Ays-pro
Ays-pro Survey Maker: vulnerabilidades y CVE
Ays-pro Survey Maker tiene 24 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE24
Últimos 12 meses8
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-65565 | Alta (7.1) | 0.25% | — | 6 ago 2026 | Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions. |
| CVE-2026-57361 | Alta (7.1) | 0.25% | — | 2 jul 2026 | Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.2.5 versions. |
| CVE-2026-26370 | Media (5.1) | 0.27% | — | 20 feb 2026 | WordPress Plugin "Survey Maker" versions 5.1.7.7 and prior contain a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser. |
| CVE-2025-64276 | Media (6.5) | 0.24% | — | 13 nov 2025 | Missing Authorization vulnerability in Ays Pro Survey Maker survey-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Survey Maker: from n/a through <= 5.1.9.4. |
| CVE-2025-12891 | Media (5.3) | 0.24% | — | 13 nov 2025 | The Survey Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ays_survey_show_results' AJAX endpoint in all versions up to, and including, 5.1.9.4. This… |
| CVE-2025-12892 | Media (5.3) | 0.22% | — | 13 nov 2025 | The Survey Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all versions up to, and including, 5.1.9.4. This… |
| CVE-2025-48098 | Alta (7.1) | 0.23% | — | 22 oct 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Maker survey-maker allows Stored XSS.This issue affects Survey Maker: from n/a through <= 5.1.8.8. |
| CVE-2025-48095 | Media (5.9) | 0.29% | — | 22 oct 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Maker survey-maker allows Stored XSS.This issue affects Survey Maker: from n/a through <= 5.1.8.8. |
| CVE-2025-32275 | Media (5.3) | 0.32% | — | 10 abr 2025 | Authentication Bypass by Spoofing vulnerability in Ays Pro Survey Maker survey-maker allows Identity Spoofing.This issue affects Survey Maker: from n/a through <= 5.1.6.3. |
| CVE-2025-22664 | Media (4.8) | 0.25% | — | 4 feb 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Maker survey-maker allows Stored XSS.This issue affects Survey Maker: from n/a through <= 5.1.3.5. |
| CVE-2024-13505 | Media (4.8) | 0.25% | — | 26 ene 2025 | The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ays_sections[5][questions][8][title]’ parameter in all versions up to, and including, 5.1.3.3 due to insufficient input… |
| CVE-2023-22697 | Crítica (9.8) | 0.64% | — | 13 dic 2024 | Missing Authorization vulnerability in Survey Maker team Survey Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Survey Maker: from n/a through 3.2.0. |
| CVE-2024-50426 | Media (4.8) | 0.26% | — | 29 oct 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Maker survey-maker allows Stored XSS.This issue affects Survey Maker: from n/a through <= 5.0.2. |
| CVE-2024-8488 | Media (4.8) | 0.28% | — | 8 oct 2024 | The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Survey fields in all versions up to, and including, 4.9.7 due to insufficient input sanitization and output escaping. This makes it… |
| CVE-2024-4061 | Media (4.8) | 0.42% | — | 21 may 2024 | The Survey Maker WordPress plugin before 4.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2023-35764 | Media (5.3) | 0.26% | — | 3 abr 2024 | Insufficient verification of data authenticity issue in Survey Maker prior to 3.6.4 allows a remote unauthenticated attacker to spoof an IP address when posting. |
| CVE-2023-34423 | Media (6.1) | 0.36% | — | 3 abr 2024 | Survey Maker prior to 3.6.4 contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the website… |
| CVE-2024-29918 | Media (5.4) | 0.39% | — | 27 mar 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Reflected XSS.This issue affects Survey Maker: from n/a through 4.0.6. |
| CVE-2024-27996 | Media (4.8) | 0.34% | — | 19 mar 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Stored XSS.This issue affects Survey Maker: from n/a through 4.0.5. |
| CVE-2023-2572 | Media (6.1) | 0.46% | — | 5 jun 2023 | The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such… |
| CVE-2023-23490 | Alta (8.8) | 2.3% | — | 20 ene 2023 | The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the 'surveys_ids' parameter of its 'ays_surveys_export_json' action. |
| CVE-2023-0038 | Media (6.1) | 0.75% | — | 3 ene 2023 | The "Survey Maker – Best WordPress Survey Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via survey answers in versions up to, and including, 3.1.3 due to insufficient input sanitization and… |
| CVE-2021-26256 | Media (6.1) | 0.83% | — | 21 feb 2022 | Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <= 2.0.6). |
| CVE-2021-24459 | Alta (8.8) | 1.4% | — | 2 ago 2021 | The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.