🚀 Invicti Acquires Kondukto to Deliver Proof-Based Application Security Posture Management
100% Signal 0% Noise
Platform
Platform Overview
ASPM
APIÂ Security
DAST
SAST
SCA
Container Security
AI-Powered AppSec
Features
Solutions
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Cost Savings Calc
Live Training
Partners
Documentation
Get a demo
Web Application Vulnerabilities Index
This page lists
144
vulnerabilities categorized as medium severity that can be detected by Invicti.
Select Category
Critical
High
Medium
Low
Best Practice
Information
Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Vulnerability Name
Classification
Severity
GibbonEdu Detected
GibbonEdu Detected
Information
GIT Detected
GIT Detected
Medium
GlassFish Server Identified
GlassFish Server Identified
Information
Google Tag Manager Identified
Google Tag Manager Identified
Information
Grafana Identified
Grafana Identified
Information
Grafana Open Redirect (CVE-2025-4123)
Grafana Open Redirect (CVE-2025-4123)
High
GraphiQL Explorer/Playground Enabled
GraphiQL Explorer/Playground Enabled
Medium
GraphQL Alias Overloading Allowed: Potential Denial of Service Vulnerability
GraphQL Alias Overloading Allowed: Potential Denial of Service Vulnerability
Medium
GraphQL Array-based Query Batching Allowed: Potential Batching Attack Vulnerability
GraphQL Array-based Query Batching Allowed: Potential Batching Attack Vulnerability
Medium
GraphQL Circular-Query via Introspection Allowed: Potential DoS Vulnerability
GraphQL Circular-Query via Introspection Allowed: Potential DoS Vulnerability
Medium
GraphQL Endpoint Detected
GraphQL Endpoint Detected
Information
GraphQL Field Suggestions Enabled
GraphQL Field Suggestions Enabled
Medium
GraphQL Introspection Query Enabled
GraphQL Introspection Query Enabled
Medium
GraphQL Library Detected (Apollo)
GraphQL Library Detected (Apollo)
Information
GraphQL Library Detected (Ariadne)
GraphQL Library Detected (Ariadne)
Information
GraphQL Library Detected (Dgraph)
GraphQL Library Detected (Dgraph)
Information
GraphQL Library Detected (Diana.jl)
GraphQL Library Detected (Diana.jl)
Information
GraphQL Library Detected (Directus)
GraphQL Library Detected (Directus)
Information
GraphQL Library Detected (GqlGen)
GraphQL Library Detected (GqlGen)
Information
GraphQL Library Detected (Graphene)
GraphQL Library Detected (Graphene)
Information
GraphQL Library Detected (GraphQL API for Wordpress)
GraphQL Library Detected (GraphQL API for Wordpress)
Information
GraphQL Library Detected (Graphql-Go)
GraphQL Library Detected (Graphql-Go)
Information
GraphQL Library Detected (graphql-java)
GraphQL Library Detected (graphql-java)
Information
GraphQL Library Detected (graphql-php)
GraphQL Library Detected (graphql-php)
Information
GraphQL Library Detected (Hasura)
GraphQL Library Detected (Hasura)
Information
GraphQL Library Detected (Hot Chocolate)
GraphQL Library Detected (Hot Chocolate)
Information
GraphQL Library Detected (Juniper)
GraphQL Library Detected (Juniper)
Information
GraphQL Library Detected (Ruby-graphql)
GraphQL Library Detected (Ruby-graphql)
Information
GraphQL Library Detected (Sangria)
GraphQL Library Detected (Sangria)
Information
GraphQL Library Detected (Tartiflette)
GraphQL Library Detected (Tartiflette)
Information
GraphQL Library Detected (WPGraphQL)
GraphQL Library Detected (WPGraphQL)
Information
GraphQL Non-JSON Mutations over GET: Potential CSRF Vulnerability
GraphQL Non-JSON Mutations over GET: Potential CSRF Vulnerability
Medium
GraphQL Non-JSON Queries over GET: Potential CSRF Vulnerability
GraphQL Non-JSON Queries over GET: Potential CSRF Vulnerability
Medium
GraphQL Non-JSON Queries over POST: Potential CSRF Vulnerability
GraphQL Non-JSON Queries over POST: Potential CSRF Vulnerability
Medium
GraphQL Unauthenticated Mutation Detected
GraphQL Unauthenticated Mutation Detected
Medium
GraphQL Unhandled Error Leakage
GraphQL Unhandled Error Leakage
Medium
Gsap Identified
Gsap Identified
Information
Gunicorn Python WSGI HTTP Server Identified
Gunicorn Python WSGI HTTP Server Identified
Information
Hammerjs Identified
Hammerjs Identified
Information
Handlebarsjs Identified
Handlebarsjs Identified
Information
Hesk Detected
Hesk Detected
Information
Hiawatha Identified
Hiawatha Identified
Information
Highcharts Identified
Highcharts Identified
Information
.htaccess File Detected
.htaccess File Detected
Information
Html5Shiv Identified
Html5Shiv Identified
Information
HTTP Header Injection
HTTP Header Injection
Medium
HTTP Header Injection (IAST)
HTTP Header Injection (IAST)
Medium
HTTP Strict Transport Security (HSTS) Errors and Warnings
HTTP Strict Transport Security (HSTS) Errors and Warnings
Medium
HTTP Strict Transport Security (HSTS) Max-Age Value Too Low
HTTP Strict Transport Security (HSTS) Max-Age Value Too Low
Information
HTTP Strict Transport Security (HSTS) Policy Not Enabled
HTTP Strict Transport Security (HSTS) Policy Not Enabled
Medium
HTTP Strict Transport Security (HSTS) via HTTP
HTTP Strict Transport Security (HSTS) via HTTP
Information
HubSpot Identified
HubSpot Identified
Information
IBM Business Process Manager (BPM) Identified
IBM Business Process Manager (BPM) Identified
Information
IBM HTTP Server Identified
IBM HTTP Server Identified
Information
IBM Rational Team Concert (RTC) Identified
IBM Rational Team Concert (RTC) Identified
Information
IBM Security Access Manager (WebSEAL) Identified
IBM Security Access Manager (WebSEAL) Identified
Information
IIS Identified
IIS Identified
Information
ImagePicker Identified
ImagePicker Identified
Information
I'm a Teapot
I'm a Teapot
Information
Incorrect Content Security Policy (CSP) Implementation
Incorrect Content Security Policy (CSP) Implementation
Information
Inferno Identified
Inferno Identified
Information
Information Disclosure (Microsoft Office)
Information Disclosure (Microsoft Office)
Low
Insecure Frame (External)
Insecure Frame (External)
Low
Insecure HTTP Usage
Insecure HTTP Usage
Medium
Insecure JSONP Endpoint
Insecure JSONP Endpoint
Low
Insecure Protocol Detected in Content Security Policy (CSP)
Insecure Protocol Detected in Content Security Policy (CSP)
Information
Insecure Reflected Content
Insecure Reflected Content
Low
Insecure Transportation Security Protocol Supported (SSLv2)
Insecure Transportation Security Protocol Supported (SSLv2)
High
Insecure Transportation Security Protocol Supported (SSLv3)
Insecure Transportation Security Protocol Supported (SSLv3)
High
Insecure Transportation Security Protocol Supported (TLS 1.0)
Insecure Transportation Security Protocol Supported (TLS 1.0)
High
Insecure Transportation Security Protocol Supported (TLS 1.1)
Insecure Transportation Security Protocol Supported (TLS 1.1)
Low
Insecure Usage of Version 1 GUID
Insecure Usage of Version 1 GUID
Information
Installation File Detected
Installation File Detected
Information
Intermediate Certificate is Signed Using a Weak Signature Algorithm
Intermediate Certificate is Signed Using a Weak Signature Algorithm
Information
1