CVE-2025-64276
- EPSS 0.03%
- Veröffentlicht 13.11.2025 09:24:31
- Zuletzt bearbeitet 17.11.2025 20:15:52
Missing Authorization vulnerability in Ays Pro Survey Maker survey-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Survey Maker: from n/a through <= 5.1.9.4.
CVE-2025-12891
- EPSS 0.06%
- Veröffentlicht 13.11.2025 04:28:00
- Zuletzt bearbeitet 14.11.2025 16:42:03
The Survey Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ays_survey_show_results' AJAX endpoint in all versions up to, and including, 5.1.9.4. This makes it possible for unauthentica...
CVE-2025-12892
- EPSS 0.07%
- Veröffentlicht 13.11.2025 03:27:38
- Zuletzt bearbeitet 14.11.2025 16:42:03
The Survey Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all versions up to, and including, 5.1.9.4. This makes it possible for unauthenti...
CVE-2025-48098
- EPSS 0.04%
- Veröffentlicht 22.10.2025 14:32:07
- Zuletzt bearbeitet 13.11.2025 11:15:59
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Maker survey-maker allows Stored XSS.This issue affects Survey Maker: from n/a through <= 5.1.8.8.
CVE-2025-48095
- EPSS 0.04%
- Veröffentlicht 22.10.2025 14:32:06
- Zuletzt bearbeitet 13.11.2025 11:15:58
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Maker survey-maker allows Stored XSS.This issue affects Survey Maker: from n/a through <= 5.1.8.8.
CVE-2025-32275
- EPSS 0.03%
- Veröffentlicht 10.04.2025 08:15:20
- Zuletzt bearbeitet 14.04.2025 12:36:13
Authentication Bypass by Spoofing vulnerability in Ays Pro Survey Maker allows Identity Spoofing. This issue affects Survey Maker: from n/a through 5.1.5.4.
CVE-2025-22664
- EPSS 0.08%
- Veröffentlicht 04.02.2025 15:15:21
- Zuletzt bearbeitet 18.04.2025 01:58:27
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Stored XSS. This issue affects Survey Maker: from n/a through 5.1.3.5.
CVE-2024-13505
- EPSS 0.13%
- Veröffentlicht 26.01.2025 12:15:28
- Zuletzt bearbeitet 04.02.2025 17:20:18
The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ays_sections[5][questions][8][title]’ parameter in all versions up to, and including, 5.1.3.3 due to insufficient input sanitization and output escaping. This...
CVE-2023-22697
- EPSS 0.3%
- Veröffentlicht 13.12.2024 15:15:10
- Zuletzt bearbeitet 17.04.2025 01:43:18
Missing Authorization vulnerability in Survey Maker team Survey Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Survey Maker: from n/a through 3.2.0.
CVE-2024-50426
- EPSS 0.18%
- Veröffentlicht 29.10.2024 09:15:10
- Zuletzt bearbeitet 18.04.2025 01:25:53
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Stored XSS.This issue affects Survey Maker: from n/a through 5.0.2.