CVE-2021-24488
- EPSS 11.24%
- Veröffentlicht 02.08.2021 11:15:10
- Zuletzt bearbeitet 21.11.2024 05:53:09
The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues
- EPSS 1.65%
- Veröffentlicht 01.01.2021 02:15:13
- Zuletzt bearbeitet 21.11.2024 05:28:33
Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter v...
CVE-2020-35939
- EPSS 2.08%
- Veröffentlicht 01.01.2021 02:15:13
- Zuletzt bearbeitet 21.11.2024 05:28:33
PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload i...
CVE-2020-35938
- EPSS 2.08%
- Veröffentlicht 01.01.2021 02:15:13
- Zuletzt bearbeitet 21.11.2024 05:28:33
PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the...
- EPSS 1.65%
- Veröffentlicht 01.01.2021 02:15:13
- Zuletzt bearbeitet 21.11.2024 05:28:33
Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parame...