PatchSiren cyber security CVE debrief
CVE-2026-105885 10Web CVE debrief
A Deserialization of Untrusted Data vulnerability exists in the 10Web Slider by 10Web plugin, affecting versions from n/a through 1.2.62. This issue allows for Object Injection. The CVE record was published on 2026-10-10T14:16:37.087Z and has not been modified since then. The NVD entry is currently 8.8 HIGH. Defenders should assess exposure and potential impact, focusing on verifying plugin versions and considering upgrades to fixed versions if available. This vulnerability can lead to potential security risks if not addressed, and defenders should prioritize verification and assessment of systems using the affected plugin versions.
- Vendor
- 10Web
- Product
- Slider by 10Web
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for systems using the 10Web Slider by 10Web plugin should assess exposure and potential impact, focusing on verifying plugin versions and considering upgrades to fixed versions if available.
Why it matters
CVE-2026-105885 is a Deserialization of Untrusted Data vulnerability in the 10Web Slider by 10Web plugin, allowing for Object Injection. Defenders should verify exposure, assess potential impact, and consider upgrades to fixed versions.
- Verification of plugin versions is necessary to determine exposure
- Potential for Object Injection requires assessment of system vulnerability
- Upgrades to fixed versions may be necessary to mitigate risk
Technical summary
The 10Web Slider by 10Web plugin, versions from n/a through 1.2.62, is vulnerable to Deserialization of Untrusted Data, allowing for Object Injection. This issue is rated as HIGH with a CVSS score of 8.8. The vulnerability exists due to insecure deserialization practices in the plugin, which can be exploited by attackers to inject malicious objects. Defenders should verify exposure and assess potential impact, focusing on systems using the affected plugin versions, and consider upgrading to a fixed version if available.
Defensive priority
Defenders should prioritize verifying exposure and assessing potential impact, focusing on systems using the affected plugin versions.
Recommended defensive actions
- Verify exposure by checking plugin versions in use
- Assess potential impact on systems using the affected plugin
- Consider upgrading to a fixed version if available
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, but additional verification is needed to confirm affected versions and potential impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105885 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105885
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105885 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105885
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.