CVEs we hold for 10web
Records whose assigning authority named 10web as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-9829Photo Gallery by 10Web <= 1.8.41 - Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode…10Web – Mobile-Friendly Image Gallery
CVE-2026-86311Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.44 - Authenticated (Contributor+) Stored Cross-Site…10Web – Mobile-Friendly Image Gallery
CVE-2026-85652Photo Gallery by 10Web <= 1.8.44 - Authenticated (Author+) SQL Injection via 'album_id' Shortcode Attribute10Web – Mobile-Friendly Image Gallery
CVE-2026-85645Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.46 - Reflected Cross-Site Scripting10Web – Mobile-Friendly Drag & Drop Contact Form Builder
CVE-2026-7048Photo Gallery by 10Web <= 1.8.40 - Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute10Web – Mobile-Friendly Image Gallery
CVE-2026-66635WordPress Slider by 10Web plugin <= 1.2.62 - CSRF to Arbitrary File Deletion vulnerability10Web
CVE-2026-66616WordPress Form Maker by 10Web plugin <= 1.15.46 - Cross Site Scripting (XSS) vulnerability10Web
CVE-2026-4388Form Maker by 10Web <= 1.15.40 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Text Box10Web – Mobile-Friendly Drag & Drop Contact Form Builder
CVE-2026-3359Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.42 - Unauthenticated SQL Injection via…10Web – Mobile-Friendly Drag & Drop Contact Form Builder
CVE-2026-3330Form Maker by 10Web <= 1.15.40 - Authenticated (Administrator+) SQL Injection via 'ip_search' Parameter10Web – Mobile-Friendly Drag & Drop Contact Form Builder
CVE-2026-32330WordPress Photo Gallery by 10Web plugin <= 1.8.37 - Cross Site Request Forgery (CSRF) vulnerability10Web
CVE-2026-27360WordPress Photo Gallery by 10Web plugin <= 1.8.38 - Cross Site Scripting (XSS) vulnerability10Web
CVE-2026-15993Form Maker by 10Web <= 1.15.44 - Authenticated (Subscriber+) SQL Injection via '{username}' Placeholder in…10Web – Mobile-Friendly Drag & Drop Contact Form Builder
CVE-2026-14287TenWeb Speed Optimizer < 2.33.5 - Unauthenticated Stored XSS via Critical CSS Token BypassUnknown 10Web Booster
CVE-2026-11777Form Maker by 10Web <= 1.15.43 - Authenticated (Administrator+) SQL Injection via 'name' Parameter10Web – Mobile-Friendly Drag & Drop Contact Form Builder
CVE-2026-11776Form Maker by 10Web <= 1.15.43 - Authenticated (Adminsitrator+) SQL Injection via 'groupids' Parameter10Web – Mobile-Friendly Drag & Drop Contact Form Builder
CVE-2026-1065Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via SVG file10Web – Mobile-Friendly Drag & Drop Contact Form Builder
CVE-2026-1058Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via Hidden Field10Web – Mobile-Friendly Drag & Drop Contact Form Builder
CVE-2026-1036Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.36 - Missing Authorization to Unauthenticated Arbitrary…10Web – Mobile-Friendly Image Gallery
CVE-2025-48341WordPress Form Maker by 10Web plugin <= 1.15.33 - Cross Site Scripting (XSS) Vulnerability10Web
CVE-2025-2269Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.34 Reflected Cross-Site Scripting via 'image_id' Parameter10Web – Mobile-Friendly Image Gallery
CVE-2025-1337710Web Booster <= 2.32.7 - Authenticated (Subscriber+) Arbitrary Folder Deletion via two_clear_page_cache10Web Booster – Website speed optimization, Cache & Page…
CVE-2024-9878Photo Gallery by 10Web <= 1.8.30 - Authenticated (Administrator+) Stored Cross-Site Scripting10Web – Mobile-Friendly Image Gallery
CVE-2024-8633Form Maker <= 1.15.27 - Authenticated (Administrator+) Stored Cross-Site Scripting10Web – Mobile-Friendly Drag & Drop Contact Form Builder
CVE-2024-7150Slider by 10Web – Responsive Image Slider <= 1.2.57 - Authenticated (Contributor+) SQL Injection via id Parameter10Web – Responsive Image Slider
CVE-2024-5481Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Path Traversal via…10Web – Mobile-Friendly Image Gallery
CVE-2024-5426Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Stored Cross-Site…10Web – Mobile-Friendly Image Gallery
CVE-2024-44043WordPress Photo Gallery by 10Web plugin <= 1.8.27 - Cross Site Scripting (XSS) vulnerability10Web
CVE-2024-43220WordPress Form Maker by 10Web plugin <= 1.15.26 - Reflected Cross Site Scripting (XSS) vulnerability10Web
CVE-2024-34437WordPress Form Maker by 10Web plugin <= 1.15.24 - Cross Site Scripting (XSS) vulnerability10Web
CVE-2024-32578WordPress Sliderby10Web plugin <= 1.2.54 - Cross Site Scripting (XSS) vulnerability10Web
CVE-2024-32534WordPress Form Maker plugin <= 1.15.23 - Cross Site Scripting (XSS) vulnerability10Web
CVE-2024-31116WordPress 10Web Map Builder for Google Maps plugin <= 1.0.74 - SQL Injection vulnerability10Web Map Builder for Google Maps
CVE-2024-29833WordPress Photo Gallery Plugin <= 1.8.21 Stored Cross Site Scripting in UploadHandler10Web PhotoGallery
CVE-2024-29832WordPress Photo Gallery Plugin <= 1.8.21 Unauthenticated Reflected Cross Site Scripting in GalleryBox current_url10Web PhotoGallery
CVE-2024-29810WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg thumb_url10Web PhotoGallery
CVE-2024-29809WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg image_url10Web PhotoGallery
CVE-2024-29808WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg image_id10Web PhotoGallery
CVE-2024-2296Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21 - Authenticated (Admin+) Stored Cross-Site Scripting…10Web – Mobile-Friendly Image Gallery
CVE-2024-2258Form Maker by 10Web <= 1.15.24 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting10Web – Mobile-Friendly Drag & Drop Contact Form Builder
CVE-2024-2112Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.22 - Sensitive Information Exposure10Web – Mobile-Friendly Drag & Drop Contact Form Builder
CVE-2024-10265Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.30 - Reflected Cross-Site Scripting via…10Web – Mobile-Friendly Drag & Drop Contact Form Builder
CVE-2024-0667Form-Maker (twb_form-maker) <= 1.15.21 - Cross-Site Request Forgery to Limited Code Execution via Execute10Web – Mobile-Friendly Drag & Drop Contact Form Builder
CVE-2024-0221Photo Gallery by 10Web - Mobile-Friendly Image Gallery <= 1.8.19 - Directory Traversal to Arbitrary File Rename10Web – Mobile-Friendly Image Gallery
CVE-2023-698510Web AI Assistant – AI content writing assistant <= 1.0.18 - Missing Authorization to Arbitrary Plugin Installation10Web AI Assistant – AI content writing assistant
CVE-2023-6924Photo Gallery by 10Web <= 1.8.18 - Authenticated (Administrator+) Stored Cross-Site Scripting via Widget10Web – Mobile-Friendly Image Gallery
CVE-2023-5709WD WidgetTwitter <= 1.0.9 - Authenticated (Contributor+) SQL Injection via Shortcode10web WD WidgetTwitter
CVE-2023-555910Web Booster < 2.24.18 - Unauthenticated Arbitrary Option DeletionUnknown 10Web Booster
CVE-2023-5048WDContactFormBuilder <= 1.0.72 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode10web WDContactFormBuilder
CVE-2023-48290WordPress Form Maker by 10Web plugin <= 1.15.20 - Captcha Bypass Vulnerability vulnerability10Web
CVE-2023-47807WordPress 10WebAnalytics plugin <= 1.2.12 - Broken Access Control vulnerability10Web 10WebAnalytics
CVE-2023-45272WordPress 10Web Map Builder for Google Maps plugin <= 1.0.73 - Notice Dismissal Vulnerability10Web Map Builder for Google Maps
CVE-2023-45071WordPress Form Maker by 10Web Plugin <= 1.15.18 is vulnerable to Cross Site Scripting (XSS)10Web – Mobile-Friendly Drag & Drop Contact Form Builder
CVE-2023-45070WordPress Form Maker by 10Web Plugin <= 1.15.18 is vulnerable to Cross Site Scripting (XSS)10Web – Mobile-Friendly Drag & Drop Contact Form Builder
CVE-2023-34375WordPress Seo By 10Web Plugin <= 1.2.9 is vulnerable to Cross Site Scripting (XSS)10Web
CVE-2023-003710WebMapBuilder < 1.0.73 - Unauthenticated SQLiUnknown 10Web Map Builder for Google Maps
CVE-2022-475810WebMapBuilder < 1.0.72 - Contributor+ Stored XSS via ShortcodeUnknown 10WebMapBuilder
CVE-2021-2504710Web Social Photo Feed < 1.4.29 - Reflected Cross-Site Scripting (XSS)Unknown 10Web Social Photo Feed
CVE-2021-24310Photo Gallery < 1.5.67 - Authenticated Stored Cross-Site Scripting via Gallery Title10Web – Mobile-Friendly Image Gallery
CVE-2020-3685310WebMapBuilder <= 1.0.63 - Unauthenticated Stored Cross-Site Scripting via Plugin Settings Change10Web Map Builder for Google Maps
66 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.