🚀 Just released:
Latio 2026 Application Security Market Report.
Read it in our Whitepapers.
100% Signal 0% Noise
Platform
Invicti Platform
Zero-noise AppSec platform
Scan Code
Secure code before runtime
SAST
Early static security analysis
Open Source (SCA)
Find vulnerable dependencies
SBOM & License Risk
Generate SBOMs and track licenses
Secrets
Detect exposed secrets in applications
Infrastructure as Code
Ingest IaC security findings
Container
Track container image vulnerabilities
Test Runtime
Test live applications like attackers
DAST & AI DAST
Test runtime, prove exploitability
Agentic Pentesting
Automate real-world attack techniques
API Security Testing
Discover and test APIs
Attack Surface Management
Identify exposed apps and endpoints
Cloud AppSec
Get a single-pane view of cloud app risk
AI AppSec
Scan smarter, accelerate remediation
Manage Vulnerabilities
See, prioritize, reduce AppSec risk
Vulnerability Management (ASPM)
Centralize and correlate AppSec findings
Compliance & Executive Reporting
Measure risk and impact
Threat Intelligence
Reachability, exploitability, and business logic
Solutions
API Discovery
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Savings Calculator
Live Training
Partners
Documentation
Get a demo
Home
/
Web Application Vulnerabilities
Web Application Vulnerabilities
Runtime SCA Findings
Looking for the vulnerability index of Invicti's legacy products?
Invicti Enterprise
Acunetix Standard & Premium
v.26.3.2229
Web Application Vulnerabilities
This page lists
24119 vulnerabilities
in
70 categories
.
Critical: 1560
High: 12984
Medium: 8644
Low: 865
Information: 66
Vulnerability Name
CVE
CWE
Severity
XOOPS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2008-4433)
CVE-2008-4433
CWE-138
High
XOOPS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2008-5665)
CVE-2008-5665
CWE-138
High
XOOPS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2017-11174)
CVE-2017-11174
CWE-138
Critical
XOOPS Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2017-7290)
CVE-2017-7290
CWE-138
High
XOOPS Other Vulnerability (CVE-2005-0743)
CVE-2005-0743
-
High
XOOPS Other Vulnerability (CVE-2005-2112)
CVE-2005-2112
-
Medium
XOOPS Other Vulnerability (CVE-2005-2113)
CVE-2005-2113
-
High
XOOPS Other Vulnerability (CVE-2005-3680)
CVE-2005-3680
-
Medium
XOOPS Other Vulnerability (CVE-2006-5810)
CVE-2006-5810
-
Medium
XOOPS Other Vulnerability (CVE-2007-0377)
CVE-2007-0377
-
High
XOOPS Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-4851)
CVE-2009-4851
CWE-264
Medium
XOOPS URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2017-12138)
CVE-2017-12138
CWE-601
Medium
XPath injection vulnerability
-
CWE-643
High
XSLT injection
-
CWE-91
High
XSS on Apache HTTP Server 413 error pages via malformed HTTP method
CVE-2007-6203
CWE-79
Medium
XWiki Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2022-41932)
CVE-2022-41932
CWE-770
Medium
XWiki Cleartext Storage of Sensitive Information Vulnerability (CVE-2023-50719)
CVE-2023-50719
CWE-312
High
XWiki Credentials Management Errors Vulnerability (CVE-2005-4862)
CVE-2005-4862
-
Medium
XWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-32730)
CVE-2021-32730
CWE-352
Medium
XWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-32732)
CVE-2021-32732
CWE-352
Medium
XWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2022-36095)
CVE-2022-36095
CWE-352
Medium
XWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2022-41927)
CVE-2022-41927
CWE-352
High
XWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-29213)
CVE-2023-29213
CWE-352
High
XWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-37277)
CVE-2023-37277
CWE-352
Critical
XWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-40572)
CVE-2023-40572
CWE-352
High
XWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-46242)
CVE-2023-46242
CWE-352
High
XWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-48293)
CVE-2023-48293
CWE-352
High
XWiki CVE-2007-4898 Vulnerability (CVE-2007-4898)
CVE-2007-4898
-
Low
XWiki CVE-2022-31166 Vulnerability (CVE-2022-31166)
CVE-2022-31166
-
High
XWiki CVE-2023-26471 Vulnerability (CVE-2023-26471)
CVE-2023-26471
-
High
XWiki CVE-2023-26473 Vulnerability (CVE-2023-26473)
CVE-2023-26473
-
Medium
XWiki CVE-2023-26474 Vulnerability (CVE-2023-26474)
CVE-2023-26474
-
High
XWiki CVE-2023-35166 Vulnerability (CVE-2023-35166)
CVE-2023-35166
-
High
XWiki CVE-2023-40573 Vulnerability (CVE-2023-40573)
CVE-2023-40573
-
High
XWiki CVE-2023-48241 Vulnerability (CVE-2023-48241)
CVE-2023-48241
-
High
XWiki CVE-2023-50720 Vulnerability (CVE-2023-50720)
CVE-2023-50720
-
Medium
XWiki Exposure of Private Personal Information to an Unauthorized Actor Vulnerability (CVE-2022-24819)
CVE-2022-24819
CWE-359
Medium
XWiki Exposure of Private Personal Information to an Unauthorized Actor Vulnerability (CVE-2022-41936)
CVE-2022-41936
CWE-359
High
XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-29203)
CVE-2023-29203
CWE-668
Medium
XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-29208)
CVE-2023-29208
CWE-668
High
XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-34467)
CVE-2023-34467
CWE-668
High
XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-35151)
CVE-2023-35151
CWE-668
High
XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-37911)
CVE-2023-37911
CWE-668
Medium
XWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-32731)
CVE-2021-32731
CWE-200
Medium
XWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2023-29517)
CVE-2023-29517
CWE-200
High
XWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2023-34466)
CVE-2023-34466
CWE-200
Medium
XWiki Files or Directories Accessible to External Parties Vulnerability (CVE-2022-23621)
CVE-2022-23621
CWE-552
Medium
XWiki Improper Access Control Vulnerability (CVE-2023-29513)
CVE-2023-29513
CWE-284
Medium
XWiki Improper Authentication Vulnerability (CVE-2022-36092)
CVE-2022-36092
CWE-287
High
XWiki Improper Authentication Vulnerability (CVE-2022-36093)
CVE-2022-36093
CWE-287
High
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2020-11057)
CVE-2020-11057
CWE-94
High
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2021-32621)
CVE-2021-32621
CWE-94
Medium
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-26477)
CVE-2023-26477
CWE-94
Critical
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-29209)
CVE-2023-29209
CWE-94
High
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-29210)
CVE-2023-29210
CWE-94
High
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-29211)
CVE-2023-29211
CWE-94
High
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-29212)
CVE-2023-29212
CWE-94
High
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-29214)
CVE-2023-29214
CWE-94
High
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-29509)
CVE-2023-29509
CWE-94
High
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-30537)
CVE-2023-30537
CWE-94
High
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-35150)
CVE-2023-35150
CWE-94
High
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-35152)
CVE-2023-35152
CWE-94
High
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-37909)
CVE-2023-37909
CWE-94
High
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-37914)
CVE-2023-37914
CWE-94
High
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-40177)
CVE-2023-40177
CWE-94
High
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-46243)
CVE-2023-46243
CWE-94
High
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-46731)
CVE-2023-46731
CWE-94
Critical
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-50721)
CVE-2023-50721
CWE-94
High
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-50723)
CVE-2023-50723
CWE-94
High
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-21650)
CVE-2024-21650
CWE-94
Critical
XWiki Improper Encoding or Escaping of Output Vulnerability (CVE-2020-13654)
CVE-2020-13654
CWE-116
High
XWiki Improper Encoding or Escaping of Output Vulnerability (CVE-2022-23620)
CVE-2022-23620
CWE-116
Medium
XWiki Improper Encoding or Escaping of Output Vulnerability (CVE-2022-36099)
CVE-2022-36099
CWE-116
High
XWiki Improper Encoding or Escaping of Output Vulnerability (CVE-2022-36100)
CVE-2022-36100
CWE-116
High
XWiki Improper Encoding or Escaping of Output Vulnerability (CVE-2022-41934)
CVE-2022-41934
CWE-116
High
«
1
...
316
317
318
...
322
»