CVE-2026-100306Medium· 5.3▾ SunlitTDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the front end. Remote unauthenticated attackers can submit form entries directly to public submission APIs without provi…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the front end. Remote unauthenticated attackers can submit form entries directly to public submission APIs without providing the password by using the form key from share links.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100305Medium· 4.3TDuck survey form through 6.0 fails to enforce form fill-in restrictions on the authenticated submission endpoint POST /user/form/data/create
CVE-2026-100303Medium· 5.4TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories
CVE-2026-100304Medium· 5.3TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open when a form does not exist, allowing authenticated users to access deleted form submissions
CVE-2026-92602High· 7.1TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController
CVE-2026-92567Medium· 6.5TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submission data
CVE-2026-95829Medium· 6.3A vulnerability was identified in TDuckCloud tduck-platform up to 5.3