Known vulnerabilities in the Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin
8 security advisories have been published for the Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder - SQL Injection (CVE-2026-15993) MEDIUM
- Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder - SQL Injection (CVE-2026-11777) MEDIUM
- Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder - SQL Injection (CVE-2026-11776) MEDIUM
- Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder - SQL Injection (CVE-2026-3359) HIGH
- Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder - SQL Injection (CVE-2026-3330) MEDIUM
- Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder - Cross-Site Scripting (XSS) (CVE-2026-4388) HIGH
- Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder - Arbitrary File Upload (CVE-2026-1065) HIGH
- Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder - Cross-Site Scripting (XSS) (CVE-2026-1058) HIGH