Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.15% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions. | |
| Aplazada | Media (5.3) | 0.31% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 11/9/2026 | 11/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions. | |
| Aplazada | Baja (2.7) | 0.30% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 28/8/2026 | 28/8/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API routes, allowing users with a role as low as Contributor to read the questions, hints and correct answer keys of quizzes belonging to other users. | |
| Aplazada | Baja (2.7) | 0.30% | — | Expressivequiz Quiz AND Survey MasterAI | 19/8/2026 | 26/8/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient… | |
| Aplazada | Baja (2.7) | 0.28% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 19/8/2026 | 26/8/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before saving a quiz's front-end text settings, allowing users with contributor-level access and above to modify the text settings of quizzes created by other users. | |
| Aplazada | Media (6.5) | 0.45% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 16/8/2026 | 20/8/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via 'randon_category' Quiz Option in all versions up to, and including, 11.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Media (6.4) | 0.42% | — | Expresstech Quiz Survey MasterAI | 16/8/2026 | 20/8/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.8) | 0.24% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 4/8/2026 | 26/8/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outputting it into an unquoted HTML attribute, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the browser of any user viewing the affected quiz. | |
| Aplazada | Baja (2.7) | 0.28% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 28/7/2026 | 28/7/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates. | |
| Aplazada | Media (5.3) | 0.37% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 27/7/2026 | 27/7/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinct responses for valid and invalid accounts, allowing unauthenticated attackers to enumerate valid usernames and to… | |
| Aplazada | Alta (8.5) | 0.36% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 23/7/2026 | 23/7/2026 | Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions. | |
| Aplazada | Media (4.3) | 0.49% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 3/7/2026 | 6/7/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.3) | 0.47% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 27/6/2026 | 29/6/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.1) | 0.25% | — | Expressionengine Quiz AND Survey MasterAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.1.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Expressionengine Quiz AND Survey MasterAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.0.0 versions. | |
| Aplazada | Media (4.9) | 0.60% | — | Expressionengine Quiz AND Survey MasterAI | 6/6/2026 | 23/7/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order' parameter in all versions up to, and including, 11.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Media (5.3) | 0.67% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 17/4/2026 | 17/6/2026 | The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and including 11.1.0. This is due to insufficient input sanitization and the execution of do_shortcode() on user-submitted quiz answer text. User-submitted answers pass through sanitize_text_field() and… | |
| Aplazada | Media (6.5) | 0.32% | — | Quizandsurveymaster Quiz AND Survey MasterAI | 23/3/2026 | 17/6/2026 | The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to SQL Injection via the 'merged_question' parameter in all versions up to, and including, 10.3.5. This is due to insufficient sanitization of user-supplied input before being used in a SQL query. The sanitize_text_field() function applied to the… | |
| Aplazada | Alta (8.5) | 0.27% | — | Expresstechsystems Quiz AND Survey MasterAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows SQL Injection.This issue affects Quiz And Survey Master: from n/a through <= 10.3.1. | |
| Aplazada | Media (4.3) | 0.19% | — | Expresstechsystems Quiz AND Survey MasterAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.4. | |
| Aplazada | Media (5.3) | 0.33% | — | Expresstechsystems Quiz AND Survey MasterAI | 19/2/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.4. | |
| Aplazada | Media (4.3) | 0.18% | — | Expresstechsystems Quiz AND Survey MasterAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.3. | |
| Analizada | Media (6.5) | 0.27% | — | Expresstech Quiz AND Survey Master | 6/1/2026 | 30/9/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability and status checks on multiple functions in all versions up to, and including, 10.3.1. This makes it possible for unauthenticated attackers to view… | |
| Analizada | Media (6.5) | 0.26% | — | Expresstech Quiz AND Survey Master | 6/1/2026 | 30/9/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injection via the ‘is_linking’ parameter in all versions up to, and including, 10.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Modificada | Media (4.3) | 0.22% | — | Expresstech Quiz AND Survey Master | 6/1/2026 | 30/9/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the qsm_dashboard_delete_result function in all versions up to, and including, 10.3.1. This makes it possible for authenticated attackers, with… |