VulnSea

10Web has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 6.5 (medium). The most common weakness class is CWE-79 (3). Most affected products: Photo Gallery by 10Web – Mobile-Friendly Image Gallery (2), Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder (1), form-maker (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
—
Last 90 days
4 prev 0

Weakness classes

Products

  • Photo Gallery by 10Web – Mobile-Friendly Image Gallery 2
  • Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder 1
  • form-maker 1
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

10Web vulnerabilities

CVEs affecting 10Web, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-85652Medium· 6.5
1w ago

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'album_id' Shortcode Attribute in all versions up to, and including, 1.8.44 due to insufficient escaping on the…

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'album_id' Shortcode Attribute in all versions up to, and including, 1.8.44 due to insufficient escaping on the…

▾ Sunlit10web · Photo Gallery by 10Web – Mobile-Friendly Image GalleryEPSS 0.55%via NVD
CVE-2026-86311Medium· 6.4
1w ago

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attributes in all versions up to, and including, 1.8.44 due to insufficient input sanitization…

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attributes in all versions up to, and including, 1.8.44 due to insufficient input sanitization…

▾ Sunlit10web · Photo Gallery by 10Web – Mobile-Friendly Image GalleryEPSS 0.26%via NVD
CVE-2026-85645Medium· 6.1
2w ago

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.46 - Reflected Cross-Site Scripting

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the bulk_action parameter in all versions up to, and including, 1.15.46 due to insufficie…

▾ Sunlit10web · Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form BuilderEPSS 0.38%via CVEORG
CVE-2026-66616High· 7.1
1mo ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Maker by 10Web form-maker allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.48.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Maker by 10Web form-maker allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.48.

▾ Twilight10Web · form-makervia NVD
10Web vulnerabilities (CVEs) · VulnSea