CVE-2026-100305Medium· 4.3▾ TwilightPoC availableTDuck survey form through 6.0 fails to enforce form fill-in restrictions on the authenticated submission endpoint POST /user/form/data/create. Authenticated attackers who know a form's key can submit unlimited entries to any form, bypass…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 23.7 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
TDuck survey form through 6.0 fails to enforce form fill-in restrictions on the authenticated submission endpoint POST /user/form/data/create. Authenticated attackers who know a form's key can submit unlimited entries to any form, bypassing publish status, time window, quota, and per-IP restrictions to falsify collected results.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100303Medium· 5.4TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories
CVE-2026-100306Medium· 5.3TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the front end
CVE-2026-92602High· 7.1TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController
CVE-2026-100304Medium· 5.3TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open when a form does not exist, allowing authenticated users to access deleted form submissions
CVE-2026-92567Medium· 6.5TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submission data
CVE-2026-95829Medium· 6.3A vulnerability was identified in TDuckCloud tduck-platform up to 5.3