← Back

10web

103 CVEs • 15 products

Products (15)

Click to collapse
Toggle
Photo Gallery
photo_gallery
Form Maker
form_maker
Slider
slider
Seo
seo
10webanalytics
10web Booster
10web_booster
10websocial
Spidercalendar
spidercalendar
Sliderby10web
sliderby10web
Ai Assistant
ai_assistant
Spidercontacts
spidercontacts

CVEs (103)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
110web
1Form Maker
Jun 17, 2026
Aug 16, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, l...Show more
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issueShow less
110web
1Photo Gallery
Jun 17, 2026
Aug 16, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images/SVG anywhere in...Show more
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images/SVG anywhere in the filesystem via a path traversal vectorShow less
110web
1Photo Gallery
Jun 17, 2026
Aug 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded SVG files added to a gallery do not contain malicious content. As a result, users allowed to add imag...Show more
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded SVG files added to a gallery do not contain malicious content. As a result, users allowed to add images to gallery can upload an SVG file containing JavaScript code, which will be executed when accessing the image directly (ie in the /wp-content/uploads/photo-gallery/ folder), leading to a Cross-Site Scripting (XSS) issueShow less
110web
1Photo Gallery
Jun 17, 2026
Jun 1, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Photo Gallery by 10Web - Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the gallery title, allowing high privilege users to create one with XSS payload in it, which will be tri...Show more
The Photo Gallery by 10Web - Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the gallery title, allowing high privilege users to create one with XSS payload in it, which will be triggered when another user will view the gallery list or the affected gallery in the admin dashboard. This is due to an incomplete fix of CVE-2019-16117Show less
110web
1Photo Gallery
Jun 17, 2026
May 14, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, album_id and _id GET parameters passed to t...Show more
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, album_id and _id GET parameters passed to the bwg_frontend_data AJAX action (available to both unauthenticated and authenticated users)Show less
110web
1Photo Gallery
Jun 17, 2026
Mar 18, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.
110web
1Slider
Jun 17, 2026
Mar 18, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were vulnerable, allowing a high privileged user (Admin), or medium one such...Show more
The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were vulnerable, allowing a high privileged user (Admin), or medium one such as Contributor+ (if "Role Options" is turn on for other users) to perform a SQL Injection attacks.Show less
110web
1Photo Gallery
Jun 17, 2026
Feb 25, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploitation of this vulnerability would allow a authenticated admin user to inject arbitrary JavaScript cod...Show more
Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploitation of this vulnerability would allow a authenticated admin user to inject arbitrary JavaScript code that is viewed by other users.Show less
110web
1Photo Gallery
Nov 21, 2024
Feb 8, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in the Photo Gallery plugin before 1.2.11 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) sort_by, (2) sort_order, (3)...Show more
Multiple cross-site scripting (XSS) vulnerabilities in the Photo Gallery plugin before 1.2.11 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) sort_by, (2) sort_order, (3) items_view, (4) dir, (5) clipboard_task, (6) clipboard_files, (7) clipboard_src, or (8) clipboard_dest parameters in an addImages action to wp-admin/admin-ajax.php.Show less
110web
1Photo Gallery
Jun 17, 2026
Sep 8, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.
110web
1Photo Gallery
Jun 17, 2026
Sep 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.
110web
1Photo Gallery
Jun 17, 2026
Sep 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.
110web
1Photo Gallery
Nov 21, 2024
Aug 30, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The photo-gallery plugin before 1.2.42 for WordPress has CSRF.
110web
1Photo Gallery
Jun 17, 2026
Aug 9, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.
110web
1Photo Gallery
Jun 17, 2026
Aug 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS.
110web
1Photo Gallery
Jun 17, 2026
Jul 30, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the aff...Show more
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php.Show less
110web
1Form Maker
Jun 17, 2026
May 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /model...Show more
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.Show less
110web
1Form Maker
Jun 17, 2026
Apr 29, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy betwee...Show more
The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.Show less
110web
1Photo Gallery
Nov 21, 2024
Feb 19, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allows remote authenticated users with edit permission to inject arbitrary web script or HTML via unspec...Show more
Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allows remote authenticated users with edit permission to inject arbitrary web script or HTML via unspecified vectors.Show less
110web
1Photo Gallery
May 13, 2026
Aug 28, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.