N/A Unfixed
2026-03-20≤ 2.5.3
SurveyJS: Drag & Drop Form Builder <= 2.5.3 - Unauthenticated Stored Cross-Site Scripting
Minimum safe version
2.5.3
Update to 2.5.3 or later to address 9 fixable vulnerabilities
SurveyJS: Drag & Drop Form Builder <= 2.5.3 - Unauthenticated Stored Cross-Site Scripting
CVE-2025-13205
CVE-2025-13194
CVE-2025-13139
CVE-2025-13140
SurveyJS <= 1.12.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
CVE-2025-32167
CVE-2025-32256
CVE-2024-12544
CVE-2024-50427