Vulnerabilities > Brainstormforce > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-07-17 CVE-2024-5252 Cross-site Scripting vulnerability in Brainstormforce Ultimate Addons for Wpbakery Page Builder
The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_info_table shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
brainstormforce CWE-79
5.4
2024-07-17 CVE-2024-5253 Cross-site Scripting vulnerability in Brainstormforce Ultimate Addons for Wpbakery Page Builder
The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ult_team shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
brainstormforce CWE-79
5.4
2024-07-17 CVE-2024-5254 Cross-site Scripting vulnerability in Brainstormforce Ultimate Addons for Wpbakery Page Builder
The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_info_banner shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
brainstormforce CWE-79
5.4
2024-07-17 CVE-2024-5255 Cross-site Scripting vulnerability in Brainstormforce Ultimate Addons for Wpbakery Page Builder
The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_dual_color shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
brainstormforce CWE-79
5.4
2024-06-19 CVE-2023-41805 Missing Authorization vulnerability in Brainstormforce Starter Templates
Missing Authorization vulnerability in Brainstorm Force Premium Starter Templates, Brainstorm Force Starter Templates astra-sites.This issue affects Premium Starter Templates: from n/a through 3.2.5; Starter Templates: from n/a through 3.2.5.
network
low complexity
brainstormforce CWE-862
6.5
2024-06-14 CVE-2023-51376 Missing Authorization vulnerability in Brainstormforce Surefeedback
Missing Authorization vulnerability in Brainstorm Force ProjectHuddle Client Site.This issue affects ProjectHuddle Client Site: from n/a through 1.0.34.
network
low complexity
brainstormforce CWE-862
4.3
2024-06-13 CVE-2024-5757 Cross-site Scripting vulnerability in Brainstormforce Elementor - Header, Footer & Blocks Template
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url attribute within the plugin's Site Title widget in all versions up to, and including, 1.6.35 due to insufficient input sanitization and output escaping.
network
low complexity
brainstormforce CWE-79
5.4
2024-06-03 CVE-2023-23730 Improper Restriction of Excessive Authentication Attempts vulnerability in Brainstormforce Spectra
Improper Restriction of Excessive Authentication Attempts vulnerability in Brainstorm Force Spectra allows Functionality Bypass.This issue affects Spectra: from n/a through 2.3.0.
network
low complexity
brainstormforce CWE-307
5.3
2024-06-03 CVE-2023-23735 Unspecified vulnerability in Brainstormforce Spectra
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Brainstorm Force Spectra allows Code Injection.This issue affects Spectra: from n/a through 2.3.0.
network
low complexity
brainstormforce
6.1
2024-06-03 CVE-2023-23738 Injection vulnerability in Brainstormforce Spectra
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Brainstorm Force Spectra allows Content Spoofing, Phishing.This issue affects Spectra: from n/a through 2.3.0.
network
low complexity
brainstormforce CWE-74
5.3