Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2625▼ 312 respecto a la semana anterior
Críticas / altas1347▲ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)61▼ 466 respecto a la semana anterior
277 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.15% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions. | |
| Aplazada | Alta (7.6) | 0.28% | — | Quiz CATAI | 30/9/2026 | 30/9/2026 | Author SQL Injection in Quiz Cat <= 3.1.1 versions. | |
| Aplazada | Media (5.3) | 0.31% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 11/9/2026 | 11/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions. | |
| Aplazada | Baja (2.7) | 0.30% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 28/8/2026 | 28/8/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allowing users with a role as low as Contributor to read the questions, hints and correct answer keys of quizzes belonging to other users. | |
| Aplazada | Baja (2.7) | 0.30% | — | Expressivequiz Quiz AND Survey MasterAI | 19/8/2026 | 26/8/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient… | |
| Aplazada | Baja (2.7) | 0.28% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 19/8/2026 | 26/8/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level access and above to modify the text settings of quizzes created by other users. | |
| Aplazada | Media (6.5) | 0.45% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 16/8/2026 | 20/8/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via 'randon_category' Quiz Option in all versions up to, and including, 11.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Media (6.4) | 0.42% | — | Expresstech Quiz Survey MasterAI | 16/8/2026 | 20/8/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.8) | 0.24% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 4/8/2026 | 26/8/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outputting it into an unquoted HTML attribute, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the browser of any user viewing the affected quiz. | |
| Aplazada | Baja (2.7) | 0.28% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 28/7/2026 | 28/7/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates. | |
| Aplazada | Media (5.3) | 0.37% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 27/7/2026 | 27/7/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to… | |
| Aplazada | Alta (8.5) | 0.36% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 23/7/2026 | 23/7/2026 | Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Thrive Quiz BuilderAI | 23/7/2026 | 23/7/2026 | Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions. | |
| Aplazada | Media (6.5) | 0.41% | — | Quiz Master NextAI | 16/7/2026 | 16/7/2026 | The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, and including, 11.2.0. This is due to insufficient escaping on the user-supplied 'pages' parameter persisted by the qsm_ajax_save_pages() AJAX handler (sanitize_text_field only) and lack of sufficient… | |
| Aplazada | Media (4.3) | 0.49% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 3/7/2026 | 6/7/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.3) | 0.47% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 27/6/2026 | 29/6/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.3) | 0.26% | — | Harmonicdesign HD QuizAI | 27/6/2026 | 29/6/2026 | The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to missing or incorrect nonce validation on the hdq_validate_nonce function. This makes it possible for unauthenticated attackers to delete or modify quizzes and questions, create new quizzes, and… | |
| Analizada | Alta (8.8) | 0.49% | — | Webkul Ajax Quiz | 19/6/2026 | 19/8/2026 | Joomla! Component Ajax Quiz 1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cid parameter. Attackers can send GET requests to index.php with the option=com_ajaxquiz and view=ajaxquiz parameters to extract… | |
| Analizada | Alta (8.8) | 0.49% | — | Joomplace Quiz Deluxe | 19/6/2026 | 19/8/2026 | Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the ajaxaction.flag_question task. Attackers can inject malicious SQL code via the stu_quiz_id or flag_quest parameters to manipulate database queries and extract… | |
| Aplazada | Media (4.3) | 0.25% | — | Pressprimer QuizAI | 18/6/2026 | 18/6/2026 | The PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.3.0 via the 'rule_id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated… | |
| Aplazada | Alta (7.1) | 0.25% | — | Expressionengine Quiz AND Survey MasterAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.1.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Expressionengine Quiz AND Survey MasterAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.0.0 versions. | |
| Aplazada | Media (4.9) | 0.60% | — | Expressionengine Quiz AND Survey MasterAI | 6/6/2026 | 23/7/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order' parameter in all versions up to, and including, 11.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Media (5.1) | 0.24% | — | Savsoft QuizAI | 15/5/2026 | 17/6/2026 | Savsoft Quiz 5.0 contains a persistent cross-site scripting vulnerability in the user account settings page that allows authenticated attackers to inject malicious HTML and JavaScript code. Attackers can inject script payloads into user profile fields at the edit_user endpoint, which execute in the browsers of users… | |
| Aplazada | Media (5.8) | 0.37% | — | Ays-pro Quiz MakerAI | 2/5/2026 | 17/6/2026 | The Quiz Maker by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rate_reason' parameter in all versions up to, and including, 6.7.1.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… |