Vulnerability index

Browse CVEs

68 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

10web Booster CRITICAL 9.1
CVE-2023-5559

The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to del…

Fix: 2.24.18+
Fix from $2,300 2023-11-27
Seo MEDIUM 6.1
CVE-2023-34375

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in 10Web SEO by 10Web plugin <= 1.2.9 versions.

Fix: after 1.2.9
Fix from $1,600 2023-11-16
Form Maker MEDIUM 6.1
CVE-2023-45070

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form …

Fix: 1.15.19+
Fix from $1,600 2023-10-18
Form Maker MEDIUM 6.1
CVE-2023-45071

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Bui…

Fix: 1.15.19+
Fix from $1,600 2023-10-18
Form Maker CRITICAL 9.8
CVE-2023-4666

The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unaut…

Fix: 1.15.20+
Fix from $2,300 2023-10-16
Image Optimizer MEDIUM 6.1
CVE-2023-2122

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter before rendering it in the pl…

Fix: 1.0.27+
Fix from $1,600 2023-08-16
Photo Gallery MEDIUM 6.1
CVE-2021-46889

The 10Web Photo Gallery plugin through 1.5.69 for WordPress allows XSS via theme_id for bwg_frontend_data. NOTE: other parameters are covered by CVE-…

Fix: after 1.5.69
Fix from $1,600 2023-06-07
10web Social Post Feed MEDIUM 6.1
CVE-2023-2503

The 10Web Social Post Feed WordPress plugin before 1.2.9 does not sanitise and escape some parameter before outputting it back in a page, leading to …

Fix: 1.2.9+
Fix from $1,600 2023-06-05
Map Builder For Google Maps CRITICAL 9.8
CVE-2023-0037

The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQ…

Fix: 1.0.73+
Fix from $2,300 2023-03-13
Map Builder For Google Maps MEDIUM 5.4
CVE-2022-4758

The 10WebMapBuilder WordPress plugin before 1.0.72 does not validate and escape some of its shortcode attributes before outputting them back in the p…

Fix: 1.0.72+
Fix from $1,600 2023-01-23
Photo Gallery MEDIUM 5.4
CVE-2022-4058

The Photo Gallery by 10Web WordPress plugin before 1.8.3 does not validate and escape some parameters before outputting them back in in JS code later…

Fix: 1.8.3+
Fix from $1,600 2022-12-19
Photo Gallery MEDIUM 6.1
CVE-2021-31693

The 10Web Photo Gallery plugin through 1.5.68 for WordPress allows XSS via album_gallery_id_0, bwg_album_search_0, and type_0 for bwg_frontend_data. …

Fix: after 1.5.68
Fix from $1,600 2022-11-29
Form Maker HIGH 7.2
CVE-2022-3300

The Form Maker by 10Web WordPress plugin before 1.15.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading …

Fix: 1.15.6+
Fix from $1,950 2022-10-25
Photo Gallery CRITICAL 9.8
CVE-2022-1281EPSS 23%

The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, maki…

Fix: after 1.6.3
Fix from $2,300 2022-05-02
Photo Gallery MEDIUM 6.1
CVE-2022-1282

The Photo Gallery by 10Web WordPress plugin before 1.6.3 does not properly sanitize the $_GET['image_url'] variable, which is reflected back to the u…

Fix: 1.6.3+
Fix from $1,600 2022-05-02
Photo Gallery CRITICAL 9.8
CVE-2022-0169EPSS 75%

The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a …

Fix: 1.6.0+
Fix from $2,300 2022-03-14
Spidercalendar MEDIUM 6.1
CVE-2022-0212

The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the …

Fix: after 1.5.65
Fix from $1,600 2022-02-14
10websocial MEDIUM 6.1
CVE-2021-25047

The 10Web Social Photo Feed WordPress plugin before 1.4.29 was affected by a reflected Cross-Site Scripting (XSS) vulnerability in the wdi_apply_chan…

Fix: 1.4.29+
Fix from $1,600 2022-01-10
Photo Gallery MEDIUM 6.1
CVE-2021-25041

The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues via the bwg_album_breadcrumb_0…

Fix: 1.5.68+
Fix from $1,600 2021-12-06
Form Maker MEDIUM 5.4
CVE-2021-24526

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outp…

Fix: 1.13.60+
Fix from $1,600 2021-08-16
Photo Gallery MEDIUM 6.1
CVE-2021-24362

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded SVG files added to a gallery d…

Fix: 1.5.75+
Fix from $1,600 2021-08-16
Photo Gallery MEDIUM 6.1
CVE-2021-24291EPSS 14%

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issu…

Fix: 1.5.69+
Fix from $1,600 2021-05-14
Photo Gallery CRITICAL 9.8
CVE-2021-24139EPSS 5%

Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models…

Fix: 1.5.55+
Fix from $2,300 2021-03-18
Slider HIGH 8.8
CVE-2021-24132

The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were v…

Fix: 1.2.36+
Fix from $1,950 2021-03-18
Photo Gallery MEDIUM 5.4
CVE-2015-1394

Multiple cross-site scripting (XSS) vulnerabilities in the Photo Gallery plugin before 1.2.11 for WordPress allow remote authenticated users to injec…

Fix: 1.2.11+
Fix from $1,600 2020-02-08
Photo Gallery CRITICAL 9.8
CVE-2019-16119EPSS 25%

SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php albu…

Fix: 1.5.35+
Fix from $2,300 2019-09-08
Photo Gallery MEDIUM 6.1
CVE-2019-16117

Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.

Fix: 1.5.35+
Fix from $1,600 2019-09-08
Photo Gallery MEDIUM 6.1
CVE-2019-16118EPSS 5%

Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.

Fix: 1.5.35+
Fix from $1,600 2019-09-08
Photo Gallery HIGH 8.8
CVE-2015-9380

The photo-gallery plugin before 1.2.42 for WordPress has CSRF.

Fix: 1.2.42+
Fix from $1,950 2019-08-30
Photo Gallery MEDIUM 5.4
CVE-2019-14797

The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS.

Fix: 1.5.23+
Fix from $1,600 2019-08-09