CVE-2026-3359
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
Minimum safe version
1.15.43
Update to 1.15.43 or later to address 49 fixable vulnerabilities
CVE-2026-3330
Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via SVG file
Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via Hidden Field
Form Maker by 10Web <= 1.15.40 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Text Box
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.38 - Unauthenticated SQL Injection
CVE-2025-15441
CVE-2025-48341
CVE-2024-13053
CVE-2024-10680
CVE-2024-10560
CVE-2024-10558
CVE-2024-13605
CVE-2024-10562
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
WordPress Form Maker by 10Web Plugin <= 1.15.30 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-8633
CVE-2024-43220
CVE-2024-6130
CVE-2024-34437
WordPress Form Maker by 10Web Plugin <= 1.15.24 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-32534
CVE-2024-2112
WordPress Form Maker by 10Web Plugin <= 1.15.21 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-48290
CVE-2023-4666
Form Maker <= 1.15.20 - Captcha Bypass
CVE-2023-45071
CVE-2023-45070
WordPress Form Maker by 10Web Plugin < 1.15.20 is vulnerable to Arbitrary File Upload
Form Maker by 10Web <= 1.15.19 - Unauthenticated Arbitrary File Upload
Form Maker <= 1.15.16 - Missing Authorization in check_score
Form Maker 1.6.4 - front_end_form_maker.php Unspecified XSS
Form Maker by 10Web < 1.13.36 - Authenticated SQL Injection
Form Maker by 10Web < 1.13.40 - Authenticated Reflected XSS
Form Maker by 10Web <= 1.13.35 - SQL Injection
Form Maker by 10Web < 1.13.40 - Reflected Cross-Site Scripting
CVE-2022-3300
WordPress Form Maker Plugin <= 1.6.4 - Unspecified Cross Site Scripting
CVE-2022-1564
WordPress Form Maker by 10Web plugin <= 1.13.4 - Cross-Site Request Forgery (CSRF) vulnerability
WordPress Form Maker by 10Web plugin <= 1.13.35 - Authenticated SQL Injection (SQLi) vulnerability
WordPress Form Maker by 10Web plugin <= 1.13.39 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability
WordPress Form Maker by 10Web plugin <= 1.13.56 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability
WordPress Form Maker by 10Web plugin <= 1.13.56 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
CVE-2018-10504
CVE-2019-11590
WordPress Form Maker by 10Web plugin <= 1.13.2 - Authenticated SQL Injection (SQLi) vulnerability
CVE-2021-24526