Vulnerabilities > 10Web > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-11-27 CVE-2023-5559 Unspecified vulnerability in 10Web Booster
The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.
network
low complexity
10web
critical
9.1
2023-10-16 CVE-2023-4666 Unspecified vulnerability in 10Web Form Maker
The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE
network
low complexity
10web
critical
9.8
2023-03-13 CVE-2023-0037 Unspecified vulnerability in 10Web MAP Builder for Google Maps
The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
network
low complexity
10web
critical
9.8
2019-09-08 CVE-2019-16119 SQL Injection vulnerability in 10Web Photo Gallery
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.
network
low complexity
10web CWE-89
critical
9.8
2019-07-30 CVE-2019-14313 SQL Injection vulnerability in 10Web Photo Gallery
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress.
network
low complexity
10web CWE-89
critical
9.8