Extension WordPress

Vulnérabilités Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder, page 2

Cette page rassemble les failles publiées pour Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.

39Vulnérabilités
1Critiques
39Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

39 fiches

CVE-2024-6130 Moyenne · 4,4
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.25 – Authenticated (Admin+) Stored Cross-Site Scripting

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.25 due to insufficient input sanitization…

Versions affectées

*-1.15.25

Correctif

1.15.26

Publication

10/06/2024

CVE-2024-34437 Moyenne · 4,4
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Form Maker by 10Web <= 1.15.24 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.24 due to insufficient input sanitization…

Versions affectées

*-1.15.24

Correctif

1.15.25

Publication

07/05/2024

CVE-2024-2258 Moyenne · 4,4
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Form Maker by 10Web <= 1.15.24 – Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name autofilled into forms in all versions up to, and including, 1.15.24…

Versions affectées

*-1.15.24

Correctif

1.15.25

Publication

26/04/2024

CVE-2024-32534 Moyenne · 4,4
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.23 – Authenticated (Admin+) Stored Cross-Site Scripting

The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.23 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-1.15.23

Correctif

1.15.24

Publication

15/04/2024

CVE-2024-2112 Moyenne · 5,9
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.22 – Sensitive Information Exposure

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.15.22 via the signature functionality. This makes it possible…

Versions affectées

*-1.15.22

Correctif

1.15.23

Publication

22/03/2024

CVE-2024-0667 Moyenne · 5,4
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Form-Maker (twb_form-maker) <= 1.15.21 – Cross-Site Request Forgery to Limited Code Execution via Execute

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.15.21. This is due to missing or incorrect nonce…

Versions affectées

*-1.15.21

Correctif

1.15.22

Publication

26/01/2024

CVE-2023-45070 Moyenne · 6,1
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Form Maker by 10Web <= 1.15.18 – Reflected Cross-Site Scripting

The Form Maker by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a few parameters related to searching in versions up to, and including, 1.15.18 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-1.15.18

Correctif

1.15.19

Publication

03/10/2023

CVE-2023-45071 Élevée · 7,2
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Form Maker by 10Web <= 1.15.18 – Unauthenticated Stored Cross-Site Scripting

The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type_textarea' field of form submissions in versions up to, and including, 1.15.18 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-1.15.18

Correctif

1.15.19

Publication

03/10/2023

CVE-2023-4666 Critique · 9,8
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Form Maker by 10Web <= 1.15.19 – Unauthenticated Arbitrary File Upload

The Form Maker by 10Web plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'type_signature' case of the save_db() function in versions up to, and including, 1.5.19. This makes it…

Versions affectées

[*, 1.15.20)

Correctif

1.15.20

Publication

07/09/2023

Vulnérabilité Moyenne · 4,3
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Form Maker <= 1.15.16 – Missing Authorization in check_score

The Form Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_score function in versions up to, and including, 1.15.16. This makes it possible for authenticated attackers, with…

Versions affectées

*-1.15.16

Correctif

1.15.17

Publication

14/06/2023

CVE-2022-3300 Élevée · 7,2
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Form Maker <= 1.15.5 – Authenticated (Administrator+) SQL Injection

The Form Maker plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in versions up to, and including, 1.15.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

Versions affectées

*-1.15.5

Correctif

1.15.6

Publication

29/09/2022

CVE-2021-24526 Moyenne · 5,4
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Form Maker <= 1.13.59 – Authenticated Stored Cross-Site Scripting

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, leading…

Versions affectées

*-1.13.59

Correctif

1.13.60

Publication

15/07/2021

Vulnérabilité Moyenne · 6,1
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Form Maker by 10Web < 1.13.40 – Reflected Cross-Site Scripting

The Form Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.13.39 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…

Versions affectées

[*, 1.13.40)

Correctif

1.13.40

Publication

12/07/2020

CVE-2019-10866 Élevée · 8,8
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Form Maker by 10Web <= 1.13.2 – Authenticated SQL Injection

In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.

Versions affectées

[*, 1.13.3)

Correctif

1.13.3

Publication

10/05/2019

CVE-2019-11590 Élevée · 8,1
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Form Maker by 10Web <= 1.13.4 – Cross-Site Request Forgery to Local File Inclusion

The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value,…

Versions affectées

*-1.13.4

Correctif

1.13.5

Publication

05/04/2019

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités