Extension WordPress
Vulnérabilités SurveyJS: Drag & Drop Form Builder
Cette page rassemble les failles publiées pour SurveyJS: Drag & Drop Form Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de SurveyJS: Drag & Drop Form Builder
10 fiches
SurveyJS: Drag & Drop Form Builder <= 2.5.3 – Unauthenticated Stored Cross-Site Scripting
The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.3 via survey result submissions. This is due to insufficient input sanitization and output escaping. The public survey page exposes…
*-2.5.3
Non indiqué
20/03/2026
SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity <= 2.5.2 – Cross-Site Request Forgery to Survey Cloning
The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due…
*-2.5.2
2.5.3
23/01/2026
SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity <= 2.5.2 – Cross-Site Request Forgery to Survey Renaming
The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due…
*-2.5.2
2.5.3
23/01/2026
SurveyJS: Drag & Drop WordPress Form Builder <= 2.5.2 – Cross-Site Request Forgery to Survey Creation
The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing nonce validation on the SurveyJS_AddSurvey AJAX action. This…
*-2.5.2
2.5.3
23/01/2026
SurveyJS: Drag & Drop WordPress Form Builder <= 1.12.20 – Cross-Site Request Forgery to Survey Deletion
The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12.20. This is due to missing nonce validation on the SurveyJS_DeleteSurvey AJAX action. This…
*-1.12.20
1.20.27
01/12/2025
SurveyJS <= 1.12.32 – Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.12.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-1.12.32
1.12.33
02/05/2025
SurveyJS <= 1.12.20 – Missing Authorization
The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions…
*-1.12.20
1.12.57
04/04/2025
SurveyJS <= 1.12.20 – Authenticated (Contributor+) Stored Cross-Site Scripting
The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.12.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-1.12.20
1.12.57
04/04/2025
SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity <= 1.12.17 – Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion via SurveyJS_DeleteFile
The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to arbitrary file deletion due to a missing capability check on the callback function of…
*-1.12.17
1.12.18
28/02/2025
SurveyJS: Drag & Drop WordPress Form Builder <= 1.9.136 – Authenticated (Subscriber+) Arbitrary File Upload
The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to,…
*-1.9.136
1.12.4
24/10/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.