Ngsurvey is a web-based survey and form-building platform with a narrow product focus; its vulnerability profile centers on application-layer weaknesses including resource-exhaustion conditions, cross-site scripting, and insecure sensitive-data storage. These classes are typical of web applications handling user input and survey responses; current severity, exploitation status, and exposure context are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ngsurvey over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-15479MEDIUM Stored cross-site scripting (XSS, CWE-79) in the survey content and administration functionality in Data Illusion Zumbrunn NGSurvey Enterprise Edition 3.6.4 on all supported platfo | Jan 7, 2026 | 5.4 | 19 | NO | NO |
CVE-2022-46484HIGH Information disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to view the password to access and arbit | Aug 2, 2023 | 7.5 | 19 | NO | NO |
CVE-2022-46485HIGH Data Illusion Survey Software Solutions ngSurvey version 2.4.28 and below is vulnerable to Denial of Service if a survey contains a "Text Field", "Comment Field" or "Contact Detail | Aug 2, 2023 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ngsurvey.
Media articles that mention a CVE ID that affects a product developed by Ngsurvey — matched by CVE ID, not by vendor name.