Known Vulnerabilities for Form Maker by Web-dorado
Listed below are 2 of the newest known vulnerabilities associated with "Form Maker" by "Web-dorado".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-39502 json | Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-11777 json | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQ... | Not Provided | 2026-06-18 | 2026-06-18 |
| CVE-2026-11776 json | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQ... | Not Provided | 2026-06-18 | 2026-06-18 |
| CVE-2026-4388 json | The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box inpu... | Not Provided | 2026-04-14 | 2026-04-14 |
| CVE-2026-3359 json | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Inject... | Not Provided | 2026-05-05 | 2026-05-05 |
| CVE-2026-3330 json | The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection via the 'ip_search', 'startdate', 'enddate', 'use... | Not Provided | 2026-04-17 | 2026-04-17 |
| CVE-2025-48341 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Maker by 10W... | Not Provided | 2025-05-19 | 2026-04-23 |
| CVE-2025-15441 json | The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" featu... | Not Provided | 2026-04-13 | 2026-04-13 |
| CVE-2024-34437 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Builder Team... | Not Provided | 2024-05-14 | 2026-04-28 |
| CVE-2024-32534 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Builder Team... | Not Provided | 2024-04-17 | 2026-04-28 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Web-dorado | Form Maker | 3.6.12 |