Known Vulnerabilities for Survey by Autodesk
Listed below are 1 of the newest known vulnerabilities associated with "Survey" by "Autodesk".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-100306 json | TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the fron... | Not Provided | 2026-09-25 | 2026-09-30 |
| CVE-2026-100305 json | TDuck survey form through 6.0 fails to enforce form fill-in restrictions on the authenticated submission endpoint POST /user/... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-100304 json | TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open when a ... | Not Provided | 2026-09-25 | 2026-09-29 |
| CVE-2026-100303 json | TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and ca... | Not Provided | 2026-09-25 | 2026-09-30 |
| CVE-2026-97685 json | An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized ... | Not Provided | 2026-09-29 | 2026-09-30 |
| CVE-2026-97289 json | Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions. | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-92730 json | LimeSurvey Community Edition 7.0.14 contains a reflected cross-site scripting vulnerability on the administrative survey-part... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-92602 json | TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController.... | Not Provided | 2026-09-16 | 2026-09-24 |
| CVE-2026-92567 json | TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpo... | Not Provided | 2026-09-16 | 2026-09-24 |
| CVE-2026-91775 json | LimeSurvey Community Edition 7.0.14 fails to safely encode attacker-controlled content from a crafted .lss survey file when ... | Not Provided | 2026-09-23 | 2026-10-02 |