10web develops a suite of WordPress plugins and hosting optimization tools that serve content creators and small-to-medium businesses, presenting a moderate but concentrated vulnerability footprint across a modestly sized product portfolio. The vendor's disclosures cluster around web-application security weaknesses—chiefly cross-site scripting, SQL injection, missing authorization, path traversal, and cross-site request forgery—that are characteristic of server-side WordPress extensions handling user input and administrative functions. Vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting the accessibility of WordPress plugins to both defenders and adversaries and the incentive to weaponize flaws in widely installed components. Core products such as Photo Gallery, Form Maker, Slider, Map Builder, and the 10web Booster appear across multiple advisories, suggesting that remediation and inventory efforts should prioritize these components. Defenders managing WordPress deployments should treat this vendor's security updates with regular attention; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 10web over time
Signals from CVEs in this vendor scope (104 CVEs).
104 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0169CRITICAL The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_front | Mar 14, 2022 | 9.8 | 86 | NO | YES |
CVE-2014-9312HIGH Unrestricted File Upload vulnerability in Photo Gallery 1.2.5. | Aug 28, 2017 | 8.8 | 65 | NO | YES |
CVE-2019-16119CRITICAL SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter. | Sep 8, 2019 | 9.8 | 56 | NO | YES |
CVE-2019-10866CRITICAL In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_f | May 23, 2019 | 9.8 | 44 | NO | YES |
CVE-2022-1281CRITICAL The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possib | May 2, 2022 | 9.8 | 43 | NO | NO |
CVE-2023-0037CRITICAL The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action | Mar 13, 2023 | 9.8 | 42 | NO | YES |
CVE-2021-24139CRITICAL Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x paramet | Mar 18, 2021 | 9.8 | 42 | NO | YES |
CVE-2023-4666CRITICAL The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbi | Oct 16, 2023 | 9.8 | 41 | NO | YES |
CVE-2023-5559CRITICAL The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the | Nov 27, 2023 | 9.1 | 36 | NO | YES |
CVE-2021-24291MEDIUM The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, alb | May 14, 2021 | 6.1 | 36 | NO | YES |
Signals from CVEs in this vendor scope (104 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 10web.
Media articles that mention a CVE ID that affects a product developed by 10web — matched by CVE ID, not by vendor name.