PT-2026-103746 · 10Web · Form Maker

·

CVE-2026-96813

·

Published

2026-10-01

·

Updated

2026-10-01

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder versions prior to 1.15.48
Description Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting (XSS). This occurs through the Mark on Map Longitude and Latitude fields, enabling the injection of arbitrary web scripts that execute when a user accesses the affected page.
Recommendations Update the plugin to version 1.15.48 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96813

Affected Products

Form Maker