Vulnerabilities in BrainStormForce
51 resultsCVE-2024-1332MEDIUMCustom Fonts – Host Your Fonts Locally <= 2.1.4 - Authenticated (Author+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2024-1814MEDIUMSpectra – WordPress Gutenberg Blocks <= 2.12.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial BlockEPSS 0.3%CVE-2026-4987HIGHSureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id'EPSS 0.3%CVE-2025-1784MEDIUMSpectra – WordPress Gutenberg Blocks <= 2.19.0 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2025-10732MEDIUMSureForms – Drag and Drop Form Builder for WordPress <= 1.12.1 - Missing Authorization to Authenticated (Contributor+) Information DisclosureEPSS 0.2%CVE-2025-14351MEDIUMCustom Fonts – Host Your Fonts Locally <= 2.1.16 - Missing Authorization to Unauthenticated Font DeletionEPSS 0.2%CVE-2025-8488MEDIUMUltimate Addons for Elementor (Formerly Elementor Header & Footer Builder) <= 2.4.6 - Missing Authorization to Authenticated (Subscriber+) Limited Settings UpdateEPSS 0.2%CVE-2026-3534MEDIUMAstra <= 4.12.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post MetaEPSS 0.2%CVE-2025-11162MEDIUMSpectra <= 2.19.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom CSSEPSS 0.2%CVE-2025-10489MEDIUMSureForms – Drag and Drop Form Builder for WordPress <= 1.12.0 - Missing Authorization to Authenticated (Contributor+) Form CreationEPSS 0.2%CVE-2025-12535MEDIUMSureForms <= 1.13.1 - Cross-Site Request Forgery Protection Bypass via Improper Nonce DistributionEPSS 0.2%