Vulnerabilities > Brainstormforce

DATE CVE VULNERABILITY TITLE RISK
2024-01-17 CVE-2023-23882 Missing Authorization vulnerability in Brainstormforce Ultimate Addons for Beaver Builder
Missing Authorization vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder – Lite.This issue affects Ultimate Addons for Beaver Builder – Lite: from n/a through 1.5.5.
network
low complexity
brainstormforce CWE-862
4.3
2023-12-29 CVE-2023-51402 Cross-Site Request Forgery (CSRF) vulnerability in Brainstormforce Ultimate Addons for Wpbakery Page Builder 3.19.14/3.19.15
Cross-Site Request Forgery (CSRF) vulnerability in Brain Storm Force Ultimate Addons for WPBakery Page Builder.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through 3.19.17.
network
low complexity
brainstormforce CWE-352
8.8
2023-12-29 CVE-2023-51397 Cross-site Scripting vulnerability in Brainstormforce WP Remote Site Search
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force WP Remote Site Search allows Stored XSS.This issue affects WP Remote Site Search: from n/a through 1.0.4.
network
low complexity
brainstormforce CWE-79
5.4
2023-12-29 CVE-2023-49830 Code Injection vulnerability in Brainstormforce Astra
Improper Control of Generation of Code ('Code Injection') vulnerability in Brainstorm Force Astra Pro.This issue affects Astra Pro: from n/a through 4.3.1.
network
low complexity
brainstormforce CWE-94
8.8
2023-12-14 CVE-2023-49833 Cross-site Scripting vulnerability in Brainstormforce Spectra
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Spectra – WordPress Gutenberg Blocks allows Stored XSS.This issue affects Spectra – WordPress Gutenberg Blocks: from n/a through 2.7.9.
network
low complexity
brainstormforce CWE-79
5.4
2023-12-07 CVE-2023-41804 Server-Side Request Forgery (SSRF) vulnerability in Brainstormforce Starter Templates
Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4.
network
low complexity
brainstormforce CWE-918
5.4
2023-11-30 CVE-2023-36682 Cross-Site Request Forgery (CSRF) vulnerability in Brainstormforce Schema PRO 2.7.7
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC Schema Pro allows Cross Site Request Forgery.This issue affects Schema Pro: from n/a through 2.7.7.
network
low complexity
brainstormforce CWE-352
8.8
2023-11-30 CVE-2023-36685 Cross-Site Request Forgery (CSRF) vulnerability in Brainstormforce Cartflows
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC CartFlows Pro allows Cross Site Request Forgery.This issue affects CartFlows Pro: from n/a through 1.11.12.
network
low complexity
brainstormforce CWE-352
8.8
2023-10-27 CVE-2023-46211 Cross-site Scripting vulnerability in Brainstormforce Ultimate Addons for Wpbakery Page Builder
Auth.
network
low complexity
brainstormforce CWE-79
5.4
2023-07-01 CVE-2020-36747 Unspecified vulnerability in Brainstormforce Lightweight Sidebar Manager
The Lightweight Sidebar Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4.
network
low complexity
brainstormforce
4.3