在 10Web 的 Slider 插件版本 <= 1.2.63 中存在未认证的跨站脚本(XSS)漏洞。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| 10Web | Slider by 10Web | n/a≤ 1.2.63 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 10Web | Slider by 10Web | n/a ~ 1.2.63 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105885 | 8.8 HIGH | WordPress Slider by 10Web plugin <= 1.2.62 - PHP Object Injection vulnerability |
| CVE-2026-107742 | 7.2 HIGH | 10Web Booster <= 2.34.8 - Unauthenticated Stored Cross-Site Scripting via Comment Author N |
| CVE-2026-42715 | 7.1 HIGH | WordPress Photo Gallery by 10Web plugin <= 1.8.47 - Cross Site Scripting (XSS) vulnerabili |
| CVE-2026-103998 | 6.1 MEDIUM | Form Maker by 10Web <= 1.15.48 - Reflected Cross-Site Scripting via 'inputs' Parameter Arr |
No comments yet