Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
70 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.30% | — | Expresstechsystems Quiz AND Survey MasterAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.2. | |
| Aplazada | Alta (8.5) | 0.27% | — | Expresstechsystems Quiz AND Survey MasterAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows SQL Injection.This issue affects Quiz And Survey Master: from n/a through <= 10.2.4. | |
| Aplazada | Media (4.3) | 0.12% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 14/8/2025 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 10.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. | |
| Analizada | Media (6.1) | 0.33% | — | Expresstech Quiz AND Survey Master | 25/3/2025 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (4.3) | 0.47% | — | Expresstechsoftwares Quiz AND Survey MasterAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in ExpressTech Quiz And Survey Master allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through 8.1.10. | |
| Modificada | Media (4.8) | 0.40% | — | Expresstech Quiz AND Survey Master | 23/9/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.7) | 0.43% | — | Expresstech Quiz AND Survey Master | 26/8/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before displaying them on a page or post where the Quiz is embedded, which could allows contributor and above roles to perform Stored Cross-Site Scripting (XSS) attacks. | |
| Analizada | Media (5.9) | 0.33% | — | Expresstech Quiz AND Survey Master | 3/8/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.1.0 does not properly sanitise and escape some of its Quizz settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.38% | — | Expresstech Quiz AND Survey Master | 11/7/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (8.8) | 0.59% | — | Expresstech Quiz AND Survey Master | 2/7/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action, leading to a SQL injection exploitable by Contributors and above role | |
| Analizada | Media (5.5) | 0.35% | — | Expresstech Quiz AND Survey Master | 1/7/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in a page/post where the Quiz is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.3) | 0.31% | — | Expresstech Quiz AND Survey Master | 14/6/2024 | 17/6/2026 | Missing Authorization vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.16. | |
| Modificada | Media (6.5) | 0.48% | — | Expresstech Quiz AND Survey Master | 7/6/2024 | 17/6/2026 | The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'question_id' parameter in all versions up to, and including, 9.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Media (5.9) | 0.34% | — | Expresstechsoftware Quiz AND Survey MasterAI | 11/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master allows Stored XSS.This issue affects Quiz And Survey Master: from n/a through 8.2.2. | |
| Aplazada | Crítica (9.3) | 2.0% | 💥 Exploit | Expresstechlabs Quiz AND Survey MasterAI | 26/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.4. | |
| Aplazada | Media (5.4) | 0.20% | — | Expresstechsoftware Quiz AND Survey MasterAI | 16/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.18. | |
| Modificada | Media (5.4) | 0.39% | — | Quizandsurveymaster Quiz AND Survey Master | 23/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master plugin <= 8.1.13 versions. | |
| Modificada | Alta (8.8) | 0.31% | — | Expresstech Quiz AND Survey Master | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.10 versions. | |
| Modificada | Media (5.4) | 0.55% | — | Expresstech Quiz AND Survey Master | 7/8/2023 | 17/6/2026 | The Quiz And Survey Master WordPress plugin before 8.1.11 does not properly sanitize and escape question titles, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (8.1) | 0.79% | — | Expresstech Quiz AND Survey Master | 9/6/2023 | 17/6/2026 | The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.8. This is due to missing nonce validation on the function associated with the qsm_remove_file_fd_question AJAX action. This makes it possible for unauthenticated attackers to delete… | |
| Modificada | Crítica (9.1) | 2.0% | — | Expresstech Quiz AND Survey Master | 9/6/2023 | 17/6/2026 | The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the function associated with the qsm_remove_file_fd_question AJAX action in versions up to, and including, 8.0.8. This makes it possible for unauthenticated attackers to delete arbitrary media files. | |
| Modificada | Alta (8.8) | 0.38% | — | Expresstech Quiz AND Survey Master | 14/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin <= 8.0.7 versions. | |
| Modificada | Media (5.3) | 0.73% | — | Expresstech Quiz AND Survey Master | 29/11/2022 | 17/6/2026 | The Quiz and Survey Master plugin for WordPress is vulnerable to input validation bypass via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input validation that allows attackers to inject content other than the specified value (i.e. a number, file path, etc..). This makes it… | |
| Modificada | Media (6.1) | 0.79% | — | Expresstech Quiz AND Survey Master | 29/11/2022 | 17/6/2026 | The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input sanitization and output escaping that allowed iframe tags to be injected. This makes it possible for unauthenticated attackers to inject… | |
| Modificada | Alta (7.5) | 0.71% | — | Expresstech Quiz AND Survey Master | 18/11/2022 | 17/6/2026 | Sensitive Information Disclosure vulnerability discovered by Quiz And Survey Master plugin <= 7.3.10 on WordPress. |