CVE-2024-35049: Surveyking

Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.

SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-25590.

Affected products

Published 2024-05-14. Last modified 2026-06-17.