Cross-Site Scripting
22 records56.4%First: 2020. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 39 vulnerability records associated with Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder, published between 2018 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2018 | 1 | |
| 2019 | 2 | |
| 2020 | 2 | |
| 2021 | 1 | |
| 2022 | 2 | |
| 2023 | 5 | |
| 2024 | 11 | |
| 2025 | 6 | |
| 2026 | 9 |
| Severity | Records | Share |
|---|---|---|
| Critical | 1 | 2.6% |
| High | 12 | 30.8% |
| Medium | 26 | 66.7% |
First: 2020. Latest: 2026.
First: 2019. Latest: 2026.
First: 2018. Latest: 2023.
First: 2019. Latest: 2024.
First: 2023. Latest: 2026.
First: 2023. Latest: 2023.
First: 2024. Latest: 2024.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
1.15.441.15.431.15.411.15.391.15.381.15.361.15.341.15.321.15.301.15.331.15.311.15.281.15.271.15.261.15.251.15.241.15.231.15.221.15.211.15.191.15.201.15.171.15.61.14.121.13.601.13.401.13.361.13.31.13.51.12.22Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-1.15.43 | Form Maker by 10Web <= 1.15.43 - Authenticated (Adminsitrator+) SQL Injection via 'groupids' Parameter | June 17, 2026 | 1.15.44 | Medium |
*-1.15.43 | Form Maker by 10Web <= 1.15.43 - Authenticated (Administrator+) SQL Injection via 'name' Parameter | June 17, 2026 | 1.15.44 | Medium |
*-1.15.42 | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.42 - Unauthenticated SQL Injection via 'inputs' | May 4, 2026 | 1.15.43 | High |
*-1.15.40 | Form Maker by 10Web <= 1.15.40 - Authenticated (Administrator+) SQL Injection via 'ip_search' Parameter | April 16, 2026 | 1.15.41 | Medium |
*-1.15.40 | Form Maker by 10Web <= 1.15.40 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Text Box | April 13, 2026 | 1.15.41 | High |
*-1.15.38 | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.38 - Unauthenticated SQL Injection | April 8, 2026 | 1.15.39 | High |
[*, 1.15.38) | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder < 1.15.38 - Unauthenticated SQL Injection | March 23, 2026 | 1.15.38 | High |
*-1.15.35 | Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via Hidden Field | February 2, 2026 | 1.15.36 | High |
*-1.15.35 | Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via SVG file | February 2, 2026 | 1.15.36 | High |
*-1.15.33 | Form Maker by 10Web <= 1.15.33 - Authenticated (Administrator+) Stored Cross-Site Scripting | May 19, 2025 | 1.15.34 | Medium |
*-1.15.31 | Form Maker by 10Web <= 1.15.31 - Authenticated (Administrator+) Stored Cross-Site Scripting | March 26, 2025 | 1.15.32 | Medium |
*-1.15.29 | Form Maker by 10Web <= 1.15.29 - Authenticated (Admin+) Stored Cross-Site Scripting | March 3, 2025 | 1.15.30 | Medium |
*-1.15.29 | Form Maker by 10Web <= 1.15.29 - Authenticated (Admin+) Stored Cross-Site Scripting | March 2, 2025 | 1.15.30 | Medium |
*-1.15.32 | Form Maker by 10Web <= 1.15.32 - Authenticated (Admin+) Stored Cross-Site Scripting | February 7, 2025 | 1.15.33 | Medium |
*-1.15.32 | Form Maker by 10Web <= 1.15.32 - Authenticated (Admin+) Stored Cross-Site Scripting | February 3, 2025 | 1.15.33 | Medium |
*-1.15.30 | Form Maker by 10Web <= 1.15.30 - Authenticated (Admin+) Stored Cross-Site Scripting | December 17, 2024 | 1.15.31 | Medium |
*-1.15.27 | Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library | December 3, 2024 | 1.15.28 | Medium |
*-1.15.30 | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.30 - Reflected Cross-Site Scripting via add_query_arg Parameter | November 10, 2024 | 1.15.31 | Medium |
*-1.15.27 | Form Maker <= 1.15.27 - Authenticated (Administrator+) Stored Cross-Site Scripting | September 25, 2024 | 1.15.28 | Medium |
*-1.15.26 | Form Maker by 10Web <= 1.15.26 - Reflected Cross-Site Scripting | August 9, 2024 | 1.15.27 | Medium |
*-1.15.25 | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.25 - Authenticated (Admin+) Stored Cross-Site Scripting | June 10, 2024 | 1.15.26 | Medium |
*-1.15.24 | Form Maker by 10Web <= 1.15.24 - Authenticated (Administrator+) Stored Cross-Site Scripting | May 7, 2024 | 1.15.25 | Medium |
*-1.15.24 | Form Maker by 10Web <= 1.15.24 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting | April 26, 2024 | 1.15.25 | Medium |
*-1.15.23 | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.23 - Authenticated (Admin+) Stored Cross-Site Scripting | April 15, 2024 | 1.15.24 | Medium |
*-1.15.22 | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.22 - Sensitive Information Exposure | March 22, 2024 | 1.15.23 | Medium |
Selected source records
Published: June 17, 2026
Published: June 17, 2026
Published: May 4, 2026
Published: April 16, 2026
Published: April 13, 2026
Published: April 8, 2026
Published: March 23, 2026
Published: February 2, 2026
Published: September 7, 2023
Published: May 10, 2019
Published: April 5, 2019
Published: April 27, 2018
Published: April 8, 2026
Published: March 23, 2026
Published: May 4, 2026
Published: September 29, 2022
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.