Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 706/1777
6.1
CVE-2024-12873

The Custom Field Manager WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back

4.8
CVE-2024-12808

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before

4.8
CVE-2024-12800

The IP Based Login WordPress plugin before 2.4.1 does not sanitise values when importing, which could allow high privile

4.8
CVE-2024-12770

The WP ULike WordPress plugin before 4.7.6 does not sanitise and escape some of its settings, which could allow high pr

4.3
CVE-2024-12750

The Competition Form WordPress plugin through 2.0 does not have CSRF check in place when updating its settings, which co

4.8
CVE-2024-12743

The MailPoet WordPress plugin before 5.5.2 does not sanitise and escape some of its settings, which could allow high pr

4.8
CVE-2024-12739

The Mobile Contact Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allo

6.1
CVE-2024-12734

The Advance Post Prefix WordPress plugin through 1.1.1, Advance Post Prefix WordPress plugin through 1.1.1 does not sani

6.1
CVE-2024-12733

The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it bac

6.1
CVE-2024-12732

The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it bac

6.1
CVE-2024-12726

The ClipArt WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page,

6.1
CVE-2024-12725

The Clasify Classified Listing WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting

6.1
CVE-2024-12724

The WP DeskLite WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in th

5.4
CVE-2024-12722

The Twitter Bootstrap Collapse aka Accordian Shortcode WordPress plugin through 1.0 does not validate and escape some of

4.8
CVE-2024-12716

The Simple Basic Contact Form WordPress plugin before 20250114 does not sanitise and escape some of its settings, which

4.8
CVE-2024-12680

The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high

4.8
CVE-2024-12679

The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high

6.5
CVE-2024-12301

The JSP Store Locator WordPress plugin through 1.0 does not have CSRF checks in some places, which could allow attackers

6.1
CVE-2024-12282

The WordPress连接微博 WordPress plugin through 2.5.6 does not have CSRF check in some places, and is missing sanitisation as

4.8
CVE-2024-11843

The Panorama WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow high p

6.1
CVE-2024-11719

The tarteaucitron-wp WordPress plugin before 0.3.0 does not have CSRF check in some places, and is missing sanitisation

5.4
CVE-2024-11718

The tarteaucitron-wp WordPress plugin before 0.3.0 allows author level and above users to add HTML into a post/page, whi

5.4
CVE-2024-11502

The Planning Center Online Giving WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attr

4.3
CVE-2024-11373

The Connexion Logs WordPress plugin through 3.0.2 does not have CSRF check in place when updating its settings, which co

4.8
CVE-2024-11266

The Geocache Stat Bar Widget WordPress plugin through 0.911 does not sanitise and escape some of its settings, which cou

4.8
CVE-2024-11221

The Full Screen (Page) Background Image Slideshow WordPress plugin through 1.1 does not sanitise and escape some of its

4.8
CVE-2024-11190

The jwp-a11y WordPress plugin through 4.1.7 does not sanitise and escape some of its settings, which could allow high pr

4.8
CVE-2024-11189

The Social Share And Social Locker WordPress plugin before 1.4.2 does not sanitise and escape some of its settings, whi

6.1
CVE-2024-11141

The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings and is missing C

4.8
CVE-2024-11109

The WP Google Review Slider WordPress plugin before 15.6 does not sanitise and escape some of its settings, which could

5.4
CVE-2024-10818

The JSFiddle Shortcode WordPress plugin before 1.1.3 does not validate and escape some of its shortcode attributes befor

4.3
CVE-2024-10677

The BTEV WordPress plugin through 2.0.2 does not have CSRF check in place when updating its settings, which could allow

4.8
CVE-2024-10639

The Auto Prune Posts WordPress plugin before 3.0.0 does not sanitise and escape some of its settings, which could allow

4.3
CVE-2024-10634

The Nokaut Offers Box WordPress plugin through 1.4.0 does not have CSRF check in place when updating its settings, which

4.8
CVE-2024-10632

The Nokaut Offers Box WordPress plugin through 1.4.0 does not sanitize and escape some of its settings, which could allo

6.5
CVE-2024-10631

The Countdown Timer for WordPress Block Editor WordPress plugin through 1.0.5 does not validate and escape some of its b

5.4
CVE-2024-10504

The Contact Form, Survey, Quiz & Popup Form Builder WordPress plugin before 1.7.1 does not sanitise and escape some par

4.8
CVE-2024-10475

The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin before 1.9.8 does not sanitise and escape

4.8
CVE-2024-10362

The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.9.1 does not sanitize and escape some of

4.8
CVE-2024-10149

The Social Slider Feed WordPress plugin before 2.2.9 does not sanitise and escape some of its settings, which could allo

4.8
CVE-2024-10145

The Hubbub Lite WordPress plugin before 1.34.4 does not sanitise and escape some of its settings, which could allow hig

4.8
CVE-2024-10144

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some

4.8
CVE-2024-10143

The MB Custom Post Types & Custom Taxonomies WordPress plugin before 2.7.7 does not sanitise and escape some of its sett

4.8
CVE-2024-10107

The Giveaways and Contests by RafflePress WordPress plugin before 1.12.17 does not sanitise and escape some of its sett

5.9
CVE-2024-10076

The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelera

5.6
CVE-2024-10075

The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible t

4.8
CVE-2024-10054

The Happyforms WordPress plugin before 1.26.3 does not sanitise and escape some of its settings, which could allow high

4.1
CVE-2024-10009

The Melapress File Monitor WordPress plugin before 2.1.0 does not sanitize and escape a parameter before using it in a S

5.3
CVE-2024-0970

This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrust

6.1
CVE-2023-7230

The illi Link Party! WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started