CVE-2026-66635High· 7.4▾ TwilightCross-Site Request Forgery (CSRF) vulnerability in 10Web Slider by 10Web slider-wd allows Cross Site Request Forgery.This issue affects Slider by 10Web: from n/a through 1.2.63.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Cross-Site Request Forgery (CSRF) vulnerability in 10Web Slider by 10Web slider-wd allows Cross Site Request Forgery.This issue affects Slider by 10Web: from n/a through 1.2.63.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-39787Medium· 6.5Unauthenticated Broken Access Control in 10Web Social Photo Feed <= 1.4.35 versions.
CVE-2026-92974Medium· 6.1The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'thumb_url' parameter in all versions up to, and including, 1.8.46 due to insufficient input sanitiza…
CVE-2026-96813High· 7.2The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields in all versions up to, and including, 1.15.47 due to i…
CVE-2025-31963Low· 2.9Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administrative configurati…
CVE-2026-102377High· 8.8Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions.
CVE-2026-94121High· 8.8Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions.