before 5.2.64 does not sanitise and escape some of its settings, which could

4.8
CVE-2024-13357

The Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high priv

4.8
CVE-2024-13313

The AWeber WordPress plugin through 7.3.20 does not sanitise and escape some of its settings, which could allow high pr

4.8
CVE-2024-13128

The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow h

4.8
CVE-2024-13127

The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow h

4.8
CVE-2024-13053

The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could

4.8
CVE-2024-12874

The Top Comments WordPress plugin through 1.0 does not sanitise and escape some of its settings, which could allow high

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started