Show filters
221 Total Results
Displaying 111-120 of 221
Sort by:
Attacker Value
Unknown

CVE-2021-26256

Disclosure Date: December 03, 2021 (last updated February 23, 2025)
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <= 2.0.6).
Attacker Value
Unknown

CVE-2021-24801

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sanitization in the Surveys' Title, this could also lead to Stored Cross-Site Scripting issues
Attacker Value
Unknown

CVE-2021-24691

Disclosure Date: October 11, 2021 (last updated February 23, 2025)
The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Attacker Value
Unknown

CVE-2021-42112

Disclosure Date: October 08, 2021 (last updated February 23, 2025)
The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.
Attacker Value
Unknown

CVE-2021-41123

Disclosure Date: October 04, 2021 (last updated February 23, 2025)
Survey Solutions is a survey management and data collection system. In affected versions the Headquarters application publishes /metrics endpoint available to any user. None of the survey answers are ever exposed, only the aggregate counters, including count of interviews, or count of assignments. Starting from version 21.09.1 the endpoint is turned off by default.
0
Attacker Value
Unknown

CVE-2021-20792

Disclosure Date: August 18, 2021 (last updated February 23, 2025)
Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script via unspecified vectors.
Attacker Value
Unknown

CVE-2021-24459

Disclosure Date: August 02, 2021 (last updated February 23, 2025)
The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
Attacker Value
Unknown

CVE-2021-24442

Disclosure Date: July 12, 2021 (last updated February 23, 2025)
The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks
Attacker Value
Unknown

CVE-2020-22607

Disclosure Date: June 28, 2021 (last updated February 22, 2025)
Cross Site Scripting vulnerabilty in LimeSurvey 4.1.11+200316 via the (1) name and (2) description parameters in application/controllers/admin/PermissiontemplatesController.php.
Attacker Value
Unknown

CVE-2020-23710

Disclosure Date: June 28, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) vulneraiblity in LimeSurvey 4.2.5 on textbox via the Notifications & data feature.