🚀 Just released:
Latio 2026 Application Security Market Report.
Read it in our Whitepapers.
100% Signal 0% Noise
Platform
Invicti Platform
Zero-noise AppSec platform
Scan Code
Secure code before runtime
SAST
Early static security analysis
Open Source (SCA)
Find vulnerable dependencies
SBOM & License Risk
Generate SBOMs and track licenses
Secrets
Detect exposed secrets in applications
Infrastructure as Code
Ingest IaC security findings
Container
Track container image vulnerabilities
Test Runtime
Test live applications like attackers
DAST & AI DAST
Test runtime, prove exploitability
Agentic Pentesting
Automate real-world attack techniques
API Security Testing
Discover and test APIs
Attack Surface Management
Identify exposed apps and endpoints
Cloud AppSec
Get a single-pane view of cloud app risk
AI AppSec
Scan smarter, accelerate remediation
Manage Vulnerabilities
See, prioritize, reduce AppSec risk
Vulnerability Management (ASPM)
Centralize and correlate AppSec findings
Compliance & Executive Reporting
Measure risk and impact
Threat Intelligence
Reachability, exploitability, and business logic
Solutions
API Discovery
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Invicti vs. Competitors
Case Studies
Contact Us
Careers
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Savings Calculator
Live Training
Partners
MSSP
Documentation
Get a demo
Web Application Vulnerabilities Index
This page lists
144
vulnerabilities categorized as medium severity that can be detected by Invicti.
Select Category
Critical
High
Medium
Low
Best Practice
Information
Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Vulnerability Name
Classification
Severity
Web.config File Detected
Web.config File Detected
CAPEC-87
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-285
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A7
,Â
OWASP 2017-A5
,Â
WASC-34
,Â
Information
WebDAV Directory Has Write Permissions (IIS)
WebDAV Directory Has Write Permissions (IIS)
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:H/RL:O/RC:C
,Â
CWE-732
,Â
ISO27001-A.9.4.1
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.8
,Â
WASC-17
,Â
High
WebDAV Enabled
WebDAV Enabled
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:H/RL:O/RC:C
,Â
CWE-16
,Â
ISO27001-A.9.4.4
,Â
WASC-15
,Â
Information
webERP Detected
webERP Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
WeBid Detected
WeBid Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
WebLogic Identified
WebLogic Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Werkzeug Python WSGI Library Identified
Werkzeug Python WSGI Library Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Whoops Error Handler Framework Detected
Whoops Error Handler Framework Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Wildcard Detected in Domain Portion of Content Security Policy (CSP) Directive
Wildcard Detected in Domain Portion of Content Security Policy (CSP) Directive
ISO27001-A.14.2.5
,Â
Information
Wildcard Detected in Port Portion of Content Security Policy (CSP) Directive
Wildcard Detected in Port Portion of Content Security Policy (CSP) Directive
ISO27001-A.14.2.5
,Â
Information
Wildcard Detected in Scheme Portion of Content Security Policy (CSP) Directive
Wildcard Detected in Scheme Portion of Content Security Policy (CSP) Directive
ISO27001-A.14.2.5
,Â
Information
WildFly Application Server Identified
WildFly Application Server Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Windows Azure Web Server Identified
Windows Azure Web Server Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Windows CE OS Identified
Windows CE OS Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Windows Server Identified
Windows Server Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Windows Short Filename
Windows Short Filename
CAPEC-87
,Â
CWE-538
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.8.2.3
,Â
OWASP 2013-A7
,Â
OWASP 2017-A6
,Â
PCI v3.2-6.5.8
,Â
WASC-34
,Â
Low
Windows Username Disclosure
Windows Username Disclosure
CAPEC-118
,Â
CWE-200
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A6
,Â
OWASP 2017-A3
,Â
PCI v3.2-6.5.5
,Â
WASC-13
,Â
Low
Wing FTP Anonymous access
Wing FTP Anonymous access
CWE-CWE-200
,Â
Low
Wing FTP Server RCE (CVE-2025-47812)
Wing FTP Server RCE (CVE-2025-47812)
CWE-CWE-158
,Â
Critical
WordPress Configuration File Detected
WordPress Configuration File Detected
CAPEC-87
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
,Â
CWE-425
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A7
,Â
OWASP 2017-A5
,Â
PCI v3.2-6.5.8
,Â
WASC-34
,Â
Information
WordPress Detected
WordPress Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
WordPress Plugin Advanced Custom Fields Extended Identified
WordPress Plugin Advanced Custom Fields Extended Identified
No items found.
Information
WordPress Plugin Advanced Custom Fields Extended Out Of Date
WordPress Plugin Advanced Custom Fields Extended Out Of Date
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
WordPress Plugin Advanced Custom Fields Extended Version Disclosure
WordPress Plugin Advanced Custom Fields Extended Version Disclosure
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
WordPress Plugin Akismet Spam Protection Out Of Date
WordPress Plugin Akismet Spam Protection Out Of Date
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
WordPress Plugin Akismet Spam Protection Version Disclosure
WordPress Plugin Akismet Spam Protection Version Disclosure
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
WordPress Plugin Akismet Spam Protector Identified
WordPress Plugin Akismet Spam Protector Identified
No items found.
Information
WordPress Plugin All In One WP Migration Identified
WordPress Plugin All In One WP Migration Identified
No items found.
Information
WordPress Plugin All-in-One WP Migration Out Of Date
WordPress Plugin All-in-One WP Migration Out Of Date
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
WordPress Plugin All-in-One WP Migration Version Disclosure
WordPress Plugin All-in-One WP Migration Version Disclosure
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
WordPress Plugin Backup Migration Identified
WordPress Plugin Backup Migration Identified
No items found.
Information
WordPress Plugin Backup Migration Out Of Date
WordPress Plugin Backup Migration Out Of Date
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
WordPress Plugin Backup Migration Version Disclosure
WordPress Plugin Backup Migration Version Disclosure
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
WordPress Plugin Classic Editor Identified
WordPress Plugin Classic Editor Identified
No items found.
Information
WordPress Plugin Classic Editor Out Of Date
WordPress Plugin Classic Editor Out Of Date
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
WordPress Plugin Classic Editor Version Disclosure
WordPress Plugin Classic Editor Version Disclosure
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
WordPress Plugin Contact Form 7 Identified
WordPress Plugin Contact Form 7 Identified
No items found.
Information
WordPress Plugin Contact Form 7 Out Of Date
WordPress Plugin Contact Form 7 Out Of Date
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
WordPress Plugin Contact Form 7 Version Disclosure
WordPress Plugin Contact Form 7 Version Disclosure
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
WordPress Plugin Contact Form by WPForms Identified
WordPress Plugin Contact Form by WPForms Identified
No items found.
Information
WordPress Plugin Contact Form by WPForms Out Of Date
WordPress Plugin Contact Form by WPForms Out Of Date
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
WordPress Plugin Contact Form by WPForms Version Disclosure
WordPress Plugin Contact Form by WPForms Version Disclosure
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
WordPress Plugin Detected
WordPress Plugin Detected
No items found.
Information
WordPress Plugin Elementor Website Builder Identified
WordPress Plugin Elementor Website Builder Identified
No items found.
Information
WordPress Plugin Elementor Website Builder Out Of Date
WordPress Plugin Elementor Website Builder Out Of Date
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
WordPress Plugin Elementor Website Builder Version Disclosure
WordPress Plugin Elementor Website Builder Version Disclosure
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
WordPress Plugin Jetpack Identified
WordPress Plugin Jetpack Identified
No items found.
Information
WordPress Plugin Jetpack Out Of Date
WordPress Plugin Jetpack Out Of Date
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
WordPress Plugin Jetpack Version Disclosure
WordPress Plugin Jetpack Version Disclosure
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
WordPress Plugin Jupiter X Core Identified
WordPress Plugin Jupiter X Core Identified
No items found.
Information
WordPress Plugin Jupiter X Core Out Of Date
WordPress Plugin Jupiter X Core Out Of Date
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
WordPress Plugin Jupiter X Core Version Disclosure
WordPress Plugin Jupiter X Core Version Disclosure
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
WordPress Plugin LiteSpeed Cache Identified
WordPress Plugin LiteSpeed Cache Identified
No items found.
Information
WordPress Plugin LiteSpeed Cache Out Of Date
WordPress Plugin LiteSpeed Cache Out Of Date
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
WordPress Plugin LiteSpeed Cache Version Disclosure
WordPress Plugin LiteSpeed Cache Version Disclosure
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
WordPress Plugin Login with Phone Number Identified
WordPress Plugin Login with Phone Number Identified
No items found.
Information
WordPress Plugin Login with Phone Number Out Of Date
WordPress Plugin Login with Phone Number Out Of Date
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
WordPress Plugin Login with Phone Number Version Disclosure
WordPress Plugin Login with Phone Number Version Disclosure
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
WordPress Plugin Really Simple SSL Identified
WordPress Plugin Really Simple SSL Identified
No items found.
Information
WordPress Plugin Really Simple SSL Out Of Date
WordPress Plugin Really Simple SSL Out Of Date
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
WordPress Plugin Really Simple SSL Version Disclosure
WordPress Plugin Really Simple SSL Version Disclosure
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
WordPress Plugin Smash Balloon Social Photo Feed Identified
WordPress Plugin Smash Balloon Social Photo Feed Identified
No items found.
Information
WordPress Plugin Smash Balloon Social Photo Feed Out Of Date
WordPress Plugin Smash Balloon Social Photo Feed Out Of Date
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
WordPress Plugin Smash Balloon Social Photo Feed Version Disclosure
WordPress Plugin Smash Balloon Social Photo Feed Version Disclosure
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
WordPress Plugin Ultimate Member Identified
WordPress Plugin Ultimate Member Identified
No items found.
Information
WordPress Plugin Ultimate Member Out Of Date
WordPress Plugin Ultimate Member Out Of Date
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
WordPress Plugin Ultimate Member Version Disclosure
WordPress Plugin Ultimate Member Version Disclosure
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
WordPress Plugin UpdraftPlus Identified
WordPress Plugin UpdraftPlus Identified
No items found.
Information
WordPress Plugin Updraft Plus Out Of Date
WordPress Plugin Updraft Plus Out Of Date
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
WordPress Plugin Updraft Plus Version Disclosure
WordPress Plugin Updraft Plus Version Disclosure
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
WordPress Plugin WooCommerce Identified
WordPress Plugin WooCommerce Identified
No items found.
Information
WordPress Plugin WooCommerce Out Of Date
WordPress Plugin WooCommerce Out Of Date
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
WordPress Plugin WooCommerce Version Disclosure
WordPress Plugin WooCommerce Version Disclosure
CAPEC-170
,Â
CWE-205
,Â
HIPAA-164.306(a)
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.18.1.3
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Low
WordPress Plugin Wordfence Security Identified
WordPress Plugin Wordfence Security Identified
No items found.
Information
1