Записи 10web
103 опубликованных записей вендора 10web.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 1,9 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 31,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')65
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')14
- CWE-862 Missing Authorization9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')7
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
103 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
61На этой неделе | CVE-2022-0169Готовый эксплойт | Photo Gallery by 10Web < 1.6.0 - Unauthenticated SQL Injection10web · photo gallery · CWE-89 | Критическая9,8 | — | 74,6 % | 14 мар. 2022 г. |
52В плане | CVE-2022-1281Proof of concept | Photo Gallery < 1.6.3 - Unauthenticated SQL Injection10web · photo gallery · CWE-89 | Критическая9,8 | — | 43,1 % | 2 мая 2022 г. |
49В плане | CVE-2014-9312Готовый эксплойт | Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.10web · photo gallery · CWE-434 | Высокая8,8 | — | 45,4 % | 28 авг. 2017 г. |
46В плане | CVE-2019-16119Proof of concept | SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries10web · photo gallery · CWE-89 | Критическая9,8 | — | 24,8 % | 8 сент. 2019 г. |
41В плане | CVE-2019-10866Proof of concept | In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the fi10web · form maker · CWE-89 | Критическая9,8 | — | 6,2 % | 23 мая 2019 г. |
41В плане | CVE-2021-24139Proof of concept | Photo Gallery by 10Web < 1.5.55 - Unauthenticated SQL Injection10web · photo gallery · CWE-89 | Критическая9,8 | — | 5,5 % | 18 мар. 2021 г. |
40В плане | CVE-2019-14313Эксплойта нет | A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress.10web · photo gallery · CWE-89 | Критическая9,8 | — | 4,5 % | 30 июл. 2019 г. |
40В плане | CVE-2023-0037Proof of concept | 10WebMapBuilder < 1.0.73 - Unauthenticated SQLi10web · map builder for google maps · CWE-89 | Критическая9,8 | — | 3,9 % | 13 мар. 2023 г. |
40В плане | CVE-2023-4666Proof of concept | Form-Maker < 1.15.20 - Unauthenticated Arbitrary File Upload10web · form maker · CWE-434 | Критическая9,8 | — | 3,3 % | 16 окт. 2023 г. |
37Наблюдать | CVE-2023-5559Proof of concept | 10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion10web · 10web booster · CWE-862 | Критическая9,1 | — | 2,8 % | 27 нояб. 2023 г. |
36Наблюдать | CVE-2021-24132Эксплойта нет | Slider by 10Web < 1.2.36 - Multiple Authenticated SQL Injection10web · slider · CWE-89 | Высокая8,8 | — | 2,6 % | 18 мар. 2021 г. |
35Наблюдать | CVE-2023-6985Proof of concept | 10Web AI Assistant – AI content writing assistant <= 1.0.18 - Missing Authorization to Arbitrary Plugin Installation10web · ai assistant · CWE-862 | Высокая8,8 | — | 1,4 % | 5 февр. 2024 г. |
35Наблюдать | CVE-2019-11590Эксплойта нет | The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local f10web · form maker · CWE-22 | Высокая8,8 | — | 1,2 % | 29 апр. 2019 г. |
35Наблюдать | CVE-2015-9380Эксплойта нет | The photo-gallery plugin before 1.2.42 for WordPress has CSRF.10web · photo gallery · CWE-352 | Высокая8,8 | — | 0,8 % | 30 авг. 2019 г. |
35Наблюдать | CVE-2024-5481Эксплойта нет | Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Path Traversal via esc_dir Function10web · photo gallery · CWE-35 | Высокая8,8 | — | 0,7 % | 7 июн. 2024 г. |
35Наблюдать | CVE-2024-7150Эксплойта нет | Slider by 10Web – Responsive Image Slider <= 1.2.57 - Authenticated (Contributor+) SQL Injection via id Parameter10web · slider · CWE-89 | Высокая8,8 | — | 0,6 % | 8 авг. 2024 г. |
32Наблюдать | CVE-2025-13377Эксплойта нет | 10Web Booster <= 2.32.7 - Authenticated (Subscriber+) Arbitrary Folder Deletion via two_clear_page_cache10web · 10web booster · CWE-22 | Высокая8,1 | — | 0,5 % | 6 дек. 2025 г. |
31Наблюдать | CVE-2015-1055Эксплойта нет | SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via th10web · photo gallery · CWE-89 | Высокая7,5 | — | 2,1 % | 16 янв. 2015 г. |
30Наблюдать | CVE-2024-2112Эксплойта нет | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.22 - Sensitive Information Exposure10web · form maker · CWE-287 | Высокая7,5 | — | 0,7 % | 9 апр. 2024 г. |
28Наблюдать | CVE-2021-24291Proof of concept | Photo Gallery < 1.5.69 - Multiple Reflected Cross-Site Scripting (XSS)10web · photo gallery · CWE-79 | Средняя6,1 | — | 14,5 % | 14 мая 2021 г. |
28Наблюдать | CVE-2017-12977Эксплойта нет | The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related10web · photo gallery · CWE-89 | Высокая7,2 | — | 1,6 % | 20 авг. 2017 г. |
28Наблюдать | CVE-2024-0221Эксплойта нет | Photo Gallery by 10Web - Mobile-Friendly Image Gallery <= 1.8.19 - Directory Traversal to Arbitrary File Rename10web · photo gallery · CWE-22 | Высокая7,2 | — | 1,3 % | 5 февр. 2024 г. |
28Наблюдать | CVE-2022-3300Эксплойта нет | Form Maker by 10Web < 1.15.6 - Admin+ SQLI10web · form maker · CWE-89 | Высокая7,2 | — | 1,1 % | 25 окт. 2022 г. |
28Наблюдать | CVE-2024-31116Эксплойта нет | WordPress 10Web Map Builder for Google Maps plugin <= 1.0.74 - SQL Injection vulnerability10web · map builder for google maps · CWE-89 | Высокая7,2 | — | 0,5 % | 31 мар. 2024 г. |
26Наблюдать | CVE-2019-16118Proof of concept | Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Option10web · photo gallery · CWE-79 | Средняя6,1 | — | 5,3 % | 8 сент. 2019 г. |
- CVE-2022-016961На этой неделе
Photo Gallery by 10Web < 1.6.0 - Unauthenticated SQL Injection
КритическаяCVSS 9,8Готовый эксплойтEPSS 75 %10web · photo gallery14 мар. 2022 г.
- CVE-2022-128152В плане
Photo Gallery < 1.6.3 - Unauthenticated SQL Injection
КритическаяCVSS 9,8Proof of conceptEPSS 43 %10web · photo gallery2 мая 2022 г.
- CVE-2014-931249В плане
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
ВысокаяCVSS 8,8Готовый эксплойтEPSS 45 %10web · photo gallery28 авг. 2017 г.
- CVE-2019-1611946В плане
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries
КритическаяCVSS 9,8Proof of conceptEPSS 25 %10web · photo gallery8 сент. 2019 г.
- CVE-2019-1086641В плане
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the fi
КритическаяCVSS 9,8Proof of conceptEPSS 6 %10web · form maker23 мая 2019 г.
- CVE-2021-2413941В плане
Photo Gallery by 10Web < 1.5.55 - Unauthenticated SQL Injection
КритическаяCVSS 9,8Proof of conceptEPSS 6 %10web · photo gallery18 мар. 2021 г.
- CVE-2019-1431340В плане
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %10web · photo gallery30 июл. 2019 г.
- CVE-2023-003740В плане
10WebMapBuilder < 1.0.73 - Unauthenticated SQLi
КритическаяCVSS 9,8Proof of conceptEPSS 4 %10web · map builder for google maps13 мар. 2023 г.
- CVE-2023-466640В плане
Form-Maker < 1.15.20 - Unauthenticated Arbitrary File Upload
КритическаяCVSS 9,8Proof of conceptEPSS 3 %10web · form maker16 окт. 2023 г.
- CVE-2023-555937Наблюдать
10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion
КритическаяCVSS 9,1Proof of conceptEPSS 3 %10web · 10web booster27 нояб. 2023 г.
- CVE-2021-2413236Наблюдать
Slider by 10Web < 1.2.36 - Multiple Authenticated SQL Injection
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %10web · slider18 мар. 2021 г.
- CVE-2023-698535Наблюдать
10Web AI Assistant – AI content writing assistant <= 1.0.18 - Missing Authorization to Arbitrary Plugin Installation
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %10web · ai assistant5 февр. 2024 г.
- CVE-2019-1159035Наблюдать
The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local f
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %10web · form maker29 апр. 2019 г.
- CVE-2015-938035Наблюдать
The photo-gallery plugin before 1.2.42 for WordPress has CSRF.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %10web · photo gallery30 авг. 2019 г.
- CVE-2024-548135Наблюдать
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Path Traversal via esc_dir Function
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %10web · photo gallery7 июн. 2024 г.
- CVE-2024-715035Наблюдать
Slider by 10Web – Responsive Image Slider <= 1.2.57 - Authenticated (Contributor+) SQL Injection via id Parameter
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %10web · slider8 авг. 2024 г.
- CVE-2025-1337732Наблюдать
10Web Booster <= 2.32.7 - Authenticated (Subscriber+) Arbitrary Folder Deletion via two_clear_page_cache
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %10web · 10web booster6 дек. 2025 г.
- CVE-2015-105531Наблюдать
SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via th
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %10web · photo gallery16 янв. 2015 г.
- CVE-2024-211230Наблюдать
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.22 - Sensitive Information Exposure
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %10web · form maker9 апр. 2024 г.
- CVE-2021-2429128Наблюдать
Photo Gallery < 1.5.69 - Multiple Reflected Cross-Site Scripting (XSS)
СредняяCVSS 6,1Proof of conceptEPSS 15 %10web · photo gallery14 мая 2021 г.
- CVE-2017-1297728Наблюдать
The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %10web · photo gallery20 авг. 2017 г.
- CVE-2024-022128Наблюдать
Photo Gallery by 10Web - Mobile-Friendly Image Gallery <= 1.8.19 - Directory Traversal to Arbitrary File Rename
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %10web · photo gallery5 февр. 2024 г.
- CVE-2022-330028Наблюдать
Form Maker by 10Web < 1.15.6 - Admin+ SQLI
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %10web · form maker25 окт. 2022 г.
- CVE-2024-3111628Наблюдать
WordPress 10Web Map Builder for Google Maps plugin <= 1.0.74 - SQL Injection vulnerability
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %10web · map builder for google maps31 мар. 2024 г.
- CVE-2019-1611826Наблюдать
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Option
СредняяCVSS 6,1Proof of conceptEPSS 5 %10web · photo gallery8 сент. 2019 г.