Form Maker
Vendor:
First CVE: Apr 29, 2019 · Active for 7 years
25
Total CVEs
More Total CVEs than 95% of tracked products
3.6
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Form Maker over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 29, 2019
7 years ago
Most Recent CVE
May 23, 2026
62 days ago
CVE Severity & Scoring
Form Maker25 CVEs
12%
64%
16%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network25 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low25 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (28.0%)
Unknown0 (0.0%)
Required18 (72.0%)
Privileges Required
Low3 (12.0%)
High12 (48.0%)
None10 (40.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10866CRITICAL In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_f | May 23, 2019 | 9.8 | 44 | NO | YES |
CVE-2023-4666CRITICAL The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbi | Oct 16, 2023 | 9.8 | 41 | NO | YES |
CVE-2018-25346HIGH WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through | May 23, 2026 | 7.1 | 30 | NO | NO |
CVE-2019-11590HIGH The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, b | Apr 29, 2019 | 8.8 | 26 | NO | NO |
CVE-2022-3300HIGH The Form Maker by 10Web WordPress plugin before 1.15.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable | Oct 25, 2022 | 7.2 | 25 | NO | NO |
CVE-2024-2112HIGH The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including | Apr 9, 2024 | 7.5 | 24 | NO | NO |
CVE-2024-10265MEDIUM The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg with | Nov 10, 2024 | 6.1 | 22 | NO | NO |
CVE-2024-0667MEDIUM The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1. | Jan 27, 2024 | 6.3 | 20 | NO | NO |
CVE-2023-45071MEDIUM Unauth. Stored Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin <= 1.15.18 versions | Oct 18, 2023 | 6.1 | 20 | NO | NO |
CVE-2024-43220MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Reflected XSS.This i | Aug 12, 2024 | 6.1 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (25 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.0% of CVEs· 97th percentile
ExploitDB
1 CVE
4.0% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (25 CVEs).
Media Mentions
Signals from CVEs in this product scope (25 CVEs).
Top CNAs Publishing CVEs For Form Maker
Top CWEs
Versions
No cataloged versions.