CVE Tools

Brainstormforce

54 CVEs tracked since 2021. Since May 2021, none of them reached CISA KEV.

Brainstormforce CVEs per month

May 2021 to Dec 2024. Point at a month, or focus the strip and use the arrow keys.
Brainstormforce CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-0520
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-0730
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-1250
2024-01null or fewer
2024-02null or fewer
2024-0380
2024-04null or fewer
2024-05120
2024-06120
2024-0780
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-1240

Products

The products that kept showing up in Brainstormforce's monthly top three, with their CVEs summed over those months.

  1. Spectra135 months
  2. Ultimate Addons For Elementor64 months
  3. Spectra Gutenberg Blocks – Website Builder For The Block Editor52 months
  4. Ultimate Addons For Beaver Builder51 month
  5. Ultimate Addons For Beaver Builder – Lite51 month
  6. Ultimate Addons For Wpbakery Page Builder51 month
  7. Elementor - Header\, Footer \& Blocks Template22 months
  8. Astra11 month
  9. Cards For Beaver Builder11 month
  10. Cartflows – Funnel Builder & Checkout Plugin For Woocommerce11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Brainstormforce.

  1. CVE-2026-16302Spectra Legacy – Gutenberg Blocks <= 2.20.0 - Authenticated (Contributor+) Sensitive Information Exposure4.3
  2. CVE-2026-18406SureForms <= 2.12.2 - Unauthenticated Stored Cross-Site Scripting via Text Field Entity-Encoded Payload7.2
  3. CVE-2026-18402SureDash <= 1.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'draweropenverposition' Block/Shortcode Attribute6.4
  4. CVE-2026-7623SureForms <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'headingWrapper' Block Attribute6.4
  5. CVE-2026-15821SureDash <= 1.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes6.4
  6. CVE-2026-15787Ultimate Addons for Elementor <= 2.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes6.4
  7. CVE-2026-12900Spectra Gutenberg Blocks <= 2.19.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via uagb/image Block6.4
  8. CVE-2026-15288SureForms – Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticated Stripe Payment Amount Manipulation7.5
  9. CVE-2026-7465Spectra Gutenberg Blocks <= 2.19.25 - Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributes8.8
  10. CVE-2026-9065Surecart - SQL Injection—
  11. CVE-2026-4987SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id'7.5
  12. CVE-2026-3534Astra <= 4.12.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta6.4
  13. CVE-2026-28038WordPress Ultimate Addons for WPBakery Page Builder plugin <= 3.21.1 - Broken Access Control vulnerability6.5
  14. CVE-2026-0950Spectra Gutenberg Blocks <= 2.19.17 - Unauthenticated Information Disclosure in Sensitive Data5.3
  15. CVE-2025-14351Custom Fonts – Host Your Fonts Locally <= 2.1.16 - Missing Authorization to Unauthenticated Font Deletion5.3

The record

Peak rank
#53 in Jun 2024
Busiest month shown
May 2024, 12 CVEs
Months with a KEV entry
0 since May 2021
Monthly snapshots
8 since 2021
Brainstormforce's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store