Vulnerability index

Browse CVEs

68 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

10web Booster HIGH 8.1
CVE-2025-13377

The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to arbitrary folder deletion due to i…

Fix: 2.32.11+
Fix from $1,950 2025-12-06
Photo Gallery MEDIUM 6.1
CVE-2025-0613

The Photo Gallery by 10Web WordPress plugin before 1.8.34 does not sanitised and escaped comment added on images by unauthenticated users, leading t…

Fix: 1.8.34+
Fix from $1,600 2025-03-31
Slider MEDIUM 6.1
CVE-2024-10565

The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as…

Fix: 1.2.62+
Fix from $1,600 2025-03-25
Slider MEDIUM 6.1
CVE-2024-10566

The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as…

Fix: 1.2.62+
Fix from $1,600 2025-03-25
Form Maker MEDIUM 6.1
CVE-2024-10265

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t…

Fix: 1.15.31+
Fix from $1,600 2024-11-10
Wps Telegram Chat MEDIUM 6.5
CVE-2024-9628

The WPS Telegram Chat plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on t…

Fix: after 4.5.4
Fix from $1,600 2024-10-25
Wps Telegram Chat MEDIUM 5.3
CVE-2024-9630

The WPS Telegram Chat plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when accessing messages in version…

Fix: after 4.5.4
Fix from $1,600 2024-10-25
10web Social Post Feed MEDIUM 6.1
CVE-2024-9607

The 10Web Social Post Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate e…

Fix: after 1.2.9
Fix from $1,600 2024-10-25
Form Maker MEDIUM 6.1
CVE-2024-43220

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10…

Fix: 1.15.27+
Fix from $1,600 2024-08-12
Slider HIGH 8.8
CVE-2024-7150

The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions u…

Fix: 1.2.58+
Fix from $1,950 2024-08-08
Spidercontacts MEDIUM 6.1
CVE-2024-6272

The SpiderContacts WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflec…

Fix: after 1.1.7
Fix from $1,600 2024-07-31
Slider MEDIUM 5.4
CVE-2024-6408

The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow high privilege users such as edi…

Fix: 1.2.57+
Fix from $1,600 2024-07-31
Slider MEDIUM 5.4
CVE-2024-6026

The Slider by 10Web WordPress plugin before 1.2.56 does not sanitise and escape some of its Slide options, which could allow authenticated users wit…

Fix: 1.2.56+
Fix from $1,600 2024-07-11
Photo Gallery HIGH 8.8
CVE-2024-5481

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including,…

Fix: 1.8.24+
Fix from $1,950 2024-06-07
Photo Gallery MEDIUM 5.4
CVE-2024-5426

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘svg’ parameter …

Fix: 1.8.24+
Fix from $1,600 2024-06-07
Form Maker MEDIUM 5.3
CVE-2023-48290

Improper Restriction of Excessive Authentication Attempts vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Functionality Bypass.Th…

Fix: 1.15.21+
Fix from $1,600 2024-06-04
Photo Gallery MEDIUM 5.3
CVE-2024-33586

Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through 1.8.20.

Fix: 1.8.21+
Fix from $1,600 2024-04-29
Form Maker MEDIUM 5.4
CVE-2024-2258

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a us…

Fix: 1.15.25+
Fix from $1,600 2024-04-27
Photo Gallery MEDIUM 6.1
CVE-2024-32583

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Photo Gallery Team Photo Gallery by 10Web allow…

Fix: 1.8.22+
Fix from $1,600 2024-04-18
Slider MEDIUM 6.1
CVE-2024-32578

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Slider by 10Web allows Reflected XSS.This…

Fix: 1.2.55+
Fix from $1,600 2024-04-18
Form Maker HIGH 7.5
CVE-2024-2112

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in al…

Fix: 1.15.23+
Fix from $1,950 2024-04-09
Map Builder For Google Maps HIGH 7.2
CVE-2024-31116

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web 10Web Map Builder for Google Maps.This is…

Fix: after 1.0.74
Fix from $1,950 2024-03-31
Photo Gallery MEDIUM 5.4
CVE-2024-29833

The image upload component allows SVG files and the regular expression used to remove script tags can be bypassed by using a Cross Site Scripting pay…

Fix: 1.8.22+
Fix from $1,600 2024-03-26
Photo Gallery MEDIUM 6.1
CVE-2024-29832

The current_url parameter of the AJAX call to the GalleryBox action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of t…

Fix: 1.8.22+
Fix from $1,600 2024-03-26
Photo Gallery MEDIUM 5.4
CVE-2024-29808

The image_id parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of t…

Fix: 1.8.22+
Fix from $1,600 2024-03-26
Photo Gallery MEDIUM 5.4
CVE-2024-29809

The image_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of …

Fix: 1.8.22+
Fix from $1,600 2024-03-26
Photo Gallery MEDIUM 5.4
CVE-2024-29810

The thumb_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of …

Fix: 1.8.22+
Fix from $1,600 2024-03-26
Photo Gallery HIGH 7.2
CVE-2024-0221

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu…

Fix: 1.8.20+
Fix from $1,950 2024-02-05
Ai Assistant HIGH 8.8
CVE-2023-6985

The 10Web AI Assistant – AI content writing assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi…

Fix: 1.0.19+
Fix from $1,950 2024-02-05
Form Maker MEDIUM 6.3
CVE-2024-0667

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve…

Fix: after 1.15.21
Fix from $1,600 2024-01-27