Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ays-pro — Vulnerabilities & Security Advisories 39

Browse all 39 CVE security advisories affecting ays-pro. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ays-pro functions as a comprehensive enterprise resource planning and customer relationship management platform, primarily serving mid-to-large organizations for operational management. Its extensive feature set has historically exposed it to a wide array of security flaws, with thirty-seven Common Vulnerabilities and Exposures currently documented. These vulnerabilities predominantly involve remote code execution, cross-site scripting, and SQL injection, often stemming from insufficient input validation and improper access controls. Several incidents highlight critical privilege escalation risks, allowing unauthorized users to gain administrative access or execute arbitrary commands on the underlying server infrastructure. The complexity of the application’s architecture has contributed to these persistent weaknesses, making regular patching and rigorous security auditing essential for deployment. Organizations utilizing ays-pro must prioritize strict configuration management to mitigate the risk of data breaches and system compromise associated with these known defects.

CVE ID Title CVSS Severity Published
CVE-2024-9462 Poll Maker – Versus Polls, Anonymous Polls, Image Polls <= 5.4.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via Poll Settings — Poll Maker – Versus Polls, Anonymous Polls, Image Polls CWE-79 5.5 Medium 2024-10-26
CVE-2024-8488 Survey Maker – Customer Satisfaction Questionnaire, Chat Survey, Calculation Form, Payment Forms <= 4.9.7 - Authenticated (Admin+) Stored Cross-Site Scripting — Survey Maker CWE-79 4.4 Medium 2024-10-08
CVE-2024-6028 Quiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter — Quiz Maker CWE-89 9.8 Critical 2024-06-25
CVE-2024-3601 Poll Maker – Best WordPress Poll Plugin <= 5.1.8 - Missing Authorization to Unauthenticated Email Enumeration — Poll Maker – Versus Polls, Anonymous Polls, Image Polls CWE-862 5.3 Medium 2024-05-02
CVE-2024-3897 Popup Box – Best WordPress Popup Plugin <= 4.3.6 - Missing Authorization to Information Exposure — Popup Box – Create Countdown, Coupon, Video, Contact Form Popups CWE-862 5.3 Medium 2024-05-02
CVE-2024-3600 Poll Maker – Best WordPress Poll Plugin <= 5.1.8 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting — Poll Maker – Versus Polls, Anonymous Polls, Image Polls CWE-862 7.2 High 2024-04-19
CVE-2024-1078 Quiz Maker <= 6.5.2.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Creation & Modification — Quiz Maker CWE-862 4.3 Medium 2024-02-07
CVE-2024-1079 Quiz Maker <= 6.5.2.4 - Missing Authorization to Unauthenticated Quiz Data Retrieval — Quiz Maker CWE-862 5.3 Medium 2024-02-07
CVE-2023-0038 Survey Maker – Best WordPress Survey Plugin <= 3.1.3 - Unauthenticated Stored Cross-Site Scripting — Survey Maker CWE-79 7.2 High 2023-01-03

This page lists every published CVE security advisory associated with ays-pro. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.