CVE-2026-26370
- EPSS 0.03%
- Veröffentlicht 20.02.2026 07:42:15
- Zuletzt bearbeitet 20.02.2026 13:49:47
WordPress Plugin "Survey Maker" versions 5.1.7.7 and prior contain a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.
CVE-2025-64276
- EPSS 0.04%
- Veröffentlicht 13.11.2025 09:24:31
- Zuletzt bearbeitet 20.01.2026 15:18:52
Missing Authorization vulnerability in Ays Pro Survey Maker survey-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Survey Maker: from n/a through <= 5.1.9.4.
CVE-2025-12891
- EPSS 0.07%
- Veröffentlicht 13.11.2025 04:28:00
- Zuletzt bearbeitet 14.11.2025 16:42:03
The Survey Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ays_survey_show_results' AJAX endpoint in all versions up to, and including, 5.1.9.4. This makes it possible for unauthentica...
CVE-2025-12892
- EPSS 0.1%
- Veröffentlicht 13.11.2025 03:27:38
- Zuletzt bearbeitet 14.11.2025 16:42:03
The Survey Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all versions up to, and including, 5.1.9.4. This makes it possible for unauthenti...
CVE-2025-48098
- EPSS 0.06%
- Veröffentlicht 22.10.2025 14:32:07
- Zuletzt bearbeitet 20.01.2026 15:16:30
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Maker survey-maker allows Stored XSS.This issue affects Survey Maker: from n/a through <= 5.1.8.8.
CVE-2025-48095
- EPSS 0.06%
- Veröffentlicht 22.10.2025 14:32:06
- Zuletzt bearbeitet 20.01.2026 15:16:30
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Maker survey-maker allows Stored XSS.This issue affects Survey Maker: from n/a through <= 5.1.8.8.
CVE-2025-32275
- EPSS 0.12%
- Veröffentlicht 10.04.2025 08:15:20
- Zuletzt bearbeitet 14.04.2025 12:36:13
Authentication Bypass by Spoofing vulnerability in Ays Pro Survey Maker allows Identity Spoofing. This issue affects Survey Maker: from n/a through 5.1.5.4.
CVE-2025-22664
- EPSS 0.08%
- Veröffentlicht 04.02.2025 15:15:21
- Zuletzt bearbeitet 18.04.2025 01:58:27
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Stored XSS. This issue affects Survey Maker: from n/a through 5.1.3.5.
CVE-2024-13505
- EPSS 0.13%
- Veröffentlicht 26.01.2025 12:15:28
- Zuletzt bearbeitet 04.02.2025 17:20:18
The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ays_sections[5][questions][8][title]’ parameter in all versions up to, and including, 5.1.3.3 due to insufficient input sanitization and output escaping. This...
CVE-2023-22697
- EPSS 0.39%
- Veröffentlicht 13.12.2024 15:15:10
- Zuletzt bearbeitet 17.04.2025 01:43:18
Missing Authorization vulnerability in Survey Maker team Survey Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Survey Maker: from n/a through 3.2.0.