Skip to main content

Vendor/product archive

10web / form_maker CVEs

Beta · best-effort

24 CVEs tagged to 10web / form_maker2 Critical, 5 High, 14 Medium, 3 Low, 0 Unrated.

CVE-2024-13053

Published May 15, 2025

The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10680

Published Apr 16, 2025

The Form Maker by 10Web WordPress plugin before 1.15.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10560

Published Mar 25, 2025

The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-10558

Published Mar 24, 2025

The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-13605

Published Feb 24, 2025

The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10562

Published Jan 7, 2025

The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-10265

Published Nov 10, 2024

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg wit…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8633

Published Sep 26, 2024

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43220

Published Aug 12, 2024

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Reflected XSS.This…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6130

Published Jul 1, 2024

The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48290

Published Jun 4, 2024

Improper Restriction of Excessive Authentication Attempts vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Functionality Bypass.This issue affects Form Maker by…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34437

Published May 14, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Stored XSS.This issue affe…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2258

Published Apr 27, 2024

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name autofilled i…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32534

Published Apr 17, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Stored XSS.This issue affe…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2112

Published Apr 9, 2024

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0667

Published Jan 27, 2024

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-45071

Published Oct 18, 2023

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin <= 1.15.18 version…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-45070

Published Oct 18, 2023

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin <= 1.15.18 vers…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-4666

Published Oct 16, 2023

The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arb…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-3300

Published Oct 25, 2022

The Form Maker by 10Web WordPress plugin before 1.15.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-1564

Published May 30, 2022

The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which could allow high privilege user such as admin to perform Cross…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24526

Published Aug 16, 2021

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10866

Published May 23, 2019

In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-11590

Published Apr 29, 2019

The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal,…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1