Skip to main content

Vendor/product archive

wpdarko / team_members CVEs

Beta · best-effort

4 CVEs tagged to wpdarko / team_members0 Critical, 0 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2024-1331

Published Mar 18, 2024

The Team Members WordPress plugin before 5.3.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embe…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3936

Published Jan 2, 2023

The Team Members WordPress plugin before 5.2.1 does not sanitize and escapes some of its settings, which could allow high-privilege users such as editors to perform Stored Cross-S…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1568

Published May 30, 2022

The Team Members WordPress plugin before 5.1.1 does not escape some of its Team settings, which could allow high privilege users such as admin to perform Cross-Site Scripting atta…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24128

Published Mar 18, 2021

Unvalidated input and lack of output encoding in the Team Members WordPress plugin, versions before 5.0.4, lead to Cross-site scripting vulnerabilities allowing medium-privileged…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1