Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Tripoloski

#25421of 56,333
9.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-50627
4.9
2026-06-18
10Web · Form Maker · CVE-2026-11776
**Name of the Vulnerable Software and Affected Versions** Form Maker by 10Web versions prior to 1.15.44 **Description** The Form Maker by 10Web plugin for WordPress contains a generic SQL Injection issue. This occurs because the user-supplied `groupids` parameter is not properly escaped and the SQL query is not sufficiently prepared. Authenticated attackers with administrator-level access or higher can append additional SQL queries to existing ones to extract sensitive information from the database. **Recommendations** Update to a version newer than 1.15.43. As a temporary workaround, restrict access to the `groupids` parameter until the update is applied.
PT-2026-50628
4.9
2026-06-18
10Web · Form Maker · CVE-2026-11777
**Name of the Vulnerable Software and Affected Versions** Form Maker by 10Web versions prior to 1.15.44 **Description** The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress contains a generic SQL Injection. This occurs because the `name` parameter is not sufficiently escaped and the existing SQL query lacks proper preparation. Authenticated attackers with administrator-level access can append additional SQL queries to extract sensitive information from the database. **Recommendations** Update to a version later than 1.15.43.