VendorsAYS Prosurvey_makerany version
Vulnerabilities

AYS Pro Survey Maker any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2023-22697
WordPress Survey Maker plugin <= 3.2.0 - Broken Access Control vulnerability
Published 2024-12-13 · Modified
9.8EPSS 0.006
CVE-2023-23490
The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the 'surveys_ids' parameter of its 'ays_surveys_export_json' action.
Published 2023-01-20 · Modified
8.8EPSS 0.023
CVE-2021-24459
Survey Maker < 1.5.6 - Authenticated Blind SQL Injections
Published 2021-08-02 · Modified
8.8EPSS 0.014
CVE-2023-0038
Survey Maker – Best WordPress Survey Plugin <= 3.1.3 - Unauthenticated Stored Cross-Site Scripting
Published 2023-01-03 · Modified
7.2EPSS 0.007
CVE-2024-29918
WordPress Survey Maker plugin <= 4.0.6 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2024-03-27 · Modified
7.1EPSS 0.004
CVE-2021-26256
WordPress Survey Maker plugin <= 2.0.6 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
Published 2022-02-21 · Modified
6.1EPSS 0.008
CVE-2023-2572
Survey Maker < 3.4.7 - Reflected XSS
Published 2023-06-05 · Modified
6.1EPSS 0.005
CVE-2023-34423
Survey Maker prior to 3.6.4 contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the website using the product with the administrative privilege.
Published 2024-04-03 · Analyzed
6.1EPSS 0.004
CVE-2024-27996
WordPress Survey Maker plugin <= 4.0.5 - Cross Site Scripting (XSS) vulnerability
Published 2024-03-19 · Modified
5.9EPSS 0.003
CVE-2024-50426
WordPress Survey Maker plugin <= 5.0.2 - Cross Site Scripting (XSS) vulnerability
Published 2024-10-29 · Modified
5.9EPSS 0.003
CVE-2025-22664
WordPress Survey Maker Plugin <= 5.1.3.5 - Cross Site Scripting (XSS) vulnerability
Published 2025-02-04 · Modified
5.9EPSS 0.002
CVE-2024-13505
Survey Maker <= 5.1.3.3 - Authenticated (Admin+) Stored Cross-Site Scripting via Survey Question
Published 2025-01-26 · Analyzed
5.5EPSS 0.003
CVE-2025-32275
WordPress Survey Maker plugin <= 5.1.6.3 - Bypass vulnerability
Published 2025-04-10 · Modified
5.3EPSS 0.003
CVE-2023-35764
Insufficient verification of data authenticity issue in Survey Maker prior to 3.6.4 allows a remote unauthenticated attacker to spoof an IP address when posting.
Published 2024-04-03 · Analyzed
5.3EPSS 0.003
CVE-2024-4061
Survey Maker < 4.2.9 - Admin+ Stored XSS via Plugin Settings
Published 2024-05-21 · Analyzed
4.8EPSS 0.004
CVE-2024-8488
Survey Maker – Customer Satisfaction Questionnaire, Chat Survey, Calculation Form, Payment Forms <= 4.9.7 - Authenticated (Admin+) Stored Cross-Site Scripting
Published 2024-10-08 · Analyzed
4.8EPSS 0.003