Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

MEDIUM Severity CVEs

CVSS 4.0 – 6.9

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

164,190
Total
101
Known Exploited
Showing 88,803 of 164,190 total · Page 87/1777
4.3
CVE-2026-65456

Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.

5.3
CVE-2026-65453

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

5.3
CVE-2026-65452

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

6.5
CVE-2026-65449

Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.

4.3
CVE-2026-64810

In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activi

5.4
CVE-2026-61981

Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.

4.3
CVE-2026-61973

Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

5.3
CVE-2026-61972

Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

6.5
CVE-2026-61946

Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.

6.5
CVE-2026-61945

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Pro

6.5
CVE-2026-59524

Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.

6.5
CVE-2026-59522

Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.

6.5
CVE-2026-59513

Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.

6.5
CVE-2026-57808

Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.

6.5
CVE-2026-57717

Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.

5.3
CVE-2026-57716

Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.

6.3
CVE-2026-57703

Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.

6.5
CVE-2026-57425

Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.

6.5
CVE-2026-57384

Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.

6.5
CVE-2026-57373

Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.

4.3
CVE-2026-27423

Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.

5.3
CVE-2026-27422

Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.

5.3
CVE-2026-27418

Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.

6.5
CVE-2026-27403

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub L

5.3
CVE-2026-27399

Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.

4.3
CVE-2026-27392

Contributor Broken Access Control in uListing <= 2.2.0 versions.

5.4
CVE-2026-27391

Subscriber Broken Access Control in uListing <= 2.2.0 versions.

6.7
CVE-2026-27377

Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.

6.5
CVE-2026-27372

Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.

5.3
CVE-2026-27355

Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.

5.3
CVE-2026-25466

Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.

5.4
CVE-2026-25427

Subscriber Broken Access Control in eRoom <= 1.7.1 versions.

4.3
CVE-2026-25424

Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.

4.4
CVE-2026-24639

Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.

5.9
CVE-2026-24628

Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.

4.3
CVE-2026-24537

Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.

5.9
CVE-2025-68081

Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.

6.1
CVE-2026-65756

Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitr

6.5
CVE-2026-65713

Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumera

6.2
CVE-2026-65712

Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check

6.5
CVE-2026-64875

Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forw

6.5
CVE-2026-64872

Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could es

5.4
CVE-2026-64871

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Admi

6.5
CVE-2026-16078

The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all

6.5
CVE-2026-15906

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via th

5.3
CVE-2026-15827

The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check

6.4
CVE-2026-15794

The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shor

4.4
CVE-2026-15786

The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is v

6.5
CVE-2026-15761

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event

4.4
CVE-2026-15647

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term

Frequently Asked Questions

What does MEDIUM severity mean for CVEs?

CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit

How many medium severity CVEs exist?

There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize medium severity vulnerabilities?

MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect MEDIUM Vulnerabilities

CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.

Get Started