🚀 Just launched:
Invicti Agentic Pentest.
The future of penetration testing is here. Read the announcement.
Log in
Invicti Platform
US
EU
CA
AppSec with Zero Noise
Platform
Invicti Platform
Zero-noise AppSec platform
Scan Code
Secure code before runtime
SAST
Early static security analysis
Open Source (SCA)
Find vulnerable dependencies
SBOM & License Risk
Generate SBOMs and track licenses
Secrets
Detect exposed secrets in applications
Infrastructure as Code
Ingest IaC security findings
Container
Track container image vulnerabilities
Test Runtime
Test live applications like attackers
DAST & AI DAST
Test runtime, prove exploitability
Agentic Pentesting
Automate real-world attack techniques
API Security Testing
Discover and test APIs
Attack Surface Management
Identify exposed apps and endpoints
Cloud AppSec
Get a single-pane view of cloud app risk
AI AppSec
Scan smarter, accelerate remediation
Manage Vulnerabilities
See, prioritize, reduce AppSec risk
Vulnerability Management (ASPM)
Centralize and correlate AppSec findings
Compliance & Executive Reporting
Measure risk and impact
Threat Intelligence
Reachability, exploitability, and business logic
Solutions
API Discovery
AI-BOM
Manage Vulnerabilities
Automate Security Workflows
Track AppSec KPIs
Manage Open Source Risk
Pricing
Why Invicti
About Us
Invicti vs. Competitors
Case Studies
Contact Us
Careers
MSSP
Partners
Resources
Resource Library
Blog
Webinars
White Papers
Podcasts
Invicti Learn
Savings Calculator
Live Training
Documentation
Vulnerability Database
Get a demo
Web Application Vulnerabilities Index
This page lists
144
vulnerabilities that can be detected by Invicti.
Select Category
Critical
High
Medium
Low
Best Practice
Information
Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Select Vulnerability
Vulnerability Name
Classification
Severity
LimeSurvey Detected
LimeSurvey Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
Information
ListJs Identified
ListJs Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
Information
LiteSpeed Web Server Identified
LiteSpeed Web Server Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
Information
Local File Inclusion
Local File Inclusion
PCI v3.2-6.5.8
,Â
CAPEC-252
,Â
CWE-22
,Â
HIPAA-164.306(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-33
,Â
OWASP 2013-A4
,Â
OWASP 2017-A5
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
,Â
High
Local File Inclusion (IAST)
Local File Inclusion (IAST)
PCI v3.2-6.5.8
,Â
CAPEC-252
,Â
CWE-22
,Â
HIPAA-164.306(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-33
,Â
OWASP 2013-A4
,Â
OWASP 2017-A5
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
,Â
High
Lodash Identified
Lodash Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
Information
Log File Detected
Log File Detected
PCI v3.2-6.5.8
,Â
CAPEC-87
,Â
CWE-425
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
WASC-34
,Â
OWASP 2013-A7
,Â
OWASP 2017-A5
,Â
Information
Login Page Identified
Login Page Identified
No items found.
Information
Lua Identified
Lua Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
Information
Magento Identified
Magento Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
Information
Mail Header Injection (IAST)
Mail Header Injection (IAST)
PCI v3.2-6.5.1
,Â
CAPEC-66
,Â
CWE-20
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-19
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
,Â
Critical
Mailman Identified
Mailman Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
Information
Malware Identified
Malware Identified
CWE-506
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
,Â
Critical
MarionetteJs Identified
MarionetteJs Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
Information
markdown-it Identified
markdown-it Identified
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
OWASP 2017-A6
,Â
WASC-13
,Â
Information
Masa CMS Identified
Masa CMS Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
Information
Mashery Proxy Identified
Mashery Proxy Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
Information
MathJax Identified
MathJax Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
Information
MathJs Identified
MathJs Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
Information
MediaWiki Detected
MediaWiki Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
Information
Mibew Messenger Detected
Mibew Messenger Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
Information
Microsoft Access Database File Detected
Microsoft Access Database File Detected
PCI v3.2-6.5.8
,Â
CWE-285
,Â
ISO27001-A.18.1.3
,Â
WASC-2
,Â
OWASP 2013-A7
,Â
OWASP 2017-A3
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
,Â
Medium
Microsoft IIS Log File Detected
Microsoft IIS Log File Detected
PCI v3.2-6.5.8
,Â
CAPEC-87
,Â
CWE-425
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.18.1.3
,Â
WASC-34
,Â
OWASP 2013-A7
,Â
OWASP 2017-A5
,Â
Low
Microsoft Outlook Personal Folders File (.pst) Found
Microsoft Outlook Personal Folders File (.pst) Found
PCI v3.2-6.5.8
,Â
CWE-284
,Â
ISO27001-A.18.1.3
,Â
WASC-2
,Â
OWASP 2013-A7
,Â
OWASP 2017-A5
,Â
Low
Mint Detected
Mint Detected
CAPEC-224
,Â
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-45
,Â
OWASP 2017-A6
,Â
Information
Misconfigured Access-Control-Allow-Origin Header
Misconfigured Access-Control-Allow-Origin Header
PCI v3.2-6.5.8
,Â
CWE-16
,Â
ISO27001-A.14.1.2
,Â
WASC-15
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Low
Misconfigured Frame
Misconfigured Frame
CWE-16
,Â
ISO27001-A.14.1.2
,Â
WASC-15
,Â
OWASP 2017-A6
,Â
Low
Misconfigured X-Frame-Options Header
Misconfigured X-Frame-Options Header
CAPEC-103
,Â
CWE-693
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Low
Missing Content-Type Header
Missing Content-Type Header
PCI v3.2-6.5.7
,Â
CWE-16
,Â
ISO27001-A.14.1.2
,Â
WASC-15
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Low
Missing frame-ancestors in CSP Declaration
Missing frame-ancestors in CSP Declaration
CWE-16
,Â
ISO27001-A.14.2.5
,Â
WASC-15
,Â
Information
Missing object-src in CSP Declaration
Missing object-src in CSP Declaration
CWE-16
,Â
ISO27001-A.14.2.5
,Â
WASC-15
,Â
Information
Missing X-Content-Type-Options Header
Missing X-Content-Type-Options Header
CWE-16
,Â
ISO27001-A.14.1.2
,Â
WASC-15
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Low
Missing X-Frame-Options Header
Missing X-Frame-Options Header
CAPEC-103
,Â
CWE-693
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Low
Missing X-XSS-Protection Header
Missing X-XSS-Protection Header
CWE-16
,Â
HIPAA-164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-15
,Â
Best Practice
Mithril Identified
Mithril Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
Information
Modernizr Identified
Modernizr Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
Information
Mod_Ssl Identified
Mod_Ssl Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
Information
MODX Detected
MODX Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
Information
Momentjs Identified
Momentjs Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
Information
MongoDB Injection (IAST)
MongoDB Injection (IAST)
PCI v3.2-6.5.1
,Â
CAPEC-66
,Â
CWE-89
,Â
HIPAA-164.306(a)
,Â
164.308(a)
,Â
ISO27001-A.14.2.5
,Â
WASC-19
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
,Â
Critical
MongoDB Operator Injection
MongoDB Operator Injection
PCI v3.2-6.5.1
,Â
CWE-943
,Â
OWASP 2013-A1
,Â
OWASP 2017-A1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
,Â
High
Mongrel Identified
Mongrel Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
Information
Moodle Detected
Moodle Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
Information
Movable Type Detected
Movable Type Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
Information
MOVEit Identified
MOVEit Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
Information
Multiple Content Security Policy (CSP) Implementation Detected
Multiple Content Security Policy (CSP) Implementation Detected
CWE-16
,Â
ISO27001-A.14.2.5
,Â
WASC-15
,Â
Information
Multiple Declarations in X-Frame-Options Header
Multiple Declarations in X-Frame-Options Header
CAPEC-103
,Â
CWE-693
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Low
Mustachejs Identified
Mustachejs Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
Information
MyBB Detected
MyBB Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
Information
Next.js React Framework Identified
Next.js React Framework Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
Information
Next.js/React Server Components RCE (CVE-2025-55182 & CVE-2025-66478)
Next.js/React Server Components RCE (CVE-2025-55182 & CVE-2025-66478)
CWE-CWE-94
,Â
Critical
Nexus Repository OSS Identified
Nexus Repository OSS Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
Information
Nginx UI Information Disclosure (CVE-2026-27944)
Nginx UI Information Disclosure (CVE-2026-27944)
CWE-CWE-306
,Â
Critical
Nginx Web Server Identified
Nginx Web Server Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
Information
Node.js Web Application does not handle uncaughtException
Node.js Web Application does not handle uncaughtException
CWE-248
,Â
WASC-14
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
,Â
Medium
Node.js Web Application does not handle unhandledRejection
Node.js Web Application does not handle unhandledRejection
CWE-248
,Â
WASC-14
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
,Â
Medium
Nonce Usage Detected in Content Security Policy (CSP) Directive
Nonce Usage Detected in Content Security Policy (CSP) Directive
ISO27001-A.14.2.5
,Â
Information
No SAML Response Signature Check
No SAML Response Signature Check
CWE-16
,Â
ISO27001-A.14.2.5
,Â
WASC-15
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
,Â
High
No Script Block Detected with the Hash Value Declared in Content Security Policy (CSP)
No Script Block Detected with the Hash Value Declared in Content Security Policy (CSP)
ISO27001-A.14.2.5
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Information
NTLM Authorization Required
NTLM Authorization Required
ISO27001-A.9.4.1
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
,Â
Information
NuSOAP Identified
NuSOAP Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
Information
Omeka Detected
Omeka Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
Information
OpenCart Detected
OpenCart Detected
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
Information
Open Policy Crossdomain.xml Detected
Open Policy Crossdomain.xml Detected
CWE-16
,Â
ISO27001-A.14.2.5
,Â
WASC-15
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:H/RL:O/RC:C
,Â
Medium
Open Redirection
Open Redirection
CWE-601
,Â
ISO27001-A.14.2.5
,Â
WASC-38
,Â
OWASP 2013-A10
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
,Â
Medium
Open Redirection (DOM based)
Open Redirection (DOM based)
CWE-601
,Â
ISO27001-A.14.2.5
,Â
WASC-38
,Â
OWASP 2013-A10
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N
,Â
Medium
Open Redirection in POST method
Open Redirection in POST method
CWE-601
,Â
ISO27001-A.14.2.5
,Â
WASC-38
,Â
OWASP 2013-A10
,Â
OWASP 2017-A5
,Â
Low
OpenResty Web Platform Identified
OpenResty Web Platform Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
Information
OpenSearch.xml Detected
OpenSearch.xml Detected
CWE-200
,Â
ISO27001-A.18.1.3
,Â
Information
Open Silverlight Client Access Policy
Open Silverlight Client Access Policy
CWE-16
,Â
ISO27001-A.14.2.5
,Â
WASC-15
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:H/RL:O/RC:C
,Â
Medium
OpenSSL Heartbleed
OpenSSL Heartbleed
PCI v3.2-6.5.2
,Â
CAPEC-216
,Â
CWE-119
,Â
ISO27001-A.14.2.5
,Â
OWASP 2013-A6
,Â
OWASP 2017-A9
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H/RL:O/RC:C
,Â
Critical
OpenSSL Identified
OpenSSL Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
Information
OpenVPN Access Server Identified
OpenVPN Access Server Identified
CWE-205
,Â
ISO27001-A.14.2.5
,Â
WASC-13
,Â
OWASP 2017-A6
,Â
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
,Â
Information
OPTIONS Method Enabled
OPTIONS Method Enabled
CAPEC-107
,Â
CWE-16
,Â
ISO27001-A.14.1.2
,Â
WASC-14
,Â
OWASP 2013-A5
,Â
OWASP 2017-A6
,Â
Information
1