Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.
In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activi
Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.
Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Pro
Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.
Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.
Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.
Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.
Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.
Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.
Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.
Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.
Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.
Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub L
Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.
Contributor Broken Access Control in uListing <= 2.2.0 versions.
Subscriber Broken Access Control in uListing <= 2.2.0 versions.
Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.
Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.
Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.
Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.
Subscriber Broken Access Control in eRoom <= 1.7.1 versions.
Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.
Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.
Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.
Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.
Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitr
Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumera
Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check
Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forw
Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could es
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Admi
The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via th
The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check
The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shor
The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is v
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started