VYPR
Vendor

Surveyjs

Products
6
CVEs
3
Across products
4
Status
Private

Products

6

Recent CVEs

3
  • CVE-2025-3815MedMay 3, 2025
    risk 0.35cvss 6.4epss 0.00

    The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.12.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2024-36043MedMay 18, 2024
    risk 0.33cvss 6.1epss 0.00

    question_image.ts in SurveyJS Form Library before 1.10.4 allows contentMode=youtube XSS via the imageLink property.

  • CVE-2025-32256MedApr 4, 2025
    risk 0.27cvss 5.3epss 0.00

    Missing Authorization vulnerability in devsoftbaltic SurveyJS surveyjs allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects SurveyJS: from n/a through <= 1.12.20.