{"cve":{"cve_id":"CVE-2023-34423","is_kev":false,"kev_date_added":null,"kev_vendor_project":null,"kev_product":null,"kev_vulnerability_name":null,"kev_short_description":null,"kev_required_action":null,"kev_due_date":null,"kev_known_ransomware":null,"kev_notes":null,"kev_cwes":null,"epss_score":0.00356,"epss_percentile":0.27316,"epss_as_of":"2026-06-23","description":"Survey Maker prior to 3.6.4 contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in to the website using the product with the administrative privilege.","published_at":"2024-04-03T07:09:42.923000Z","last_modified_at":null,"cvss_v3_score":6.1,"cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cvss_v3_severity":"MEDIUM","cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":"none","ssvc_automatable":false,"ssvc_technical_impact":"partial","cwes":["CWE-79"],"nvd_references":["https://wordpress.org/plugins/survey-maker/","https://jvn.jp/en/jp/JVN51098626/"],"vuln_status":null,"trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:39.878444Z","updated_at":"2026-06-29T01:32:48.307488Z"},"effective_severity":"MEDIUM","badges":[],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"R","value_label":"Required"},{"metric":"S","name":"Scope","value":"C","value_label":"Changed"},{"metric":"C","name":"Confidentiality","value":"L","value_label":"Low"},{"metric":"I","name":"Integrity","value":"L","value_label":"Low"},{"metric":"A","name":"Availability","value":"N","value_label":"None"}]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"ays-pro-plugins","vendor_name":"AYS Pro Plugins","product_slug":"survey-maker","product_name":"Survey Maker","version_start":"prior to 3.6.4","version_start_inclusive":true,"version_end":"prior to 3.6.4","version_end_inclusive":true,"cpe23_uri":"cve5:ays-pro-plugins:survey-maker:prior to 3.6.4:prior to 3.6.4"}],"exploit_refs":[],"news":[],"references":[{"url":"https://wordpress.org/plugins/survey-maker/","source_type":"MISC","tags":[]},{"url":"https://jvn.jp/en/jp/JVN51098626/","source_type":"MISC","tags":[]}],"timeline":[{"type":"published","at":"2024-04-03T07:09:42.923000Z","label":"CVE published","source":null},{"type":"cvss_changed","at":"2026-06-28T17:28:48.844579Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:28:48.844579Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:28:48.844579Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"ssvc_changed","at":"2026-06-29T01:32:48.307488Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-29T01:32:48.307488Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-29T01:32:48.307488Z","label":"SSVC decision revised","source":"vulnrichment"}]}