10web records
103 published records for vendor 10web.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 1.9%
- Pre-auth RCE
- 5
- With a fix record
- 31.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')65
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')14
- CWE-862 Missing Authorization9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')7
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
The weakness classes this vendor ships most often: where to look.
CWEAll records
103 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
61This week | CVE-2022-0169Weaponized | Photo Gallery by 10Web < 1.6.0 - Unauthenticated SQL Injection10web · photo gallery · CWE-89 | Critical9.8 | — | 74.6% | Mar 14, 2022 |
52Plan | CVE-2022-1281Proof of concept | Photo Gallery < 1.6.3 - Unauthenticated SQL Injection10web · photo gallery · CWE-89 | Critical9.8 | — | 43.1% | May 2, 2022 |
49Plan | CVE-2014-9312Weaponized | Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.10web · photo gallery · CWE-434 | High8.8 | — | 45.4% | Aug 28, 2017 |
46Plan | CVE-2019-16119Proof of concept | SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries10web · photo gallery · CWE-89 | Critical9.8 | — | 24.8% | Sep 8, 2019 |
41Plan | CVE-2019-10866Proof of concept | In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the fi10web · form maker · CWE-89 | Critical9.8 | — | 6.2% | May 23, 2019 |
41Plan | CVE-2021-24139Proof of concept | Photo Gallery by 10Web < 1.5.55 - Unauthenticated SQL Injection10web · photo gallery · CWE-89 | Critical9.8 | — | 5.5% | Mar 18, 2021 |
40Plan | CVE-2019-14313No exploit | A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress.10web · photo gallery · CWE-89 | Critical9.8 | — | 4.5% | Jul 30, 2019 |
40Plan | CVE-2023-0037Proof of concept | 10WebMapBuilder < 1.0.73 - Unauthenticated SQLi10web · map builder for google maps · CWE-89 | Critical9.8 | — | 3.9% | Mar 13, 2023 |
40Plan | CVE-2023-4666Proof of concept | Form-Maker < 1.15.20 - Unauthenticated Arbitrary File Upload10web · form maker · CWE-434 | Critical9.8 | — | 3.3% | Oct 16, 2023 |
37Monitor | CVE-2023-5559Proof of concept | 10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion10web · 10web booster · CWE-862 | Critical9.1 | — | 2.8% | Nov 27, 2023 |
36Monitor | CVE-2021-24132No exploit | Slider by 10Web < 1.2.36 - Multiple Authenticated SQL Injection10web · slider · CWE-89 | High8.8 | — | 2.6% | Mar 18, 2021 |
35Monitor | CVE-2023-6985Proof of concept | 10Web AI Assistant – AI content writing assistant <= 1.0.18 - Missing Authorization to Arbitrary Plugin Installation10web · ai assistant · CWE-862 | High8.8 | — | 1.4% | Feb 5, 2024 |
35Monitor | CVE-2019-11590No exploit | The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local f10web · form maker · CWE-22 | High8.8 | — | 1.2% | Apr 29, 2019 |
35Monitor | CVE-2015-9380No exploit | The photo-gallery plugin before 1.2.42 for WordPress has CSRF.10web · photo gallery · CWE-352 | High8.8 | — | 0.8% | Aug 30, 2019 |
35Monitor | CVE-2024-5481No exploit | Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Path Traversal via esc_dir Function10web · photo gallery · CWE-35 | High8.8 | — | 0.7% | Jun 7, 2024 |
35Monitor | CVE-2024-7150No exploit | Slider by 10Web – Responsive Image Slider <= 1.2.57 - Authenticated (Contributor+) SQL Injection via id Parameter10web · slider · CWE-89 | High8.8 | — | 0.6% | Aug 8, 2024 |
32Monitor | CVE-2025-13377No exploit | 10Web Booster <= 2.32.7 - Authenticated (Subscriber+) Arbitrary Folder Deletion via two_clear_page_cache10web · 10web booster · CWE-22 | High8.1 | — | 0.5% | Dec 6, 2025 |
31Monitor | CVE-2015-1055No exploit | SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via th10web · photo gallery · CWE-89 | High7.5 | — | 2.1% | Jan 16, 2015 |
30Monitor | CVE-2024-2112No exploit | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.22 - Sensitive Information Exposure10web · form maker · CWE-287 | High7.5 | — | 0.7% | Apr 9, 2024 |
28Monitor | CVE-2021-24291Proof of concept | Photo Gallery < 1.5.69 - Multiple Reflected Cross-Site Scripting (XSS)10web · photo gallery · CWE-79 | Medium6.1 | — | 14.5% | May 14, 2021 |
28Monitor | CVE-2017-12977No exploit | The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related10web · photo gallery · CWE-89 | High7.2 | — | 1.6% | Aug 20, 2017 |
28Monitor | CVE-2024-0221No exploit | Photo Gallery by 10Web - Mobile-Friendly Image Gallery <= 1.8.19 - Directory Traversal to Arbitrary File Rename10web · photo gallery · CWE-22 | High7.2 | — | 1.3% | Feb 5, 2024 |
28Monitor | CVE-2022-3300No exploit | Form Maker by 10Web < 1.15.6 - Admin+ SQLI10web · form maker · CWE-89 | High7.2 | — | 1.1% | Oct 25, 2022 |
28Monitor | CVE-2024-31116No exploit | WordPress 10Web Map Builder for Google Maps plugin <= 1.0.74 - SQL Injection vulnerability10web · map builder for google maps · CWE-89 | High7.2 | — | 0.5% | Mar 31, 2024 |
26Monitor | CVE-2019-16118Proof of concept | Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Option10web · photo gallery · CWE-79 | Medium6.1 | — | 5.3% | Sep 8, 2019 |
- CVE-2022-016961This week
Photo Gallery by 10Web < 1.6.0 - Unauthenticated SQL Injection
CriticalCVSS 9.8WeaponizedEPSS 75%10web · photo galleryMar 14, 2022
- CVE-2022-128152Plan
Photo Gallery < 1.6.3 - Unauthenticated SQL Injection
CriticalCVSS 9.8Proof of conceptEPSS 43%10web · photo galleryMay 2, 2022
- CVE-2014-931249Plan
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
HighCVSS 8.8WeaponizedEPSS 45%10web · photo galleryAug 28, 2017
- CVE-2019-1611946Plan
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries
CriticalCVSS 9.8Proof of conceptEPSS 25%10web · photo gallerySep 8, 2019
- CVE-2019-1086641Plan
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the fi
CriticalCVSS 9.8Proof of conceptEPSS 6%10web · form makerMay 23, 2019
- CVE-2021-2413941Plan
Photo Gallery by 10Web < 1.5.55 - Unauthenticated SQL Injection
CriticalCVSS 9.8Proof of conceptEPSS 6%10web · photo galleryMar 18, 2021
- CVE-2019-1431340Plan
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress.
CriticalCVSS 9.8No exploitEPSS 4%10web · photo galleryJul 30, 2019
- CVE-2023-003740Plan
10WebMapBuilder < 1.0.73 - Unauthenticated SQLi
CriticalCVSS 9.8Proof of conceptEPSS 4%10web · map builder for google mapsMar 13, 2023
- CVE-2023-466640Plan
Form-Maker < 1.15.20 - Unauthenticated Arbitrary File Upload
CriticalCVSS 9.8Proof of conceptEPSS 3%10web · form makerOct 16, 2023
- CVE-2023-555937Monitor
10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion
CriticalCVSS 9.1Proof of conceptEPSS 3%10web · 10web boosterNov 27, 2023
- CVE-2021-2413236Monitor
Slider by 10Web < 1.2.36 - Multiple Authenticated SQL Injection
HighCVSS 8.8No exploitEPSS 3%10web · sliderMar 18, 2021
- CVE-2023-698535Monitor
10Web AI Assistant – AI content writing assistant <= 1.0.18 - Missing Authorization to Arbitrary Plugin Installation
HighCVSS 8.8Proof of conceptEPSS 1%10web · ai assistantFeb 5, 2024
- CVE-2019-1159035Monitor
The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local f
HighCVSS 8.8No exploitEPSS 1%10web · form makerApr 29, 2019
- CVE-2015-938035Monitor
The photo-gallery plugin before 1.2.42 for WordPress has CSRF.
HighCVSS 8.8No exploitEPSS 1%10web · photo galleryAug 30, 2019
- CVE-2024-548135Monitor
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Path Traversal via esc_dir Function
HighCVSS 8.8No exploitEPSS 1%10web · photo galleryJun 7, 2024
- CVE-2024-715035Monitor
Slider by 10Web – Responsive Image Slider <= 1.2.57 - Authenticated (Contributor+) SQL Injection via id Parameter
HighCVSS 8.8No exploitEPSS 1%10web · sliderAug 8, 2024
- CVE-2025-1337732Monitor
10Web Booster <= 2.32.7 - Authenticated (Subscriber+) Arbitrary Folder Deletion via two_clear_page_cache
HighCVSS 8.1No exploitEPSS 1%10web · 10web boosterDec 6, 2025
- CVE-2015-105531Monitor
SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via th
HighCVSS 7.5No exploitEPSS 2%10web · photo galleryJan 16, 2015
- CVE-2024-211230Monitor
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.22 - Sensitive Information Exposure
HighCVSS 7.5No exploitEPSS 1%10web · form makerApr 9, 2024
- CVE-2021-2429128Monitor
Photo Gallery < 1.5.69 - Multiple Reflected Cross-Site Scripting (XSS)
MediumCVSS 6.1Proof of conceptEPSS 15%10web · photo galleryMay 14, 2021
- CVE-2017-1297728Monitor
The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related
HighCVSS 7.2No exploitEPSS 2%10web · photo galleryAug 20, 2017
- CVE-2024-022128Monitor
Photo Gallery by 10Web - Mobile-Friendly Image Gallery <= 1.8.19 - Directory Traversal to Arbitrary File Rename
HighCVSS 7.2No exploitEPSS 1%10web · photo galleryFeb 5, 2024
- CVE-2022-330028Monitor
Form Maker by 10Web < 1.15.6 - Admin+ SQLI
HighCVSS 7.2No exploitEPSS 1%10web · form makerOct 25, 2022
- CVE-2024-3111628Monitor
WordPress 10Web Map Builder for Google Maps plugin <= 1.0.74 - SQL Injection vulnerability
HighCVSS 7.2No exploitEPSS 1%10web · map builder for google mapsMar 31, 2024
- CVE-2019-1611826Monitor
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Option
MediumCVSS 6.1Proof of conceptEPSS 5%10web · photo gallerySep 8, 2019