Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

317 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.8)0.24%—Quizandsurveymaster Quiz AND Survey MasterAI4/8/202626/8/2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outputting it into an unquoted HTML attribute, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the browser of any user viewing the affected quiz.
AplazadaBaja (2.1)0.35%—Diaowen DwsurveyAI4/8/202612/8/2026
A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file /api/dwsurvey/app/survey/up-survey-status.do of the component Survey Status Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been…
AplazadaBaja (2.1)0.36%—Diaowen DwsurveyAI4/8/202612/8/2026
A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey/app/v6/dw-design-survey/dev-survey.do of the component Survey Handler. The manipulation results in authorization bypass. The attack can be launched remotely. The exploit…
AplazadaMedia (4.3)0.34%—Survey Form BlockAI29/7/202630/7/2026
The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_data() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export all survey…
AplazadaBaja (2.7)0.28%—Quizandsurveymaster Quiz AND Survey MasterAI28/7/202628/7/2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates.
AplazadaMedia (5.3)0.37%—Quizandsurveymaster Quiz AND Survey MasterAI27/7/202627/7/2026
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to…
AplazadaAlta (8.5)0.36%—Quizandsurveymaster Quiz AND Survey MasterAI23/7/202623/7/2026
Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.
AplazadaMedia (6.3)0.35%—LimesurveyAI20/7/202623/7/2026
LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey template endpoint that allows authenticated users to cause the server to issue arbitrary HTTP requests by supplying a manipulated Host header. Attackers can exploit the unsanitized use of the HTTP Host…
AplazadaMedia (4.3)0.49%—Quizandsurveymaster Quiz AND Survey MasterAI3/7/20266/7/2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…
AplazadaAlta (7.1)0.25%—Ays-pro Survey MakerAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.2.5 versions.
AplazadaMedia (4.3)0.47%—Quizandsurveymaster Quiz AND Survey MasterAI27/6/202629/6/2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…
AnalizadaAlta (8.8)0.49%—Joomplace Survey Force Deluxe19/6/202619/8/2026
Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the invite parameter. Attackers can send GET requests to the component with crafted SQL payloads in the invite parameter to extract…
AplazadaAlta (7.1)0.25%—Expressionengine Quiz AND Survey MasterAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.1.2 versions.
AplazadaAlta (7.1)0.25%—Expressionengine Quiz AND Survey MasterAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.0.0 versions.
AplazadaAlta (8.7)0.60%—LimesurveyAI9/6/202623/7/2026
The RemoteControl API methods invite_participants and remind_participants pass a caller-supplied token-ID array into TokenDynamic::findUninvited(), which concatenates the values directly into a tid IN ('...') SQL clause without parameterization or input validation. A remote, authenticated attacker holding the…
AplazadaAlta (8.7)0.66%—LimesurveyAI9/6/202623/7/2026
LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. The optional allowedHosts allowlist that would constrain this is undefined in the default (and documented) configuration, so LSHttpRequest::checkIsAllowedHost() results in no operation. A remote,…
AplazadaMedia (4.9)0.60%—Expressionengine Quiz AND Survey MasterAI6/6/202623/7/2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order' parameter in all versions up to, and including, 11.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
AplazadaAlta (8.8)0.28%—Survey AND PollAI10/5/202625/7/2026
WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wp_sap cookie parameter. Attackers can craft SQL payloads in the cookie to extract sensitive database information including…
AplazadaMedia (5.3)0.67%—Quizandsurveymaster Quiz AND Survey MasterAI17/4/202617/6/2026
The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and including 11.1.0. This is due to insufficient input sanitization and the execution of do_shortcode() on user-submitted quiz answer text. User-submitted answers pass through sanitize_text_field() and…
AnalizadaMedia (6.1)0.28%—Limesurvey9/4/202617/6/2026
Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via the Box[title] and box[url] parameters.
AnalizadaMedia (6.1)0.23%—Limesurvey9/4/202617/6/2026
A Reflected Cross-Site Scripting (XSS) affects LimeSurvey versions prior to 6.15.11+250909, due to the lack of validation of gid parameter in getInstance() function in application/models/QuestionCreate.php. This allows an attacker to craft a malicious URL and compromise the logged in user.
AplazadaAlta (8.7)0.44%—Console-surveyAI30/3/202617/6/2026
A vulnerability of authorization bypass through user-controlled key in the 'console-survey/api/v1/answer/{EVENTID}/{TIMESTAMP}/' endpoint. Exploiting this vulnerability would allow an unauthenticated attacker to enumerate event IDs and obtain the complete Q&A history. This publicly exposed data may include IDs,…
AplazadaMedia (6.5)0.32%—Quizandsurveymaster Quiz AND Survey MasterAI23/3/202617/6/2026
The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to SQL Injection via the 'merged_question' parameter in all versions up to, and including, 10.3.5. This is due to insufficient sanitization of user-supplied input before being used in a SQL query. The sanitize_text_field() function applied to the…
AplazadaAlta (7.2)0.28%—SurveyjsAI21/3/202617/6/2026
The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.3 via survey result submissions. This is due to insufficient input sanitization and output escaping. The public survey page exposes the nonce required for submission, allowing unauthenticated…
AplazadaMedia (4.4)0.24%—SurveyAI21/3/202617/6/2026
The Survey plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary…