Skip to main content

Vendor/product archive

10web / slider CVEs

Beta · best-effort

9 CVEs tagged to 10web / slider0 Critical, 3 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2024-10566

Published Mar 25, 2025

The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10565

Published Mar 25, 2025

The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8283

Published Sep 30, 2024

The Slider by 10Web WordPress plugin before 1.2.59 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7150

Published Aug 8, 2024

The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 1.2.57 du…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-6408

Published Jul 31, 2024

The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow high privilege users such as editors and above to perform Cros…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6026

Published Jul 11, 2024

The Slider by 10Web WordPress plugin before 1.2.56 does not sanitise and escape some of its Slide options, which could allow authenticated users with access to the Sliders (by de…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32578

Published Apr 18, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Slider by 10Web allows Reflected XSS.This issue affects Slider by 10Web…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4197

Published Dec 26, 2022

The Sliderby10Web WordPress plugin before 1.2.53 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Si…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24132

Published Mar 18, 2021

The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were vulnerable, allowing a high pri…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1