Pickplugins

Team Showcase

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.78%
  • Veröffentlicht 18.09.2024 00:15:09
  • Zuletzt bearbeitet 01.04.2026 16:17:48

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase team allows Reflected XSS.This issue affects Team Showcase: from n/a through <= 1.22.25.

  • EPSS 0.16%
  • Veröffentlicht 18.08.2024 15:15:04
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS.This issue affects Team Showcase: from n/a through 1.22.23.

Exploit
  • EPSS 1.32%
  • Veröffentlicht 01.01.2021 02:15:13
  • Zuletzt bearbeitet 21.11.2024 05:28:33

Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter v...

Exploit
  • EPSS 1.38%
  • Veröffentlicht 01.01.2021 02:15:13
  • Zuletzt bearbeitet 21.11.2024 05:28:33

Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parame...

Exploit
  • EPSS 1.34%
  • Veröffentlicht 01.01.2021 02:15:13
  • Zuletzt bearbeitet 21.11.2024 05:28:33

PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the...

Exploit
  • EPSS 1.4%
  • Veröffentlicht 01.01.2021 02:15:13
  • Zuletzt bearbeitet 21.11.2024 05:28:33

PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload i...