Vulnerabilities > 10Web > Form Maker

DATE CVE VULNERABILITY TITLE RISK
2024-11-10 CVE-2024-10265 Cross-site Scripting vulnerability in 10Web Form Maker
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.15.30.
network
low complexity
10web CWE-79
6.1
2024-09-26 CVE-2024-8633 Cross-site Scripting vulnerability in 10Web Form Maker
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.27 due to insufficient input sanitization and output escaping.
network
low complexity
10web CWE-79
4.8
2024-08-12 CVE-2024-43220 Cross-site Scripting vulnerability in 10Web Form Maker
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Reflected XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.26.
network
low complexity
10web CWE-79
6.1
2024-06-04 CVE-2023-48290 Unspecified vulnerability in 10Web Form Maker
Improper Restriction of Excessive Authentication Attempts vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Functionality Bypass.This issue affects Form Maker by 10Web: from n/a through 1.15.20.
network
low complexity
10web
5.3
2024-05-14 CVE-2024-34437 Unspecified vulnerability in 10Web Form Maker
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.24.
network
low complexity
10web
4.8
2024-04-27 CVE-2024-2258 Unspecified vulnerability in 10Web Form Maker
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name autofilled into forms in all versions up to, and including, 1.15.24 due to insufficient input sanitization and output escaping.
network
low complexity
10web
5.4
2024-04-17 CVE-2024-32534 Unspecified vulnerability in 10Web Form Maker
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.23.
network
low complexity
10web
4.8
2024-04-09 CVE-2024-2112 Unspecified vulnerability in 10Web Form Maker
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.15.22 via the signature functionality.
network
low complexity
10web
7.5
2024-01-27 CVE-2024-0667 Cross-Site Request Forgery (CSRF) vulnerability in 10Web Form Maker
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.15.21.
network
low complexity
10web CWE-352
6.3
2023-10-18 CVE-2023-45070 Unspecified vulnerability in 10Web Form Maker
Unauth.
network
low complexity
10web
6.1