Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
278 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.79% | — | Expresstech Quiz AND Survey Master | 29/11/2022 | 17/6/2026 | The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input sanitization and output escaping that allowed iframe tags to be injected. This makes it possible for unauthenticated attackers to inject… | |
| Modificada | Alta (7.5) | 0.46% | — | WEB Based Quiz System Project WEB Based Quiz System | 25/11/2022 | 17/6/2026 | Web Based Quiz System v1.0 transmits user passwords in plaintext during the authentication process, allowing attackers to obtain users' passwords via a bruteforce attack. | |
| Modificada | Alta (7.5) | 0.71% | — | Expresstech Quiz AND Survey Master | 18/11/2022 | 17/6/2026 | Sensitive Information Disclosure vulnerability discovered by Quiz And Survey Master plugin <= 7.3.10 on WordPress. | |
| Modificada | Media (6.1) | 0.45% | — | Expresstech Quiz AND Survey Master | 18/11/2022 | 17/6/2026 | Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress. | |
| Modificada | Crítica (9.8) | 0.75% | — | Expresstech Quiz AND Survey Master | 18/11/2022 | 17/6/2026 | Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress. | |
| Modificada | Media (5.4) | 0.47% | — | Expresstech Quiz AND Survey Master | 17/11/2022 | 17/6/2026 | Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3.4 on WordPress. | |
| Modificada | Alta (8.8) | 0.58% | — | Expresstech Quiz AND Survey Master | 3/11/2022 | 17/6/2026 | Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress. | |
| Modificada | Alta (7.2) | 0.91% | — | Expresstech Quiz AND Survey Master | 28/10/2022 | 17/6/2026 | Auth. SQL Injection (SQLi) vulnerability in Quiz And Survey Master plugin <= 7.3.4 on WordPress. | |
| Modificada | Media (5.4) | 0.46% | — | Expresstech Quiz AND Survey Master | 28/10/2022 | 17/6/2026 | Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress. | |
| Modificada | Media (5.4) | 0.50% | — | Expresstech Quiz AND Survey Master | 28/10/2022 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 on WordPress. | |
| Modificada | Media (4.3) | 0.50% | — | Quizandsurveymaster Quiz AND Survey Master | 30/9/2022 | 17/6/2026 | Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz. | |
| Modificada | Media (5.3) | 0.57% | — | Squiz Matrix | 6/9/2022 | 17/6/2026 | Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate authorization when submitting a request to change a user's contact details. NOTE: this is disputed by both the vendor and the original discoverer because it is a site-specific finding, not a finding about… | |
| Modificada | Media (4.8) | 0.61% | — | Mtouch Quiz Project Mtouch Quiz | 8/8/2022 | 17/6/2026 | The mTouch Quiz WordPress plugin through 3.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Crítica (9.8) | 0.93% | — | WEB Based Quiz System Project WEB Based Quiz System | 2/8/2022 | 17/6/2026 | Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the qid parameter at update.php. | |
| Modificada | Crítica (9.3) | 1.4% | — | Automatedquizeval Project Automatedquizeval | 11/7/2022 | 17/6/2026 | The sravaniboinepelli/AutomatedQuizEval repository through 2020-04-27 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Alta (8.8) | 1.1% | — | WEB Based Quiz System Project WEB Based Quiz System | 15/6/2022 | 17/6/2026 | Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the eid parameter at welcome.php. | |
| Modificada | Media (5.4) | 0.58% | — | Psychological Tests & Quizzes Project Psychological Tests & Quizzes | 26/4/2022 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin <= 0.21.19 on WordPress possible for users with contributor or higher role via &wpt_test_page_submit_button_caption parameter. | |
| Modificada | Media (5.4) | 0.57% | — | Psychological Tests & Quizzes Project Psychological Tests & Quizzes | 26/4/2022 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin <= 0.21.19 on WordPress possible for users with contributor or higher user rights. | |
| Modificada | Media (5.4) | 0.97% | — | Expresstech Quiz AND Survey Master | 17/1/2022 | 17/6/2026 | Stored cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote authenticated attacker to inject an arbitrary script via an website that uses Quiz And Survey Master. | |
| Modificada | Media (6.1) | 1.3% | — | Expresstech Quiz AND Survey Master | 17/1/2022 | 17/6/2026 | Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.65% | — | Expresstech Quiz AND Survey Master | 17/1/2022 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page. | |
| Modificada | Media (4.8) | 0.62% | — | Quiz Tool Lite Project Quiz Tool Lite | 8/11/2021 | 17/6/2026 | The Quiz Tool Lite WordPress plugin through 2.3.15 does not sanitize multiple input fields used when creating or managing quizzes and in other setting options, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (6.5) | 0.67% | — | Wp-pro-quiz Project Wp-pro-quiz | 1/11/2021 | 17/6/2026 | The WP-Pro-Quiz WordPress plugin through 0.37 does not have CSRF check in place when deleting a quiz, which could allow an attacker to make a logged in admin delete arbitrary quiz on the blog | |
| Modificada | Media (4.8) | 0.62% | — | Expresstech Quiz AND Survey Master | 11/10/2021 | 17/6/2026 | The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (5.4) | 0.62% | — | Kibokolabs Chained Quiz | 11/10/2021 | 17/6/2026 | The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings. |