Extension WordPress
Vulnérabilités Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder, page 2
Cette page rassemble les failles publiées pour Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
39 fiches
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.25 – Authenticated (Admin+) Stored Cross-Site Scripting
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.25 due to insufficient input sanitization…
*-1.15.25
1.15.26
10/06/2024
Form Maker by 10Web <= 1.15.24 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.24 due to insufficient input sanitization…
*-1.15.24
1.15.25
07/05/2024
Form Maker by 10Web <= 1.15.24 – Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name autofilled into forms in all versions up to, and including, 1.15.24…
*-1.15.24
1.15.25
26/04/2024
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.23 – Authenticated (Admin+) Stored Cross-Site Scripting
The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.23 due to insufficient input sanitization and output escaping. This makes it possible for…
*-1.15.23
1.15.24
15/04/2024
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.22 – Sensitive Information Exposure
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.15.22 via the signature functionality. This makes it possible…
*-1.15.22
1.15.23
22/03/2024
Form-Maker (twb_form-maker) <= 1.15.21 – Cross-Site Request Forgery to Limited Code Execution via Execute
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.15.21. This is due to missing or incorrect nonce…
*-1.15.21
1.15.22
26/01/2024
Form Maker <= 1.15.20 – Captcha Bypass
The Form Maker plugin for WordPress is vulnerable to Captcha Bypass in versions up to, and including, 1.15.20 due to insufficient input verification. This makes it possible for unauthenticated attackers to automate form submissions.
[*, 1.15.21)
1.15.21
11/10/2023
Form Maker by 10Web <= 1.15.18 – Reflected Cross-Site Scripting
The Form Maker by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a few parameters related to searching in versions up to, and including, 1.15.18 due to insufficient input sanitization and output escaping. This makes…
*-1.15.18
1.15.19
03/10/2023
Form Maker by 10Web <= 1.15.18 – Unauthenticated Stored Cross-Site Scripting
The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type_textarea' field of form submissions in versions up to, and including, 1.15.18 due to insufficient input sanitization and output escaping. This makes…
*-1.15.18
1.15.19
03/10/2023
Form Maker by 10Web <= 1.15.19 – Unauthenticated Arbitrary File Upload
The Form Maker by 10Web plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'type_signature' case of the save_db() function in versions up to, and including, 1.5.19. This makes it…
[*, 1.15.20)
1.15.20
07/09/2023
Form Maker <= 1.15.16 – Missing Authorization in check_score
The Form Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_score function in versions up to, and including, 1.15.16. This makes it possible for authenticated attackers, with…
*-1.15.16
1.15.17
14/06/2023
Form Maker <= 1.15.5 – Authenticated (Administrator+) SQL Injection
The Form Maker plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in versions up to, and including, 1.15.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
*-1.15.5
1.15.6
29/09/2022
Form Maker <= 1.14.11 – Stored Cross-Site Scripting
The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which could allow high privilege user such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
*-1.14.11
1.14.12
09/05/2022
Form Maker <= 1.13.59 – Authenticated Stored Cross-Site Scripting
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, leading…
*-1.13.59
1.13.60
15/07/2021
Form Maker by 10Web < 1.13.40 – Reflected Cross-Site Scripting
The Form Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.13.39 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
[*, 1.13.40)
1.13.40
12/07/2020
Form Maker by 10Web <= 1.13.35 – SQL Injection
The Form Maker plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in versions up to, and including, 1.13.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
*-1.13.35
1.13.36
26/05/2020
Form Maker by 10Web <= 1.13.2 – Authenticated SQL Injection
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.
[*, 1.13.3)
1.13.3
10/05/2019
Form Maker by 10Web <= 1.13.4 – Cross-Site Request Forgery to Local File Inclusion
The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value,…
*-1.13.4
1.13.5
05/04/2019
Form Maker by 10Web <= 1.12.21 – CSV Injection
The WebDorado "Form Maker by WD" plugin before 1.12.22 for WordPress allows CSV injection.
[*, 1.12.22)
1.12.22
27/04/2018
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.