CVE-2026-65565
- EPSS 0.18%
- Veröffentlicht 06.08.2026 14:27:39
- Zuletzt bearbeitet 12.08.2026 20:58:37
Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions.
CVE-2026-57361
- EPSS 0.19%
- Veröffentlicht 02.07.2026 11:15:21
- Zuletzt bearbeitet 02.07.2026 20:17:04
Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.2.5 versions.
CVE-2026-26370
- EPSS 0.19%
- Veröffentlicht 20.02.2026 07:42:15
- Zuletzt bearbeitet 15.04.2026 00:35:42
WordPress Plugin "Survey Maker" versions 5.1.7.7 and prior contain a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.
CVE-2025-64276
- EPSS 0.24%
- Veröffentlicht 13.11.2025 09:24:31
- Zuletzt bearbeitet 15.04.2026 00:35:42
Missing Authorization vulnerability in Ays Pro Survey Maker survey-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Survey Maker: from n/a through <= 5.1.9.4.
CVE-2025-12891
- EPSS 0.24%
- Veröffentlicht 13.11.2025 04:28:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Survey Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ays_survey_show_results' AJAX endpoint in all versions up to, and including, 5.1.9.4. This makes it possible for unauthentica...
CVE-2025-12892
- EPSS 0.22%
- Veröffentlicht 13.11.2025 03:27:38
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Survey Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all versions up to, and including, 5.1.9.4. This makes it possible for unauthenti...
CVE-2025-48098
- EPSS 0.21%
- Veröffentlicht 22.10.2025 14:32:07
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Maker survey-maker allows Stored XSS.This issue affects Survey Maker: from n/a through <= 5.1.8.8.
CVE-2025-48095
- EPSS 0.27%
- Veröffentlicht 22.10.2025 14:32:06
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Maker survey-maker allows Stored XSS.This issue affects Survey Maker: from n/a through <= 5.1.8.8.
CVE-2025-32275
- EPSS 0.31%
- Veröffentlicht 10.04.2025 08:15:20
- Zuletzt bearbeitet 29.04.2026 10:16:46
Authentication Bypass by Spoofing vulnerability in Ays Pro Survey Maker survey-maker allows Identity Spoofing.This issue affects Survey Maker: from n/a through <= 5.1.6.3.
CVE-2025-22664
- EPSS 0.24%
- Veröffentlicht 04.02.2025 15:15:21
- Zuletzt bearbeitet 23.04.2026 15:23:21
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Maker survey-maker allows Stored XSS.This issue affects Survey Maker: from n/a through <= 5.1.3.5.