Vulnerabilities > Brainstormforce > Elementor Header Footer Blocks Template > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-07-22 CVE-2024-33933 Cross-site Scripting vulnerability in Brainstormforce Elementor - Header, Footer & Blocks Template
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainstorm Force, Nikhil Chavan Elementor – Header, Footer & Blocks Template allows DOM-Based XSS.This issue affects Elementor – Header, Footer & Blocks Template: from n/a through 1.6.35.
network
low complexity
brainstormforce CWE-79
5.4
2024-06-13 CVE-2024-5757 Cross-site Scripting vulnerability in Brainstormforce Elementor - Header, Footer & Blocks Template
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url attribute within the plugin's Site Title widget in all versions up to, and including, 1.6.35 due to insufficient input sanitization and output escaping.
network
low complexity
brainstormforce CWE-79
5.4