CVE-2026-100303: Tduckcloud Tduck-Survey-Form
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories. Authenticated non-admin users can add, modify, or delete themes and theme categories affecting forms owned by other users.
Affected products
- Tduckcloud Tduck-Survey-Form: up to and including 6.0
Published 2026-09-25. Last modified 2026-09-30.