Vulnerabilities > Brainstormforce
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-11-30 | CVE-2023-36682 | Unspecified vulnerability in Brainstormforce Schema PRO 2.7.7 Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC Schema Pro allows Cross Site Request Forgery.This issue affects Schema Pro: from n/a through 2.7.7. | 8.8 |
2023-11-30 | CVE-2023-36685 | Unspecified vulnerability in Brainstormforce Cartflows Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC CartFlows Pro allows Cross Site Request Forgery.This issue affects CartFlows Pro: from n/a through 1.11.12. | 8.8 |
2023-10-27 | CVE-2023-46211 | Unspecified vulnerability in Brainstormforce Ultimate Addons for Wpbakery Page Builder Auth. | 5.4 |
2023-06-07 | CVE-2020-36702 | Missing Authorization vulnerability in Brainstormforce Spectra The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. | 4.3 |
2023-05-26 | CVE-2023-25058 | Unspecified vulnerability in Brainstormforce Schema Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Schema – All In One Schema Rich Snippets plugin <= 1.6.5 versions. | 8.8 |
2023-05-23 | CVE-2022-46851 | Unspecified vulnerability in Brainstormforce Starter Templates Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates plugin <= 3.1.20 versions. | 8.8 |
2023-02-21 | CVE-2020-36656 | Cross-site Scripting vulnerability in Brainstormforce Spectra The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks. | 5.4 |
2021-11-17 | CVE-2021-42360 | Unspecified vulnerability in Brainstormforce Starter Templates On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-elementor-batch-process AJAX action. | 5.4 |
2021-08-09 | CVE-2021-24507 | Unspecified vulnerability in Brainstormforce Astra The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues | 9.8 |
2021-05-05 | CVE-2021-24271 | Unspecified vulnerability in Brainstormforce Ultimate Addons for Elementor The “Ultimate Addons for Elementor” WordPress Plugin before 1.30.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method. | 5.4 |