Lucene search

K

Survey Security Vulnerabilities

cve
cve

CVE-2023-51507

Missing Authorization vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through...

5.3CVSS

5.4AI Score

0.0004EPSS

2024-06-14 02:15 AM
36
cve
cve

CVE-2024-4266

The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.8.8 via the 'handle_file' function. This can allow unauthenticated attackers to extract sensitive data, such as...

5.3CVSS

5.3AI Score

0.001EPSS

2024-06-11 08:15 AM
23
cve
cve

CVE-2024-3592

The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'question_id' parameter in all versions up to, and including, 9.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient...

9.9CVSS

7.4AI Score

0.001EPSS

2024-06-07 06:15 AM
26
cve
cve

CVE-2024-4157

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.1.15 via deserialization of untrusted input in the extractDynamicValues function. This makes it possible for.....

7.5CVSS

7AI Score

0.001EPSS

2024-05-22 08:15 AM
28
cve
cve

CVE-2024-4061

The Survey Maker WordPress plugin before 4.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite...

5.6AI Score

0.0004EPSS

2024-05-21 06:15 AM
41
cve
cve

CVE-2024-4709

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘subject’ parameter in versions up to, and including, 5.1.16 due to insufficient input sanitization and output escaping. This makes it....

7.2CVSS

5.7AI Score

0.001EPSS

2024-05-18 08:15 AM
30
cve
cve

CVE-2024-2782

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp-json/fluentform/v1/global-settings REST API endpoint in all versions up to, and including,.....

7.5CVSS

6.5AI Score

0.0005EPSS

2024-05-18 08:15 AM
46
cve
cve

CVE-2024-2772

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in all versions up to, and including, 5.1.13 due to insufficient input sanitization and output escaping. This makes it...

6.4CVSS

6.8AI Score

0.001EPSS

2024-05-18 08:15 AM
30
cve
cve

CVE-2024-2771

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint in all versions up to, and including, 5.1.16. This makes...

9.8CVSS

7.7AI Score

0.001EPSS

2024-05-18 08:15 AM
53
cve
cve

CVE-2024-1945

The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'arflite_remove_preview_data' function in all versions up to, and including, 1.6.4. This makes it possible for.....

7.1CVSS

6.3AI Score

0.0004EPSS

2024-05-02 05:15 PM
26
cve
cve

CVE-2024-27966

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master allows Stored XSS.This issue affects Quiz And Survey Master: from n/a through...

5.9CVSS

9.1AI Score

0.0004EPSS

2024-04-11 01:25 AM
33
cve
cve

CVE-2023-35764

Insufficient verification of data authenticity issue in Survey Maker prior to 3.6.4 allows a remote unauthenticated attacker to spoof an IP address when...

6.8AI Score

0.0004EPSS

2024-04-03 08:15 AM
35
cve
cve

CVE-2023-34423

Survey Maker prior to 3.6.4 contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the website using the product with the administrative...

6AI Score

0.0004EPSS

2024-04-03 08:15 AM
30
cve
cve

CVE-2024-2791

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 3.8.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...

6.4CVSS

7.6AI Score

0.0004EPSS

2024-04-02 06:15 AM
28
cve
cve

CVE-2024-29918

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Reflected XSS.This issue affects Survey Maker: from n/a through...

7.1CVSS

9.3AI Score

0.0004EPSS

2024-03-27 08:15 AM
35
cve
cve

CVE-2023-28787

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through...

9.3CVSS

7.6AI Score

0.0004EPSS

2024-03-26 09:15 PM
29
cve
cve

CVE-2024-27996

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Stored XSS.This issue affects Survey Maker: from n/a through...

5.9CVSS

9.1AI Score

0.0004EPSS

2024-03-19 05:15 PM
37
cve
cve

CVE-2023-51521

Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through...

5.4CVSS

5.5AI Score

0.0004EPSS

2024-03-16 01:15 AM
16
cve
cve

CVE-2023-6957

The Fluent Forms plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.9 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in...

4.9CVSS

5.5AI Score

0.0004EPSS

2024-03-13 04:15 PM
19
cve
cve

CVE-2024-0660

The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.7.2. This is due to missing or incorrect nonce validation on the update_settings function. This....

6.1CVSS

5.1AI Score

0.001EPSS

2024-02-05 10:16 PM
26
cve
cve

CVE-2023-51534

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brave Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content allows Stored XSS.This issue affects Brave – Create Popup, Optins, Lead Generation, Survey,...

5.9CVSS

5.1AI Score

0.0004EPSS

2024-02-01 11:15 AM
27
cve
cve

CVE-2024-21796

Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4 and Electronic Deliverables Creation Support Tool (Design & Survey Edition) prior to Ver1.0.4 improperly restrict XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files....

5.5CVSS

5.4AI Score

0.001EPSS

2024-01-24 02:15 AM
13
cve
cve

CVE-2023-6828

The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ arf_http_referrer_url’ parameter in all versions up to, and including, 1.5.8 due to insufficient input sanitization and output escaping....

7.2CVSS

5.9AI Score

0.001EPSS

2024-01-11 09:15 AM
51
cve
cve

CVE-2023-6842

The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name field label and description field label parameter in all versions up to 6.7 (inclusive) due to insufficient input...

4.8CVSS

5.1AI Score

0.0004EPSS

2024-01-09 07:15 AM
18
cve
cve

CVE-2023-6830

The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vulnerability allows unauthenticated users to inject arbitrary HTML code into form fields. When the form data is viewed by an administrator in the Entries View Page, the injected...

6.5CVSS

6.7AI Score

0.001EPSS

2024-01-09 07:15 AM
18
cve
cve

CVE-2023-47834

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master plugin <= 8.1.13...

6.5CVSS

5.8AI Score

0.0004EPSS

2023-11-23 12:15 AM
53
cve
cve

CVE-2023-36007

Microsoft Send Customer Voice survey from Dynamics 365 Spoofing...

7.6CVSS

5.4AI Score

0.001EPSS

2023-11-14 09:15 PM
51
cve
cve

CVE-2023-26524

Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.10...

8.8CVSS

8.8AI Score

0.001EPSS

2023-11-13 12:15 AM
50
cve
cve

CVE-2023-3575

The Quiz And Survey Master WordPress plugin before 8.1.11 does not properly sanitize and escape question titles, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting...

5.4CVSS

5.2AI Score

0.0004EPSS

2023-08-07 03:15 PM
31
cve
cve

CVE-2023-38057

An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text answers. This allows a cross site scripting attack while reading the replies as authenticated agent. This issue affects.....

5.4CVSS

5.3AI Score

0.0005EPSS

2023-07-24 09:15 AM
23
cve
cve

CVE-2023-0292

The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.8. This is due to missing nonce validation on the function associated with the qsm_remove_file_fd_question AJAX action. This makes it possible for unauthenticated...

8.1CVSS

7.7AI Score

0.006EPSS

2023-06-09 06:15 AM
16
cve
cve

CVE-2023-0291

The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and including, 8.0.8. This makes it possible for unauthenticated attackers to delete...

9.1CVSS

9AI Score

0.003EPSS

2023-06-09 06:15 AM
17
cve
cve

CVE-2023-2572

The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as...

6.1CVSS

6.3AI Score

0.001EPSS

2023-06-05 02:15 PM
16
cve
cve

CVE-2023-28313

Microsoft Dynamics 365 Customer Voice Cross-Site Scripting...

6.1CVSS

6.3AI Score

0.001EPSS

2023-04-11 09:15 PM
62
cve
cve

CVE-2023-29492

Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response...

9.8CVSS

9AI Score

0.029EPSS

2023-04-11 05:15 AM
474
In Wild
2
cve
cve

CVE-2023-1946

A vulnerability was found in SourceCodester Survey Application System 1.0 and classified as problematic. This issue affects some unknown processing of the component Add New Handler. The manipulation of the argument Title with the input prompt(document.domain) leads to cross site scripting. The...

6.1CVSS

6AI Score

0.001EPSS

2023-04-07 11:15 PM
17
cve
cve

CVE-2022-46862

Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.7...

8.8CVSS

8.8AI Score

0.001EPSS

2023-02-14 12:15 PM
21
cve
cve

CVE-2023-23490

The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the 'surveys_ids' parameter of its 'ays_surveys_export_json'...

8.8CVSS

8.8AI Score

0.001EPSS

2023-01-20 07:15 PM
28
cve
cve

CVE-2023-0038

The "Survey Maker – Best WordPress Survey Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via survey answers in versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject.....

7.2CVSS

5.8AI Score

0.001EPSS

2023-01-03 02:15 PM
32
cve
cve

CVE-2022-4033

The Quiz and Survey Master plugin for WordPress is vulnerable to input validation bypass via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input validation that allows attackers to inject content other than the specified value (i.e. a number, file path,...

5.3CVSS

5.1AI Score

0.001EPSS

2022-11-29 09:15 PM
26
2
cve
cve

CVE-2022-4032

The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input sanitization and output escaping that allowed iframe tags to be injected. This makes it possible for unauthenticated.....

7.2CVSS

6.3AI Score

0.001EPSS

2022-11-29 09:15 PM
30
2
cve
cve

CVE-2022-42883

Sensitive Information Disclosure vulnerability discovered by Quiz And Survey Master plugin <= 7.3.10 on...

7.5CVSS

7.3AI Score

0.002EPSS

2022-11-18 11:15 PM
31
6
cve
cve

CVE-2022-40698

Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Quiz And Survey Master plugin <= 7.3.10 on...

6.1CVSS

5.9AI Score

0.001EPSS

2022-11-18 11:15 PM
34
3
cve
cve

CVE-2022-41652

Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on...

9.8CVSS

9.4AI Score

0.002EPSS

2022-11-18 07:15 PM
35
3
cve
cve

CVE-2021-36905

Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3.4 on...

5.4CVSS

5.4AI Score

0.001EPSS

2022-11-17 11:15 PM
33
16
cve
cve

CVE-2021-36906

Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on...

8.8CVSS

8.8AI Score

0.001EPSS

2022-11-03 08:15 PM
32
3
cve
cve

CVE-2021-36898

Auth. SQL Injection (SQLi) vulnerability in Quiz And Survey Master plugin <= 7.3.4 on...

9.1CVSS

7.4AI Score

0.001EPSS

2022-10-28 06:15 PM
36
10
cve
cve

CVE-2021-36864

Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on...

5.4CVSS

5.3AI Score

0.001EPSS

2022-10-28 06:15 PM
38
8
cve
cve

CVE-2021-36863

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on...

5.4CVSS

5.2AI Score

0.001EPSS

2022-10-28 04:15 PM
33
5
cve
cve

CVE-2009-2776

SQL injection vulnerability in showresult.asp in Smart ASP Survey allows remote attackers to execute arbitrary SQL commands via the catid...

8.7AI Score

0.001EPSS

2022-10-03 04:24 PM
23
Total number of security vulnerabilities97