Blueastral Vulnerabilities
Comprehensive security vulnerability database for Blueastral products
4
0
1
0
Severity Distribution
| Description | Vendor / Product | Exploit Status | |||
|---|---|---|---|---|---|
| CVE-2024-35768 | 4.8 | This vulnerability allows an attacker to inject malicious scripts into web pages created with the Live Composer Page Builder, which can then execute when users visit those pages, potentially stealing sensitive information or hijacking user sessions. It affects versions from the earliest release up to 1.5.42, meaning any site using these versions is at risk if they allow untrusted input to be included in the page content. | blueastralpage builder\ | Theoretical | almost 2 years agoJun 21, 2024 |
| CVE-2024-35779 | 5.4 | This vulnerability allows an attacker to inject malicious scripts into web pages created with the Live Composer Page Builder, which can then be executed in the browsers of users who visit those pages. It affects versions from the earliest release up to 1.5.42, meaning if you're using one of those versions, your site could be at risk if proper input validation isn't implemented. | blueastralpage builder\ | Theoretical | almost 2 years agoJun 21, 2024 |
| CVE-2023-52193 | 5.4 | This vulnerability allows an attacker to inject malicious scripts into web pages created with the Live Composer Page Builder, which can then be executed in the browsers of users visiting those pages. It affects versions up to 1.5.23, and for the attack to work, the attacker needs to have access to a way to input content into the page builder. | blueastralpage builder\ | Theoretical | about 2 years agoFeb 1, 2024 |
| CVE-2022-4669 | 5.4 | This vulnerability allows attackers with contributor roles or higher to inject malicious scripts into web pages, potentially leading to Stored Cross-Site Scripting (XSS) attacks that can steal user data or hijack sessions. It occurs because the Page Builder plugin fails to properly check and clean up certain inputs before displaying them on the site. | blueastralpage builder\ | Exploit Available | about 3 years agoFeb 21, 2023 |
About Blueastral Security
This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Blueastral products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.
Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.