CVE-2024-8633

Form Maker <= 1.15.27 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 9,148 live websites that are affected by CVE-2024-8633.

Test my site




Affected Software

Product  Form Maker
Category Form Builders
Vulnerable Domains9,148 live websites (64.31% of Form Maker install base)
Vulnerable Versions
  • from 0 through 1.15.27
Vulnerable Versions Count257 versions ( 58.14% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Sep 26, 2024
  • Updated - Sep 26, 2024

Credits

  • Joel Indra (finder)

CVE-2024-8633 usage by Country

United States3,627 websites



Germany1,014 websites
France481 websites
GB386 websites
Netherlands369 websites
Italy248 websites
Russia215 websites
Denmark180 websites
Canada176 websites
Switzerland161 websites

CVE-2024-8633 usage by TLD

.com3,796 websites
.org705 websites
.de469 websites
.nl352 websites
.co.uk254 websites
.net232 websites
.ru211 websites
.it206 websites
.fr162 websites
.ch145 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-8633

Top websites that are affected by CVE-2024-8633. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States*,***
********.nl Netherlands***,***
******.com United States***,***
*****.eu Slovenia***,***
*************.***.au Australia***,***
*******.*****.ee Estonia***,***
****************.org United States***,***
****************.org United States***,***
******************.org United States***,***
******************.com United States***,***
See full domain list

FAQ

CVE-2024-8633 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Form Maker
A total of 9,148 websites have been identified as vulnerable to CVE-2024-8633, discovered through global website indexing conducted by WebTechSurvey.
Form Maker is susceptible to CVE-2024-8633 vulnerability.
Form Maker versions before, and including, 1.15.27 are vulnerable to CVE-2024-8633.