Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 86/1777
5.9
CVE-2026-65534

Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.

6.5
CVE-2026-65533

Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.

4.8
CVE-2026-65531

Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.

4.3
CVE-2026-65530

Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.

5.3
CVE-2026-65529

Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.

6.5
CVE-2026-65528

Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions.

6.5
CVE-2026-65527

Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.

5.3
CVE-2026-65525

Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.

4.3
CVE-2026-65524

Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.

6.5
CVE-2026-65522

Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 ve

5.3
CVE-2026-65521

Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.

6.5
CVE-2026-65519

Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.

6.5
CVE-2026-65518

Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.

6.5
CVE-2026-65514

Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.

5.4
CVE-2026-65512

Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allow

5.3
CVE-2026-65506

Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.

5.3
CVE-2026-65505

Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

6.5
CVE-2026-65503

Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

5.3
CVE-2026-65501

Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.

6.5
CVE-2026-65499

Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.

5.3
CVE-2026-65498

Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.

4.4
CVE-2026-65496

Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.

4.3
CVE-2026-65491

Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.

5.3
CVE-2026-65490

Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.

5.3
CVE-2026-65489

Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.

5.3
CVE-2026-65487

Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.

5.3
CVE-2026-65486

Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.

5.3
CVE-2026-65485

Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.

6.3
CVE-2026-65484

Contributor Broken Access Control in Style Kits <= 2.6.5 versions.

5.9
CVE-2026-65483

Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions.

6.5
CVE-2026-65482

Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.

6.5
CVE-2026-65480

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem

5.4
CVE-2026-65479

Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.

5.4
CVE-2026-65478

Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.

5.3
CVE-2026-65476

Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.

6.5
CVE-2026-65475

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Im

5.3
CVE-2026-65474

Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.

6.5
CVE-2026-65473

Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.

5.3
CVE-2026-65472

Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.

6.5
CVE-2026-65470

Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.

5.3
CVE-2026-65469

Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.

5.3
CVE-2026-65468

Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.

4.9
CVE-2026-65467

Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.

4.9
CVE-2026-65466

Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.

6.5
CVE-2026-65465

Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.

5.4
CVE-2026-65464

Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.

5.4
CVE-2026-65463

Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.

4.3
CVE-2026-65460

Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.

4.3
CVE-2026-65458

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby P

4.3
CVE-2026-65457

Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started