Vulnerabilities > Brainstormforce

DATE CVE VULNERABILITY TITLE RISK
2023-12-29 CVE-2023-49830 Code Injection vulnerability in Brainstormforce Astra
Improper Control of Generation of Code ('Code Injection') vulnerability in Brainstorm Force Astra Pro.This issue affects Astra Pro: from n/a through 4.3.1.
network
low complexity
brainstormforce CWE-94
8.8
2023-12-14 CVE-2023-49833 Cross-site Scripting vulnerability in Brainstormforce Spectra
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Spectra – WordPress Gutenberg Blocks allows Stored XSS.This issue affects Spectra – WordPress Gutenberg Blocks: from n/a through 2.7.9.
network
low complexity
brainstormforce CWE-79
5.4
2023-12-07 CVE-2023-41804 Server-Side Request Forgery (SSRF) vulnerability in Brainstormforce Starter Templates
Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4.
network
low complexity
brainstormforce CWE-918
5.4
2023-11-30 CVE-2023-36682 Cross-Site Request Forgery (CSRF) vulnerability in Brainstormforce Schema PRO 2.7.7
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC Schema Pro allows Cross Site Request Forgery.This issue affects Schema Pro: from n/a through 2.7.7.
network
low complexity
brainstormforce CWE-352
8.8
2023-11-30 CVE-2023-36685 Cross-Site Request Forgery (CSRF) vulnerability in Brainstormforce Cartflows
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC CartFlows Pro allows Cross Site Request Forgery.This issue affects CartFlows Pro: from n/a through 1.11.12.
network
low complexity
brainstormforce CWE-352
8.8
2023-10-27 CVE-2023-46211 Cross-site Scripting vulnerability in Brainstormforce Ultimate Addons for Wpbakery Page Builder
Auth.
network
low complexity
brainstormforce CWE-79
5.4
2023-07-01 CVE-2020-36747 Unspecified vulnerability in Brainstormforce Lightweight Sidebar Manager
The Lightweight Sidebar Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4.
network
low complexity
brainstormforce
4.3
2023-07-01 CVE-2020-36737 Unspecified vulnerability in Brainstormforce Import / Export Customizer Settings 1.0.1/1.0.2/1.0.3
The Import / Export Customizer Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.3.
network
low complexity
brainstormforce
4.3
2023-06-07 CVE-2020-36702 Missing Authorization vulnerability in Brainstormforce Spectra
The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7.
network
low complexity
brainstormforce CWE-862
4.3
2023-05-26 CVE-2023-25058 Cross-Site Request Forgery (CSRF) vulnerability in Brainstormforce Schema
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Schema – All In One Schema Rich Snippets plugin <= 1.6.5 versions.
network
low complexity
brainstormforce CWE-352
8.8