Vulnerabilities > 10Web > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-11-27 | CVE-2023-5559 | Unspecified vulnerability in 10Web Booster The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service. | 9.1 |
2023-10-16 | CVE-2023-4666 | Unspecified vulnerability in 10Web Form Maker The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE | 9.8 |
2023-03-13 | CVE-2023-0037 | Unspecified vulnerability in 10Web MAP Builder for Google Maps The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection | 9.8 |
2019-09-08 | CVE-2019-16119 | SQL Injection vulnerability in 10Web Photo Gallery SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter. | 9.8 |
2019-07-30 | CVE-2019-14313 | SQL Injection vulnerability in 10Web Photo Gallery A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. | 9.8 |