Vendor
Brainstorm Force vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 22 vulnerabilities in Brainstorm Force: 0 in the last 7 days and 15 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-62134, was published on 11 September 2026. 3 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 15
- Critical, all time
- 2
- Exploited in the wild
- 0
About Brainstorm Force
Brainstorm Force is a software development company that creates themes and plugins for WordPress.
Brainstorm Force technologies
Latest Brainstorm Force vulnerabilities
- CVE-2026-62134: Starter Templates contributor IDOR vulnerabilitymediumCVSS 4.3EPSS 0.3%
- CVE-2026-85308: Brainstorm Force SureForms authorization bypass in access controlmediumCVSS 5.3EPSS 0.3%
- CVE-2026-80433: SureFeedback Client Site sensitive data exposurehighCVSS 7.5EPSS 0.4%
- CVE-2026-32553: OttoKit server-side request forgeryhighCVSS 7.2EPSS 0.3%
- CVE-2026-66688: Ultimate Addons for Elementor Contributor Cross Site ScriptingmediumCVSS 6.5EPSS 0.2%
- CVE-2026-10827: Spectra WordPress plugin stored CSS injection in block attributesinfoCVSS 3.5
- CVE-2026-7623: Brainstorm Force SureForms stored XSS in headingWrapper parametermediumCVSS 6.4
- CVE-2026-14921: Brainstorm Force Ultimate Addons for WPBakery Page Builder Stored XSSinfoCVSS 7.5
- CVE-2026-15382: Brainstorm Force Ultimate Addons for WPBakery unauthenticated font deletioninfoCVSS 6.5
- CVE-2026-15821: Brainstorm Force SureDash Stored XSS in Shortcode AttributesmediumCVSS 6.4
- CVE-2026-15787: Brainstorm Force Ultimate Addons for Elementor Stored XSS in Navigation Menu WidgetmediumCVSS 6.4
- CVE-2026-12900: Brainstorm Force Spectra Stored XSS in uagb/image blockmediumCVSS 6.4
- CVE-2026-12869: Header Footer Builder for Elementor Stored XSS via Template ImportinfoCVSS 6.8
- CVE-2026-57401: Brainstorm Force SureDash path traversal arbitrary file deletioncriticalCVSS 9.9
- CVE-2026-15288: Brainstorm Force SureForms improper input validation in payment processinghighCVSS 7.5
- CVE-2026-54813: Brainstorm Force SureDash blind SQL injectionhighCVSS 8.5EPSS 0.2%
- CVE-2026-49781: Brainstorm Force OttoKit PHP object injectioncriticalCVSS 9.8
- CVE-2026-39470: Brainstorm Force WooCommerce Cart Abandonment Recovery privilege escalationhighCVSS 7.2
- CVE-2026-7465: Brainstorm Force Spectra Gutenberg Blocks Remote Code ExecutionhighCVSS 8.8
- CVE-2026-45442: Brainstorm Force Presto Player missing authorization in access controlmediumCVSS 4.3
- CVE-2026-39479: Brainstorm Force OttoKit blind SQL injection in suretriggershighCVSS 7.6EPSS 0.3%
- CVE-2026-39477: Brainstorm Force CartFlows missing authorization in WordPress pluginmediumCVSS 4.3EPSS 0.2%
Most severe Brainstorm Force vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-57401: Brainstorm Force SureDash path traversal arbitrary file deletioncriticalCVSS 9.9
- CVE-2026-49781: Brainstorm Force OttoKit PHP object injectioncriticalCVSS 9.8
- CVE-2026-7465: Brainstorm Force Spectra Gutenberg Blocks Remote Code ExecutionhighCVSS 8.8
- CVE-2026-54813: Brainstorm Force SureDash blind SQL injectionhighCVSS 8.5EPSS 0.2%
- CVE-2026-39479: Brainstorm Force OttoKit blind SQL injection in suretriggershighCVSS 7.6EPSS 0.3%
- CVE-2026-80433: SureFeedback Client Site sensitive data exposurehighCVSS 7.5EPSS 0.4%
- CVE-2026-15288: Brainstorm Force SureForms improper input validation in payment processinghighCVSS 7.5
- CVE-2026-32553: OttoKit server-side request forgeryhighCVSS 7.2EPSS 0.3%
- CVE-2026-39470: Brainstorm Force WooCommerce Cart Abandonment Recovery privilege escalationhighCVSS 7.2
- CVE-2026-66688: Ultimate Addons for Elementor Contributor Cross Site ScriptingmediumCVSS 6.5EPSS 0.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 1 | 0 | |
| 13 Jul 2026 | 2 | 1 | |
| 20 Jul 2026 | 3 | 0 | |
| 27 Jul 2026 | 4 | 0 | |
| 3 Aug 2026 | 1 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 1 | 0 | |
| 7 Sep 2026 | 1 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/brainstorm-force.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Brainstorm Force vulnerabilities", https://junglewise.ai/threats/vendors/brainstorm-force, 26 September 2026.