Diaowen
Diaowen Dwsurvey: vulnerabilidades y CVE
Diaowen Dwsurvey tiene 10 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses4
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-75325 | Crítica (9.8) | 0.64% | — | 26 ago 2026 | DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters. |
| CVE-2026-18723 | Baja (2.1) | 0.35% | — | 4 ago 2026 | A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file /api/dwsurvey/app/survey/up-survey-status.do of the component Survey Status Handler. This… |
| CVE-2026-18722 | Baja (2.1) | 0.36% | — | 4 ago 2026 | A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey/app/v6/dw-design-survey/dev-survey.do of the component Survey… |
| CVE-2025-63248 | Alta (7.5) | 0.29% | — | 5 nov 2025 | DWSurvey 6.14.0 is vulnerable to Incorrect Access Control. When deleting a questionnaire, replacing the questionnaire ID with the ID of another questionnaire can enable the deletion of other questionnaires. |
| CVE-2023-40980 | Crítica (9.8) | 1.3% | — | 1 sept 2023 | File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file. |
| CVE-2020-20070 | Media (6.1) | 0.56% | — | 20 jun 2023 | Cross Site Scripting vulnerability found in wkeyuan DWSurvey 1.0 allows a remote attacker to execute arbitrary code via thequltemld parameter of the qu-multi-fillblank!answers.action file. |
| CVE-2021-39384 | Crítica (9.8) | 1.2% | — | 20 mar 2022 | DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.java. |
| CVE-2021-39383 | Crítica (9.8) | 3.1% | — | 20 mar 2022 | DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java. |
| CVE-2019-15095 | Media (6.1) | 0.87% | — | 16 ago 2019 | DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter. |
| CVE-2019-14747 | Media (6.1) | 0.79% | — | 7 ago 2019 | DWSurvey through 2019-07-22 has stored XSS via the design/my-survey-design!copySurvey.action surveyName parameter. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.