TDuckCloud has 4 CVEs on record between 2025 and 2026. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 6.8 (medium), with 1 rated critical. Most affected products: tduck-survey-form (2), tduck (1), tduck-platform (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.8
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Products
- tduck-survey-form 2
- tduck 1
- tduck-platform 1
Worst active — by depth score
CVE-2025-57631Critical· 9.8SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file upload module54CVE-2026-92602High· 7.1TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController51CVE-2026-92567Medium· 6.5TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submission data36CVE-2026-95829Medium· 6.3A vulnerability was identified in TDuckCloud tduck-platform up to 5.335
TDuckCloud vulnerabilities
CVEs affecting TDuckCloud, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-95829Medium· 6.3A vulnerability was identified in TDuckCloud tduck-platform up to 5.3
A vulnerability was identified in TDuckCloud tduck-platform up to 5.3. This vulnerability affects the function PaginationInnerInterceptor.concatOrderBy of the file tduck-api/src/main/java/com/tduck/cloud/api/config/MybatisPlusConfig.java…
CVE-2026-92602High· 7.1PoCTDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController
TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController. Authenticated attackers can attach webhooks to other users' forms and exfiltrate submissions to arbitrary exter…
CVE-2026-92567Medium· 6.5TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submission data
TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submission data. Attackers can discover submi…
CVE-2025-57631Critical· 9.8SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file upload module
SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file upload module