Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
278 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.39% | — | Ays-pro Quiz Maker | 1/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Quiz Maker quiz-maker allows SQL Injection.This issue affects Quiz Maker: from n/a through <= 6.6.8.7. | |
| Aplazada | Baja (2.7) | 0.45% | — | Fatcatapps Quiz CATAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in fatcatapps Quiz Cat quiz-cat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz Cat: from n/a through <= 3.0.8. | |
| Analizada | Media (6.1) | 0.33% | — | Expresstech Quiz AND Survey Master | 25/3/2025 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Alta (7.1) | 0.28% | — | Binnyva QuizzinAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in binnyva Quizzin quizzin allows Reflected XSS.This issue affects Quizzin: from n/a through <= 1.01.4. | |
| Aplazada | Media (4.4) | 0.48% | — | Quiz OrganizerAI | 26/2/2025 | 17/6/2026 | The Quiz Organizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that… | |
| Analizada | Media (5.4) | 0.25% | — | Najeebmedia Easy Quiz Maker | 12/2/2025 | 17/6/2026 | The Easy Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wqt-question' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.15% | — | Cyrillg Fyrebox QuizzesAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CyrilG Fyrebox Quizzes fyrebox-shortcode allows Stored XSS.This issue affects Fyrebox Quizzes: from n/a through <= 3.1. | |
| Aplazada | Media (6.1) | 0.32% | — | Quiz Maker BusinessAIQuiz Maker DeveloperAIQuiz Maker AgencyAI | 26/1/2025 | 17/6/2026 | The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency) due to insufficient input… | |
| Aplazada | Alta (7.3) | 0.55% | — | Quiz Maker BusinessAIQuiz Maker DeveloperAIQuiz Maker AgencyAI | 26/1/2025 | 17/6/2026 | The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency). This is due to the software allowing users to execute an… | |
| Analizada | Alta (7.5) | 0.85% | — | Ays-pro Quiz Maker | 26/1/2025 | 17/6/2026 | The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency) due to insufficient escaping on the user supplied… | |
| Aplazada | Alta (7.2) | 0.47% | — | Ays-pro Quiz Maker BusinessAIAys-pro Quiz Maker DeveloperAIAys-pro Quiz Maker AgencyAI | 26/1/2025 | 17/6/2026 | The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ays_save_google_credentials' function in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and… | |
| Aplazada | Media (4.4) | 0.33% | — | Kibokolabs Chained QuizAI | 24/1/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Bob Chained Quiz chained-quiz allows Server Side Request Forgery.This issue affects Chained Quiz: from n/a through <= 1.3.2.9. | |
| Aplazada | Alta (7.1) | 0.26% | — | Oleksandr87 University Quizzes OnlineAI | 23/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oleksandr87 University Quizzes Online university-quizzes-online allows Reflected XSS.This issue affects University Quizzes Online: from n/a through <= 1.4. | |
| Aplazada | Media (6.5) | 0.40% | — | Revenuehunt Product-recommendation-quiz-for-ecommerceAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in RevenueHunt Product Recommendation Quiz for eCommerce product-recommendation-quiz-for-ecommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Recommendation Quiz for eCommerce: from n/a through <= 2.1.2. | |
| Aplazada | Media (4.3) | 0.47% | — | Expresstechsoftwares Quiz AND Survey MasterAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in ExpressTech Quiz And Survey Master allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through 8.1.10. | |
| Aplazada | Alta (8.8) | 0.43% | — | AI QuizAI | 6/12/2024 | 17/6/2026 | The AI Quiz | Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ai_quiz_update_style() function in all versions up to, and including, 1.1. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (8.8) | 0.47% | — | Kibokolabs Watu Quiz | 2/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Watu Quiz watu allows SQL Injection.This issue affects Watu Quiz: from n/a through <= 3.4.1.2. | |
| Aplazada | Media (5.3) | 0.55% | — | Kekotron AI QuizAI | 2/12/2024 | 17/6/2026 | Missing Authorization vulnerability in kekotron AI Quiz ai-quiz allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects AI Quiz: from n/a through <= 1.1. | |
| Aplazada | Media (5.4) | 0.48% | — | Harmonicdesign HD Quiz Save Results LightAI | 19/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Harmonic Design HD Quiz – Save Results Light hd-quiz-save-results-light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HD Quiz – Save Results Light: from n/a through <= 0.5. | |
| Aplazada | Media (5.3) | 0.38% | — | Kibokolabs Chained QuizAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Kiboko Labs Chained Quiz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chained Quiz: from n/a through 1.3.2.8. | |
| Modificada | Media (4.8) | 0.40% | — | Expresstech Quiz AND Survey Master | 23/9/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (5.3) | 0.61% | — | Fabian Online Quiz Site | 20/9/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Online Quiz Site 1.0. This issue affects some unknown processing of the file showtest.php. The manipulation of the argument subid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (6.9) | 0.65% | — | Fabian Online Quiz Site | 27/8/2024 | 17/6/2026 | A vulnerability was found in code-projects Online Quiz Site 1.0 and classified as critical. This issue affects some unknown processing of the file index.php. The manipulation of the argument loginid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (6.9) | 0.65% | — | Fabian Online Quiz Site | 26/8/2024 | 17/6/2026 | A vulnerability was found in code-projects Online Quiz Site 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file signupuser.php. The manipulation of the argument lid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (4.7) | 0.43% | — | Expresstech Quiz AND Survey Master | 26/8/2024 | 17/6/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before displaying them on a page or post where the Quiz is embedded, which could allows contributor and above roles to perform Stored Cross-Site Scripting (XSS) attacks. |