Diaowen maintains a focused survey and data-collection application (DwSurvey) with a narrow but specialized user base. Vulnerabilities in this product skew strongly toward critical severity and center on application-layer input handling and access control, recurring across cross-site scripting, unrestricted file upload, authorization bypass, and code injection weaknesses that are characteristic of web-facing survey and form-management systems. Live exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Diaowen over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-39383CRITICAL DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java. | Mar 20, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-39384CRITICAL DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.java. | Mar 20, 2022 | 9.8 | 30 | NO | NO |
CVE-2023-40980CRITICAL File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/Upload | Sep 1, 2023 | 9.8 | 26 | NO | NO |
CVE-2025-63248HIGH DWSurvey 6.14.0 is vulnerable to Incorrect Access Control. When deleting a questionnaire, replacing the questionnaire ID with the ID of another questionnaire can enable the deletio | Nov 5, 2025 | 7.5 | 24 | NO | NO |
CVE-2019-14747MEDIUM DWSurvey through 2019-07-22 has stored XSS via the design/my-survey-design!copySurvey.action surveyName parameter. | Aug 7, 2019 | 6.1 | 21 | NO | NO |
CVE-2020-20070MEDIUM Cross Site Scripting vulnerability found in wkeyuan DWSurvey 1.0 allows a remote attacker to execute arbitrary code via thequltemld parameter of the qu-multi-fillblank!answers.acti | Jun 20, 2023 | 6.1 | 20 | NO | NO |
CVE-2019-15095MEDIUM DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter. | Aug 16, 2019 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Diaowen.
Media articles that mention a CVE ID that affects a product developed by Diaowen — matched by CVE ID, not by vendor name.