Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
317 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.85% | — | Limesurvey | 10/3/2026 | 5/7/2026 | A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server. | |
| Modificada | Alta (7.5) | 0.47% | — | Limesurvey | 10/3/2026 | 5/7/2026 | SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive information from the database. | |
| Aplazada | Alta (8.5) | 0.27% | — | Expresstechsystems Quiz AND Survey MasterAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows SQL Injection.This issue affects Quiz And Survey Master: from n/a through <= 10.3.1. | |
| Aplazada | Media (5.1) | 0.27% | — | Ays-pro Survey MakerAI | 20/2/2026 | 17/6/2026 | WordPress Plugin "Survey Maker" versions 5.1.7.7 and prior contain a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser. | |
| Aplazada | Media (4.3) | 0.19% | — | Expresstechsystems Quiz AND Survey MasterAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.4. | |
| Aplazada | Media (5.3) | 0.33% | — | Expresstechsystems Quiz AND Survey MasterAI | 19/2/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.4. | |
| Aplazada | Media (5.1) | 0.28% | — | Zendesk Sweethawk SurveyAI | 3/2/2026 | 17/6/2026 | Zendesk SweetHawk Survey 1.6 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through support ticket submissions. Attackers can insert XSS payloads like script tags into ticket text that automatically execute when survey pages are loaded by other users. | |
| Modificada | Media (5.1) | 0.29% | — | Limesurvey | 28/1/2026 | 17/6/2026 | LimeSurvey 4.3.10 contains a stored cross-site scripting vulnerability in the Survey Menu functionality of the administration panel. Attackers can inject malicious SVG scripts through the Surveymenu[title] and Surveymenu[parent_id] parameters to execute arbitrary JavaScript in administrative contexts. | |
| Aplazada | Media (4.3) | 0.14% | — | Surveyjs Drag Drop Wordpress Form BuilderAI | 24/1/2026 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on the `SurveyJS_CloneSurvey` AJAX action. This… | |
| Aplazada | Media (4.3) | 0.15% | — | Surveyjs Drag Drop Wordpress Form BuilderAI | 24/1/2026 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing nonce verification on the 'SurveyJS_RenameSurvey' AJAX action. This makes it… | |
| Aplazada | Media (4.3) | 0.15% | — | Surveyjs Drag AND Drop Form BuilderAI | 24/1/2026 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing nonce validation on the SurveyJS_AddSurvey AJAX action. This makes it possible for unauthenticated attackers to create surveys via a… | |
| Aplazada | Media (4.3) | 0.18% | — | Expresstechsystems Quiz AND Survey MasterAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.3. | |
| Aplazada | Media (5.1) | 0.47% | — | Opinionstage Poll Survey AND Quiz MakerAI | 16/1/2026 | 17/6/2026 | Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site scripting (XSS) vulnerability via multiple parameters due to insufficient input validation and output escaping. An unauthenticated attacker can inject arbitrary script into content that executes… | |
| Analizada | Media (5.1) | 0.20% | — | Ngsurvey | 7/1/2026 | 30/9/2026 | Stored cross-site scripting (XSS, CWE-79) in the survey content and administration functionality in Data Illusion Zumbrunn NGSurvey Enterprise Edition 3.6.4 on all supported platforms ( on Windows and Linux servers ) allows authenticated remote users with survey creation or edit privileges to execute arbitrary… | |
| Analizada | Media (6.5) | 0.27% | — | Expresstech Quiz AND Survey Master | 6/1/2026 | 30/9/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability and status checks on multiple functions in all versions up to, and including, 10.3.1. This makes it possible for unauthenticated attackers to view… | |
| Analizada | Media (6.5) | 0.26% | — | Expresstech Quiz AND Survey Master | 6/1/2026 | 30/9/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injection via the ‘is_linking’ parameter in all versions up to, and including, 10.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Modificada | Media (4.3) | 0.22% | — | Expresstech Quiz AND Survey Master | 6/1/2026 | 30/9/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the qsm_dashboard_delete_result function in all versions up to, and including, 10.3.1. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.33% | — | Opinionstage Poll Survey AND Quiz MakerAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Opinion Stage Poll, Survey & Quiz Maker Plugin by Opinion Stage social-polls-by-opinionstage allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll, Survey & Quiz Maker Plugin by Opinion Stage: from n/a through <= 19.12.0. | |
| Aplazada | Media (5.3) | 0.30% | — | Expresstechsystems Quiz AND Survey MasterAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.2. | |
| Aplazada | Media (5.3) | 0.29% | — | SurveyfunnelAI | 5/12/2025 | 17/6/2026 | The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.5 via several unprotected /wp-json/surveyfunnel/v2/ REST API endpoints. This makes it possible for unauthenticated attackers to extract sensitive data from… | |
| Aplazada | Media (6.4) | 0.22% | — | SurveyfunnelAI | 5/12/2025 | 25/9/2026 | The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'surveyfunnel_lite_survey' shortcode in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.15% | — | Surveyjs Drag Drop Form BuilderAI | 2/12/2025 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12.20. This is due to missing nonce validation on the SurveyJS_DeleteSurvey AJAX action. This makes it possible for unauthenticated attackers to delete surveys via a… | |
| Aplazada | Alta (8.6) | 0.30% | — | NgsurveyAI | 1/12/2025 | 3/9/2026 | Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user. | |
| Aplazada | Media (4.3) | 0.15% | — | Opinionstage Poll Survey Quiz MakerAI | 27/11/2025 | 17/6/2026 | The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 19.12.0. This is due to missing or insufficient nonce validation on the disconnect_account_action function. This makes it possible for unauthenticated attackers… | |
| Analizada | Media (6.9) | 0.26% | — | Limesurvey | 20/11/2025 | 17/6/2026 | In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed session cookie. Instead of displaying a generic error message, the system exposes internal backend information, including the use of the Yii framework, the MySQL/MariaDB database engine, the table name… |