VYPR

Team

by WordPress

Source repositories

CVEs (6)

  • CVE-2024-9921CriOct 14, 2024
    risk 0.64cvss 9.8epss 0.01

    The Team+ from TEAMPLUS TECHNOLOGY does not properly validate specific page parameter, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify and delete database contents.

  • CVE-2025-14124HigJan 5, 2026
    risk 0.56cvss 8.6epss 0.02

    The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

  • CVE-2024-9922HigOct 14, 2024
    risk 0.49cvss 7.5epss 0.01

    The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

  • CVE-2024-43321MedAug 18, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS.This issue affects Team Showcase: from n/a through 1.22.23.

  • CVE-2024-9923MedOct 14, 2024
    risk 0.32cvss 4.9epss 0.01

    The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with administrator privileges to move arbitrary system files to the website root directory and access them.

  • CVE-2024-9236MedMay 15, 2025
    risk 0.31cvss 4.8epss 0.00

    The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).