Team
This hub aggregates every CVE we track for Team. Use it to gauge the current risk picture and drill into individual advisories.
other
13
CVEs tracked
2
Critical
2
High
0
In CISA KEV
Severity distribution
MEDIUM9HIGH2CRITICAL2
Monthly trend
0
3
0
0
0
1
0
0
0
0
0
0
1
0
0
0
0
0
2
0
0
0
0
0
2024-092026-08
Latest CVEs
The 13 most recently published vulnerabilities affecting Team.
- CVE-2026-25026WordPress Team plugin <= 5.0.11 - Broken Access Control vulnerability7.5
- CVE-2026-32396WordPress Team plugin <= 5.0.13 - Broken Access Control vulnerability5.3
- CVE-2025-57975WordPress Team Plugin <= 5.0.6 - Broken Access Control Vulnerability4.3
- CVE-2024-13439Team – Team Members Showcase Plugin <= 4.4.9 - Missing Authorization to Authenticated (Subscriber+) Settings Update4.3
- CVE-2024-9923TEAMPLUS TECHNOLOGY Team+ - Arbitrary File Move through Path Traversal4.9
- CVE-2024-9922TEAMPLUS TECHNOLOGY Team+ - Arbitrary File Read through Path Traversal7.5
- CVE-2024-9921TEAMPLUS TECHNOLOGY Team+ - SQL Injection9.8
- CVE-2022-34650WordPress Team plugin <= 1.2.6 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities4.1
- CVE-2022-34853WordPress Team plugin <= 1.2.6 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities4.1
- CVE-2019-0647An information disclosure vulnerability exists when Team Foundation Server does not properly handle variables marked as secret, aka "Team Foundation Server Information Disclosure Vulnerability." Th...6.5
- CVE-2019-0646A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka "Team Foundation Server Cross-site Scripting Vulnerability." This a...5.4
- CVE-2018-8529A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on the communication between the TFS and Search services, aka "Team Foundation Ser...9.8
- CVE-2018-8602A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka "Team Foundation Server Cross-site Scripting Vulnerability." This a...5.4
Product normalization is registry-driven with AI assist and human review. How it works