Vulnerability index

Browse CVEs

66 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2023-23730 Improper Restriction of Excessive Authentication Attempts vulnerability in Brainstorm Force Spectra allows Functionality Bypass.This issue affects Sp… Spectra 2.3.1+ Fix from $1,6002024-06-03 MEDIUM 5.4 CVE-2024-4366 The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘block_id’ parameter in versions u… Spectra 2.13.1+ Fix from $1,6002024-05-24 MEDIUM 5.4 CVE-2024-1332 The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg file upload in all versions up t… Custom Fonts 2.1.5+ Fix from $1,6002024-05-24 MEDIUM 5.4 CVE-2024-2618 The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the size attribute in all versions up to,… Elementor Header \& Footer Builder 1.6.27+ Fix from $1,6002024-05-24 MEDIUM 5.4 CVE-2024-1814 The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial block in all … Spectra 2.12.9+ Fix from $1,6002024-05-23 MEDIUM 5.4 CVE-2024-1815 The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Gallery block in al… Spectra 2.12.9+ Fix from $1,6002024-05-23 HIGH 8.8 CVE-2023-51398 Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder allows Privilege Escalation.This issue affects Ult… Ultimate Addons For Beaver Builder 1.35.15+ Fix from $1,9502024-05-17 MEDIUM 6.5 CVE-2023-51401 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder a… Ultimate Addons For Beaver Builder 1.35.14+ Fix from $1,6002024-05-17 MEDIUM 5.4 CVE-2024-2619 The Elementor Header & Footer Builder for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.6.26 due to insufficient … Elementor Header \& Footer Builder 1.6.27+ Fix from $1,6002024-05-16 MEDIUM 5.4 CVE-2024-4634 The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hfe_svg_mime_types’ function in vers… Elementor Header \& Footer Builder 1.6.29+ Fix from $1,6002024-05-16 MEDIUM 5.4 CVE-2024-2305 The Cards for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the BootstrapCard link in all versions up to, and… Cards For Beaver Builder 1.1.3+ Fix from $1,6002024-04-09 MEDIUM 5.4 CVE-2023-6486 The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS metabox in all versions… Spectra 2.10.4+ Fix from $1,6002024-04-09 MEDIUM 5.4 CVE-2024-2144 The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Separator widget in all… Ultimate Addons For Beaver Builder 1.5.8+ Fix from $1,6002024-03-30 MEDIUM 5.4 CVE-2024-2141 The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget in all versions… Ultimate Addons For Beaver Builder 1.5.8+ Fix from $1,6002024-03-30 MEDIUM 5.4 CVE-2024-2142 The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Info Table widget in all vers… Ultimate Addons For Beaver Builder 1.5.8+ Fix from $1,6002024-03-30 MEDIUM 5.4 CVE-2024-2143 The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading widget in all version… Ultimate Addons For Beaver Builder 1.5.8+ Fix from $1,6002024-03-30 MEDIUM 5.4 CVE-2024-2140 The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Icons widget in all … Ultimate Addons For Beaver Builder 1.5.8+ Fix from $1,6002024-03-30 MEDIUM 6.5 CVE-2023-36679 Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6. Spectra 2.6.7+ Fix from $1,6002024-03-28 MEDIUM 5.4 CVE-2024-1237 The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the flyout_layout attribute in all versio… Elementor Header \& Footer Builder 1.6.25+ Fix from $1,6002024-03-13 HIGH 8.8 CVE-2023-51402 Cross-Site Request Forgery (CSRF) vulnerability in Brain Storm Force Ultimate Addons for WPBakery Page Builder.This issue affects Ultimate Addons for… Ultimate Addons For Wpbakery Page Builder after 3.19.17 Fix from $1,9502023-12-29 MEDIUM 5.4 CVE-2023-51397 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force WP Remote Site Search allows S… Wp Remote Site Search after 1.0.4 Fix from $1,6002023-12-29 HIGH 8.8 CVE-2023-49830 Improper Control of Generation of Code ('Code Injection') vulnerability in Brainstorm Force Astra Pro.This issue affects Astra Pro: from n/a through … Astra after 4.3.1 Fix from $1,9502023-12-29 MEDIUM 5.4 CVE-2023-49833 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Spectra – WordPress Gutenberg … Spectra 2.7.10+ Fix from $1,6002023-12-14 MEDIUM 5.4 CVE-2023-41804 Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates.This issue a… Starter Templates 3.2.5+ Fix from $1,6002023-12-07 HIGH 8.8 CVE-2023-36682 Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC Schema Pro allows Cross Site Request Forgery.This issue affects Schema Pro… Schema 2.7.8+ Fix from $1,9502023-11-30 HIGH 8.8 CVE-2023-36685 Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC CartFlows Pro allows Cross Site Request Forgery.This issue affects CartFlo… Cartflows after 1.11.12 Fix from $1,9502023-11-30 MEDIUM 5.4 CVE-2023-46211 Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder plugin <= 3.19.14 … Ultimate Addons For Wpbakery Page Builder 3.19.15+ Fix from $1,6002023-10-27 HIGH 8.8 CVE-2023-25058 Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Schema – All In One Schema Rich Snippets plugin <= 1.6.5 versions. Schema 1.6.6+ Fix from $1,9502023-05-26 HIGH 8.8 CVE-2022-46851 Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates plugin <= 3.1.20 versions. Starter Templates 3.1.21+ Fix from $1,9502023-05-23 MEDIUM 5.4 CVE-2020-36656 The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stor… Spectra 1.15.0+ Fix from $1,6002023-02-21