Vulnerability index

Browse CVEs

68 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2025-13377 The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to arbitrary folder deletion due to i… 10web Booster 2.32.11+ Fix from $1,9502025-12-06 MEDIUM 6.1 CVE-2025-0613 The Photo Gallery by 10Web WordPress plugin before 1.8.34 does not sanitised and escaped comment added on images by unauthenticated users, leading t… Photo Gallery 1.8.34+ Fix from $1,6002025-03-31 MEDIUM 6.1 CVE-2024-10565 The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as… Slider 1.2.62+ Fix from $1,6002025-03-25 MEDIUM 6.1 CVE-2024-10566 The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as… Slider 1.2.62+ Fix from $1,6002025-03-25 MEDIUM 6.1 CVE-2024-10265 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t… Form Maker 1.15.31+ Fix from $1,6002024-11-10 MEDIUM 6.5 CVE-2024-9628 The WPS Telegram Chat plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on t… Wps Telegram Chat after 4.5.4 Fix from $1,6002024-10-25 MEDIUM 5.3 CVE-2024-9630 The WPS Telegram Chat plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when accessing messages in version… Wps Telegram Chat after 4.5.4 Fix from $1,6002024-10-25 MEDIUM 6.1 CVE-2024-9607 The 10Web Social Post Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate e… 10web Social Post Feed after 1.2.9 Fix from $1,6002024-10-25 MEDIUM 6.1 CVE-2024-43220 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10… Form Maker 1.15.27+ Fix from $1,6002024-08-12 HIGH 8.8 CVE-2024-7150 The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions u… Slider 1.2.58+ Fix from $1,9502024-08-08 MEDIUM 6.1 CVE-2024-6272 The SpiderContacts WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflec… Spidercontacts after 1.1.7 Fix from $1,6002024-07-31 MEDIUM 5.4 CVE-2024-6408 The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow high privilege users such as edi… Slider 1.2.57+ Fix from $1,6002024-07-31 MEDIUM 5.4 CVE-2024-6026 The Slider by 10Web WordPress plugin before 1.2.56 does not sanitise and escape some of its Slide options, which could allow authenticated users wit… Slider 1.2.56+ Fix from $1,6002024-07-11 HIGH 8.8 CVE-2024-5481 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including,… Photo Gallery 1.8.24+ Fix from $1,9502024-06-07 MEDIUM 5.4 CVE-2024-5426 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘svg’ parameter … Photo Gallery 1.8.24+ Fix from $1,6002024-06-07 MEDIUM 5.3 CVE-2023-48290 Improper Restriction of Excessive Authentication Attempts vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Functionality Bypass.Th… Form Maker 1.15.21+ Fix from $1,6002024-06-04 MEDIUM 5.3 CVE-2024-33586 Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through 1.8.20. Photo Gallery 1.8.21+ Fix from $1,6002024-04-29 MEDIUM 5.4 CVE-2024-2258 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a us… Form Maker 1.15.25+ Fix from $1,6002024-04-27 MEDIUM 6.1 CVE-2024-32583 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Photo Gallery Team Photo Gallery by 10Web allow… Photo Gallery 1.8.22+ Fix from $1,6002024-04-18 MEDIUM 6.1 CVE-2024-32578 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Slider by 10Web allows Reflected XSS.This… Slider 1.2.55+ Fix from $1,6002024-04-18 HIGH 7.5 CVE-2024-2112 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in al… Form Maker 1.15.23+ Fix from $1,9502024-04-09 HIGH 7.2 CVE-2024-31116 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web 10Web Map Builder for Google Maps.This is… Map Builder For Google Maps after 1.0.74 Fix from $1,9502024-03-31 MEDIUM 5.4 CVE-2024-29833 The image upload component allows SVG files and the regular expression used to remove script tags can be bypassed by using a Cross Site Scripting pay… Photo Gallery 1.8.22+ Fix from $1,6002024-03-26 MEDIUM 6.1 CVE-2024-29832 The current_url parameter of the AJAX call to the GalleryBox action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of t… Photo Gallery 1.8.22+ Fix from $1,6002024-03-26 MEDIUM 5.4 CVE-2024-29808 The image_id parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of t… Photo Gallery 1.8.22+ Fix from $1,6002024-03-26 MEDIUM 5.4 CVE-2024-29809 The image_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of … Photo Gallery 1.8.22+ Fix from $1,6002024-03-26 MEDIUM 5.4 CVE-2024-29810 The thumb_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of … Photo Gallery 1.8.22+ Fix from $1,6002024-03-26 HIGH 7.2 CVE-2024-0221 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu… Photo Gallery 1.8.20+ Fix from $1,9502024-02-05 HIGH 8.8 CVE-2023-6985 The 10Web AI Assistant – AI content writing assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… Ai Assistant 1.0.19+ Fix from $1,9502024-02-05 MEDIUM 6.3 CVE-2024-0667 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve… Form Maker after 1.15.21 Fix from $1,6002024-01-27