Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
317 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.32% | — | Ays-pro Survey Maker | 10/4/2025 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in Ays Pro Survey Maker survey-maker allows Identity Spoofing.This issue affects Survey Maker: from n/a through <= 5.1.6.3. | |
| Aplazada | Media (5.3) | 0.37% | — | Devsoftbaltic SurveyjsAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in devsoftbaltic SurveyJS surveyjs allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects SurveyJS: from n/a through <= 1.12.20. | |
| Aplazada | Media (6.5) | 0.40% | — | Devsoftbaltic SurveyjsAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devsoftbaltic SurveyJS surveyjs allows Stored XSS.This issue affects SurveyJS: from n/a through <= 1.12.20. | |
| Analizada | Media (6.1) | 0.33% | — | Expresstech Quiz AND Survey Master | 25/3/2025 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (4.8) | 0.28% | — | Willbrubaker Awesome Surveys | 11/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Will Brubaker Awesome Surveys awesome-surveys allows Stored XSS.This issue affects Awesome Surveys: from n/a through <= 2.0.10. | |
| Aplazada | Alta (7.1) | 0.28% | — | Richestsoft RS SurveyAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in richestsoft RS Survey rs-survey allows Reflected XSS.This issue affects RS Survey: from n/a through <= 1.0. | |
| Aplazada | Alta (8.8) | 0.77% | — | Surveyjs Drag AND Drop Wordpress Form BuilderAI | 1/3/2025 | 17/6/2026 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to arbitrary file deletion due to a missing capability check on the callback function of the SurveyJS_DeleteFile class in all versions up to, and including, 1.12.17. This… | |
| Analizada | Media (6.5) | 0.39% | — | Modalsurvey Simple Signup Form | 18/2/2025 | 17/6/2026 | The Simple Signup Form plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'ssf' shortcode in all versions up to, and including, 1.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Modificada | Media (4.8) | 0.25% | — | Ays-pro Survey Maker | 4/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Maker survey-maker allows Stored XSS.This issue affects Survey Maker: from n/a through <= 5.1.3.5. | |
| Analizada | Media (6.5) | 0.35% | — | Modalsurvey Wordpress Survey AND Poll | 30/1/2025 | 17/6/2026 | The WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'survey' shortcode in all versions up to, and including, 1.7.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Analizada | Media (4.8) | 0.25% | — | Ays-pro Survey Maker | 26/1/2025 | 17/6/2026 | The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ays_sections[5][questions][8][title]’ parameter in all versions up to, and including, 5.1.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.34% | — | Wordpress Survey PollAI | 7/1/2025 | 17/6/2026 | The WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsurveypoll_results' shortcode in all versions up to, and including, 1.7.5 due to insufficient input sanitization and output escaping on user supplied… | |
| Aplazada | Media (6.4) | 0.29% | — | Mightyforms Contact Form Survey AND Form BuilderAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in mightyforms Contact Form, Survey & Form Builder – MightyForms mightyforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form, Survey & Form Builder – MightyForms: from n/a through <= 1.3.9. | |
| Aplazada | Media (5.4) | 0.41% | — | Mare.io Popup Surveys AND PollsAI | 16/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Eric Sloan Popup Surveys & Polls for WordPress (Mare.io) popup-surveys allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Surveys & Polls for WordPress (Mare.io): from n/a through <= 1.36. | |
| Aplazada | Media (4.3) | 0.47% | — | Expresstechsoftwares Quiz AND Survey MasterAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in ExpressTech Quiz And Survey Master allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through 8.1.10. | |
| Modificada | Crítica (9.8) | 0.64% | — | Ays-pro Survey Maker | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Survey Maker team Survey Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Survey Maker: from n/a through 3.2.0. | |
| Analizada | Crítica (9.8) | 0.54% | — | Oretnom23 Survey Application System | 7/11/2024 | 17/6/2026 | SourceCodester Survey Application System 1.0 is vulnerable to SQL Injection in takeSurvey.php via the id parameter. | |
| Aplazada | Crítica (9.9) | 1.0% | 💥 PoC | Devsoftbaltic SurveyjsAI | 29/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in devsoftbaltic SurveyJS surveyjs.This issue affects SurveyJS: from n/a through <= 1.9.136. | |
| Modificada | Media (4.8) | 0.26% | — | Ays-pro Survey Maker | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Maker survey-maker allows Stored XSS.This issue affects Survey Maker: from n/a through <= 5.0.2. | |
| Analizada | Media (4.8) | 0.28% | — | Ays-pro Survey Maker | 8/10/2024 | 17/6/2026 | The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Survey fields in all versions up to, and including, 4.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Modificada | Media (6.1) | 0.57% | — | Limesurvey | 7/10/2024 | 5/7/2026 | Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validation and output encoding in the Alert Widget's message component. | |
| Modificada | Media (6.1) | 0.57% | — | Limesurvey | 7/10/2024 | 5/7/2026 | Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code via a crafted script to the title and comment fields. | |
| Modificada | Media (4.8) | 0.40% | — | Expresstech Quiz AND Survey Master | 23/9/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (6.5) | 0.50% | — | Limesurvey | 3/9/2024 | 17/6/2026 | A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a malicious domain. | |
| Analizada | Alta (8.8) | 1.0% | — | Limesurvey | 3/9/2024 | 17/6/2026 | An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload into the lng parameter of the js_localize.php function |