PatchSiren

10Web CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH 10Web CVE published 2026-10-07

CVE-2026-42710

A SQL Injection vulnerability exists in the WordPress Slider by 10Web plugin versions up to 1.2.63. This issue allows for Blind SQL Injection, posing a significant risk to affected systems. The vulnerability can lead to potential unauthorized access to sensitive data, possible disruption of website functionality, and risk of lateral movement within the network. WordPress administrators and users of the Sl [truncated]

MEDIUM 10web CVE published 2026-10-03

CVE-2026-92974

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress, versions up to and including 1.8.46, is vulnerable to Reflected Cross-Site Scripting via the 'thumb_url' parameter. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts into pages that execute if a user with the manage_options capability can be tricked into performing an action, such as clicking [truncated]

HIGH 10web CVE published 2026-10-01

CVE-2026-96813

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields in all versions up to, and including, 1.15.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute wheneve [truncated]

MEDIUM 10web CVE published 2026-09-18

CVE-2026-85652

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'album_id' Shortcode Attribute in all versions up to, and including, 1.8.44. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from [truncated]

HIGH 10Web CVE published 2026-08-20

CVE-2026-66616

CVE-2026-66616 is a Stored Cross-Site Scripting (XSS) vulnerability in the Form Maker by 10Web plugin, affecting versions from n/a through 1.15.48. This issue allows attackers to inject malicious scripts into web pages, potentially leading to unauthorized actions or data theft when users interact with the affected pages. The vulnerability has a CVSS score of 7.1 and is considered HIGH severity. Defenders [truncated]

MEDIUM 10Web CVE published 2026-08-19

CVE-2026-14287

The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenticated request handler and does not escape attacker-supplied stylesheet content before rendering it into the page head, allowing an unauthenticated attacker to store markup that executes as JavaScript in the browser of anonymous visitors to an affected page.

HIGH 10Web CVE published 2026-08-18

CVE-2026-66635

A Cross-Site Request Forgery (CSRF) vulnerability exists in the 10Web Slider by 10Web plugin, affecting versions from n/a through 1.2.63. This issue allows for Cross Site Request Forgery. Defenders should assess exposure, particularly those managing WordPress installations with the affected plugin. The vulnerability's impact on operations requires verification from official sources. Remediation priority f [truncated]

MEDIUM 10web CVE published 2026-06-18

CVE-2026-11777

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'name' parameter in all versions up to, and including, 1.15.43. The vulnerability exists due to insufficient escaping of the user-supplied 'name' parameter and inadequate preparation of existing SQL queries. This allows authenticated attackers with administrator-le [truncated]

MEDIUM 10web CVE published 2026-06-18

CVE-2026-11776

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'groupids' parameter in all versions up to, and including, 1.15.43. This vulnerability exists due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. As a result, authenticated attackers with adminis [truncated]

CRITICAL 10Web CVE published 2026-06-15

CVE-2026-39502

CVE-2026-39502 is a critical vulnerability in the Form Maker by 10Web plugin for WordPress, affecting versions up to and including 1.15.38. This vulnerability, with a CVSS score of 9.3, allows unauthenticated SQL injection attacks. The vulnerability was published on [cvePublishedAt] and last modified on [cveModifiedAt].

MEDIUM 10web CVE published 2026-06-06

CVE-2026-9829

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'compact_album_order_by' Shortcode Parameter in all versions up to, and including, 1.8.41. This vulnerability is due to insufficient escaping on the user-supplied parameter and a lack of sufficient preparation on the existing SQL query. Authenticated attackers with contributor-leve [truncated]

HIGH 10Web CVE published 2026-06-04

CVE-2026-49771

A Blind SQL Injection vulnerability was discovered in the Photo Gallery by 10Web plugin, affecting versions from n/a through 1.8.41. This issue, tracked as CVE-2026-49771, has a CVSS score of 7.6 and is classified as HIGH severity. The vulnerability allows for Blind SQL Injection attacks, which can potentially lead to unauthorized access to sensitive data. The issue was published on [cvePublishedAt] and l [truncated]

MEDIUM 10web CVE published 2026-05-28

CVE-2026-7048

A time-based blind SQL injection vulnerability exists in the Photo Gallery by 10Web WordPress plugin. The flaw resides in the 'order_by' parameter where insufficient escaping and lack of query preparation allow authenticated attackers with contributor-level access or higher to inject malicious SQL. Attackers can exploit this by embedding a crafted shortcode in posts or drafts, which executes injected SQL [truncated]

HIGH 10Web CVE published 2026-05-23

CVE-2018-25346

CVE-2018-25346 documents SQL injection vulnerabilities in WordPress Form Maker Plugin versions 1.12.24 and below. The vulnerability allows authenticated attackers to manipulate database queries by injecting SQL code through the FormMakerSQLMapping and generete_csv actions via POST requests containing malicious payloads in the name and search_labels parameters. This enables database extraction, modificatio [truncated]

MEDIUM 10Web CVE published 2026-04-13

CVE-2025-15441

The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the 'MySQL Mapping' feature is in use, potentially allowing SQL Injection attacks. This vulnerability could enable attackers to execute unauthorized SQL queries, leading to data breaches or system compromise. WordPress administrators and security teams should assess exposure and prioritize patching to versio [truncated]