SecAlerts
1

10web

Security Risk Profile

41
/100
medium

Security Risk Score

Comprehensive risk assessment based on 117 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from January 16, 2015 to present

117
Total CVEs
36
Critical+High
0
Exploited
23
Unpatched

Threat Assessment

Avg CVSS
6.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
23
Critical/High
Risk Level
41/100
medium
📈 3 in Last 30 Days

Severity Distribution

Critical
12
High
24
Medium
76
Low
5

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
29

Age Distribution

Common Weaknesses (CWE)

1
XSS
67
2
SQL Injection
25
3
Path Traversal
8
4
CSRF
7
5
Malicious File Upload
2

Most Affected Products

1. 10web Photo Gallery Wordpress46
2. 10web Form Maker Wordpress24
3. 10web Form Maker20
4. 10web Photo Gallery12
5. 10web Slider Wordpress9

Recent Vulnerabilities

See more →
CVE-2026-66616
CVSS 7.1high

WordPress Form Maker by 10Web plugin <= 1.15.46 - Cross Site Scripting (XSS) vulnerability

Aug 20, 2026🔧 No Patch
CVE-2026-15993
CVSS 5.3medium

Form Maker by 10Web <= 1.15.44 - Authenticated (Subscriber+) SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause

Aug 15, 2026🔧 No Patch
CVE-2026-16977
CVSS 8.1high

Form Maker by 10Web < 1.15.45 - Subscriber+ SQL Injection via display_name

Aug 12, 2026🔧 No Patch
CVE-2026-11776
CVSS 4.9medium

Form Maker by 10Web <= 1.15.43 - Authenticated (Adminsitrator+) SQL Injection via 'groupids' Parameter

Jun 18, 2026🔧 No Patch
CVE-2026-11777
CVSS 4.9medium

Form Maker by 10Web <= 1.15.43 - Authenticated (Administrator+) SQL Injection via 'name' Parameter

Jun 18, 2026🔧 No Patch
CVE-2026-39502
CVSS 9.3critical

WordPress Form Maker by 10Web plugin <= 1.15.38 - SQL Injection vulnerability

Jun 15, 2026🔧 No Patch
CVE-2026-9829
CVSS 6.5EPSS 0%medium

Photo Gallery by 10Web <= 1.8.41 - Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Parameter

Jun 6, 2026🔧 No Patch
CVE-2026-49771
CVSS 7.6high

WordPress Photo Gallery by 10Web plugin <= 1.8.41 - SQL Injection vulnerability

Jun 4, 2026🔧 No Patch
CVE-2026-7048
CVSS 6.5medium

Photo Gallery by 10Web <= 1.8.40 - Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute

May 28, 2026🔧 No Patch
CVE-2026-3359
CVSS 7.5high

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.42 - Unauthenticated SQL Injection via 'inputs'

May 5, 2026🔧 No Patch

Monitor 10web in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

10web Security Vulnerabilities & Risk Score | 117 CVEs | SecAlerts - SecAlerts