Skip to main content

Vendor archive

10web CVEs

Beta · best-effort

103 CVEs tagged to vendor 10web11 Critical, 15 High, 72 Medium, 5 Low, 0 Unrated.

CVE-2025-13377

Published Dec 6, 2025

The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to arbitrary folder deletion due to insufficient file path validati…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-8670

Published May 15, 2025

The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Store…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13053

Published May 15, 2025

The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10680

Published Apr 16, 2025

The Form Maker by 10Web WordPress plugin before 1.15.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0613

Published Mar 31, 2025

The Photo Gallery by 10Web WordPress plugin before 1.8.34 does not sanitised and escaped comment added on images by unauthenticated users, leading to an Unauthenticated Stored-XS…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-10566

Published Mar 25, 2025

The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10565

Published Mar 25, 2025

The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10560

Published Mar 25, 2025

The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-13124

Published Mar 24, 2025

The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Store…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-10558

Published Mar 24, 2025

The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-13605

Published Feb 24, 2025

The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10562

Published Jan 7, 2025

The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-47807

Published Jan 2, 2025

Missing Authorization vulnerability in 10Web 10WebAnalytics wd-google-analytics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 10WebAna…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-45272

Published Jan 2, 2025

Missing Authorization vulnerability in 10Web 10Web Map Builder for Google Maps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 10Web Map…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33995

Published Dec 13, 2024

Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo G…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10704

Published Nov 29, 2024

The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Store…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10265

Published Nov 10, 2024

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg wit…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9878

Published Nov 5, 2024

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and includin…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9630

Published Oct 25, 2024

The WPS Telegram Chat plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when accessing messages in versions up to, and including, 4.6.0.…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9628

Published Oct 25, 2024

The WPS Telegram Chat plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Wps_Telegram_Chat_Admin::c…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9607

Published Oct 25, 2024

The 10Web Social Post Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all vers…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5968

Published Oct 9, 2024

The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery settings, which could allow high privilege users such as admin…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-44043

Published Oct 6, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Stored XSS.This issue affec…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8283

Published Sep 30, 2024

The Slider by 10Web WordPress plugin before 1.2.59 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8633

Published Sep 26, 2024

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 103 CVEsPage 1 of 5