Vulnerabilities > 10Web > Form Maker > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-09-26 CVE-2024-8633 Cross-site Scripting vulnerability in 10Web Form Maker
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.27 due to insufficient input sanitization and output escaping.
network
low complexity
10web CWE-79
4.8
2024-01-27 CVE-2024-0667 Cross-Site Request Forgery (CSRF) vulnerability in 10Web Form Maker
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.15.21.
network
low complexity
10web CWE-352
6.3
2023-10-18 CVE-2023-45070 Cross-site Scripting vulnerability in 10Web Form Maker
Unauth.
network
low complexity
10web CWE-79
6.1
2023-10-18 CVE-2023-45071 Cross-site Scripting vulnerability in 10Web Form Maker
Unauth.
network
low complexity
10web CWE-79
6.1
2021-08-16 CVE-2021-24526 Cross-site Scripting vulnerability in 10Web Form Maker
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue
network
low complexity
10web CWE-79
5.4
2019-04-29 CVE-2019-11590 Inclusion of Functionality from Untrusted Control Sphere vulnerability in 10Web Form Maker
The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.
network
10web CWE-829
6.8