Home/Product/10web form maker
Product

10web form maker

26 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-13053
< 1.15.33
The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high
4.8MEDIUM
CVE-2024-10680
< 1.15.32
The Form Maker by 10Web WordPress plugin before 1.15.32 does not sanitise and escape some of its settings, which could allow high
4.8MEDIUM
CVE-2024-10560
< 1.15.30
The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high
3.5LOW
CVE-2024-10558
< 1.15.30
The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high
3.5LOW
CVE-2024-13605
< 1.15.33
The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high
4.8MEDIUM
CVE-2024-10562
< 1.15.31
The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could allow high
2.7LOW
CVE-2024-10265
< 1.15.31
The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-S
6.1MEDIUM
CVE-2024-8633
< 1.15.28
The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site
5.5MEDIUM
CVE-2024-43220
< 1.15.27
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 10Web Form Builder Te
7.1HIGH
CVE-2024-6130
< 1.15.26
The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could allow high
4.8MEDIUM
CVE-2023-48290
< 1.15.21
Improper Restriction of Excessive Authentication Attempts vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Func
5.3MEDIUM
CVE-2024-34437
< 1.15.25
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Builder Team Form
5.9MEDIUM
CVE-2024-2258
< 1.15.25
The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site
4.4MEDIUM
CVE-2024-32534
< 1.15.24
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Builder Team Form
5.9MEDIUM
CVE-2024-2112
< 1.15.23
The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensitive Informa
5.9MEDIUM
CVE-2024-0667
<= 1.15.21
The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Reques
5.4MEDIUM
CVE-2023-45071
< 1.15.19
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web - Mobile-Friendly Drag & Dr
7.1HIGH
CVE-2023-45070
< 1.15.19
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web - Mobile-Friendly Drag &
7.1HIGH
CVE-2023-4666
< 1.15.20
The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user in
9.8CRITICAL
CVE-2022-3300
< 1.15.6
The Form Maker by 10Web WordPress plugin before 1.15.6 does not properly sanitise and escape a parameter before using it in a SQL
7.2HIGH
CVE-2022-1564
<= 1.14.12
The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which could allow h
4.8MEDIUM
CVE-2021-24526
< 1.13.60
The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its For
5.4MEDIUM
CVE-2019-10866
< 1.13.3
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters
9.8CRITICAL
CVE-2019-11590
< 1.13.5
The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resulta
8.8HIGH
CVE-2018-10504
< 1.12.24
The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.
7.8HIGH
CVE-2018-5991
all versions
SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats request, a d
9.8CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin