Astra Brainstormforce Astra

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Brainstormforce Astra.

By the Year

In 2026 there have been 1 vulnerability in Brainstormforce Astra with an average score of 6.4 out of ten. Astra did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.




Year Vulnerabilities Average Score
2026 1 6.40
2025 0 0.00
2024 3 7.60
2023 1 8.80
2022 0 0.00
2021 1 9.80

It may take a day or so for new Astra vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Brainstormforce Astra Security Vulnerabilities

Astra WP Theme <=4.12.3 Stored XSS via ast-page/ast-content meta
CVE-2026-3534 6.4 - Medium - March 11, 2026

The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `ast-page-background-meta` and `ast-content-background-meta` post meta fields in all versions up to, and including, 4.12.3. This is due to insufficient input sanitization on meta registration and missing output escaping in the `astra_get_responsive_background_obj()` function for four CSS-context sub-properties (`background-color`, `background-image`, `overlay-color`, `overlay-gradient`). This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

Missing Auth in Brainstorm Force Astra Bulk Edit 1.2.7
CVE-2023-44148 8.8 - High - June 19, 2024

Missing Authorization vulnerability in Brainstorm Force Astra Bulk Edit.This issue affects Astra Bulk Edit: from n/a through 1.2.7.

AuthZ

Astra WP Theme <=4.6.8 XSS via display name injection
CVE-2024-2347 6.4 - Medium - April 09, 2024

The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name in all versions up to, and including, 4.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

XSS

WordPress Astra Stored XSS pre-4.6.4 (CVE-2024-29768)
CVE-2024-29768 - March 27, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra allows Stored XSS.This issue affects Astra: from n/a through 4.6.4.

XSS

Astra Pro <4.3.2 Code Injection via Improper Code Generation
CVE-2023-49830 8.8 - High - December 29, 2023

Improper Control of Generation of Code ('Code Injection') vulnerability in Brainstorm Force Astra Pro.This issue affects Astra Pro: from n/a through 4.3.1.

Code Injection

The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters
CVE-2021-24507 9.8 - Critical - August 09, 2021

The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues

SQL Injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Brainstormforce Astra or by Brainstormforce? Click the Watch button to subscribe.

subscribe