Brainstormforce
Brainstormforce Astra: vulnerabilidades y CVE
Brainstormforce Astra tiene 7 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses2
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-27085 | Baja (2.7) | 0.30% | — | 30 sept 2026 | Shop manager Content Injection in Astra WordPress Theme <= 4.13.12 versions. |
| CVE-2026-3534 | Media (6.4) | 0.35% | — | 11 mar 2026 | The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `ast-page-background-meta` and `ast-content-background-meta` post meta fields in all versions up to, and including, 4.12.3. This is due… |
| CVE-2023-44148 | Alta (8.8) | 0.39% | — | 19 jun 2024 | Missing Authorization vulnerability in Brainstorm Force Astra Bulk Edit.This issue affects Astra Bulk Edit: from n/a through 1.2.7. |
| CVE-2024-2347 | Media (6.4) | 0.35% | — | 9 abr 2024 | The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name in all versions up to, and including, 4.6.8 due to insufficient input sanitization and output escaping. This makes it… |
| CVE-2024-29768 | Media (5.9) | 0.36% | — | 27 mar 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra allows Stored XSS.This issue affects Astra: from n/a through 4.6.4. |
| CVE-2023-49830 | Alta (8.8) | 0.66% | — | 29 dic 2023 | Improper Control of Generation of Code ('Code Injection') vulnerability in Brainstorm Force Astra Pro.This issue affects Astra Pro: from n/a through 4.3.1. |
| CVE-2021-24507 | Crítica (9.8) | 11% | — | 9 ago 2021 | The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Brainstormforce
Spectra · 21Sureforms · 20Ultimate Addons FOR Wpbakery Page Builder · 12Ultimate Addons FOR Beaver Builder · 10Ultimate Addons FOR Elementor · 9Elementor Header & Footer Builder · 7Starter Templates · 5Suredash · 4Schema · 4Astra Widgets · 3Cartflows · 3Elementor - Header, Footer & Blocks Template · 3