Vulnerabilities > Brainstormforce > High

DATE CVE VULNERABILITY TITLE RISK
2024-07-09 CVE-2024-37455 Unspecified vulnerability in Brainstormforce Ultimate Addons for Elementor
Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Elementor allows Privilege Escalation.This issue affects Ultimate Addons for Elementor: from n/a through 1.36.31.
network
low complexity
brainstormforce
8.8
2024-06-19 CVE-2023-36676 Missing Authorization vulnerability in Brainstormforce Spectra
Missing Authorization vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6.
network
low complexity
brainstormforce CWE-862
8.8
2024-06-19 CVE-2023-44148 Missing Authorization vulnerability in Brainstormforce Astra
Missing Authorization vulnerability in Brainstorm Force Astra Bulk Edit.This issue affects Astra Bulk Edit: from n/a through 1.2.7.
network
low complexity
brainstormforce CWE-862
8.8
2024-06-19 CVE-2023-44151 Missing Authorization vulnerability in Brainstormforce Pre-Publish Checklist
Missing Authorization vulnerability in Brainstorm Force Pre-Publish Checklist.This issue affects Pre-Publish Checklist: from n/a through 1.1.1.
network
low complexity
brainstormforce CWE-862
8.8
2023-12-29 CVE-2023-51402 Cross-Site Request Forgery (CSRF) vulnerability in Brainstormforce Ultimate Addons for Wpbakery Page Builder 3.19.14/3.19.15
Cross-Site Request Forgery (CSRF) vulnerability in Brain Storm Force Ultimate Addons for WPBakery Page Builder.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through 3.19.17.
network
low complexity
brainstormforce CWE-352
8.8
2023-12-29 CVE-2023-49830 Code Injection vulnerability in Brainstormforce Astra
Improper Control of Generation of Code ('Code Injection') vulnerability in Brainstorm Force Astra Pro.This issue affects Astra Pro: from n/a through 4.3.1.
network
low complexity
brainstormforce CWE-94
8.8
2023-11-30 CVE-2023-36682 Cross-Site Request Forgery (CSRF) vulnerability in Brainstormforce Schema PRO 2.7.7
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC Schema Pro allows Cross Site Request Forgery.This issue affects Schema Pro: from n/a through 2.7.7.
network
low complexity
brainstormforce CWE-352
8.8
2023-11-30 CVE-2023-36685 Cross-Site Request Forgery (CSRF) vulnerability in Brainstormforce Cartflows
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC CartFlows Pro allows Cross Site Request Forgery.This issue affects CartFlows Pro: from n/a through 1.11.12.
network
low complexity
brainstormforce CWE-352
8.8
2023-05-26 CVE-2023-25058 Cross-Site Request Forgery (CSRF) vulnerability in Brainstormforce Schema
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Schema – All In One Schema Rich Snippets plugin <= 1.6.5 versions.
network
low complexity
brainstormforce CWE-352
8.8
2023-05-23 CVE-2022-46851 Cross-Site Request Forgery (CSRF) vulnerability in Brainstormforce Starter Templates
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates plugin <= 3.1.20 versions.
network
low complexity
brainstormforce CWE-352
8.8