CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase team allows Reflected XSS.This issue affects Team Showcase: from n/a through <= 1.22.25. |
1Pickplugins 2Post Grid Team ShowcaseNov 21, 2024 Jan 1, 2021 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a rem...Show more |
1Pickplugins 2Post Grid Team ShowcaseNov 21, 2024 Jan 1, 2021 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely...Show more |
1Pickplugins 2Post Grid Team ShowcaseNov 21, 2024 Jan 1, 2021 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafte...Show more |
1Pickplugins 2Post Grid Team ShowcaseNov 21, 2024 Jan 1, 2021 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted pay...Show more |