PT-2026-71016 · 10Web · Form Maker

·

CVE-2026-16977

·

Published

2026-08-12

·

Updated

2026-08-12

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Form Maker by 10Web versions prior to 1.15.45
Description This issue occurs when the software fails to properly parameterize a user-controlled value used in a dynamic SQL query for a database-backed choice field. This allows users with subscriber-level privileges to perform a second-order SQL injection, which is a type of attack where malicious input is stored by the application and later executed as a command when the stored data is retrieved and used in a different query. The vulnerable variable is display name.
Recommendations Update Form Maker by 10Web to version 1.15.45 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16977

Affected Products

Form Maker