Vulnerabilities in ays-pro

38 results
Vexday analysis

A AYS-Pro apresenta um portfólio moderado de 38 vulnerabilidades, com 3 críticas, mas sem evidência atual de exploração ativa em campo. O risco é contido pela ausência de CVEs no catálogo KEV, embora a fraqueza dominante em controle de acesso (CWE-862) represente um vetor estrutural. O fluxo recente (2 divulgações nos últimos 90 dias) indica manutenção contínua, não deterioração acelerada.

CVE-2025-12620MEDIUMPoll Maker – Versus Polls, Anonymous Polls, Image Polls <= 6.0.7 - Authenticated (Administrator+) SQL Injection via `filterbyauthor` ParameterEPSS 0.3%CVE-2026-8995MEDIUMPoll Maker by AYS <= 6.3.7 - Authenticated (Subscriber+) Sensitive Information Exposure in 'ays_poll_get_user_information' AJAX ActionEPSS 0.3%CVE-2025-13381MEDIUMAI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.0 - Missing Authorization to Unauthenticated Media File UploadsEPSS 0.3%CVE-2025-13378MEDIUMAI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.0 - Unauthenticated Server-Side Request Forgery via 'pinecone_url' ParameterEPSS 0.3%CVE-2024-12575MEDIUMPoll Maker – Versus Polls, Anonymous Polls, Image Polls <= 5.8.9 - Unauthenticated Basic Information ExposureEPSS 0.3%CVE-2024-8488MEDIUMSurvey Maker – Customer Satisfaction Questionnaire, Chat Survey, Calculation Form, Payment Forms <= 4.9.7 - Authenticated (Admin+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2026-1320HIGHSecure Copy Content Protection and Content Locking <= 4.9.8 - Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For HeaderEPSS 0.3%CVE-2024-13505MEDIUMSurvey Maker <= 5.1.3.3 - Authenticated (Admin+) Stored Cross-Site Scripting via Survey QuestionEPSS 0.2%CVE-2025-12891MEDIUMSurvey Maker <= 5.1.9.4 - Missing Authorization to Unauthenticated Information ExposureEPSS 0.2%CVE-2026-6817MEDIUMQuiz Maker by AYS <= 6.7.1.29 - Unauthenticated Stored Cross-Site Scripting via 'rate_reason'EPSS 0.2%CVE-2026-2384MEDIUMQuiz Maker <= 6.7.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.2%CVE-2025-12892MEDIUMSurvey Maker <= 5.1.9.4 - Missing Authorization to Unauthenticated Limited Option UpdateEPSS 0.2%CVE-2026-2367MEDIUMSecure Copy Content Protection and Content Locking <= 5.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode AttributeEPSS 0.2%CVE-2026-1165MEDIUMPopup Box <= 6.1.1 - Cross-Site Request Forgery to Popup Status ChangeEPSS 0.2%CVE-2025-14159MEDIUMSecure Copy Content Protection and Content Locking <= 4.9.2 - Cross-Site Request Forgery to Data ExportEPSS 0.2%CVE-2025-13685MEDIUMPhoto Gallery by Ays <= 6.4.8 - Cross-Site Request Forgery to Bulk ActionsEPSS 0.2%CVE-2024-12115MEDIUMPoll Maker <= 5.5.4 - Cross-Site Request Forgery to Poll DuplicationEPSS 0.2%CVE-2025-14454MEDIUMImage Slider by Ays- Responsive Slider and Carousel <= 2.7.0 - Cross-Site Request Forgery to Arbitrary Slider DeletionEPSS 0.2%