Vulnerabilities > Pickplugins > Team Showcase > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-09-18 | CVE-2024-44002 | Cross-site Scripting vulnerability in Pickplugins Team Showcase Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Reflected XSS.This issue affects Team Showcase: from n/a through 1.22.25. | 6.1 |
2021-01-01 | CVE-2020-35939 | Deserialization of Untrusted Data vulnerability in Pickplugins Post Grid and Team Showcase PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. | 6.0 |
2021-01-01 | CVE-2020-35938 | Injection vulnerability in Pickplugins Post Grid and Team Showcase PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. | 6.0 |
2021-01-01 | CVE-2020-35937 | Cross-site Scripting vulnerability in Pickplugins Post Grid and Team Showcase Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. | 6.0 |
2021-01-01 | CVE-2020-35936 | Cross-site Scripting vulnerability in Pickplugins Post Grid and Team Showcase Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. | 6.0 |