Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

10Web — Vulnerabilities & Security Advisories 57

Browse all 57 CVE security advisories affecting 10Web. AI-powered Chinese analysis, POCs, and references for each vulnerability.

10Web operates as an automated WordPress hosting and management platform, primarily serving small to medium-sized businesses seeking simplified site deployment and maintenance. Security audits have identified forty-one Common Vulnerabilities and Exposures (CVEs) associated with its infrastructure and software components. Historically, these flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from outdated dependencies or misconfigured server environments. While no single catastrophic data breach has been publicly attributed directly to 10Web’s core platform, the high volume of CVEs indicates persistent challenges in patch management and code review processes. The organization generally responds to disclosures by releasing updates, yet the accumulation of unresolved or legacy issues suggests a reactive rather than proactive security posture. Users relying on this service must remain vigilant regarding plugin compatibility and server configuration to mitigate risks associated with these documented weaknesses.

CVE ID Title CVSS Severity Published
CVE-2026-96813 Form Maker by 10Web <= 1.15.47 - Unauthenticated Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields — Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder CWE-79 7.2 High 2026-10-01
CVE-2026-102377 WordPress Photo Gallery by 10Web plugin <= 1.8.46 - PHP Object Injection vulnerability — Photo Gallery by 10Web CWE-502 8.8 High 2026-09-30
CVE-2026-94121 WordPress 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin <= 2.33.6 - PHP Object Injection vulnerability — 10Web Booster – Website speed optimization, Cache & Page Speed optimizer CWE-502 8.8 High 2026-09-30
CVE-2026-85652 Photo Gallery by 10Web <= 1.8.44 - Authenticated (Author+) SQL Injection via 'album_id' Shortcode Attribute — Photo Gallery by 10Web – Mobile-Friendly Image Gallery CWE-89 6.5 Medium 2026-09-18
CVE-2026-86311 Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.44 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes — Photo Gallery by 10Web – Mobile-Friendly Image Gallery CWE-79 6.4 Medium 2026-09-17
CVE-2026-85645 Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.46 - Reflected Cross-Site Scripting — Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder CWE-79 6.1 Medium 2026-09-10
CVE-2026-66616 WordPress Form Maker by 10Web plugin <= 1.15.48 - Cross Site Scripting (XSS) vulnerability — Form Maker by 10Web CWE-79 7.1 High 2026-08-20
CVE-2026-66635 WordPress Slider by 10Web plugin <= 1.2.62 - CSRF to Arbitrary File Deletion vulnerability — Slider by 10Web CWE-352 7.4 High 2026-08-18
CVE-2026-15993 Form Maker by 10Web <= 1.15.44 - Authenticated (Subscriber+) SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause — Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder CWE-89 5.3 Medium 2026-08-15
CVE-2026-11776 Form Maker by 10Web <= 1.15.43 - Authenticated (Adminsitrator+) SQL Injection via 'groupids' Parameter — Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder CWE-89 4.9 Medium 2026-06-18
CVE-2026-11777 Form Maker by 10Web <= 1.15.43 - Authenticated (Administrator+) SQL Injection via 'name' Parameter — Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder CWE-89 4.9 Medium 2026-06-18
CVE-2026-39502 WordPress Form Maker by 10Web plugin <= 1.15.38 - SQL Injection vulnerability — Form Maker by 10Web CWE-89 9.3 Critical 2026-06-15
CVE-2026-9829 Photo Gallery by 10Web <= 1.8.41 - Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Parameter — Photo Gallery by 10Web – Mobile-Friendly Image Gallery CWE-89 6.5 Medium 2026-06-06
CVE-2026-49771 WordPress Photo Gallery by 10Web plugin <= 1.8.41 - SQL Injection vulnerability — Photo Gallery by 10Web CWE-89 7.6 High 2026-06-04
CVE-2026-7048 Photo Gallery by 10Web <= 1.8.40 - Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute — Photo Gallery by 10Web – Mobile-Friendly Image Gallery CWE-89 6.5 Medium 2026-05-28
CVE-2018-25346 WordPress Form Maker Plugin 1.12.24 SQL Injection via admin-ajax.php — Form Maker CWE-89 7.1 High 2026-05-23
CVE-2026-3359 Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.42 - Unauthenticated SQL Injection via 'inputs' — Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder CWE-89 7.5 High 2026-05-05
CVE-2026-3330 Form Maker by 10Web <= 1.15.40 - Authenticated (Administrator+) SQL Injection via 'ip_search' Parameter — Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder CWE-89 4.9 Medium 2026-04-17
CVE-2026-4388 Form Maker by 10Web <= 1.15.40 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Text Box — Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder CWE-79 7.2 High 2026-04-14
CVE-2026-32330 WordPress Photo Gallery by 10Web plugin <= 1.8.37 - Cross Site Request Forgery (CSRF) vulnerability — Photo Gallery by 10Web CWE-352 4.3 Medium 2026-03-13
CVE-2026-27360 WordPress Photo Gallery by 10Web plugin <= 1.8.38 - Cross Site Scripting (XSS) vulnerability — Photo Gallery by 10Web CWE-79 5.9 Medium 2026-02-19
CVE-2026-1058 Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via Hidden Field — Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder CWE-79 7.1 High 2026-02-03
CVE-2026-1065 Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via SVG file — Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder CWE-434 7.2 High 2026-02-03
CVE-2026-1036 Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.36 - Missing Authorization to Unauthenticated Arbitrary Comment Deletion — Photo Gallery by 10Web – Mobile-Friendly Image Gallery CWE-862 5.3 Medium 2026-01-21
CVE-2025-13377 10Web Booster <= 2.32.7 - Authenticated (Subscriber+) Arbitrary Folder Deletion via two_clear_page_cache — 10Web Booster – Website speed optimization, Cache & Page Speed optimizer CWE-22 9.6 Critical 2025-12-06
CVE-2020-36853 10WebMapBuilder <= 1.0.63 - Unauthenticated Stored Cross-Site Scripting via Plugin Settings Change — 10Web Map Builder for Google Maps CWE-79 7.2 High 2025-10-18
CVE-2025-48341 WordPress Form Maker by 10Web plugin <= 1.15.33 - Cross Site Scripting (XSS) Vulnerability — Form Maker by 10Web CWE-79 5.9 Medium 2025-05-19
CVE-2025-2269 Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.34 Reflected Cross-Site Scripting via 'image_id' Parameter — Photo Gallery by 10Web – Mobile-Friendly Image Gallery CWE-79 6.1 Medium 2025-04-11
CVE-2023-45272 WordPress 10Web Map Builder for Google Maps plugin <= 1.0.73 - Notice Dismissal Vulnerability — 10Web Map Builder for Google Maps CWE-862 5.4 Medium 2025-01-02
CVE-2023-47807 WordPress 10WebAnalytics plugin <= 1.2.12 - Broken Access Control vulnerability — 10WebAnalytics CWE-862 4.3 Medium 2025-01-02

This page lists every published CVE security advisory associated with 10Web. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.