Extension WordPress
Vulnérabilités Team Showcase
Cette page rassemble les failles publiées pour Team Showcase, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Team Showcase
7 fiches
Team Showcase <= 1.22.28 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.22.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-1.22.28
Non indiqué
25/05/2026
Team Showcase <= 1.22.25 – Reflected Cross-Site Scripting
The Team Showcase plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.22.25 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-1.22.25
1.22.26
16/09/2024
Team Showcase <= 1.22.23 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.22.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-1.22.23
1.22.24
16/08/2024
Team Showcase <= 1.22.15 – Object Injection
PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source…
[*, 1.22.16)
1.22.16
17/09/2020
Team Showcase <= 1.22.15 – Stored Cross-Site Scripting
Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action…
[*, 1.22.16)
1.22.16
17/09/2020
Team Showcase <= 1.22.15 – Stored Cross-Site Scripting
Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action…
[*, 1.22.16)
1.22.16
17/09/2020
Team Showcase <= 1.22.15 – Object Injection
PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source…
[*, 1.22.16)
1.22.16
17/09/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.