CVE-2023-36676
- EPSS 0.21%
- Veröffentlicht 19.06.2024 14:15:11
- Zuletzt bearbeitet 21.11.2024 08:10:20
Missing Authorization vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6.
CVE-2023-23738
- EPSS 0.35%
- Veröffentlicht 03.06.2024 22:15:09
- Zuletzt bearbeitet 10.04.2025 18:55:39
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Brainstorm Force Spectra allows Content Spoofing, Phishing.This issue affects Spectra: from n/a through 2.3.0.
CVE-2023-23735
- EPSS 0.34%
- Veröffentlicht 03.06.2024 22:15:09
- Zuletzt bearbeitet 01.03.2025 01:48:32
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Brainstorm Force Spectra allows Code Injection.This issue affects Spectra: from n/a through 2.3.0.
CVE-2023-23730
- EPSS 0.13%
- Veröffentlicht 03.06.2024 22:15:08
- Zuletzt bearbeitet 10.04.2025 18:38:28
Improper Restriction of Excessive Authentication Attempts vulnerability in Brainstorm Force Spectra allows Functionality Bypass.This issue affects Spectra: from n/a through 2.3.0.
CVE-2024-4366
- EPSS 0.15%
- Veröffentlicht 24.05.2024 08:15:09
- Zuletzt bearbeitet 07.02.2025 17:13:56
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘block_id’ parameter in versions up to, and including, 2.13.0 due to insufficient input sanitization and output escaping. This makes it...
CVE-2024-1815
- EPSS 0.2%
- Veröffentlicht 23.05.2024 11:15:23
- Zuletzt bearbeitet 07.02.2025 17:13:45
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Gallery block in all versions up to, and including, 2.12.8 due to insufficient input sanitization and output escaping on...
CVE-2024-1814
- EPSS 0.2%
- Veröffentlicht 23.05.2024 11:15:23
- Zuletzt bearbeitet 07.02.2025 17:13:34
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial block in all versions up to, and including, 2.12.8 due to insufficient input sanitization and output escaping on u...
CVE-2024-3107
- EPSS 0.31%
- Veröffentlicht 02.05.2024 17:15:22
- Zuletzt bearbeitet 06.02.2025 18:05:03
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 2.12.6 via the get_block_default_attributes function. This allows authenticated attackers, with contributor-level permissi...
CVE-2023-6486
- EPSS 0.32%
- Veröffentlicht 09.04.2024 19:15:12
- Zuletzt bearbeitet 06.02.2025 18:58:52
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS metabox in all versions up to and including 2.10.3 due to insufficient input sanitization and output escaping. This makes it...
CVE-2023-36679
- EPSS 0.36%
- Veröffentlicht 28.03.2024 06:15:09
- Zuletzt bearbeitet 05.03.2025 20:50:02
Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6.