PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105885 10Web CVE debrief

A Deserialization of Untrusted Data vulnerability exists in the 10Web Slider by 10Web plugin, affecting versions from n/a through 1.2.62. This issue allows for Object Injection. The CVE record was published on 2026-10-10T14:16:37.087Z and has not been modified since then. The NVD entry is currently 8.8 HIGH. Defenders should assess exposure and potential impact, focusing on verifying plugin versions and considering upgrades to fixed versions if available. This vulnerability can lead to potential security risks if not addressed, and defenders should prioritize verification and assessment of systems using the affected plugin versions.

Vendor
10Web
Product
Slider by 10Web
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for systems using the 10Web Slider by 10Web plugin should assess exposure and potential impact, focusing on verifying plugin versions and considering upgrades to fixed versions if available.

Why it matters

CVE-2026-105885 is a Deserialization of Untrusted Data vulnerability in the 10Web Slider by 10Web plugin, allowing for Object Injection. Defenders should verify exposure, assess potential impact, and consider upgrades to fixed versions.

  • Verification of plugin versions is necessary to determine exposure
  • Potential for Object Injection requires assessment of system vulnerability
  • Upgrades to fixed versions may be necessary to mitigate risk

Technical summary

The 10Web Slider by 10Web plugin, versions from n/a through 1.2.62, is vulnerable to Deserialization of Untrusted Data, allowing for Object Injection. This issue is rated as HIGH with a CVSS score of 8.8. The vulnerability exists due to insecure deserialization practices in the plugin, which can be exploited by attackers to inject malicious objects. Defenders should verify exposure and assess potential impact, focusing on systems using the affected plugin versions, and consider upgrading to a fixed version if available.

Defensive priority

Defenders should prioritize verifying exposure and assessing potential impact, focusing on systems using the affected plugin versions.

Recommended defensive actions

  • Verify exposure by checking plugin versions in use
  • Assess potential impact on systems using the affected plugin
  • Consider upgrading to a fixed version if available

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, but additional verification is needed to confirm affected versions and potential impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105885 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105885

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105885 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105885

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.