10web Slider
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in 10web Slider.
By the Year
In 2026 there have been 0 vulnerabilities in 10web Slider. Last year, in 2025 Slider had 2 security vulnerabilities published. Right now, Slider is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 2 | 0.00 |
| 2024 | 5 | 6.28 |
| 2023 | 0 | 0.00 |
| 2022 | 1 | 4.80 |
| 2021 | 1 | 8.80 |
It may take a day or so for new Slider vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent 10web Slider Security Vulnerabilities
XSS via unsanitised settings in Slider by 10Web WP plugin <1.2.62
CVE-2024-10566
- March 25, 2025
The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
XSS
Stored XSS in 10Web Slider WP Plugin before 1.2.62
CVE-2024-10565
- March 25, 2025
The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
XSS
WordPress Slider 10Web Plugin v<1.2.59 Stored XSS
CVE-2024-8283
4.8 - Medium
- September 30, 2024
The Slider by 10Web WordPress plugin before 1.2.59 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
XSS
SQLi via id param in Slider by 10Web <=1.2.57 (WordPress)
CVE-2024-7150
8.8 - High
- August 08, 2024
The Slider by 10Web Responsive Image Slider plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 1.2.57 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
SQL Injection
XSS in Slider by 10Web WP plugin (v<1.2.57) for privileged users
CVE-2024-6408
- July 31, 2024
The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow high privilege users such as editors and above to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Stored XSS in Slider by 10Web WP Plugin <1.2.56
CVE-2024-6026
5.4 - Medium
- July 11, 2024
The Slider by 10Web WordPress plugin before 1.2.56 does not sanitise and escape some of its Slide options, which could allow authenticated users with access to the Sliders (by default Administrator, however this can be changed via the Slider by 10Web WordPress plugin before 1.2.56's options) and the ability to add images (Editor+) to perform Stored Cross-Site Scripting attacks
XSS
10Web Slider <=1.2.54 Reflected XSS Vulnerability
CVE-2024-32578
6.1 - Medium
- April 18, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Slider by 10Web allows Reflected XSS.This issue affects Slider by 10Web: from n/a through 1.2.54.
XSS in Sliderby10Web WP Plugin <1.2.53 via Unsanitized Settings
CVE-2022-4197
4.8 - Medium
- December 26, 2022
The Sliderby10Web WordPress plugin before 1.2.53 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
XSS
The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were vulnerable
CVE-2021-24132
8.8 - High
- March 18, 2021
The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were vulnerable, allowing a high privileged user (Admin), or medium one such as Contributor+ (if "Role Options" is turn on for other users) to perform a SQL Injection attacks.
SQL Injection
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for 10web Slider or by 10web? Click the Watch button to subscribe.