Extension WordPress
Vulnérabilités Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
Cette page rassemble les failles publiées pour Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
39 fiches
Form Maker by 10Web <= 1.15.43 – Authenticated (Adminsitrator+) SQL Injection via 'groupids' Parameter
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'groupids' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping…
*-1.15.43
1.15.44
17/06/2026
Form Maker by 10Web <= 1.15.43 – Authenticated (Administrator+) SQL Injection via 'name' Parameter
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'name' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping…
*-1.15.43
1.15.44
17/06/2026
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.42 – Unauthenticated SQL Injection via 'inputs'
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Injection via the 'inputs' parameter in versions up to, and including, 1.15.42 due to insufficient escaping on the…
*-1.15.42
1.15.43
04/05/2026
Form Maker by 10Web <= 1.15.40 – Authenticated (Administrator+) SQL Injection via 'ip_search' Parameter
The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection via the 'ip_search', 'startdate', 'enddate', 'username_search', and 'useremail_search' parameters in all versions up to, and including, 1.15.40. This is due to the `WDW_FM_Library::validate_data()` method calling…
*-1.15.40
1.15.41
16/04/2026
Form Maker by 10Web <= 1.15.40 – Unauthenticated Stored Cross-Site Scripting via Matrix Field Text Box
The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box input type) in form submissions in all versions up to, and including, 1.15.40. This is due to insufficient…
*-1.15.40
1.15.41
13/04/2026
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.38 – Unauthenticated SQL Injection
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.15.38 due to insufficient escaping on the user supplied parameter and…
*-1.15.38
1.15.39
08/04/2026
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder < 1.15.38 – Unauthenticated SQL Injection
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Injection in versions up to 1.15.38 due to insufficient escaping on the user supplied parameter and lack of…
[*, 1.15.38)
1.15.38
23/03/2026
Form Maker by 10Web <= 1.15.35 – Unauthenticated Stored Cross-Site Scripting via Hidden Field
The Form Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via hidden field values in all versions up to, and including, 1.15.35. This is due to insufficient output escaping when displaying hidden field values in the…
*-1.15.35
1.15.36
02/02/2026
Form Maker by 10Web <= 1.15.35 – Unauthenticated Stored Cross-Site Scripting via SVG file
The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.35. This is due to the plugin's default file upload allowlist including SVG files combined with weak…
*-1.15.35
1.15.36
02/02/2026
Form Maker by 10Web <= 1.15.33 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.15.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
*-1.15.33
1.15.34
19/05/2025
Form Maker by 10Web <= 1.15.31 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.31 due to insufficient input sanitization…
*-1.15.31
1.15.32
26/03/2025
Form Maker by 10Web <= 1.15.29 – Authenticated (Admin+) Stored Cross-Site Scripting
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.29 due to insufficient input sanitization…
*-1.15.29
1.15.30
03/03/2025
Form Maker by 10Web <= 1.15.29 – Authenticated (Admin+) Stored Cross-Site Scripting
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.29 due to insufficient input sanitization…
*-1.15.29
1.15.30
02/03/2025
Form Maker by 10Web <= 1.15.32 – Authenticated (Admin+) Stored Cross-Site Scripting
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.32 due to insufficient input sanitization…
*-1.15.32
1.15.33
07/02/2025
Form Maker by 10Web <= 1.15.32 – Authenticated (Admin+) Stored Cross-Site Scripting
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.32 due to insufficient input sanitization…
*-1.15.32
1.15.33
03/02/2025
Form Maker by 10Web <= 1.15.30 – Authenticated (Admin+) Stored Cross-Site Scripting
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.30 due to insufficient input sanitization…
*-1.15.30
1.15.31
17/12/2024
Multiple Plugins <= (Various Versions) – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-1.15.27
1.15.28
03/12/2024
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.30 – Reflected Cross-Site Scripting via add_query_arg Parameter
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up…
*-1.15.30
1.15.31
10/11/2024
Form Maker <= 1.15.27 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.27 due to insufficient input sanitization and output escaping.…
*-1.15.27
1.15.28
26/09/2024
Form Maker by 10Web <= 1.15.26 – Reflected Cross-Site Scripting
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.15.26 due to insufficient input sanitization and output escaping.…
*-1.15.26
1.15.27
09/08/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.