This page lists publicly disclosed CVE vulnerabilities affecting brainstormforce astra (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2023-44148 | Missing Authorization vulnerability in Brainstorm Force Astra Bulk Edit.This issue affects Astra Bulk Edit: from n/a through 1.2.7. | [email protected] | 5.4 | 0.27% | 2024-06-19 | 2024-11-21 |
| CVE-2023-49830 | Improper Control of Generation of Code ('Code Injection') vulnerability in Brainstorm Force Astra Pro.This issue affects Astra Pro: from n/a through 4.3.1. | [email protected] | 9.9 | 0.69% | 2023-12-29 | 2026-04-28 |
| CVE-2021-24507 | The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues | [email protected] | 9.8 | 44.20% | 2021-08-09 | 2024-11-21 |