Show filters
221 Total Results
Displaying 111-120 of 221
Sort by:
Attacker Value
Unknown
CVE-2021-26256
Disclosure Date: December 03, 2021 (last updated February 23, 2025)
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <= 2.0.6).
0
Attacker Value
Unknown
CVE-2021-24801
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sanitization in the Surveys' Title, this could also lead to Stored Cross-Site Scripting issues
0
Attacker Value
Unknown
CVE-2021-24691
Disclosure Date: October 11, 2021 (last updated February 23, 2025)
The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
0
Attacker Value
Unknown
CVE-2021-42112
Disclosure Date: October 08, 2021 (last updated February 23, 2025)
The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.
0
Attacker Value
Unknown
CVE-2021-41123
Disclosure Date: October 04, 2021 (last updated February 23, 2025)
Survey Solutions is a survey management and data collection system. In affected versions the Headquarters application publishes /metrics endpoint available to any user. None of the survey answers are ever exposed, only the aggregate counters, including count of interviews, or count of assignments. Starting from version 21.09.1 the endpoint is turned off by default.
0
Attacker Value
Unknown
CVE-2021-20792
Disclosure Date: August 18, 2021 (last updated February 23, 2025)
Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script via unspecified vectors.
0
Attacker Value
Unknown
CVE-2021-24459
Disclosure Date: August 02, 2021 (last updated February 23, 2025)
The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
0
Attacker Value
Unknown
CVE-2021-24442
Disclosure Date: July 12, 2021 (last updated February 23, 2025)
The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks
0
Attacker Value
Unknown
CVE-2020-22607
Disclosure Date: June 28, 2021 (last updated February 22, 2025)
Cross Site Scripting vulnerabilty in LimeSurvey 4.1.11+200316 via the (1) name and (2) description parameters in application/controllers/admin/PermissiontemplatesController.php.
0
Attacker Value
Unknown
CVE-2020-23710
Disclosure Date: June 28, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) vulneraiblity in LimeSurvey 4.2.5 on textbox via the Notifications & data feature.
0