🚀 Invicti Acquires Kondukto to Deliver Proof-Based Application Security Posture Management
100% Signal 0% Noise
Platform
Platform Overview
ASPM
APIÂ Security
DAST
SAST
SCA
Container Security
AI-Powered AppSec
Features
Solutions
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Cost Savings Calc
Live Training
Partners
Documentation
Get a demo
Web Application Vulnerabilities Index
This page lists
144
vulnerabilities categorized as medium severity that can be detected by Invicti.
Select Category
Critical
High
Medium
Low
Best Practice
Information
Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Vulnerability Name
Classification
Severity
Server-Side Request Forgery
Server-Side Request Forgery
Medium
Server-Side Request Forgery (Apache Server Status)
Server-Side Request Forgery (Apache Server Status)
High
Server-Side Request Forgery (AWS)
Server-Side Request Forgery (AWS)
High
Server-Side Request Forgery (elmah)
Server-Side Request Forgery (elmah)
High
Server-Side Request Forgery (elmah MVC)
Server-Side Request Forgery (elmah MVC)
High
Server-Side Request Forgery (Equinix)
Server-Side Request Forgery (Equinix)
Critical
Server-Side Request Forgery (MySQL)
Server-Side Request Forgery (MySQL)
High
Server-Side Request Forgery (Oracle Cloud)
Server-Side Request Forgery (Oracle Cloud)
Critical
Server-Side Request Forgery (Packet Cloud)
Server-Side Request Forgery (Packet Cloud)
Critical
Server-Side Request Forgery (SSH)
Server-Side Request Forgery (SSH)
High
Server-Side Request Forgery (Time Based)
Server-Side Request Forgery (Time Based)
Medium
Server-Side Request Forgery (trace.axd)
Server-Side Request Forgery (trace.axd)
Critical
Server-Side Template Injection
Server-Side Template Injection
Critical
Server-Side Template Injection (ASP.NET Razor)
Server-Side Template Injection (ASP.NET Razor)
Critical
Server-Side Template Injection (IAST)
Server-Side Template Injection (IAST)
High
Server-Side Template Injection (Java FreeMarker)
Server-Side Template Injection (Java FreeMarker)
Critical
Server-Side Template Injection (Java Pebble)
Server-Side Template Injection (Java Pebble)
Critical
Server-Side Template Injection (Java Velocity)
Server-Side Template Injection (Java Velocity)
Critical
Server-Side Template Injection (JinJava)
Server-Side Template Injection (JinJava)
Critical
Server-Side Template Injection (Node.js Dot)
Server-Side Template Injection (Node.js Dot)
Critical
Server-Side Template Injection (Node.js EJS)
Server-Side Template Injection (Node.js EJS)
Critical
Server-Side Template Injection (Ruby ERB)
Server-Side Template Injection (Ruby ERB)
Critical
Session Cookie Not Marked as Secure
Session Cookie Not Marked as Secure
Medium
SharePoint Identified
SharePoint Identified
Information
SharePoint "ToolShell" RCE (CVE-2025-49704/CVE-2025-49706/CVE-2025-53770/CVE-2025-53771)
SharePoint "ToolShell" RCE (CVE-2025-49704/CVE-2025-49706/CVE-2025-53770/CVE-2025-53771)
Critical
Shell Script Detected
Shell Script Detected
Information
Shopify Identified
Shopify Identified
Information
Silverlight Client Access Policy Detected
Silverlight Client Access Policy Detected
Information
Silverstripe CMS Detected
Silverstripe CMS Detected
Information
SimpleHelp Path Traversal (CVE-2024-57727)
SimpleHelp Path Traversal (CVE-2024-57727)
High
Sitecore Arbitrary File Read (CVE-2024-46938)
Sitecore Arbitrary File Read (CVE-2024-46938)
High
Sitecore XM/XP Insecure Deserialization (CVE-2025-27218)
Sitecore XM/XP Insecure Deserialization (CVE-2025-27218)
Critical
Sitemap Detected
Sitemap Detected
Information
Slick Identified
Slick Identified
Information
SnapSvg Identified
SnapSvg Identified
Information
Social Security Number Disclosure
Social Security Number Disclosure
Low
SonicWall SSL-VPN Server Identified
SonicWall SSL-VPN Server Identified
Information
Sortablejs Identified
Sortablejs Identified
Information
Source Code Disclosure (ASP.NET)
Source Code Disclosure (ASP.NET)
Medium
Source Code Disclosure (ColdFusion)
Source Code Disclosure (ColdFusion)
Medium
Source Code Disclosure (Generic)
Source Code Disclosure (Generic)
Medium
Source Code Disclosure (Java)
Source Code Disclosure (Java)
Medium
Source Code Disclosure (Java Servlet)
Source Code Disclosure (Java Servlet)
Medium
Source Code Disclosure (JSP)
Source Code Disclosure (JSP)
Medium
Source Code Disclosure (Perl)
Source Code Disclosure (Perl)
Medium
Source Code Disclosure (PHP)
Source Code Disclosure (PHP)
Medium
Source Code Disclosure (Python)
Source Code Disclosure (Python)
Medium
Source Code Disclosure (Ruby)
Source Code Disclosure (Ruby)
Medium
Source Code Disclosure (Tomcat)
Source Code Disclosure (Tomcat)
Medium
Spring Boot Actuator Endpoint Detected
Spring Boot Actuator Endpoint Detected
Medium
Spring Boot Misconfiguration: Actuator endpoint security disabled
Spring Boot Misconfiguration: Actuator endpoint security disabled
Medium
Spring Boot Misconfiguration: Admin MBean enabled
Spring Boot Misconfiguration: Admin MBean enabled
Medium
Spring Boot Misconfiguration: All Spring Boot Actuator endpoints are web exposed
Spring Boot Misconfiguration: All Spring Boot Actuator endpoints are web exposed
Medium
Spring Boot Misconfiguration: Datasource credentials stored in the properties file
Spring Boot Misconfiguration: Datasource credentials stored in the properties file
Medium
Spring Boot Misconfiguration: Developer tools enabled on production
Spring Boot Misconfiguration: Developer tools enabled on production
Medium
Spring Boot Misconfiguration: H2 console enabled
Spring Boot Misconfiguration: H2 console enabled
Medium
Spring Boot Misconfiguration: MongoDB credentials stored in the properties file
Spring Boot Misconfiguration: MongoDB credentials stored in the properties file
Medium
Spring Boot Misconfiguration: Overly long session timeout
Spring Boot Misconfiguration: Overly long session timeout
Medium
Spring Boot Misconfiguration: Spring Boot Actuator shutdown endpoint is web exposed
Spring Boot Misconfiguration: Spring Boot Actuator shutdown endpoint is web exposed
Medium
Spring Boot Misconfiguration: Unsafe value for session tracking
Spring Boot Misconfiguration: Unsafe value for session tracking
Medium
Spring Framework Identified
Spring Framework Identified
Information
Spring Misconfiguration: HTML Escaping disabled
Spring Misconfiguration: HTML Escaping disabled
Medium
SQL File Detected
SQL File Detected
Information
SQL Injection
SQL Injection
Critical
SQL Injection (IAST)
SQL Injection (IAST)
Critical
SQLite Database File Found
SQLite Database File Found
Medium
Squarespace Identified
Squarespace Identified
Information
Squid Identified
Squid Identified
Information
SSL Certificate Is About To Expire
SSL Certificate Is About To Expire
Medium
SSL Certificate Name Hostname Mismatch
SSL Certificate Name Hostname Mismatch
Medium
SSL/TLS Not Implemented
SSL/TLS Not Implemented
Medium
SSL Untrusted Root Certificate
SSL Untrusted Root Certificate
Medium
Stack Trace Disclosure (Apache MyFaces)
Stack Trace Disclosure (Apache MyFaces)
Low
Stack Trace Disclosure (Apache Shiro)
Stack Trace Disclosure (Apache Shiro)
Low
1