CVE-2020-35936, CVE-2020-35937
The Post Grid plugin before version 2.0.73 contains stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious JavaScript code through layout imports. An attacker can exploit this by providing a crafted payload hosted remotely in the source parameter and triggering the import via AJAX with the team_import_xml_layouts action. The injected scripts are then permanently stored and executed in the application, affecting all users who interact with the compromised layouts.
Based on public CVE data (MITRE/NVD).