🚀 Just released:
Latio 2026 Application Security Market Report.
Read it in our Whitepapers.
100% Signal 0% Noise
Platform
Invicti Platform
Zero-noise AppSec platform
Scan Code
Secure code before runtime
SAST
Early static security analysis
Open Source (SCA)
Find vulnerable dependencies
SBOM & License Risk
Generate SBOMs and track licenses
Secrets
Detect exposed secrets in applications
Infrastructure as Code
Ingest IaC security findings
Container
Track container image vulnerabilities
Test Runtime
Test live applications like attackers
DAST & AI DAST
Test runtime, prove exploitability
Agentic Pentesting
Automate real-world attack techniques
API Security Testing
Discover and test APIs
Attack Surface Management
Identify exposed apps and endpoints
Cloud AppSec
Get a single-pane view of cloud app risk
AI AppSec
Scan smarter, accelerate remediation
Manage Vulnerabilities
See, prioritize, reduce AppSec risk
Vulnerability Management (ASPM)
Centralize and correlate AppSec findings
Compliance & Executive Reporting
Measure risk and impact
Threat Intelligence
Reachability, exploitability, and business logic
Solutions
API Discovery
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Invicti vs. Competitors
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Savings Calculator
Live Training
Partners
MSSP
Documentation
Get a demo
Web Application Vulnerabilities Index
This page lists
144
vulnerabilities categorized as medium severity that can be detected by Invicti.
Select Category
Critical
High
Medium
Low
Best Practice
Information
Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Vulnerability Name
Classification
Severity
Fortigate SSL VPN Arbitrary File reading (CVE-2018-13379)
Fortigate SSL VPN Arbitrary File reading (CVE-2018-13379)
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
,Â
CWE-22
,Â
High
FortiWeb Authentication Bypass (CVE-2025-64446)
FortiWeb Authentication Bypass (CVE-2025-64446)
CWE-CWE-23
,Â
Critical
Foundation Identified
Foundation Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Frame Injection
Frame Injection
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
,Â
CWE-601
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
PCI v3.2-6.5.1
,Â
WASC-38
,Â
Medium
Front Accounting Detected
Front Accounting Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
FrontPage Identified
FrontPage Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
FuelUx Identified
FuelUx Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Generic Email Address Disclosure
Generic Email Address Disclosure
CAPEC-118
,Â
CWE-200
,Â
ISO27001-A.18.1.4
,Â
WASC-13
,Â
Information
GeoServer Identified
GeoServer Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
GibbonEdu Detected
GibbonEdu Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
GIT Detected
GIT Detected
CAPEC-118
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
,Â
CWE-527
,Â
ISO27001-A.9.4.5
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Medium
GlassFish Server Identified
GlassFish Server Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Google Tag Manager Identified
Google Tag Manager Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Grafana Identified
Grafana Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Grafana Open Redirect (CVE-2025-4123)
Grafana Open Redirect (CVE-2025-4123)
CWE-CWE-601
,Â
High
GraphiQL Explorer/Playground Enabled
GraphiQL Explorer/Playground Enabled
AV:N/AC:L/Au:N/C:P/I:N/A:N
,Â
CWE-CWE-200
,Â
Medium
GraphQL Alias Overloading Allowed: Potential Denial of Service Vulnerability
GraphQL Alias Overloading Allowed: Potential Denial of Service Vulnerability
AV:N/AC:L/Au:N/C:N/I:N/A:P
,Â
CWE-CWE-400
,Â
Medium
GraphQL Array-based Query Batching Allowed: Potential Batching Attack Vulnerability
GraphQL Array-based Query Batching Allowed: Potential Batching Attack Vulnerability
AV:N/AC:L/Au:N/C:P/I:P/A:P
,Â
CWE-CWE-770
,Â
Medium
GraphQL Circular-Query via Introspection Allowed: Potential DoS Vulnerability
GraphQL Circular-Query via Introspection Allowed: Potential DoS Vulnerability
AV:N/AC:L/Au:N/C:N/I:N/A:P
,Â
CWE-CWE-400
,Â
Medium
GraphQL Endpoint Detected
GraphQL Endpoint Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
GraphQL Field Suggestions Enabled
GraphQL Field Suggestions Enabled
AV:N/AC:L/Au:N/C:P/I:N/A:N
,Â
CWE-CWE-200
,Â
Medium
GraphQL Introspection Query Enabled
GraphQL Introspection Query Enabled
AV:N/AC:L/Au:N/C:P/I:N/A:N
,Â
CWE-CWE-200
,Â
Medium
GraphQL Library Detected (Apollo)
GraphQL Library Detected (Apollo)
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
GraphQL Library Detected (Ariadne)
GraphQL Library Detected (Ariadne)
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
GraphQL Library Detected (Dgraph)
GraphQL Library Detected (Dgraph)
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
GraphQL Library Detected (Diana.jl)
GraphQL Library Detected (Diana.jl)
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
GraphQL Library Detected (Directus)
GraphQL Library Detected (Directus)
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
GraphQL Library Detected (GqlGen)
GraphQL Library Detected (GqlGen)
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
GraphQL Library Detected (Graphene)
GraphQL Library Detected (Graphene)
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
GraphQL Library Detected (GraphQL API for Wordpress)
GraphQL Library Detected (GraphQL API for Wordpress)
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
GraphQL Library Detected (Graphql-Go)
GraphQL Library Detected (Graphql-Go)
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
GraphQL Library Detected (graphql-java)
GraphQL Library Detected (graphql-java)
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
GraphQL Library Detected (graphql-php)
GraphQL Library Detected (graphql-php)
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
GraphQL Library Detected (Hasura)
GraphQL Library Detected (Hasura)
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
GraphQL Library Detected (Hot Chocolate)
GraphQL Library Detected (Hot Chocolate)
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
GraphQL Library Detected (Juniper)
GraphQL Library Detected (Juniper)
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
GraphQL Library Detected (Ruby-graphql)
GraphQL Library Detected (Ruby-graphql)
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
GraphQL Library Detected (Sangria)
GraphQL Library Detected (Sangria)
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
GraphQL Library Detected (Tartiflette)
GraphQL Library Detected (Tartiflette)
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
GraphQL Library Detected (WPGraphQL)
GraphQL Library Detected (WPGraphQL)
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
GraphQL Non-JSON Mutations over GET: Potential CSRF Vulnerability
GraphQL Non-JSON Mutations over GET: Potential CSRF Vulnerability
AV:N/AC:M/Au:N/C:P/I:P/A:N
,Â
CWE-CWE-352
,Â
Medium
GraphQL Non-JSON Queries over GET: Potential CSRF Vulnerability
GraphQL Non-JSON Queries over GET: Potential CSRF Vulnerability
AV:N/AC:M/Au:N/C:P/I:P/A:N
,Â
CWE-CWE-352
,Â
Medium
GraphQL Non-JSON Queries over POST: Potential CSRF Vulnerability
GraphQL Non-JSON Queries over POST: Potential CSRF Vulnerability
AV:N/AC:M/Au:N/C:P/I:P/A:N
,Â
CWE-CWE-352
,Â
Medium
GraphQL Unauthenticated Mutation Detected
GraphQL Unauthenticated Mutation Detected
AV:N/AC:L/Au:N/C:P/I:N/A:N
,Â
CWE-CWE-306
,Â
Medium
GraphQL Unhandled Error Leakage
GraphQL Unhandled Error Leakage
AV:N/AC:L/Au:N/C:P/I:N/A:N
,Â
CWE-CWE-209
,Â
Medium
Gsap Identified
Gsap Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Gunicorn Python WSGI HTTP Server Identified
Gunicorn Python WSGI HTTP Server Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Hammerjs Identified
Hammerjs Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Handlebarsjs Identified
Handlebarsjs Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Hesk Detected
Hesk Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Hiawatha Identified
Hiawatha Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Highcharts Identified
Highcharts Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
.htaccess File Detected
.htaccess File Detected
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
,Â
CWE-285
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Information
Html5Shiv Identified
Html5Shiv Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
HTTP Header Injection
HTTP Header Injection
CAPEC-105
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
,Â
CWE-93
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
PCI v3.2-6.5.1
,Â
WASC-24
,Â
Medium
HTTP Header Injection (IAST)
HTTP Header Injection (IAST)
CAPEC-105
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
,Â
CWE-93
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
PCI v3.2-6.5.1
,Â
WASC-24
,Â
Medium
HTTP Parameter Pollution
HTTP Parameter Pollution
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
,Â
CWE-88
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
Medium
HTTP Strict Transport Security (HSTS) Errors and Warnings
HTTP Strict Transport Security (HSTS) Errors and Warnings
CWE-16
,Â
ISO27001-A.14.1.2
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-15
,Â
Medium
HTTP Strict Transport Security (HSTS) Max-Age Value Too Low
HTTP Strict Transport Security (HSTS) Max-Age Value Too Low
CWE-16
,Â
ISO27001-A.14.1.2
,Â
WASC-15
,Â
Information
HTTP Strict Transport Security (HSTS) Policy Not Enabled
HTTP Strict Transport Security (HSTS) Policy Not Enabled
CAPEC-217
,Â
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
,Â
CWE-523
,Â
ISO27001-A.14.1.2
,Â
OWASP 2013-A6
,Â
OWASP 2017-A3
,Â
WASC-4
,Â
Medium
HTTP Strict Transport Security (HSTS) via HTTP
HTTP Strict Transport Security (HSTS) via HTTP
CWE-16
,Â
ISO27001-A.14.1.2
,Â
OWASP 2017-A6
,Â
WASC-15
,Â
Information
HubSpot Identified
HubSpot Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
IBM Business Process Manager (BPM) Identified
IBM Business Process Manager (BPM) Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
IBM HTTP Server Identified
IBM HTTP Server Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
IBM Rational Team Concert (RTC) Identified
IBM Rational Team Concert (RTC) Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
IBM Security Access Manager (WebSEAL) Identified
IBM Security Access Manager (WebSEAL) Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
IIS Identified
IIS Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
ImagePicker Identified
ImagePicker Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
I'm a Teapot
I'm a Teapot
ISO27001-None
,Â
Information
Incorrect Content Security Policy (CSP) Implementation
Incorrect Content Security Policy (CSP) Implementation
CWE-16
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-15
,Â
Information
Inferno Identified
Inferno Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Information Disclosure (Microsoft Office)
Information Disclosure (Microsoft Office)
CAPEC-118
,Â
CWE-200
,Â
ISO27001-A.18.1.3
,Â
PCI v3.2-6.5.5
,Â
WASC-13
,Â
Low
Insecure Frame (External)
Insecure Frame (External)
CWE-16
,Â
ISO27001-A.14.1.2
,Â
OWASP 2017-A6
,Â
WASC-15
,Â
Low
Insecure HTTP Usage
Insecure HTTP Usage
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
,Â
ISO27001-A.14.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A3
,Â
WASC-4
,Â
Medium
1