CVE-2026-85645Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.46 - Reflected Cross-Site Scripting Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Published 09/10/2026 Severity Medium CVE-2026-66616WordPress Form Maker by 10Web plugin <= 1.15.46 - Cross Site Scripting (XSS) vulnerability Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web Published 08/20/2026 Severity High CVE-2026-66635WordPress Slider by 10Web plugin <= 1.2.62 - CSRF to Arbitrary File Deletion vulnerability Exploitation status Not known exploited Fix YesAffected product S Slider by 10Web Published 08/18/2026 Severity High CVE-2026-15993Form Maker by 10Web <= 1.15.44 - Authenticated (Subscriber+) SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Published 08/15/2026 Severity Medium CVE-2026-28184Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 08/13/2026 Severity Unknown CVE-2026-11776Form Maker by 10Web <= 1.15.43 - Authenticated (Adminsitrator+) SQL Injection via 'groupids' Parameter Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Published 06/18/2026 Severity Medium CVE-2026-11777Form Maker by 10Web <= 1.15.43 - Authenticated (Administrator+) SQL Injection via 'name' Parameter Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Published 06/18/2026 Severity Medium CVE-2026-39502WordPress Form Maker by 10Web plugin <= 1.15.38 - SQL Injection vulnerability Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web Published 06/15/2026 Severity Critical CVE-2026-9829Photo Gallery by 10Web <= 1.8.41 - Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Parameter Exploitation status Not known exploited Fix YesAffected product P Photo Gallery by 10Web – Mobile-Friendly Image Gallery Published 06/06/2026 Severity Medium CVE-2026-49771WordPress Photo Gallery by 10Web plugin <= 1.8.41 - SQL Injection vulnerability Exploitation status Not known exploited Fix YesAffected product P Photo Gallery by 10Web Published 06/04/2026 Severity High CVE-2026-7048Photo Gallery by 10Web <= 1.8.40 - Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute Exploitation status Not known exploited Fix YesAffected product P Photo Gallery by 10Web – Mobile-Friendly Image Gallery Published 05/28/2026 Severity Medium CVE-2018-25346WordPress Form Maker Plugin 1.12.24 SQL Injection via admin-ajax.php Exploitation status Public exploit Fix Not confirmed Affected product F Form Maker Published 05/23/2026 Severity High CVE-2026-3359Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.42 - Unauthenticated SQL Injection via 'inputs' Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Published 05/05/2026 Severity High CVE-2026-3330Form Maker by 10Web <= 1.15.40 - Authenticated (Administrator+) SQL Injection via 'ip_search' Parameter Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Published 04/17/2026 Severity Medium CVE-2026-4388Form Maker by 10Web <= 1.15.40 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Text Box Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Published 04/14/2026 Severity High CVE-2026-32330WordPress Photo Gallery by 10Web plugin <= 1.8.37 - Cross Site Request Forgery (CSRF) vulnerability Exploitation status Not known exploited Fix YesAffected product P Photo Gallery by 10Web Published 03/13/2026 Severity Medium CVE-2026-27360WordPress Photo Gallery by 10Web plugin <= 1.8.38 - Cross Site Scripting (XSS) vulnerability Exploitation status Not known exploited Fix YesAffected product P Photo Gallery by 10Web Published 02/19/2026 Severity Medium CVE-2026-1058Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via Hidden Field Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Published 02/03/2026 Severity High CVE-2026-1065Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via SVG file Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Published 02/03/2026 Severity High CVE-2026-1036Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.36 - Missing Authorization to Unauthenticated Arbitrary Comment Deletion Exploitation status Not known exploited Fix YesAffected product P Photo Gallery by 10Web – Mobile-Friendly Image Gallery Published 01/21/2026 Severity Medium CVE-2025-1337710Web Booster <= 2.32.7 - Authenticated (Subscriber+) Arbitrary Folder Deletion via two_clear_page_cache Exploitation status Not known exploited Fix YesAffected product 1 10Web Booster – Website speed optimization, Cache & Page Speed optimizer Published 12/06/2025 Severity Critical CVE-2020-3685310WebMapBuilder <= 1.0.63 - Unauthenticated Stored Cross-Site Scripting via Plugin Settings Change Exploitation status Not known exploited Fix YesAffected product 1 10Web Map Builder for Google Maps Published 10/18/2025 Severity High CVE-2025-48341WordPress Form Maker by 10Web plugin <= 1.15.33 - Cross Site Scripting (XSS) Vulnerability Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web Published 05/19/2025 Severity Medium CVE-2024-8670Photo Gallery by 10Web < 1.8.29 - Admin+ Stored XSS Exploitation status Public exploit Fix YesAffected product P Photo Gallery by 10Web Published 05/15/2025 Severity Medium CVE-2024-13053Form Maker by 10Web < 1.15.33 - Admin+ Stored XSS via Theme Title Exploitation status Public exploit Fix YesAffected product F Form Maker by 10Web Published 05/15/2025 Severity Medium CVE-2024-10680Form Maker by 10Web < 1.15.32 - Admin+ Stored XSS Exploitation status Public exploit Fix YesAffected product F Form Maker by 10Web Published 04/16/2025 Severity Medium CVE-2025-2269Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.34 Reflected Cross-Site Scripting via 'image_id' Parameter Exploitation status Not known exploited Fix YesAffected product P Photo Gallery by 10Web – Mobile-Friendly Image Gallery Published 04/11/2025 Severity Medium CVE-2025-0613Photo Gallery < 1.8.34 - Unauthenticated Stored XSS Exploitation status Public exploit Fix YesAffected product P Photo Gallery by 10Web Published 03/31/2025 Severity Medium CVE-2024-10566Slider by 10Web < 1.2.62 - Contributor+ Stored XSS Exploitation status Public exploit Fix YesAffected product S Slider by 10Web Published 03/25/2025 Severity Medium CVE-2024-10565Slider by 10Web < 1.2.62 - Admin+ Stored XSS via Widget Exploitation status Public exploit Fix YesAffected product S Slider by 10Web Published 03/25/2025 Severity Medium CVE-2024-10560Form Maker by 10Web < 1.15.30 - Admin+ Stored XSS Exploitation status Public exploit Fix YesAffected product F Form Maker by 10Web Published 03/25/2025 Severity Low CVE-2024-13124Photo Gallery by 10Web < 1.8.33 - Admin+ Stored XSS Exploitation status Public exploit Fix YesAffected product P Photo Gallery by 10Web Published 03/24/2025 Severity Low CVE-2024-10558Form Maker by 10Web < 1.15.30 - Admin+ Stored XSS Exploitation status Public exploit Fix YesAffected product F Form Maker by 10Web Published 03/24/2025 Severity Low CVE-2024-13605Form Maker by 10Web < 1.15.33 - Admin+ Stored XSS Exploitation status Public exploit Fix YesAffected product F Form Maker by 10Web Published 02/24/2025 Severity Medium CVE-2024-10562Form Maker by 10Web < 1.15.31 - Admin+ Stored XSS Exploitation status Public exploit Fix YesAffected product F Form Maker by 10Web Published 01/07/2025 Severity Low CVE-2023-45272WordPress 10Web Map Builder for Google Maps plugin <= 1.0.73 - Notice Dismissal Vulnerability Exploitation status Not known exploited Fix YesAffected product 1 10Web Map Builder for Google Maps Published 01/02/2025 Severity Medium CVE-2023-47807WordPress 10WebAnalytics plugin <= 1.2.12 - Broken Access Control vulnerability Exploitation status Not known exploited Fix YesAffected product 1 10WebAnalytics Published 01/02/2025 Severity Medium CVE-2023-33995WordPress Photo Gallery by 10Web plugin <= 1.8.15 - Broken Access Control vulnerability Exploitation status Not known exploited Fix YesAffected product P Photo Gallery by 10Web Published 12/13/2024 Severity Medium CVE-2024-5020Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Published 12/04/2024 Severity Medium CVE-2024-10704Photo Gallery by 10Web < 1.8.31 - Admin+ Stored XSS Exploitation status Public exploit Fix YesAffected product P Photo Gallery by 10Web Published 11/29/2024 Severity Medium CVE-2024-10265Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.30 - Reflected Cross-Site Scripting via add_query_arg Parameter Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Published 11/10/2024 Severity Medium CVE-2024-9878Photo Gallery by 10Web <= 1.8.30 - Authenticated (Administrator+) Stored Cross-Site Scripting Exploitation status Not known exploited Fix YesAffected product P Photo Gallery by 10Web – Mobile-Friendly Image Gallery Published 11/05/2024 Severity Medium CVE-2024-9628WPS Telegram Chat <= 4.6.0 - Authenticated (Subscriber+) Unauthorized Access to Telegram Bot API Exploitation status Not known exploited Fix YesAffected product W WPS Telegram Chat Published 10/25/2024 Severity Medium CVE-2024-9630WPS Telegram Chat <= 4.6.0 - Missing Authorization to Information Exposure Exploitation status Not known exploited Fix YesAffected product W WPS Telegram Chat Published 10/25/2024 Severity Medium CVE-2024-960710Web Social Post Feed <= 1.2.9 - Reflected Cross-Site Scripting Exploitation status Not known exploited Fix YesAffected product 1 10Web Social Post Feed Published 10/25/2024 Severity Medium CVE-2024-5968Photo Gallery by 10Web <= 1.8.27 - Admin+ Stored XSS Exploitation status Public exploit Fix YesAffected product P Photo Gallery by 10Web Published 10/09/2024 Severity Medium CVE-2024-44043WordPress Photo Gallery by 10Web plugin <= 1.8.27 - Cross Site Scripting (XSS) vulnerability Exploitation status Not known exploited Fix YesAffected product P Photo Gallery by 10Web Published 10/06/2024 Severity Medium CVE-2024-8283Slider by 10Web < 1.2.59 - Admin+ Stored XSS Exploitation status Public exploit Fix YesAffected product S Slider by 10Web Published 09/30/2024 Severity Medium CVE-2024-8633Form Maker <= 1.15.27 - Authenticated (Administrator+) Stored Cross-Site Scripting Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Published 09/26/2024 Severity Medium CVE-2024-43220WordPress Form Maker by 10Web plugin <= 1.15.26 - Reflected Cross Site Scripting (XSS) vulnerability Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web Published 08/12/2024 Severity High CVE-2024-7150Slider by 10Web – Responsive Image Slider <= 1.2.57 - Authenticated (Contributor+) SQL Injection via id Parameter Exploitation status Not known exploited Fix YesAffected product S Slider by 10Web – Responsive Image Slider Published 08/08/2024 Severity High CVE-2024-6408Slider by 10Web < 1.2.57 - Editor+ Stored XSS Exploitation status Public exploit Fix YesAffected product S Slider by 10Web Published 07/31/2024 Severity Medium CVE-2024-6272SpiderContacts <= 1.1.7 - Reflected XSS Exploitation status Public exploit Fix Not confirmed Affected product S SpiderContacts Published 07/31/2024 Severity Medium CVE-2024-6026Slider by 10Web < 1.2.56 - Editor+ Stored XSS Exploitation status Public exploit Fix YesAffected product S Slider by 10Web Published 07/11/2024 Severity Medium CVE-2024-6130Form Maker by 10Web < 1.15.26 - Admin+ Stored XSS Exploitation status Public exploit Fix YesAffected product F Form Maker by 10Web Published 07/01/2024 Severity Medium CVE-2024-35628WordPress Photo Gallery by 10Web plugin <= 1.8.25 - Broken Access Control vulnerability Exploitation status Not known exploited Fix YesAffected product P Photo Gallery by 10Web Published 06/11/2024 Severity Medium CVE-2024-5481Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Path Traversal via esc_dir Function Exploitation status Not known exploited Fix YesAffected product P Photo Gallery by 10Web – Mobile-Friendly Image Gallery Published 06/07/2024 Severity Medium CVE-2024-5426Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Stored Cross-Site Scripting via Zipped SVG Exploitation status Not known exploited Fix YesAffected product P Photo Gallery by 10Web – Mobile-Friendly Image Gallery Published 06/07/2024 Severity Medium CVE-2023-48290WordPress Form Maker by 10Web plugin <= 1.15.20 - Captcha Bypass Vulnerability vulnerability Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web Published 06/04/2024 Severity Medium CVE-2024-34437WordPress Form Maker by 10Web plugin <= 1.15.24 - Cross Site Scripting (XSS) vulnerability Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web Published 05/09/2024 Severity Medium CVE-2024-33586WordPress Photo Gallery by 10Web plugin <= 1.8.20 - Broken Access Control vulnerability Exploitation status Not known exploited Fix YesAffected product P Photo Gallery by 10Web Published 04/29/2024 Severity Medium CVE-2024-2258Form Maker by 10Web <= 1.15.24 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Published 04/27/2024 Severity Medium CVE-2024-32578WordPress Sliderby10Web plugin <= 1.2.54 - Cross Site Scripting (XSS) vulnerability Exploitation status Not known exploited Fix YesAffected product S Slider by 10Web Published 04/18/2024 Severity High CVE-2024-32583WordPress Photo Gallery by 10Web plugin <= 1.8.21 - Reflected Cross Site Scripting (XSS) vulnerability Exploitation status Not known exploited Fix YesAffected product P Photo Gallery by 10Web Published 04/18/2024 Severity High CVE-2024-32534WordPress Form Maker plugin <= 1.15.23 - Cross Site Scripting (XSS) vulnerability Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web Published 04/17/2024 Severity Medium CVE-2024-2112Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.22 - Sensitive Information Exposure Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Published 04/09/2024 Severity Medium CVE-2024-2296Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21 - Authenticated (Admin+) Stored Cross-Site Scripting via SVG Exploitation status Not known exploited Fix YesAffected product P Photo Gallery by 10Web – Mobile-Friendly Image Gallery Published 04/06/2024 Severity Medium CVE-2024-31116WordPress 10Web Map Builder for Google Maps plugin <= 1.0.74 - SQL Injection vulnerability Exploitation status Not known exploited Fix YesAffected product 1 10Web Map Builder for Google Maps Published 03/31/2024 Severity High CVE-2024-29833WordPress Photo Gallery Plugin <= 1.8.21 Stored Cross Site Scripting in UploadHandler Exploitation status Public exploit Fix YesAffected product P PhotoGallery Published 03/26/2024 Severity Medium CVE-2024-29810WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg thumb_url Exploitation status Public exploit Fix YesAffected product P PhotoGallery Published 03/26/2024 Severity Medium CVE-2024-29809WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg image_url Exploitation status Public exploit Fix YesAffected product P PhotoGallery Published 03/26/2024 Severity Medium CVE-2024-29808WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg image_id Exploitation status Public exploit Fix YesAffected product P PhotoGallery Published 03/26/2024 Severity Medium CVE-2024-29832WordPress Photo Gallery Plugin <= 1.8.21 Unauthenticated Reflected Cross Site Scripting in GalleryBox current_url Exploitation status Public exploit Fix YesAffected product P PhotoGallery Published 03/26/2024 Severity Medium CVE-2024-0221Photo Gallery by 10Web - Mobile-Friendly Image Gallery <= 1.8.19 - Directory Traversal to Arbitrary File Rename Exploitation status Not known exploited Fix YesAffected product P Photo Gallery by 10Web – Mobile-Friendly Image Gallery Published 02/05/2024 Severity Critical CVE-2023-698510Web AI Assistant – AI content writing assistant <= 1.0.18 - Missing Authorization to Arbitrary Plugin Installation Exploitation status Not known exploited Fix YesAffected product 1 10Web AI Assistant – AI content writing assistant Published 02/05/2024 Severity Medium CVE-2024-0667Form-Maker (twb_form-maker) <= 1.15.21 - Cross-Site Request Forgery to Limited Code Execution via Execute Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Published 01/27/2024 Severity Medium CVE-2023-6924Photo Gallery by 10Web <= 1.8.18 - Authenticated (Administrator+) Stored Cross-Site Scripting via Widget Exploitation status Not known exploited Fix YesAffected product P Photo Gallery by 10Web – Mobile-Friendly Image Gallery Published 01/11/2024 Severity Medium CVE-2023-555910Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion Exploitation status Public exploit Fix YesAffected product 1 10Web Booster Published 11/27/2023 Severity Unknown CVE-2023-5048WDContactFormBuilder <= 1.0.72 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Exploitation status Not confirmed Fix YesAffected product W WDContactFormBuilder Published 11/22/2023 Severity Medium CVE-2023-34375WordPress Seo By 10Web Plugin <= 1.2.9 is vulnerable to Cross Site Scripting (XSS) Exploitation status Not confirmed Fix YesAffected product S SEO by 10Web Published 11/16/2023 Severity High CVE-2023-5709WD WidgetTwitter <= 1.0.9 - Authenticated (Contributor+) SQL Injection via Shortcode Exploitation status Not known exploited Fix YesAffected product W WD WidgetTwitter Published 11/07/2023 Severity High CVE-2023-45071WordPress Form Maker by 10Web Plugin <= 1.15.18 is vulnerable to Cross Site Scripting (XSS) Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Published 10/18/2023 Severity High CVE-2023-45070WordPress Form Maker by 10Web Plugin <= 1.15.18 is vulnerable to Cross Site Scripting (XSS) Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Published 10/18/2023 Severity High CVE-2023-4666Form-Maker < 1.15.20 - Unauthenticated Arbitrary File Upload Exploitation status Public exploit Fix YesAffected product F Form Maker by 10Web Published 10/16/2023 Severity Critical CVE-2023-2122Image Optimizer by 10web < 1.0.27 - Reflected Cross-Site Scripting Exploitation status Public exploit Fix YesAffected product I Image Optimizer by 10web Published 08/16/2023 Severity Unknown CVE-2020-3675610WebAnalytics <= 1.2.8 - Cross-Site Request Forgery Bypass Exploitation status Not known exploited Fix YesAffected product 1 10WebAnalytics Published 07/12/2023 Severity Medium CVE-2021-46889Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 06/07/2023 Severity Unknown CVE-2023-2224Seo By 10Web < 1.2.7 - Admin+ Stored XSS Exploitation status Public exploit Fix YesAffected product S SEO by 10Web Published 06/05/2023 Severity Medium CVE-2023-250310WebSocial < 1.2.9 - Reflected XSS Exploitation status Public exploit Fix YesAffected product 1 10Web Social Post Feed Published 06/05/2023 Severity Medium CVE-2023-2117Image Optimizer by 10web < 1.0.27 - Admin+ Path Traversal Exploitation status Public exploit Fix YesAffected product I Image Optimizer by 10web Published 05/30/2023 Severity Low CVE-2023-1427Photo Gallery by 10Web < 1.8.15 - Admin+ Path Traversal Exploitation status Public exploit Fix YesAffected product P Photo Gallery by 10Web Published 04/17/2023 Severity Medium CVE-2023-003710WebMapBuilder < 1.0.73 - Unauthenticated SQLi Exploitation status Public exploit Fix YesAffected product 1 10Web Map Builder for Google Maps Published 03/13/2023 Severity Critical CVE-2022-475810WebMapBuilder < 1.0.72 - Contributor+ Stored XSS via Shortcode Exploitation status Public exploit Fix YesAffected product 1 10WebMapBuilder Published 01/23/2023 Severity Medium CVE-2022-4197Sliderby10Web < 1.2.53 - Admin+ Stored XSS Exploitation status Public exploit Fix YesAffected product S Sliderby10Web Published 12/26/2022 Severity Medium CVE-2022-4058Photo Gallery < 1.8.3 - Stored XSS via CSRF Exploitation status Public exploit Fix YesAffected product P Photo Gallery by 10Web Published 12/19/2022 Severity Unknown CVE-2021-31693Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 11/29/2022 Severity Unknown CVE-2022-3300Form Maker by 10Web < 1.15.6 - Admin+ SQLI Exploitation status Not known exploited Fix YesAffected product F Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Published 10/25/2022 Severity High CVE-2022-1394Photo Gallery < 1.6.4 - Admin+ Stored Cross-Site Scripting Exploitation status Not confirmed Fix YesAffected product P Photo Gallery by 10Web – Mobile-Friendly Image Gallery Published 06/06/2022 Severity Unknown CVE-2022-1564Form Maker By 10Web < 1.14.12 - Admin+ Stored Cross-Site Scripting Exploitation status Not confirmed Fix YesAffected product F Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Published 05/30/2022 Severity Unknown CVE-2022-1320Sliderby10Web < 1.2.52 - Admin+ Stored Cross-Site Scripting Exploitation status Not confirmed Fix YesAffected product S Sliderby10Web Published 05/23/2022 Severity Unknown