Vulnerabilities > 10Web > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-11-27 CVE-2023-5559 Unspecified vulnerability in 10Web Booster
The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.
network
low complexity
10web
critical
9.1
2023-10-16 CVE-2023-4666 Unspecified vulnerability in 10Web Form Maker
The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE
network
low complexity
10web
critical
9.8
2023-03-13 CVE-2023-0037 Unspecified vulnerability in 10Web MAP Builder for Google Maps
The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
network
low complexity
10web
critical
9.8
2022-05-02 CVE-2022-1281 Unspecified vulnerability in 10Web Photo Gallery
The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.
network
low complexity
10web
critical
9.8
2022-03-14 CVE-2022-0169 Unspecified vulnerability in 10Web Photo Gallery
The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection
network
low complexity
10web
critical
9.8
2021-03-18 CVE-2021-24139 SQL Injection vulnerability in 10Web Photo Gallery
Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.
network
low complexity
10web CWE-89
critical
9.8
2019-09-08 CVE-2019-16119 SQL Injection vulnerability in 10Web Photo Gallery
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.
network
low complexity
10web CWE-89
critical
9.8
2019-07-30 CVE-2019-14313 SQL Injection vulnerability in 10Web Photo Gallery
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress.
network
low complexity
10web CWE-89
critical
9.8
2019-05-23 CVE-2019-10866 SQL Injection vulnerability in 10Web Form Maker
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.
network
low complexity
10web CWE-89
critical
9.8