Showing 2 vulnerabilities on this page for form_maker

Signals CISA KEV Ransomware Nuclei
10web vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WordPress Form Maker by 10Web plugin <= 1.15.20 - Captcha Bypass Vulnerability vulnerability

Improper Restriction of Excessive Authentication Attempts vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Functionality Bypass.This issue affects Form Maker by 10Web: from n/a through 1.15.20.

CWE-307Jun 4, 2024
CVSS5.3v3.1EPSS0.374%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Form-Maker < 1.15.20 - Unauthenticated Arbitrary File Upload

The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE

CWE-434Oct 16, 20231 related artifact
CVSS9.8v3.1EPSS3.28%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX