TDuckCloud tduck-survey-form

6 known vulnerabilities in TDuckCloud tduck-survey-form, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-100306 CVSS 6.9 medium TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the front end. Remote…
  • CVE-2026-100305 CVSS 5.3 medium TDuck survey form through 6.0 fails to enforce form fill-in restrictions on the authenticated submission endpoint POST…
  • CVE-2026-100304 CVSS 6.0 medium TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open when a form does not…
  • CVE-2026-100303 CVSS 5.3 medium TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories…
  • CVE-2026-92602 CVSS 7.1 high TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController…
  • CVE-2026-92567 CVSS 7.1 high TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that…