10Web vulnerabilities
4 CVEs tracked
10Web appears in our reporting primarily through its WordPress plugins. Recent items highlight vulnerabilities in 'Form Maker' (before 1.15.45), 'Slider' (<= 1.2.62), and 'Booster' (before 2.33.5) plugins. Key risks include SQL injection via poorly parameterized dynamic queries (CVE-2026-16977, CVE-2026-15993), unauthenticated CSRF in the Slider plugin (CVE-2026-66635), and an access validation flaw in Booster that could lead to stored content injection (CVE-2026-14287). Defenders should urgently audit their versions of these plugins, apply the vendor-supplied patches, and pay special attention to second-order SQL injection risks from subscriber-level users in 'Form Maker'.
Azərbaycanca: 10Web əsasən WordPress plugin-ləri ilə hesabatlarımızda görünür. Mövcud xəbərlər 'Form Maker' (1.15.45-dən əvvəl), 'Slider' (1.2.62 və aşağı) və 'Booster' (2.33.5-dən əvvəl) pluginlərində boşluqları göstərir. Əsas risklər SQL injection (CVE-2026-16977, CVE-2026-15993), autentifikasiya olunmamış CSRF (CVE-2026-66635) və yadda saxlanan məzmun inyeksiyasına (CVE-2026-14287) səbəb ola biləcək giriş doğrulama səhvləridir. Müdafiəçilər bu pluginlərin versiyalarını dərhal yoxlamalı və təchizatçının təqdim etdiyi yamaları tətbiq etməlidir, xüsusilə `Form Maker` üçün subscriber səviyyəli istifadəçilərdən gələn ikinci dərəcəli SQL injection hücumlarına diqqət yetirməlidir.
This vendor's CVEs4
This hub is built from skopnix's own reporting on 10Web: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.