Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

278 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.62%—Harmonicdesign HD Quiz23/8/202117/6/2026
The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when generating the Quiz, which could lead to Stored Cross-Site Scripting issues
ModificadaMedia (6.1)3.4%💥 ExploitExpresstech Quiz AND Survey Master18/8/202117/6/2026
Cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script via unspecified vectors.
ModificadaAlta (7.2)1.3%—Ays-pro Quiz Maker2/8/202117/6/2026
The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL statements, leading to SQL injection issues in the admin dashboard
ModificadaMedia (6.1)0.83%—Expresstech Quiz AND Survey Master20/6/202117/6/2026
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue. This could allow for privilege escalation by inducing a logged in admin to…
ModificadaAlta (8.8)1.9%—Expresstech Quiz AND Survey Master12/4/202117/6/2026
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin before 7.1.12 did not sanitise the result_id GET parameter on pages with the [qsm_result] shortcode without id attribute, concatenating it in a SQL statement and leading to an SQL injection. The lowest role allowed to use this…
ModificadaMedia (5.3)2.1%💥 ExploitThrivethemes FocusblogThrivethemes IgnitionThrivethemes LuxeThrivethemes Minus+1612/4/202117/6/2026
The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive…
ModificadaMedia (6.1)0.86%—WEB Based Quiz System Project WEB Based Quiz System10/3/202117/6/2026
Web Based Quiz System 1.0 is affected by cross-site scripting (XSS) in register.php through the name parameter.
ModificadaMedia (6.1)0.86%—WEB Based Quiz System Project WEB Based Quiz System9/3/202117/6/2026
Web Based Quiz System 1.0 is affected by cross-site scripting (XSS) in admin.php through the options parameter.
ModificadaCrítica (9.9)76%💥 ExploitExpresstech Quiz AND Survey Master1/1/202117/6/2026
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an attacker to reinstall with a WordPress instance under their control. This occurred via…
ModificadaCrítica (9.8)5.1%—Expresstech Quiz AND Survey Master1/1/202117/6/2026
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution. If a quiz question could be answered by uploading a file, only the Content-Type header was checked during the upload,…
ModificadaMedia (4.8)0.61%—Techkshetrainfo Savsoft Quiz26/12/202017/6/2026
Savsoft Quiz 5 is affected by: Cross Site Scripting (XSS) via field_title (aka a title on the custom fields page).
ModificadaMedia (6.1)1.8%—Techkshetrainfo Savsoft Quiz26/12/202017/6/2026
A Cross Site Scripting (XSS) vulnerability in Savsoft Quiz v5.0 allows remote attackers to inject arbitrary web script or HTML via the Skype ID field.
ModificadaMedia (6.1)9.8%💥 ExploitTechkshetrainfo Savsoft Quiz25/8/202017/6/2026
TechKshetra Info Solutions Pvt. Ltd Savsoft Quiz 5.5 and earlier has XSS which can result in an attacker injecting the XSS payload in the User Registration section and each time the admin visits the manage user section from the admin panel, the XSS triggers and the attacker can steal the cookie via crafted payload.
ModificadaMedia (6.5)1.0%—Expresstech Quiz AND Survey Master16/8/202017/6/2026
php/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant stored XSS, via the question_name parameter because js/admin_question.js mishandles parsing inside of a SCRIPT element.
ModificadaCrítica (9.8)2.7%—Kibokolabs Chained Quiz10/3/202017/6/2026
controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote unauthenticated users to execute arbitrary SQL commands via the 'answer' and 'answers' parameters.
ModificadaMedia (6.1)1.6%—Kibokolabs Chained Quiz17/1/202017/6/2026
The chained-quiz plugin 1.1.8.1 for WordPress has reflected XSS via the wp-admin/admin-ajax.php total_questions parameter.
ModificadaMedia (6.1)1.7%—Expresstech Quiz AND Survey Master13/12/201917/6/2026
The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter (and/or the quiz_id parameter). The component is: admin/quiz-options-page.php.…
ModificadaCrítica (9.1)3.4%—Squiz Matrix11/12/201917/6/2026
An issue was discovered in core/assets/form/form_question_types/form_question_type_file_upload/form_question_type_file_upload.inc in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can delete arbitrary files from the server during…
ModificadaAlta (7.5)4.8%—Squiz Matrix11/12/201917/6/2026
An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can trigger arbitrary unserialization of a PHP object from a packages/cms/page_templates/page_remote_content/page_remote_content.inc POST parameter during…
ModificadaMedia (5.4)0.78%—Mtouch Quiz Project Mtouch Quiz20/9/201917/6/2026
The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via a quiz name.
ModificadaMedia (6.5)0.67%—Mtouch Quiz Project Mtouch Quiz20/9/201917/6/2026
The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS.
ModificadaMedia (6.5)0.67%—Mtouch Quiz Project Mtouch Quiz20/9/201917/6/2026
The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF.
ModificadaMedia (6.1)1.0%—Mtouch Quiz Project Mtouch Quiz20/9/201917/6/2026
The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via the quiz parameter during a Quiz Manage operation.
ModificadaMedia (6.1)1.2%—Slickquiz Project Slickquiz13/9/201917/6/2026
An XSS issue was discovered in the slickquiz plugin through 1.3.7.1 for WordPress. The save_quiz_score functionality available via the /wp-admin/admin-ajax.php endpoint allows unauthenticated users to submit quiz solutions/answers, which are stored in the database and later shown in the WordPress backend for all users…
ModificadaAlta (8.8)2.3%—Slickquiz Project Slickquiz13/9/201917/6/2026
The slickquiz plugin through 1.3.7.1 for WordPress allows SQL Injection by Subscriber users, as demonstrated by a /wp-admin/admin.php?page=slickquiz-scores&id= or /wp-admin/admin.php?page=slickquiz-edit&id= or /wp-admin/admin.php?page=slickquiz-preview&id= URI.
Orbitaley — Vulnerabilidades