Vulnerabilidades em BrainStormForce
56 resultadosAnálise Vexday
BrainStormForce apresenta um perfil de risco mínimo com apenas 1 CVE catalogado e nenhuma exploração ativa confirmada. A vulnerabilidade, relacionada a controle de permissões (CWE-284), não é crítica e não foi publicada recentemente, sugerindo risco residual baixo.
CVE-2025-1784MEDIUMSpectra – WordPress Gutenberg Blocks <= 2.19.0 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2024-4366MEDIUMSpectra – WordPress Gutenberg Blocks <= 2.13.0 - Authenticated (Author+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2024-1815MEDIUMSpectra – WordPress Gutenberg Blocks <= 2.12.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Gallery BlockEPSS 0.3%CVE-2024-1814MEDIUMSpectra – WordPress Gutenberg Blocks <= 2.12.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial BlockEPSS 0.3%CVE-2024-1332MEDIUMCustom Fonts – Host Your Fonts Locally <= 2.1.4 - Authenticated (Author+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2026-15787MEDIUMUltimate Addons for Elementor <= 2.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon AttributesEPSS 0.2%CVE-2025-10732MEDIUMSureForms – Drag and Drop Form Builder for WordPress <= 1.12.1 - Missing Authorization to Authenticated (Contributor+) Information DisclosureEPSS 0.2%CVE-2025-14351MEDIUMCustom Fonts – Host Your Fonts Locally <= 2.1.16 - Missing Authorization to Unauthenticated Font DeletionEPSS 0.2%CVE-2025-8488MEDIUMUltimate Addons for Elementor (Formerly Elementor Header & Footer Builder) <= 2.4.6 - Missing Authorization to Authenticated (Subscriber+) Limited Settings UpdateEPSS 0.2%CVE-2025-11162MEDIUMSpectra <= 2.19.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom CSSEPSS 0.2%CVE-2026-7623MEDIUMSureForms <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'headingWrapper' Block AttributeEPSS 0.2%CVE-2025-12535MEDIUMSureForms <= 1.13.1 - Cross-Site Request Forgery Protection Bypass via Improper Nonce DistributionEPSS 0.2%CVE-2026-15821MEDIUMSureDash <= 1.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode AttributesEPSS 0.2%CVE-2026-3534MEDIUMAstra <= 4.12.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post MetaEPSS 0.2%CVE-2026-12900MEDIUMSpectra Gutenberg Blocks <= 2.19.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via uagb/image BlockEPSS 0.2%CVE-2025-10489MEDIUMSureForms – Drag and Drop Form Builder for WordPress <= 1.12.0 - Missing Authorization to Authenticated (Contributor+) Form CreationEPSS 0.2%