Extension WordPress

Vulnérabilités SurveyJS: Drag & Drop Form Builder

Cette page rassemble les failles publiées pour SurveyJS: Drag & Drop Form Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.

10Vulnérabilités
0Critiques
9Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de SurveyJS: Drag & Drop Form Builder

10 fiches

CVE-2026-2440 Élevée · 7,2
SurveyJS: Drag & Drop Form Builder

SurveyJS: Drag & Drop Form Builder <= 2.5.3 – Unauthenticated Stored Cross-Site Scripting

The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.3 via survey result submissions. This is due to insufficient input sanitization and output escaping. The public survey page exposes…

Versions affectées

*-2.5.3

Correctif

Non indiqué

Publication

20/03/2026

CVE-2025-13205 Moyenne · 4,3
SurveyJS: Drag & Drop Form Builder

SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity <= 2.5.2 – Cross-Site Request Forgery to Survey Cloning

The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due…

Versions affectées

*-2.5.2

Correctif

2.5.3

Publication

23/01/2026

CVE-2025-13194 Moyenne · 4,3
SurveyJS: Drag & Drop Form Builder

SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity <= 2.5.2 – Cross-Site Request Forgery to Survey Renaming

The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due…

Versions affectées

*-2.5.2

Correctif

2.5.3

Publication

23/01/2026

CVE-2025-13139 Moyenne · 4,3
SurveyJS: Drag & Drop Form Builder

SurveyJS: Drag & Drop WordPress Form Builder <= 2.5.2 – Cross-Site Request Forgery to Survey Creation

The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing nonce validation on the SurveyJS_AddSurvey AJAX action. This…

Versions affectées

*-2.5.2

Correctif

2.5.3

Publication

23/01/2026

CVE-2025-13140 Moyenne · 4,3
SurveyJS: Drag & Drop Form Builder

SurveyJS: Drag & Drop WordPress Form Builder <= 1.12.20 – Cross-Site Request Forgery to Survey Deletion

The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12.20. This is due to missing nonce validation on the SurveyJS_DeleteSurvey AJAX action. This…

Versions affectées

*-1.12.20

Correctif

1.20.27

Publication

01/12/2025

CVE-2025-3815 Moyenne · 6,4
SurveyJS: Drag & Drop Form Builder

SurveyJS <= 1.12.32 – Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter

The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.12.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

Versions affectées

*-1.12.32

Correctif

1.12.33

Publication

02/05/2025

CVE-2025-32167 Moyenne · 6,4
SurveyJS: Drag & Drop Form Builder

SurveyJS <= 1.12.20 – Authenticated (Contributor+) Stored Cross-Site Scripting

The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.12.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…

Versions affectées

*-1.12.20

Correctif

1.12.57

Publication

04/04/2025

CVE-2024-12544 Élevée · 8,8
SurveyJS: Drag & Drop Form Builder

SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity <= 1.12.17 – Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion via SurveyJS_DeleteFile

The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to arbitrary file deletion due to a missing capability check on the callback function of…

Versions affectées

*-1.12.17

Correctif

1.12.18

Publication

28/02/2025

CVE-2024-50427 Élevée · 8,8
SurveyJS: Drag & Drop Form Builder

SurveyJS: Drag & Drop WordPress Form Builder <= 1.9.136 – Authenticated (Subscriber+) Arbitrary File Upload

The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to,…

Versions affectées

*-1.9.136

Correctif

1.12.4

Publication

24/10/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités