Vulnerabilities > Brainstormforce

DATE CVE VULNERABILITY TITLE RISK
2025-01-07 CVE-2024-56274 Cross-site Scripting vulnerability in Brainstormforce Astra Widgets
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets allows Stored XSS.This issue affects Astra Widgets: from n/a through 1.2.15.
network
low complexity
brainstormforce CWE-79
5.4
2024-12-23 CVE-2024-11230 Cross-site Scripting vulnerability in Brainstormforce Elementor Header & Footer Builder
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘size’ parameter in all versions up to, and including, 1.6.46 due to insufficient input sanitization and output escaping.
network
low complexity
brainstormforce CWE-79
5.4
2024-12-09 CVE-2023-23825 Missing Authorization vulnerability in Brainstormforce Spectra
Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0.
network
low complexity
brainstormforce CWE-862
8.8
2024-12-09 CVE-2023-23834 Missing Authorization vulnerability in Brainstormforce Spectra
Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0.
network
low complexity
brainstormforce CWE-862
critical
9.8
2024-12-03 CVE-2024-10484 Cross-site Scripting vulnerability in Brainstormforce Spectra
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Team' widget in all versions up to, and including, 2.16.2 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
brainstormforce CWE-79
5.4
2024-11-08 CVE-2024-10325 Cross-site Scripting vulnerability in Brainstormforce Elementor Header & Footer Builder
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.6.45 due to insufficient input sanitization and output escaping.
network
low complexity
brainstormforce CWE-79
5.4
2024-11-01 CVE-2024-37517 Missing Authorization vulnerability in Brainstormforce Spectra
Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.13.7.
network
low complexity
brainstormforce CWE-862
8.8
2024-10-28 CVE-2024-50439 Cross-site Scripting vulnerability in Brainstormforce Astra Widgets
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets allows Stored XSS.This issue affects Astra Widgets: from n/a through 1.2.14.
network
low complexity
brainstormforce CWE-79
5.4
2024-10-24 CVE-2024-10050 Unspecified vulnerability in Brainstormforce Elementor Header & Footer Builder
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 1.6.43 via the hfe_template shortcode.
network
low complexity
brainstormforce
4.3
2024-08-12 CVE-2024-43151 Cross-site Scripting vulnerability in Brainstormforce Ultimate Addons for Beaver Builder
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder – Lite allows Stored XSS.This issue affects Ultimate Addons for Beaver Builder – Lite: from n/a through 1.5.9.
network
low complexity
brainstormforce CWE-79
5.4