Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

278 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.79%—Expresstech Quiz AND Survey Master29/11/202217/6/2026
The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input sanitization and output escaping that allowed iframe tags to be injected. This makes it possible for unauthenticated attackers to inject…
ModificadaAlta (7.5)0.46%—WEB Based Quiz System Project WEB Based Quiz System25/11/202217/6/2026
Web Based Quiz System v1.0 transmits user passwords in plaintext during the authentication process, allowing attackers to obtain users' passwords via a bruteforce attack.
ModificadaAlta (7.5)0.71%—Expresstech Quiz AND Survey Master18/11/202217/6/2026
Sensitive Information Disclosure vulnerability discovered by Quiz And Survey Master plugin <= 7.3.10 on WordPress.
ModificadaMedia (6.1)0.45%—Expresstech Quiz AND Survey Master18/11/202217/6/2026
Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.
ModificadaCrítica (9.8)0.75%—Expresstech Quiz AND Survey Master18/11/202217/6/2026
Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.
ModificadaMedia (5.4)0.47%—Expresstech Quiz AND Survey Master17/11/202217/6/2026
Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3.4 on WordPress.
ModificadaAlta (8.8)0.58%—Expresstech Quiz AND Survey Master3/11/202217/6/2026
Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress.
ModificadaAlta (7.2)0.91%—Expresstech Quiz AND Survey Master28/10/202217/6/2026
Auth. SQL Injection (SQLi) vulnerability in Quiz And Survey Master plugin <= 7.3.4 on WordPress.
ModificadaMedia (5.4)0.46%—Expresstech Quiz AND Survey Master28/10/202217/6/2026
Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress.
ModificadaMedia (5.4)0.50%—Expresstech Quiz AND Survey Master28/10/202217/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress.
ModificadaMedia (4.3)0.50%—Quizandsurveymaster Quiz AND Survey Master30/9/202217/6/2026
Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz.
ModificadaMedia (5.3)0.57%—Squiz Matrix6/9/202217/6/2026
Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate authorization when submitting a request to change a user's contact details. NOTE: this is disputed by both the vendor and the original discoverer because it is a site-specific finding, not a finding about…
ModificadaMedia (4.8)0.61%—Mtouch Quiz Project Mtouch Quiz8/8/202217/6/2026
The mTouch Quiz WordPress plugin through 3.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaCrítica (9.8)0.93%—WEB Based Quiz System Project WEB Based Quiz System2/8/202217/6/2026
Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the qid parameter at update.php.
ModificadaCrítica (9.3)1.4%—Automatedquizeval Project Automatedquizeval11/7/202217/6/2026
The sravaniboinepelli/AutomatedQuizEval repository through 2020-04-27 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaAlta (8.8)1.1%—WEB Based Quiz System Project WEB Based Quiz System15/6/202217/6/2026
Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the eid parameter at welcome.php.
ModificadaMedia (5.4)0.58%—Psychological Tests & Quizzes Project Psychological Tests & Quizzes26/4/202217/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin <= 0.21.19 on WordPress possible for users with contributor or higher role via &wpt_test_page_submit_button_caption parameter.
ModificadaMedia (5.4)0.57%—Psychological Tests & Quizzes Project Psychological Tests & Quizzes26/4/202217/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin <= 0.21.19 on WordPress possible for users with contributor or higher user rights.
ModificadaMedia (5.4)0.97%—Expresstech Quiz AND Survey Master17/1/202217/6/2026
Stored cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote authenticated attacker to inject an arbitrary script via an website that uses Quiz And Survey Master.
ModificadaMedia (6.1)1.3%—Expresstech Quiz AND Survey Master17/1/202217/6/2026
Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to inject an arbitrary script via unspecified vectors.
ModificadaAlta (8.8)0.65%—Expresstech Quiz AND Survey Master17/1/202217/6/2026
Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page.
ModificadaMedia (4.8)0.62%—Quiz Tool Lite Project Quiz Tool Lite8/11/202117/6/2026
The Quiz Tool Lite WordPress plugin through 2.3.15 does not sanitize multiple input fields used when creating or managing quizzes and in other setting options, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (6.5)0.67%—Wp-pro-quiz Project Wp-pro-quiz1/11/202117/6/2026
The WP-Pro-Quiz WordPress plugin through 0.37 does not have CSRF check in place when deleting a quiz, which could allow an attacker to make a logged in admin delete arbitrary quiz on the blog
ModificadaMedia (4.8)0.62%—Expresstech Quiz AND Survey Master11/10/202117/6/2026
The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaMedia (5.4)0.62%—Kibokolabs Chained Quiz11/10/202117/6/2026
The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings.
Orbitaley — Vulnerabilidades