Surveys Project maintains a focused survey application product characterized by a narrow but notable vulnerability footprint centered on SQL injection weaknesses in input handling. This application-layer injection risk reflects common exposure patterns in database-driven survey tools; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Surveys Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1002021CRITICAL Vulnerability in wordpress plugin surveys v1.01.8, The code in individual_responses.php does not sanitize the survey_id variable before placing it inside of an SQL query. | Sep 14, 2017 | 9.8 | 32 | NO | NO |
CVE-2017-1002020CRITICAL Vulnerability in wordpress plugin surveys v1.01.8, The code in survey_form.php does not sanitize the action variable before placing it inside of an SQL query. | Sep 14, 2017 | 9.8 | 29 | NO | NO |
CVE-2017-1002022CRITICAL Vulnerability in wordpress plugin surveys v1.01.8, The code in questions.php does not sanitize the survey variable before placing it inside of an SQL query. | Sep 14, 2017 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Surveys Project.
Media articles that mention a CVE ID that affects a product developed by Surveys Project — matched by CVE ID, not by vendor name.