🚀 Just released:
Latio 2026 Application Security Market Report.
Read it in our Whitepapers.
100% Signal 0% Noise
Platform
Invicti Platform
Zero-noise AppSec platform
Scan Code
Secure code before runtime
SAST
Early static security analysis
Open Source (SCA)
Find vulnerable dependencies
SBOM & License Risk
Generate SBOMs and track licenses
Secrets
Detect exposed secrets in applications
Infrastructure as Code
Ingest IaC security findings
Container
Track container image vulnerabilities
Test Runtime
Test live applications like attackers
DAST & AI DAST
Test runtime, prove exploitability
Agentic Pentesting
Automate real-world attack techniques
API Security Testing
Discover and test APIs
Attack Surface Management
Identify exposed apps and endpoints
Cloud AppSec
Get a single-pane view of cloud app risk
AI AppSec
Scan smarter, accelerate remediation
Manage Vulnerabilities
See, prioritize, reduce AppSec risk
Vulnerability Management (ASPM)
Centralize and correlate AppSec findings
Compliance & Executive Reporting
Measure risk and impact
Threat Intelligence
Reachability, exploitability, and business logic
Solutions
API Discovery
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Invicti vs. Competitors
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Savings Calculator
Live Training
Partners
MSSP
Documentation
Get a demo
Web Application Vulnerabilities Index
This page lists
144
vulnerabilities categorized as medium severity that can be detected by Invicti.
Select Category
Critical
High
Medium
Low
Best Practice
Information
Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Vulnerability Name
Classification
Severity
Out-of-date Version (YOURLS)
Out-of-date Version (YOURLS)
CAPEC-310
,Â
CWE-1035
,Â
HIPAA-164.308(a)(1)(i)
,Â
ISO27001-A.14.1.2
,Â
OWASP 2013-A9
,Â
OWASP 2017-A9
,Â
PCI v3.2-6.2
,Â
Information
Out-of-date Version (YUI)
Out-of-date Version (YUI)
CAPEC-310
,Â
CWE-1035
,Â
HIPAA-164.308(a)(1)(i)
,Â
ISO27001-A.14.1.2
,Â
OWASP 2013-A9
,Â
OWASP 2017-A9
,Â
PCI v3.2-6.2
,Â
Information
Out-of-date Version (Zen Cart)
Out-of-date Version (Zen Cart)
CAPEC-310
,Â
CWE-1035
,Â
HIPAA-164.308(a)(1)(i)
,Â
ISO27001-A.14.1.2
,Â
OWASP 2013-A9
,Â
OWASP 2017-A9
,Â
PCI v3.2-6.2
,Â
Information
Out-of-date Version (ZenPhoto)
Out-of-date Version (ZenPhoto)
CAPEC-310
,Â
CWE-1035
,Â
HIPAA-164.308(a)(1)(i)
,Â
ISO27001-A.14.1.2
,Â
OWASP 2013-A9
,Â
OWASP 2017-A9
,Â
PCI v3.2-6.2
,Â
Information
Out-of-date Version (Zepto.js)
Out-of-date Version (Zepto.js)
CAPEC-310
,Â
CWE-1035
,Â
HIPAA-164.308(a)(1)(i)
,Â
ISO27001-A.14.1.2
,Â
OWASP 2013-A9
,Â
OWASP 2017-A9
,Â
PCI v3.2-6.2
,Â
Information
Out-of-date Version (Zikula)
Out-of-date Version (Zikula)
CAPEC-310
,Â
CWE-1035
,Â
HIPAA-164.308(a)(1)(i)
,Â
ISO27001-A.14.1.2
,Â
OWASP 2013-A9
,Â
OWASP 2017-A9
,Â
PCI v3.2-6.2
,Â
Information
Out-of-date Version (Zope)
Out-of-date Version (Zope)
CAPEC-310
,Â
CWE-1035
,Â
HIPAA-164.308(a)(1)(i)
,Â
ISO27001-A.14.1.2
,Â
OWASP 2013-A9
,Â
OWASP 2017-A9
,Â
PCI v3.2-6.2
,Â
Information
Out-of-date Version (Zurmo)
Out-of-date Version (Zurmo)
CAPEC-310
,Â
CWE-1035
,Â
HIPAA-164.308(a)(1)(i)
,Â
ISO27001-A.14.1.2
,Â
OWASP 2013-A9
,Â
OWASP 2017-A9
,Â
PCI v3.2-6.2
,Â
Information
Overly Long Session Timeout
Overly Long Session Timeout
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
,Â
CWE-16
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Medium
ownCloud Detected
ownCloud Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Palo Alto PAN-OS Management Interface Auth Bypass (CVE-2024-0012/CVE-2024-9474)
Palo Alto PAN-OS Management Interface Auth Bypass (CVE-2024-0012/CVE-2024-9474)
CWE-CWE-306
,Â
Critical
PAN-OS GlobalProtect XSS (CVE-2025-0133)
PAN-OS GlobalProtect XSS (CVE-2025-0133)
CWE-CWE-79
,Â
Medium
PAN-OS Management Interface Authentication Bypass (CVE-2025-0108)
PAN-OS Management Interface Authentication Bypass (CVE-2025-0108)
CWE-CWE-287
,Â
Critical
Pardot Server Identified
Pardot Server Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Passive Mixed Content over HTTPS
Passive Mixed Content over HTTPS
CWE-319
,Â
ISO27001-A.14.1.3
,Â
OWASP 2013-A6
,Â
OWASP 2017-A3
,Â
Low
Passive Web Backdoor Detected
Passive Web Backdoor Detected
CWE-507
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.12.2.1
,Â
OWASP 2017-A10
,Â
PCI v3.2-6.5.6
,Â
Low
Password Transmitted over HTTP
Password Transmitted over HTTP
CAPEC-65
,Â
CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
,Â
CWE-319
,Â
ISO27001-A.14.1.3
,Â
OWASP 2013-A6
,Â
OWASP 2017-A3
,Â
PCI v3.2-6.5.4
,Â
WASC-4
,Â
High
Password Transmitted over Query String
Password Transmitted over Query String
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
,Â
CWE-598
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A6
,Â
OWASP 2017-A3
,Â
PCI v3.2-6.5.4
,Â
WASC-13
,Â
Medium
Payara Identified
Payara Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
PdfJs Identified
PdfJs Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Pega Identified
Pega Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Perl Identified
Perl Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
pH7CMS Detected
pH7CMS Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Phaser Identified
Phaser Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Phishing by Navigating Browser Tabs
Phishing by Navigating Browser Tabs
CWE-16
,Â
ISO27001-A.14.1.2
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-15
,Â
Low
Phorum Detected
Phorum Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Php Address Book Detected
Php Address Book Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
PHP allow_url_fopen Is Enabled
PHP allow_url_fopen Is Enabled
CWE-16
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Low
PHP allow_url_include Is Enabled
PHP allow_url_include Is Enabled
CWE-16
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Low
phpBB Detected
phpBB Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
PHP display_errors Is Enabled
PHP display_errors Is Enabled
CWE-211
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Low
PHP enable_dl Is Enabled
PHP enable_dl Is Enabled
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
,Â
CWE-16
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Medium
PhpFusion Detected
PhpFusion Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
PHP Identified
PHP Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
phpinfo() Output Detected
phpinfo() Output Detected
CWE-213
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A6
,Â
OWASP 2017-A3
,Â
WASC-13
,Â
Low
phpList Detected
phpList Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
phpLiteAdmin Detected
phpLiteAdmin Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
PHP magic_quotes_gpc Is Disabled
PHP magic_quotes_gpc Is Disabled
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
,Â
CWE-16
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Medium
phpMoAdmin Detected
phpMoAdmin Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
phpMyAdmin Detected
phpMyAdmin Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
PhpMyFAQ Detected
PhpMyFAQ Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
PHP open_basedir Is Not Configured
PHP open_basedir Is Not Configured
CWE-16
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Low
PHP register_globals Is Enabled
PHP register_globals Is Enabled
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
,Â
CWE-473
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Medium
PHP session.use_only_cookies Is Disabled
PHP session.use_only_cookies Is Disabled
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
,Â
CWE-598
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Medium
PHP session.use_trans_sid Is Enabled
PHP session.use_trans_sid Is Enabled
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
,Â
CWE-598
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Medium
Phusion Passenger Identified
Phusion Passenger Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Piwigo Detected
Piwigo Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Piwik Detected
Piwik Detected
CAPEC-224
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-45
,Â
Information
PixiJs Identified
PixiJs Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Play Web Framework Identified
Play Web Framework Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Plesk (Linux) Identified
Plesk (Linux) Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Plesk (Windows) Identified
Plesk (Windows) Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Plone CMS Identified
Plone CMS Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Plupload Identified
Plupload Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
PmWiki Detected
PmWiki Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Podcast Generator Detected
Podcast Generator Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Polyfill.io Supply Chain Attack
Polyfill.io Supply Chain Attack
No items found.
High
Polymer Identified
Polymer Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Popper.js Identified
Popper.js Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
PossibleBlindMongoDB
PossibleBlindMongoDB
CAPEC-66
,Â
CWE-89
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
PCI v3.2-6.5.1
,Â
WASC-19
,Â
Critical
Possible Boolean Mongo Db Injection
Possible Boolean Mongo Db Injection
CAPEC-66
,Â
CWE-89
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
PCI v3.2-6.5.1
,Â
WASC-19
,Â
Critical
PrestaShop Detected
PrestaShop Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
PrettyPhoto Identified
PrettyPhoto Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Private Burp Collaborator Server Identified
Private Burp Collaborator Server Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Private Json Web Key Set Disclosure
Private Json Web Key Set Disclosure
CAPEC-118
,Â
CWE-200
,Â
ISO27001-A.18.1.4
,Â
WASC-13
,Â
Critical
Programming Error Message
Programming Error Message
CAPEC-118
,Â
CWE-210
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.5
,Â
WASC-13
,Â
Low
Programming Error Message (Ruby)
Programming Error Message (Ruby)
CAPEC-118
,Â
CWE-210
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.5
,Â
WASC-13
,Â
Low
Progress MOVEit Transfer SQL Injection
Progress MOVEit Transfer SQL Injection
CAPEC-66
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
CWE-89
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
PCI v3.2-6.5.1
,Â
WASC-19
,Â
High
ProjectSend Detected
ProjectSend Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Prototypejs Identified
Prototypejs Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Prototype Pollution
Prototype Pollution
CAPEC-180
,Â
CWE-1321
,Â
HIPAA-164.306(a)
,Â
ISO27001-A.13.1.3
,Â
OWASP 2013-A9
,Â
OWASP 2017-A9
,Â
PCI v3.2-6.5.7
,Â
Information
Python Identified
Python Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Python WSGIserver Identified
Python WSGIserver Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
qdPM Detected
qdPM Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
1