CVE-2025-15441Medium· 6.8▾ SunlitThe Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" feature is in use, which could make SQL Injection attacks possible in certain contexts.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" feature is in use, which could make SQL Injection attacks possible in certain contexts.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-15410High· 7.3A vulnerability was identified in code-projects Online Guitar Store 1.0
CVE-2025-15420High· 7.3A security vulnerability has been detected in Yonyou KSOA 9.0
CVE-2025-15212Medium· 6.3A vulnerability was detected in code-projects Refugee Food Management System 1.0
CVE-2025-14258High· 7.3A vulnerability has been found in itsourcecode Student Management System 1.0
CVE-2025-13567Medium· 6.3A vulnerability was detected in itsourcecode COVID Tracking System 1.0
CVE-2025-13289Medium· 6.3A vulnerability was detected in 1000projects Design & Development of Student Database Management System 1.0