What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Reflected XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.26.
Explanation of Vulnerability in Simple Terms
02Summary
Form Maker by 10Web contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into form pages. An attacker can craft a malicious link or page that, when visited by a site user, executes JavaScript in the victim's browser. This can lead to session hijacking, credential theft, or defacement. The vulnerability affects versions up to 1.15.26.
What an attacker can do
03Attacker Capabilities
Inject and execute malicious JavaScript in a visitor's browser when they view a compromised form.
Potential impact on your site
04Site Impact
Visitors to your forms may have their sessions hijacked, credentials stolen, or see defaced content.
Conditions required to exploit
05Prerequisites
The victim must visit a page or click a link containing the malicious payload; no authentication required.
Key dates
06Disclosure timeline
August 12, 2024
CVE published
April 28, 2026
Record updated