Skip to content
Noroxi

10web records

103 published records for vendor 10web.

All records

103 records
  • CVE-2022-0169
    61This week

    Photo Gallery by 10Web < 1.6.0 - Unauthenticated SQL Injection

    CriticalCVSS 9.8WeaponizedEPSS 75%

    10web · photo galleryMar 14, 2022

  • Photo Gallery < 1.6.3 - Unauthenticated SQL Injection

    CriticalCVSS 9.8Proof of conceptEPSS 43%

    10web · photo galleryMay 2, 2022

  • Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.

    HighCVSS 8.8WeaponizedEPSS 45%

    10web · photo galleryAug 28, 2017

  • SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries

    CriticalCVSS 9.8Proof of conceptEPSS 25%

    10web · photo gallerySep 8, 2019

  • In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the fi

    CriticalCVSS 9.8Proof of conceptEPSS 6%

    10web · form makerMay 23, 2019

  • Photo Gallery by 10Web < 1.5.55 - Unauthenticated SQL Injection

    CriticalCVSS 9.8Proof of conceptEPSS 6%

    10web · photo galleryMar 18, 2021

  • A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress.

    CriticalCVSS 9.8No exploitEPSS 4%

    10web · photo galleryJul 30, 2019

  • 10WebMapBuilder < 1.0.73 - Unauthenticated SQLi

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    10web · map builder for google mapsMar 13, 2023

  • Form-Maker < 1.15.20 - Unauthenticated Arbitrary File Upload

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    10web · form makerOct 16, 2023

  • CVE-2023-5559
    37Monitor

    10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion

    CriticalCVSS 9.1Proof of conceptEPSS 3%

    10web · 10web boosterNov 27, 2023

  • Slider by 10Web < 1.2.36 - Multiple Authenticated SQL Injection

    HighCVSS 8.8No exploitEPSS 3%

    10web · sliderMar 18, 2021

  • CVE-2023-6985
    35Monitor

    10Web AI Assistant – AI content writing assistant <= 1.0.18 - Missing Authorization to Arbitrary Plugin Installation

    HighCVSS 8.8Proof of conceptEPSS 1%

    10web · ai assistantFeb 5, 2024

  • The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local f

    HighCVSS 8.8No exploitEPSS 1%

    10web · form makerApr 29, 2019

  • CVE-2015-9380
    35Monitor

    The photo-gallery plugin before 1.2.42 for WordPress has CSRF.

    HighCVSS 8.8No exploitEPSS 1%

    10web · photo galleryAug 30, 2019

  • CVE-2024-5481
    35Monitor

    Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Path Traversal via esc_dir Function

    HighCVSS 8.8No exploitEPSS 1%

    10web · photo galleryJun 7, 2024

  • CVE-2024-7150
    35Monitor

    Slider by 10Web – Responsive Image Slider <= 1.2.57 - Authenticated (Contributor+) SQL Injection via id Parameter

    HighCVSS 8.8No exploitEPSS 1%

    10web · sliderAug 8, 2024

  • 10Web Booster <= 2.32.7 - Authenticated (Subscriber+) Arbitrary Folder Deletion via two_clear_page_cache

    HighCVSS 8.1No exploitEPSS 1%

    10web · 10web boosterDec 6, 2025

  • CVE-2015-1055
    31Monitor

    SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via th

    HighCVSS 7.5No exploitEPSS 2%

    10web · photo galleryJan 16, 2015

  • CVE-2024-2112
    30Monitor

    Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.22 - Sensitive Information Exposure

    HighCVSS 7.5No exploitEPSS 1%

    10web · form makerApr 9, 2024

  • Photo Gallery < 1.5.69 - Multiple Reflected Cross-Site Scripting (XSS)

    MediumCVSS 6.1Proof of conceptEPSS 15%

    10web · photo galleryMay 14, 2021

  • The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related

    HighCVSS 7.2No exploitEPSS 2%

    10web · photo galleryAug 20, 2017

  • CVE-2024-0221
    28Monitor

    Photo Gallery by 10Web - Mobile-Friendly Image Gallery <= 1.8.19 - Directory Traversal to Arbitrary File Rename

    HighCVSS 7.2No exploitEPSS 1%

    10web · photo galleryFeb 5, 2024

  • CVE-2022-3300
    28Monitor

    Form Maker by 10Web < 1.15.6 - Admin+ SQLI

    HighCVSS 7.2No exploitEPSS 1%

    10web · form makerOct 25, 2022

  • WordPress 10Web Map Builder for Google Maps plugin <= 1.0.74 - SQL Injection vulnerability

    HighCVSS 7.2No exploitEPSS 1%

    10web · map builder for google mapsMar 31, 2024

  • Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Option

    MediumCVSS 6.1Proof of conceptEPSS 5%

    10web · photo gallerySep 8, 2019