Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Form Maker by 10Web — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in Form Maker by 10Web, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting Form Maker by 10Web, a WordPress plugin used for creating and managing forms. The collection encompasses various weakness types, including cross-site scripting, information disclosure, and privilege escalation, documented within a specific historical timeframe. Readers can utilize this resource to track vendor security advisories, analyze the prevalence of specific weakness classes, and review the complete vulnerability history of this product. By centralizing disclosed issues, the page provides a structured overview of known flaws without requiring users to navigate multiple disparate security databases. This allows security professionals and site administrators to identify patterns in reported incidents, assess the frequency of patches, and evaluate the overall security posture of the plugin over time. The data presented is intended for informational purposes, helping stakeholders understand potential risks associated with using this specific software component in their web environments. No individual vulnerability identifiers are listed in this introductory summary, directing attention instead to the broader context of the plugin's security landscape and the types of threats that have historically impacted its functionality.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-66616 WordPress Form Maker by 10Web plugin <= 1.15.48 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-08-20
CVE-2026-16977 Form Maker by 10Web < 1.15.45 - Subscriber+ SQL Injection via display_name - - 2026-08-12
CVE-2026-39502 WordPress Form Maker by 10Web plugin <= 1.15.38 - SQL Injection vulnerability CWE-89 9.3 Critical 2026-06-15
CVE-2025-15441 Form Maker < 1.15.38 - SQL Injection 9.8 - 2026-04-13
CVE-2025-48341 WordPress Form Maker by 10Web plugin <= 1.15.33 - Cross Site Scripting (XSS) Vulnerability CWE-79 5.9 Medium 2025-05-19
CVE-2024-13053 Form Maker by 10Web < 1.15.33 - Admin+ Stored XSS via Theme Title 4.8AI Medium AI 2025-05-15
CVE-2024-10680 Form Maker by 10Web < 1.15.32 - Admin+ Stored XSS 4.8AI Medium AI 2025-04-16
CVE-2024-10560 Form Maker by 10Web < 1.15.30 - Admin+ Stored XSS 4.8 - 2025-03-25
CVE-2024-10558 Form Maker by 10Web < 1.15.30 - Admin+ Stored XSS 4.8AI Medium AI 2025-03-24
CVE-2024-13605 Form Maker by 10Web < 1.15.33 - Admin+ Stored XSS 4.8 - 2025-02-24
CVE-2024-10562 Form Maker by 10Web < 1.15.31 - Admin+ Stored XSS 4.8 - 2025-01-07
CVE-2024-43220 WordPress Form Maker by 10Web plugin <= 1.15.26 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2024-08-12
CVE-2023-48290 WordPress Form Maker by 10Web plugin <= 1.15.20 - Captcha Bypass Vulnerability vulnerability CWE-307 5.3 Medium 2024-06-04
CVE-2024-34437 WordPress Form Maker by 10Web plugin <= 1.15.24 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium 2024-05-09
CVE-2024-32534 WordPress Form Maker plugin <= 1.15.23 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium 2024-04-17
CVE-2023-4666 Form-Maker < 1.15.20 - Unauthenticated Arbitrary File Upload 9.8 - 2023-10-16

All 16 known CVE vulnerabilities affecting Form Maker by 10Web with full Chinese analysis, references, and POCs where available.