This page aggregates publicly disclosed CVE and security risk information related to surveyking, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2024-35050 | An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was deleted by an Admin. | [email protected] | 8.8 | 0.16% | 2024-05-14 | 2025-04-23 |
| CVE-2024-35049 | SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-25590. | [email protected] | 9.1 | 0.27% | 2024-05-14 | 2025-04-23 |
| CVE-2024-35048 | An issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password. | [email protected] | 4.3 | 0.13% | 2024-05-14 | 2025-04-23 |
| CVE-2022-25590 | SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application. | [email protected] | 6.5 | 0.40% | 2022-03-25 | 2024-11-21 |