Description
Cross Site Scripting (XSS) vulnerability in SurveyJS Survey Creator v.1.9.132 and before, allows attackers to execute arbitrary code and obtain sensitive information via the title parameter in form.
Recommendation
Update the survey-creator package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.9.133
- Patched version(s): 1.9.133
References
Related Issues
- DOM clobbering could escalate to Cross-site Scripting (XSS) - CVE-2024-45389
- DOM clobbering could escalate to Cross-site Scripting (XSS) - pagefind - CVE-2024-45389
- DOM clobbering could escalate to Cross-site Scripting (XSS) - @pagefind/default-ui - CVE-2024-45389
- VvvebJs Reflected Cross-Site Scripting (XSS) vulnerability - CVE-2024-29271
You might also like:
- Tags:
- npm
- survey-creator
Anything's wrong? Let us know Last updated on June 11, 2026


