Vulnerability index

Browse CVEs

68 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2023-5559 The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to del… 10web Booster 2.24.18+ Fix from $2,3002023-11-27 MEDIUM 6.1 CVE-2023-34375 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in 10Web SEO by 10Web plugin <= 1.2.9 versions. Seo after 1.2.9 Fix from $1,6002023-11-16 MEDIUM 6.1 CVE-2023-45070 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form … Form Maker 1.15.19+ Fix from $1,6002023-10-18 MEDIUM 6.1 CVE-2023-45071 Unauth. Stored Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Bui… Form Maker 1.15.19+ Fix from $1,6002023-10-18 CRITICAL 9.8 CVE-2023-4666 The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unaut… Form Maker 1.15.20+ Fix from $2,3002023-10-16 MEDIUM 6.1 CVE-2023-2122 The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter before rendering it in the pl… Image Optimizer 1.0.27+ Fix from $1,6002023-08-16 MEDIUM 6.1 CVE-2021-46889 The 10Web Photo Gallery plugin through 1.5.69 for WordPress allows XSS via theme_id for bwg_frontend_data. NOTE: other parameters are covered by CVE-… Photo Gallery after 1.5.69 Fix from $1,6002023-06-07 MEDIUM 6.1 CVE-2023-2503 The 10Web Social Post Feed WordPress plugin before 1.2.9 does not sanitise and escape some parameter before outputting it back in a page, leading to … 10web Social Post Feed 1.2.9+ Fix from $1,6002023-06-05 CRITICAL 9.8 CVE-2023-0037 The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQ… Map Builder For Google Maps 1.0.73+ Fix from $2,3002023-03-13 MEDIUM 5.4 CVE-2022-4758 The 10WebMapBuilder WordPress plugin before 1.0.72 does not validate and escape some of its shortcode attributes before outputting them back in the p… Map Builder For Google Maps 1.0.72+ Fix from $1,6002023-01-23 MEDIUM 5.4 CVE-2022-4058 The Photo Gallery by 10Web WordPress plugin before 1.8.3 does not validate and escape some parameters before outputting them back in in JS code later… Photo Gallery 1.8.3+ Fix from $1,6002022-12-19 MEDIUM 6.1 CVE-2021-31693 The 10Web Photo Gallery plugin through 1.5.68 for WordPress allows XSS via album_gallery_id_0, bwg_album_search_0, and type_0 for bwg_frontend_data. … Photo Gallery after 1.5.68 Fix from $1,6002022-11-29 HIGH 7.2 CVE-2022-3300 The Form Maker by 10Web WordPress plugin before 1.15.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading … Form Maker 1.15.6+ Fix from $1,9502022-10-25 CRITICAL 9.8 CVE-2022-1281EPSS 23% The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, maki… Photo Gallery after 1.6.3 Fix from $2,3002022-05-02 MEDIUM 6.1 CVE-2022-1282 The Photo Gallery by 10Web WordPress plugin before 1.6.3 does not properly sanitize the $_GET['image_url'] variable, which is reflected back to the u… Photo Gallery 1.6.3+ Fix from $1,6002022-05-02 CRITICAL 9.8 CVE-2022-0169EPSS 75% The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a … Photo Gallery 1.6.0+ Fix from $2,3002022-03-14 MEDIUM 6.1 CVE-2022-0212 The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the … Spidercalendar after 1.5.65 Fix from $1,6002022-02-14 MEDIUM 6.1 CVE-2021-25047 The 10Web Social Photo Feed WordPress plugin before 1.4.29 was affected by a reflected Cross-Site Scripting (XSS) vulnerability in the wdi_apply_chan… 10websocial 1.4.29+ Fix from $1,6002022-01-10 MEDIUM 6.1 CVE-2021-25041 The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues via the bwg_album_breadcrumb_0… Photo Gallery 1.5.68+ Fix from $1,6002021-12-06 MEDIUM 5.4 CVE-2021-24526 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outp… Form Maker 1.13.60+ Fix from $1,6002021-08-16 MEDIUM 6.1 CVE-2021-24362 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded SVG files added to a gallery d… Photo Gallery 1.5.75+ Fix from $1,6002021-08-16 MEDIUM 6.1 CVE-2021-24291EPSS 14% The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issu… Photo Gallery 1.5.69+ Fix from $1,6002021-05-14 CRITICAL 9.8 CVE-2021-24139EPSS 5% Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models… Photo Gallery 1.5.55+ Fix from $2,3002021-03-18 HIGH 8.8 CVE-2021-24132 The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were v… Slider 1.2.36+ Fix from $1,9502021-03-18 MEDIUM 5.4 CVE-2015-1394 Multiple cross-site scripting (XSS) vulnerabilities in the Photo Gallery plugin before 1.2.11 for WordPress allow remote authenticated users to injec… Photo Gallery 1.2.11+ Fix from $1,6002020-02-08 CRITICAL 9.8 CVE-2019-16119EPSS 25% SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php albu… Photo Gallery 1.5.35+ Fix from $2,3002019-09-08 MEDIUM 6.1 CVE-2019-16117 Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php. Photo Gallery 1.5.35+ Fix from $1,6002019-09-08 MEDIUM 6.1 CVE-2019-16118EPSS 5% Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php. Photo Gallery 1.5.35+ Fix from $1,6002019-09-08 HIGH 8.8 CVE-2015-9380 The photo-gallery plugin before 1.2.42 for WordPress has CSRF. Photo Gallery 1.2.42+ Fix from $1,9502019-08-30 MEDIUM 5.4 CVE-2019-14797 The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS. Photo Gallery 1.5.23+ Fix from $1,6002019-08-09