← Back

Surveyking

surveyking

Vendor: Surveyking • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Surveyking
1Surveyking
Jun 17, 2026
May 14, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was deleted by an Admin.
1Surveyking
1Surveyking
Jun 17, 2026
May 14, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-25590.
1Surveyking
1Surveyking
Jun 17, 2026
May 14, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password.
1Surveyking
1Surveyking
Jul 9, 2026
Mar 25, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.