Pickplugins

Team Showcase

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.55%
  • Veröffentlicht 18.09.2024 00:15:09
  • Zuletzt bearbeitet 25.09.2024 20:06:13

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Reflected XSS.This issue affects Team Showcase: from n/a through 1.22.25.

  • EPSS 0.16%
  • Veröffentlicht 18.08.2024 15:15:04
  • Zuletzt bearbeitet 19.08.2024 12:59:59

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS.This issue affects Team Showcase: from n/a through 1.22.23.

Exploit
  • EPSS 1.32%
  • Veröffentlicht 01.01.2021 02:15:13
  • Zuletzt bearbeitet 21.11.2024 05:28:33

Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter v...

Exploit
  • EPSS 1.38%
  • Veröffentlicht 01.01.2021 02:15:13
  • Zuletzt bearbeitet 21.11.2024 05:28:33

Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parame...

Exploit
  • EPSS 1.34%
  • Veröffentlicht 01.01.2021 02:15:13
  • Zuletzt bearbeitet 21.11.2024 05:28:33

PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the...

Exploit
  • EPSS 1.4%
  • Veröffentlicht 01.01.2021 02:15:13
  • Zuletzt bearbeitet 21.11.2024 05:28:33

PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload i...