CVE Tools

Form Maker By 10web – Mobile-friendly Drag & Drop Contact Form Builder

17 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Form Maker By 10web – Mobile-friendly Drag & Drop Contact Form Builder, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Form Maker By 10web – Mobile-friendly Drag & Drop Contact Form Builder CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Form Maker By 10web – Mobile-friendly Drag & Drop Contact Form Builder CVEs per month
MonthCVEs
2024-100
2024-111
2024-121
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-022
2026-030
2026-042
2026-051
2026-062
2026-070
2026-081
2026-091

Severity

How the 17 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High635%
  • Medium1165%

Latest CVEs

The 15 most recently published vulnerabilities affecting Form Maker By 10web – Mobile-friendly Drag & Drop Contact Form Builder.

  1. CVE-2026-85645Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.46 - Reflected Cross-Site Scripting6.1
  2. CVE-2026-15993Form Maker by 10Web <= 1.15.44 - Authenticated (Subscriber+) SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause5.3
  3. CVE-2026-11776Form Maker by 10Web <= 1.15.43 - Authenticated (Adminsitrator+) SQL Injection via 'groupids' Parameter4.9
  4. CVE-2026-11777Form Maker by 10Web <= 1.15.43 - Authenticated (Administrator+) SQL Injection via 'name' Parameter4.9
  5. CVE-2026-3359Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.42 - Unauthenticated SQL Injection via 'inputs'7.5
  6. CVE-2026-3330Form Maker by 10Web <= 1.15.40 - Authenticated (Administrator+) SQL Injection via 'ip_search' Parameter4.9
  7. CVE-2026-4388Form Maker by 10Web <= 1.15.40 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Text Box7.2
  8. CVE-2026-1058Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via Hidden Field7.1
  9. CVE-2026-1065Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via SVG file7.2
  10. CVE-2024-5020Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library6.4
  11. CVE-2024-10265Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.30 - Reflected Cross-Site Scripting via add_query_arg Parameter6.1
  12. CVE-2024-8633Form Maker <= 1.15.27 - Authenticated (Administrator+) Stored Cross-Site Scripting5.5
  13. CVE-2024-2258Form Maker by 10Web <= 1.15.24 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting4.4
  14. CVE-2024-2112Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.22 - Sensitive Information Exposure5.9
  15. CVE-2024-0667Form-Maker (twb_form-maker) <= 1.15.21 - Cross-Site Request Forgery to Limited Code Execution via Execute5.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store