Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

BrainStormForce — Vulnerabilities & Security Advisories 57

Browse all 57 CVE security advisories affecting BrainStormForce. AI-powered Chinese analysis, POCs, and references for each vulnerability.

BrainStormForce operates as a provider of enterprise collaboration and knowledge management solutions, primarily serving organizations seeking centralized information sharing platforms. Security audits have identified forty-nine Common Vulnerabilities and Exposures (CVEs) associated with its software ecosystem, indicating a significant historical attack surface. The most prevalent vulnerability classes include Cross-Site Scripting (XSS), which allows attackers to inject malicious scripts into web pages viewed by other users, and Remote Code Execution (RCE) flaws that enable unauthorized control over server systems. Additionally, instances of broken access control and privilege escalation have been documented, suggesting weaknesses in user permission management. While no single catastrophic data breach has been widely publicized as a direct result of these specific CVEs, the cumulative nature of these flaws highlights the necessity for rigorous patch management and continuous security monitoring to mitigate risks within deployed environments.

CVE ID Title CVSS Severity Published
CVE-2026-18402 SureDash <= 1.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'draweropenverposition' Block/Shortcode Attribute — SureDash – Community, Courses & Member Dashboard CWE-79 6.4 Medium 2026-08-16
CVE-2026-7623 SureForms <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'headingWrapper' Block Attribute — SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz CWE-79 6.4 Medium 2026-08-01
CVE-2026-15821 SureDash <= 1.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes — SureDash – Community, Courses & Member Dashboard CWE-79 6.4 Medium 2026-07-24
CVE-2026-15787 Ultimate Addons for Elementor <= 2.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes — Ultimate Addons for Elementor CWE-79 6.4 Medium 2026-07-22
CVE-2026-12900 Spectra Gutenberg Blocks <= 2.19.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via uagb/image Block — Spectra Legacy – Gutenberg Blocks CWE-79 6.4 Medium 2026-07-20
CVE-2026-15288 SureForms – Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticated Stripe Payment Amount Manipulation — SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator CWE-20 7.5 High 2026-07-10
CVE-2026-7465 Spectra Gutenberg Blocks <= 2.19.25 - Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributes — Spectra Gutenberg Blocks – Website Builder for the Block Editor CWE-269 8.8 High 2026-05-30
CVE-2026-9065 Surecart - SQL Injection — Surecart CWE-89 - - 2026-05-20
CVE-2026-4987 SureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id' — SureForms – Contact Form, Payment Form & Other Custom Form Builder CWE-20 7.5 High 2026-03-28
CVE-2026-3534 Astra <= 4.12.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta — Astra CWE-79 6.4 Medium 2026-03-11
CVE-2026-0950 Spectra Gutenberg Blocks <= 2.19.17 - Unauthenticated Information Disclosure in Sensitive Data — Spectra Gutenberg Blocks – Website Builder for the Block Editor CWE-200 5.3 Medium 2026-02-03
CVE-2025-14351 Custom Fonts – Host Your Fonts Locally <= 2.1.16 - Missing Authorization to Unauthenticated Font Deletion — Custom Fonts – Host Your Fonts Locally CWE-862 5.3 Medium 2026-01-20
CVE-2025-14855 SureForms <= 2.2.0 - Unauthenticated Stored Cross-Site Scripting — SureForms – Contact Form, Payment Form & Other Custom Form Builder CWE-79 7.2 High 2025-12-21
CVE-2025-13065 Starter Templates <= 4.4.41 - Authenticated (Author+) Arbitrary File Upload via WXR Upload Bypass — Starter Templates – AI-Powered Templates for Elementor & Gutenberg CWE-434 8.8 High 2025-12-06
CVE-2025-13516 SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers <= 1.9.0 - Unauthenticated Arbitrary File Upload — SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers CWE-434 8.1 High 2025-12-02
CVE-2025-12535 SureForms <= 1.13.1 - Cross-Site Request Forgery Protection Bypass via Improper Nonce Distribution — SureForms – Contact Form, Payment Form & Other Custom Form Builder CWE-352 5.3 Medium 2025-11-19
CVE-2025-12536 SureForms <= 1.13.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure — SureForms – Contact Form, Payment Form & Other Custom Form Builder CWE-359 5.3 Medium 2025-11-13
CVE-2025-11162 Spectra <= 2.19.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom CSS — Spectra Gutenberg Blocks – Website Builder for the Block Editor CWE-79 6.4 Medium 2025-11-05
CVE-2025-10732 SureForms – Drag and Drop Form Builder for WordPress <= 1.12.1 - Missing Authorization to Authenticated (Contributor+) Information Disclosure — SureForms – Contact Form, Payment Form & Other Custom Form Builder CWE-862 4.3 Medium 2025-10-14
CVE-2025-10489 SureForms – Drag and Drop Form Builder for WordPress <= 1.12.0 - Missing Authorization to Authenticated (Contributor+) Form Creation — SureForms – Contact Form, Payment Form & Other Custom Form Builder CWE-862 4.3 Medium 2025-09-20
CVE-2025-8488 Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) <= 2.4.6 - Missing Authorization to Authenticated (Subscriber+) Limited Settings Update — Ultimate Addons for Elementor CWE-862 4.3 Medium 2025-08-02
CVE-2025-6691 SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission Deletion — SureForms – Drag and Drop Form Builder for WordPress CWE-73 8.1 High 2025-07-09
CVE-2025-6742 SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated PHP Object Injection (PHAR) Triggered via Admin Submission Deletion — SureForms – Drag and Drop Form Builder for WordPress CWE-502 7.5 High 2025-07-09
CVE-2025-3102 SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation — OttoKit: All-in-One Automation Platform CWE-697 8.1 High 2025-04-10
CVE-2025-1784 Spectra – WordPress Gutenberg Blocks <= 2.19.0 - Authenticated (Contributor+) Stored Cross-Site Scripting — Spectra Gutenberg Blocks – Website Builder for the Block Editor CWE-79 6.4 Medium 2025-03-26
CVE-2024-12713 SureForms – Drag and Drop Form Builder for WordPress <= 1.2.2 - Missing Authorization to Unauthenticated Protected Post Disclosure — SureForms – Contact Form, Payment Form & Other Custom Form Builder CWE-862 5.3 Medium 2025-01-08
CVE-2024-11230 Elementor Header & Footer Builder <= 1.6.46 - Authenticated (Contributor+) Stored Cross-Site Scripting via Page Title Widget — Ultimate Addons for Elementor CWE-79 6.4 Medium 2024-12-23
CVE-2024-10484 Spectra – WordPress Gutenberg Blocks <= 2.16.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Widget — Spectra Gutenberg Blocks – Website Builder for the Block Editor CWE-79 6.4 Medium 2024-12-03
CVE-2024-10325 Elementor Header & Footer Builder <= 1.6.45 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload — Ultimate Addons for Elementor CWE-79 6.4 Medium 2024-11-08
CVE-2024-10050 Elementor Header & Footer Builder <= 1.6.43 - Authenticated (Contributor+) Information Disclosure via Shortcode — Ultimate Addons for Elementor CWE-200 4.3 Medium 2024-10-24

This page lists every published CVE security advisory associated with BrainStormForce. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.