Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

10web

First CVE: Jan 16, 2015Active for: 12 yearsTotal CVEs: 104
30.6
VTI Score
Low

10web develops a suite of WordPress plugins and hosting optimization tools that serve content creators and small-to-medium businesses, presenting a moderate but concentrated vulnerability footprint across a modestly sized product portfolio. The vendor's disclosures cluster around web-application security weaknesses—chiefly cross-site scripting, SQL injection, missing authorization, path traversal, and cross-site request forgery—that are characteristic of server-side WordPress extensions handling user input and administrative functions. Vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting the accessibility of WordPress plugins to both defenders and adversaries and the incentive to weaponize flaws in widely installed components. Core products such as Photo Gallery, Form Maker, Slider, Map Builder, and the 10web Booster appear across multiple advisories, suggesting that remediation and inventory efforts should prioritize these components. Defenders managing WordPress deployments should treat this vendor's security updates with regular attention; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
104
Total CVEs
More Total CVEs than 99% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by 10web over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 16, 2015
11 years ago
Most Recent CVE
May 23, 2026
62 days ago

Products(15 total)

Top CVEs

Signals from CVEs in this vendor scope (104 CVEs).

104 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-0169CRITICAL
The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_front
Mar 14, 20229.886NOYES
CVE-2014-9312HIGH
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
Aug 28, 20178.865NOYES
CVE-2019-16119CRITICAL
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.
Sep 8, 20199.856NOYES
CVE-2019-10866CRITICAL
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_f
May 23, 20199.844NOYES
CVE-2022-1281CRITICAL
The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possib
May 2, 20229.843NONO
CVE-2023-0037CRITICAL
The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action
Mar 13, 20239.842NOYES
CVE-2021-24139CRITICAL
Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x paramet
Mar 18, 20219.842NOYES
CVE-2023-4666CRITICAL
The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbi
Oct 16, 20239.841NOYES
CVE-2023-5559CRITICAL
The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the
Nov 27, 20239.136NOYES
CVE-2021-24291MEDIUM
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, alb
May 14, 20216.136NOYES
View all 104 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products104 CVEs
72%
14%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network102 (98.1%)
Unknown2 (1.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low102 (98.1%)
High0 (0.0%)
Unknown2 (1.9%)
User Interaction
None34 (32.7%)
Unknown2 (1.9%)
Required68 (65.4%)
Privileges Required
Low26 (25.0%)
High34 (32.7%)
None42 (40.4%)
Unknown2 (1.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (104 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
1.9% of CVEs· 97th percentile
Nuclei
9 CVEs
8.7% of CVEs· 96th percentile
ExploitDB
5 CVEs
4.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by 10web.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by 10web — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For 10web's Products

View all 6 CNAs →

Top CWEs