Vulnerabilities > AYS PRO
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-08-23 | CVE-2023-32498 | Cross-site Scripting vulnerability in Ays-Pro Easy Form Auth. | 4.8 |
2023-08-18 | CVE-2023-32107 | Cross-site Scripting vulnerability in Ays-Pro Photo Gallery Unauth. | 6.1 |
2023-06-21 | CVE-2023-27414 | Cross-site Scripting vulnerability in Ays-Pro Popup BOX Unauth. | 6.1 |
2023-06-12 | CVE-2023-2568 | Unspecified vulnerability in Ays-Pro Photo Gallery The Photo Gallery by Ays WordPress plugin before 5.1.7 does not escape some parameters before outputting it back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin | 6.1 |
2023-06-05 | CVE-2023-2571 | Unspecified vulnerability in Ays-Pro Quiz Maker The Quiz Maker WordPress plugin before 6.4.2.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin | 6.1 |
2023-06-05 | CVE-2023-2572 | Unspecified vulnerability in Ays-Pro Survey Maker The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin | 6.1 |
2023-01-20 | CVE-2023-23490 | SQL Injection vulnerability in Ays-Pro Survey Maker The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the 'surveys_ids' parameter of its 'ays_surveys_export_json' action. | 8.8 |
2023-01-03 | CVE-2023-0038 | Unspecified vulnerability in Ays-Pro Survey Maker The "Survey Maker – Best WordPress Survey Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via survey answers in versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping. | 6.1 |
2022-05-30 | CVE-2022-1456 | Cross-site Scripting vulnerability in Ays-Pro Poll Maker The Poll Maker WordPress plugin before 4.0.2 does not sanitise and escape some settings, which could allow high privilege users such as admin to perform Store Cross-Site Scripting attack even when unfiltered_html is disallowed | 3.5 |
2022-05-09 | CVE-2022-1013 | SQL Injection vulnerability in Ays-Pro Personal Dictionary The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability. | 7.5 |