Show filters
221 Total Results
Displaying 91-100 of 221
Sort by:
Attacker Value
Unknown
CVE-2022-34656
Disclosure Date: August 25, 2022 (last updated February 24, 2025)
Authenticated (admin+) Cross-Site Scripting (XSS) vulnerability in wpdevart Poll, Survey, Questionnaire and Voting system plugin <= 1.7.4 at WordPress.
0
Attacker Value
Unknown
CVE-2022-29710
Disclosure Date: May 25, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execute arbitrary web scripts or HTML via a crafted plugin.
0
Attacker Value
Unknown
CVE-2022-29728
Disclosure Date: May 11, 2022 (last updated February 23, 2025)
Survey Sparrow Enterprise Survey Software 2022 has a Reflected cross-site scripting (XSS) vulnerability in the test parameter.
0
Attacker Value
Unknown
CVE-2022-29727
Disclosure Date: May 11, 2022 (last updated February 23, 2025)
Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter.
0
Attacker Value
Unknown
CVE-2022-25590
Disclosure Date: March 25, 2022 (last updated February 23, 2025)
SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.
0
Attacker Value
Unknown
CVE-2022-26249
Disclosure Date: March 24, 2022 (last updated February 23, 2025)
Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitive information via a CSV injection attack.
0
Attacker Value
Unknown
CVE-2021-39384
Disclosure Date: March 20, 2022 (last updated February 23, 2025)
DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.java.
0
Attacker Value
Unknown
CVE-2021-39383
Disclosure Date: March 20, 2022 (last updated February 23, 2025)
DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java.
0
Attacker Value
Unknown
CVE-2021-44967
Disclosure Date: February 24, 2022 (last updated February 23, 2025)
A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a superadmin, and therefore the security model is not violated by this finding.
0
Attacker Value
Unknown
CVE-2021-24765
Disclosure Date: February 01, 2022 (last updated February 23, 2025)
The Perfect Survey WordPress plugin through 1.5.2 does not validate and escape the X-Forwarded-For header value before outputting it in the statistic page when the Anonymize IP setting of a survey is turned off, leading to a Stored Cross-Site Scripting issue
0